New Security Tools and VPN

To boil it down to one word, we were shocked when we looked at the alerts we saw for our Trend Micro customers. While your security is good, it can be a lot better. The same goes for our VPN customers. Start watching for the new tools.

Let’s look at overall security first. Three keys to good security – in our opinion – are: malware detection, phishing detection, and reliability. We have joined our colleagues in IT and security in finding that Trend Micro has fallen to average or below-average performance in these areas. We came to our conclusion by comparing the alerts we saw in your systems to industry-wide reports. The software was getting buggier and less effective in our opinion, and we found better tools from a number of other vendors. A key element for us is making sure we keep your system out of danger 24/7/365.

Our new security tools will be a combination of products instead of relying on one vendor. This will give us the ability to tailor stronger tools to your specific needs. We believe all of us will sleep better at night once we have the new tools installed. They will cost a little more, but they will be well worth the investment.

We’re also rolling out a new VPN. While we like ZTNA (Zero Trust Network Access) as a way of verifying access to a network, VPNs are ubiquitous and usually easier to administer. Our new VPN will be easier to maintain (which can help you keep it more secure), and it will create a more locked-down environment (which also keeps you more secure).

The feature I like most about the new VPN is that it allows me to connect to any Wi-Fi network in the world and trigger software to route traffic through a specific device. I have device called a Raspberry Pi, a computer the size of a credit card with the power to run a desktop. I use mine to route all my internet traffic through my home internet to home/office computer. The VPN removes worries about rerouting and who might see my traffic. That’s an important feature if you’re forced to use a public Wi-Fi network or even hotel network that’s supposed to be password-protected. You really can’t be assured one of those networks has been compromised.

If you travel and want access to all your home-based streaming accounts, our new VPN will see your home or office internet if you have it set up to do so.

While we’ll be contacting all of our clients to offer our new security tools and VPN, you can contact us for more information about how they can work for you. Call us – 973-433-6676 – or email us to discuss your objectives and your needs.

AI: the Good, the Bad, and the Ugly

AI gives you the tools to do a lot of things in a fraction of the time they used to require. But using AI has its privacy costs, and trying to avoid them can lead to some really bad consequences. AI also doesn’t always get things right.

The most important thing you need to know about AI is that it’s not private. As soon as you put something into AI, it’s out in the world. AI makes its living by collecting data from the internet – lots of data at lightning-fast speed and often without permission. That means they frequently gather sensitive information without your knowledge or consent, and that data can be used for purposes you didn’t agree to, raising ethical concerns. AI can also enable unchecked surveillance, and when you combine that with the vast amounts of data stored by AI systems, you could be set up for the heightened risk of unauthorized access and data breaches. That’s bad and ugly.

Protecting your privacy takes some work. Best practices include never sharing sensitive information, actively controlling data settings, and using approved AI tools. Additionally, regularly deleting past chat histories and reading privacy policies can help ensure better data security. To be anonymous, consider using tools that run locally on your device instead of cloud-based services, and utilize a secure browser with privacy features. You can also use a VPN and sign up with a disposable email address to further protect your identity. DO NOT try to use the dark web. I have some good “street smarts” in the internet world, but these streets are populated by some really bad people. You can easily stumble into a really bad place and be ruined. It’s not like a game.

You also need to remember that AI is not always correct or all that smart. AI can provide wrong answers, so it’s up to you to make sure you verify any information you get from it. A wrong answer could create a life-and-death situation, a costly business decision, or a major inconvenience – just to name a few.

But what I find really frustrating is when Copilot puts you into a loop that is not related in any way to what you’re trying to do. I understand how computers work – they’re anal – but you are supposed to be able to use plain English get your work done or get information. I got into some serious verbal tiffs with my AI; it was really ugly.

However, if you check and double-check AI and really stay on top of it, the technology can work wonders. As an example, I was able to create in just a few hours a travel itinerary that combined independent travel and a cruise. It got us down to the minute we would arrive in various locations, and in the next-to-the-last stage, it gave us choices of hotels that met specific criteria. On the downside, it included a hotel that doesn’t exist, but the beauty was that as I continued to feed it information, it kept narrowing down our options to those that were more acceptable. The lesson from this exercise is that you have to verify all the information, but the bottom line is that it saved me days of work.

We can help you peel away the bad and the ugly to get to the good stuff in AI. Call us – 973-433-6676 – or email us to see how you can keep your corporate data safe and prevent employees from leaking sensitive information. We can set up rules for how your system uses AI. Our new security software tools provide safeguards if you choose to use them.

Block That Flow – Device Code Flow in Microsoft Entra ID

As you read this, I’m at the Xchange Security Conference in Dallas, and I learned something yesterday that I must share to protect your data. I will need to work with you to block device code flow in Microsoft Entra ID. In simple terms, it’s disabling a code system that’s similar to how you match a code on two devices when signing into Netflix.

Device code flow is typically used to sign into accounts on devices such as smart TVs or IoT devices. You enter the short code displayed on the device into a separate device, such as your smartphone or computer, to complete the authentication process.

It’s super convenient, but it also poses security risks, particularly related to phishing attacks. Attackers can exploit this flow to gain unauthorized access to accounts without needing to steal credentials directly. It’s especially critical to prevent phishing attacks.

Microsoft advises organizations to block device code flow unless absolutely necessary. This should help mitigate the risk of phishing attacks. At the same time, we will need to help you implement conditional access policies to control and restrict the use of device code flow. This includes specifying when and where it can be used.

We can tailor conditional access policies based on factors such as user location, device status, and risk assessments. This allows you to enforce specific security measures that align with your needs and compliance requirements. This approach enhances security by ensuring that only authorized users can access sensitive information.

Some of things we’ll discuss with you are:

  1. Determining which users or groups need specific access controls based on their roles or functions.
  2. Setting conditions based on the factors mentioned above. For example, you might require MFA for users accessing data from untrusted locations.
  3. Choosing the appropriate access controls, such as blocking access, requiring MFA, or enforcing device compliance.
  4. Testing all of your policies in a report-only mode to assess their impact without affecting users.
  5. Continuously monitoring the effectiveness of the policies and make adjustments as necessary based on user feedback and security incidents.

Call us – 973-433-6676 – or email us to discuss how to block the flow and develop access control policies for your specific needs.

Take Your Seat

I save every client email because when you contact me with a problem, I can see what related problems you’ve had and find a solution faster. I have good rules to file every email, but there are still lots and lots of messages to manage. I’m not a programmer, but I developed a routine using Copilot to make my email searches more efficient.

Admittedly, it took some doing to develop my system, and it took some refining to get it to where I wanted it to be. The key for me – and for just about all users – was knowing the right questions to ask Copilot to get the desired outcome.

I use Outlook just like most of you to manage my email, and I need to manage my messages across several email addresses and services, such as my own domain and providers such as Gmail. Outlook can search every email address you have, but it doesn’t always show you every message – which means the message you need is hiding somewhere.

Using the AI power of Copilot, I was able to write a routine to handle detailed email searches meeting numerous criteria. The beauty of AI is that I could write them in English, not code, and get answers back in English. That helped me refine my search instructions by asking Copilot more questions.

However, there are two caveats.

The first caveat is that you need to understand how computer programming works (just like you understand how your car works but don’t necessarily know how to fix it). Computers are extremely anal, so you must ask exact questions. AI doesn’t do a good job – yet – of reading your mind. If you’re too general, you’ll get vague answers.

In my case, I had to use a combination of AI and some manual steps before being able to tell the software how I wanted my email stored and how to develop new routines for storage going forward. I have been able to cut my search time dramatically to provide you with better service.

The second caveat is that you need to invest in a license (or seat in tech jargon), to get the most out of Copilot – or just about any AI engine. The free versions just have the power to create the routines that can really make a difference. Licensing can run $20 to $30 per seat, so you need to know who in your organization needs the capability of Copilot and has the ability to use it.

Going in, you can be assured that Microsoft is aware of your privacy concerns and doesn’t use your data to train its AI models. Microsoft 365 Copilot complies with privacy regulations such as the General Data Protection Regulation (GDPR), and security measures are in place regardless of whether you have a Pro license.

We can help you with the entire Copilot process. Call us – 973-433-6676 – or email us to discuss what you need Copilot to do, writing instructions for Copilot, determining the number of seats you’ll need and training the people who will occupy those seats.

COVID and the iPhone 6

We’re still feeling the effects of the COVID-19 pandemic six years ago in many aspects of our lives. When it came to technology, lots of businesses made huge investments to accommodate remote workplaces. If you haven’t made any investments in your technology since then, it’s like using an iPhone 6, which was released in 2014.

What’s the connection? It’s the speed of change. The iPhone 6 debuted 12 years ago. Think about how the performance of your current iPhone compares to an iPhone 6 – or any single-digit model. Remember, we’re up to iPhone 17.

Now, think about all the equipment you bought six years ago to meet the computing needs brought on by the COVID19 pandemic. In half the time that it took the “revolutionary” iPhone 6 to become a benchmark for obsolescence, your COVID-era technology is now obsolete.

Windows-based computing has advanced in four key areas since 2020, starting with the introduction of Windows 11 in 2021. It featured a new interface for improved windows management and productivity features such as Snap Layouts and virtual desktops to help you organize your workspace better.

But the big stuff was under the hood.

Windows 11 includes several security features like Microsoft Defender Antivirus, Trusted Platform Module (TPM) 2.0, and passwordless authentication options such as Windows Hello and Passkeys to protect against cyber threats. Administrator Protection is a new feature that adds an extra layer of security by requiring Windows Hello authentication for admin tasks, reducing the risk of unauthorized system changes.

Windows 11 also brought Microsoft Copilot: An embedded AI-powered tool to help with tasks like summarizing documents, drafting emails, and managing system settings. It also made possible Smart App Control that predicts which applications are safe to run, enhancing security. It was also much faster, making it better able to handle all the tasks we require for complex computing and cloud technology.

For today’s typical business needs, the minimum required specs for a Windows-based computer include an Intel 8th Generation or AMD Ryzen 3000 series processor, 16GB of RAM, and a 256GB SSD. It’s also essential to have the Windows 11 operating system to meet ever-evolving cybersecurity measures and the speed requirements to use cloud-computing effectively. In addition, Microsoft has ended support for Windows 10, and that system will no longer get security updates and bug fixes. Eventually, too, better-performing application software won’t work with it.

We can help you get your hardware up to date. Call us – 973-433-6676 – or email us for an audit.

Microsoft’s Annoyances

A lot of our clients are complaining about Microsoft’s annoying habit of making unannounced changes in features and in how we access what’s left and what we need. We can complain all we want, but this is one case where we just need to bite the bullet and work around various issues.

The biggest annoyances with Microsoft revolve around the New Outlook and the Classic (Old) Outlook. While New Outlook is faster and has some really good message management features, it doesn’t handle attachments as well as its “classic” version.

One of our clients receives .csv files as attachments from their bank. They can’t open them in New Outlook. The only solution is to toggle back to Classic Outlook to download the files and then toggle back. It’s an extra step I find having to use myself, and it doesn’t make me happy.

Other missing features cited in discussion groups and various articles are editing and writing features that used Word, especially for shortcuts; dozens of message handling options; calendar editing options, especially not having Word for editing; lack of print options in Mail view; using Outlook without a mouse; and PST file support.

Microsoft acknowledges that many features are missing and claims to be working on them, but our feeling is that they won’t do anything that will take a lot of time and money. My own feeling is that they don’t have engineers talking to people anymore. If you read responses to complaints, they seem like they were generated by bots; there’s little or no empathy for their customers.

Of course, Microsoft is not alone. Other tech companies seem to do what they want when they want, knowing that most of us have few or no alternatives. It seems that workarounds are the only solution to their shortcomings.

Workarounds are where we can help. Call us – 973-433-6676 – or email us and tell us what you’re trying to do with Outlook, Microsoft apps and apps from other software publishers. We’ll work with you to find workarounds that can make you more efficient.

Copilot is My God?

We likely don’t realize how much AI plays a role in our daily lives. You know those annoying phone trees, the ones that don’t seem to ask the right questions for your problem or offer a good answer or access to a real human being? That’s AI at work. They drive me nuts, but what keeps me awake is who has access to my data?

Many of our customers are turning to Microsoft Copilot to access the power of AI, and if you’re thinking about doing it, here are a couple of things to consider.

As you’ll discover upfront, there’s a free version and a paid version. The main difference is that free Copilot is a basic AI assistant with web-grounded chat and limited image creation. The paid Copilot Pro and Microsoft 365 Copilot offer deeper integration with Microsoft apps, priority access to advanced models, and higher usage limits. I can use ChatGPT to create Excel formulas for my data, but it’s the paid version that accesses my data.

AI carries a number of risks, including data poisoning, adversarial attacks, and privacy leakage, which can compromise a model’s integrity and sensitive data. There’s also the potential for model theft and vulnerabilities in the supply chain and APIs. Let’s focus on risks related to data, privacy, and model integrity.

  • Privacy Leakage: AI models trained on sensitive data may inadvertently leak that information through their outputs. This includes data inversion and membership inference attacks, where attackers try to extract private information about the training data.
  • Model Stealing: Attackers can reverse-engineer or replicate an AI model by analyzing its outputs, which can be used for malicious purposes or to steal intellectual property.
  • Data Breaches: AI systems often require large amounts of data, making them attractive targets for data theft. A breach can expose sensitive personal, financial, or proprietary information.

Whether you use AI or not, Windows 11 and your computer play key roles in your security. All computers are not created equal. If you do a lot of work with Copilot, your computer may not cut it. You should have a computer with a neural processing unit (NPU) capable of processing 40 TOPS – 40 trillion operations per second. Anything less than that will require your computer to offload data from your CPU and graphics card by sending it to the cloud.

Sending it to the cloud involves a security risk, no matter how small the risk may be, and that’s a breach opportunity. Sending data to the cloud also slows you down. If your computer can keep all your work local, it’s faster and more private.

Windows-based computer chips that run 40+ TOPS or more are the specialized Neural Processing Units (NPUs) in new “Copilot+ PCs,” which include processors from Intel’s Lunar Lake series and upcoming Qualcomm Snapdragon X Elite/Plus chips. These are not standard CPUs like the Intel Core Ultra 7 155H, which does not meet the requirement.

Computers capable of 40 TOPS start at around $600 to $700. More powerful and versatile models can cost more than $1,000, but prices could be much higher, depending on the NPU or if it uses a more expensive, high-performance GPU, which can add significant cost for graphics-intensive tasks. In addition, you likely will have licensing fees depending on what you’re doing and how many computers are doing the work.

We can help you assess your AI needs and sort through myriad options for Copilot licenses and the computers needed to accomplish the tasks you require. AI can require a large investment, which requires intensive investigation. Contact us by phone – 973-433-6676 – or email to set up an appointment to start the investigation process.

 

Carrots: The Root of Speedier Scrolling, Less Clutter

Carrots can provide useful shortcuts for navigation and decluttering your screen. You can find them almost anywhere on your screen. You’ve likely seen them and never paid much attention to them.

The carrot symbol ^ can be pointed in any of four directions on a screen – up, down, left, right – and carrots are most useful in File Explorer and Outlook, although they’re not exclusive to those apps.

Most of us will find carrots useful for doing a quick search in File Explorer. If you look at the upper left corner of File Explorer, you’ll see three listings: Home, Gallery, and your OneDrive. In Home, for example, you might find a screen to the right that shows > Recommended on the top row and > Recent, Favorites, Shared. If one of those three folders is highlighted, you can click on it and get a listing of files for a quick search. You can then open a selected file or simply collapse the listing by clicking on the downward-pointing carrot.

In the next grouping on the left, clicking on Documents or Pictures, for example, opens a dropdown menu of folders and subfolders (showing as many levels of subfolders as you have) to give you a quick look at your files. We’ve found it quicker to search this way than scrolling through our folder or subfolder lists of Documents or Pictures.

Farther down on the left are This PC and Network. Clicking the > carrots will show you more information about files on your PC or devices connected to your network. Again, they’re easily collapsable.

Similarly with Outlook, you can use carrots to expand or collapse your Favorites and the contents of each mailbox (account) that you have through Outlook. This can help you keep your screen less cluttered and more organized, helping to navigate the contents of each account more efficiently.

Working in Microsoft Word, if you keep the ribbon open and expanded across the top, you can access more options by using carrots for things such as fonts, sizes, colors, bullets in bullet lists, etc.

We encourage you to look for carrots in File Explorer, Outlook, and your Office apps. Looking at the results of each click may lead you to a new shortcut that makes your computing life easier.

Windows Shades

You wouldn’t believe how many versions there are of Windows 10 and Windows 11. Don’t bother to try to count them. Instead, start making a plan to make sure you have the latest version of each throughout your organization and a plan to update on a regular basis.

Let’s look first at Windows 10. As we all know, Microsoft will end its support of this operating system (OS) in October, but there are ways to keep it going with security updates. You have two options to enroll in the Extended Security Updates (ESU) program for free. That will enable you to receive critical and important security updates from October 15, 2025, through October 13, 2026. You can also enroll in a wizard accessible via notifications and the Settings app.

In order to take advantage of the extended support, you need to know which version of Windows 10 you have on your computer(s) and see if it will be supported. Since its introduction, Microsoft has issued 14 versions of Windows 10, covering office, home, and student versions and updates for each. If you have version 1903 of Windows 10, for example, you won’t be able to receive any updates. To extend your Windows 10 use, you need to have version 22H2.

Depending on your hardware, it may or may not be possible to update your Windows 10 to a version that can work with security updates going forward. To check your Windows version, navigate to Settings > System > About. Under “Windows specifications,” you’ll find the edition and version of your Windows operating system.

Windows 11, by the way, has four versions, with a new one expected this fall.

A key thing to know about Windows – and your app software – is that you used to be able to install newer app software on older versions of Windows. That’s becoming less and less possible. One of our clients learned about that when they couldn’t install a new app their accounting firm had suggested because their Windows version wasn’t compatible.

As we go forward, this is only going to become a more critical issue. Both OS companies, such as Microsoft, and app publishers, will need to meet their customers’ need for more speed to process more data and provide the security measures needed to protect critical data.

Don’t wait until your technology system collapses under the weight of more data and faster-moving environments. We can help you by analyzing your current system – both hardware and OS – with an eye toward your future needs. That will help you develop a plan (and a budget) to make changes with minimal disruptions to your business. Call us – 973-433-6676 – or email us to set an appointment to talk about it.

Cybersecurity Keeps Them Awake at Night

“What keeps you awake at night?” That’s a question that seems to come up at many a business networking group when someone begins to offer a solution to a problem they can solve. If you’re a CEO at a major corporation, the answer to that question is: cybersecurity.

Internet systems are more complex, and complexity leads to more risks. It’s become a boardroom issue, and the most concerning part of the problem should be the increased time it takes to find a system intrusion. It now takes 292 days – more than nine months – to discover a breach.

Part of the problem is the size and complexity of large corporate networks. They have thousands of endpoints, and it’s become harder to spot anomalies and deploy patches. While our clients typically don’t have large, sprawling networks, we all interact on the corporate or personal level with large global networks for just about everything we do.

Other parts of the problem are that companies may take too long to investigate the breach, and then they need time to develop a plan to patch it. That time is directly related to the network’s size and complexity. If a company doesn’t have a continuous monitoring plan (yes, it’s hard to believe a large company wouldn’t have one), it also extends the time to discover a breach.

Two other reasons are:

  1. Hackers have better stealth tools to invade a network. Once they’re in undetected, they can take their time to look at all of their victim’s data to see what’s best to monetize.
  2. Hackers can steal login credentials and hang around a system for a long time until they’re detected.

Companies that can detect intrusions in less than 100 days can save $1 million in containment costs. But they may not be as motivated as you are to protect your network and the people they serve.

Here are some things you can do right away:

  1. Make sure you have strong passwords for every account you and your employees and family members have.
  2. Insist on using passkeys or some other form of two-factor authentication (2FA) wherever possible. A good authenticator should be device-specific and tied to a device that’s always with the user.
  3. Make sure all your software (operating systems and apps) and firmware (hardware systems) is up to date.
  4. Have an easily accessible list of your key usernames and passwords for emergency use.

Microsoft is making strides in a couple of areas. The company introduced passkey support across most of its consumer apps a year ago, allowing you to sign into your account without the need for 2FA methods or remembering long passwords. Today, it’s encouraging all new signups to use passkeys as it removes passwords as the default.

Windows Hello allows users to securely sign in to their accounts with their face, fingerprint, or PIN. Today, more than 99 percent of users sign into their Windows devices using Hello. The company reports that 98 percent of passkey attempts to login are successful; passwords are only 32 percent successful.

To help keep all your software up to date, Microsoft is developing an update orchestration platform designed to unify the updating system for all apps, drivers, and system components on Windows systems. Right now, it’s aimed at developers and IT product teams. The goal is to run an update scan tool that will queue downloads and updates at optimal times. We’ll see if they can actually make it work.

That’s in the future. For the here and now, we recommend you contact us for a security audit. It’s something you should do annually to make sure you’ve taken the four steps we enumerated above. At the very least you can strengthen your own systems before the big guys know they were breached. Call us – 973-433-6676 – or email us for an appointment.