Blog

  • Improving RIA compliance with Microsoft Compliance Manager

    Improving RIA compliance with Microsoft Compliance Manager

    Not all RIA firms have the labor force and resources to focus solely on compliance like large corporations do. That’s why RIAs should be aware of tools like Microsoft 365’s Compliance Manager to help with their compliance needs.

    What is Microsoft Compliance Manager?

    Compliance Manager is Microsoft’s proprietary compliance management solution that you can access via the Microsoft 365 compliance center. This solution is designed to be an end-to-end service for managing and tracking compliance activities. On your first visit to the portal, Compliance Manager provides you with an initial assessment of your compliance posture, making it an excellent jump-off point for any RIA firm’s compliance journey.

    What is the Microsoft Compliance Score?

    The Microsoft Compliance Score is a measure of how much progress your RIA has made in completing recommended actions in your Microsoft system to improve data protection and regulatory compliance. It is not an absolute assessment of your total compliance profile, but it helps your firm substantially in meeting industry and legal requirements. Your Compliance Score provides an easy-to-digest snapshot of your RIA company’s compliance profile, so you can easily make adjustments and improvements as necessary.

    Related article: Check your RIA’s cloud security score

    How do I read my organization’s Compliance Score?

    Your Compliance Score is computed via the preventative, detective, and corrective actions your IT service provider has enabled on your Azure’s or 365 Suite’s Compliance Manager. Each action has a pre-assigned score based on its importance (mandatory or discretionary) and their role (preventative, detective, or corrective). The higher your RIA firm’s total score, the better your compliance profile.

    Here is a breakdown of the scores for each action type:

    Action type Score
    Preventative mandatory 27
    Preventative discretionary 9
    Detective mandatory 3
    Detective discretionary 1
    Corrective mandatory 3
    Corrective discretionary 1

     
    Mandatory actions hold higher weight, as they are based on real-world regulatory requirements. Preventative actions also rank highly in terms of Compliance Scores, as they help ensure that your RIA firm is addressing its compliance needs before implementation, thus preventing the need for detection or correction.

    How does Compliance Manager help RIAs?

    If your system is properly configured with as many preventative mandatory and preventative discretionary actions as possible, there will be little need for detective and corrective actions. This proactive stance should be adopted, as it makes the tedious process of compliance less overwhelming.

    Related article: Staying SEC-compliant with Microsoft’s email archiving

    It also saves your team the headache of going through painstaking lengths of checking each document and transaction for compliance and completeness. With a properly configured Azure/365 system, they won’t need to scrutinize every step of each file, as the system does it for them. This type of automation is a tried and tested way to eliminate errors and improve compliance for any RIA.

    Enhance your RIA’s compliance with Compliance Manager, available with your Microsoft Azure or 365 software. It works best when configured properly — which our highly trained technicians can do for you. Contact us today so we can assess your system and correctly integrate Microsoft Azure or 365.

  • Man-in-the-Middle Attack –  SCAM OF THE MONTH

    Man-in-the-Middle Attack – SCAM OF THE MONTH

    Mina was traveling abroad and enjoying a life-changing cultural experience. She was always on the go, taking in all the city sights she could see while updating her blog along the way. To make her blog upload efforts easier, Mina set her phone up with the AutoConnect feature so she could automatically connect to any Wi-Fi network that she’d previously connected to. Mina took a break at a Sam’s Cafe and her phone connected to the “SamsCafe” network. She began updating her blog then realized she needed to check her bank balance. She used her phone and logged into her bank’s mobile website to review her balance. A few hours later, Mina received a message from her bank that her account had insufficient funds and it had been wiped out earlier that day.

    Did you spot the red flags?

    • Mina turned on Auto-Connect in an effort to save time accessing the internet.
    • Mina connected to her banking portal while on an unsecured Wi-Fi network.
    • Mina failed to verify the legitimacy of the Wi-Fi network she was connecting to.

    What you should know about this scam

    Avoid Auto-Connecting/Auto-Joining free Wi-Fi networks. When you use this feature, your device remembers a specific SSID (Service Set Identifier) for a network. Scammers can create their own fake Wi-Fi networks and set their own SSIDs to mirror the account they are mimicking. So, your device will be connecting to a verified SSID but it will be one owned and managed by the scammer.
    This is an example of a Man-In-The-Middle Attack where an attacker uses their technology to position themselves between their victim and the platform they are connecting to. By remaining in the middle, the attacker can watch, record, and manipulate their target’s activity, without them knowing. Thus, the websites visited and passwords entered can be easily observed or the attacker could direct their victim to a malicious webpage.

    Protect yourself

    1. Try using a VPN (Virtual Private Network) to help create a secure connection.
    2. Use legitimate Wi-Fi connections that you can verify.
    3. Set up Two-Factor Authentication on critical accounts.

    Even with these additional security layers, the best approach is to avoid accessing sensitive accounts and information when on a public Wi-Fi connection.

  • What is endpoint security and is your RIA on top of it?

    What is endpoint security and is your RIA on top of it?

    Cybersecurity is critical for modern organizations but even more so for RIAs and other financial services providers. Not only do you have to steer clear of opportunistic cybercriminals, but you must also proactively comply with the increasingly stringent requirements of both the US Securities and Exchange Commission and the Financial Industry Regulatory Authority when it comes to protecting valuable data.

    Fortunately, there are plenty of solutions that you can tap into to mitigate cybersecurity risks and increase the security of the sensitive information you handle. One of these security solutions is endpoint security.

    The importance of managing and securing endpoints

    Your RIA probably has a mix of office-based, remote, and hybrid workers who are using their personal and office-issued devices to work from anywhere. Although this practice increases work flexibility, failing to implement proper endpoint protections poses substantial security risks.

    Using unsecured endpoints, even if it’s just to send an email or to access sensitive business information, leaves your RIA’s data vulnerable to theft and other cyberthreats. This is especially dangerous considering that cybercriminals often start with the weakest link in the security chain: the end users.

    Having a centrally managed endpoint security system is a great defense against a wide array of threats and advanced targeted attacks.

    What is endpoint security?

    Endpoint security protects the data and workflows stored in or used by all the desktops, laptops, mobile devices, and other remote computing devices that connect to your network. It is achieved by using endpoint protection technologies — such as antivirus software, data encryption, intrusion prevention, and data loss prevention — to detect and stop a variety of threats before they even enter a network.

    Implementing endpoint security often involves deploying an endpoint protection platform (EPP) on end-user devices. Doing so allows your IT services provider to remotely control security for every device from a centralized console. From there, they can roll out updates, authenticate login attempts, block unsafe or unauthorized apps, and encrypt data on individual devices to prevent data loss.

    Related reading: Hiring an IT Services Company for your RIA? Here are the things you should know.

    What are the benefits of endpoint security?

    Aside from protecting end-user devices, endpoint security provides a host of other benefits:

    1. Increased visibility – With a next-gen EPP, your IT services provider can discover all of the devices connecting to your network and, consequently, address potential vulnerabilities before cybercriminals can exploit them.
    2. Cost savings – Endpoint security proactively prevents cyberattacks, which keeps you from spending on remediation efforts and other related expenses. It also aids in device performance, which can translate to greater productivity and even bigger cost savings.
    3. Time savings – Using an endpoint security solution streamlines the management and prevention of online threats, which frees up your staff to focus on core business objectives.
    4. Better compliance – Many industries are governed by data privacy and security regulations. Financial services providers, especially, require special precautions to ensure the safety and integrity of private client information and valuable business data and protect against fraud.

    It’s crucial to manage and secure all the devices used by your employees for work-related matters. Fortunately, with the right combination of endpoint protection tools, your IT services provider can manage endpoints using an approach that’s right for your RIA. For example, they can implement multifactor authentication to validate user identities and grant access to particular apps, like their emails or Microsoft Teams.

    Your IT services provider can also choose to take full control over company-issued devices. For example, from the centralized dashboard of your EPP, they can set password and PIN requirements, establish a secure connection via a virtual private network, install security software, and do much more to protect your RIA’s endpoints.

    Improving endpoint security not only secures your RIA but also enables your team to communicate and collaborate effectively and improve productivity across the board. Contact us today!

  • Securing your RIA’s cloud apps

    Securing your RIA’s cloud apps

    Are you aware of all the devices, apps, and other technology your staff use for work? From personal smartphones to social media apps and productivity software to mail services and personal cloud storage, it’s possible that the employees at your RIA firm are using devices, software, and services without the knowledge of management or your IT services provider.

    The use of these unvetted solutions is referred to as shadow IT. While these seemingly harmless technologies help employees manage their time more efficiently, complete tasks faster, and communicate easily with coworkers and clients, using them without notifying IT comes at a price. Doing so exposes your RIA to a wide variety of risks, especially when sensitive data is processed in cloud-based apps or storage platforms.

    With data breaches happening every day, it’s crucial for financial firms and similar institutions to mitigate the risks of shadow IT. For RIA firms, it’s not only important to protect data, devices, and applications, but it’s also necessary to configure and deploy security controls and policies to adhere to stringent regulatory compliance frameworks.

    A cloud access security broker (CASB) like Microsoft Cloud App Security can help your firm manage these risks, meet regulatory compliance requirements, and more.

    For RIA firms, it’s not only important to protect data, devices, and applications, but it’s also necessary to configure and deploy security controls and policies to adhere to stringent regulatory compliance frameworks.

    But first, what is a CASB?

    A CASB is a security app that acts as an intermediary between users and cloud applications. It is essentially a control point for your IT team to monitor all cloud programs, apps, files, and data that your team uses or handles.

    A CASB comes with a suite of security functions, such as:

    • Data loss prevention (DLP) – ensures that sensitive data across files, devices, and cloud apps and storage is not lost, misused, or accessed by unauthorized users
    • File-level encryption – translates data into an unreadable code that can only be read by users with a special encryption key, securing files before they even reach the cloud
    • Two-factor authentication – enhances the security of the user authentication process by requiring information beyond a simple username and password combination
    • Single sign-on – allows users to log in once and access multiple apps without needing to re-enter authentication factors
    • Access control – enables IT administrators to revoke access to files, devices, or accounts should an employee leave the company or should a device be lost or stolen
    • Auditing – lets IT administrators check if users are handling data on cloud solutions securely and take action on unauthorized activity
    • Enforcement – allows IT administrators to monitor user activity in real time, detect usage patterns, and identify unusual behavior

    With a CASB, your IT team can identify, assess, and manage shadow IT, protect data in vetted apps, and mitigate various online threats.

    Microsoft Cloud App Security

    Microsoft Cloud App Security is a CASB that provides organizations with enterprise-grade visibility, control, and protection for all the cloud-based apps and services they use. It makes security easier and more transparent through centralized management and automation.

    In particular, Microsoft Cloud App Security helps your IT team to:

    1. Discover and control shadow IT use

    Microsoft Cloud App Security has a catalog of over 17,000 public cloud apps. Your IT team can use this to discover which apps are being used by your team and the risk level of each. This makes it easy for your IT team to manage shadow IT and ensure the security and compliance of your firm’s cloud apps.

    2. Safeguard your data in the cloud

    With a unified and holistic view of your cloud apps, your IT team can easily manage data (whether at rest or in transit) in Microsoft Cloud App Security. They have the ability to search for sensitive files and then choose to control and protect them, keep them from being shared externally, or notify file owners if files are being shared inappropriately. Your IT team can also apply security controls across all your sanctioned cloud apps in real time.

    3. Protect against threats

    Threat protection from Microsoft Cloud App Security alerts your IT team of unusual behavior or risky activities in your cloud environment, allowing them to identify risks such as ransomware, compromised users, or rogue applications. It then helps them automate responses to incidents and limit the risks to your firm.

    4. Assess the compliance of your cloud solutions

    Like all Microsoft cloud products and services, Microsoft Cloud App Security is designed to address rigorous security and privacy demands. It can help your IT services provider assess if your cloud apps comply with relevant laws, policies, and regulations. The complete list of Microsoft compliance offerings can be found here.

    If you need help in securing your cloud environment or want to learn more about Microsoft Cloud App Security, get in touch with our experts today. We can provide your small- to mid-sized RIA firm complete solutions for the security, support, and management of your IT infrastructure.

  • Microsoft 365 E5 provides Identity Protection for your RIA

    Microsoft 365 E5 provides Identity Protection for your RIA

    The vast majority of security breaches today occur when attackers gain access to an IT environment using stolen identities or accounts. It’s therefore crucial that you monitor your RIA firm’s accounts and passwords to determine if they have been compromised. One of the best tools for this is Azure Active Directory (Azure AD) Identity Protection.

    What is Azure AD Identity Protection?

    Identity Protection is a feature that allows organizations to automatically detect, investigate, and remediate suspicious logins or users.

    Specifically, it looks for sign-in risks and user risks.

    Sign-in risks measure the likelihood that a sign-in attempt was made by someone other than the user. The red flags include:

    • Sign-ins from anonymous IP addresses
    • Sign-ins from malware-linked IP addresses
    • Sign-ins from atypical locations (e.g., when two or more sign-ins occur from distant locations within a short period of time)
    • Sign-ins with unfamiliar properties that have not been seen recently for a given use

    Meanwhile, user risks represent the likelihood that an account is compromised. These risks are often associated with unusual behavior (e.g., when an account shows unusual activity or when its usage patterns are similar to known attacks) or leaked credentials.

    While Microsoft does not provide specific details about how they calculate risk, they determine what qualifies as risky sign-ins by using learnings and data they acquired from Azure AD, public Microsoft accounts, and Xbox.

    Identity Protection comes with Microsoft 365 E5, Microsoft 365 E3 with the E5 Security add-on, EMS E5, or Azure AD Premium P2 licenses.

    Identity Protection policies

    With Identity Protection, your IT service provider can define whether a risk is low, medium, or high and determine the acceptable level of risk for your RIA firm. Then, they can set up alerts and automate responses or actions to identified risks through risk policies.

    There are different risk policies that your IT service provider can enable depending on the type of risk. A sign-in risk policy analyzes every user sign-in and gives a risk score based on the probability that the sign-in was not performed by the real account owner. Based on this score, Identity Protection can either block access, allow access, or allow access but require multifactor authentication (MFA).

    Once a sign-in risk is identified, the user is informed of what triggered the risk and what action they need to take to remediate the issue. They might receive this notification, for example:

    On the other hand, a user risk policy uses knowledge about a user’s normal behavioral patterns to calculate the probability that their identity was compromised. Based on this risk score, Identity Protection decides whether to block access, allow access, or allow access but require a password change using Azure AD self-service password reset.

    As with a sign-in risk, once a user risk is identified, the user is informed of what triggered the risk and what they need to provide to resolve the issue. They might receive this notification:

    Lastly, Identity Protection can help your firm implement an MFA registration policy that provides a second layer of protection to user identities by asking users to complete an additional verification step after entering their username and password. What’s great about enabling this policy is it ensures that new users are registered for MFA from the first time they log into their account.

    So after your IT service provider configures an MFA registration policy, Identity Protection will prompt your users to register for MFA the next time they sign in. The user will get this notification:

    They will have 14 days to complete the registration. During this two-week period, users can choose not to register yet still be allowed to use the service. After that, they will have to complete registration before they are allowed to sign in again.

    Investigating and remediating risks enables your IT service provider to identify weaknesses in your security strategy and understand how to improve your firm’s identity security posture.

    Investigating and remediating detected risks

    Once Identity Protection detects risks in your environment, it generates reports that your IT service provider can use to investigate the said risks. These reports contain information that can help your IT service provider make an informed decision as to whether they think the user is legitimate or the account has been compromised. Should your IT service provider decide that the case is the latter, they must take action to remediate the risks — that is if they’re not already using risk policies to automatically deal with these risks.

    Investigating and remediating risks enables your IT service provider to identify weaknesses in your security strategy and understand how to improve your firm’s identity security posture.

    Need help securing your RIA firm’s identities?

    We at RIA WorkSpace thrive and excel in helping small- and mid-sized RIA firms manage and secure their IT operations. Contact us today to learn how our customized solutions can help you better respond to identity risks and avoid them and other cyber risks in the future.

  • Protecting your data when a RIA departs the company

    Protecting your data when a RIA departs the company

    When employees leave, they are required to return all the company-issued items in their possession. These include all the data they had access to in the course of their tenure. This is especially important in the finance industry, as RIAs handle sensitive personal and financial data for their clients.

    But not only should your organization make sure these files are returned intact, you should also ensure that departing RIAs are unable to copy and misuse company files.

    Here are some important steps you should take so that business information remains uncompromised:

    Enforce data policies

    Data policies define how business data is handled before, during, and after any RIA’s tenure with your company. These are a documented set of guidelines that helps ensure all information assets are managed consistently and properly. It also dictates how your organization’s IT is configured. Your IT provider should already have configured your data system so that all documents and files adhere to the data policy automatically, so there’s no need to manually agree to every rule each time. Data policies are absolutely essential for RIA practices, as protecting your clients’ financial information is one of your most important responsibilities.

    Develop policies and procedures that should be followed by RIAs who are parting ways with the organization. Your IT provider’s preparation is critical at this stage, but none of these exit policies will matter if proactive steps — such as laptop preconfigurations and device management tool installations — were not accomplished.

    Aside from data policies, staff should also contain clauses about appropriate use of business information, company-issued devices, and other resources. For one, RIAs should be explicitly informed that any equipment and data that belongs to the company should not be compromised. Anyone departing the organization will need to surrender all company-owned devices and files before they will be allowed to exit.

    Deploy role-based access

    Maintaining the integrity of your information system requires being proactive. Access roles should be predetermined long before any employee is allowed to view and/or edit client and organizational data. Have your IT partner deploy role-based access control (RBAC) throughout your organization so that employees only gain access to files that they are authorized to view or change.

    RBAC can also be set to allow temporary access to certain files, making it not only a tool for security, but also for facilitating efficient task completion. And because RBAC tools on modern enterprise software like Microsoft Azure can be automated, they can help reduce administrative and IT work and improve compliance in one fell swoop.

    Related article: Microsoft Data Loss Prevention Tools for RIAs

    Prevent data loss

    Data loss comes in many shapes and forms. Including the potential that an exiting employee takes information with them when they leave. They may try to download, print, or email the information in order to have it available once they are no longer employed by you. This is why a thoroughly-configured data policy is critical to protection. Also, using tools like Microsoft Data Loss Prevention (DLP) will make sure your data policy is automatically enforced, eliminating the need for tedious, manual monitoring.

    For instance, Microsoft DLP can be configured to block access to files when an unauthorized user tries to access them. Or if an employee attempts to send emails containing restricted files, DLP can block the email and inform a compliance officer or manager of the attempt. Audits can also be done so that managers can check how files are handled by the people who access them. Audit reports can also be compiled to document email conversation flows and more.

    Lock down devices

    Lastly, make sure your RIAs’ devices are configured so that your IT provider can lock them down when necessary. Not all employee departures are amicable, so it would be wise to install programs and apps like Microsoft Intune, which will let your IT administrators remotely wipe or retire laptops when necessary. Installation and configuration of such apps can be mandatorily applied through your data policy, even if your company allows employees to bring their own devices.

    Related article: Bring your own device policy template

    Upholding the integrity of your business data should be your utmost priority. Doing so will put your clients at ease and help solidify your reputation as a trusted RIA practice. Protect your sensitive data with RIA Workspace’s RIA-specialized technologies. Contact us today to learn about our services.

  • Vaccine schedulers – SCAM OF THE MONTH

    Vaccine schedulers – SCAM OF THE MONTH

    Each month, we highlight REAL examples of tactics criminals are using RIGHT NOW to take advantage of you and your colleagues. We hope this will better prepare you when the next scam hits.

    Marcie had been waiting patiently for her chance to get the Covid-19 vaccine. When her time finally came, and her first does was administered, she wanted to share her excitement on social media. Marcie snapped a selfie holding up her vaccine card. The card didn’t contain much information, just her name, date of birth, and vaccine details. She posted the picture online and shared it publicly, not just with her friends.

    A week later Marcie received a call to book her second vaccine, but the scheduler said they need her government identification number and more personal information to complete the booking. Marcie obliged, not realizing she just gave away her information to a scammer.

    Did you spot the red flags?

    1. Marcie posted her picture publicly, allowing everyone to see it.
    2. Her picture contained valuable personal information which was used against her in a follow up scam.
    3. The scammer posed as a vaccine scheduler with knowledge from the simple image Marcie posted.

    What you should know about this scam

    Social media sites are great for sharing information with friends and family but watch what you post and to whom. Keep any posts containing your personal information private so only those in your circle can see them.

    Vaccination cards are wildly popular right now among the cybercrime community. They are being forged and sold through many online channels. The forged cards could be used by others to receive your second dose or provide additional information for scammers to use in their attacks against you.

    Although it may not seem like much, an image or post containing your personal details such as name and date of birth can be a goldmine for a cybercriminal. This information could be used for additional spear phishing attacks or identity theft.

  • Check your RIA’s Cloud Security Score

    Check your RIA’s Cloud Security Score

    As a registered investment adviser (RIA), you must protect the data and privacy of your clients. It’s not only an ethical obligation but also a professional one — RIA firms are required to have internal controls and programs that keep client data secure and compliant with federal securities laws.

    However, with rapidly evolving cybersecurity risks, it can be challenging to ensure that you have appropriate and sufficient protective measures in place at all times. Fortunately, there is a way to continuously and easily assess and improve your RIA firm’s security posture — with Microsoft Secure Score.

    What is Microsoft Secure Score?

    The vast majority of security breaches occur because of poor cyber hygiene. Sometimes, users misconfigure devices, fail to keep software up to date, recycle passwords, or simply don’t know how to spot potential security issues. This leaves an organization vulnerable to breaches and other cyberattacks.

    Secure Score provides you with visibility, guidance, and controls that help boost your security posture. It measures the extent to which your firm has adopted security controls across your Microsoft products, which include Microsoft 365 (and Exchange Online), Azure Active Directory, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Cloud App Security, and Microsoft Teams.

    Essentially, Secure Score tells you how well aligned your security configurations are with Microsoft’s best security practices. And based on your score, your IT staff can take specific actions to help strengthen your defenses against common attacks.

    How Secure Score works

    Secure Score determines what Microsoft services you use and creates an inventory of all the possible improvements that will keep your environment secure. You achieve points for the following:

    • Setting up recommended security features
    • Performing security-related tasks
    • Addressing recommended actions using third-party solutions

    Points are calculated daily, and as your firm implements more controls, your score increases accordingly. Some security configurations are more effective than others and are assigned more points, but keep in mind that not every security measure can work for your IT environment.

    Secure Score not only allows you to proactively uncover security vulnerabilities, but it also highlights the actions your firm can take to offset various cybersecurity risks. With this level of visibility and awareness, there’s a clear path your IT staff can take to ensure that your RIA firm is doing everything it can to keep your clients’ information safe.

    How to check your current score

    You can access Secure Score’s centralized dashboard in the Microsoft 365 security center. To check your current score, click the Overview tab and find the tile that says Your secure score on the first column. Here, you’ll see your score as a percentage value and how many points you’ve achieved out of the total possible points.

    Take action to improve your score

    In the Improvement actions tab, you’ll see the various security recommendations and their corresponding status (e.g., to address, planned, completed). When you select a specific improvement action, it opens a page that shows detailed steps on how to implement that particular recommendation. It also presents any license prerequisites, potential user impact, and affected users.

    While the recommendations you receive will depend on your service subscriptions and your security needs, there are five key actions your firm can take to increase your score and security. These are:

    • Enable multifactor authentication.
    • Password-protect all mobile devices.
    • Enable audit data recording.
    • Disable inactive accounts.
    • Limit the number of admins you have.

    Don’t fret — your IT staff will take care of monitoring and improving your Secure Score. You don’t have to drill into the details yourself. What’s important is that you work with them to determine which improvements are most crucial to increasing your business’s cloud security score.

    If you need help securing your environment or want to learn more about Microsoft Secure Score, contact us today. We provide complete solutions for securing, supporting, and managing the IT infrastructure and operations of small- to mid-sized RIA firms nationwide.

  • “Can’t view the content? Please click Enable Editing.” SCAM OF THE MONTH

    “Can’t view the content? Please click Enable Editing.” SCAM OF THE MONTH

    Each month, we highlight REAL examples of tactics criminals are using RIGHT NOW to take advantage of you and your colleagues. We hope this will better prepare you when the next scam hits.

    Paulo doesn’t know much about the tax process and generally fumbles though it. One day, Paulo received an email from his local tax agency with an important message about an error in his 2020 taxes. As this was one of his concerns, Paulo panicked and proceeded to pen the attached Word document. The file that opened was blurred out and impossible to read, but the text on the document read “Can’t view the content? Please click “Enable Editing” and “Enable Content” on the yellow menu bar.”

    As instructed, Paulo clicked these buttons. The blurred image did not improve but rather Paulo unleashed a powerful malware that took over his computer.

    Did you spot the red flags?

    • 1. The supposed local tax agency sent Paulo an email with important tax information. Most reputable tax agencies will not use email to send or request sensitive tax material.
    • 2. The file Paulo opened had unreadable content, prompting him to “Enable Editing” and “Enable Content”

    What you should know about this scam

    Enable Editing, Enable Content, and Enable Macros are common tactics used in phishing campaigns. The scammer can easily design their malicious attack within a Macro. When their victim clicks on one of these prompts, they are allowing the malware to run, unleashing it on the device.

    This particular attack, when enabled, will release Remote Access Trojans, also known as RATs. When activated, the attacker can take control of their victim’s device and steal sensitive information. Consistent with other attacks, these threats are designed to stay under-the-radar, making them more difficult to spot and stop by prevention tools.

    This scam is very real and happening as we speak. Cybercriminals are able to purchase the tools to achieve these scams for a low price, and their purchase even includes a customer service support line! Watch for this or similar attacks this tax season and warn friends and family.

    There are tools that can help protect you from phishing scams like this, and they just might be part of your current Microsoft subscription. Check out our blog “Advanced threat protection features ideal for email security at RIAs” or contact us for more information.