SpiceCorps of Western Chicagoland Suburbs @SpiceCorpsWCS #SPICECORPS
23 Slides7.53 MB
SpiceCorps of Western Chicagoland Suburbs @SpiceCorpsWCS #SPICECORPS
Agenda Review recently added/updated Spiceworks features Passwords vs. Passphrases Ransomware stats Internet of Things security Malware tools & resources Sponsor presentation: Webroot Raffles! Q&A #SPICECORPS
Daily Challenge Daily Challenge Test your tech IQ and have a break during your workday with a single IT question. Answer your first challenge, build your streak, and up your IT knowledge. Use the dashboard to track your progress, see which topics you excel at, and earn badges along the way! Take the challenge here: community.spiceworks.com/daily-challenge #SPICECORPS
New Community Feed Your New Feed The best of the start and feed pages, with even more functionality and customization. Personalized content, top news of the day, and the Daily Challenge. And you can read everything in-line! Check it out here: community.spiceworks.com/my-feed #SPICECORPS
Spiceworks Community Mobile App Spiceworks Mobile App All the power of Spiceworks, personalized, faster, and now on your mobile device. Download on Android and iOS phones here: www.spice.ly/mobilefeed #SPICECORPS
Cloud Helpdesk Spiceworks Help Desk – Cloud Edition We’ve made a few updates to help IT pros get things done even quicker: Updated user portal (AD/LDAP Integration, custom attributes, custom forms, Knowledge Base) SLA/Ticket Alerting (to allow you to get notifications when tickets have not been worked/closed in a given amount of time) App Center Integration Check it all out here: spiceworks.com/free-help-desk-software User portal #SPICECORPS
Connectivity Dashboard With the Spiceworks Connectivity Dashboard, you can see all users’ connectivity and view speed to their applications. Figure out if there’s an issue with: ISP Application Other issues onsite like floor switch, wifi access point, etc Check it all out here: spiceworks.com/it-troubleshooting #SPICECORPS
Network Monitor 1.5 Historical Data See what’s happening on your network over time Maintenance Windows Turn off alerts for regularly scheduled maintenance Watch More Devices Add devices to your Online Watchlist on your dashboard Check it out and learn more here: community.spiceworks.com/blogs/products/2400 #SPICECORPS
SpiceWorld Come to the most happenin’ IT conference around, SpiceWorld! Hang out with fellow IT pros, attend useful tech sessions and have blast while you’re at it. Learn more and register here: spiceworks.com/spiceworld/ Locations & dates: Austin, TX Nov. 1 – 3, 2016 London, UK 23 – 24 May, 2017 #SPICECORPS
Passwords vs. Passphrases #SPICECORPS
xkcd.com/936 #SPICECORPS
Common Password Practices Minimum length 8-12 characters Complexity requirements Required change every 30/60/90 days Leads to difficult-to-remember passwords Users forget password more often Password post-its on monitors Users use easy-to-guess passwords Users reuse passwords, incrementing a number #SPICECORPS
Password cracking New password cracking cluster – 350b guesses/second 25 AMD Radeon card cluster Virtual OpenCL cluster platform and ocl-Hashcat Plus Examines around 50 hash algorithms Can try every possible 8-character Microsoft password in 5.5 hrs Crack 20 char passphrase Numeric only: 3.5 trillion years Lowercase only: 1 sextillion years Alphanumeric symbols: 295 quintillion years #SPICECORPS
Passphrase Benefits 20 character passphrases impossible to brute force Easy for users to remember Easier to type without complexity requirements Password post-its won’t make sense to passersby Less need to unlock user accounts or reset passwords Can lessen password change interval – 6/12 months #SPICECORPS
Ransomware #SPICECORPS
Spiceworks surveyed over 300 IT pros about ransomware here’s what we found. #SPICECORPS
#SPICECORPS
Internet of Things #SPICECORPS
Statistics More than 21 billion devices by 2020 IDC estimates 90% of all IT networks will have IoT security breach in next 5 years 70% of most commonly used IoT devices contain vulnerabilities (HP) 40% IT pros believe their network is unprepared to find connected IoT threats 37% of IT pros unable to determine number of connected IoT devices on network #SPICECORPS
Top Device Threats 2016 BYOD and customization of corporate hardware Mobile hotspot vendors Insecure, misconfigured, or vulnerable IoT devices 56% of HP printers deployed “open by default” Insecure devices used as backdoor into network Unauthorized or misconfigured APs 35% of APs in last 6-12 months show weak or no encryption #SPICECORPS
Malware Tools & Resources #SPICECORPS
Spiceworks Outbreaks Guide https://community.spiceworks.com/security/threats-vulnerabilit ies-malware Spiceworks SNAP! https://community.spiceworks.com/originals/snap VirusTotal http://virustotal.com Sandboxie ( 52/yr commercial, 21 personal) http://sandboxie.com #SPICECORPS
Webroot #SPICECORPS