Free HIPAA Risk Awareness & Compliance Survey

Free HIPAA Risk Awareness & Compliance Survey

If you are in the healthcare business you have HIPAA compliance requirements to adhere to. Maybe you are not aware of what they or maybe you just want to gauge your organization’s readiness prior to seeking professional help? We have provided a short survey quiz that will give you a score and some suggestions. The HIPAA Awareness & Compliance Survey helps to determine your office’s degree of HIPAA compliance and awareness.
Free HIPAA Awareness & Compliance Survey
It’s free so take a minute or two and get your score.

[WpProQuiz 2]

We want to be your provider and assessor of choice for all of your HIPPA needs! For additional information please contact us using the form below or call us at 1-888-896-6207.

Schedule some time with our HIPPA Risk Compliance Superheroes!

Error: Contact form not found.

The Citadel Breached – The Cyber Security Act of 2015

Continuum GRC unveils the next generation of cyber-crime prevention for organizations with NIST and SEC, NFA compliance requirements in concert with the Cyber Security Act of 2015.

Continuum GRC released the next generation antidote to fight cyber crime, compliance failures, corporate fraud and criminal cyber-misconduct with the IT Audit Machine (ITAM IT audit software).

Continuum GRC releases the next generation of cyber security crime prevention addressing breach epidemic in concert with the Cyber Security Act of 2015.

Considered to be the best assessment tool for governance, risk and compliance (GRC) in the global business community in compliance with the Cyber Security Act of 2015, this next generation of ITAM IT audit software ups the ante by managing big data and frameworks with virtually endless possibilities. These new enterprise capabilities coupled with the already powerful analytic and logic features are a technological force to be reckoned with.

Congress & President Obama recently enacted a cybersecurity piece of legislation known as the “Cybersecurity Act of 2015” which is designed to ensure that public companies “provide a basic amount of information about the degree to which a firm is protecting the economic and financial interests of the firm from cyber-attacks” using guidance from the SEC, NFA and the National Institute of Standards and Technology (NIST).

In addition, the Cyber Security Act of 2015 strengthens and prioritizes cybersecurity at publicly traded companies by encouraging the disclosure of cybersecurity expertise, or lack thereof, on corporate boards at these companies. This legislation requires companies to disclose – in their SEC, NFA filings – whether they have a director who is a “cybersecurity expert” – and if not, why having this expertise on the board isn’t necessary because of other cybersecurity steps taken by the company.

The Cyber Security Act of 2015 would require the SEC, NFA and the National Institute of Standards and Technology (NIST) to provide guidance on the qualifications necessary to be a cybersecurity expert.

Michael Peters, CEO of Continuum GRC said “The IT Audit Machine NIST and SEC, NFA compliance assessment modules are just one of the many innovations from Continuum GRC that really sets us apart from other cyberspace Security, governance, risk and compliance software firms.”

The top sources for learning more about the threatscape for cyber security since 2005 has been the Privacy Rights Clearinghouse and a similar industry analysis resource is the Identity Theft Resource Center who have only been tracking cyber security breach statistics since 2014. Continuum GRC has been leading the charge since 2000 when the company introduced the concept of Proactive Cyber Security™ to the world.

Annual number of data breaches and exposed records in the United States from 2005 to 2015.

When the majority of cyber threats are waged against the SMB space and a whopping 60% of those companies will be out of business within six (6) months post breach, we are understandably sympathetic to the rising level of despair company leaders and the board is suffering with.

“Are we next? That is the big question being asked more frequently now at the board level.” Said Peters

This second chart shows the percentages by industry where the cyber security data breach threats are being most successful.

Annual number of data breaches and exposed records by industry in the United States from 2005 to 2015.

NIST regulations are complex and expertise in deciphering this regulatory mystery is in short supply which is one reason ITAM IT audit software is such a great solution. Continuum GRC removed the guesswork from compliance completely. With intuitive and guided questionnaires you cannot make mistakes and missteps putting your company at risk.

Gone are the days where audits, assessments and compliance work was overshadowed by endless spreadsheets, version control madness, escalating costs and audit anarchy. The IT Audit Machine puts the power of technology, collaboration and simplicity to work for the entire enterprise and does it in a progressive, proactive way.

Cyber-crime prevention is of paramount concern to organizations of all sizes, all industries and on all parts of the world. Continuum GRC put its extensive experience in cybercrime and fraud prevention in the governance, risk and compliance (GRC) spaces to work for the global business community.

“Service providers globally are under increasing attack by cyber criminals. These criminal acts could have been prevented through a proactive cyber security position. Continuum GRC is proactive cyber security with our NIST compliance and assessment automation modules and templates.” said Peters.

Continuum GRC’s primary purpose is to help organizations attain, maintain, and demonstrate compliance and information security excellence, in any jurisdiction. Continuum GRC specializes in IT security, risk, privacy, governance, cyberspace law and compliance leadership solutions and is fully dedicated to global success in these disciplines.

Learn more about Continuum GRC and why Continuum GRC is Proactive Cyber Security™!

Download the whitepaper!

Have a question or want to schedule some time with our Superheroes?

[bpscheduler_booking_form]

Human Hacking, Not Automated Attacks, Top Cyber Threat

Human hacking, also known as social engineering, has surpassed hardware and software vulnerabilities and is now the top cybersecurity threat, Computer Weekly reports:

Human hacking, also known as social engineering, has surpassed hardware and software vulnerabilities and is now the top cybersecurity threat.

[A]ttackers shifted away from automated exploits in 2015. Instead, attackers engaged people through email, social media and mobile apps to do the dirty work of infecting systems, stealing credentials and transferring funds.

 Researchers found that machine exploits were replaced by human exploitation, with attackers opting for attachment-based social engineering campaigns rather than purchasing expensive technical exploit kits.

 Across attacks of all sizes, threat actors used social engineering to trick people into doing things that once depended on malicious code.

What is Human Hacking?

Human hacking is a type of con during which, instead of trying to hack into a system, the hacker engages in old-fashioned espionage techniques that involve human interaction and prey on weaknesses in human psychology, such as helpfulness, curiosity—even greed. A human hacker may approach an access-controlled door carrying a number of packages and pretend to fumble for their key or access card; an unsuspecting employee, thinking they are being helpful to a co-worker, opens the door for the hacker. This technique is known in the industry as tailgaiting. Or, using the pretexting technique, the hacker may phone an employee, pose as a help desk worker, and attempt to get the employee to provide their system access credentials.

These simple techniques are surprisingly effective. TechTarget reports that a human hacker recently used pretexting to compromise the U.S. Department of Justice. The hacker phoned the DOJ, pretending to be a new employee who was having difficulty accessing the department’s web portal. The hacker was quickly provided with a token that granted him full access to the DOJ intranet. As a result, information on 20,000 FBI agents and 9,000 Department of Homeland Security employees was publicly leaked.

Other common human hacking techniques include:

  • Baiting takes advantage of human curiosity—or, in some cases, greed. The attacker puts a legitimate-looking and interesting label (such as “Employee Salary Report Q4”) on a malware-infected device, such as a USB drive, then leaves it in a place where someone will find it, such as a bathroom, a hallway, or an elevator. Then, the hacker simply waits for someone to pick up the device and insert it into their computer.
  • Phishing is a technique most Internet users have seen in action. The hacker (or phisher) sends an email that appears to be from a legitimate source, usually a bank or another business. The email requests that the receiver “verify” information by clicking on a link and warns of dire consequences, such as their account being deactivated, if the receiver does not do so. The link leads to a legitimate-looking but fraudulent website that requests personal information, such as online banking access credentials or even a debit card PIN.
  • Spear phishing is a more targeted form of phishing where a particular individual or organization is phished, as opposed to random mass attacks.
  • A Scareware scheme combines malware and human psychology. The con involves tricking victims into believing they have downloaded illegal content or that their computers have been infected with malware. The human hacker then offers the victim a “fix” in the form of a download – which is actually malware.

How Can Your Organization Prevent Human Hacking?

As with all cyber security issues, the best defense is a good offense. Continuum GRC recommends that organizations take a proactive approach to preventing human hacking, beginning with establishing a comprehensive cyber security policy and employee training program. If employees are aware of the types of cons human hackers run, they can learn to identify and report them before any damage is done. Continuum GRC offers the fastest ticket to policy and governance readiness in the business.

Additionally, organizations that conduct ongoing risk assessments and fix the gaps identified are on average a whopping 96% less likely to suffer a breach by hackers. Continuum GRC recommends organizations of any size implement a risk management program sooner than later when it may be too late.

Continuum GRC offers full-service and in-house risk assessment and risk management subscriptions helping companies all around the world sustain a proactive cyber security program. Continuum GRC is proactive cyber security®. Call 1-888-896-6207 to discuss your organization’s cyber security needs and find out how we can help you prevent human hacking.