Tag: CDSPI

  • ‘Pay up or else!’: The rise of ransomware

    ‘Pay up or else!’: The rise of ransomware

    Ransomware is malicious software that is designed to block access to computer files, folders, or a whole system. It typically encrypts the victim’s data, rendering it inaccessible, and then displays a message demanding payment, often in cryptocurrency, in exchange for a decryption key that will release the data.

    Ransomware can infiltrate systems through phishing emails, software vulnerabilities, or downloads from malicious websites. All it takes is one wrong click and ransomware can be deployed to wreak havoc on individuals, businesses, and organizations of all sizes, causing significant disruption to operations, compromising sensitive data, and inflicting financial losses.

    Sixty per cent of small to medium enterprises that experience a cyber attack and do not have cyber insurance will fail within six months.1

    cybersecurityventures.com

    ‘We don’t negotiate with terrorists’

    While widely attributed to U.S. President Richard Nixon, the principle of “We do not negotiate with terrorists” has been ingrained in political rhetoric for decades. After falling prey to a ransomware attack, most organizations are faced with the decision of whether or not to pay the ransom demand. Ultimately, the decision to pay is with the insurer (if you have cyber insurance), but most insurers will take into consideration the wishes of the policyholder.

    Paying the ransom doesn’t necessarily mean an organization will regain access to its encrypted data. This is often because the decryption utilities provided by those responsible for the attack simply don’t work. Remember: These are criminals, and there’s nothing that says they must satisfy their end of the agreement after receiving payment. This goes not only for handing over a functional ransomware decryption key, but for deleting any stolen data, too.

    The rising popularity of cryptocurrencies has further enabled cybercriminals and helped them evade law enforcement. Ransom payments in cryptocurrency are difficult to trace and can be easily converted into cash.

    In a recently published report titled, “Ransomware: The True Cost to Business,” nearly half of respondents (46 per cent) who fulfilled their attackers’ demands regained access to their data following payment only to find that some if not all their data was corrupted. Just 51 per cent said they successfully recovered all their data after paying, with three per cent admitting they didn’t get any of their data back after payment.2

    Despite these statistics, negotiations with ransomware terrorists do occur. During a recent CDSPI webinar, Douglas Fast, Vice-President and Client Executive at BFL Canada, recounted a scenario involving a client dealing with a ransomware attack. Hackers demanded $400,000 for the release of data, which included sensitive client files.

    “The Beazley breach response team wasted no time,” he said. “Within hours, a team of experts, including forensics specialists, legal advisors, privacy experts, and negotiators, was mobilized to manage the situation. Through strategic negotiations, they managed to significantly reduce the ransom to $185,000. Ultimately, the insurer covered the ransom amount, recovered the data, and effectively resolved the crisis.”3

    Ransom demands vary widely depending on the attacker’s sophistication and their perception of how much their target can afford to pay — varying from thousands to tens of millions of dollars. However, Nicholas Hickey of Beazley Insurance cautions, “As a dentist and businessperson, you’re not expected to, nor should you, know the intricacies of negotiating with criminals. That’s why we have professional negotiators on staff as part of the Breach Response Team.”4

    Ransomware demands on the rise

    Ransomware attacks have surged by 25 per cent, and that number keeps rising, according to a recent report. By some estimates, however, the ransom payment only accounts for a small portion — often as little as 15 per cent — of the overall costs associated with the attack. The cost of downtime (an average of 22 days to fully resume operations)5 and recovery of lost data after a ransomware attack often exceeds the actual ransom.

    Beyond the immediate damage caused by a breach, the reputational damage can be catastrophic in terms of how customers perceive a brand’s commitment to data security. This loss of trust can lead to long-term reputational damage, loss of customers/patients, and potential legal and regulatory repercussions, all of which can far outweigh the initial cost of the ransom.

    Strategies to prevent ransomware attacks

    Ransomware is an evolving threat, and small businesses should take proactive measures to protect against financial loss.

    “The fundamental operations of your practice are almost completely digital,” says Phil Fodchuk, National Leader, Cyber Security at MNP Digital. “Without a well-functioning computer system, you’d likely completely shut down.” 

    With this constantly evolving threat, Fodchuk urges clients to think about their practice’s cyber security needs the same way they think about recommending regular check-ups.

    “It’s part of an overall approach to prevention that ensures measures can be taken as early as possible if needed to prevent negative outcomes,”6 he says.

    The five-step process to protect your business:7

    Take time to put a plan in place so you’re not left scrambling.

    Is cyber insurance worth it?

    Cyber insurance is a critical tool necessary to protect yourself and your practice from cybercrime, but it can’t be your entire strategy. Your best approach is to build strong defenses against attacks, regardless of whether or not you’re insured. A ransomware attack can happen any time, to any organization. Immediately upon discovering your systems have been compromised, contact your cyber insurance provider. A breach response team will be deployed to provide support and counsel to aid in the resumption of business operations.

    References

    1 60 percent of small companies close within six months of being hacked (cybersecurityventures.com)
    2 Freed, Anthony M. Three reasons why you should never pay ransomware attackers. Cyberreason.com
    3 CDSPI webinar. March 2024.
    4 Ibid
    5 The cost of ransomware: Why every business pays, one way or another. March 2023.
    6 Fodchuk, Phil. How to effectively protect your practice from cyber security threats. MNP Digital. December 2023.
    7 Cyber security basics for dentists. Presentation by MNP Digital. February 2024.

  • Cyber hygiene: Protecting dental practices in the digital age

    Cyber hygiene: Protecting dental practices in the digital age

    Contributed by CDSPI

    In busy dental practices, where the whirl of drills, the hum of suction, and the murmur of voices fill the air, an unexpected concern has emerged: cyber hygiene.

    While it may seem odd to link dental care to the care of digital assets, it is a vital connection to make in today’s world. Just as you emphasize the importance of brushing, flossing, and regular check-ups to maintain oral health, so, too, must you prioritize the fundamentals of cyber hygiene to safeguard digital operations.

    In essence, cyber hygiene is about cultivating a structured and intelligent environment that mitigates the risks of external threats without requiring constant IT intervention. It’s akin to preventive care in dentistry — taking proactive measures to ward off potential issues before they escalate into serious problems. By adhering to cyber hygiene best practices, dental offices can not only protect sensitive patient data, but also ensure smooth operations without the constant fear of cyber attacks looming overhead.

    Cyber hygiene is foundational to both cybersecurity and cyber resilience. While cybersecurity guards against threats, cyber resilience improves an organization’s ability to recover and resume normal operations after a security breach. Cyber resilience strategies involve cybersecurity, incident response, business continuity, and disaster recovery.

    So, what are these best practices dental offices should be adopting?

    1. Implement automated backup systems

    First and foremost, dental practices must prioritize the implementation of robust automated backup systems. No longer is manual backup sufficient in the age of sophisticated cyber threats. By leveraging automated backup solutions, such as reputable cloud services, practices can ensure that vital information remains protected even in the event of a breach or system failure. This not only safeguards patient records and sensitive data but also frees up valuable time for dental staff to focus on patient care.

    2. Embrace risk management

    In the ever-evolving landscape of cyber threats, risk management is paramount. Dental practices must anticipate potential vulnerabilities and have strategies in place to mitigate them effectively. From identifying potential points of entry for cyber attackers to developing response plans in the event of a breach, proactive risk management can significantly bolster the resilience of a practice’s digital infrastructure.

    3. Control access

    Access control is another crucial aspect of cyber hygiene. Dental practices must invest in tools and services that automate authentication processes and monitor access to sensitive information. By enforcing strict access controls, practices can minimize the risk of unauthorized access and swiftly identify any anomalies or suspicious activity within their systems.

    The granting of administrative privileges should be approached with caution and diligence. Practices must implement processes to assess the necessity of such privileges, determine their validity period, and enforce multiple authentication factors for added security.

    Moreover, it’s essential to have mechanisms in place to revoke privileges promptly when they are no longer needed, ensuring access remains tightly controlled at all times. One common example is when temporary reception staff are brought in to the practice. Allowing these individuals limited access is necessary so they can perform their role, but imposing limits to what they can access and revoking privileges when they leave is critical for maintaining the integrity of the practice’s digital security.

    By carefully managing administrative privileges, dental practices can minimize the risk of unauthorized access and potential breaches of sensitive information. This approach not only protects patient confidentiality, but also preserves the trust and reputation of the practice. In an era where data breaches and cyber threats loom large, proactive measures such as these are essential for safeguarding the digital assets of dental practices and ensuring the continued delivery of quality care to patients.

    4. Train employees

    Individuals play a crucial role in maintaining the security of the practice’s digital assets. Encourage employees to create strong, complex passwords and consider utilizing password management tools to securely store and manage credentials. Simplistic or recycled passwords are practically an open invitation to malicious hackers. Create a company password policy to protect enterprise security by establishing rules, requirements, and expectations around user credentials.

    Emphasize the importance of regularly updating passwords and avoiding the reuse of passwords across multiple accounts to minimize the risk of credential compromise.

    5. Use MFA

    Multi-factor authentication (MFA) has become an industry standard in cyber hygiene and is required to qualify for cyber insurance. MFA requires two or more authentication factors, such as a password and a one-time code sent to the user’s mobile device or email address. Rather than just asking for a username and password, MFA requires one or more additional verification factors, which decreases the likelihood of a successful cyber attack.

    6. Update software

    Having the latest security software, web browser, and operating system are the best defenses against viruses, malware, and other online threats.

    As companies increasingly digitize their businesses and automate operations, unpatched or end-of-life software present significant cybersecurity threats. A recent survey revealed that 60% of breach victims said their breach’s cause was an unpatched known vulnerability. Once considered optional, software patching has become vital due to the increasing frequency and costs of cyber incidents that result from these exposures. The good news is that once vulnerabilities are known, patches are routinely made available quickly.

    7. Email security

    Educate employees about the dangers of phishing attacks and the importance of exercising caution when opening emails from unfamiliar or suspicious sources. Likewise, warn against downloading software or files from untrusted sources, as these can often harbour malware or other malicious threats.

    Remember: Good cyber hygiene isn’t a set-it-and-forget-it proposition. Rather, it encompasses an array of habits, practices, and initiatives on the part of organizations and their users, with the goal of achieving and maintaining the healthiest possible security posture.

    Bottom line

    Regardless of the preventative measures you take, a determined cyber criminal may one day access your systems. This is why it is crucial to have cyber insurance in place.

    Cyber attacks and breaches are increasing, becoming more costly and damaging. CDSPI is in the business of protecting dentists and their practices and have addressed this need by introducing CDSPI Cyber Insurance. Cyber insurance can help your business financially recover if devices or documents are lost or stolen, or if computer networks are breached, leading to information being stolen or ransomed, business operations interrupted, or computer systems corrupted. Visit cdspi.com/insurance/cyber to learn more.

    While insurance can defray many costs of a security breach, only tight security and good cyber protection practices can protect your practice from attack. In essence, cyber hygiene is the cornerstone of digital security for dental practices in today’s interconnected world. Just as proper oral hygiene is essential for maintaining a healthy smile, so, too, is diligent cyber hygiene crucial for safeguarding sensitive patient data and preserving the integrity of dental operations. By implementing robust security measures, prioritizing risk management, promoting cyber awareness among staff, and protecting yourself with cyber insurance, dental practices can ensure their digital infrastructure remains resilient in the face of evolving cyber threats. After all, in the world of dentistry, prevention is always better than cure — and the same holds true for cyber hygiene.

    The information provided in this article is for general informational purposes only and is not intended to replace or serve as substitute for any professional advice. Consult with a professional advisor for advice concerning matters specific to your situation before making any decisions.

    Best practices for your practice

    1. Back up your data
    2. Have a risk management strategy. Know your legal requirements and obligations
    3. Grant limited access rights
    4. Provide training to employees
    5. User multi-factor authentication
    6. Use security software and update /patch regularly
    7. Implement email security
    8. Protect your practice with CDSPI Cyber Insurance

    The CDSPI Cyber Insurance program is exclusively distributed by BFL CANADA Risk and Insurance Services, Inc., and underwritten by Beazley Canada Limited. The CDSPI Cyber Insurance Program is not available to residents of Québec.

  • Following financial advice on social media and what to watch out for

    Following financial advice on social media and what to watch out for

    Some people aren’t taught about personal finance at home or school and can struggle with investing their money, managing debt, or budgeting their monthly income. This is one reason some turn to social media to learn how to manage their money.

    Know the landscape

    As of April 2022, 4.7 billion (or 59%) of the world’s population were social media users.1 Apart from the usual suspects offering political commentary, humour, and celebrity gossip, the social media landscape also includes a subset of users known as ‘influencers.’ These users have the ability to influence potential buyers of a product or service by promoting the items through their social media channels. Usually, their sphere of influence increases by the number of followers they have. Influencers make money primarily from partnerships with the brands whose products they promote, but there is a growing movement towards full transparency after media reports of influencers being fined and receiving payments they did not disclose.2

    Facebook, Twitter, TikTok, Instagram, YouTube, Snapchat, Reddit, and LinkedIn are all vehicles that contain popular personal finance, investing, and entrepreneurship content shared by influencers.

    Often, financial influencers produce educational content that is presented in an entertaining way and gets them noticed on a worldwide platform. In fact, the new term ‘finfluencers’ — or financial influencers — is being used for those who focus just on financial matters. However, be cautious of the fact that these influencers may not be licensed financial professionals. Free advice, tips, and strategies are great ways to dip your toe into learning a bit more about finance. At a minimum, ‘finfluencers’ can help you know what questions to ask a financial advisor.

    What to watch out for

    When scrolling through social media, remember the rule of thumb “take it with a grain of salt” and proceed with a healthy dose of skepticism. Watch out for get-rich-quick scams and promises that are too good to be true. Cryptocurrencies have boomed (and plummeted) in recent times so they tend to generate a lot of online chatter — but is this an investment that fits with your risk tolerance? Simply put, risk tolerance is the level of risk an investor is willing to take. Risk can mean opportunity, but it is also about tolerating the potential for losses, the ability to withstand market swings, and the inability to predict what’s ahead. Online investors need to be aware of the added risk of criminals pretending to be reputable advisors and subsequently stealing personal/banking information.

    The bottom line

    Influencers cast a large net on social media as a means of gaining followers; however, they don’t know a client’s individual situation and aren’t necessarily able to recommend what fits for each follower.

    Also, be wary of not knowing what credentials, if any, a financial influencer has. They are not subject to the same regulations and educational requirements as licensed financial professionals. Additionally, there is no legal requirement that social media users disclose any conflicts of interest or compensation they may receive for making recommendations.

    That said, following these financial influencers can be a first step in learning more about managing your finances and your money. There’s almost certainly a personal finance niche on any platform that can pique your interest. Remember, though: Your circumstances, experiences, and situation are likely significantly different from the individual to whom the mass-produced financial advice is oriented towards.

    When it comes to trusting someone with your money, your future, and your privacy, CDSPI has been a trusted partner to dentists and the dental community for more than 60 years. Our advisors are CERTIFIED FINANCIAL PLANNER® professionals with a strong understanding of many of the financial challenges of running a successful dental practice with the expertise that can help you achieve your financial goals.

    References

    1 Internet and social media users in the world 2022 | Statista

    2 SEC.gov | Two Celebrities Charged with Unlawfully Touting Coin Offerings