An Overview of GDAP

January 29th, 2025 → 11:41 pm @ // No Comments

One of the biggest concerns in Cybersecurity today is that of making sure employees, third party vendors, etc. have all been assigned the optimal mix of rights, permissions, and privileges to conduct their everyday job tasks.  However, trying to do this is a lot harder than it looks.  For example, you do not want to give too much or give too little.  To help resolve this issue, Microsoft has come out with a new tool called “GDAP”. What Is GDAP? It is an acronym that stands for “Granular Delegated Administrative Privilege”.  It can be technically defined as follows: “It is a security feature that provides partners with least-privileged access following the Zero Trust cybersecurity protocol.” (SOURCE:  1). It contains two particularly important concepts: Least Privilege: This is where you assign an employee or a third-party vendor just enough rights, permissions, and privileges to do what they need to do and […]

Blog

Is Your Social Security Number Leaked? Here’s How To Find Out And What To Do Next

November 20th, 2024 → 10:02 pm @ // No Comments

By this point, most people’s Social Security numbers (SSNs), a.k.a. one of the most important pieces of data assigned to you, have found their way onto the dark web. Thanks to breaches at major companies, government sites and even health care providers, millions of SSNs are floating around in cybercriminal circles. It’s alarming, but is it really that big of a deal? Spoiler alert: yes, it is. Here’s why a compromised SSN can wreak havoc on your life, how to check if yours has been leaked and what to do if it has. Is A Leaked Social Security Number Really That Serious? Your Social Security number is a key piece of your identity, especially in the US. With just your SSN, a hacker can unlock a world of financial and personal information, allowing them to impersonate you, take out loans and potentially access sensitive accounts. Even if you don’t see […]

Blog

Bulk Emailing Pitfalls: Protect Yourself and Your Business

August 8th, 2024 → 11:59 pm @ // No Comments

Sending email marketing campaigns has become a must for any business, no matter how large or small they are.  But, sending emails en masse can pose serious problems to your business. These risks are reviewed in more detail in this article. What Are The Risks? Some of the major risks are as follows: Limits will be placed: If you go through the traditional Internet Services Provider (ISP), you are normally allowed to create as many email addresses as you need to and send as much email as you need to within reason.  But if you exceed beyond this threshold on a consistent basis, your ISP will simply view these emails as “Spam”, and mark them as such.  As a result, if any of them go through, it will be delivered at a much slower rate than normal.  Or in a worst-case scenario, they may not be delivered at all. Being […]

Business

Simplify Your CMMC L1 Self-Assessment with the KAMIND DIY KIT

August 2nd, 2024 → 11:08 pm @ // No Comments

Achieving Cybersecurity Maturity Model Certification (CMMC) Level 1 compliance is essential for organizations involved in the defense sector. However, navigating the requirements and ensuring readiness can be daunting and expensive. That’s where the DIY KIT for CMMC L1 self-assessment comes in. What is the DIY KIT? The DIY KIT is a comprehensive, cost-effective solution designed to help Organizations Seeking Certification (OSCs) prepare for CMMC Level 1 compliance. Created by trained CMMC experts, this Do-It-Yourself kit provides all the necessary tools and guidance to conduct a thorough self-assessment. Key Features of the DIY KIT Pre-Built Templates The KIT includes expertly crafted templates for policies, procedures, and assessment checklists. These templates are easy to customize, allowing you to tailor them to your organization’s specific needs. Detailed Work Instructions With step-by-step instructions, the DIY KIT simplifies the process of gathering and documenting evidence for compliance. Follow the clear guidelines to ensure all necessary […]

CMMC

Backdoor Attacks

February 28th, 2024 → 11:44 am @ // No Comments

Backdoor Attacks We all have heard, and perhaps even been a victim of a Cyberattack (hopefully that is not the case).  Some of the most common types of attacks that we hear of today are things like Phishing, Ransomware, Insider Threats, etc.  But there is another one that lurks out there, which has not appeared too much in the news headlines.  That is Backdoor Attacks, and they are the focal point of this article. What Is A Backdoor Attack? This happens when the Cyberattacker deploys a malicious payload on the backend of a system.  Through this, they will attempt to gain access to whatever they can via bypassing all of the normal authentication and authorization methods.  So rather than trying to waste time in hijacking your password, the Cyberattacker will try to penetrate in this “brute force” way so that they can get in as quickly as possible, without being […]

Cybersecurity

The Permission Creep Index

November 13th, 2023 → 8:27 pm @ // No Comments

One of the greatest risks to businesses today is the over-assignment of rights, permissions, and privileges to employees.  Therefore, CISOs, managers, etc. are all taught to adopt the concept of “Least “Privilege”.  This is where you give your employees just enough of what they need to conduct their daily job tasks, no more and no less.  To make this more effective to organizations, Microsoft has created a new tool called the “Permissions Management Dashboard”, and is further examined in this article. What Is It??? Essentially, it provides you with an overview of all of the permissions and even privileged accounts that your IT Security team has assigned to all of the employees in your company, What is unique about this tool is that it is not just native to Microsoft Azure, you can also use it to check the level of permissions that have been assigned in all of the […]

Cybersecurity

Setting Up The Session Border Control For GCC High

April 30th, 2023 → 7:43 am @ // No Comments

As you know, the GCC (Government Community Cloud) is a specialized type of Cloud deployment that allows defense contractors to secure datasets provided to them from the DoD.  GCC High, is a separate data center that meets the Government standard for security and is located in the Continental United States and managed by US citizens.  In one of our recent blogs, we examined how to deploy Audio Conferencing for this.  In this blog, we examine how to deploy the SBC (Session Base Controller) for it as well. What Is The SBC? It is acronym that simply stands for “Session Border Controller”.  In non-technical terms, this is the tool that is used to help protect and secure any VoIP based communications that you are engaged with.  A company that deploys a SBC has complete control over the VOIP data traffic and can secure the traffic as needed.  To deploy it, follow […]

Blog