Client Area

This section can be repurposed a number of ways.

cybersecurity Tag

Keyboard with blue overlay

Every 39 Seconds
The most alarming number in cybersecurity…

Count to thirty-nine.
By the time you get there, a cyberattack has just been launched somewhere in the world. Not a vague, background threat. A real, targeted, often automated strike against a real organization: a business, a hospital, a law firm.

By the time you finish this paragraph, three more.

The, 39 seconds” figure is sourced from multiple independent research bodies: Forbes, Varonis, IBM, and represents the average global frequency of documented cyberattacks. It is one of the most cited statistics in cybersecurity. It is also one of the least truly understood.

Understanding it isn’t about being alarmed. It’s about grasping what it means operationally: for your firm, your clients, and the decisions you make about how seriously you take your defenses.

What 39 Seconds Actually Means

Raw numbers are easy to tune out. So let’s make it concrete.

  • Right now, reading this:
    ~5 attacks have been launched
  • During a 1-hour meeting
    ~92 attacks globally
  • During a standard workday
    ~738 attacks
  • Today alone
    ~26,000 attacks (Forbes)

Those 26,000 daily attacks are not randomly distributed. They are targeted, triage-scored by automated tools that continuously scan for weaknesses. Law firms appear on those lists with alarming frequency, not because attackers have a grievance with the legal profession, but because the math works in their favor.

Law firms hold extraordinarily high-value data: privileged communications, litigation strategy, merger documents, client financials. And they have historically underinvested in security. That combination: high value, lower defenses, is exactly what automated tools are designed to find.

Who Is Launching 26,000 Attacks a Day

The majority of today’s attacks are not conducted by individuals at keyboards manually probing systems. Cybercrime has industrialized.

Organized criminal enterprises operate with the structure of legitimate businesses: development teams building malware, operations teams managing attack infrastructure, finance teams processing ransom payments. The average ransomware payout in 2025 reached $1,000,000 (Sophos). This is a mature, profitable criminal economy.

Nation-state actors add a different layer, their objectives are intelligence and disruption, not just ransom. For firms serving clients in sensitive industries, the relevance of state-sponsored hacking is not theoretical.

But the largest volume of attacks in the 39-second cadence comes from automated opportunistic tools. They scan IP ranges continuously, probing for unpatched software, weak passwords, and misconfigured systems. They don’t need a specific reason to target your firm. They just need to find a door that isn’t properly locked.

$1M

Average ransomware payout, 2025 (Sophos)

0.05%

Chance attacker is prosecuted (World Economic Forum)

That 0.05% prosecution figure is perhaps the most clarifying number in the entire threat landscape. Cybercriminals operate in near-total impunity. The deterrent effect of prosecution, which shapes behavior in almost every other crime category, is essentially absent. This is why the 39-second clock exists and why it will not slow down on its own.

The 88% Problem

Here is the statistic that matters most for law firms specifically: 88% of cybersecurity breaches involve human error (Stanford University).

Not sophisticated technical intrusions. Not nation-state zero-days. Someone clicking a link. Reusing a password. Uploading a privileged document to an AI tool. Wiring money after receiving a convincing phone call.

This is not a criticism of the people involved. They are operating in an environment precision-engineered to exploit their trust, their time pressure, and their instinct to be responsive. Attackers study legal culture specifically: the deadline urgency, the partner-staff trust dynamic, the expectation that requests from senior people are acted on quickly and quietly.

The implication is that technical defenses alone are not sufficient. A team that receives monthly, scenario-specific security training, not an annual checkbox exercise, but realistic simulations of the exact attacks they will face, is a fundamentally different security posture than one that doesn’t. Culture and habits are part of your security stack.

What It Costs When the Clock Finds You

The average cost of a US data breach in 2025 reached $10.22 million, an all-time high, according to IBM. That figure covers direct costs: forensic investigation, incident response, system restoration, ransom payments. For a 20-to-50-attorney firm, direct costs alone can run $150,000 to $500,000 before factoring in anything else.

Then come the dimensions unique to law firms. ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information. A breach resulting from inadequate security can trigger bar investigations, disciplinary proceedings, and malpractice claims. The regulatory exposure compounds the financial exposure in ways that are uniquely devastating for professional services practices.

The Hiscox Cyber Readiness Report found that 43% of organizations lost clients following a cyberattack. For a law firm where client relationships are the firm’s primary asset, that loss is potentially the most lasting damage of all.

That 181-day detection average deserves emphasis. Attackers are frequently inside networks for six months before anyone knows — reading emails, downloading files, positioning for maximum damage. The breach you discover is rarely the breach that began.

What the Clock Demands of Your Firm

The 39-second clock is not a reason to panic. It is a reason to be clear-eyed and deliberate. Here is what an adequate response looks like.

  • Know your actual posture: Most firms discover significant gaps between the security they believe they have and the security that exists when assessed professionally. Get an honest evaluation — not a vendor pitch, a real assessment against current threat standards.
  • Upgrade email security: Modern AI-powered email tools detect anomalies in communication patterns rather than keywords. They sandbox suspicious links before anyone clicks. Traditional spam filters were not designed for AI-generated phishing.
  • Deploy MFA everywhere: On email, case management, financial systems, cloud storage, remote access. MFA is the single most effective control against credential-based attacks. It should be considered non-negotiable.
  • Move to EDR: Endpoint Detection and Response analyzes behavioral patterns rather than signature matching. It catches threats that traditional antivirus was never designed to see.
  • Monitor continuously: Attackers don’t observe business hours. If your security posture goes dark at 5 PM, that is a gap automated tools will find. 24/7 monitoring is not optional in this environment.
  • Train specifically and frequently: Scenario-based training, monthly. Phishing simulations against the exact attacks your team will face. A no-blame reporting culture where people feel safe flagging suspicious activity immediately.

The Question the Clock Is Asking

Every 39 seconds. 26,000 attacks today. 88% starting with human error. $10.22 million average cost. 0.05% chance of prosecution.

The question it keeps asking is simple: what does it find when it reaches you?

 

Need a partner in IT solutions? Contact us here!

Console lines
Four AI-powered attacks targeting law firms right now and why fighting back requires using AI yourself.
 
It’s 10:47 AM on a Tuesday. A senior associate receives an email from opposing counsel referencing the exact case she’s worked on for three weeks. The name is right. The case is right. The tone is perfect.
 
She clicks the link.
 
By 3:15 PM, every screen in your office shows a ransom note.
The email that started it wasn’t written by a human. AI scraped your firm’s public data, court filings, and the associate’s LinkedIn profile and generated something indistinguishable from a legitimate message, in seconds.
 
This is the 2026 threat landscape. AI has changed the economics of cybercrime fundamentally: tasks that once required skilled teams now run automatically, at scale, for almost nothing. Meanwhile, most law firms are still defending against 2020-era attacks.
 
Here are the four AI-powered threats you need to understand and what each one demands of your defenses.

Threat 1: AI-Powered Phishing

Surgically Precise Emails Your Team Cannot Ppot

AI analyzes court filings, firm websites, LinkedIn profiles, and prior email patterns to craft messages that are contextually perfect. No typos. No generic greetings. Your real case name, your real colleague, your firm’s exact tone.

Standard spam filters were built to catch the old generation of phishing — suspicious domains, generic keywords, structural red flags. AI-generated phishing contains none of these. It bypasses technical filters and human instincts simultaneously.

The attack chain is fast. Credentials captured, network mapped, ransomware positioned — all within hours. The average time from a single click to full network compromise is four hours.
Law firms are especially exposed. Legal culture runs on urgency and trust: when an email references a real deadline and comes from a familiar name, the instinct is to act, not verify. Attackers engineer exactly this pressure.

4 hours

Average time from phishing click to full network compromise

Source: IBM Threat Intelligence 2025

The defense requires AI fighting AI: behavioral email security that detects anomalies rather than keywords, link sandboxing that evaluates URLs before anyone clicks, and MFA everywhere so that stolen credentials alone are not enough to compromise your systems. Monthly phishing simulations, not annual checkbox training are the difference between a team that recognizes these attacks and one that doesn’t.

Threat 2: Voice Cloning

Three Seconds of Audio is All It Takes

AI clones a voice from any public recording — a podcast, a video, a recorded CLE — and produces a perfect replica. The attacker calls your bookkeeper, paralegal, or associate, sounds exactly like your managing partner, and requests an urgent wire transfer.

“Hi Sarah, it’s David. I’m in a client meeting, wire $75,000 to the settlement account before 4 PM. I’ll send the details now.”

The voice is identical. The scenario is plausible. The instructions arrive by email from a spoofed account. And $75,000 is gone.

Voice cloning attacks work because law firms run on trust. Partners are often unreachable. Deals are always urgent. That professional culture, weaponized by AI, becomes a liability.

One rule stops 100% of voice cloning attacks: any wire transfer request, regardless of who it appears to come from, requires verbal confirmation on a pre-established number from your contacts or firm directory. Not the number that called you. A number you already have. Thirty seconds of friction eliminates the entire threat category.

Threat 3: Deepfake Executives

Video Calls Your Eyes Cannot Distinguish From Real

Deepfake technology places a real person’s face and voice onto fabricated video in real time. What required Hollywood resources five years ago now costs an attacker roughly $50 and a consumer laptop.

The attack: a staff member receives a video call from what appears to be the managing partner. Face right. Voice right. Mannerisms right. The “partner” explains a deal is closing and needs an urgent, confidential financial transaction processed immediately.

The financial damage is severe. But the more insidious threat is evidentiary: fabricated video evidence, false depositions, manipulated court submissions. Law firms are not just organizational targets — they are custodians of the legal record.

Defense requires a process, not just technology. Any unusual request received by video — especially one combining urgency and confidentiality — should trigger an out-of-band call on a pre-established number. The technology to fake a video call is accessible. The technology to simultaneously fake a phone call to a number you already have is not. AI-powered deepfake detection tools are also emerging as a necessary component of enterprise security stacks.

Threat 4: Automated Vulnerability Scanning

The Attacker Who Never Sleeps and Never Gets Tired

AI-powered scanning tools probe your entire digital footprint continuously, identifying unpatched software, misconfigured systems, exposed credentials, and open ports. When they find a weakness, they generate tailored exploits and either deploy them or sell access to specialists.

This automation has changed the economics of targeting law firms. Previously, attacking a small practice required significant human effort for modest return. Now, automated tools scan thousands of firms simultaneously and prioritize the weakest ones. Your firm doesn’t need to be targeted specifically, it just needs to appear vulnerable in a scan.

277 DAYS – Average time attackers are inside a network before discovery. 

The timeline is the most alarming part. Attackers are frequently inside networks for months before anyone knows, reading emails, downloading files, and positioning ransomware for simultaneous deployment across every system. The “good enough” security posture: antivirus, a firewall, occasional patching,  was designed for a world where attackers had to work for their access. It is not designed for this one.

The Question Your Firm Needs to Answer

Attackers are using AI offensively. The firms that survive 2026 are the ones using it defensively. Right now, only one side is bringing AI to this fight. The question is which side yours is on.

Our Commitment to Community and Growth

We champion personal growth and societal contribution by encouraging our team to engage in charity work, supporting them with additional time off and funded trips to make a tangible difference. Reflecting our commitment to these values, we contribute a deliberate portion of our earnings to carefully selected charities each year. Our philanthropic efforts span national organizations and local initiatives, from St. Jude to various artistic programs and human-i-t.

Making a Real Difference

At OWG, we partner with these organizations to enact real change—a claim many assert, but few truly fulfill. Our dedication to these values not only defines our corporate culture but also underscores our mission to leave the world better than we found it.

Need a partner in IT solutions? Contact us here!

Navigating Cybersecurity
The phone call came at 7 AM on a Monday.
A managing partner at a mid-sized law firm. Thirty attorneys. Solid reputation. Decades in business.
“We’ve been breached. All our files are encrypted. They’re threatening to publish our client data. What do we do?”
This conversation happens more often than you’d think. And it’s happening to firms just like yours.

The Reality: You're the Prime Target

Cybersecurity is no longer just a technical concern, it’s a legal, ethical, and reputational imperative.

According to the ABA 2024 Cybersecurity Tech Report, 27% of law firms experienced a data breach in the past year. Even more concerning: over half admitted they lacked a formal incident response plan.

Let that sink in: One in four firms were breached. Half weren’t prepared for it.

Law firms, accounting practices, and professional service organizations aren’t just potential targets. You’re prime targets. And attackers know exactly why.

Why Attackers Target Professional Services

  1. High-Value Data
    Client financial records. Legal strategies. M&A plans. Attorney-client privileged communications. Every file is valuable—for ransom, competitive intelligence, or sale on the dark web.
  2. Attorney-Client Privilege Is Leverage
    Threatening to publish privileged communications creates nuclear-level pressure. The reputational fallout often makes firms pay.
  3. Smaller Security Budgets
    Fortune 500 companies have security operations centers and dedicated teams. Professional services? Maybe one IT person. Attackers exploit this.
  4. Trust Enables Social Engineering
    “Hi, this is [senior partner]. I need you to wire $50K for a client settlement. Urgent.”
    These attacks work because professional services operate on trust and urgency. Attackers weaponize both.
  5. Regulatory Pressure
    Bar associations and mandatory disclosure requirements create immense pressure. Three weeks offline means potential sanctions, malpractice claims, and license risk. Attackers know firms will pay to avoid this.

The Threat Landscape Changed

AI-Powered Phishing

AI now writes emails that know your name, reference real colleagues, match your firm’s tone perfectly, and include legitimate-looking links. Your staff can’t reliably spot these anymore. Neither can most email filters.

Ransomware 2.0

Modern ransomware steals your data first, then encrypts it. If you don’t pay, your client files get published on leak sites, privileged communications become public, and opposing counsel gets your litigation strategy.

Supply Chain Attacks

Attackers compromise your case management software, document systems, or cloud backup providers. Every vendor with access is a potential entry point.

Deepfakes

AI can clone voices with seconds of audio. Imagine a “video call” with a senior partner authorizing a wire transfer—except it’s not actually them.

The Compliance Crisis

Professional services face overlapping requirements that make security failures career-ending:
 
ABA Model Rule 1.6(c): You must implement reasonable cybersecurity measures. Failure is an ethical violation.
 
State Bar Rules: Mandatory breach notification, required security training, specific technical controls. Violations can result in sanctions or disbarment.
 
GDPR: Fines up to €20 million or 4% of revenue. Even one EU client triggers requirements.
 
SOC 2: Corporate clients increasingly demand certification before engagement.
 
Cyber Insurance: Requirements now include MFA, quarterly backup testing, EDR, regular audits, and documented incident response plans. Can’t prove it? No policy.

What Actually Protects You

Most breaches are preventable. Here’s what non-negotiable security looks like in 2026:
  1.  Multi-Factor Authentication Everywhere
    Not just email. Case management, document systems, banking, cloud storage, remote access. 81% of breaches involve stolen credentials. MFA stops this cold.
  2. Tested Backups
    “We have backups” doesn’t count if you’ve never tested restoring them. Quarterly restore tests must be documented. Too many firms discover during an attack that backups don’t work.
  3. Encryption Everywhere
    Data at rest, data in transit, endpoints, email. If a device is lost or stolen, encryption is your last defense.
  4. Proper Access Controls
    Does every paralegal need admin access? Every associate need access to every file? Least privilege access limits damage when accounts are compromised.
  5. Advanced Email Security
    AI-powered phishing requires AI-powered detection. Standard spam filters aren’t enough. You need tools that analyze behavior patterns and detect credential phishing.
  6. Endpoint Detection and Response (EDR)
    Antivirus is dead. Modern threats bypass it easily. EDR provides behavioral analysis, automatic containment, and forensic data.
  7. Security Awareness Training
    Not annual compliance theater. Monthly 5-minute lessons with real examples, simulated phishing tests, and immediate feedback. Create a culture where people report suspicious activity immediately.
  8. Formal Incident Response Plan
    When you’re breached at 2 AM, you don’t want to be figuring out who to call, what to shut down, or how to notify clients. Document it. Test it. Update it.
  9. Vendor Risk Management
    Before onboarding vendors, verify their security certifications, encryption practices, access controls, and incident response processes. Document everything in contracts.
  10. Regular Security Audits
    Quarterly internal reviews of access, updates, and compliance. Annual external audits by qualified professionals who find what internal teams miss.

The AI Era Requires New Thinking

AI-Powered Defense

You can’t manually review every email for AI-generated phishing. You need security tools that use AI to detect anomalous behavior, credential theft, deepfakes, and threats in real-time.

But AI Creates New Risks

Your team is using ChatGPT to draft documents and summarize case law. Are they uploading privileged information? Using tools that train on your data?

You need an AI usage policy that:

  • Defines what can/cannot go into AI tools
  • Specifies approved tools (business versions that don’t train on data)
  • Requires training on safe usage
  • Monitors compliance

Security as Competitive Advantage

When prospects ask “How do you protect our data?” or “Are you SOC 2 certified?” you want to answer confidently and credibly.
 
Security builds trust. Trust wins clients.
 
The firms winning high-value work in 2026 demonstrate—not just claim—robust security practices.
 
The question isn’t whether you’ll invest in security.
 
The question is whether you’ll invest before or after being breached.

Take Action Today

We specialize in helping law firms, accounting practices, and professional services organizations navigate cybersecurity, compliance, and the evolving threat landscape.
Schedule a free security assessment:

  • Honest evaluation of your current security posture
  • Identification of critical gaps and risks
  • Prioritized roadmap for improvements
  • No obligation, no sales pressure
Trends 2026
What Actually Matters for Your Business…

Look, every January the internet explodes with tech predictions that sound like they were written by someone who’s never run a business. AI everything. Quantum computing. Buzzwords on buzzwords.

Here’s what we’ve learned: most “trends” don’t matter to you until they actually affect your operations or put your business at risk.

So instead of the usual hype, here’s what’s actually happening in 2026 that you need to pay attention to—and what to do about it.

 

1. AI Is Standard Business Infrastructure Now

The Reality:

AI tools are becoming as standard as email. Microsoft Copilot is baked into most Microsoft 365 plans. Your team is already using ChatGPT, Claude, and similar tools to draft emails and research topics, often without realizing they might be leaking sensitive data.

What You Need to Do:

  • Create an AI usage policy immediately
  • Get business versions that don’t train on your data (Copilot for Business, ChatGPT Enterprise)
  • Train your team on safe AI usage

Real Talk:

AI won’t replace your team, but employees who know how to use AI will replace those who don’t.

2. Ransomware Got Smarter and Nastier

The Reality:

Ransomware groups now use AI to write convincing phishing emails, they’re targeting smaller businesses (easier targets), and they’re not just encrypting your files—they’re stealing them first and threatening to publish everything if you don’t pay.
 
Insurance companies are getting picky too. No multi-factor authentication? No backup testing? Good luck getting coverage.

What You Need to Do:

  • Multi-factor authentication on EVERYTHING
  • Test your backups (actually do a restore, don’t just assume they work)
  • Get email filtering that catches threats before they reach inboxes
  • Have an incident response plan before you need it

Real Talk:

Average ransomware payment is $200K+ for small businesses, with 21 days of downtime. Can you survive three weeks offline?

3. Cloud Sprawl is Killing Your Budget

The Reality:

Everyone’s in the cloud, but most businesses have no idea what they’re paying for. Shadow IT everywhere—employees buying subscriptions, departments using different tools, nobody tracking anything.
 
Your cloud bill is probably 30-40% higher than it needs to be. Plus, every SaaS tool is another potential security hole.

What You Need to Do:

  • Audit subscriptions quarterly (pull those credit card statements)
  • Consolidate tools where possible
  • Implement single sign-on (SSO) for centralized access control
  • Set up proper permissions on shared drives

Real Talk:

We found $47,000 in annual waste for one client last month. That’s nearly $4K a month just… gone.

4. Your Employees Will Make Mistakes, Plan for It

The Reality:

Security training is important, but your employees are tired, busy, and checking email at 11 PM on their phones. They’ll make mistakes. The real problem is when they’re too embarrassed to report it immediately.

What You Need to Do:

  • Create a no-blame reporting culture
  • Implement security that works in the background (EDR tools)
  • Make security convenient (password managers, SSO, easy MFA)
  • Regular short training (5 minutes monthly, not annual 2-hour sessions)

Real Talk:

Your security problem isn’t the employee who clicked something, it’s that one click gave access to your entire network. That’s an architecture problem, not a people problem.

5. Zero Trust Isn't Just for Big Companies

The Reality:

“Zero Trust” is a fancy way of saying “stop assuming everyone inside your network is safe.” Your employees work from home, coffee shops, airports, your network perimeter doesn’t exist anymore.

What You Need to Do:

  • Start with MFA everywhere (yes, again)
  • Implement least-privilege access (nobody needs access to everything)
  • Look into zero-trust network access (ZTNA) tools instead of old VPNs
  • Monitor everything (3 AM access from Bulgaria should raise flags)

Real Talk:

Zero Trust sounds like overkill until a stolen password gives someone access to your entire file server.

6. Compliance Has Teeth Now

The Reality:

GDPR, CCPA, HIPAA, CMMC, regulators aren’t sending warning letters anymore. They’re hitting businesses with real penalties. “I didn’t know” isn’t a defense.
 
Your clients are asking more questions too. RFPs include security questionnaires. Partners want proof of your cybersecurity measures.

What You Need to Do:

  • Understand what regulations apply to you
  • Document everything (policies, procedures, evidence)
  • Regular security audits (don’t wait for deadlines or breaches)
  • Consider cyber insurance (but they’ll require security measures first)

Real Talk:

Compliance is a pain, but it’s a competitive advantage when you can confidently answer security questionnaires while competitors fumble.

7. You Can't Build an In-House Security Team (So Stop Trying)

The Reality:

There are 3.5 million unfilled cybersecurity jobs globally. A junior security analyst costs $80K+. A senior one? $150K+. You can’t afford that, and even if you could, you can’t find them.

What You Need to Do:

  • Stop trying to do everything in-house
  • Find a managed service partner who actually cares (not just ticket-takers)
  • Get 24/7 monitoring (attacks don’t happen 9-5)
  • Invest in the relationship (your IT partner should feel like part of your team)

Real Talk:

One full-time IT person costs $60-80K plus benefits. A managed service gives you a whole team with specialized skills for roughly the same cost.

8. Remote Work Security Can't Be an Afterthought

The Reality:

Your security perimeter is now every employee’s home network, phone, laptop, and coffee shop WiFi. The “protect the office network and you’re fine” approach is dead.

What You Need to Do:

  • Secure all endpoints (every laptop, phone, tablet)
  • Company-managed devices only (BYOD is asking for trouble)
  • Cloud-based security that works anywhere
  • Modern access solutions (VPN or better alternatives like ZTNA)

Real Talk:

Secure the users, not the location.

9. Supply Chain Attacks Are Everywhere

The Reality:

Why break into your network when attackers can breach your software vendor and push malware through their update system? Every vendor and tool is a potential entry point.

What You Need to Do:

  • Vet vendors before signing up (ask about their security practices)
  • Limit vendor access (sandbox it)
  • Monitor third-party tools
  • Have a vendor incident response plan

Real Talk:

You can have perfect security and still get breached because a vendor three steps removed got compromised.

10. Passwords Are Finally Dying

The Reality:

Passwordless authentication is getting real. Apple, Google, and Microsoft are pushing passkeys hard. More services offer FaceID, fingerprint, or security key login instead of passwords.

What You Need to Do:

  • Enable passkeys where available
  • Still use password managers (we’re not fully passwordless yet)
  • MFA everywhere
  • Plan migration as your tools add passkey support

Real Talk:

Passwordless is both more secure AND more convenient. Rare win-win.
Technology should make your business run better, not keep you up at night. You don’t need to be on the bleeding edge of everything, but you need the basics covered: strong authentication, good backups, proper monitoring, trained employees, and a partner who has your back.
These aren’t abstract future problems, they’re affecting businesses right now. The question isn’t whether these trends will impact you. It’s whether you’ll be ready when they do.
 
Want help making sense of this? We do free security assessments, no sales pitch, no fear mongering. Just an honest look at where you stand and recommendations you can actually act on.
 

Schedule your free security assessment.

Business Email Compromise –  When the criminal’s reading your email.

 

We’re all connected – the closer a hacker gets to your vendor, your client, your partner… the closer they are to you. Here’s the story of an advertising agency who thought they were communicating with their event venue.

Inc. estimates 60% of companies go out of business within six months of a cyber attack.

Haven’t we had enough attacks, hacks and breaches? The best offense is a strong defense – it’s time to start defending ourselves! 

 

Drop your name and email to learn more, or tag our calendar to setup a conversation.

Whats a vulnerability assessment

Can today’s business leader explain what a vulnerability assessment actually is?

Like trying to explain what water tastes like, or defining the word “the”, we’ve found that while today’s business leader is quite familiar with the term “vulnerability assessment” few can explain what a vulnerability assessment actually is.

 

Even more, ask three IT professionals what a vulnerability assessment is and you’re likely to get three different answers.  

So what is a vulnerability assessment? How often should you have one? How much should you expect to pay? And what’s the difference between a vulnerability assessment and a penetration test? .

Defining a vulnerability assessment as “the process of defining, identifying, classifying, and prioritizing vulnerabilities in computer systems,applications, and network infrastructures”, our friends at TechTarget have published an excellent article defining the process and detailing some of the finer points. Below is a summary of TechTarget’s publication, and a few of their highlighted best practices. (For a deeper dive into the process, check out www.techtarget.com/searchsecurity/definition/vulnerability-assessment-vulnerability-analysis) ‍

As explained by Linda-Rosencrance of TechTarget, a vulnerability assessment can provide an organization with the necessary knowledge to understand and react to threats within its environment. Organizations of any size, or even individuals who face an increased risk of cyber attacks, can benefit from some form of vulnerability assessment, but large enterprises and high-target organizations (eg. insurance agencies, financial institutions, accounting firms, medical offices, law firms) that are subject to attacks will benefit most from a vulnerability analysis as they provide an organization details on any security weaknesses in its environment and direction on how to assess the risks associated with those weaknesses. 

 

The process offers an organization a better understanding of its technology assets, security flaws and overall risk, thereby reducing the likelihood that a cybercriminal will breach its systems and catch the business off-guard.‍

Types of vulnerability assessments

·        Network-based scans: Used to identify possible network security attacks. This type of scan can also detect vulnerable systems on wired or wireless networks.
·        Host-based scans: Used to locate and identify vulnerabilities in servers, workstations or other network hosts.This type of scan usually examines ports and services that may also be visible to network-based scans. However, it offers greater visibility into the configuration settings and patch history of scanned systems, even legacy systems.
·        Wireless network scans: Focus on points of attack within the organization’s wireless network infrastructure. In addition to identifying rogue access points, a wireless network scan can also validate that a company’s network is securely configured.
·        Application scans: Test websites to detect known software vulnerabilities and incorrect configurations in network or web applications.
·        Database scans: Identify weak points in a database to prevent malicious attacks, such as SQL injection attacks.

Vulnerability assessment vs. pen test

A vulnerability assessment often includes a penetration testing component to identify vulnerabilities in an organization’s personnel, procedures or processes. These vulnerabilities might not normally be detectable with network or system scans. The process is sometimes referred to as vulnerability assessment/penetration testing, or VAPT.

 

However, penetration testing is not sufficient as a complete vulnerability assessment and is, in fact, a separate process.

A vulnerability assessment aims to uncover vulnerabilities in a network and recommend the appropriate mitigation or remediation to reduce or remove the risks. It uses automated network security scanning tools, and lists the results in an assessment report. However, it does so without evaluating specific attack goals or scenarios. Organizations should employ vulnerability testing on a regular basis to ensure the security of their networks, particularly when changes are made. For example, testing should be done when services are added, new equipment is installed or ports are opened.

 

 

Penetration testing, in contrast, involves identifying vulnerabilities and attempting to exploit them in order to attack. Although sometimes carried out in concert with vulnerability assessments, the primary aim of penetration testing is to check whether a vulnerability really exists and infiltrate the organization. In addition, penetration testing tries to prove that exploiting a vulnerability can damage the application or network.

Finally, while a vulnerability assessment is usually automated to cover a wide variety of unpatched vulnerabilities, penetration testing generally combines automated and manual techniques to help testers delve further into the vulnerabilities and exploit them to gain access to the network in a controlled environment.

For more information or to discuss how a vulnerability assessment can help your organization just complete the form below or set a time to connect.

Portions of this article were written by Linda-Rosencrance and published by TechTarget at www.TechTarget.com/searchsecurity/definition/vulnerability-assessment-vulnerability-analysis

Zero-Trust-Cybersecurity

As the business community faces down cyber threats, one medical office is defending itself with a Zero Trust approach to cybersecurity

Physicians have always been at the front of the line when it came to technology integration. Among the first to realize the benefits wearing a pager, having a cell phone, using a tablet, and essentially digitizing their business, doctors and researchers are typical early adopters of mobile, Cloud and IOT systems. 

As attacks on the healthcare industry make weekly news, personal information (PII) floods the black market, and steep fines take their toll,doctors and practice administrators wonder what they can do differently. 

A holistic strategy, a Zero Trust approach to cybersecurity means that you:

     1) Verify Explicitly
     2) Use Least Privilege
     3) Assume Breach

Want to learn more? Complete the form and download the business case.

Zero Trust

As cyberattacks on midsize firms prove inevitable, are you ready to be hit?

A strong defensive posture minimizes exposure, limits collateral damage and protects client privacy. ‍

We’ve been providing IT consulting and technology services to the mid-size business community since 1999, and from basic firewalls to advanced breach detection systems we absolutely guarantee there’s no shortage of security products designed to protect the enterprise. 

 

But third party/supply chain attacks have changed this game. Drastically. And, from the most basic user training videos, to a 24×7 monitored security and information management (SEIM) system, there’s not one thing a business can do to protect data when its business management system, ERP or CRM is breached. Bottom line – every business on the planet relies on third-party software and there’s simply no safe place to hide. Boo!

Since shutting down shop isn’t an option, we must, as always, take up this threat and face it head on!

 

As we wrote in an post about Zero Trust Cybersecurity, you can only worry about what’s within your control. Since fully defending against this attack isn’t possible, we can only protect our organizations and prepare to be attacked.

1. Deploy a multi-layered detection and response approach. Multisyllable marketing jargon aside – as quickly as possible, you need to know you’ve been breached, and you need a post-attack response plan (or plans). “Honeytokens” or virtual trip wires setup to alert organizations of suspicious activity in their network are a great tool. If a being breached is bad, not learning about it till days or weeks after it happens is worse and not knowing what to do next can be catastrophic. www.upguard.com/blog/how-to-prevent-supply-chain-attacks

2. Include threat hunting as regularly scheduled IT maintenance. As described by our partners at SentinolneOne, threat hunting is quite a different activity from incident response (IR). While IR methodologies aim to determine what happened after a data breach, a threat hunting team searches for attacks that have slipped through your defensive layers to help you find adversaries hiding in your network before they can execute an attack or fulfill their goals.

 

3. Work with a SIEM solution that offers automated remediation actions. A security information and event management (or SIEM) is a cybersecurity solution that collects and converges data from different parts of your IT environment with the intent of monitoring your firm’s security levels. Providing advanced visibility and insight into your users, endpoints, traffic, activity, and more, a SIEM enables you to maintain oversight into your network and beyond the perimeter as your company scales.

4. Log capture and file retention for critical infrastructure. As detailed in this whitepaper from the National Institute for Standards & Technology (NIST) nvlpubs.nist, log management is essential to ensuring that computer security records are stored in sufficient detail for an appropriate period of time. Routine log analysis is beneficial for identifying security incidents, policy violations, fraudulent activity, and operational problems. 

5. Encryption for all data. In cryptography, encryption is the process of encoding information or sensitive data so only authorized parties can access it. While encryption can’t prevent criminal activity or third-party attacks, it does deny intelligible content to the interceptor. For more on encryption, we recommend this article published by UpGuard www.upguard.com/blog/encryption.

6. Use two-factor/multi-factor authentication. With two-factor authentication enabled, criminals who do gain access to user login credentials aren’t automatically granted entry. A key element to a Zero-Trust Security framework, multi-factor authentication requires users validate their identity to provide that extra layer of security.

Above all, at OWG we believe cybersecurity will always come down to your corporate culture and your posture – on your toes, knees bent, arms ready. Stay sharp, be prepared and have your plan in place and you’ll have an advantage and typically able to weather the storm. The complacent or unprepared will get swallowed.  

 

For more information, or to set a time to speak, drop your name and email below and we’ll reach out.

 

 #StaySafeOnline‍

Always Verify

Confusion about Zero Trust is making it harder to implement

 

 

As we detailed in our business case exploring the Zero Trust, at its core, ZT is a concept and shift in how organizations approach the idea of security and data privacy.

 

It’s not one product or piece of software, rather an approach that assumes breach and secures your organization by requiring users prove they are who they say they are and be granted gated access accordingly.

As explained in a recent article from WIRED, “What is Zero Trust” the approach eliminates the old moat & castle networking model and instead of trusting particular devices and assuming what’s inside your walls are safe, a Zero Trust methodology uses verification, network segmentation and least privilege to protect the enterprise.

 

Eliminate the moat & castle model of cybersecurity

 

 

Eliminate the moat & castle model of cybersecurity

Under the old model, all the computers, servers, and other devices physically in an office building were on the same network and trusted each other. Your work computer could connect to the printer on your floor or find team documents on a shared server. Tools like firewalls and antivirus were set up to view anything outside the organization as bad;everything inside the network didn’t merit much scrutiny. 

 

However, the explosion of mobile devices, cloud services,and remote/hybrid work have radically challenged those assumptions. Organizations can’t physically control every device its employees use anymore. And even if they could, once an attacker slipped by perimeter defenses, the network would instantly grant them a lot of trust and freedom. “Outside bad, inside good.”‍

“Zero Trust is a concept, not an action.”

Ken Westin, Security Researcher

Instead of trusting particular devices or connections from certain places, Zero Trust demands that people prove they are who they claim and should therefore be granted access. Typically, that means logging into a corporate account with biometrics or a hardware security key in addition to usernames and passwords to make it harder for attackers to impersonate users. And even once someone gets through, it’s on a need-to-know or need-to-access basis. If you don’t invoice contractors as part of your job, your corporate account shouldn’t tie into the billing platform.

 

Zero Trust isn’t a single piece of software you can install or a box you can check, but a philosophy, a set of concepts, a mantra,a mindset.

 

You still must implement things like device and software inventory, network segmentation, access controls.

 

Confusion about the real meaning and purpose of Zero Trust makes it harder for people to implement the ideas in practice. Proponents are largely in agreement about the overall goals and purpose behind the phrase, but busy executives or IT admins with other things to worry about can easily be led astray and end up implementing security protections that simply reinforce old approaches rather than ushering in something new. 

 

Here at OWG, we work with our partner clients and help them engineer a true Zero Trust methodology throughout their IT ecosystem. If you have questions or would like to see if we can help your organization better protect its most critical data, email partnerwithus@overwatchgrp.com or click here to set a time to speak.i 

As organizations across the country begin to adopt the Zero Trust approach, federal agencies will do the same.

As part of a new cybersecurity strategy released Wednesday, the administration outlines its vision for moving government agencies towards a “zero trust” architecture — a cybersecurity model where users and devices are only given permissions to access network resources necessary for the task at hand and are authenticated on a case-by-case basis.

 

 

The key document was published as a memorandum from the Office of Management and Budget (OMB), the administration’s policy arm, and addressed to the heads of all executive departments and agencies.
According to the memorandum, shifting towards a zero trust architecture will require the implementation of stronger enterprise identity and access controls, including more widespread use of multi-factor authentication — specifically hardware-based authentication tokens like access cards, rather than push notifications or SMS. Agencies were also instructed to aim for a complete inventory of every device authorized and operated for official business, to be monitored according to specifications set by the Cybersecurity and Infrastructure Security Agency (CISA).
 
“In the face of increasingly sophisticated cyber threats, the Administration is taking decisive action to bolster the Federal Government’s cyber defenses,” said acting OMB director Shalanda Young in a statement. “This zero trust strategy is about ensuring the Federal Government leads by example, and it marks another key milestone in our efforts to repel attacks from those who would do the United States harm.”
The White House’s announcement cited the Log4j security vulnerability as “the latest evidence that adversaries will continue to find new opportunities to get their foot in the door.” The vulnerability, one of the most serious and widespread cybersecurity threats for years, first began to be exploited in December 2021. At the time, government agencies were instructed by CISA to immediately patch vulnerable assets or take other mitigation measures. The FTC also subsequently warned companies in the private sector to remediate the vulnerability to avoid potential legal action for putting consumers at risk.
“As our adversaries continue to pursue innovative ways to breach our infrastructure, we must continue to fundamentally transform our approach to federal cybersecurity,” said CISA director Jen Easterly. “Zero trust is a key element of this effort to modernize and strengthen our defenses. CISA will continue to provide technical support and operational expertise to agencies as we strive to achieve a shared baseline of maturity.”
An initial draft of the strategy was released in September 2021 for public comment and since then has been shaped by input from the cybersecurity industry as well as other fields of the public and private sector.
With the final strategy now released, government agencies have been issued 30 days to designate a strategy implementation lead within their organization and 60 days to submit an implementation plan to the OMB.
 

Drop your name and email to learn more, or tag my calendar to setup a conversation.

 

 

Portions of this article were originally published by The Verge and is available at https://www.theverge.com/2022/1/26/22902630/white-house-instructs-agencies-cybersecurity-strategy-memo-cisa