Falling Down the CMMC Rabbit Hole

February 26th, 2020


Sometimes, government requirements and regulations can make you feel like you are Alice falling down new rabbit holes, trying to figure out just what exactly your business needs to do to win (and keep) your contracts and subcontracts. Do you need to be NIST certified? SP 800-53 or SP 800-171, or both?  What are FARS […]

Mozilla’s Firefox’s Default DoH

February 26th, 2020

51e7d6414b55b114a6da8c7ccf203163143ad6e75454774a702b 1280 Mozilla

Beginning today, February 25, 2020, Mozilla will now automatically send all of their US-based customers’ DNS queries to Cloudflare DNS servers, as opposed to the default DNS servers set by their users via their new feature, DNS-over-HTTPS (DoH). DoH executes DNS look-ups over an encrypted server instead of just sending them over plaintext, making it […]

Former Head of NSA Left Retirement to Help Cybersecurity Shortfall

February 26th, 2020

Cybersecurity lock chains

There is a national shortage of cybersecurity specialists, and the former head of the NSA, Mike McConnell, is actively trying to fix that issue. McConnell is a DC professional but is now splitting his time between there and the University of South Florida, in an attempt to fill in this gap of about 500,000 professionals […]

Hackers Close Down a Natural Gas Compression Facility

February 20th, 2020

Natural gas facility

Hackers used a spear-phishing campaign to successfully target an undisclosed natural gas compression facility here in the US, leading to a two-day closure. Their network and data were encrypted with ransomware, which essentially shut down the company’s control and communication abilities. While CISA did not provide many details about the virus involved, it appears that […]

Patients’ PTSD Details Leaked After Law Firms Hacked

February 19th, 2020

Soldier and dog

Law firms appear to be the latest black hat hacking trend. No less than FIVE law firms have been breached by cybercriminal group, Maze, in the last four months, and the results have been devastating.  Not only have these criminals STOLEN data, but they’ve also released extremely sensitive protected health information (PHI) from veterans’ pain […]

Columbus County School Still Not Whole After October Cyberattack

February 18th, 2020

6925546437 Ebf987867d B Apple Worm

The Columbus County school system, which was taken offline after a cybersecurity attack last October, is STILL feeling the effects today, even though progress is being made. Last night, school officials updated the county commissioners at a meeting on their current situation.  The National Guard has been helping and while some of their equipment has […]

Is CMMC Going to Cost My Business a Small Fortune?

February 17th, 2020

Hundred dollar bills

One of the most frequent questions I hear from our clients about the new Cybersecurity Maturity Model Certification, after a few choice words, is: “How much is this going to cost me?” It’s a great question, and one I can’t fully answer because, unfortunately, they haven’t even rolled out the auditor program yet!! That being […]

NHS Cyber Security Strengthened

January 31st, 2020

Arm wrestling

Healthcare providers in the US aren’t the only ones dealing with increased cyber attacks. A new report shows that while the National Health Service (NHS – the UK’s Government-funded medical and health care services provider) was compromised over 200 times by ransomware attacks from 2014 to 2017, the measures they took to fortify their cyber […]

Is Your Data Being Sold to Marketers by Your Antivirus Software Company?

January 31st, 2020

Hand over money

“Nothing in life is free.” A lot of people use Avast’s antivirus to protect their computer.  It costs you nothing out of pocket and it’s a pretty effective little cybersecurity tool. Sound to good to be true right? That’s because it is. Did you know that, by default, Avast not only collects your browser activity, […]

United Nations Hack and Cover-Up

January 31st, 2020

Not only has it been leaked that the UN was hacked, but there’s also evidence suggesting they tried to cover it up. What We Know According to a confidential internal document that was leaked to The New Humanitarian and shared with the  Associated Press (AP), more than 40 servers in Geneva and Vienna were compromised.  […]

Hackers Have Started Ransoming Patient Data… to the Patients

January 22nd, 2020

looking out rainy window

As if having your medical data compromised wasn’t bad enough… Now your medical secrets are being held hostage! It’s a breezy but sunny afternoon.  You’re going about your day, minding your own business when you receive a random text message from an unknown number saying that they have personal medical information about you that they will […]

Was Your Data Compromised by Equifax? Better Act Fast!

January 17th, 2020


Two billion dollars sure does sound like a lot of money for a class action lawsuit, but when you are a major credit reporting agency whose negligence compromised over 147 million people’s personal information? It’s really not.  Click here to file a claim free, online, if you were a potential victim of the massive Equifax […]

Authenticate Your Google Account With Your iPhone

January 16th, 2020

52e5d341435aa914ea898675c6203f78083edbe25a53714070287f 1280 Authentication

Among all the security features available today, two-factor authentication (2FA) is by far one of the most important, and apparently, Google is aware of that!  In their most recent iOS “Smart Lock” app update, they included a feature that will allow you to use your iPhone as a physical 2FA device.  After you set it […]

Microsoft’s Comprehensive End of Support List for 2020

January 14th, 2020

I know you are all aware of what I’m about to tell you, but just in case you momentarily forgot, I’m going to refresh your memory… Every year, Microsoft stops supporting select versions of its software.  What this means is that they discontinue any sort of security updates or patches.   What does this mean for […]

Just How Not “HIPAA Mandatory” Is Encryption?

January 8th, 2020

53e6d6474851b114a6da8c7ccf203163143ad9ed55517949762e 1280 Medical Security

In case you were ever wondering if your practice needs to encrypt its ePHI? Let the $3 million HIPAA penalty paid last month by the University of Rochester Medical Center (URMC), one of the largest medical systems in NY State, serve as a warning. The Department of Health and Human Services’ Office for Civil Rights […]

FBI Warns Business Owners: Beware of Increasing Maze Attacks

January 8th, 2020

57e8d5474e5ba514ea898675c6203f78083edbe25b557440732f7b 1280 Maze

Directly on the heels of LockerGoga and MegaCortex, a different strand of ransomware, Maze, which was first discovered nearly a year ago, started to target private companies in the US in November, and the FBI wants to make sure you know about it. Just two days after issuing an alert for LockerGoga and MegaCortex, the […]

Twitter Vulnerability Exposed in a Big Way

December 26th, 2019

9774490844 61368be03e B Twitter

Ibrahim Balic, a security researcher, recently exposed a flaw in Twitter’s app that allowed to match unique Twitter user accounts with 17 million phone numbers months ago.  He was able to accomplish this by uploading large lists of phone numbers by way of Twitter’s “Contacts Upload” feature that is available on the social media giant’s […]

Ransomware Attack Shuts Down New Orleans

December 14th, 2019

57e1d2454e5aaf14ea898675c6203f78083edbe25556784b722b7f 1280 New Orleans

It seems like something that only happens in movies and TV shows: It’s Friday the 13th.  You, your colleagues, your entire department, the entire city, in fact, receives the same command to power down their computers immediately and disconnect all devices from the network. But this wasn’t a movie and it wasn’t a TV show… […]

Sentara Doubled Down When They Should Have Folded

December 10th, 2019

57e4d6444d55aa14ea898675c6203f78083edbe25556704e732a72 1280 Blackjack

“Eight is Enough” A great, wholesome, family show from the late 70’s and early 80’s.  Also: what Sentara Hospital, with over 300 facilities across the states of North Carolina and Virginia, is telling the Department of Health and Human Services’ Office for Civil Rights (OCR) after being on the receiving end last month of this […]

Russian Hackers Hold Nursing Home Patients’ Data Ransom for $14M

December 9th, 2019


There is a reason hackers have started targeting hospitals and medical practices.  Not only is their cyber security known to be woefully lacking (despite the best efforts of the U.S. Department of Health and Human Services [HHS] and HIPAA regulations), but the electric Patient Health Information (ePHI) can literally be life and death.  Meaning?  The […]