Emerging GDPR

Chances are this affects your organisation

GDPR stands for General Data Protection Regulation, which will become law in May of this year. It tightens up on existing Data Protectionregulations. It does have implications for everyone on the web, but it also extends to your back office systems (so beyond your website and email systems and our relationship) where you have recorded in any form; personal information.

Right now I have not read it all. I will return with some recommendations or things to think about in late Feb or early March. In terms of your websites, there may be things you need to do. For any CRM (Customer Relationship Management System) or any database or method for recording personal information, you will be affected. So do not ignore it.

Information Commisioner Office

You can start by going to this link and reading the material there: ICO GDPR.

Online learning course

A colleague has also pointed out that there is a self guided course available for free which takes around 3hrs. I have not looked at this yet, but do check it out. Go to Future Learn.   I have not validated either of these yet. Do not pay anyone any money just in case there is a solicitation for money (unless you wish to). Guidance on the regulations should be available from multiple sources for free. I suspect that there will be a lot of FUD as well (Fear Uncertainty and Doubt) peddled by some consultants seeking to help you for a fee. So do take care. Continue reading Emerging GDPR

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Fast Secure Contact Form

Some of the websites I have built use a plugin called Fast Secure Contact Form. It was a very popular form handler highly regarded by users written by Mike Challis.  The plugin was sold to a third party in June of this year and the new owner attempted to manipulate the code in the plugin to set up adverts.

Please check ASAP whether the version that is currently in use on your website is version 4.0.56. You can do that by logging in, and going to the Plugins page and look down the list. You will see an entry similar to the one below which includes the version number.

If you have version 4.0.56 you are OK! Don’t panic. 

If your site is at an earlier version contact me immediately and I will sort out updating it. 

(update: 6:00am 27/9/17 Nobody has reported a problem so far, all sites have upgraded automatically. That was to be expected. If you cannot find Fast Secure Contact form another method is used for forms on your website. Probably Form Manager. You are not affected by this notice.)

Why is this important?

Continue reading Fast Secure Contact Form

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Is my internet slow?

Or…   the Onion of Discontent

There are many reasons why an internet connection may be slow, some of them will be directly under your control, and others will be under the control of the equipment manufacturers of the devices used that the communications pass through. The extent of which is from the device you are using to the server at the far end of the connection. Various services providers share the responsibility of carrying the traffic. It is a complex picture to reconcile.

Where is the problem?

When trying to establish where a problem exists the first person you call is your service provider (BT, Talk Talk, Virgin etc). They will follow a fixed trouble shooting process which will try to prove that the problem is something you are doing, or have done or is within that part of the network you control. They adopt this approach because if nothing is listed as a fault in your area, then statistically it is most likely to be something at your end.

That will include your router/ hub, your phone wiring, the building materials used in your house, the location of WiFi access points, the list is large. They will not be as direct as that, however those are the implications. Continue reading Is my internet slow?

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Phishing Page

What is it?

We have all read about phishing trojans, but many of you probably do not know what they are or how they work. I came across one over the weekend while backing up a client’s website. My anti virus system prevented me from downloading the backup to my computer and warned me that one was present. As I was concerned about the security of this particular website I took it apart to find out where it was, and what it was doing.

Phishing

Phishing refers to a form of identity theft, it is where credentials like a user name and password are compromised, often without your knowledge. Other than reading about them, I had not come across one before. This one relates to stealing the credentials to access someones email address and email password.

I turned off my anti-virus (not recommended if you do not know the risks) and downloaded the zipped folder containing the files into a special area on my computer and then inspected the files. Two files contained code, one was a web page. Only one of the files was being flagged as the one containing the Phishing Trojan, the file contents were very simple, they packaged up the information and sent out an email to two recipients.  Continue reading Phishing Page

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Two Scams to be aware of…..

I have come across two scams this week targeting small regional charities, one about domain registration, I came across several years ago, but it looks like it is still going on. The first is encouraging you to call a premium rate number.

Scam #1  Contact me message

You all have forms on your websites, and you usually get legitimate enquiries on these forms. Do however check the contents in a message and if the only way you can contact someone is via a premium rate number then don’t bother calling. If the content is virtually non existent like this one below, it is encouraging you to call a premium rate number. In this particular case I checked the number through a web search. This individual is sending messages to websites through contact forms.  So if 10 people call back then that is £1+ they have made depending on how long they keep you on the phone, you would not know what their premium rate is prior to calling.

If you are not sure, type in the following into a Google Search form:  who called me 08712771062  (Obviously substitute the number you wish to check. In this particular case it took me to this page: http://who-called.co.uk/Number/08712771062 if you read the reported cases there, you can see the depth of the scam and other people’s comments.

Normally anyone contacting your organisation will provide more information in the form for you to process and not leave a short message like this.

Scam #2  About your domain name

In many cases I am looking after your domain names, so if you get anything like this send it to me, it is a bit more subtle than the previous one. In general domain names are registered to organisations and that registered information can be located on the internet. So a determined third party can find it and then contact you. This is how the domain scam works: Continue reading Two Scams to be aware of…..

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Group Calendar

I have been asked on a number of occasions is it possible to have a group or office shared calendar. The problem is generally those people who are used to using Outlook in a business context have used an Exchange Server which managed all of the calendaring functions for you. In a charity situation, particularly a small regional one, it is not very likely that your charity uses a Microsoft Exchange server. The calendar management needs to be handled at a central point such as a server.

I received a request about a group calendar a few days ago and did some digging and have come up with a solution. So if you are interested in having an office calendaring system that is online, that your volunteers and office staff can log into then this may be for you. Continue reading Group Calendar

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Good Catch ESET

Here it is a bit closer:

I have recommended to quite a few of my clients the benefit of using both an antivirus program and a personal firewall. The products I have used for around 20yrs now are from ESET.  I currently use Smart Security.

It simply runs in the background and checks things for you. I frequently use mxtoolbox.com to check out information relating to websites. I went to one just now and in my haste typed in mextoolbox.com (there is an e in there that should not be in there). A sharp hacker has taken out that domain name and used it to hide a virus. It was detected as I opened the webpage.

If you just use a free AV product, this would not have been detected. Many of the charities I work with have no AV, or free AV products. I consider myself to be very careful on the web. But even I can make a mistake.

I recommend Eset Smart Security to protect your Windows computer. You can find out about here:  https://www.eset.com/uk/home/smart-security/

As a charity you can get it heavily discounted, and if you buy more than one or multiple licenses then it is even lower cost.

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail

Wannacry Ransomware

On Friday the 12th of May a large cyber attack occurred infecting computers all around the world. In the UK, many NHS systems were affected bringing IT systems to a halt. Researchers indicate it is not clear why this particular event occurred so quickly, it is unlikely to simply be people clicking on links in emails, which is one way these viruses end up on computers. One researcher accidentally found a “Kill Switch” for this virus on Friday afternoon which stopped computers encrypting disks around the world. So while this last major event stopped pretty soon after it started, other variants have already appeared, but have not propagated as quickly as the one on Friday.

I have visited a few of my clients over the years, because of the nature of the business and the low IT budget, computers are often old and frequently not up to date. Another feature is some do not have any anti-virus software running on them either. These circumstances can leave you open to an attack of this type and many other less crippling viruses.  Continue reading Wannacry Ransomware

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail