From her blog Adesso Albums entitled,
"Authorize.NOT"
Friday, July 3, 2009 by Lesley Mattos
About 11:00 p.m. Pacific last night, there was a fire in the data center in Seattle, Washington where the credit card processing company for our e-commerce site is located. It was almost 12 hours before Authorize.NOT, as I like to refer to them now, resolved the issue but it took them 9 of those hours before they reached out to their customer base through Twitter.
The scary thing about this is that the Companys back up servers were impacted by the fire as well. Now I'm a very (VERY) small business compared to Authorize.net and even I know that redundancy means more than one copy of your important data and more than one place for it to reside. For God sake, they're the #1 credit card processing company in the world, you'd think they'd know that too!
Whoever is tweeting for them is now singing the praises of their response to the situation. The "tweet" - "Been on conf. call with the team for hours now. Impressed with how calm & meticulous they have been thru this entire event." Great. Next time try communicating that you've got it all under control the instant the issue arises so your customers aren't pulling up a blank website or calling a number that says the company is closed for the holiday weekend. Communicate with YOUR customers so that they can be proactive with theirs. It's not rocket science, it's just good customer relations.
Absent any information, here's what we did for our customers who were unable to complete purchases of our unique instant photo guest books to use for their wedding guest book, baby keepsake album, birthday or wedding shower guest book:
* We checked to see who had abandoned their shopping cart since the outage
* We sent an email to each of them, informing them about the outage and letting them know that we'd contact them again when the situation was resolved
* We offered them a 10% discount on their order when they did come back
The good news (and there always is some) is that I'd bet that someone has lit a firecracker under the "calm and meticulous" Authorize.NOT team are thinking long and hard over this holiday weekend about redundancy and beefing up their crisis communication plan. Let's hope so!
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Wednesday, July 8, 2009
Thursday, June 4, 2009
what NOT to do
Phishing and other scams are prevalent. I receive them from time to time.
In this real life story, one very intelligent friend of mine was duped, and her mistake is everyone's lesson in what NOT to do.
She received an email from Yahoo, her email provider, asking for your password, and thinking it was official, she replied. Mistake.
Yesterday morning I received this email from her (so did ALL her other email contacts, business and personal); typos in the quoted section appear as I received it:
I am in a hurry writing you this message i am sorry i didn't inform you about my urgent trip to London, i don't have much time on the pc here,so i have to brief you my present situation which requires your urgent response actually, I had a trip to London but unfortunately for me all my money got stolen at the hotel where i lodged due to a robbery incident that happened in the hotel.I had been so restless since last night cos i have been without any money moreover the Hotel's telephone lines here got dissconnected by the robbers and they are trying to get them fixed back i have access to only emails at the library because my mobile cant work here so i didnt bring it along,please i want you to help me with money so please can you send me 1,200 Pounds so when i return back i would refund it back to you as soon as i get home,I am so confused right now and dont know what to do,Please you can have it sent through Western Union Money Transfer so will get it immediately its sent but let me know if you can help me then i will make findings.please let me hear from you so i can give you my the address and name where you can send the money to today please.Its really urgent for me as i dont know what to do right now than to leave here soonest you send it to me and i'll pay you back immediately i get home..Thanks alot for your kindness,
I will really appreciate your quick response.
Best Regards
(I deleted her name to protect her innocence!!!)
I thought that a professional writer (which she is) would do a better job writing this and her husband would have sent the money if this were indeed a real situation. Besides we knew she was home and not in London.
But the annoyance of having to admit her error and the consequences to all her email contacts ruined her day. And don't you think she felt her online security was violated? Humor: she did admit that as a result of this scam email, she never knew she had so many friends who cared so much about her...silver lining?
Even if it seems official, forward that phishing email to abuse@(your ISP).com. They will track the bad guys down if they can. If they have time to...
So tell your friends, your kids, you parents, that what appears to be a legitimate, official-looking request for your email password is actually a scam designed to find one dummy in your email list who might just send the money to help you out in a panic, and enrich a scammer.
Be safe.
In this real life story, one very intelligent friend of mine was duped, and her mistake is everyone's lesson in what NOT to do.
She received an email from Yahoo, her email provider, asking for your password, and thinking it was official, she replied. Mistake.
Yesterday morning I received this email from her (so did ALL her other email contacts, business and personal); typos in the quoted section appear as I received it:
I am in a hurry writing you this message i am sorry i didn't inform you about my urgent trip to London, i don't have much time on the pc here,so i have to brief you my present situation which requires your urgent response actually, I had a trip to London but unfortunately for me all my money got stolen at the hotel where i lodged due to a robbery incident that happened in the hotel.I had been so restless since last night cos i have been without any money moreover the Hotel's telephone lines here got dissconnected by the robbers and they are trying to get them fixed back i have access to only emails at the library because my mobile cant work here so i didnt bring it along,please i want you to help me with money so please can you send me 1,200 Pounds so when i return back i would refund it back to you as soon as i get home,I am so confused right now and dont know what to do,Please you can have it sent through Western Union Money Transfer so will get it immediately its sent but let me know if you can help me then i will make findings.please let me hear from you so i can give you my the address and name where you can send the money to today please.Its really urgent for me as i dont know what to do right now than to leave here soonest you send it to me and i'll pay you back immediately i get home..Thanks alot for your kindness,
I will really appreciate your quick response.
Best Regards
(I deleted her name to protect her innocence!!!)
I thought that a professional writer (which she is) would do a better job writing this and her husband would have sent the money if this were indeed a real situation. Besides we knew she was home and not in London.
But the annoyance of having to admit her error and the consequences to all her email contacts ruined her day. And don't you think she felt her online security was violated? Humor: she did admit that as a result of this scam email, she never knew she had so many friends who cared so much about her...silver lining?
Even if it seems official, forward that phishing email to abuse@(your ISP).com. They will track the bad guys down if they can. If they have time to...
So tell your friends, your kids, you parents, that what appears to be a legitimate, official-looking request for your email password is actually a scam designed to find one dummy in your email list who might just send the money to help you out in a panic, and enrich a scammer.
Be safe.
Sunday, September 21, 2008
new law
On October 1st, 2008 a new law will be enforced in Connecticut.
In a nutshell, every business, nonprofit or other organization that requests private identification numbers
In a nutshell, every business, nonprofit or other organization that requests private identification numbers
- Social Security numbers
- health insurance numbers
- driver's license numbers
- credit card numbers, etc.
must encrypt them on their systems, limit access to them by employees who are in a need-to-know status, and post a policy on their website, intranet and on employee bulletin boards saying this is their policy.
To download my white paper on ways to implement this law and to protect yourself from most breaches, go to: http://marchalpert.googlepages.com/whitepaper_new_law_in_ct_01oct08.
Please feel free to share with others.
Tuesday, October 9, 2007
Response to our posting yesterday on the change of the law in Connecticut
Here's a response we just received to our posting on the new law in Connecticut (see posting dated 08Oct07):
That's EXACTLY the type of response that makes us feel this blog is worthwhile-helping one client at a time...
Please tell others about this law. It affects all of us in one way or another and other states are adding the law to their books.
If anyone has a question about best practices, please contact us for a no-obligation phone consultation.
Hi Marc,
thanks for the update on the new bill. I printed it off and will review to make sure we are covered. I believe we are doing most of the suggestions already. Your blog is great.
SC
thanks for the update on the new bill. I printed it off and will review to make sure we are covered. I believe we are doing most of the suggestions already. Your blog is great.
SC
That's EXACTLY the type of response that makes us feel this blog is worthwhile-helping one client at a time...
Please tell others about this law. It affects all of us in one way or another and other states are adding the law to their books.
If anyone has a question about best practices, please contact us for a no-obligation phone consultation.
Monday, October 8, 2007
The law in Connecticut has changed
Public service announcement to my Connecticut clients:
Connecticut Substitute Bill 1089 was enacted as of 01Oct07. It places the onus on each merchant, organization, or company to:
By adopting the credit card payment industry's PCI DSS compliance(Payment Card Industry Data Security Standard), you can make strides towards protecting yourself from this liability:
1. Install and maintain a firewall configuration on any computer to protect cardholder data-these are easy to get and free.
2. Do not use vendor-supplied defaults for system passwords and other security passwords-change them and make them as difficult as possible to guess or steal.
3. Protect stored cardholder data: lock up any receipts or paperwork that contains full credit card numbers and names, addresses, etc. When no longer needed, shred it!
4. Encrypt transmission of cardholder data across open, public networks-do not email this data under any circumstances.
5. Use and regularly update anti-virus software-this is obvious.
6. Develop and maintain secure systems and applications-document the security methods and stick to them.
7.Restrict access to cardholder data by business need-to-know: do not trust employees, in-house volunteers or temp workers with access to this information!
8.Assign a unique ID to each person with computer access-each employee should get an ID and password so you can track the access to this data if you had to.
9.Restrict physical access to cardholder data-lock it up or shred it
10.Track and monitor all access to network resources and cardholder data-again, be careful and question anything that looks suspicious. If you had a breach of security, the sooner you act on it, the better!
11.Regularly test security systems and processes-this helps protect you. Set a schedule to do this NOW so you do not forget.
12.Maintain a policy that addresses information security-write it down, have your employees read and agree to it.
While these steps will not completely protect you (nothing will), heightened awareness of the need to maintain security of personal financial data and documenting the precautions you have taken will avert the serious financial penalties you might otherwise face.
If you have any questions, please let us know.
Connecticut Substitute Bill 1089 was enacted as of 01Oct07. It places the onus on each merchant, organization, or company to:
- disclose any breach of personal financial data originating from your location to the authorities without unreasonable delay
- that party shall be liable to a bank whose customers’ personal financial data was compromised, for any costs, to protect their financial interests, including :
–Cancelling credit or debit cards or accounts,
–Closing any account or blocking any transactions,
–Opening or reopening any accounts,
–Refunding any account,
–Any assistance to customers.
(highlighting added for emphasis)
HOW DO YOU KEEP THIS FROM HAPPENING TO YOU?By adopting the credit card payment industry's PCI DSS compliance(Payment Card Industry Data Security Standard), you can make strides towards protecting yourself from this liability:
1. Install and maintain a firewall configuration on any computer to protect cardholder data-these are easy to get and free.
2. Do not use vendor-supplied defaults for system passwords and other security passwords-change them and make them as difficult as possible to guess or steal.
3. Protect stored cardholder data: lock up any receipts or paperwork that contains full credit card numbers and names, addresses, etc. When no longer needed, shred it!
4. Encrypt transmission of cardholder data across open, public networks-do not email this data under any circumstances.
5. Use and regularly update anti-virus software-this is obvious.
6. Develop and maintain secure systems and applications-document the security methods and stick to them.
7.Restrict access to cardholder data by business need-to-know: do not trust employees, in-house volunteers or temp workers with access to this information!
8.Assign a unique ID to each person with computer access-each employee should get an ID and password so you can track the access to this data if you had to.
9.Restrict physical access to cardholder data-lock it up or shred it
10.Track and monitor all access to network resources and cardholder data-again, be careful and question anything that looks suspicious. If you had a breach of security, the sooner you act on it, the better!
11.Regularly test security systems and processes-this helps protect you. Set a schedule to do this NOW so you do not forget.
12.Maintain a policy that addresses information security-write it down, have your employees read and agree to it.
While these steps will not completely protect you (nothing will), heightened awareness of the need to maintain security of personal financial data and documenting the precautions you have taken will avert the serious financial penalties you might otherwise face.
If you have any questions, please let us know.
Subscribe to:
Posts (Atom)