Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, August 30, 2017

Aruba ClearPass Part 2



Is your business prepared? Today’s organizations face a complex IT infrastructure, more exposed to cyberattacks than ever. The Internet of Things, an always-on mobile workforce and BYOD make visibility into your network more challenging and critical.

Identifying what’s on your network is a never-ending challenge. Not only do you need to prevent malicious users from gaining access, you have to protect against unauthorized devices and applications.

Businesses today embrace the idea of anywhere, anytime connectivity, but often ignore the need for secure network access control. Many employ a “laid back NAC” solution. Others choose the same vendor for security and network infrastructure. Both these approaches give the illusion of security, even compliance, but in reality, leave extensive security gaps.

As an Aruba ClearPass expert and partner, Convergent Technologies Group can help you reduce time spent identifying devices on your network, enforce policies, and protect your network. We will help you address questions, like:

  • What’s on my network?
  • How do I simplify mobile security?
  • Can I limit mobile devices without limiting productivity or increasing security risks?
  • How do I unify internal and external security tools?

Get started by taking this brief assessment to help you determine your network’s level of security and see how your business might be at risk. To enforce security standards throughout your enterprise, you need secure enterprise network access control (NAC). 

Aruba ClearPass is changing the NAC space, helping companies understand what’s on your network and keeping your information secure. This is an important first step in building a strategy to take control of what’s connecting to your network to keep your data secure and your business safe.

For more information about what the Aruba ClearPass solution can do to defend your network, contact Convergent Technologies Group at sales@ctgva.com or 804-353-5307.




Tuesday, August 22, 2017

Aruba ClearPass Part 1



By Jeff Joyner


Network Access Control or NAC has been around for over a decade, but there are many organizations where this technology has yet to be embraced.  This may be changing thanks to the trend of BYOD (bring your own device).  Companies who want to have more control with the devices allowed on their network are turning to NAC to provide this type of security solution.  The HPE/Aruba ClearPass platform is a best-of-breed product that will provide granular control of wireless and wired access and be able to grow as your company grows.

Say you want to allow employees the ability to connect their personal tablets or laptops to the corporate network where you control which resources can be accessed.  And you want to make sure these devices have appropriate security software installed and updated.  You also have contractors on site that require wired and/or wireless connectivity to the network and need to have access to specific resources during business hours only.  ClearPass can do all of this and much more.

Guest wireless is often offered with either an open (no password) network or with a password that rarely gets changed.  ClearPass can automate individual password generation per user with limitations on bandwidth and time-of-day access if preferred.  You can also force guests to request access with approval from an internal user (manager, receptionist, etc).

ClearPass is flexible in that it works with many vendors, so you don’t have to rip out your current switching environment to make this solution work.  It also supports multiple operating systems including Windows, Mac OS X, Linux, iOS and Android.

For more information about what the Aruba ClearPass solution can do for your network, contact CTG Sales at sales@ctgva.com or 804-353-5307.



Jeff Joyner is a network engineer at Convergent Technologies Group.

Friday, July 14, 2017

A New Compute Experience: An Exploration of HPE’s Gen10 Servers

By Rod Knowles

Is your business finding it difficult to adapt to industry and marketplace shifts, analyzing the customer experience and/or innovating products and services rapidly?  If so, then you’re probably not thinking about, or have a plan in place for your digital transformation.  In today’s economy, digital transformation is the key to a businesses success and remaining ahead of the competition.  Through 4 key transformation areas:  Protecting the digital enterprise, Empowering the data-driven organization, Enabling workplace productivity and Transforming to a hybrid infrastructure, companies can increase profits, agility, flexibility, employee productivity and the customer experience while reducing costs and risk.  For businesses to thrive and easily adapt to their digital transformation, they need a computing environment that will deliver a Hybrid IT infrastructure providing agility, security and economic control.  HPE’s new Gen10 server line accomplishes just that.  Automation, optimized performance of workloads, secure compute lifecycle and flexible capacity are just a few of the benefits your company can gain from switching to an HPE Gen10 server.  In the next few sections, I will break down the benefits on the Gen10 line as its related to agility, security, and economic control.

Obtaining a more agile infrastructure

Manual IT operation processes can be slow and error-prone.  With the new iLO5, being introduced in all Gen10 servers, you will be able to accelerate maintenance tasks, at scale, with automated scheduling and rollback.  iLO5’s RESTful API helps automate and operate server components in all Gen10 servers from staging and updating the server BIOS, iLO, Secure Boot and TPM.  With iLO5’s intelligent provisioning, IT departments can perform initial setup tasks 22% faster than with previous versions of IP on Gen9 servers. Gen10's new Intelligent Systems Tuning can harness the power of the next generation of Intel Xeon processors and balance workloads which allows you to run more workloads on more cores, up to 28 on Intel's New Xeon Platinum processors, resulting in reduced licensing costs and more power/cooling efficiency. Couple that with HPEs new NVDIMMs to utilize the fastest persistent memory available, while realizing the real-world benefits of memory backup power, OS & Application support, reduction of database licensing costs and the fastest tier of storage on HPE Servers.

Increasing security awareness and control

Gen10 security, a better way to stay one step ahead of increasingly sophisticated attacks and protect your business utilizing the world’s most secure industry standard servers. Let’s talk about that for one quick moment, “The World’s Most Secure Industry Standard Servers”.  As recently announced at HPE Discover 2017, HPE engaged InfusionPoints to conduct an independent assessment of the security of the Gen10 Server’s hardware and platform firmware against three of HPE’s competitors. The test consisted of attacks against physical interfaces, platform firmware, and network interfaces.  The results showed that HPE Gen10 servers are a significant step ahead of their competitors and that HPE’s introduction of silicon root of trust will set new standards in providing auditable control of the integrity of platform firmware.

The new Gen10 family of servers provides a host of security features:  firmware protection, run time attack detection, behavioral risk mitigation, data protection, compliance planning and End of Life disposal.  HPE’s new firmware protection is backed by HPE’s own silicon fingerprint unique to each and every server.  With HPE’s silicon root of trust, Gen10 servers WILL NOT boot unless the firmware matches the fingerprint and is protected through the entire supply chain: manufacturing, distribution, shipping, configuration, and installation. It’s locked and HPE is the only vendor who can do this.  When the server boots, millions of lines of firmware code run and verify before the operating system even boots.  Additionally, the firmware is checked every 24 hours verifying validity and credibility of UEFI, CPLD, iLO, IE and ME and reports any malware or compromised code.  Firmware can also be checked and validated on drives, NICs and other HPE server options containing firmware. When a detection of compromised firmware is discovered, the ability to send alerts and quickly recover to a good known state can be set to occur automatically or you can choose to take the compromised server offline.  The ability to recover other server settings can also be recovered as well as the future ability to recover operating systems. 
HPE’s Gen10 servers also offer advanced machine learning that identifies any malicious behavior.  Think of it like this:  The system endlessly trains itself and learns behavioral patterns.  It then analyses and identifies changes in these patterns that may relate to suspicious activity and informs you if there is a threat.  This advanced machine learning technology utilizing Niara’s behavioral analytics protects your organization from inside attacks.  Gen10 servers are protected from inception to their demise. When your server(s) are being disposed of, its embedded data cannot be reconstructed or accessed any longer, forever, utilizing enhanced data protection and encryption.

Managing Your Time and Money Productively

In addition to the Gen10’s server line agility and security features, Economic Control helps you control costs with over-provisioning, out-of-control public cloud costs and the pressures of transforming without the appropriate budget.  Utilizing HPE Flexible Capacity will help align your costs with monthly usage and requires no upfront payments.  Pay only for what you use and scale in minutes, not months.  If you're currently a legacy Gen9 server owner, there are several options for transitioning to a Gen10 server by utilizing one of HPE’s investment models for transforming from legacy IT to a hybrid IT model.

For more information on HPE Storage and Networking, please contact Convergent Technologies Group at 888-353-5307 or via our contact us page



 Rod Knowles is a solution architect with Convergent Technologies Group.

Wednesday, January 18, 2017

CTG Expands into North Carolina

By Caylor Feeley


Convergent Technologies Group is proud of our growth over the last decade and our customer-focused culture. And now, we’re moving ahead in a new direction, with our recent expansion into North Carolina. 

Expanding beyond our Central Virginia headquarters will allow us to strengthen our already existing relationships, and will also enhance our ability to effectively serve a new set of clients. Convergent Technologies Group has a tradition of growing businesses in Virginia, Washington D.C. and Maryland with our IT solutions that fit our customer’s precise needs. Our expansion into North Carolina will not only grow our clientele and market reach but will provide full-service technology solutions to our customers in the region. North Carolina's economy grew from tobacco farming and textiles into a leader in modern industries, such as aerospace, biotechnology, banking and energy. The fast-growing economy and the state's thriving technology-based industries create a strong fit for CTG's presence.

Convergent Technologies Group is dedicated to cultivating positive business relationships in North Carolina and providing organizations with targeted information technology solutions, particularly in the ever-changing digital economy. Technology allows us to connect with clients wherever they are. As we have developed new relationships, we want to ensure that our clients have a local account manager who can better understand their business and market they operate in. With solutions including cloud, collaboration, data center, disaster recovery, managed services and more, we analyze our clients’ specific wants and needs to create a tailored approach that will deliver against company objectives. 

Representing us in the North Carolina region is Bailey Mountcastle, who has joined CTG as a territory account manager. A Virginia Tech business management graduate, Bailey is highly motivated and dedicated, and looks to provide every business with the most effective keys to transform its IT department into a revenue-building department. Whether you need products, services or a mix of both Bailey can recommend and deliver solutions that will benefit both your current and future technology needs. Reach out to Bailey here

Caylor Feeley is a junior marketing specialist at CTG.

Thursday, September 1, 2016

Executive Retreat at The Greenbrier to Focus on Continuity, Transformation

By Elizabeth Foster



“Continuity” and the willingness to “step and think outside of the box” are words that describe The Greenbrier, Convergent Technologies Group and Hewlett Packard Enterprise.


In June, The Greenbrier – a historical legacy as one of America’s best resorts – and its community was tested as it faced massive flooding, the result of unprecedented levels of torrential rain. The national news showed images of homes, cars and other debris swept away in seemingly unstopping waves of water and mud. While the devastation destroyed much of the community, it didn’t stop the heart and resiliency of the community, which was buoyed by the reaction and support of The Greenbrier.


Even though this majestic, historical property was assessing severe damage across its property, the resort’s leaders opened its heart and its rooms to those who had lost everything. Two months later, many are still in the early stages of rebuilding their homes – and their lives.


Recognizing its role as a beacon in the community and a major employer in the region, The Greenbrier worked diligently to re-open its doors. In two months, Convergent Technologies Group will return again to The Greenbrier to host its annual Executive Retreat, partnering with HPE to discuss that latest in technology today – including resiliency when the unexpected might occur.


The background for the Oct. 21-23 is fitting. HPE is known for plowing through challenges, and today is recognized as a juggernaut for innovation and tried-and-tested technology. As a Platinum Partner, CTG shares those same values, refusing to settle for the status quo and pushing for next-generation solutions. At the same time, both companies have a history of empowering their people to be nimble, to be intuitive, to strive for excellence on a daily basis and to never settle for less than perfection.


For the Executive Retreat, technology leaders from Maryland, the District of Columbia, Virginia and North Carolina will be coming together with HPE’s Chief Business Strategist & Innovation Officer (aka Chief Creatologist) Joe Batista and CTG executives for open and frank discussions about today’s challenges. From digital transformation and the Internet of Things, from mobility issues to the need for hyper converged systems to handle virtual and storage environments, HPE and CTG together bring a new way of thinking and doing business. Collaboration is key but not the main factor for spurring on changes in technology. Executives are forced to do more with less with shrinking budgets and manpower, while still delivering business processes and continuity.


Perhaps not surprisingly, Batista’s keynote address will explore “The Pivoting Industry: What’s Your Next Move?”


Our CTG co-founders, John Monahan and Jeff Garell, have a united vision and focus for supporting their clients. They believe that executives who attend The Greenbrier Executive Retreat this year will expand their knowledge by learning key business best practices and how to maximize hyper converged environments to lower cost and down time – not to mention finite details on how to shrink and lower the cost of data footprint in the data center. And that’s just a few highlights.


We’ll be sharing more in the coming weeks about this Executive Retreat, which will featured rich discussions about technology and innovative thinking against the backdrop of historical elegance at The Greenbrier. Have you talked with us about saving a seat for you at this once-in-your-business-lifetime experience?


Elizabeth Foster is an inside sales representative at Convergent Technologies Group.


Monday, July 25, 2016

FortiExpress Brings Facts to You

By Carley Wessler
In this summer heat, nothing beats air conditioning and a cold beverage.
Next week, Convergent Technologies Group is offering that to our customers – with the bonus of inside access to the latest information security in the business.
We’re hosting the FortiExpress – an information security lab on wheels – at Hardywood Park Craft Brewery, 1601 Overbrook Road, #A. The event will kick off at 4 p.m. on Thursday, Aug. 4.

FortiExpress is an innovative resource created by Fortinet, our preferred partner for information security products. The lab is an 18-wheeler that brings Fortinet’s Network Security Platform to life.

Actually, Fortinet commissioned a pair of mobile labs, which are on the road in the “FAST & Secure” tour with stops in 100 cities and logging 25,000 miles over 270 days. We’re honored to bring the FortiExpress to Central Virginia.

Here’s why your business needs you to attend:

Technology showcase – don’t just take our word for it. Explore the full suite of Fortinet security products that offer the latest in security threat detection from the best in the industry.
Demonstrations – see for yourself how the best security products are both fast and easy to implement.
Mobile data center – set up for performance testing.
Networking – talk with other IT leaders across the region and learn about the changing threat landscape and ways to improve your security infrastructure.

Unfortunately, we can only fit so many people in the mobile lab, even when it’s expanded to its full 1,200-square-foot presentation size, and you don’t want to miss this opportunity. To reserve your space, simply click here to register online to reserve your space. The live presentations and demo will run from 4:30-5:30 p.m.

And once you’ve taken in everything in the FortiExpress, we’ll be offering refreshments and beverages at Hardywood until 7 p.m. We look forward to helping you learn more about the right security products that will protect the heart of your enterprise.

Carley Wessler is an account executive at Convergent Technologies Group.

Wednesday, October 7, 2015

Thin Client Technology Is Game Changer for Mobility


By Doug Carter

HP and Windows have launched a new rugged product that is going to change the game on how companies manage their mobile workforces.

The new HP Elitepad 1000 G2 TC Tablet is a rugged Thin Client that offers all of the functionality of a fully loaded table – delivered with the value, security, manageability and long life that corporations love to have.

With 5.7 million more Thin Client units implemented in 2014 and 7.8 million projected worldwide by 2018, HP has certainly set the bar high for its competition with the new Thin Client rugged tablet. Offering improved technologies in Virtual Desktop Infrastructure, Desktop as a Service and Cloud Solutions, combined with a Windows-embedded operating system, HP has claimed the top rung in the worldwide market for Windows-based Thin Client tablets.

What can customers expect from this rugged mobile Thin Client tablet?

To start, this tablet delivers a consistent experience with trusted and familiar standard tools for system administration, along with user-friendly applications that are intuitive, interactive and integrates with existing infrastructure. This tablet also offers the best:

Security: Because security is on the forefront of everyone’s thoughts these days, HP and Windows offer comprehensive security on this amazing unit, combined with HP’s TPM, NIST, Fiber NICs, Multiple Authentication Solutions and HP Easy Shell, Windows provides BitLocker, AppLocker, Write Filters and Predictable Security Update Schedule.

Cloud Power: Microsoft Azure provides a reliable platform customized to meet customer needs. Azure RemoteApp on HP Thin Clients allows customers to run business applications and to scale to meet their business demands, with easy configuration and remote management.

With Office 365, customers have the capability for security-enhanced, cloud-hosted office applications, business-class email with Outlook WebApp, and instant messaging, voice and video calls with Skype.

Connectivity and Communication: A critical part of field reporting is connectivity and communication. The Thin Client with embedded Gobi (Verizon/AT&T) and 2D/3D Barcode reader – aligned with the same hardware and driver ecosystem as Windows desktop operating systems – provides easy access to drivers for printers, scanners, card readers and headsets. It provides high-fidelity communication in the VDI environment or the browser-based cloud. With Microsoft RDP/RFX, Citrix HDX, VMware Vie, HP RGS provides the most complete protocol support for virtualization technology.

Value Add from HP Software: HP Device Manager, HP Velocity and HP Easy Shell provide a rich software ecosystem to optimize the ease of deployment of HP’s Thin Client tablet.



Based in our North Carolina office, Doug Carter is the mobility account manager at Convergent Technologies Group.

Wednesday, August 12, 2015

Mobility Delivers Flexibility, Durability to Field

By Doug Carter

Business and services don’t happen within the confines of a traditional 9-to-5 home office anymore, so why should your technology?

Some mobility applications are easy to recognize, such as police departments and other emergency responders looking to access safety information and relay time-sensitive event information. Those mobile connections directly support smart decisions that save lives.

All mobility applications might not have that element of human drama, but those are increasingly becoming lifelines for growing businesses and organizations in the modern economy. Across virtually every customer segment today, we’re fielding requests to deploy mobile solutions, such as utility and telecommunications field crews having constant access while on the road. Retailers want tablets that allow them to meet customers out on the sales floor, not just at the stationary cash register. Physicians want portable tools that allow them to bring real-time access to medical data into patient exam rooms, while still meeting increasingly more stringent privacy requirements.

To make all that happen, CTG first works to understand precisely what our clients want to accomplish beyond conventional office walls. With that information, we can develop a comprehensive approach that delivers what our clients need – and sets a foundation that allows them to continue to seize the opportunities of mobile as it evolves virtually daily.

Personally, I came to CTG to support this segment with more than 20 years of law enforcement and investigative experience in strategy planning and execution within the public sector and enterprise markets. Does anyone remember doing things the first ways that we went mobile, which required lugging cumbersome laptops, looking for telephone landlines to connect by modem and crossing your fingers that it would work? We’ve come a long way with powerful (and streamlined) new options – but we still advise our clients to think critically on the best ways to implement mobile solutions, starting first and foremost with protocols that safeguard their information.

At the same time, remember that devices are not mobile, people are. With the extreme work challenges and environmental conditions that our customers face, they want to know their products are going to work every time. Not most or part of the time, but every time. Simplicity to the end user and quality assurance that data collection and communication is going to be there when it counts. In the field, time is everything and communication is key to making critical decisions that could save someone's life. That is why we have secured great partner relationships that we and our customers know can be trusted.   

Over the coming months, we’ll talk more about our different partners and how we deploy their products and services in the field for our customers. For now, let’s talk about the initial questions we ask of clients pursuing mobile solutions, including the initial investment in rugged vs. non-rugged (commercial grade) technology.

  • Rugged products are designed to take a lot of abuse. These devices are resistant to heat, cold, vibration, water (spills/rain), fog/salt, dust and accidental drops. Trust me, all of that can happen on the road – sometimes at the very same time. Initial products were developed on the roughest military front lines, so you know they were built to be dependable.
  • The more you handle mobile devices, the more rugged they should be. Think about the end game. Will your employees be constantly moving devices in and out of commercial trucks? Then I would certainly recommend rugged computers, as commercial or consumer grades will not hold up. Our rugged partners back up their belief in their products’ durability over time with competitive warranties.
  • Think about if you really need a keyboard. A rugged device could be a tablet or a computer. Before you make the investment, consider what you expect your crews to do from the field – now and a couple of years down the road. If you decide a keyboard is important for occasional reporting, you could augment a tablet with a non-rugged Bluetooth keyboard.
  • Windows or Android? Again, consider how your mobile technology will interact with what you are using back at headquarters.
  • Assess how mobile devices will connect outside of WiFi. Understand who your carriers are in your service area, so you invest in the right internal air cards.
  • Make it easy for your people to do their work. The mobile products we recommend feature Quadra Clear Screens, which means your people are able to view information even in direct sunlight. These feature amazing clarity.
  • Determine whether your field crews need a camera. Tablets today come with great cameras, providing for an all-in-one solution that eliminates stand-alone cameras, photo cards and cumbersome cords.

Investing in rugged technology is, rightly so, a significant investment. But these products and solutions are designed specifically for operations on the go, offering the right approaches to make mobility a competitive advantage – whether in streamlining information access for emergency responders to save lives 0r helping you find better ways to meet your customers where they are.

Based in our North Carolina office, Doug Carter is the mobility account manager at Convergent Technologies Group.

Thursday, June 18, 2015

The 4 P’s for Securing the Road Warrior (Part II)

By Jeff Garell

Whether you're hitting the road for business or personal travel, making sure you keep your company or individual information secure should be the top of your list. In yesterday’s blog post, we discussed Plan and Prepare. Today, let’s tackle the last two topics: Prevent and Purify

Prevent 
Now that you're on the road, you need to be a little more aware of your surroundings – whether making sure you collect everything after passing through the X-ray station or sitting in the airport lounge waiting for your flight. Be sure all of your stuff is accounted for and NEVER, NEVER, NEVER put anything of value in your checked luggage.

Clothes and toiletries can be replaced relatively cheaply compared to your tech gear, fancy cameras, and the like. As mentioned in yesterday’s post, the less gear you bring, the less you have to worry about tracking.

Once you've navigated the Transportation Security Administration and airport gauntlet, you've arrived at your destination. And it’s smooth sailing from here, right? Not really. There are still potential threats all around, and your prevention steps go beyond the physical safety of your gear:

1. Check the room safe: Is it big enough to fit all of your electronics if you want to ever leave them behind? If not, what can or should you do? This is a tough one. You can choose to take the risk and leave it behind, try to hide it somewhere (between mattress & boxspring? Duct Taped to the outside of the building?), or you'll just need to take it with you. Whatever you choose for this trip, you might need to consider paring down your pile before the next one so you can fit your gear in that safe next time.

2. Be aware of housekeeping: I tend to not make much of a mess, even on the longest of trips, so I often leave the “Do Not Disturb” sign on my door for the duration of my stay. If I run into the staff in the hall, I'll explain (and often sign something) that I don't want my room cleaned. If I need something such as fresh towels, I’ll call or go to the front desk and make the request. How does this help? If no one is supposed to ever be in my room but me, then the key card access logs will be easy to narrow down. Additionally, I have walked down the halls during housekeeping time and have often seen many doors left open while the staff members work their way along the corridor. In fact, I've approached my room while it was getting cleaned, walked right in, grabbed a couple of things (my notepad), and walked out without being challenged as to whether this was my room. That’s when I decided this was a better tactic. If you want to get your room cleaned, take everything of value with you.

3. Validate the Wi-Fi: This advice applies to your visits to the Starbucks, Panera and anywhere else that doles out free Wi-Fi. Here’s one spot where you'll want to do some practicing before you hit the road so you have the process down. Whenever I sign on to the Wi-Fi, I'll quickly scan the network (using nmap) to see if I can find any other devices on it. A properly configured guest network should block “conversations” between guests on that network. If it doesn't, you should seriously reconsider whether you should use that Internet service. If I can see your device, then I can see your traffic and capture your data.

In addition, at hotel check-in, verify the Wi-Fi network name so you connect to the correct one. I recently stayed at a well-known hotel chain that uses something along the lines of "IBahnxxxx" (with the x’s being a number) as its guest network, but, when looking for it, I saw several variations of “hotelName_Guest” access points. If you connect to the wrong one, you're now connected through a stranger’s “access point,” and someone could decrypt your session in what’s called a Man-in-the-Middle Attack. Had I not checked, I probably would have connected to the more obvious access point names.

4. Turn it off: No, not your glowing personality, but your device. If it’s connected to Wi-Fi and you're not using it, turn it off. Just closing the lid of your laptop isn't really good enough for a motivated enough attacker. If you're connecting to an Ethernet port (wired), then be sure to disconnect the cable. Many IT departments enable something called Wake-on-LAN (WoL) so they can turn your machine on remotely if they need to do maintenance; leave a machine on the wired hotel network, and your laptop could be turned on while you're away. If you've followed the advice about encrypting your drive, then there’s much less to worry about regarding WoL.

All right, your trip is nearly over, and it’s time to check out. You hung on to those room card keys right? I ask because there are hotel systems that will put some of your personal data – and, in a few cases, your credit card info – in plain text on that card. These systems are getting phased out, but I certainly won't trust that the hotel I'm in has the latest and greatest software or systems – even if it’s new. Every key card comes home with me and gets friendly with the shredder.

Purify 
OK, finding a “P” word for remediate or fix was a little challenging. So by "Purify", I mean when you get back home (or to the office), it’s time for a heavy duty scan by your anti-virus/anti-malware tools.

If you have an IT department, ask what you should do given available tools. For the most part, you're looking to make sure that you don’t share something picked up while on the road. Some people take this to an extreme by fully restoring their equipment with backups they made before traveling. Unless you're going to a hacker conference, this is probably not necessary, but some will still do it.

This might seem to be a pretty daunting list of things to think about - and these rules apply whether you're on vacation or on a business trip - but given the potential loss you could experience, it’s well worth the effort. I hope you've picked up a few good ideas that will help keep your gear and data safe while on the road.

Happy and safe travels!

Jeff Garell is a co-founder of Convergent Technologies Group.

Wednesday, June 17, 2015

The 4 P’s for Securing the Road Warrior

By Jeff Garell

I travel pretty often in my business – not as much as some, but more than others – and I've found some pretty common sense methods to make sure my equipment and data remains safe.

Those simple action steps each start with the letter P: Plan, Prepare, Prevent and Purify.

Plan 
Do I really need to bring all of this?

Every time I go on the road – whether for a simple overnighter or a longer trip – I evaluate the tools I expect to need. On many trips, I’ll really only need a tablet and my cell phone. I follow this routine because the less I bring with me, the less chance there is to lose something – not to mention the lighter my travel load will be if I don’t need my laptop, extra monitor, mobile hotspot, power bricks/chargers, as well as various cables and power strips for all of it. Sadly, occasionally I need to haul all that gear but fortunately not too often.

The key to making this work is ensuring that you will have the tools (software) you need on the devices that you chose to bring. In the past, I’ve tested that I can perform the majority of my work on a tablet by putting away my laptop and just using the tablet in the office for a week. While I recognized a small productivity hit and I surely wouldn't want to do it long term, that test showed that I can work effectively on many trips with a much smaller tech footprint.

Paring down your gear means less chance of leaving something behind or taking your eyes off the pile and having it walk away without your knowledge.

Prepare
Once you've decided what to bring, take time to ensure your data is safe.

The first thing to do is make sure important data is backed up. I know: Backups are boring. But it’s better than the total freak out you’ll experience when you realize it’s gone. I'd highly suggest making copies of anything important you’ll need on the trip. Leave one copy with a colleague at the office and put the other on a USB drive that does not get tucked into your laptop bag. If that bag gets stolen or left behind, then there was no point in the extra backup. This extra backup will allow you to purchase or borrow another machine and still make the most of the trip.

Just as important is making sure you have run updates on your operating system, current anti-virus, and that your laptop firewall will be on (or that you know how to turn it on) when you're traveling.

If you carry any confidential or regulated information (think HIPAA, proprietary/financial data, or the super secret plans for your island lair), make sure you are using whole disk encryption. This encrypts your entire drive and requires a password before the operating system even starts. It’s an extra step on every boot but is critical if you have data that needs an additional layer of security. Should your laptop get stolen, then all you've lost is the laptop (you did back up your data already, right?). Yes, it’s a pain in elbow to have to buy a new device but much less so than having your confidential information out in the wild.

And when you're not using your laptop, shut it down completely. Your laptop’s sleep/hibernation mode does not cause the drive to be in an encrypted state.

Tomorrow: Prevent and Purify
We covered a lot of ground today, so we’ll finish the discussion tomorrow, when we’ll share some additional practical tips to use every time you travel.

Jeff Garell is a co-founder of Convergent Technologies Group.

Wednesday, May 13, 2015

Picking the Right Cloud

Last week, we discussed some common ground around what the Cloud should offer. Now let’s go with an analogy that I may just pile drive in to the ground by the end of this, but that I think is appropriate as we talk about types of clouds. And that is utilities. More specifically, let's talk power/electricity.

1. Public Cloud
Unless you live in the remote Western outback, odds are that you get electricity from your local power company.  You don't need to know how the utility company generated power or even how they delivered it to your home. You just know when it's there and when it's not. As a customer of cloud services, this works in a similar fashion.

You don't need to know, or totally care, about how your cloud provider's servers are configured, what the brand is, where they're physically located, or the name of the system administrators that keep it running. You will generally just care that it's there. Whether it's gmail/Google Apps, Office 365, or even if you are savvy enough to spin up your own servers on Amazon Web Services, you just don't need to know what is making all of that cloudy goodness happen. This is the public cloud.

However, if you’re a large enough company and are making a big move from housing your servers locally and onto the cloud, you'll be asking about all of the stuff most people don't care about when they use a hosted service.  For most businesses, though, it's more about brand recognition (Google, Microsoft, Amazon) than grilling potential providers about their infrastructure.

2. Private Cloud
A private cloud – which is generally used by large organizations with a well-qualified IT staff – is the equivalent (to return to our utilities metaphor) of running your own power generation operation.  

Using the same or similar technologies as the HPs, Googles, Microsofts and Amazons of the world, these businesses build out the network, servers, software and processes to deliver a similar set of services and characteristics internally. This is not for the light-hearted (or light-walleted) and very much like building your own power plant. The advantage is you get all of the benefits of cloudiness with all of the control that many organizations require or desire.

Just to add to the confusion, there is such a thing as a hosted private cloud, which may sound like it should be called a hybrid cloud, but it's not. You basically still run on a large cloud platform, but many more mechanisms keep your services separated from public services. You might need a VPN connection to get into your hosted private cloud.

3. Hybrid Cloud
No. This isn’t a Prius with a WiFi connection. That said, you have probably estimated that this combines public and private  cloud services. (In this case, private cloud is used as you've built your own in-house cloud).  This kind of setup offers the best of both worlds in that you can move services that may not be as critical  (or super secret) out to a Public Cloud provider and back as your own workloads require.  

Another common use of a hybrid cloud is for backup and recovery, as well as archiving.  Many companies today rent rack space in a data center, invest in another pile of hardware and set things up so that if their main office (or primary data center) were to have an issue they can continue to operate from that backup data center.  By deploying a private cloud and enabling it to talk and move services seamlessly to a public cloud provider,  they get a previously unheard of level of resiliency at a relatively low cost.

I almost forgot to whip out the power analogy (you know you would miss that). This is similar to having some solar panels that you use to cut down on your power bill a bit, but you still need the extra boost on a cloudy (pun intended) day and occasionally might even generate enough to sell back.  

4. Cumulonimbus Cloud
Ok, this isn't really a thing unless you're into the weather.   

I'm going to sign off for now, but I hope I've set us up with a common understanding of the cloud. Future posts will discuss different cases for the small, medium and large businesses, as well as myths and myth-busting.

In the next few weeks, our CTG team will be building our own private cloud, using HP Helion OpenStack on our Lab BladeSystems and 3PAR Storage. It's going to be a fun ride! Keep following us on social media to follow our journey.

Jeff Garell is a co-founder of Convergent Technologies Group.

Thursday, April 23, 2015

Kidnapping Your Data

Ransomware attacks at several of our customers over the past several weeks – including two in the past five days alone - speaks to the urgency with which you should understand and take action.

Ransomware, sometimes known by the names CryptoLocker or CryptoWall, are exploits that encrypt your data and then demand money to free it. So far, we've had some luck in mitigating the data loss for some customers that have been hit. Good backup practices in those cases saved the day.

First response is essential

I can't stress this enough: Call us immediately – but don’t wait for us to arrive before starting the first steps outlined below. 

The key first step is to right click the ransom note (usually a text file in the same directories as the encrypted files), select properties, and whomever owns that text file, well, that is the one that's infected.

Next, get any machine(s) off whatever network that file owner might have been using around the date/time that the file was created. Turn it off. Don't turn it back on until the operating system has been reloaded.

We'll want to look at every ransom note text file on the drive to make sure you don't have more than one infected machine. Do not delete those ransom note files: They're not infected, and they'll tell us how far the malware got before it stopped. They also hold important information should your worst case recovery option – paying the hackers - becomes the only option

Now that you’ve (hopefully) mitigated the problem’s spread, start lining up your recovery options.

1. Do you have a good recent backup? A good backup solution can reduce the amount of data lost to hours, or, at worst, days. Days might not be a big deal depending on the volume of changes to a file. The proposal you wrote a year ago? Not a biggie. Your accounting database? Probably a biggie.

2. Pay the ransom. Unfortunately, you might have to balance the ransom cost with the value of that hijacked data. At least you won't have ABC News doing a story on you, like a certain sheriff's department in that link above. The good news is that these efforts are specifically intended to generate revenue. In an odd bout of honor among thieves, they’ll want to unlock your files after payment because, if they don’t, then no one will pay.

Why? Why? Why?!! (or should that be How?? How?? How??!!)

The first thing we hear is "How did this happen? I have anti-virus running!" That doesn't really matter. In fact, we've seen in one case that anti-virus programs were blocking less than 20 percent of malware.

The latest efforts have gotten even more sophisticated. Where once you had to actually do something – such as click on a link or ad, go somewhere potentially suspect, or download software – now you just need to visit your favorite well-known website (think big trusted organizations with ads on their sites). This has gotten pervasive enough to get its own name: malvertising. Yes, those flashy (pun intended) ads that pop up and try to get your attention are the vector for this exploit. I'll skip repeating what other news stories or blogs say, and we can go on to some good suggestions to avoid this issue.

How to avoid ransomware

While you might be tempted to move to a remote cabin in Montana or disconnect the Internet entirely, you do have other viable options. But they come with some trade-offs, such as Web pages not rendering how they're intended or having to occasionally let scripts run on a site that requires it. Get hit once and lose critical data, and those trade-offs become more tolerable.

1. Choose your browser wisely. I rarely use Internet Explorer unless a vendor’s site is still locked in to some proprietary Microsoft Web things. Consider switching to FireFox or Chrome. Most of the security analysts I know and listen to use FireFox as their primary browser.

2. Add some extensions (add-ons) to your browser. Add and enable Flash and script blockers, which will stop ads and scripts from automatically running and potentially delivering the malware to your machine. For FireFox, I have FlashBlock and NoScript running. Each gives me the option to enable the Flash or scripts on a case-by-case basis, but nothing runs automatically, For Chrome I use FlashControl and ScriptSafe.

3. Stop clicking on shortened URLs. Those things can take you anywhere, and you won't know until it's too late. I know that kitten pic that someone tweeted about is incredibly tempting. Don't do it. At least not on a company PC.

4. Keep your applications and operating systems up-to-date. When you receive security patches and updates, be sure you are routinely running them.

5. User Awareness is paramount. You can’t take adequate precautions without being aware of the dangers. Given the ever-changing threat landscape of the Internet, make awareness a recurring theme. Over the next few months, we'll be putting together a regular published newsletter that you can forward to your employees.

6. Good backups are the answer. That statement probably stands on its own. Whether it's some outsider encrypting your data or a disk drive failing, you want to be able to get that data back.

The bad guys are getting more creative, and your traditional firewalls and anti-virus are no longer enough to hold off the horde. CTG is ready to come in and consult on ways to better protect your data from thieves, vandals and kidnappers.

 Jeff Garell is co-founder of CTG.

Wednesday, April 15, 2015

4 Reasons You Need CTG as Your IT Partner Right Now

It’s easy to call Convergent Technologies Group an IT company. But that’s like saying Nike is an athletics company or Kraft is a food company. Each of us provides a range of products or services under that category umbrella, but each of us has strategically honed in on core offerings that reflect what we can deliver best for our customers.

Being nimble and staying on the leading edge of the ever-changing IT market has been an integral part of CTG’s evolution over the past decade. We now offer a core platform of services that allow us to meet many common IT needs for our customers, no matter where they are in their lifecycle or within their industry.

Some customers come to CTG looking for a specific service, then deepen their relationship with us as they learn more about our extended capabilities. Other clients – including startups and smaller mom-and-pop operations – recognize us from the beginning as a daily partner to whom they can entrust their complete IT needs.

So, why should you consider CTG right now as your IT partner?

1.      We build the data center that meets your needs. From the initial steps of planning the architecture that aligns with your business operations to implementing storage and backup services to handle everyday tasks, we start by sitting down with our customers to understand both current and targeted goals, working to develop an IT framework that can scale with the business. Within that, we incorporate disaster planning and recovery, as well as integrating the best applications to support your varied business tasks. With our strong relationships to the nation’s top IT manufacturers, including as an HP Gold Partner, we can deliver the highest-quality platforms at the smartest cost for your business, including next-generation resources such as virtualization.

2.      We keep your IT secure. Every day, you hear news of attempted – or worse, successful – hacks on corporate technology networks. Because this is one of the biggest worries for business owners, we have developed critical processes using the most-effective tools to put up the best defense. The first step, with the customer’s blessing, is to do our own penetration testing to identify a network’s vulnerabilities, coupled with security audits and assessments. We then offer best-in-class resources, which are continually updated, to protect you and your business.

3.      We offer managed services that keep your doors open for business.Our remote support and help desk actively track and monitor your network operations, because we know that even the best systems can have their bad days. We often find and solve those hiccups before you – or your customer – even notice. We also offer cloud solutions and other resources that allow you to focus your energy on where it matters most: your business and customers.

4.      We support you wherever you are. Work doesn't happen in the office from 9-to-5 anymore. You and your workers are handling more and more remotely, whether delivering a presentation at a client’s office or catching up on a project at home after leaving early to watch a child’s performance. We can implement the best mobility resources and wireless solutions to ensure you can work productively, while maintaining the highest network security.

Information technology long ago stopped being a one-size-fits-all business commodity. We know that, which is why every solution we craft is based on the specific needs of our customers. We listen to what you need, then apply our expertise to develop the IT services that let you run your daily business effectively and efficiently.

John Monahan is co-founder of CTG.