Malaysia Ranked 33rd Among Countries Globally on Internet Security Threat Activities
KUALA LUMPUR, Malaysia – 21 April 2014 – After lurking in the shadows for the first ten months of 2013, cybercriminals unleashed the most damaging series of cyberattacks in history. Symantec Corp.’s (Nasdaq: SYMC) Internet Security Threat Report Volume 19 (ISTR 19), shows a significant shift in cybercriminal behaviour, revealing the bad guys are plotting for months before pulling off huge heists – instead of executing quick hits with smaller rewards.
In 2013, there was a 62 percent increase in the number of data breaches globally from the previous year, resulting in more than 552 million identities exposed – proving cybercrime remains a real and damaging threat to consumers and businesses alike. One mega breach can possibly be worth 50 smaller attacks.
“While the level of sophistication continues to grow among cyber attackers, what was surprising last year was the cyber attackers’ willingness to be a lot more patient – waiting to strike until the reward is bigger and better,” said Eric Hoh, Symantec’s Vice President for Asia South and Korea regions.“With cybercriminals constantly innovating and enhancing their modes of attacks, companies globally and in Malaysia cannot afford to let their guard down. The consequences of complacency can be far-reaching, causing commercial and reputation damage.”
Nigel Tan, Director of Systems Engineering at Symantec Malaysia said, “Malaysia’s Internet security profile declined last year and ranked 33rd among countries globally on Internet security threat activities. This is a clear indication that cybercriminals have not slowed down, in fact they are increasing the efficiency of their campaigns and have their eye on Small and Medium Businesses (SMBs) with less than 500 employees, in particular the healthcare and transport/utility sectors in Malaysia.”
Defense is Harder than Offense
The size and scope of data breaches globally is exploding, putting the trust and reputation of businesses at risk, and increasingly compromising consumers’ personal information – from credit card numbers and medical records to passwords and bank account details. Each of the eight top data breaches in 2013 resulted in the loss of tens of millions of data records. By comparison, 2012 only had a single data breach reach that threshold.
“For cybercriminals, the potential for huge paydays means large-scale cyber attacks are here to stay. Companies of all sizes need to re-examine, re-think and possibly re-architect their security posture,” said David Rajoo, Principal Consultant at Symantec Malaysia.
Targeted attacks were up 91 percent globally in 2013 and lasted an average of three times longer compared to 2012. Personal assistants and those working in public relations were the two most targeted professions – cybercriminals use them as a stepping stone toward higher-profile targets like celebrities or business executives.
“What is interesting is the targeted attacks became slow and low as cyber attackers increased the number of campaigns they ran, but decreased the emails used and the number of people they attacked in each campaign. It’s almost as if they brought in efficiency experts to improve their attack campaigns,” David explained.
How to Maintain Cyber Resiliency
While the increasing flow of data from smart devices, apps and other online services is tantalising to cybercriminals, there are steps businesses and consumers can take to better protect themselves – whether it be from a mega data breach, targeted attack or common spam. Symantec recommends the following best practices:
For Businesses:
Know your data: Protection must focus on the information – not the device or data centre. Understand where your sensitive data resides and where it is flowing to help identify the best policies and procedures to protect it.
Educate employees: Provide guidance on information protection, including company policies and procedures for protecting sensitive data on personal and corporate devices.
Implement a strong security posture: Strengthen your security infrastructure with data loss prevention, network security, endpoint security, encryption, strong authentication and defensive measures, including reputation-based technologies.
For Consumers:
Be security savvy: Passwords are the keys to your kingdom. Use password management software to create strong, unique passwords for each site you visit and keep your devices – including smartphones – updated with the latest security software.
Be vigilant: Review bank and credit card statements for irregularities, be cautious when handling unsolicited or unexpected emails and be wary of online offers that seem too good to be true – they usually are.
Know who you work with: Familiarise yourself with policies from retailers and online services that may request your banking or personal information. As a best practice, visit the company’s official website directly (as opposed to clicking on an emailed link) if you must share sensitive information.
Monday, April 21, 2014
New Era of ‘Mega Breaches’ Signals Bigger Payouts and Shifting Behaviour for Cybercriminals
Thursday, March 13, 2014
Mitigating Security Threats on Point of Sale Systems in Malaysia
By Nigel Tan (陈善龙).
Director, Systems Engineering, Malaysia
One of the earliest forms of cybercrime is credit and debit card data theft and this continues to persist today. Cybercrime gangs organise sophisticated operations to steal vast amounts of data before selling it in underground marketplaces. Criminals can use the data stolen from a card’s magnetic strip to create clones and it’s a potentially lucrative business with individual cards selling for up to US$100.
“There are several routes attackers can take to steal this data. One option is to gain access to a database where card data is stored. But another option is to target the point at which a retailer first acquires that card data – the point of sale (POS) system,” said Nigel Tan, Director of Systems Engineering, Symantec Malaysia.
He explained that while many POS transactions are in the form of cash, many of these payments are made by customers swiping their cards through a card reader. These card readers may be standalone devices but modern POS systems, particularly those in larger retailers, are all-in-one systems which can handle a variety of customer transactions such as sales, returns, gift cards and promotions. Most importantly from a security standpoint, they can handle multiple payment types.
Given the sensitive financial and sometimes, personal data to which modern POS systems have access, it is an obvious but not always well recognised fact that the security of these systems is of utmost importance.
Security issues in POS systems
Modern POS systems are specially configured computers with sales software installed and equipped with a card reader. Using a process known as “skimming”, card data can be stolen by installing a device onto the card reader which can read the data off the card’s magnetic strip. As this requires additional hardware and physical access to the card reader, it is difficult to carry out this type of theft on a large scale.
This led to the development of malware which can copy the card data as soon as it’s read by the card reader. The first of such attacks were seen in 2005 with a series of campaigns orchestrated by Albert Gonzalez, a hacker who stole over 170 million card numbers. Since then, an industry has developed around attacking POS systems, with tools readily available on the underground marketplace.
“Despite improvements in card security technologies and the requirements of the Payment Card Industry (PCI) Data Security Standard (DSS), there are still gaps in the security of POS systems. This coupled with more general security weaknesses in corporate IT infrastructure means that retailers find themselves exposed to increasingly resourceful and organised cybercriminal gangs,” said Tan.
Card data theft is likely to continue in the near term. Stolen card data has a limited shelf-life. Credit card companies are quick to spot anomalous spending patterns, as are observant card owners. This means that criminals need a steady supply of “fresh” card numbers.
The good news is that retailers will learn lessons from attacks and take steps to prevent the re-occurrence of this type of attack. Payment technology will also change. Many US retailers are now expediting the transition to Europay, Mastercard and VISA (EMV) standards, or “chip and pin” payment technologies. Chip and Pin cards are much more difficult to clone, making them less attractive to attackers. And of course new payment models may take over. Smartphones may become the new credit cards as mobile, or NFC, payment technology becomes more widely adopted.
“There’s no doubt that cybercriminals will respond to these changes. But as retailers adopt newer technologies and security companies continue to monitor the attackers, large-scale POS thefts will become more difficult and certainly less profitable,” said Tan.
Risks with End of Support for Windows XP
The majority of POS systems run the older Windows XP version of Windows Embedded. This older version is more susceptible to vulnerabilities and therefore more open to attack. In addition, Microsoft will end technical assistance for Windows XP operating system on 8 April 2014, including automatic updates and regularly issued security patches. Systems that continue to use Windows XP after the deadline will face increased security risks, particularly if new vulnerabilities are discovered in the operating system. Consequently, these systems are susceptible to a wide variety of attack scenarios which could lead to large scale data breaches. Organisations with systems running on Windows XP Embedded (XPE) face a similar situation, but more time to transition, as Microsoft will end support for XPE in January 2016.
As many POS systems are running a version of Windows, they are also capable of running any malware that runs on Windows. Thus, attackers do not need specialised skills in order to target POS systems and malware that were not specifically designed for use on POS systems could be easily repurposed for use against them.
Layered Protection
“There are many steps that POS operators can take to reduce the risk from attacks against POS systems but above all, the overarching reminder is to implement layered security on the POS systems and throughout the network,” advised Tan.
A properly configured endpoint protection product can block even the most determined attacker, and this is especially true when it comes to a POS system. POS systems actually have a security advantage over a PC as a single function device. Because no one on that device is web browsing, emailing or opening shared drives, the functionally of the machine and the files needed on that machine are limited.
Symantec Endpoint Protection built on multiple layers of protection, including Symantec Insight and SONAR, is designed to protect against new and unknown threats. It also offers tools to reduce the attack surface by limiting the specific applications running on the machine, as well as controls the devices and applications allowed to access the network. Limiting applications and network accessibility on the machines can render malware useless because it won't be allowed to run on the machines or the network. Symantec Critical System Protection also offers important server protections for physical and virtual data centers that allow enterprises to lock down applications, configuration settings and resources so that malicious code and vulnerabilities cannot be exploited.
In short, to implement the best protection for Windows-based POS systems, organisations need to have layered security as part of the IT architecture.
发表者
SC Cyberworld
0
评论
标签: Cybercrime, Symantec, Windows XP
Monday, January 27, 2014
IBM Sets U.S. Patent Record; Achieves 21st Straight Year of Patent Leadership
IBM inventors received more than 6,800 U.S. patents in 2013 including 3 from Malaysia
PETALING JAYA 27 Jan 2014: IBM (NYSE: IBM) inventors received a record-setting 6,809 patents for 2013, making it the 21st consecutive year the company topped the annual list of U.S. patent leaders. The 6,809 patents included three that were awarded to Malaysian teams whose inventions have helped our clients improve their business processes.
The three local patents were for the following inventions: automated paper consumption tracking and auditing; message oriented construction of web services; and, spacer and process to enhance the strain in the channel with stress liner.
"IBMers in Malaysia are proud with the recognition that underscores that when talent and creativity are combined with teamwork, the results are immeasurable," said IBM Malaysia managing director, Paul Moung.
“We take pride in being recognized as the U.S. patent leader, but patents are only one gauge of innovation. Equally significant is the impact that our patented inventions have when they are used to enable solutions that help clients and societies solve problems,”said Bernie Meyerson, IBM Fellow and VP of Innovation. “Furthermore, the broad range of inventions that these patents represent underscores the need for a patent system that equally and fairly promotes and supports innovation across all technical fields.”
IBM's 2013 patent total exceeded the combined totals of Amazon, Google, EMC, HP, Intel, Oracle/SUN and Symantec. The company's record 2013 patent count was made possible by more than 8,000 IBM inventors residing in 47 different U.S. states and 41 countries.
The Top Ten list of 2013 U.S. patent recipients* includes:
1 IBM 6,809
2 Samsung 4,676
3 Canon 3,825
4 Sony 3,098
5 Microsoft 2,660
6 Panasonic 2,601
7 Toshiba 2,416
8 Hon Hai 2,279
9 Qualcomm 2,103
10 LG Electronics 1,947
Friday, January 17, 2014
Symantec Introduces Unique New Technologies in Malaysia to Fight Evolving Targeted Attacks
New Disarm technology and network threat protection for Mac computers added to Symantec’s protection portfolio
KUALA LUMPUR, Malaysia – January 16, 2014 – Symantec (NASDAQ:SYMC) today announced new additions to its industry leading protection technologies to protect organisations from targeted attacks. The powerful new innovations include Disarm technology in Symantec Messaging Gateway and the addition of Network Threat Protection in Symantec Endpoint Protection for Mac computers.
Defending against sophisticated targeted attacks is now the norm, and it’s not just large companies that are being impacted. Targeted attacks are growing significantly among businesses with fewer than 250 employees. Small businesses globally are the target of 31 percent of all attacks, according to the 2013 Internet Security Threat Report. Small companies are an attractive target for cybercriminals as they have fewer security safeguards and often have business relationships with larger companies which may be the ultimate target of attackers.
“The new technologies, combined with our comprehensive solution portfolio, will protect organisations in Malaysia from threats at the gateway, on the endpoint and in the data centre,” she added.
Protection at the Gateway: Disarm Technology
Developed by Symantec Research Labs, Symantec’s advanced research division, the new Disarm technology in Symantec Messaging Gateway 10.5 uses a first-of-a-kind technique to protect companies from targeted attacks. Most targeted attacks are now delivered in the form of malicious, but seemingly innocuous, documents delivered over email. Each such malicious document, e.g., a PDF, DOC or XLS file, contains an embedded attack, and when a victim simply views the document, their computer is automatically and silently compromised.
Traditional protection technologies attempt to scan documents for suspicious characteristics. The problem is that many of these document-based attacks are purposefully crafted so they don’t look suspicious, and as a result, they go undetected.
“Disarm technology takes a whole new approach. Instead of scanning the document, it essentially makes a digital harmless carbon copy of every incoming email attachment/document, delivering this carbon copy to the recipient, rather than the original, potentially malicious document. The result is that the recipient is never exposed to the attacker’s malicious attachment,” said David Rajoo, Principal Consultant, Symantec Malaysia.
According to Symantec research, the Disarm technology would have blocked 98 percent of attacks that exploit zero-day document vulnerabilities thus far in 2013 – these are attacks that were entirely unknown and would therefore have likely evaded all traditional scanners, heuristics, emulators and even Virtual Execution (VX) solutions.
Protection at the Endpoint: Network Threat Protection for Mac Computers
Symantec has added its advanced Network Threat Protection technology to the Mac version of the Symantec Endpoint Protection 12.1.4. “Many Mac users think they’re impervious to attacks, and as a result don’t take security seriously. But the reality is that this makes Mac users a potential goldmine for targeted attackers. Symantec’s Network Threat Protection technology intercepts incoming network traffic before it can impact the Mac computers, looking for targeted attack exploits and automatically blocking them,” said David.
Network Threat Protection technology uses a patented, application-level, protocol-aware Intrusion Prevention System to not only identify and block known attacks, but also identify and block many unknown or day-zero attacks.
Protection at the Data Centre: Solutions to Protect the Physical and Virtual Data Centre
Symantec also protects an organisation’s critical assets and information in the data centre. Symantec offers Symantec Critical System Protection (CSP), a server lockdown solution designed to protect both physical and virtual infrastructure. Organisations can install and configure CSP so it only allows known-legitimate activities on your servers and blocks all other (anomalous) activities. If a targeted attacker does compromise a server, they must – by definition – perform activities that will deviate from the norm in order to access sensitive data on the machine, or elsewhere in the data centre. CSP automatically detects and blocks those deviations, stopping the attack automatically. Only approved software programs are allowed to run, and those programs are only allowed to perform approved behaviors, access approved resources, etc.
Targeted Attack Protection Powered by Unmatched Expertise, Global Intelligence
In addition to these new innovative technologies, Symantec’s security solutions are powered by the Symantec Global Intelligence Network (GIN) and a team of more than 550 researchers around the world. Symantec’s GIN platform collects anonymous telemetry from Symantec’s hundreds of millions of customers and sensors around the clock. Symantec uses this data – more than 2.5 trillion rows of security telemetry – to automatically discover new attacks, and monitor attacker networks. Symantec also uses this data to develop predictive, proactive protection technologies, such as Symantec’s Insight reputation technology, for gateway, endpoint and data centre offerings.
Symantec (赛门铁克) 在马来西亚推出独特新技术全方位防御不断演变的针对性攻击
Symantec (赛门铁克)扩大防御产品组合推出新 Disarm 技术和网络威胁防护更完善保护 Mac 电脑
吉隆坡,马来西亚 - 2014年1月16日 – Symantec (赛门铁克) (NASDAQ:SYMC) 今日宣布为业界领先的防御解决分案推出全新独特技术,帮助用户全方位防御针对性攻击。此次发布的强大创新技术包括在 Symantec (赛门铁克) Messaging Gateway 中置入全新 Disarm 技术,及在Symantec 端点安全防护产品 (Symantec (赛门铁克) Endpoint Protection) 中融入网络威胁防护 (Network Threat Protection) 技术,提升保护Mac 电脑系统的功能。
如今,防御复杂的针对性攻击已成规范,而且针对性攻击不仅限于大型企业机构。规模少于250名员工的公司,受到针对性攻击的数次也显著增加。根据2013 互联网安全威胁报告 在所有攻击对象中有31%是全球的小型企业。小型公司成为受欢迎的攻击目标,是因为小型公司具有较少安全措施,并常与大企业展开业务联系;而这些大企业或许是黑客发动针对性攻击的最终目标。
Symantec (赛门铁克)马来西亚总监Josephine Ho(何美丽)说:“严守防线,避免企业机构受到不断演变的针对性攻击,是目前首席资讯安全执行员(CISO)和 IT经理最关注的要务;针对性攻击已成为主要威胁趋势的重要部分。”
她补充:“新技术结合我们的全方位解决方案组合,保护马来西亚的企业机构免受到从网关、端点、数据中心或任何其他途径进入企业网络的威胁。”
保护网关:Disarm 技术
在 Messaging Gateway 10.5 中新增的 Disarm 技术,是由Symantec (赛门铁克) 的高阶研发部 Symantec 研发实验室开发,采用业界创新技术以保护公司免受针对性攻击的侵害。现在的大部分针对性攻击通过电子邮件发送看似无害的文件作恶意攻击。这些恶意文件例如PDF,DOC或XLS格式的文档,其中含有嵌入式攻击。当用户打开这些恶意文件时,他们的电脑就会在完全不知情的状况下,自动受到攻击。
传统保护技术会扫描文件以检测可疑特征。但问题是,这些恶意文件都经过精心策划,伪装成无害的样子,因此都不会被发现。
Symantec (赛门铁克)马来西亚首席顾问David Rajoo说:“创新的Disarm技术采用全新方法对抗攻击。有别于一般扫描文件,它将每一个进来的邮件附件/文件,替换成无害数码副本,然后将副本交付给收件人,而不是可能附有恶意程序的原件。因此收件人不会接触到恶意文件。”
据 Symantec 的研究发现,Disarm 技术能够拦截至2013年为止 98% 利用zero-Day 漏洞的攻击。因为这些攻击完全未知,因此可能逃避传统的病毒指纹、启发式检测、模拟器以及虚拟执行(VX)解决方案。
保护端点:网络威胁防护,全面保护 Mac 电脑系统
Symantec (赛门铁克)已将其先进的网络威胁防护 (Network Threat Protection) 技术,加入 Mac 版Symantec (赛门铁克) Endpoint Protection 12.1.4。David 说道:“由于许多Mac用户认为不会受到攻击,因此忽视安全问题。而事实是这种想法使 Mac用户成为针对性攻击者的潜在金矿。Symantec (赛门铁克)的网络威胁防护技术能迅速截获进入系统的网络流量,从而准确定位针对性攻击的漏洞利用并自动将其拦截,有效防止 Mac 电脑受到攻击。”
网络威胁防护采用一项获得专利的应用层协议感知入侵防御系统(Intrusion Prevention System ),不仅能识别和拦截已知攻击,也能识别和拦截许多未知攻击或Zero-Day漏洞攻击。
保护数据中心:保护现实和虚拟数据中心的解决方案
Symantec (赛门铁克) 也保护企业机构于数据中心的重要资产和资讯。Symantec (赛门铁克)提供Symantec (赛门铁克) Critical System Protection(CSP),一款专为保护现实和虚拟基础设施的服务器锁定解决方案。企业机构可以安装和配置CSP,令它只允许已知的合法活动在服务器上运行,并拦截其它所有(反常的)活动。如果针对性攻击对服务器构成威胁,它们会根据规定采取偏离常态的行动,以访问电脑上或数据中心任何地方的敏感数据。CSP将自动监测到这些行动,并自动拦截攻击行为。只有被许可的软件程序可以在系统中运行,而且这些程序只能执行被许可的行为操作、访问被许可的资源等等。
针对性攻击防护技术获得尖端技术团队和全球智能网络的支持
除了这些创新技术,Symantec (赛门铁克) 的安全解决方案由Symantec 全球智能网络k (GIN) 及一支由世界各地550多名研究人员组成的专业队伍提供积极支持。Symantec的GIN平台昼夜不停的收集来自Symantec (赛门铁克)数以百万计用户和传感器的匿名遥测。Symantec (赛门铁克)运用此超过2.5万亿行安全遥测数据以自动发现新的攻击,并监控攻击者网络。此外,Symantec (赛门铁克)也运用这些数据开发可预测的主动防护技术,例如Symantec (赛门铁克)的 Insight信誉技术,供应网关、端点和数据中心产品。
Wednesday, December 18, 2013
Symantec offering enables datacenters to adopt SSDs while leveraging existing storage investments
Storage Foundation customers may realize 400 percent performance gains over traditional SANs
KUALA LUMPUR, Malaysia – 18 December 2013 – Symantec (NASDAQ: SYMC) announced a new version of its Storage Foundation software, enabling data centres to leverage Solid State Drives (SSDs) in ways that could allow customers to access mission critical data and applications 400 percent faster than traditional Storage Area Networks (SANs). It is also the only offering to provide these benefits regardless of which storage hardware components are in place. Customers as a result are free to choose any storage infrastructure provider, and businesses can make critical decisions faster.
The growth of mission-critical data and applications, supporting real-time decision-making, is driving SSD adoption to increase performance within the data center. Adoption, however, has lacked the central management intelligence that customers need to manage their storage efficiently and effectively. Symantec’s offering solves this problem while allowing customers to combine SSDs with existing Direct Attached Storage (DAS) and SANs without compromising availability.
New feature highlights
Storage Foundation 6.1 functionalities and benefits include:
• A vendor-agnostic intuitive caching layer, enabled by Symantec’s SmartIO technology. SmartIO detects critical application workloads and caches only the hot data on local SSDs, which could result in up to 400 percent improved performance over traditional secondary storage.
• Flexible Storage Sharing (FSS) technology enables servers to access remote data as if it were from local storage. This allows organizations to reduce storage costs by up to 80 percent using commoditized storage hardware, while helping to ensure that all data is replicated, protected, and available.
Monday, October 7, 2013
2013 Norton Report: Cost per Cybercrime Victim Up 50 Per cent
Consumers Sleeping with their Smartphones and Tablets, but Failing to Use Protection
KUALA LUMPUR, Malaysia – October 3, 2013 – Symantec (NASDAQ:SYMC) today released the global findings from the 2013 Norton Report, which shows that while the number of online adults who have experienced cybercrime has decreased (from 46 percent in 2012 to 41 percent in 2013), the average cost per victim has risen by 50 percent (from US$197 in 2012 to US$298 in 2013).
“With the borderless nature of the Internet, cybercrime threats are not confined to any specific country and Malaysia is not immune to it. Today’s cybercriminals are using more sophisticated attacks such as ransomware and spear-phising, which yield them more money per attack than ever before,” said Alex Ong, Country Director, Symantec Malaysia.
He added, “Consumers can no longer be careless in protecting their valuable information, whether it is their personal identity, credit card or financial details. With an increasing number of Malaysians connecting to the Internet using their mobile devices, they need to take proactive steps to protect their information from security risks, especially threats that come through mobile devices.”
With 49 per cent consumers globally using their personal mobile device for both work and play, this creates entirely new security risks for enterprises as cybercriminals have the potential to access even more valuable information. This year’s report further reveals that as consumers become more mobile and connected, these conveniences often come at a cost to them and their security. Despite the fact that 63 percent of those surveyed own smartphones and 30 percent own tablets, nearly one-in-two don’t take basic precautions such as using passwords, having security software or backing up files on their mobile device.
“Unfortunately while consumers are protecting their computers, there is a general lack of awareness to safeguard their smartphones and tablets. It’s as if they have alarm systems for their homes, but they’re leaving their cars unlocked with the windows wide open. This carelessness places them, and their digital identities, at risk,” said David Rajoo, Senior Technical Consultant, Symantec Malaysia.
The 2013 Norton Report also finds that many consumers are engaging in risky behavior that has them playing a game of chance with their private information, putting them at risk of becoming the next victim of online criminals. Survey results show that this isn’t entirely due to lack of awareness. In fact, one-third (34 percent) of consumers surveyed admitted that the convenience of being constantly connected outweighed any potential security risks. Even when 62 percent said that there is no such thing as “online privacy” in today’s world and 61 percent assume that “everything they put online will / can be seen by any and everyone.”
For more findings from the 2013 Norton Report, please visit go.symantec.com/norton-report-2013 . For more information on Norton mobile protection offerings, please visit http://malaysia.norton.com .
Tuesday, September 10, 2013
New Norton Products: Compatibility with New Features of Windows 8.1, Advanced Protection, Simplified Setup
KUALA LUMPUR, Malaysia – September 5, 2013 – Norton by Symantec (Nasdaq: SYMC) today announced the release of the latest versions of award-winning Norton core security products, which keep consumers safe from evolving threats in their daily online lives. The latest versions improve on the industry’s leading protection and performance, and are designed for compatibility with the new features of Windows 8.1.
According to Symantec Security Threat Report, Web attacks increased 30 percent in 2012, driven by the easy availability of malware toolkits and the high frequency of unpatched vulnerabilities on websites.
What’s New and Improved
Each of the products’ five patented layers of protection saw many improvements to security, performance and usability. The key enhancements include:
Advanced repair – Drawing on Symantec’s Global Intelligence Network, new advanced repair capabilities leverage a broader set of Internet-connected resources to repair with greater consistency.
Improved SONAR engine – This year the products have significantly improved the behavioral-based protection engine called SONAR, which operates on the premise that while the physical nature of malware changes, its behavior often does not. As a result, SONAR now allows the latest products to discover and shut down malware that attempts to disguise its bad behavior by operating inside legitimate Windows processes.
SONAR-assisted remediation and cleanup – SONAR helps with the removal and cleanup of malware attempts by saving the evidence of the attack for later use by Norton’s repair technologies. This remediation helps to ensure that all traces of a malware attack are removed and a system is returned to its original state.
Simpler setup and management – Users can quickly download and install the latest version of their product for their device type and subsequently ensure that all their devices are protected.
Faster performance – Based on recent testing, compared with last year’s releases, Norton products have improved boot time by 15 percent, install speed by 10 percent and memory usage during scan by 100MBs, resulting in the fastest and lightest performance yet. (Source: PassMark, August 2013)
Enhanced Norton Identity Safe – This product release brings a whole new look to Norton’s password management tool. It also includes improved form filling, with drag-and-drop functionality and full vault searches available directly from the toolbar to help manage passwords even more securely and conveniently.
The latest versions of Norton 360 Multi-Device[1], Norton 360, Norton Internet Security and Norton AntiVirus are now available for purchase in Malaysia through various retailers and online at http://malaysia.norton.com. The MSRP for Norton 360 Multi-Device is MYR 199.99, which provides one year of protection for up to five devices. The MSRP for Norton 360 is MYR 169.99, which provides one year of protection for up to three PCs. The MSRP for Norton Internet Security is MYR 139.99 which provides one year of protection for up to three PCs. The MSRP for Norton AntiVirus is MYR 59.99, which provides one year of protection for one PC.
Monday, August 26, 2013
Symantec Security Response: Chinese Ransomlock Malware Changes Windows Login Credentials
Although ransomware has become an international problem, we rarely see Chinese versions. Recently, Symantec Security Response noticed a new type of ransomlock malware that not only originates from China but also uses a new ransom technique to force users into paying to have their computers unlocked.
This threat is written in Easy Programming Language and is spread mostly through a popular Chinese instant messaging provider. Once a computer is compromised, the threat changes the login credentials of the current user and restarts the system using the newly created credentials. The login password is changed to “tan123456789” (this was hardcoded in the sample we acquired) but the malware author may update the threat and change the password. The account name is changed to “contact [IM ACCOUNT USER ID] if you want to know the password” (English translation)so that once the computer has restarted, and the user is unable to log in, they will see the account name/message and contact the user ID in order to get the new password.
If the victim contacts the provided user ID, who is more than likely the malware author, they will see a statement on the profile page asking for approximately 20 Chinese Yuan (US$3.25). The statement says that the login password will be sent as soon as the money is received and that if the malware author is pestered by the user they will be blocked.
Symantec detects this threat as Trojan.Ransomlock.AF. For users already infected with this threat, there are several ways to restore system access:
1. Use password “tan123456789” to log into the system and reset the password (as mentioned before, this might not always work as the password may be changed by the malware author)
2. Use another administrator account to log into the system and reset the password
3. If your current account is not a super administrator account, enter safe mode and log in as super administrator and then reset the password
4. Use Windows recovery disk to reset the password
If you’d like to receive similar updates such as this, follow us at @SymantecASEAN.
Tuesday, July 30, 2013
Symantec Report Finds Vulnerabilities Up by 16 Percent in First Half of 2013
The latest Symantec Intelligence Report found the total number of vulnerabilities in the first half of 2013 was up by 16 percent compared to the same time period in 2012. The number of zero day vulnerabilities discovered in the first half of 2013 has already reached a total of 12, compared to only 14 found for the whole of 2012.
In addition, the report also found that small and medium businesses (SMBs) continue to be a target market segment for cybercriminals. The highest ratio of phishing attacks in June 2013 was identified in emails sent to SMB organisations (1-250 employees), with 1 in 325 emails blocked as a phishing scam, compared with 1 in 293 for 2012.
Phishing attacks spoofing financial organisations, including banks, accounted for 69 percent of phishing scams in June. This includes a variety of information and personal details that can be used for identity fraud, and theft of financial details can be quickly turned into large amounts of money, rather than goods which must be laundered first and require more time to process.
For more details on the vulnerabilities, phishing attacks and latest analysis on data breaches, malware, spam and endpoint security, please refer to the June 2013 Symantec Intelligence Report.
Monday, July 22, 2013
Great Eastern Life Partners Symantec To Strengthen Information Protection
KUALA LUMPUR, Malaysia – July 22, 2013 – Great Eastern Life Assurance (Malaysia) Berhad (Great Eastern Life) is going beyond the normal scope of financial protection as they announce the partnership with Symantec Corporation to strengthen Great Eastern Life’s information protection with Symantec’s comprehensive suite of solutions, providing the key stakeholders of the organisation a peace of mind knowing that their information is protected.
With a history that spans more than 104 years, Great Eastern Life embarked on a brand repositioning last year as a Life company. This transition puts customers at large at the centre of the organisation's heart, with much emphasis on data protection. It is critical for the organisation not just to deliver financial security but also data protection to its 2.9 million policyholders and 17,000 agents across Malaysia.
“In order to effectively meet the various requirements and expectations of our stakeholders, the IT department has a responsibility to proactively review and implement technologies that strengthen our company’s information protection posture. We have strong collaboration within the organisation, in terms of people and process, to implement the necessary measures,” said Vincent Chin, Great Eastern Life’s Senior Vice President and Head, Information Technology.
(from left):
Nigel Tan, Director of Systems Engineering, Symantec Malaysia
Vincent Chin, Senior Vice President and Head, Information Technology, Great Eastern Life Assurance (Malaysia) Berhad
Alex Ong, Country Director, Symantec Malaysia
He added, “Great Eastern Life has a long standing and strong partnership with Symantec in information security, storage management and high availability. Symantec’s vision and leadership in information security and storage technologies complement Great Eastern Life’s IT objectives and business aspirations.”
Alex Ong, Symantec Malaysia’s Country Director said, “As the IT security landscape continues to evolve, companies need to be better prepared to protect their most critical business data with advanced technology. Great Eastern Life’s move to place information protection as one of their top priorities is commendable. Symantec’s long term partnership with Great Eastern Life in protecting their business’ critical information and policyholders is a demonstration of the strength of our technology and comprehensive product portfolio, trusted by one of the largest and oldest insurance company in Malaysia. We are committed to work with Great Eastern Life in continuing to provide leading solutions to ensure their IT infrastructure is resilient, flexible and well protected.”
Investing in Securing the Future
Great Eastern Life has set its sight on developing a good security culture in its business ecosystem, which includes its employees and business partners. “We conduct periodic security and compliance communication sessions to increase the awareness level on security and to empower our employees and business partners with best practices to stay safe online,” Chin said.
Such initiatives complement the information security systems and policies that the company has been implementing.
“Essentially, information security is beyond technology as it encompasses the management of people and business processes. The users in our business environment can be the strongest or the weakest link to information security, therefore developing a good security culture among users across our company is critical. This culture is in fact driven top-down in Great Eastern Life,” he explained.
In strengthening the information protection of its agency networks, Great Eastern Life has recently partnered with Symantec in offering Norton Internet Security to help its agency force enhance security on their endpoint devices. Chin pointed out that this is an important initiative as the agency network is a vital component to the company’s business ecosystem.
In addition, to ensure the best possible protection against new and evolving threats, Great Eastern Life had taken extensive initiatives on endpoint protection by standardising on Symantec Protection Suite and Symantec Mail Security to protect its desktops, laptops, and email infrastructure. Based on Great Eastern Life’s statistics, about 80 percent of their incoming email was spam, which could pose a security threat to their systems. The company has seen a notable reduction in spam since implementing Symantec Mail Security. In addition to reduce email server workload, Symantec’s security solutions also provide an overview of the state of security across the organisation.
As safeguarding customer data and ensuring data integrity are Great Eastern Life’s top priority, the company has selected Symantec Endpoint Protection (SEP) and has implemented whole disk encryption for its PCs and Notebooks. According to Chin, “SEP has enabled us to enforce policy on USB usage besides disk encryption, protection against malware and network threats. With the SEP central console, we have visibility of the information security posture and status of protection for our PCs and servers. Symantec solutions combined with other security controls provide us with more comprehensive measures in information protection.
In terms of compliance, Great Eastern Life implemented Symantec Control Compliance Suite (CCS) to automate compliance checks for servers and databases. “Without the CCS tool, it is very laborious for us to perform “eye-ball” checks against hardening standards and known vulnerabilities. The introduction of CCS gives us better control of policies implementation. In addition, the centralised management console features provides a bird’s eye view of our IT compliance posture and enables our system engineers to respond quickly in identifying gaps,” Chin said.
Managing Information Growth Through Storage Management
With the rapid growth of information in businesses of all sizes, the cost of managing the information is also escalating. According to Symantec’s 2012 State of Information Survey, the total size of information stored globally by all businesses has reached 2.2 zettabytes.
Building on the company’s strong fundamental of IT infrastructure, Great Eastern Life is strengthening its storage management, consolidation and optimisation initiatives in addressing the rapid increase of information as a result of the expansion of the company’s customer base and agency network.
According to Chin, “Great Eastern Life has made significant investments over the last few years to achieve economies of scale and uplift its overall capabilities. The company has embraced new technologies and initiated strategic programs, which include being a part of its regional data centre consolidation, server consolidation, virtualisation, storage and backup consolidation.”
Great Eastern Life’s IT team today manages a total storage capacity of more than 200 terabytes residing on enterprise storage supporting well over 100 business applications. This has grown exponentially from 60 terabytes in a span of three years due to business growth and new business capabilities that leveraged on IT to provide the competitive edge.
Along with this exponential growth in storage came a new challenge to ensure backups can be completed within the allocated time and prevent using business hours for backup requirements. With Symantec NetBackup and Veritas Storage Foundation already in place at Great Eastern Life, this provides a resilient foundation for the company’s IT infrastructure to handle the growth and this was further enhanced with Symantec NetBackup Data Protection Optimization as the natural choice for data deduplication technology.
A proven solution with real-world deduplication ratios as high as 15:1, Symantec NetBackup Data Protection Optimization enabled Great Eastern Life to maintain the five hours backup window. Additionally, Symantec NetBackup Data Protection Optimization offers features to optimise resource utilisation by reducing energy consumption, data centre footprint and overall storage costs.
The adoption of Symantec NetBackup suite of data protection solutions enables the IT team at Great Eastern Life to perform effective daily operations as Symantec NetBackup provides a unified policy management that allows end-to-end management of the entire data lifecycle, with backup and recovery options to meet different business needs.
Moving Forward
Looking ahead, Great Eastern Life is now working on the next wave of IT initiatives. This includes the possible adoption of private cloud solutions and software as a service (SaaS) to cater to its escalating IT resource requirements as a result of increasing business demands for IT services and its burgeoning pool of field agents which now totals more than 17,000. “We are monitoring these trends and technologies closely on how they can benefit our business. As a financial institution, we will apply stringent reviews on the security aspect of cloud solutions prior to any adoption,” said Chin.
For Great Eastern Life, having solutions that can provide comprehensive protection and strong vendor support are critical to ensure IT security, data privacy and scalability in storage management are effective, as the company continues to grow and stay at the forefront of the insurance industry.
Symantec products implemented at Great Eastern Life:
Symantec Control Compliance Suite
Symantec Protection Suite
Symantec Messaging Gateway
Veritas CommandCentral Storage
Veritas Storage Foundation
Symantec NetBackup
Symantec NetBackup Data Protection Optimization
Symantec Ops Center Analytics
Symantec Endpoint Encryption Removable Storage
Symantec Encryption Management Server/PGP Universal Server
Symantec Drive Encryption/Whole Disk Encryption
大东方人寿与赛门铁克成为合作伙伴,强化公司资讯安全保护方案
吉隆坡,马来西亚 – 2013年7月 22日 – 大东方人寿保险(马来西亚)有限公司(简称大东方人寿)超越一般财务保障范畴,宣布与赛门铁克展开合作关系,采用赛门铁克全面完整的解决方案,进一步强化大东方人寿的资讯安全保护,确保公司重要利益关系客户资讯得到完善保护,让他们更加安心及高枕无忧。
去年,创建至今超过104年的大东方人寿重新设定公司品牌定位,转型为一家与客户共同为人生喝彩的良伴 (LIFE Company)。这项转型计划将客户视为企业的核心力量,资讯保护就是极为重要的关键。公司不仅仅必须为全马各地超过290万个保单客户和 17, 000 名代理员提供财务保障,更必须兼顾资料安全管理。
日新月异的网络威胁现象、不断变化的法规,以及每日迅速增加的资讯量等因素,导致资讯保护成为每家企业的重要部分。另外,马来西亚最新通过的2010年个人资料保护法令制定了许多法规需求(例如:保护个人资料的重要性),这也促使大东方人寿更加关注资料保护这个部分。
“为了满足客户的不同需求和期待,资讯科技部门有责任积极审视及实施能够强化公司资料保护方面的科技。无论是人才、程序或执行必要措施,公司内部都拥有稳健的整合方案。”大东方人寿资讯资深副总裁兼资讯科技部门主管陈国麟先生表示。
他补充说明:“大东方人寿在资讯安全管理、储存管理方案及高应用性解决方案方面与赛门铁克建立悠久稳健的合作关系。赛门铁克在资讯安全管理和储存科技方面的理念和领导能力,能够与大东方人寿的目标与商业愿景达到相辅相成的作用。”
马来西亚赛门铁克区域总监王和伟表示:“随着资讯科技网络安全不断演进,企业必须做好充分准备,采用先进科技来保护重要商业数据。大东方人寿将资讯保护列为企业优先考量之一的做法非常值得赞扬。赛门铁克与大东方人寿建立长期合作关系,保护公司商业重要资讯和保单客户资料,这充分验证了我们在科技方面的卓越优势及拥有完整产品解决方案,因此获得马来西亚最历史悠久及最大保险公司之一的信赖。我们会竭尽全力与大东方人寿紧密合作,持续提供领先市场的解决方案,确保他们的资讯科技设备可适应变化、弹性灵活及提供完善保护。”
投资现在,保障未来
大东方人寿设定目标为其公司商业生态系统推行完善的资讯安全保护文化,其中也包含员工和商业伙伴:“我们定期举办安全性及遵循性相关会议活动,提高员工及商业伙伴在这方面的警觉程度,让他们在使用网络时可采取最安全的措施。”陈先生表示。
这些措施有助于强化公司目前采用的资讯安全系统和政策。
“原则上,资讯安全管理不仅仅取决科技,更包括人力管理和商业程序。我们的商业环境用户与资讯安全管理的连接可能是最强或最差的,因此在用户群中创造出完善良好的安全管理文化非常重要。事实上,大东方人寿公司从上到下都遵循这个文化。”他进一步解释。
为了加强代理员网络的资讯保护管理,大东方人寿最近与赛门铁克合作提供诺顿网络安全管理(Norton Internet Security),帮助代理员加强他们端点设备的安全管理。陈国麟指出,这是一项非常重要的决策,因为代理员网络就是公司商业生态系统的重要部分。
除此之外, 为了确保在面对不断更新及演变的网络威胁时提供最好的安全保护,大东方人寿在端点防护方面投入大量资源,统一采用赛门铁克安全防护配套(Symantec Protection Suite)和赛门铁克电子邮件安全解决方案(Symantec Mail Security)以保护公司的桌上型电脑、手提电脑和电邮装置。大东方人寿统计数据显示,大约80%的接收邮件都是垃圾邮件,这可能对公司系统造成安全威胁。装置赛门铁克电子邮件安全解决方案后,大东方人寿公司发现垃圾邮件明显减少。除了减少电邮伺服器的工作量,赛门铁克的安全解决方案也提供企业整体安全状况管理。
由于保护客户资料和确保数据完整性是大东方人寿的优先事项,该公司选择了赛门铁克端点防护安全解决方案(Symantec Endpoint Protection,简称SEP),同时为所有桌上型电脑和手提电脑装置全磁碟加密软件。陈国麟表示:“除了磁碟加密、阻截恶意软件和网络安全威胁,SEP解决方案也能让我们制定USB使用政策。SEP中央控制台让我们可以掌控桌上型电脑和伺服器的资讯安全管理和防护进度。赛门铁克解决方案与其它安全控制措施结合,为我们提供更完整全面的资讯安全保护。”
在使用遵循性方面,大东方人寿装置了赛门铁克整体控制解决方案配套(Control Compliance Suite,简称CCS),自动化检查伺服器和数据库的整体安全和遵循状态:“缺少CCS解决方案的情况下,我们必须以人工方式检查系统安全强化指南及安全漏洞。CCS解决方案的推出让我们在掌控政策实施方面更趋完善。另外,中央控制台也具备评估资讯科技遵循性状况的鸟瞰图功能,让我们的系统工程师可在发现应用缺口时迅速处理。”陈国麟说。
采用储存管理方案,管理信息增加现况
随着不同类型企业的资讯信息迅速增加,管理信息的成本也逐渐提升。赛门铁克2012年资讯现况调查报告显示,所有企业的信息存储总量已高达2.2 zettabytes。
奠定稳健资讯科技设备基础的同时,大东方人寿也强化其储存管理、整合巩固及优化措施,管理因客户群和代理员网络日益扩展而迅速增加的信息。
陈国麟表示:“过去几年,大东方人寿投入大量资金以符合规模经济现况及提升公司整体能力。公司采用了崭新科技及推动策略性计划,其中包括整合区域数据中心、伺服器整合、虚拟化、储存和备份集中管理。”
目前,大东方人手资讯科技部门团队管理超过200TB的企业总储存量,支援超过100个商业应用程序。由于业务成长和利用资讯科技新功能以提高企业竞争优势等因素,导致这些储存量在短短3年内翻倍增加。
储存量的翻倍增加也带来了新挑战,企业必须确保在既定时间内完成备份,同时避免在工作时间进行备份要求。大东方人寿已经装置了赛门铁克NetBackup资料备份解决方案和Veritas储存管理方案,为公司科技资讯设备提供弹性处理基础以应付信息增加现象,重复数据删除科技的产品选件 – 赛门铁克NetBackup资料保护优化解决方案则进一步强化系统表现。
赛门铁克NetBackup资料保护优化解决方案是一款实际重复数据删除比例高达15:1的可靠产品,这让大东方人寿可以维持长达5小时的备份时段。另外,它也具备减少电量消耗、数据中心占用空间和整体储存成本等特点,可最大程度优化资源利用率。
装置赛门铁克NetBackup资料保护解决方案让大东方人寿的科技资讯团队可以更有效率
地执行日常营运,因为此解决方案提供通用政策管理系统,让用户可以对整个数据生命周期进行端点至端点管理,同时提供备份和复原选项以满足不同商业模式的需求。
展望未来
展望未来,大东方人寿已开始朝着下一波资讯科技发展浪潮做出努力。为了应付业务增
长而提升的资讯科技服务需求,以及满足迅速成长代理员人数(目前代理员总数已超过17,000名)的资源需求,大东方人寿采取的措施包括了考量装置私有云解决方案
(Private Cloud Solutions)和“软件即服务”产品(简称SaaS)。
“我们一直密切关注这些趋势和科技为我们带来的商业效益。作为一家财务机构,在装置任何云端解决方案之前,我们将会严禁审核相关的安全考量事项。”陈国麟表示。
对于大东方人寿而言,拥有能够提供完整保护解决方案和稳健供应商支援非常重要,这样才能确保资讯科技安全管理、数据隐私管理和储存管理扩充性的有效运作,这是因为
公司一直不断成长并站在引领保险业界的前沿地位。
大东方人寿装置的赛门铁克解决方案产品:
Symantec Control Compliance Suite
Symantec Protection Suite
Symantec Messaging Gateway
Veritas CommandCentral Storage
Veritas Storage Foundation
Symantec NetBackup
Symantec NetBackup Data Protection Optimization
Symantec Ops Center Analytics
Symantec Endpoint Encryption Removable Storage
Symantec Encryption Management Server/PGP Universal Server
Symantec Drive Encryption/Whole Disk Encryption
Wednesday, July 17, 2013
Norton Mobile Security Delivers App Privacy Protection
New Norton™ Mobile Insight intelligence technology performs dynamic mobile app analysis, reveals which leak personal information
KUALA LUMPUR, Malaysia – July 17, 2013 – Symantec (Nasdaq: SYMC) recently released the latest version of Norton Mobile Security, which delivers powerful, effective protection for Android smartphones and tablets, iPhones and iPads . The latest updates to Norton Mobile Security for Android address privacy, a growing area of consumer concern, with new intelligence technology called Norton Mobile Insight. Privacy risk scans powered by Norton Mobile Insight will reveal which mobile applications may put the user’s personal information at risk. The latest updates to Norton Mobile Security also extend enhanced anti-theft capabilities to iPhone and iPad with a “scream” alarm to help users quickly find their missing mobile device.
For mobile device users, maintaining control of their personal information is a major concern. In fact, 57 percent of app users have uninstalled or declined to install an app to protect their personal information . To address this issue, in addition to scanning for security risks, Norton Mobile Security now scans apps for privacy risk-related attributes. For example, Norton Mobile Security will now flag an application and notify a user if a mobile app is found to export information such as a user’s contacts, photos or call logs. Because consumers don’t have knowledge of how their data may be used, collected or shared, they are not able to maintain control of their personal information. Norton Mobile Security empowers consumers to protect their personal information and make informed decisions about which apps to keep or remove.
Norton Mobile Insight
Users of Norton Mobile Security benefit from Norton Mobile Insight, a proprietary intelligence tool that provides dynamic analysis for every app in more than 200 app stores to determine potential security risks, privacy risks and potentially intrusive behavior. Norton Mobile Insight has analyzed more than four million apps to date and determined that more than 30 percent of them leak data such as personal contacts or call logs. Currently, Norton Mobile Insight processes 10,000 new apps every 24 hours and to date has identified 300,000 apps as malicious and 1.5 million apps as being associated with greyware — such as aggressive ad networks — or potential privacy risks.
Pricing and Availability
Norton Mobile Security has an MSRP of RM49.99 and is available for purchase via various retailers, the Norton online store or Google Play. In addition, Norton 360 Multi-Device will be updated with the features in the latest release of Norton Mobile Security. Norton customers with a valid product subscription are eligible to receive the latest product updates via the subscription service model. For more information, visit the Norton Update center at http://updatecenter.norton.com. Consumers can visit norton.com/nmsprivacy to learn more about Norton Mobile Security.
Thursday, July 4, 2013
MAXIS OFFERS ANDROID CUSTOMERS A SECURE INTERNET EXPERIENCE WITH NORTON MOBILE SECURITY
• Offers Norton Mobile Security, in partnership with Symantec to protect Android devices from digital threats and remotely locate, lock and wipe data from lost or stolen devices
• New service is part of the Maxis Secure portfolio, that enables customers to enjoy a safer mobile experience
Kuala Lumpur, 4 July 2013. Malaysia’s only integrated communications service provider, Maxis Berhad (Maxis), is the first telecommunications company in the country to partner with global security software leader, Symantec (NASDAQ: SYMC), to offer Norton Mobile Security. The partnership will empower Maxis subscribers to protect their Android devices from digital threats and enable them to remotely locate, lock and even wipe data from a lost or stolen device.
Mobile phones are an integral part of consumers’ lives, with two-thirds of adults worldwide reporting they use a mobile device to access the Internet. However, one in three mobile device users have had a device lost or stolen, putting their sensitive information at risk . With Norton Mobile Security, Maxis Android customers will be able to protect their smartphone and tablet with one convenient solution.
“It’s no secret that people are using mobile devices more than ever in their daily lives, for everything from connecting with friends to paying for a cup of coffee,” said Eric Hoh, vice president, Asia South Region, Symantec. “As we use our mobile phones in new and innovative ways, we’re also putting sensitive information at risk, if the device gets lost or stolen. With Norton Mobile Security, we are making it simple for people to protect their Android smartphones and safeguard their data.”
Norton Mobile Security offers protection for Android devices and data for only RM1 a week or RM3 a month through features such as:
• Anti-Phishing Web Protection – Protects and reports malicious sites that may contain malware. Through this feature, users are protected from malicious websites that could try to steal your personal information.
• Call & Text Blocker – Allows users to block specific people or phone numbers so that users are not disturbed by unwanted calls and SMS.
• Lost Notice – In the event of a lost phone, allows users to send customised message to the person who located the device to have it returned.
• Remote Lock – Users are able to lock the device remotely via the web or SMS to prevent others from accessing the data and information on the device.
• Remote Locate – Pinpoints lost or stolen phones or tablets on a map to help users find their devices fast.
• Remote Wipe – Allows users to wipe data and information in the device, both of which are stored in the internal memory or external memory, via SMS or the web.
Maxis Secure suite of security services provides customers greater security through secure networks with 3G and 4G speeds coupled with affordable data plans for an optimal and safer internet experience. Maxis also provides additional services to secure customers’ devices such as Locker, a free personal cloud service to back up and retrieve lost data and device protection, which ensures stolen or damaged devices are replaced.
Pricing and availability
Maxis Android subscribers can easily enjoy the full benefits of Norton Mobile Security by subscribing to either weekly or monthly package. As an added benefit, customers who subscribe to Norton Mobile Security will enjoy a 1-month free trial from the time of subscription. To subscribe to Norton Mobile Security via Maxis UMB, dial *200# from their mobile phones and choose Maxis Secure. Alternatively, customers can subscribe via SMS. For 1-week protection, send ON NMS7 to 20088 via SMS. For 1-month protection, send ON NMS30 to 20088.
For further information on Norton Mobile Security, please visit http://malaysia.norton.com/norton-mobile-security/. Customers may also find more details on Maxis Secure at http://www.maxis.com.my/personal/secure/.
Sunday, June 23, 2013
Symantec Issues Global SMB IT Confidence Index
Study Shows Higher IT Confidence Linked to Greater Business Outcomes Globally and in Malaysia
KUALA LUMPUR, Malaysia – June 19, 2013 – Symantec Corp. (Nasdaq: SYMC) today released its 2013 Global SMB IT Confidence Index, which found that SMBs with higher IT Confidence scores are more successful in leveraging IT to drive their business, and ultimately experience stronger, better business outcomes.
“In Malaysia, the survey shows how the attitudes about IT of SMB founders have a positive correlation between protecting their information assets and achieving their business goals,” said Alex Ong, country director of Symantec Malaysia. “If small businesses want to maximise their success, they need to embrace IT as a strategic tool with the potential to deliver a competitive advantage and really drive their business.”
Koh Ee Laine, senior technical consultant of Symantec Malaysia, added, “It is also interesting to note from the survey that the typical top-tier SMB spends seven percent less on computing than bottom-tier organisations, which may be due to their commitment to invest in the right technology from the beginning and having the future growth of the company in mind. There are significant advantages in a forward thinking attitude towards computing when it is embraced for strategic purposes rather than being treated as simply a necessary evil.”
Symantec surveyed nearly 2,500 SMBs across the globe to determine their attitude toward IT, including 101 organisations in Malaysia. Their responses were utilised to develop an “SMB IT Confidence Index,” a measure of how confident they are in using IT to address strategic business goals. Three tiers of companies emerged, with the contrast between the top tier and bottom tier forming the basis of the survey’s key takeaways.
IT Confidence Starts at the Top
One of the biggest drivers of high IT Confidence scores was the founder’s perspective and how that impacts IT. Seventy-four percent of top tiers said their founder’s previous business experience has a somewhat to extreme influence on their IT philosophies, compared to 61 percent of companies with low-ranking index scores, and 75 percent in Malaysia. In addition, 83 percent of top-tier SMBs use IT as a strategic business enabler, compared to just 44 percent of bottom-tier SMBs, and 73 percent in Malaysia. Top tiers are also more likely to invest in a high quality IT infrastructure and deploy advanced computing platforms, such as cloud and mobility, seeing innovative technologies as being worth the potential risk.
In Malaysia, competition and the complexity of the business in general were tied as the top business challenges, followed by the increased pace of the business. In addition, data protection, followed by security and disaster preparedness have been listed as the most significant IT issues in the country.
Higher IT Confidence Tied to Better Business Outcomes
SMBs with the highest IT Confidence Indices are doing better than their bottom-tier counterparts in a variety of ways. Eighty-one percent of top-tier SMBs said “using computing strategically to drive our business forward” was a somewhat to extremely effective way to increase market share, compared to just 35 percent of the bottom-tier SMBs, and 68 percent in Malaysia.
Additionally, these SMBs have made information security a business priority, with 78 percent stating they are somewhat/extremely secure versus 39 percent for the bottom tier, and 79 percent in Malaysia. Top-tier SMBs also see fewer cyberattacks and lower monetary losses (51 percent lower annual loss from cyberattacks), and in areas such as storage management, backup windows and disaster preparedness, the top tiers report much smaller impacts from IT complexity.
To Duplicate the Success of Highly Ranked SMBs, Think Like a Founder:
Invest for value, not cost. When evaluating IT solutions for business, SMBs should consider long-term cost and value, and determine what technologies will help differentiate them from the competition while supporting future growth.
Use IT strategically to address core business objectives. Top-ranking SMBs match the right IT initiative to their business goal. They are more aggressive at deploying advanced technologies such as mobile and cloud, and they focus on efficiency. For example, top-tier SMBs would consider using online collaboration tools and video conferencing to reduce landline and travel costs.
Keep your IT house in order. Especially when it comes to protecting data – data loss can be a death sentence for an SMB. In terms of security, SMBs are now being specifically targeted by cybercriminals. Top-tier SMBs understand the importance of keeping security up-to-date, and 81 percent aggressively employ security measures. The same pattern holds true for backup and disaster preparedness.
Symantec’s 2013 Global SMB IT Confidence Index
Symantec’s 2013 Global SMB IT Confidence Index is a result of research conducted by ReRez in February-March 2013. The full study represents 2,452 organisations from 20 countries, including 101 organisations from Malaysia Responses came from companies with a range of 10 to 250 employees.
Friday, June 7, 2013
Global Banking Trojan Citadel Taken Down!
Citadel, a banking Trojan which has been in existence since 2011, has been recently taken down by Microsoft and members of the financial services industry and the FBI. The takedown operation resulted in over 1,000 Citadel botnets being taken offline.
As with most banking Trojans, Citadel is a full crimeware kit, providing the attackers with payload builders, a command and control (C&C) server infrastructure, and configuration scripts to target various banks. Citadel is a descendant of that other behemoth of the financial Trojan world, Trojan.Zbot (Zeus). It came into existence after the Zeus source code was leaked in 2011, with criminal groups taking that code and enhancing it.
Citadel infections have spread around the globe so Symantec welcomes news of the takedown of these Citadel botnets. While these takedowns may not eliminate the threat of Citadel completely, it certainly disrupts current campaigns and sends out a clear message to attackers that their actions are being monitored. Symantec also welcomes the cooperation between the public and private sector in taking action against this threat.
For more information about the world of financial Trojans, read our whitepaper. Symantec's current antivirus and intrusion prevention signatures provide protection against Citadel infections.
Thursday, March 21, 2013
Symantec Security Response | Spammers Getting Cheeky with "X-Ray vision" Apps to Lure Victims
Ever heard of an app that allows X-Ray vision through clothes?
The Symantec Response Team recently monitored a malicious app known as Android.Uracto that sends spam messages by SMS to phone numbers stored in the device’s Contacts. Recipients are easily tricked because the invitation to download the app is coming from someone they know rather than from an unknown sender.
The site (shown in the figure below) where the link takes the user to introduces an app called “Infrared X-Ray” that supposedly allows the user to see through clothes when viewed through the device’s camera and of course also allows pictures to be taken. Not surprisingly, the app does not work. However, once executed, details stored in the device’s Contacts are uploaded to a predetermined server.
Further investigations conducted by Symantec has led to the discovery of ten similar apps developed by the same group of spammers. The servers hosting the domains appear to be located in Singapore and in Georgia in the United States.
1. Steals data stored in the device’s Contacts.
2. Steals contact details but also sends SMS messages, containing a link to download the malicious app, to all the contacts.
3. Steals contact details and attempts to scam the victim into paying for fake services.
For more information, please proceed to the following Symantec Security Response blog posts:
· Android Malware Spams Victim’s Contacts
· Android.Uracto Used to Trick Mothers, Anime Fans, Gamers, and More
To stay updated on cyber security threats such as the above, follow us at @SymantecASEAN.
Symantec advises users to refrain from clicking links found in messages such as emails and SMS messages from unknown senders as well as suspicious messages from known senders. Furthermore, only download apps from trustworthy vendors. Users who have installed one of Symantec’s security apps, Norton Mobile Security or Symantec Mobile Security, are protected from this threat, which is detected as Android.Uracto. For more general safety tips for smartphones and tablets, please visit our Mobile Security website.
Tuesday, March 5, 2013
Symantec Survey in Malaysia Reveals Upsurge in Rogue Clouds and Other Hidden Costs
KUALA LUMPUR, Malaysia – March 5, 2013 – Organisations in Malaysia are widely migrating to the cloud to gain competitive advantages around speed, agility and flexibility according to the Malaysia findings of Symantec Corp’s. (Nasdaq: SYMC) recent Avoiding the Hidden Costs of Cloud 2013 Survey. In fact, 99 percent of organisations in Malaysia are at least discussing cloud, up from 70 percent about a year ago. Other key survey findings showed enterprises and SMBs are experiencing escalating costs tied to rogue cloud use, complex backup and recovery, and inefficient cloud storage. Rogue clouds are defined as business groups implementing public cloud applications that are not managed by or integrated into the company’s IT infrastructure.
Industry experts predict several key issues will arise in 2013 focused on the financial pressures and security challenges of cloud computing. Business continuity is seen as an important issue with the increase in cloud outages posing greater risks than security breaches. An outage may impact businesses and pose important concerns around data loss prevention, backup, time spent on data recovery and the associated costs. However, with advance preparation, organisations can build safe, agile and efficient clouds that will enable them to meet their business goals.
(from left):Dave Elliot, Senior Product Marketing Manager, Global Cloud Marketing, Symantec. Nigel Tan, Director of Systems Engineering, Symantec Malaysia.
“A majority of businesses in Malaysia are at least discussing cloud as the benefits in improving agility and reducing costs are clear. However, in a rush to implement cloud, there are a host of hidden costs unwary organisations may face. The hidden costs of cloud implementation can negate the benefits if not properly contained,” said Nigel Tan, director of Systems Engineering at Symantec Malaysia.
“By taking control of cloud deployments through foresight and planning, companies in Malaysia can seize advantage of the flexibility and cost savings associated with the cloud, while minimising the data control and security risks linked with rogue cloud use,” Tan added.
“Wherever companies go with clouds, we will provide the protection and control they need across public and private cloud environments. Symantec’s vision is for safe, agile and efficient clouds. In five years, companies will operate in a converged IT world of cloud, virtualisation and mobile computing where clouds are safe. IT organizations will have better visibility, control and compliance across their private and public clouds,” said Dave Elliott, Symantec’s senior product marketing manager for Global Cloud.
“To achieve this safe clouds environment, the IT industry needs to enforce rigorous cloud strategies around the protection of policy, information, people and infrastructures. Symantec’s comprehensive portfolio provides companies of all sizes a variety of cloud solutions to address their specific needs and current IT environments.”
Rogue Cloud Implementations
According to the Malaysia findings of the survey, rogue cloud deployments are one of the cost pitfalls. It is a surprisingly common problem, found in 95 percent of businesses in Malaysia within the last year. It also seems to be an issue experienced more by enterprises, due to their larger company size, than SMBs.
Among organisations who reported rogue cloud issues, 47 percent experienced the exposure of confidential information, and 40 percent or more faced defacement of Web properties, stolen goods or services, and account takeover issues. The most commonly cited reasons for undertaking rogue cloud projects were to save time and money.
Cloud Backup and Recovery Issues
Cloud is complicating backup and recovery. First, 59 percent of organisations in Malaysia use three or more solutions to backup their physical, virtual and cloud data—leading to increased IT inefficiencies, risk and training costs. Furthermore, almost half (47 percent) percent of organisations in Malaysia have lost cloud data, and most (83 percent) have experienced recovery failures.
Finally, most see cloud recovery as a slow, tedious process. Only about one fourth (27 percent) of organisations in Malaysia rate this as fast and 22 percent estimate it would take three or more days to recover from a catastrophic loss of data in the cloud.
Inefficient Cloud Storage
One of the key advantages to cloud storage is how simple it is to provision. Sometimes this simplicity leads to inefficient cloud storage. Generally, organisations strive to maintain a storage utilisation rate above 50 percent. According to the survey, cloud storage utilisation globally is surprisingly low at 17 percent. There is a tremendous difference in this area between enterprises globally (which are utilising 26 percent of their storage) and SMBs (which is a shockingly low seven percent). Furthermore, within Malaysia, just over half admit very little, if any, of their cloud data is deduplicated, further compounding the problem.
Compliance and eDiscovery Concerns
According to the survey, 64 percent of organisations in Malaysia are concerned about meeting compliance requirements in the cloud, and a slightly larger number (71 percent) are concerned about being able to prove they have met cloud compliance requirements. This concern about information in the cloud is well founded, as 39 percent of organisations have been fined for cloud privacy violations.
eDiscovery is creating additional pressure on businesses to quickly find the right information. About half (51 percent) of businesses in Malaysia reported receiving eDiscovery requests for cloud data. Of those, almost two-thirds (61 percent) have missed their cloud discovery deadlines, leading to fines and legal risks.
Data in Transit Issues
Organisations have all sorts of assets in the cloud – such as web properties, online businesses or web applications – that require SSL (Secure Sockets Layer) certificates to protect the data in transit whether it is personal or financial information, business transactions and other online interactions. The Malaysia findings of the survey showed companies found managing many SSL certificates to be highly complex: Just 33 percent rate cloud SSL certificate management as easy and only 48 percent are certain their cloud-partner’s certificates are in compliance with corporate standards.
Hidden Costs Are Easily Avoided
The survey shows ignoring these hidden costs will have a serious impact on business. However, these issues are easily mitigated with careful planning, implementation and management:
• Focus policies on information and people, not technologies or platforms
• Educate, monitor and enforce policies
• Embrace tools that are platform agnostic
• Deduplicate data in the cloud
Symantec’s Avoiding the Hidden Costs of Cloud 2013 Survey
Symantec’s 2013 Cloud Survey is a result of research conducted by ReRez in September-October 2012. The full study represents 3,236 organisations from 29 countries, including 150 organisations in Malaysia. Responses came from companies with a range of five to more than 5,000 employees. Of those responses, 1,358 came from SMBs and 1,878 came from enterprises.
赛门铁克马来西亚调查显示不合格云端服务(Rogue Clouds)及隐形成本暴增
马来西亚吉隆坡 – 2013年3月5日 – 赛门铁克公司(Nasdaq: SYMC) 近日发布的《2013年云端隐形成本调查》(Avoiding the Hidden Costs of Cloud 2013 Survey)马来西亚数据显示,马来西亚企业广泛迁移至云端以获取速度、敏捷度和灵活性方面的竞争优势。事实上,99%的马来西亚企业已开始讨论云端技术,比率超越了一年前的70%。此调查的另一项重要发现显示,大企业和中小型企业都面对着不合格云端服务(rogue cloud)、复杂的备份和复原、以及云端存储效率欠佳等问题,因而造成成本增加。不合格云端服务定义为企业采用并非由公司资讯科技部门管理,也没有与资讯科技基础建设整合的公共云端应用。
业界专家预测,2013年即将崛起的几项重要问题主要围绕在云端计算的财务压力和保安挑战等范畴。随着日趋频繁的云端服务中断事故会引发比安全漏洞更大的风险,维持业务持续性被视为重大议题。云端服务中断将对业务造成影响并引发各项重大关注,其中包括:预防数据遗失、备份、数据复原及相关成本等等。然而,在事前作好准备的情况下,企业则可以建立安全、灵活、高效,同时又能满足其商业目标需求的云端服务。
“由于云端服务在提高灵活运用和降低成本方面的效果显著,因此大部分马来西亚企业都在讨论云端服务。但是,未经谨慎考量而太过仓促实施云端服务的企业可能会面对大量的隐形成本问题。如果没有妥善处理,这些隐形成本会导致云端服务的好处被否定。”马来西亚赛门铁克系统工程总监陈善龙表示。
“通过谨慎考量和完善规划来掌控云端服务部署,企业可以充分利用云端服务灵活性和节约成本,同时最大限度减少不合格云端服务带来的数据控制和安全风险。”陈先生补充说明。
“当企业决定采用云端服务,我们将为它们提供公共云端和私人云端环境所需要的保护和监控。赛门铁克的愿景是提供安全、灵活及高效率的云端服务。未来5年,企业将进入汇合云端、虚拟化和行动运算的资讯科技运作环境,资讯科技部门对于公共云端和私人云端将拥有更好的能见度、管理和法规遵循能力。”赛门铁克全球云端资深产品市场经理Dave Elliot表示。
“为了实现安全云端环境的愿境,资讯科技领域必须进一步强化政策保护、资讯、人力和基础设施方面的严格云端策略。赛门铁克拥有完善全面的解决方案,可以为各类型企业提供多元化云端服务方案,以满足企业的特别需求和现有资讯科技环境。”
不合格云端服务部署
这项调查的马来西亚数据显示,不合格云端服务是最大的隐形成本之一。令人惊讶的是这居然极其普遍,多达95%的马来西亚企业在去年曾遇到这个问题。由于公司规模比较庞大,这个问题对大型企业的影响超过了中小型企业。
在呈报遭遇不合格云端服务问题的企业中,47%表示发生机密信息泄露的情况,40%或以上的企业经历网站内容被窜改、货品或服务被盗窃,以及帐户盗用等问题。企业采用不合格云端服务最常见的原因则是节省时间和金钱。
云端备份和复原问题
云端计算将备份和复原变得更为复杂。首先,59%的马来西亚企业采用三个或更多的解决方案来备份其实体、虚拟和云端数据,这种情况导致资讯科技效率降低、增加风险和培训成本。此外,大约半数 (47%) 马来西亚企业曾面临过数据丢失的事件,而大部分企业 (83%)经历过数据复原失败的情况。
最后,大部分企业都认为云端数据复原是一个缓慢、冗长的过程,只有四分之一(27%)的马来西亚企业评定此过程迅速,而22%则预计必须耗费三天或更长时间才能将遭受灾难性损失的云端数据复原。
云端存储效率欠佳
云端存储的关键优势之一在于其部署过程简单,但这个优势有时却会导致云端存储效率欠佳。一般情况下,企业会设法把存储利用率维持在50%以上。根据这项调查显示,全球云端存储的利用率却出乎意料低至17%。在这方面,全球大企业(存储利用率达至26%)和中小型企业(低至让人惊讶的7%利用率)存在巨大差距。另外,超过半数的马来西亚企业承认,它们很少进行云端数据的重复删除技术操作,让有关问题变得更为复杂。
法规遵循与电子搜证(eDiscovery)考量
调查显示,64%的马来西亚企业担心能否符合云端服务的法规要求,更多企业(71%)担忧无法证明已经符合云端法规遵循的要求。事实上,39%企业曾因违反云端私隐权规定而被罚款,因此企业确实有必要关注法规遵循问题。
电子搜证(eDiscovery) 可以快速地找到正确的资讯,但也为企业带来额外压力。超过半数(51%) 的马来西亚企业呈报曾被要求进行云端搜证以提供云端资料,其中有三分之二 (61%) 错过了云端搜证的期限,因而面临罚款和法律风险。
数据传输问题
企业在云端存储各种企业资产(例如:web属性、在线业务或web应用),无论是个人信息、财务资料、商业交易或其他在线业务,这些都需要安全套接层(Secure Sockets Layer,简称SSL)证书来保证数据传输的安全。
这项调查的马来西亚数据显示,企业认为管理大量SSL证书相当复杂,仅有33%评定云端服务SSL证书管理相对简单。另外,确定其云端服务合作伙伴证书符合企业标准的也仅占48%.
轻松避免隐形成本
调查显示,忽略这些隐形成本将对业务产生严重的影响。但是,谨慎周密的规划、实施和管理能够轻松减少这些问题:
• 将策略重点放在信息和人,而不是技术或平台。
• 教育、管理并监督策略实施 。
• 采用不受平台限制的工具。
• 对云端数据进行重复数据删除。
关于赛门铁克2013年云端隐形成本调查
赛门铁克2013年云端隐形成本调查是由ReRez於2012年9月至10月期间进行的研究。整个调查涵盖了来自29个国家的3,236家企业,其中包括了150间马来西亚企业。受访企业的员工人数介于5人至5,000人以上。这些企业中包括1,359间中小企业及1,878家大型企业。
发表者
SC Cyberworld
0
评论
标签: Cloud Computing, Symantec
Saturday, January 19, 2013
Symantec System Recovery 2013 Delivers Powerful and Easy To Use System Protection for Windows Server 2012 and vSphere 5.1; Now Available in Malaysia
KUALA LUMPUR, Malaysia – January 18, 2013– Symantec Corp. today announced Symantec System Recovery 2013 in Malaysia, providing organisations with comprehensive system protection with full platform support for Windows 8, Windows Server 2012 and vSphere 5.1. With the new version, system recovery is even more efficient and easier to manage with simplified installation, efficient backup and reconciliation, free centralised management, and easier issue diagnosis. Symantec System Recovery 2013 continues to allow companies to restore physical and virtual systems in minutes, even to bare metal, dissimilar hardware, remote locations, or virtual environments.
The new features in this latest release further extend Symantec System Recovery’s leadership position in disaster recovery and data protection for businesses of all sizes. Symantec System Recovery 2013 includes support for the latest applications and operating systems, a new management solution for large scale deployments, and faster backup windows by up to 750 percent.
Operational continuity and recovery from outages paramount for SMBs
Symantec System Recovery 2013 delivers superior backup and disaster recovery for servers, desktops, laptops, and virtual machines that enable businesses to recover from downtime or disasters in minutes. With patented Restore Anyware technology, IT administrators can rapidly restore exactly what they need, when and where they need it–including entire physical and virtual machines to bare metal or dissimilar hardware as well as files, folders, and granular application objects. Symantec System Recovery also provides cross-platform Physical-to-Virtual (P2V), Virtual-to-Virtual (V2V), and Virtual to-Physical (V2P) recoveries, an important complement to physical and virtual environments.
Advanced monitoring and added platform support make backup and recovery tasks quick and simple
Once the files to be backed up, a backup schedule, and a backup destination have been set, Symantec System Recovery begins backup automatically. Because Symantec System Recovery uses image-backup technology to capture a snapshot of the entire system, back-up and recovery tasks take just a few minutes. Symantec System Recovery 2013 adds support for the Windows Server 2012, Windows 8, and vSphere 5 platforms and a new monitoring tool, System Recovery Monitor. The System Recovery Monitor does not require a dedicated server, but can monitor the backup of several servers and desktops centrally with one system running Windows. It makes backup progress and the state of the backup system visible with its simple user interface, making it easy for non-IT specialists to use.
Additional new features in Symantec System Recovery 2013
• UEFI Support: Symantec System Recovery now enables boot from UEFI (Unified Extensible Firmware Interface) in addition to BIOS.
• 64 bit Support: Full 64 bit support is now included.
• Smart Reconciliation: Backups and reconciliation are efficiently completed by tracking changed blocks. The reconcile time is significantly reduced to seconds by eliminating the need to do a complete reconcile in cases of crashes or abrupt shutdowns.
o Incremental Backup without reconcile – Backups are at least 35 percent faster than Symantec System Recovery 2011
o Full Backup – Backups are at least 15 percent faster than Symantec System Recovery 2011
o Incremental Backup with reconcile – Backups are at least 750 percent faster than Symantec System Recovery 2011
• Updated Symantec System Recovery Linux Edition: The Symantec System Recovery Linux Edition now includes the ability to perform incremental backups and schedule backup jobs.
Product Information and Details
• Blog post: New Symantec System Recovery Out Now
• Availability: Symantec System Recovery 2013 is available now. For more information visit http://www.symantec.com/products-solutions/families/?fid=system-recovery
Wednesday, November 28, 2012
Symantec: Year End Holiday Online Shopping Tips
The year-end holiday season is upon us with school holidays already well underway. While most of us consider the holiday season to spend precious time with family and friends, we will also spend a considerable amount of money online. The growth in online spending is increasing globally, and with this rise in online shopping comes an increase in cybercrime.
As more people go online worldwide, individuals are increasingly becoming targets for fraudsters and cyber-criminals. According to the 2012 Norton Cybercrime Report from Symantec, cybercrime claims 556 million victims globally each year. Both businesses and consumers are victims of malware, phishing and malvertising threats.
There are simple ways to stay safe online to ensure an enjoyable shopping experience online. The following are five tips to stay safe online:
1. Look for an HTTPS and/or padlock in your browser address bar before submitting personal information on a website. A website with “https://” before the address indicates that it is secured with a SSL (Secure Socket Layer) certificate, a digital computer file (or small piece of code) that has two specific functions – authentication and verification; and data encryption.
Just as a passport may only be issued by a country’s government officials, an SSL certificate is most reliable when issued by a trusted Certificate Authority (CA). The CA has to follow very strict rules and policies about who may or may not receive an SSL certificate. When you have a valid SSL certificate from a trusted CA, there is a higher degree of trust by your customers, clients or partners.
2. When the browser address bar is lit up green, the identity of that website has been strictly validated.
3. Look for a trust mark, such as the (the Check Mark) Norton Secured Seal. It proves that the website is legitimate, and not a spoofed website.
4. If an offer in an online ad or an email sounds too good to be true, it probably is. You may be tempted to click, but you’d be wise to junk them instead.
5. Have Strong Passwords and Keep them Unique. “Cooldude” is not an acceptable password. Pay attention to the passwords for your email, social networking, and online banking accounts. Keep them as unique as you can:
• At least 8 characters
• Random mixture of characters upper and lower case, numbers, punctuation and symbols
• Use words not found in dictionary
• Never use the same password twice
• Change your password every 6 months








Nigel+-+Vincent+-+Alex+.jpg)







