PCI-Compliance-IT-Security

4 Signs that You’re Out of PCI Compliance

Compliance with the standards set by the Payment Card Industry (PCI) Security Standards Council can be cumbersome and flat out difficult. And the punishment for non-compliance can be stiff penalties and fines – or even worse, non-compliance could allow a hacker or data thief to get into your company’s systems and steal critical data from you or your customers. To avoid these unsavory outcomes, it is best to make sure that your business gets PCI compliant and maintain that compliance status. It is critical that you know if your company is PCI compliant so that you can keep your business protected from fines and hackers alike. Here are some of the ways that you can know if your business is not compliant. If any of these signs describe your business, then it is time to make a change and get back into compliance.

You Store Cardholder Data

Storing cardholder data means that you have highly sensitive information that can be stolen on your systems. To maintain PCI compliance, you should not save or store any cardholder data, whether in digital or written form. To avoid storing cardholder data, you can use a card reader, POS terminal, or a payment processor that doesn’t retain that information. That way, you don’t have to think about protecting or encrypting that data on your systems.

You Don’t Have A Separate Network For Payment Processing

PCI compliance can put extra pressure and security measures on your network. That’s why it is a good idea to have a separate system for your regular business connection just for payment processing. This is especially relevant if you are using IP-based credit card terminals.

You Don’t Automatically Log Customers Out

When your customers log in and make a purchase, they might be doing so on a public computer or at a public kiosk. When they leave that computer, they might forget to log out, allowing another person to stumble upon their open session and make unauthorized purchases. Make sure that you avoid these kinds of scenarios by automatically logging your users out of their sessions after a set period. If for example, users are automatically logged out after five minutes being idle, you have a significantly higher chance of stopping unauthorized purchases.

Your Employees Don’t Have Unique Login Information

To be PCI compliant, all of your employees need to have their unique login information for sensitive systems. That way, if there an issue, you know which employee was responsible.

smart-guns-obama-executive-order

New Obama Executive Order Creates Investment In Smart Guns

Obama’s New Executive Order

President Obama has long been frustrated by the lack of gun legislation in Congress and earlier this month, he announced an executive order that would clarify some existing laws already on the books. President Obama’s new executive order will expand background checks to include gun shows and some private sales, which previously allowed buyers and sellers to come together and complete a transaction without doing a background check. President Obama will be hiring more ATF agents and other federal agents to ramp up enforcement of gun laws. But the President also did something else fascinating — he created an investment in smart gun technology.

The Investment in Smart guns

President Obama’s interest in smart gun technology is not accidental. The President knows that while stricter gun legislation and potential penalties would be nearly impossible to pass through Congress, smart gun technology could make sense for responsible gun owners, law enforcement, and the greater population alike. The executive order creates three directives for federal departments on smart guns:

  • It authorizes research and development spending
  • Departments must now review the availability of gun safety technology and possible improvements
  • It permits research on how smart technology can limit gun-related homicides

Smart gun technology is appealing because it uses sensors that can read fingerprints or radio waves to determine who is authorized to use the weapon. Some smart guns are even using more complex indicators, such as grip recognition. This technology could keep guns out of the wrong hands and prevent violence if guns are stolen or sold illegally.

Detractors

Even though President Obama’s executive order was applauded by many, some groups have claimed it is illegal and unnecessary. Among these groups are the NRA, which is perhaps Congress’s strongest lobby. There are legitimate concerns about the accuracy of smart gun technology, but perhaps extensive research could curb some of those fears.

What is the Future Of Smart Gun Technology?

In the future, smart gun technology could be incorporated into all federal agencies. Once the federal government proves that smart gun technology is accurate and can work within its departments, it will likely filter down through the states and to the US population as states and localities pass their own laws. President Obama’s hope is that smart guns will eventually have legislation in Congress, making the technology a key component in owning a firearm.

regulatory compliance

Three Most Important Facts About Regulatory Compliance

When it comes to regulatory compliance, even the most enthusiastic managers can quickly get bored. It’s not hard to see why—regulatory compliance can be a long and frustrating process if you are trying to stay compliant without any professional help. Because regulatory compliance is so complex, it can be difficult to understand some of the legal concepts behind the process. That’s why we’ve broken down the three most important facts, so that you can easily know what’s vital to your business without having to pore over dozens of policy documents or looking through legalese.

  1. You Need Physical and Digital Security Policies

Sure, digital security policies get all of the press. And they are absolutely critical to your company’s regulatory compliance, as well as your long term success. But you need physical security policies too. You need to specific which employees are allowed physical access to particular facilities. This includes guests and vendors too—you have to be able to know who is able to access server rooms and other rooms that house critical IT infrastructure. These policies breed accountability. In order to uphold these physical security policies, you can use key codes, badges, or other ways to regulate access.

  1. Compliance Issues Must Be Relayed To Employees

Because regulatory compliance issues are so complex, it can be difficult to make them seem relevant and purposeful to employees. But if your regulatory compliance efforts are to succeed, you must let your employees know the importance of compliance and train them to make sure that they are up to date. The best way to do this isn’t to throw complex legalese at them, but to use simpler terms. Compliance isn’t always black and white, there are always grey areas, and your employees need to know what is expected of them when they encounter a grey area.

  1. There Are Hidden Benefits To Compliance

Often, it is assumed that there are no benefits to regulatory compliance other than avoiding fines and penalties. That isn’t true. There are hidden benefits to compliance that your business can take advantage of. Compliant businesses are more up to date on industry trends, and generally have more streamlined employee processes, where employees know what the appropriate decisions are. Compliance can improve standardization across your business, which can ultimately result in greater efficiency as well. Businesses that are compliant tend to have greater transparency, with workers at all levels—from the top down—more aware of what is expected of them.

unified communications

Unified Communications Helps You Communicate Like the Special Forces

Why Communication Is So Critical

 Your company’s communications are absolutely vital to your business’s long term goals. Your long term goal might be producing a strong product, or improving your relationship with your customers. But how can you get any of those things done without communication? Your team needs to be able to quickly share ideas and move forward with company projects. If your employees can’t reach each other and are constantly getting sent to voicemail, then they probably aren’t going to get much work done for your business. More companies are looking into improving their communications infrastructure and making it easier for their employees to communicate. More efficient communication means better productivity, which at the end of the day means a better bottom line. And that’s just more money that you can reinvest into reaching your company’s goals.

What Are Unified Communications?

 So what are unified communications? Unified communications describes a single system that can complete many different lines of communication, such as web conferencing, instant messaging, emails, phone calls, voicemails, and more. Simplifying your communications infrastructure by having a single system allows you to save money and it helps your employees be more efficient. How much time have you spent looking for the password to an instant messaging client? Or looking through your bag for the mobile device with the right web conferencing app? With unified communications, those are problems of the past. Instantly connect with employees, business partners, and customers and make communicating simple and easy again. Get projects done faster and improve your relationship with your clients.

Let Cognoscape Get Your Team Communicating Like Special Forces

Let Cognoscape Get Your Team Communicating Like Special Forces

When special forces are out in the battle field, they are relying on the person next to them with their life. That’s why they train especially hard on communication. Special forces teams move like a single entity, quickly and efficiently communicating to get the job done right the first time. That’s how your team’s communications should be, minus the battlefield of course. We want your team to be more efficient, and unified communications infrastructure with a single communications platform is the way to do just that. Cognoscape can help your business implement the right unified communications solution to fit your specific needs. Our team of technicians and IT consultants can help your company find the right fit when it comes to IT infrastructure. If your business is ready to improve its communications and enhance productivity, then give Cognoscape a call today!

Best VoIP Service

What is Included in the Best VoIP Service

Don’t Let Communication Issues Hold Your Company Back

Even in today’s digital world, communication can be difficult. You would think that all of the mobile devices and applications would make communication easier, but all of those gadgets can quickly turn into clutter. When you have a laptop, a desktop, a smartphone, a tablet, and a fax machine, it can get hard for any business to properly manage their communication. The problem is that not managing your communication properly can lead to big consequences for your business. When you are missing calls and playing phone tag with your employees or your clients, you are wasting time and losing productivity. When your employees can’t effectively communication, guess what? Your projects take longer to complete, and your clients aren’t happy about it. So how can you speed up communication and make it more cost effective? That’s where VoIP solutions come in.

What The Best VoIP Service Can Do For Your Business

When you are working on improving your company’s communication, you don’t just want any VoIP service. You want the best VoIP service that you can get. And luckily, that’s exactly what Cognoscape offers. CognoVoice, Cognoscape’s VoIP solution, is the best VoIP service because of the features it offers businesses. CognoVoice offers companies the ability to manage all of their communications—phone calls, voicemails, e-mail, fax, text, data, and more—all from a single machine. Easily make and receive calls on the go by turning your computer into a telephone, so that you never have to miss another conference call again. Wouldn’t it be easier managing all of your communications from a single device, rather than looking around for your tablet, texting on your smartphone, while responding to e-mails from your desktop computer?

Make Communication Easy

Communication doesn’t have to be difficult. It doesn’t have to be expensive or limit your company’s productivity. CognoVoice is the best VoIP service because it provides companies with a way to manage their communications quickly, easily, and affordably. Whether you need to manage a high volume of calls with SIP trunking or you want a scalable phone solution that can grow alongside your business, CognoVoice is the way to go. Reduce your infrastructure and maintenance costs along the way and eliminate the need to constantly invest in expensive IT infrastructure for your company’s communications! Contact us today to learn more.

Giving Thanks on Thanksgiving

How do you give thanks during the holiday months?

November is the month when we spend one day with our families and/or friends, we feast on generations-old dishes, and we post on Facebook all the things for which we are thankful, but we at Cognoscape want to take it further this year. We want every one of our friends, clients, customers, employees and partners to know we are truly thankful for their business and support. Even if customers or business relations have long left our side, we want them to know they matter, too. Without each and every person we work(ed) with, we would not be the company we are today.

There are many ways we can give thanks and do often. Giving thanks can be buying coffee for the person behind you in line, shaking hands with a vet or active duty service member and thanking them for their service, baking a pie for your neighbor, giving your child’s bus driver or teacher a special gift, treating a neighbor or co-worker to dinner, or simply hugging a friend or relative and telling them how much they mean to them. Maybe your mentor is on your mind around the holidays. You can reach out and thank him/her for supporting and inspiring you. For some—including many here at the office—giving thanks includes volunteering around the holidays. Even though we will eat good food and drink good wine, we are aware of the fact that many people do not get that. Cognoscape strives to be a good citizen. Giving thanks can also take the form of writing thank-you letters, and this is ours to you: Thank You.

This is the month that allows Cognoscape to reflect on past experiences—failures and triumphs, present operations, and future goals to determine what it is we want the world to know about us and our brand. What is Cognoscape’s legacy? For what are we admired, whom can we help in the process, and whom do we have to thank for our successes?

Our legacy mindset is your promise. This Thanksgiving, we at Cognoscape—both leaders and employees—are tuning-in to our legacy mindsets to create an environment of transparency, reliability and client-focused attention. Our legacy transforms with each and every experience and interaction we have, and we have you—our clients—to thank for that.

What is our legacy-driven mindset? To us, it is our process of both evaluating and reflecting upon the stages through which we have traveled to get here. We consider our mentors, our employee relationships, our business decisions, our daily interactions with our clients, and the progress we have made thus far to create an environment of trust that we and our customers can be proud of.

With that in mind, we want to reflect on our legacy and take a moment to thank for getting us to this point. Thank you for your support, your dedication, and for the future we hope to share together.

What Gamers Need to Know About Online Security

Remember when video games were limited to Player 1 and Player 2? The explosion in video game technology has made it possible for gamers to evolve from playing Pong alone in their bedroom to becoming part of a complex online network of games. Massive Multiple Online Role Playing Games (MMORPGs), such as World of Warcraft have millions of players online at any given time.

By 2017, the video game industry worldwide is expected to generate over $80 billion in revenue, due largely to online gaming. Like anything that exists on the Internet, there are increased online security risks, questioning the safety of online gaming. Below we discuss the risk assessment involved with playing video games online and how to protect yourself.

 

Technological Risk Assessment of Online Gaming

There are a number of technological risks to your computer system when one becomes involved with online gaming.

 

  • Worms and Viruses: Instant messaging programs and email messages can house viruses that arrive as attachments, or are hidden in game files that are downloaded or found in installed software.
  • Malware: Worms and viruses can be used to install malware in order to take advantage of the social networks associated with online games that use email, chat or voice communication. The malware is used to invite you to visit fake websites or to open up email attachments that contain malicious software and install it on your computer. This software is then used to gain access to personal information for financial gain.
  • Compromised or Insecure Game Servers: When software on a game server has been compromised, any computers that connect to it can become compromised. By exploiting vulnerabilities, online criminals can gain access to your computer and control it remotely. Malicious users can use your computer to install Trojan horses, spyware, adware or access personal information on any computer that connects to yours during gaming or communications.
  • Insecure Game Coding: Some game protocols for communicating information between machines are not as secure as other protocols. Game code may not be monitored as well as other commercial software. Erratic behavior on your computer can introduce dangerous vulnerabilities.

 

Social Risks of Online Gaming

Now that video games involve community chats, talks and instant messaging, a whole new batch of social risks are involved, such as:

 

  • Identity Theft: Malicious gamers can take information from your profile created in games and use it to set up accounts in your name, access your financial accounts or sell your personal information.
  • Social Engineering: Cyber-criminals try to trick gamers into installing software on your computer that they can use to control it, launch attacks on other devices or monitor your online activities.

General Security Practices for Online Gamers

Here are the most common ways to protect yourself when participating in online gaming:

 

  • Securely configure your web browsers.
  • Use antivirus programs.
  • Do not open files attached to email or instant messages without being cautious.
  • Use a firewall.
  • Verify the security and authenticity of new software and downloaded files.
  • Update and patch your application software.
  • Identify then back up financial and personal data.
  • Create and use strong passwords that are unique to that system.
  • Use administrator mode only if the vendor is reputable.
  • Play the game at the game site and save web browsing for a later date.

 

Contact us if you have any questions about security for online gaming or for your personal or business network.

3 True Urban Legends

Every year on and around Halloween, families and kids look forward to Trick-or-Treating, Halloween parties, haunted houses, and other festivities to celebrate this ancient Wiccan holiday. Every year we also hear about the urban legends told by someone who swears they’re true. They heard it from a friend, who heard it from a friend, who – you get the idea.

The majority of urban legends are false. After all, how can Goat Man be real? There are a few such urban legends that do have some truth to them, and you should be worried.

 

Slender Man

The origins of Slender Man tie directly back to the forums of Something Awful, a humor site for people who enjoy joking about Dungeons & Dragons, tricky Photoshopping, and general prankery. On June 8, 2009 Slender Man was created by Victor Surge when he Photoshopped an image of a tall, shadowy figure with tentacles for arms haunting two small children.

Since then, Slender Man has taken on a proverbial life of its own and has now become a true urban legend. In some stories Slender Man preys solely on children, in others he kills indiscriminately, disemboweling his victims and bagging up their organs. Still in others, Slender Man simply compels his victims to kill each other.

That’s just what happened in Waukesha, WI on May 31, 2014. Two 12-year-old girls lured another 12-year-old girl, their friend, into the woods and stabbed her 19 times with a large kitchen knife, allegedly in order to impress Slender Man and prove he was real. The 12-year-old girl survived the attack but it goes to show – an urban legend doesn’t have to be based on ancient myth or story to be taken seriously and be given a life of its own.

 

The Hitchhiker

We’ve all heard the stories. A woman stops at a gas station to get gas, goes inside to get something and then drives away not realizing a murderous hitchhiker has stowed away and is hiding in her backseat. She doesn’t realize it until it’s too late and her body is found several days later in a ditch nearby.

Versions of this story almost always stay true to the hitchhiker’s target being female. Some versions tell of a Good Samaritan driving behind her flashing his headlights and trying to warn her. Other versions involve some sort of gang initiation. Either way, this is something that does happen, just not the way you think. A woman was strangled to death in her car just after dropping off her daughter at daycare. A man snuck into the backseat of her car while it was unattended and waited for her to return. Once she did, he killed her and escaped with her car.

The moral? Always lock your doors.

 

Poisoned Halloween Candy

It’s every parent’s worst nightmare and a child’s deepest fear. Who doesn’t enjoy rummaging through their bag of goodies at the end of a good Halloween night, but fears not waking up the next morning after eating a few pieces of candy. Most of these stories consist of hidden razor blades and lacing candy with poison. Though this doesn’t happen as often as one would think, it has happened. Please be vigilant about checking your child’s candy.

In 1974 Ronald Clark O’Bryan of Waco, TX laced pieces of candy with cyanide. He, however, was no stranger to his victims. O’Bryan was having serious financial troubles and decided his way out from under his mountain of debt was collecting on a $20,000 life insurance policy he had taken out on his children. He gave the poisoned candy to his son, daughter, and two other children. He helped his son, Timothy O’Bryan, ingest the cyanide-laced Pixie Stick. Timothy died as a result. O’Bryan was nicknamed “The Candyman”, and was caught and put to death via lethal injection.

cognoscape dallas

Cognoscape CEO and Owner Charles Tholen Added to CompTIA Executive Council

Cognoscape CEO and Owner, Charles Tholen, was recently added to the IT Security Community Executive Council at CompTIA. As an Executive Council member, Charles is able to directly and indirectly use his wealth of knowledge and experience running Cognoscape to help other members of the CompTIA community.

CompTIA is the voice of the world’s information technology (IT) industry and operates as a non-profit trade association. The goal of CompTIA and its members include advancing the global interests of IT professionals and IT channel organizations. It’s accomplished by providing industry-leading IT certifications and IT business credentials, IT education, resources, and the ability to connect with like-minded, leading IT industry experts.

The Board of Directors is made up of top executives and thought-leaders working in various esteemed positions within the IT channel. The board helps guide the trade association and the IT industry at large. The executive staff helps manage the operations of CompTIA, which includes membership, education, certification, advocacy and philanthropy programs, as well as finance, marketing, legal, and information technology departments.

Charles will be heavily involved in working with others within the IT industry to ensure they have what they need to be successful.

Take Advantage of A Network Security Specialist for Your Business

The more our society becomes dependent on technology, the more we see an increase in data breaches, cyber crimes, and leaking of sensitive information. This is why the government and businesses of all sizes are focusing more of their efforts on network security. When it comes to keeping your information safe, you can’t go at it alone. Network security specialists are in high demand for assisting companies with their online safety needs. Below we discuss the importance of working with a network security specialist to keep your business secure and information safe.

 

Role of a Network Security Specialist

Your network security specialist is in charge of safeguarding your computer system and protecting it from threats. Threats may be external or internal in nature, but some of the biggest threats to network security generally come from outside sources. The network security specialist will install firewalls and programs that issue alerts when there is an attempt to infiltrate the system. Network security specialists are constantly updating their level of knowledge to keep up with the growing technology industry.

 

Advantages of Hiring a Network Security Specialist

Having a network security specialist in your arsenal of weapons to combat hackers has many advantages, including:

 

Protection of Company Data

Part of the job of a network security specialist is to constantly monitor the flow of information within the network, prevent unauthorized users from accessing sensitive data, and check on bandwidth usage. This data may be pertaining to customers when dealing with companies like banks or other large corporations. Information such as phone numbers, account numbers, credit card numbers, addresses, and emails can become exposed. Government agencies will have information that pertains to internal communications and secret operations, posing as threats to national security. A network security specialist is vital to the safety of these organizations’ information.

 

Setting IT Infrastructure Usage Rules

A network security specialist is one who is in charge of designing and implementing security protocols within a computer network. This involves having control over the data that users have access to and setting up password authentications and firewalls. The specialist is able to block access to particular websites as well as prevent the installation and usage of certain applications that may pose a threat to the network infrastructure. With a network security specialist on board, they will be able to catch employees violating company computer policies and notify their manager.

 

Custom Security for Your Network

Your network security specialist will sit down with you and create a plan that is specific to your business’s needs. There is no “one-size-fits-all” model for any company and should never be offered to clients. Your custom network security plan will help your business grow much quicker by eliminating potential technology roadblocks that pop up. If you do not have a network security specialist working with your organization, you run the risk of losing customers to security breaches.

 

We want to be your network security specialist! Contact us today and we will discuss the best path for your company to follow when it comes to data and network security.