7 tips for avoiding data loss in Office 365

7 tips for avoiding data loss in Office 365 Microsoft understands the value of your business’s data and the costly repercussions of losing it. That’s why they’ve released a slew of security and compliance tools for Office 365 subscribers. But given the increasing sophistication and frequency of data breaches, Office 365 cloud security solutions won’t be enough to protect your files. You’ll need to follow these seven security tips to truly avoid data loss in Office 365.

Take advantage of policy alerts Establishing policy notifications in Office 365’s Compliance Center can help you meet your company’s data security obligations. For instance, policy tips can warn employees about sending confidential information anytime they’re about to send messages to contacts who aren’t listed in the company network. These preemptive warnings can prevent data leaks and also educate users on safer data sharing practices.

Secure mobile devices With the growing trend of using personal smartphones and tablets to access work email, calendar, contacts, and documents, securing mobile devices is now a critical part of protecting your organization’s data. Installing mobile device management features for Office 365 enables you to manage security policies and access rules, and remotely wipe sensitive data from mobile devices if they’re lost or stolen.

Use multi-factor authentication Because of the growing sophistication of today’s cyberattacks, a single password shouldn’t be the only safeguard for Office 365 accounts. To reduce account hijacking instances, you must enable Office 365 multi-factor authentication. This feature makes it more difficult for hackers to access your account since they not only have to guess user passwords but also provide a second authentication factor like a temporary SMS code.

Apply session timeouts Many employees usually forget to log out of their Office 365 accounts and keep their computers or mobile devices unlocked. This could give unauthorized users unfettered access to company accounts, allowing them to compromise sensitive data. But by applying session timeouts to Office 365, email accounts, and internal networks, the system will automatically log users out after 10 minutes, preventing hackers from simply opening company workstations and accessing private information.

Avoid public calendar sharing Office 365 calendar sharing features allows employees to share and sync their schedules with their colleagues. However, publicly sharing this schedule is a bad idea. Enabling public calendar sharing helps attackers understand how your company works, determine who’s away, and identify your most vulnerable users. For instance, if security administrators are publicly listed as “Away on vacation,” an attacker may see this as an opportunity to unleash a slew of malware attacks to corrupt your data before your business can respond.

Employ role-based access controls Another Office 365 feature that will limit the flow of sensitive data across your company is access management. This lets you determine which user (or users) have access to specific files in your company. For example, front-of-house staff won’t be able to read or edit executive-level documents, minimizing data leaks.

Encrypt emails Encrypting classified information is your last line of defense to secure your data. Should hackers intercept your emails, encryption tools will make files unreadable to unauthorized recipients. This is a must-have for Office 365, where files and emails are shared on a regular basis.

While Office 365 offers users the ability to share data and collaborate flexibly, you must be aware of the potential data security risks at all times. When you work with us, we will make sure your business keeps up with ever-changing data security and compliance obligations. And if you need help securing your Office 365, we can help with that too! Simply contact us today.

 

A brief history of virtual quarantines

A brief history of virtual quarantines Malware is becoming more sophisticated every day, and we recommend several solutions for dealing with it. One of the most interesting of these is achievable via cutting-edge virtualization technology. Often referred to as sandboxing, this solution is a great way to quarantine and test suspicious applications before exposing them to your entire network.

What is sandboxing?

Sandboxing is one of the rare concepts in virtualization that the average person can usually grasp in just a couple short sentences. Essentially, sandboxing is the practice of tricking an application or program into thinking it is running on a regular computer, and observing how it performs. This is especially useful for testing whether unknown applications are hiding malware.

Obviously, it gets far more complicated once you delve into the details of how you implement a sandboxing technique, but the short answer is that it almost always involves virtualized computers. The program you want to test thinks it’s been opened on a full-fledged workstation of server and can act normally, but it’s actually inside of a tightly controlled virtual space that forbids it from copying itself or deleting files outside of what is included in the sandbox.

An effective way to quarantine

Virtualization is no simple task, but the benefits of sandboxing definitely make the effort worth it. For example, virtualized workstations can essentially be created and destroyed with the flip of a switch. That means:

  1. You aren’t required to manage permanent resources to utilize a sandbox. Turn it on when you need it, and when you’re done the resources necessary to run it are reset and returned to your server’s available capacity.
  2. When malware is exposed inside a sandbox, removing it is as simple as destroying the virtual machine. Compare that to running a physical workstation dedicated solely to sandboxing. Formatting and reinstalling the machine would take several hours.
  3. Variables such as which operating system the sandbox runs, which permissions quarantined applications are granted, and minimum testing times can be employed and altered in extremely short periods of time.

This strategy has been around for nearly two decades, and some cybersecurity experts have spent their entire careers working toward the perfect virtual sandbox.

Containers: the next step in this evolution

Recently, the virtualization industry has been almost totally consumed by the topic of “containers.” Instead of creating entire virtual workstations to run suspicious applications in, containers are virtual spaces with exactly enough hardware and software resources to run whatever the container was designed to do.

Think of the metaphor literally: Older sandboxes came in a uniform size, which was almost always significantly larger than whatever you were placing into them. Containers let you design the size and shape of the sandbox based on your exact specifications.

Quarantined virtual spaces fit nicely into the sandbox metaphor, but actually implementing them is impossible without trained help. Whether you’re looking for enhanced security protocols or increased efficiency with your hardware resources, our virtualization services can help. Call us today.

Windows 10 Creators Update: new features

Windows 10 Creators Update: new features Instead of an outright operating system update, Microsoft is now releasing named updates that come with enhancements and other features that individual users and businesses should get excited about. Its latest, Creators Update on Windows 10, includes new design touches and a handful of productivity features. Are the new features worth the updates?

Controlled updates

If you’ve been using Windows 10, you’re familiar with this scenario: While you’re on your computer, the system automatically reboots for automatic updates, interrupting your workflow. Although automatically having your system updated on time has advantages, it can also be a burden and a nuisance because it leaves you with no option to decline or delay an update -- which you might want to do especially when you’re in the middle of a critical task.

With the Creators Update, you can choose to pause updates for a week. It also lets you set Active Hours, an 18-hour window when Windows won’t install updates. It’s a minor enhancement that should be a welcome feature to users who like having better control over their system updates.

Improved privacy controls

When Windows 10 was launched, privacy was a big concern among users, mainly because of the amount and nature of data being collected. Users and certain regulatory bodies were alarmed that Microsoft, through Windows 10, didn’t have enough control over how it processes and collects data. Microsoft initially responded by announcing that setting up privacy protocols will be easier when it launches its new updates.

And now, Microsoft has taken steps to address these privacy issues. Creators Update introduces a Privacy Dashboard, which offers a more seamless and user-friendly way to control privacy settings, specifically in terms of location, speech recognition, diagnostics, tailored diagnostics data, and relevant ads.

Another privacy enhancement is in Windows Defender, which now features improved scanning options and better reporting of your PC’s performance and health.

Other small changes

Other interface enhancements and updates to the Windows 10 ecosystem also add a nice touch to the overall user experience. These updates include more vivid themes, a bluetooth-enabled lock function called Dynamic Lock, new display settings, videos and maps writing capabilities, and more.

Among the other new features, users might not immediately notice the upgraded storage settings. If you’re worried about all these new applications and programs taking up space in your PC, don’t fret. The new update also comes with a storage setting that auto-deletes unnecessary files when your storage space is about to run out.

All in all, businesses that use Windows 10 can expect better privacy, controlled updates, improved security, and a smoother user experience with the Creators Update. Microsoft is expected to introduce even more updates later this year, and if you want to know how you can make the most of these and other Microsoft features, we’re here to help.