SlideShare une entreprise Scribd logo
1  sur  30
Télécharger pour lire hors ligne
Cyber Security
&
Office365
Security Best Practices &
Office 365
Intro & About David
 Professionally Supporting Small and Medium Businesses
Succeed for over 20 years!
 Microsoft Certified Office 365 Specialist
 Skilled to plan, migrate, deploy, and manage
Microsoft 365 services for the Enterprise
 Skilled in Identity, Security & Compliance management and
supporting technologies.
 >15 years working with financial clients
Office: 03 9005 4686 | david@solvebusiness.com.au
https://solvebusiness.com.au
Housekeeping
 Thanks for attending
 Thankyou Ian Chait for the Opportunity to speak here.
 I will try to make this as interesting as I can
 Raise your hands, ask questions, it will be more interesting
that way
 At the end I will give you a way to get some extra info.
War Stories
 Who’s been hacked or seen a hack ?
 Let’s share our experiences
Security
Overview
Let’s take a 10 min high level look at
the Security Landscape
from your point of view
Targets
Threats
Actions
Targets
 Bookkeepers, YOU ARE a Target
 Your responsibility to yourself and your clients
 You are gatekeeper of your Clients’ Data
 Your Identity has Value!
 Time to invest in yourself, seek to improve skills
(or buy these in)
Threats
 The commercialisation of Threats…
 Business Email Compromise
 Phishing / Dodgy Emails
 Banking Detail Change
 Crypto or Ransomware
 Bad Actor’s…
 Target identity
 you won’t know
 sit in a system undetected
Recent News – Aug 13, 2019
https://www.mybusiness.com.au/finance/6092-50-000-loss-as-hacker-takes-control-of-invoicing
“One business recently lost over $50,000 as a result of a
hacker taking control of the email of the person responsible
for invoicing who was on maternity leave. The hacker then
used this access to re-issue unpaid invoices with different
account payment details”
“By the time everyone realised what had happened, the new
account had been wiped clean and shut down.”
“Hackers are no longer the typical hooded criminal in a
basement with a binary code on the screen — we are now
under threat by large-scale criminal organisations located all
around the world.”
Recent Phishing Email Success
Google and Facebook lose >$100M
Tom Huddleston Jr., 12:34 PM ET Wed, 27 March 2019
https://www.cnbc.com/amp/2019/03/27/phishing-email-scam-stole-100-million-from-facebook-and-
google.html?fbclid=IwAR0b5vY_w5FZzPXl9WgAWc4PaWYLa3_cPWiK4u_prvlfRehM_RxZbb1sVZ4
Action: Notifiable Data Breach
 What is a Notifiable Data
Breach
 Why you must do
 Your Responsibilities
 Identify
 Protect
 Manage
 Report
 Office 365 DLP
A data breach happens when personal
information is accessed or disclosed without
authorisation or is lost.
If the Privacy Act 1988 covers your
organisation or agency, you must notify
affected individuals and us when a data
breach involving personal information is
likely to result in serious harm.
https://www.oaic.gov.au/privacy/notifiable-data-breaches/
Story: Marriot Hotel breach – 2018
 Marriott knowledge September 8
 monitoring system detected an anomaly a day earlier
 In November realised they were compromised earlier
 In JULY 2014 !
 Approximate impacts:
 5.25 million guests’ unencrypted passport numbers
 20.3 million encrypted passport numbers
 8.6 million encrypted credit or debit card numbers
 More Info: https://news.marriott.com/2019/01/marriott-provides-update-on-starwood-database-security-incident/
Security Dilemma
 Security done right is a process, know there will
be impact
 Some Impact is GOOD
 means security is working
Secure
CheapUsable
Action: Being Secure, Where to Start
 Our Systems & behaviour, it starts with us
 Windows Editions – they matter!
 Think Securely
 Know our business processes
Normal
Process
Order
Photo by Oscar Sutton on Unsplash
Office 365 &
Productivity
Office 365 is about more than
desktop apps, it’s an integrated
platform with applications and
systems
it all should be protected by at least
2FA at a minimum.
OneDrive
SharePoint
Teams
OneNote
Forms
Bookings
Office 365 File Storage
 Traditional Concepts
OneDrive = My Stuff
Your personal files
Your Early Drafts before you share
Teams = My Teams Stuff
Smaller Groups of People
Files and Tabs in Teams
SharePoint = Everyone’s Stuff
Published work
Intranet Sites
Office 365 File Storage
- Common Features
 Version History
 Co-Authoring
 External Sharing
 Mobile Access
 Drag and Drop
 Sync (offline access)
Simply save your data to Office 365 to get all these benefits…
OneDrive
 Your File Area
 At least 1TB
 Does everything Dropbox and others do
 Files On Demand
 Known Folder Move (backup for your PC)
SharePoint
MORE
COMPLEX
THAN
ONEDRIVE
NORMALLY USED
BY LARGER
ORGANISATIONS
CUSTOMISABLE SPECIALISED
DISCUSS
OFFLINE
Teams
Available in Most
Business Office
Plans
Collaborative
workspace
Customisable
OneNote
 Access Anywhere, any device
 Searchable
 Shareable
 Embed and Edit Files
 Immersive Reader
 Easy, Familiar
Forms
 Easily create Surveys and polls
 collect customer feedback, measure employee
satisfaction, organize team events etc
 Shareable internally and externally
 Results collected in Excel
 Supports Branding and Branching
 GDPR Compliant Security
Bookings
 Allow your customers to book appointments direct
 Only shows available time (knows your calendar)
 Advanced Rules to Keep Control
 Automated Client follow-ups and reminders
Security Best
Practices
Let’s discuss SECURITY and what to
look out for and tools that can help
you.
Lets also look at how use of these
increases your value to your
customers
Encrypt
2FA
Password Tools
Strong Passwords
Get Trained
Encrypt Sensitive Data
 Bitlocker
 iPhone and Android devices
 Use a PIN or Biometric
 USB Sticks
 limit use
 Encrypt where possible
 Be cautious
 Lost n Found (never use)
Office 365 2FA
 Office 365 2FA
 Enable for ALL Users, no exceptions
 TXT or Microsoft Authenticator App (Preferred)
 Fraud Alert where license permits
Password Management
 Lastpass
 Authenticators from Microsoft, Google, Authy
 Others
 1Password, Dashlane, Keeper
Backup
 Still Critical
 Even in the Cloud
 Automated
 Reduced Reliance on Humans
Strong
Passwords
 Must be unique across sites
 Complexity
 Not Social Related
 Not your name
 P@ssW0rd1 is not secure
 Not your dog’s name
(save renaming your dog!)
Photo by Oscar Sutton on Unsplash
Get Trained
 Greater Skills means
 > Proficiency
 >Professional, >Trustworthy
 Save time, > profit
 Better training lowers risks
 UK Girl Guides do Cyber Security Badges
Q&A
Your questions answered
Our Promise to you
Anyone at this ICB meeting can reach out for a one on one personal discussion about their
technology and security. If we can help with Security and Office 365 then we’ll work out a
next step and meet up.
Please pass a business card or email address and we’ll send you a Resource Data Sheet
that you can use for a self check and reminder and a booking link to grab some one on
one time.
You can share the resource sheet you anyone you please.
Professional Microsoft Office 365 Management and Office IT Management is what we do
and we can tailor a bundle for you to include things such as the correct Office 365
licenses, Professional Management and backup, it just depends what’s required.
How can we help you ?

Contenu connexe

Tendances

UAE Microsoft MVPs - How To become Microsoft MVP
UAE Microsoft MVPs - How To become Microsoft MVPUAE Microsoft MVPs - How To become Microsoft MVP
UAE Microsoft MVPs - How To become Microsoft MVP
Ammar Hasayen
 

Tendances (15)

Azure Cloud Security
Azure Cloud SecurityAzure Cloud Security
Azure Cloud Security
 
The Emerge Of The Modern Workplace
The Emerge Of The Modern WorkplaceThe Emerge Of The Modern Workplace
The Emerge Of The Modern Workplace
 
Getting More Out Of Microsoft 365: From The Microsoft Graph To Workplace Anal...
Getting More Out Of Microsoft 365: From The Microsoft Graph To Workplace Anal...Getting More Out Of Microsoft 365: From The Microsoft Graph To Workplace Anal...
Getting More Out Of Microsoft 365: From The Microsoft Graph To Workplace Anal...
 
Why Metadata Matters in SharePoint Search and Information Governance Webinar
Why Metadata Matters in SharePoint Search and Information Governance WebinarWhy Metadata Matters in SharePoint Search and Information Governance Webinar
Why Metadata Matters in SharePoint Search and Information Governance Webinar
 
Microsoft 365 Threat Management and security - EMS E5
Microsoft 365 Threat Management and security - EMS E5Microsoft 365 Threat Management and security - EMS E5
Microsoft 365 Threat Management and security - EMS E5
 
Webinar Q&A Featuring Panelists from Office 365 and X1
Webinar Q&A Featuring Panelists from Office 365 and X1Webinar Q&A Featuring Panelists from Office 365 and X1
Webinar Q&A Featuring Panelists from Office 365 and X1
 
10 Worst Practices for SharePoint intranets
10 Worst Practices for SharePoint intranets10 Worst Practices for SharePoint intranets
10 Worst Practices for SharePoint intranets
 
Office 365 - Communication Square LLC
Office 365 - Communication Square LLCOffice 365 - Communication Square LLC
Office 365 - Communication Square LLC
 
Securing your Organization with Microsoft 365
Securing your Organization with Microsoft 365Securing your Organization with Microsoft 365
Securing your Organization with Microsoft 365
 
What is Microsoft 365 Business?
What is Microsoft 365 Business?What is Microsoft 365 Business?
What is Microsoft 365 Business?
 
UAE Microsoft MVPs - How To become Microsoft MVP
UAE Microsoft MVPs - How To become Microsoft MVPUAE Microsoft MVPs - How To become Microsoft MVP
UAE Microsoft MVPs - How To become Microsoft MVP
 
Concurrency Modern Workplace 2017
Concurrency Modern Workplace 2017Concurrency Modern Workplace 2017
Concurrency Modern Workplace 2017
 
June 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know WebinarJune 2020 Microsoft 365 Need to Know Webinar
June 2020 Microsoft 365 Need to Know Webinar
 
Modern Workplace - Shift to Cloud
Modern Workplace - Shift to CloudModern Workplace - Shift to Cloud
Modern Workplace - Shift to Cloud
 
Data Loss Prevention in O365
Data Loss Prevention in O365Data Loss Prevention in O365
Data Loss Prevention in O365
 

Similaire à ICB Security and Office 365

Myths about moving to the _Final
Myths about moving to the _FinalMyths about moving to the _Final
Myths about moving to the _Final
Laura Winkenbach
 
SharePoint_IRMS_Conference.pdf
SharePoint_IRMS_Conference.pdfSharePoint_IRMS_Conference.pdf
SharePoint_IRMS_Conference.pdf
ssusera76ea9
 

Similaire à ICB Security and Office 365 (20)

Office 365 smb guidelines for pure bookkeeping (slideshare)
Office 365 smb guidelines for pure bookkeeping (slideshare)Office 365 smb guidelines for pure bookkeeping (slideshare)
Office 365 smb guidelines for pure bookkeeping (slideshare)
 
Original
OriginalOriginal
Original
 
Microsoft Teams in the Modern Workplace
Microsoft Teams in the Modern WorkplaceMicrosoft Teams in the Modern Workplace
Microsoft Teams in the Modern Workplace
 
Microsoft 365 | Modern workplace
Microsoft 365 | Modern workplaceMicrosoft 365 | Modern workplace
Microsoft 365 | Modern workplace
 
Office 365 Security - Its 2am do you know whos in your office 365
Office 365 Security - Its 2am do you know whos in your office 365Office 365 Security - Its 2am do you know whos in your office 365
Office 365 Security - Its 2am do you know whos in your office 365
 
SPC18 - Getting Started with Office 365 Advanced Threat Protection for ShareP...
SPC18 - Getting Started with Office 365 Advanced Threat Protection for ShareP...SPC18 - Getting Started with Office 365 Advanced Threat Protection for ShareP...
SPC18 - Getting Started with Office 365 Advanced Threat Protection for ShareP...
 
Novaquantum advanced security for Microsoft 365
Novaquantum advanced security for Microsoft 365Novaquantum advanced security for Microsoft 365
Novaquantum advanced security for Microsoft 365
 
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss PreventionaMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
aMS SouthEast Asia 2021 - Microsoft 365 Data Loss Prevention
 
Coaching in the Cloud
Coaching in the CloudCoaching in the Cloud
Coaching in the Cloud
 
365 Degrees: Looking at Office 365, SharePoint, and Dynamics 365 by Steve Reid
365 Degrees: Looking at Office 365, SharePoint, and Dynamics 365 by Steve Reid365 Degrees: Looking at Office 365, SharePoint, and Dynamics 365 by Steve Reid
365 Degrees: Looking at Office 365, SharePoint, and Dynamics 365 by Steve Reid
 
Myths about moving to the _Final
Myths about moving to the _FinalMyths about moving to the _Final
Myths about moving to the _Final
 
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
Rencore Webinar: Understanding EU GDPR from an Office 365 perspective with Pa...
 
May 2018 Office 365 Need to Know Webinar
May 2018 Office 365 Need to Know WebinarMay 2018 Office 365 Need to Know Webinar
May 2018 Office 365 Need to Know Webinar
 
Microsoft 365 business
Microsoft 365 businessMicrosoft 365 business
Microsoft 365 business
 
ConnXus myCBC Webinar Series: Cybersecurity Risks to Your Business
ConnXus myCBC Webinar Series: Cybersecurity Risks to Your BusinessConnXus myCBC Webinar Series: Cybersecurity Risks to Your Business
ConnXus myCBC Webinar Series: Cybersecurity Risks to Your Business
 
SharePoint_IRMS_Conference.pdf
SharePoint_IRMS_Conference.pdfSharePoint_IRMS_Conference.pdf
SharePoint_IRMS_Conference.pdf
 
Prevención de la pérdida de datos (DLP) con O365
Prevención de la pérdida de datos (DLP) con O365Prevención de la pérdida de datos (DLP) con O365
Prevención de la pérdida de datos (DLP) con O365
 
Microsoft 365 Business Overview
Microsoft 365 Business OverviewMicrosoft 365 Business Overview
Microsoft 365 Business Overview
 
Getting started with Microsoft Office 365 by Vignesh Ganesan
Getting started with Microsoft Office 365 by Vignesh GanesanGetting started with Microsoft Office 365 by Vignesh Ganesan
Getting started with Microsoft Office 365 by Vignesh Ganesan
 
Pitching Microsoft 365
Pitching Microsoft 365Pitching Microsoft 365
Pitching Microsoft 365
 

Dernier

Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
dollysharma2066
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 

Dernier (20)

Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Majnu Ka Tilla, Delhi Contact Us 8377877756
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 

ICB Security and Office 365

  • 2. Intro & About David  Professionally Supporting Small and Medium Businesses Succeed for over 20 years!  Microsoft Certified Office 365 Specialist  Skilled to plan, migrate, deploy, and manage Microsoft 365 services for the Enterprise  Skilled in Identity, Security & Compliance management and supporting technologies.  >15 years working with financial clients Office: 03 9005 4686 | david@solvebusiness.com.au https://solvebusiness.com.au
  • 3. Housekeeping  Thanks for attending  Thankyou Ian Chait for the Opportunity to speak here.  I will try to make this as interesting as I can  Raise your hands, ask questions, it will be more interesting that way  At the end I will give you a way to get some extra info.
  • 4. War Stories  Who’s been hacked or seen a hack ?  Let’s share our experiences
  • 5. Security Overview Let’s take a 10 min high level look at the Security Landscape from your point of view Targets Threats Actions
  • 6. Targets  Bookkeepers, YOU ARE a Target  Your responsibility to yourself and your clients  You are gatekeeper of your Clients’ Data  Your Identity has Value!  Time to invest in yourself, seek to improve skills (or buy these in)
  • 7. Threats  The commercialisation of Threats…  Business Email Compromise  Phishing / Dodgy Emails  Banking Detail Change  Crypto or Ransomware  Bad Actor’s…  Target identity  you won’t know  sit in a system undetected
  • 8. Recent News – Aug 13, 2019 https://www.mybusiness.com.au/finance/6092-50-000-loss-as-hacker-takes-control-of-invoicing “One business recently lost over $50,000 as a result of a hacker taking control of the email of the person responsible for invoicing who was on maternity leave. The hacker then used this access to re-issue unpaid invoices with different account payment details” “By the time everyone realised what had happened, the new account had been wiped clean and shut down.” “Hackers are no longer the typical hooded criminal in a basement with a binary code on the screen — we are now under threat by large-scale criminal organisations located all around the world.”
  • 9. Recent Phishing Email Success Google and Facebook lose >$100M Tom Huddleston Jr., 12:34 PM ET Wed, 27 March 2019 https://www.cnbc.com/amp/2019/03/27/phishing-email-scam-stole-100-million-from-facebook-and- google.html?fbclid=IwAR0b5vY_w5FZzPXl9WgAWc4PaWYLa3_cPWiK4u_prvlfRehM_RxZbb1sVZ4
  • 10. Action: Notifiable Data Breach  What is a Notifiable Data Breach  Why you must do  Your Responsibilities  Identify  Protect  Manage  Report  Office 365 DLP A data breach happens when personal information is accessed or disclosed without authorisation or is lost. If the Privacy Act 1988 covers your organisation or agency, you must notify affected individuals and us when a data breach involving personal information is likely to result in serious harm. https://www.oaic.gov.au/privacy/notifiable-data-breaches/
  • 11. Story: Marriot Hotel breach – 2018  Marriott knowledge September 8  monitoring system detected an anomaly a day earlier  In November realised they were compromised earlier  In JULY 2014 !  Approximate impacts:  5.25 million guests’ unencrypted passport numbers  20.3 million encrypted passport numbers  8.6 million encrypted credit or debit card numbers  More Info: https://news.marriott.com/2019/01/marriott-provides-update-on-starwood-database-security-incident/
  • 12. Security Dilemma  Security done right is a process, know there will be impact  Some Impact is GOOD  means security is working Secure CheapUsable
  • 13. Action: Being Secure, Where to Start  Our Systems & behaviour, it starts with us  Windows Editions – they matter!  Think Securely  Know our business processes Normal Process Order Photo by Oscar Sutton on Unsplash
  • 14. Office 365 & Productivity Office 365 is about more than desktop apps, it’s an integrated platform with applications and systems it all should be protected by at least 2FA at a minimum. OneDrive SharePoint Teams OneNote Forms Bookings
  • 15. Office 365 File Storage  Traditional Concepts OneDrive = My Stuff Your personal files Your Early Drafts before you share Teams = My Teams Stuff Smaller Groups of People Files and Tabs in Teams SharePoint = Everyone’s Stuff Published work Intranet Sites
  • 16. Office 365 File Storage - Common Features  Version History  Co-Authoring  External Sharing  Mobile Access  Drag and Drop  Sync (offline access) Simply save your data to Office 365 to get all these benefits…
  • 17. OneDrive  Your File Area  At least 1TB  Does everything Dropbox and others do  Files On Demand  Known Folder Move (backup for your PC)
  • 19. Teams Available in Most Business Office Plans Collaborative workspace Customisable
  • 20. OneNote  Access Anywhere, any device  Searchable  Shareable  Embed and Edit Files  Immersive Reader  Easy, Familiar
  • 21. Forms  Easily create Surveys and polls  collect customer feedback, measure employee satisfaction, organize team events etc  Shareable internally and externally  Results collected in Excel  Supports Branding and Branching  GDPR Compliant Security
  • 22. Bookings  Allow your customers to book appointments direct  Only shows available time (knows your calendar)  Advanced Rules to Keep Control  Automated Client follow-ups and reminders
  • 23. Security Best Practices Let’s discuss SECURITY and what to look out for and tools that can help you. Lets also look at how use of these increases your value to your customers Encrypt 2FA Password Tools Strong Passwords Get Trained
  • 24. Encrypt Sensitive Data  Bitlocker  iPhone and Android devices  Use a PIN or Biometric  USB Sticks  limit use  Encrypt where possible  Be cautious  Lost n Found (never use)
  • 25. Office 365 2FA  Office 365 2FA  Enable for ALL Users, no exceptions  TXT or Microsoft Authenticator App (Preferred)  Fraud Alert where license permits
  • 26. Password Management  Lastpass  Authenticators from Microsoft, Google, Authy  Others  1Password, Dashlane, Keeper
  • 27. Backup  Still Critical  Even in the Cloud  Automated  Reduced Reliance on Humans
  • 28. Strong Passwords  Must be unique across sites  Complexity  Not Social Related  Not your name  P@ssW0rd1 is not secure  Not your dog’s name (save renaming your dog!) Photo by Oscar Sutton on Unsplash
  • 29. Get Trained  Greater Skills means  > Proficiency  >Professional, >Trustworthy  Save time, > profit  Better training lowers risks  UK Girl Guides do Cyber Security Badges
  • 30. Q&A Your questions answered Our Promise to you Anyone at this ICB meeting can reach out for a one on one personal discussion about their technology and security. If we can help with Security and Office 365 then we’ll work out a next step and meet up. Please pass a business card or email address and we’ll send you a Resource Data Sheet that you can use for a self check and reminder and a booking link to grab some one on one time. You can share the resource sheet you anyone you please. Professional Microsoft Office 365 Management and Office IT Management is what we do and we can tailor a bundle for you to include things such as the correct Office 365 licenses, Professional Management and backup, it just depends what’s required. How can we help you ?