
Half a year down and finally some good weather ! Roll on July.
Here’s a roundup of tips, tricks and articles that may be of interest.
Disaster Recover Month
Following on from last month’s focus on why Business Continuity services are important, July will see Alchemy focus on the area of Disaster Recover, and how it differs.
Please see follow us on LinkedIn for more content – HERE.
Azure & Amazon Cloud Services
As you are aware we operate our own Hosting platform, which is used for a multitude of services we provide. We are naturally aware ‘other’ providers are sometimes used within the Client environment – Azure and AWS being the big two – but often on more of an ad-hoc basis we have noticed, without full oversight or knowledge of the permutations.
If you would like us to manage these for you, we can migrate them to our own AWS or Azure tenants, so that we can overlay some financial and operational controls. This way you maintain the quality of your instance without affecting operations but add support & quality of service structures, to ensure the right services are delivered at the right costs.
Just ask…
What is the MITRE ATT&CK framework ?
Cyber Security is a big thing at the moment and will most likely continue to be for the next few years. You may have heard the phrase “Mitre Attack” mentioned, but not understood what it relates to.
The “Mitre ATT&CK framework” is a detailed knowledge base of the tactics cybercriminals use to target victims. Using real-world examples, it shows you how hackers prepare, launch, and execute attacks.
The framework matrix is split into tactics and techniques. A tactic is a goal the cybercriminal wants to achieve, such as accessing credentials. A technique is the action or actions that achieve the tactical goal, such as brute force.
Firstly ATT&CK stands for adversarial tactics, techniques, and common knowledge.
The framework covers 14 tactics:
- Reconnaissance – finding information to plan an attack
- Resource development – building resources to support operations
- Initial access – entering a network
- Execution – running malicious code
- Persistence – maintaining network access
- Privilege escalation – gaining advanced access permissions
- Defence evasion – avoiding detection
- Credential access – stealing account information
- Discovery – gathering system and network intelligence
- Lateral movement – controlling remote systems
- Collection – gathering relevant, goal-related information
- Command and control – communicating with systems without detection
- Exfiltration – stealing network data gathered at the collection stage
- Impact – disrupting service availability and data integrity
All play an important role in any Penetration Testing services you choose to purchase or need running for your Cyber Insurances.
Internet Connectivity Services
I’m sure you’ve heard of them, with acronyms like ADSL, VDSL, FTTC. If you’re baffled by what’s available at your locations, let alone know what they mean, then don’t worry – we do them all. A few others too – FTTP & Leased Lines being the more popular Business-grade services on offer.
So, if you’re still using an old-school 80/20 VDSL line, Gigabit speeds can be yours for as little as £41 per month !
Private Browsing Misconceptions
Think that switching to ‘In-Private’ browsing keeps you nice and safe on the internet..? Incognito mode may sound perfect when using Chrome, but does it really keep you as safe as you think..? The answer = NO.
All Private Browsing actually does is create a temporary browsing session in which nothing is recorded on your computer… so that when you close the browser all traces of that activity ON THAT COMPUTER will be erased.
This is what can still happen though:
- If you log into a web app during private browsing the website still knows it’s you
- your IP address will still be exposed, so your approximate location is available
- web-based malware can still affect you as normal
- the network administrator (school, work) still has a full view of which sites you visit
- your internet provider will still knows which sites you visit and how long for
- government-level surveillance is unaffected by in-private browsing
- as temporary cookies are still stored, Ad-Tracking services still function while your browsing session is open
5 Things to Do When Your Outlook Mailbox Is Full
Fixing a “Your Mailbox is Full” error in Microsoft Outlook is as easy as getting rid of unwanted items from your mailbox. You have multiple tools to help you find old and large items as well as a few other ways to reduce the mailbox size. If you want to try these first before calling us, go ahead:
-
- Mailbox cleanup – go to File/Mailbox cleanup in Outlook. There are a few options in there to bulk find/delete/move files
- Save Attachments elsewhere – these are usually the largest part of an email
- Find & remove large files manually
- Remove Deleted Items – your deleted folder still occupies your mailbox storage, so remove them permanently. Right click on your deleted items folder, select ‘properties’, then AutoArchive, select a timeframe then click ‘permanently delete old items’
- Automatically Archive Old Emails – follow this click trail in Outlook File/Advanced/Auto Archive
Failing the above, or if this become an all too regular process, standard Microsoft mailbox licenses can be doubled in size… but unfortunately this comes at an extra cost as it will need another license adding. Still, an option though for those who have hit the buffers hard.
As usual, here if you need us.
