Come 2018 and evaluating IT effectiveness has gone well beyond just whether the lights are still on. Reliability is still critical – more so than ever, in a world where much of our business information resides only in server databases and customers expect service within thirty seconds rather than thirty days. But when every business in the marketplace is using similar software tools and network configurations, mere operability is no longer sufficient to justify the never-ending stream of funds that go into IT services.
Modern IT has a multitude of functions. Listing just a few of the most obvious would include:
All of those functions have costs, and they all have benefits, but stopping at asking whether the business is still operating is too low a benchmark. In the modern business environment, every element of a business needs to justify its costs. From human resources to physical infrastructure, every employee and every branch office must return value to the business. IT should not be any different. So the question should not be “Is everything working?” The question that should be asked is “What value does IT bring to the business?”
Answering this question requires us to classify IT in terms of the outcomes it should be delivering. In general terms there are six key deliverables from business IT:
To these three factors of every-day IT we can add three more:
Each of these deliverables can be framed in a way that is measurable, and that means we can put KPIs around them.
Speed, quality and cost are the important measures, but optimising one normally comes at the expense of the others. Compromises must always be made, and context will dictate whether speed, cost or quality is the primary requirement.
To the three core metrics can be added a fourth: customer satisfaction. A business’s information technology function functions as a business unit, and the clients are your own employees. Even if the IT function is entirely reliable and well within costs, poor employee satisfaction can still impact the effectiveness of IT and the business as a whole.
IT costs include the costs of labour and personnel; subscription costs for software, online services and information resources; one-off costs for software licenses; and hardware costs. The business should establish an IT budget baseline and measure performance on an ongoing basis.
Speed can be measured in terms of how quickly issues are identified and addressed. In the case of special projects and development functions, speed can measure how quickly requests and projects are delivered.
A business can set SLAs for response and recovery to outages. You don’t want to ever put these measurements to the test, but you can perform test runs to estimate required times without interrupting business operations for real. In the case of special or development projects, the KPIs can be set for the time between scoping meeting / signoff and delivery / go-live of the finished product.
Quality is measured in terms of how well software and services meet business needs, and measures both fit-for-purpose and reliability. Software that never breaks but is difficult or unpleasant to use might still score poorly in terms of quality.
We can attempt to measure the effectiveness of any specific software tool or ERP system by listing the primary functions an application performs. Then, if any of these functions are unavailable, the application is considered ‘down’ even if most of the application is usable.
Whatever the approach taken, it’s important to be specific in what is being measured. Both IT departments and business management get frustrated when network issues are simply defined as “we are experiencing slowdowns.” One technique to solve this problem is to document workflow steps or screen transitions and define target speeds for rendering each screen. This allows actual performance to be compared to this goal. The percentage of time the goal is hit provides a good indicator of the customer service level (CSL).
How successful is IT from the perspective of the end customer? Measuring customer satisfaction can be done informally through anecdote, but as with all measurements the more specific your measurement methodology is, the more actionable and reliable the outcomes will be. Some companies have gone so far as to implement an internal IT Customer satisfaction surveys for staff.
]]>Recently Microsoft made an announcement concerning the future of Microsoft Office. Microsoft Office is still the de facto productivity suite for business, so any changes Microsoft makes have the potential to affect millions of business users. Almost certainly, your own business relies on MS Office software.
In the past, buying software was as simple as purchasing a boxed product. After that you owned the software and could install and use it as long as computers still have CD-ROM drives. However, selling a single copy of a piece of software is not ideal for a software company reliant on constant sales. Thus we have seen many companies shifting to a subscription model for their software. Adobe’s Creative Cloud, MYOB accounting software and Symantec Internet Security are just a few examples of products offered either optionally or only in an online subscription model. Microsoft’s push to move customers onto their cloud offering Office 365, and Office 365 software subscription, follows in the same vein. According to Gartner, “By 2020, more than 80 percent of software vendors will change their business model from traditional license and maintenance to subscription.”
Likely your business still has perpetual license Office software in use, whether that’s Office 2007 or 2016. In many cases, businesses acquire their copies of Office along with the workstations in an OEM (“Original Equiment Manufacturer”) model. Under this model, the software is installed on the computer for the life of the hardware but not transferable to another computer. A computer’s normal hardware lifetime is between four and five years. By the end of a computer’s lifetime, any software it comes with is likely to be towards the end of its life. With a new version of Office available every few years, by the time any computer was replaced there would be a new version of Microsoft Windows and a new version of Office available.
At the same time, Microsoft has changed not just the way it provides Windows and Office, but also how it releases new versions. Microsoft calls Windows 10 “the last version of Windows”, because instead of planning a “Windows 11”, it intends to roll out biannual feature updates to the existing software. The latest version of Microsoft Office, “Office 2016”, is being treated in a similar manner. Whilst Microsoft has said that it will release at least one more version of boxed-product perpetual license Microsoft Office, those on Office 365 subscriptions will always have the latest version.
However, it must be understood that many businesses stretch the working life of their computer hardware out by reassigning computers between users depending on their computing needs. The truth is that a four-year-old computer is more than capable of running basic business software, such as Microsoft Office, for many years beyond its recommended lifetime. Accordingly, many small-to-medium businesses have a mixture of new and older computers running a variety of software versions.
If your business is still running Windows 7 computers with Office 2010, these will still be fully functional for now. Microsoft’s recent announcement, however, puts a hard end date on such a machine. After October 13 2020, any version of Microsoft Office that is out of “mainstream support” will no longer be able to connect to Microsoft’s cloud products. These include Sharepoint, OneDrive (online storage), Lync / Skype for Business (teleconferencing and online meetings) and, crucially, Office 365 for email. So what does “Mainstream Support” mean? And what if you’re not using Office 365?
Mainstream Support is offered by Microsoft for the first five years of release of any new version of software. As the current Office 2016 software reaches five years on the same date – 13 October 2020 – no current version of Microsoft Office will be in mainstream support, so all current stand-alone versions of Office will not be able to connect to an Office 365 email mailbox. In other words, by October 2020, if you’re using Office 365 email or other Microsoft cloud services, then every computer in your business will need either a new version of Office, or a subscription through Office 365 Premium.
There has always been a three-version support window for Microsoft Exchange and Outlook. If your business runs Microsoft Exchange Server 2013 for its email, then the earliest version of Outlook that can connect to it is Outlook 2007. Exchange Online, used by Office 365, currently supports Outlook 2007 with reduced functionality, but even this is temporary, as from October 2017 Office 365 will only be compatible with Outlook 2010 and above. Microsoft’s announced change tightens the restrictions further.
So can you retain a copy of Microsoft Exchange Server onsite instead of moving to Office 365? Unfortunately, Exchange Server also has a finite lifespan. See the following table for a simplified summary of Exchange Server versions (including their most recent patch, service pack or Cumulative Update), what versions of Outlook they will support, and how long they will continue receiving support from Microsoft.
| Exchange Server version | Released | Latest version of Outlook supported | Mainstream support ends | Extended support ends | Current status |
|---|---|---|---|---|---|
| Exchange Server 2003 | October 2003 | Outlook 98 (Outlook 2010 is the latest version of Outlook that can connect) | April 14, 2009 | April 8, 2014 | Currently out of support |
| Exchange Server 2007 | March 8, 2007 | Outlook 2002 | April 10, 2012 | April 11, 2017 | Currently out of support |
| Exchange Server 2010 | November 9, 2009 | Outlook 2003 SP2 | January 13, 2015 | January 14, 2020 | Extended support |
| Exchange Server 2013 | December 3, 2012 | Outlook 2007 SP3 | April 10, 2018 | April 11, 2023 | Mainstream support |
| Exchange Server 2016 | October 1, 2015 | Outlook 2010 SP2 | October 13, 2020 | October 14, 2025 | Mainstream support |
| Exchange Online (Office 365) | October 1, 2015 | Outlook 2007 (until October 2017) Outlook 2010 (after October 2017) |
The take-home message is that for any computers your business purchases between now and October 2020, you should expect to require either a Microsoft Office subscription through Office 365, volume licensing or other means, or an upgrade of Microsoft Office to make it compatible with your Office 365 email. Contact Adams Consulting Group for an obligation-free discussion of your email service and Microsoft Office versions.
]]>This kind of malicious software, known as “ransomware”, is not new; we’ve written about it before. WannaCry is, however, the largest ever ransomware infection to date, affecting users in over 170 countries. So what was it about this specific outbreak that made it so prevalent, so damaging, and so well-reported? How did this virus operate, and are businesses still at risk?
The United States of America’s NSA security agency maintains a catalogue of hacking tools and system vulnerabilities that it uses in the course of its operations. These vulnerabilities include holes and weaknesses in the security of Microsoft Windows operating systems. Rather than advising the public and software providers about vulnerabilities, the NSA preferred to leave them active. However, in late 2016 the cache was hacked by an unknown group, and this highly damaging information made its way into the hands of malicious users.
By March 2017, the NSA appears to have advised Microsoft of the specific vulnerabilities that would later be used by WannaCry. Microsoft acted promptly to patch the security holes using its regular update patch program for Windows computers, with a security patch released in early April. Computer users and system administrators had several weeks to ensure their machines were patched and secure before WannaCry was released in May.
Three days after WannaCry’s introduction, hundreds of thousands of computers had been infected, including businesses like FedEx and Renault, universities in China, Germany’s federal railway system and Russia’s Interior Ministry. Britain’s public health system was particularly badly affected, with operations rescheduled and patients turned away from emergency rooms.
Security researchers were able to rapidly stop the WannaCrypt virus from spreading any further, but they did so due to a vulnerability in the virus code and the poor organisation of the hackers. The code of the virus included a “kill switch” that researchers were able to trigger.
However, the core vulnerability that WannaCrypt attacked is still present in unpatched Windows computers, and hackers are creating and releasing modified versions of the WannaCrypt virus (and others), that have closed the particular hole that stopped the weekend’s attack. In the two days following the successful “cure” of WannaCrypt, there have been several identified new variants released. The initial outbreak of WannaCrypt is past, but the underlying weakness is still there.
The best way to ensure that WannaCrypt and its descendants do not infect a computer network is to ensure that all Windows machines are fully patched with security updates. The NSA vulnerability in Windows is so severe that Microsoft has released a patch specifically for computers that would otherwise not be subject to support – those using Windows XP or Windows 8.
In addition to security patching of Windows itself, most major antivirus and internet security companies now include protection against WannaCrypt and similar viruses in their software. Symantec Endpoint Protection, the internet security package Adams Consulting Group recommends for clients, was already protecting against WannaCrypt before it was released, and computers protected by this software are currently safe.
However, viruses are always mutating and being redesigned to take advantage of new holes in computer security. The best solution is always to keep antivirus up to date, patch your operating systems, and ensure you have a working external backup of all critical business files.
Viruses such as WannaCrypt operate in three distinct phases: infection, propagation and payload. An effective security approach will address all three.
The first thing a virus has to do is to get onto a vulnerable computer. The original infection of WannaCrypt is unclear, but it may have been disseminated by spam emails encouraging users to click on an attachment; running any unknown software will always put your computer at risk despite the best antivirus software. Alternatively, some WannaCrypt variants have been seen on corrupted websites, where simply visiting the site without the appropriate protection can be enough to infect a computer. Prevention of a virus infection requires a combination of user behaviour (treating all incoming emails with caution, particularly those from users you don’t know) and up-to-date antivirus software.
Following the initial infection, WannaCrypt was able to use the Windows vulnerability to reproduce itself and spread through internal networks. During the propagation phase, a virus infects as many files and programs as it can access with copies of itself, throughout the host computer and, if possible, through other computers on the network. Most viruses can only affect the one machine and will require action before another computer can be infected. This is often where the payload comes into operation. Once a virus has infected a computer, there is little that can be done to prevent propagation, but keeping systems patched is vital to ensure that computers are not infected by other affected computers on the network.
Once the virus is fully propagated through the computer’s files, it is able to execute its payload, the action for which it was designed. Sometimes that action will be invisible to the user – for example, turning the infected computer into a factory for spam email. In other instances the payload is intended to generate money for the attackers, whether through scaring users with popup windows to convince them to buy and download “cleaning” software (which will often further increase the virus damage) or, as in the case of WannaCrypt, encrypting files and providing a ransom message. Dealing with a virus once it has begun executing its payload will typically involve an expensive, time-consuming cleanup job to isolate and remove the virus and restore corrupted files. In the case of ransomware like WannaCrypt, recovery might require restoration from backup. We do not recommend payment of any demanded ransom.
Whilst the attack by WannaCrypt appears to be over, the threat from the NSA-revealed Windows bug is not diminished. The next versions of this malware will not be so easily stopped. The best defense is to ensure that all workstations are up to date with antivirus software and system patches.
Most Windows workstations will be set to automatically receive and implement patches, and if so they will be safe from infection. However, for computers using Windows XP and Windows 8, a manual patching process is required. The required patches can be sourced direct from Microsoft at this link. Alternatively, contact Adams Consulting Group or your preferred IT services consultancy to review and update the workstations in your network.
]]>The traditional HDD utilises magnetic disks/platters and a reader on a computer-controlled arm. Like an old-fashioned record player, the disks spin and the reader detects the changes in magnetisation around each track of the platter. The disks spin at high speed. Different kinds of drives spin at different speeds, and generally, the faster the spin, the quicker data can be put on or taken off the drive. The fastest traditional HDDs run at 10,000rpm but the extra speed comes at a cost of a lower maximum capacity. Most drives currently spin at 7200rpm. HDDs are a high-capacity form of storage, with disks up to 4 terabytes in size, and except for high-end premium hardware, most drives are very cheap (larger drives are available at well under 1c/gigabyte of storage). The down-sides of HDDs are energy use, lifespan and limits on data access speed. As with any hardware with moving parts, components of a hard drive will wear out over time. HDDs use relatively high amounts of energy to spin platters at high speed, with read heads being held and moved mere nanometers above the surface. This makes them not only subject to wear and tear, but also fragile and susceptible to shocks. Sudden power failure can also damage traditional drives as the read head is left in position above the magnetic disks.
Solid-State Drives (SSDs) have no moving parts. Instead, they use flash memory – the same kind of storage found in flash cards and USB thumb-drives. Inside a standard, modern SSD you will find dozens of computer chips, comprising the digital storage of your precious documents and data. With no moving parts, SSDs are more energy-efficient, smaller, lighter and more robust than traditional HDDs. SSDs are not susceptible to sudden physical shocks as HDDs, and the loss of power will not damage them.
SSDs are also much faster than HDDs. Accessing any information from a traditional drive requires the read head to navigate to the right place on the correct platter to find the data, often multiple times within a single file if it has been split into multiple blocks of storage (fragmented). SSDs feed the data from flash storage almost instantaneously, and can do so with multiple pieces of data at a time. SSDs are often two to three times faster than even a fast HDD – to the extent that data speed is constrained by the SATA interface to the computer, not by the drive itself.
Faster, stronger, more efficient – what’s not to like? But SSDs also have disadvantages in some situations. SSDs are significantly more expensive than HDDs, currently being slightly under $1/gigabyte of storage. While they are more physically robust than HDDs, the method of operation imposes a lifespan limit on an SSD, measured in terms of the number of read/write operations. The data content on each part of the media on a flash disk can only be changed a limited number of times, usually only a few thousand. SSDs under normal operation will shift data onto new data blocks when the old ones become “tired”, but this requires extra free space to be available. The actual usable space on an SSD is thus reduced if you want to extend the life of the drive. At Adams Consulting Group, we recommend that SSDs never be used to capacity; keeping at least 20% of the drive free will mean it will last significantly longer.
Using an SSD to capacity will reduce its lifespan. Unfortunately, when an SSD develops a fault, it usually does so with little to no warning, and in many cases any content stored on the device may be unrecoverable. Vital business information should never be saved on a single SSD drive for this reason. We recommend utilising multiple drives in RAID configuration for server configuration. Employee workstations can utilise SSDs with no danger of data loss if files are stored on an appropriately configured and backed-up file server.
The cost differential combined with the limitations of read/write operations means that HDDs and SSDs each have different uses in the business environment. The ideal storage configuration combines SSDs and HDDs for different kinds of content.
In some specific circumstances, for instance in a terminal services environment, it may be worth considering use of a Hybrid drive – a standard HDD with a small amount on integrated SSD storage. Hybrid drives use software to identify files that are accessed regularly, and places a copy in the SSD portion for rapid access when required. The result is a drive with the capacity and cost advantages of a traditional HDD, with the blazing speed of an SSD when it’s most useful. Hybrid drives require a period when the software “learns” the best data to cache, and are highly dependent on controller software, so they’re not as simple to manage as traditional drives, but in some situations they can be an ideal solution.
If you’re considering your storage options for your server, your network or for individual workstations, contact Adams Consulting Group for an obligation-free discussion of the most appropriate solutions.
]]>Today we’re looking at one of the most recent new feature additions: Microsoft Planner.
Planner is a simple tool to facilitate low-level project management. Using Planner, you create a “Plan”- effectively, a project. Within that project, you can then create tasks and assign them due dates and allocate the staff member with responsibility. Tasks can be grouped into sections – for example, planning, implementation and support. Planner gives you a simple chart view where you can track the project’s tasks by responsible person and completion status: not started, overdue, in progress or completed.
At the base level, that’s not very impressive. Planner operates like Microsoft Project after removing features such as dependencies, Gantt charts and resource allocations. It’s more comprehensive than a mobile phone task management app – but not by a long way.
Fortunately that’s not the only string to Planner’s bow. Microsoft says: “The addition of Planner to the Office 365 lineup introduces a new and improved way for businesses, schools and organizations to structure teamwork easily and get more done. With Planner, teams can create new plans; organize, assign and collaborate on tasks; set due dates; update statuses and share files, while visual dashboards and email notifications keep everyone informed on progress.”
The key is the way that Planner integrates into other Office 365 tools. Each Plan automatically generates a new Office 365 “Group” – effectively a workgroup comprising all those personnel allocated to any part of the project. The Group is used for email, which is automatically collated into a project folder in your email client. The project has an allocated OneNote page where team members can collaborate their notes, accessible through a OneNote client or via a web client. The project Group gets a dedicated Calendar (unfortunately, at present, tasks with deadlines don’t get added automatically to the calendar). The project even has an allocated store in the SharePoint document library where files can be saved for centralised access by any on the team.
Suddenly Planner is so much more than just a list of Tasks. It combines the tasks, responsibilities and deadlines with file sharing, dedicated email conversations and progress notes.
Planner still has its share of limitations. Currently you can’t allocate more than one person to a task, and Plans are only open to those within your own organisation: if your project requires input from third-party organisations, you’re going to have to work around this. Microsoft says it is working on adding these features to Planner, as well as Plan templates, customisable dashboards and apps for iOS, Android and Windows Phone.
Planner is no replacement for Microsoft Project. If you’re used to managing projects using the full features Project offers, there may be little value in Planner. But for smaller-scale projects, or for ongoing management of internal teams, Planner may well be worth investigating.
Planner is available for all users on both Microsoft Office 365 Business Premium and Microsoft Office 365 Essentials plans.
]]>From the late 1990s through to the 2010s, business email has typically relied on having an up to date on-premises server to host and run a local copy of Microsoft Exchange. Having an internal email server meant businesses had total control over their email infrastructure, and Microsoft Exchange was (and remains) a very powerful email, calendaring, task management and contact management solution.
As with any powerful piece of software, increases in power and flexibility meant a substantial growth in complexity. Building and maintaining an on-premises Exchange server is highly complex and time-consuming, and these requirements grow exponentially if a business needs to support more than one office location, third-party software (such as anti-spam solutions or enterprise software applications) or large numbers of users.
In the early years of this decade, Google Apps, along with other providers, started aggressively pushing online “cloud” email solutions into the business marketplace. Apart from advantages of availability and simpler management, cloud email reduced the reliance of businesses on local servers, and the growth of online email solutions threatened Microsoft’s dominance in business computing.
Microsoft’s response was to invest heavily into its own cloud solution, Office 365. Two major factors now impact upon the considerations of business email solutions: the availability of a robust online (“cloud”) email infrastructure platform, and the retirement of the Small Business Server platform.
Office 365 is a cloud service. Unlike an on-premises server, access to email through Office 365 is not dependent on the availability of internet connectivity in the business’ office. For some Australian small businesses struggling with internet reliability, this can represent an improvement in email reliability.
As a hosted service, Microsoft takes care of the service and its infrastructure. With a Service Level Agreement of 99.99% availability, Office 365 should always be available to any user with internet access. If internet service to the business’ head office is interrupted, email is still available to those working from other offices, on the road or from home. With the increasing mobility of the modern workforce, along with the explosion in personal devices (phones, laptops and tablets) the requirements to support remote access on multiple devices rise exponentially, and Office 365 mitigates some of this complexity for a business’ IT support.
This also means that the computing resources that might otherwise have been dedicated to running a local Exchange server, on an existing or new server, are not required. Reducing the server requirements in an office, and the complexity that is required for managing multiple server functions, can improve the productivity of the business as a whole even before email reliability is considered.
Office 365 doesn’t just do email. Exchange Online is a large part of the offering and the reason most businesses consider it, but Microsoft is building and adding on other services that further increase the return on investment. All the functions of Exchange Server are covered – email, contacts, tasks, calendars and appointments and public folders. But all Office 365 accounts also include:
The combination of collaboration, information management and productivity tools with the Exchange services a business needs combine to produce an ecosystem that, if used properly, can revolutionise the way a business operates.
Until 2015, Microsoft made the decision for SMEs easy, by providing the Small Business Server suite of software. Small Business Server bundled a recent version of the Microsoft Server platform with a full copy of Exchange Server. Together, these provided all the software infrastructure a SMB could need to run their operations, and it became a very successful offering. By one estimate, up to 85% of small-to-medium businesses (as surveyed in 2004) either implemented or planned to implement Small Business Server, and that was early in the bundle’s extended life. For a very attractive price, businesses obtained the software (and initial licenses) to run a server and an in-house email platform.
With the release of Windows Server 2012, Microsoft no longer offers a Small Business Server bundle. Cloud email offerings from Google (and others) have showed that the momentum for SMBs is towards cloud hosting for their email and other services. Microsoft has recognised that the idea of a small business hosting an internal server (for email specifically, but also eventually for file and domain services) is one with a very limited lifespan.
With Small Business Server retired, businesses are left with two very different upgrade paths. It is still possible to license and install an on-premises version of Exchange Server, and this might be the way forward for a large business with complex requirements, or concerns over service reliability or data sovereignty. However, there is no longer a low-cost option to achieve this: it is required to buy a host server, and separately purchase and install an instance of Exchange. Microsoft also does not recommend installing Exchange on a domain server, meaning that a best-practices installation requires a separate server dedicated to hosting the email function, further increasing the cost and complexity of this solution. Finally, there are license costs involved: each user of Exchange requires both a server access license and an Exchange server license.
The other upgrade path, and clearly the one Microsoft is pushing for SMBs, is towards Office 365. To this end, Microsoft offers a no-frills, low-cost on-site server option that suffices to run internal network management but does not include email. If your business server has reached end-of-life (or experiences a failure that requires replacement) replacing it with a new on-premises Exchange server may cost significantly more than implementing Office 365 for your email, even before maintenance costs and availability benefits are considered.
Forrester Research ran a comprehensive analysis of return on investment for a hypothetical mid-size business. The analysis returned an overall ROI of 162%. (You can read about the case study here.) Naturally, each business’ return on Office 365 will be different based on its mix of staff requirements as well as the level to which the various components are utilised. To get the most value out of Office 365, a business should expect not only to use it for email and calendar appointments, but to capitalise on the other offerings included in an Office 365 license. Adams Consulting Group can work with you to identify the opportunities available to improve your business productivity.
]]>Unfortunately, antivirus and antispam are not impregnable. Protection software can recognise malicious files when they’re downloaded and can filter out most likely attacks that hide amongst the hundreds of spam emails you receive every day. But it only takes one new virus to arise before the antivirus software is able to recognise it, one email to slip through the net, or one link in an internet browser to be clicked, and a compromise can happen. Usually, with good virus cleaning tools, a competent IT consultancy can recover or clean your systems following such a breach.
Recent years have seen the rise of a much scarier form of malware from which recovery can be a much more involved process. As this form of attack can be more directly profitable for the attacker, its prevalence is increasing. Known as “Ransomware”, this form of attack locks your computers or your data and then demands a ransom be paid before you can be given back your own files.
A typical ransomware attack begins like any other virus attack. A user clicks on a link in an email that leads to an infected program, or somebody clicks on a link on a site that is compromised. If the user’s antivirus is out of date or the virus is too new, it can run on the user’s computer and the virus is inside the network.
Once active inside the network, the virus can go to work. The least damaging form is known as “Scareware” and it does little more than give the user pop-ups indicating that the machine is compromised, and recovery will require the payment of a ransom. This kind of attack can generally be cleaned with standard tools. Other attackers are more serious and will actually lock the system, making it impossible to boot or operate normally until the virus is cleaned out or the ransom is paid.
The most damaging – and, unfortunately, increasingly common – variant actually locks the files on both the local computer and any files accessible on the network. Typically this includes all document files (from Microsoft Office, text files, Acrobat files, AutoCAD drawings, ZIP file archives and more). Because there will typically be hundreds or thousands such files on local workstations and available via the network, the process of locking the files can take some time – up to several hours. The virus may go undetected for this time until users attempt to open a locked file, or the locking process is complete and the ransom demand is delivered.
Ransomware attackers may be built to encrypt the target files, making them completely unusable. Suddenly, the contents of the victim’s computer – and, more seriously, their work folders on the network – are unable to be opened. The business cannot survive without regaining access to those files. The encryption used in these attacks is, in practical terms, not possible to crack. In most cases, there are only two options available to the affected business.
Paying the attacker off is never a recommended approach. Payment is generally demanded in untraceable currencies such as Bitcoin, so there is little chance of recovery of the money. Moreover there is nothing to stop them taking the ransom and simply disappearing with the files still locked. The unlocking process can be time-consuming and difficult as well. Nevertheless, various companies who have been compromised in this way have elected to pay off the ransom in order to avoid the negative publicity of having been successfully attacked. Some analysts at the FBI have indicated that “just paying up” might be the best approach if there is data that must be recovered and is not backed up.
Some previous malware attacks have been known to hide out of sight until all backups are also compromised; however, this kind of sophistication is a dedicated attack against the target company, rather than the largely automated attacks that form the predominant majority of ransomware attacks. For many companies the best solution will be to restore all content from a backup, assuming backups have been effectively kept.
Recent successful ransomware attacks have included the ABC in Australia, and a number of Police Departments in the United States. Unfortunately, it’s not possible to be completely safe from compromise, despite the best antivirus and antispam protection. Nevertheless, investing in and maintaining internet security software is a very effective method of preventing the vast majority of possible attacks. Adams Consulting Group also has access to preventative tools that work in conjunction with standard antivirus software to prevent encryption attacks.
In the unlikely event of a successful ransomware attack against your business, the most effective response is to ensure that you have in place a thorough backup procedure that includes backups being kept offsite and disconnected from your network. If you should happen to become affected by such a malware attack, sometimes restoring from a backup can be the only effective remedy.
Contact Adams Consulting Group for a free consultation if you are concerned about your antivirus and backup systems.
]]>On 29 July 2015, Microsoft released the newest version of its operating system, Windows 10. You might be forgiven for thinking it seems only last year that Windows 8 came out, but it has been almost exactly three years since the release of Windows 8, in line with Microsoft’s release schedule.
Microsoft has a patchy history with Windows releases. There is a good likelihood that your business still operates some computers with Windows XP and Vista installed. The venerable Windows XP, despite no longer being supported by Microsoft, is still estimated to be installed on over 10% of business computers. Windows XP is remembered as a familiar, effective and, if not loved, at least appreciated operating system. Windows Vista – not so much.
It is a virtual certainty that your business will also have Windows 7 computers, but as the popular Windows 7 has been available until very recently, you might not yet be running any machines with Windows 8. Windows 8 suffered from some of the same perception issues as experienced by Windows Vista. With Windows 8, Microsoft attempted to create an operating system for tablets and mobile devices, but users on standard desktops found the adjustments jarring. Perhaps unfairly, Windows 8 acquired a bad reputation and despite Microsoft’s attempts to smooth over the discomfort with its 8.1 update, many users and businesses have avoided updating to the new system.
With this in mind, we have written this review with new users in mind – those with no experience of Windows 8. Windows 10 is a hybrid of familiarity, with many elements and improvements from Windows 7 retained or reimplemented, and the best elements of Windows 8 refined and streamlined.
Windows 10 takes a step back from the adventurous departures of Windows 8, with familiar interface elements and tasks restored. Many of the complaints levelled at Windows 8 were aimed at the replacement of the Start Menu with a Start Screen – a full screen replacing the familiar pop-up panel with active and resizeable tiles. These tiles still exist in Windows 10, but wedged into the new-style Start menu. In Windows 8 these “Live Tiles” would show your latest LinkedIn updates, news headlines, current weather or stocks information, and other relevant data. While they’re hidden inside the Start Menu, they lose the benefit of being instantly visible. It can still be useful to see, for instance, that you have new emails without needing to open your email client.
Instant information is also available in the Notification Centre. Living in the system tray, the Notification panel provides you instant visibility of new emails, application updates and requests, and other important or useful information as configured. The notification centre is completed with the action tiles, giving direct access to options to turn wifi, bluetooth or flight mode on or off, connect to a VPN, set the computer into tablet mode, take instant notes, or other functions gathered into a convenient location.
Tablet mode is automatically enabled upon undocking an appropriate device, for instance a convertible tablet device. Tablet mode brings back the full screen start menu that caused Windows 8 so much grief (but was widely acknowledged as being ideal for use on a touch device) and makes other changes to make the system finger-friendly without a mouse.
Another obvious addition to Windows 10 is the universal Search bar, permanently located at the bottom left of the screen. Replacing the search Charm from Windows 8, this little text field allows users to search the internet (via Microsoft’s search engine, Bing) and the local computer for files and applications. In use, we found the search effective more often than not for finding specific files or applications. It will take some time before it replaces Google as the web search of choice.
The Charms of Windows 8 are gone, which will disconcert those who have become used to them but will not worry the majority who avoided the upgrade to Windows 8. Instead, system settings are scattered across a variety of locations, from the Notification panel to the Control Panel and a new Settings option on the start menu. In practice, most things users will need will just work out of the box, and those that will not can be set centrally by system administrators and Group Policy.
Under the covers, Microsoft has continued the process of streamlining and optimising it began with Windows 7. 7 was faster than Vista, and 8 was significantly faster to start and run than Windows 7. In benchmarks, Windows 10 tests as faster again – but only just. In practical terms, Windows 10 is an improvement on Windows 7, but no real advance on Windows 8.
Also new is the new web browser – Microsoft Edge, replacing Internet Explorer. Web developers across the world breathed a sigh of relief when the retirement of Internet Explorer was announced, but Edge still seems part-baked. It may mature into the “browser of tomorrow” but it’s not there yet; in our recommendation, stay with Chrome or Firefox for now.
Windows 10 Professional and Enterprise versions include a range of new “killer apps” that offer clear potential to businesses, but might also be of interest for private users.
The last several versions of Windows have supported alt-tab keystrokes to jump between open applications, and each version has featured further refinements to viewing the inventory of your current workspace. Alt-Tab still exists in Windows 10, but it’s been joined by Windows-Tab which arrays your open apps in a neat grid of tiles. More interesting is the new feature of Virtual Desktops. Virtual Desktops operate like separate monitors, allowing you to have applications open and arranged to your liking, protected from accidental closure or relocation until you activate that specific desktop view. Whilst it doesn’t compete with using multiple physical screens, having multiple separate desktops on a single computer is still a step up from being limited to a single screen. Power users will likely find it a significant productivity boost. Use Ctrl-Win-D to instantly create a new virtual desktop, or use the Task View icon in the taskbar.
Another power user tool is the built in support for Hyper-V. Versions of Windows 10 from Professional upwards are able to optionally install a Hyper-V manager. This is Microsoft’s answer to VMWare and other virtualisation solutions and has been built into Microsoft Server systems for years, but the inclusion in Windows 10 allows users to set up separate virtual machines for trialling software, or to safely run older or insecure operating systems. Software developers will find it a particular boon. Medium and large enterprises might find novel ways to use virtualisation for security, standard operating environment and system / software distribution purposes.
As the perennial target for virus authors and malware producers for decades, Microsoft is always at the forefront of software security, if often on the back foot. Microsoft has added new methods of logging onto Windows using biometrics or dedicated device PINs. Laptop providers have been offering fingerprint logon for years, but Windows 10’s new “Hello” features include facial recognition that automatically unlocks the computer when you approach and locks it when you leave. New computers with Windows 10 may have the hardware required for the new biometric security features; most likely your office currently does not have any machines currently able to use this feature. Windows 10 makes further advances in system security. From technical security measures such as “Device Guard” and refined User Access Control, to the automatic inclusion of Windows Defender and better default security settings in web browsers, Microsoft takes two steps forward.
And with a variety of default permissions to share data with Microsoft and others, they have taken one step backwards. Keeping an eye on the default security and sharing options is required to avoid exposing a range of information and tracking data to Microsoft, which in some business contexts may be damaging.
Some of the automatic sharing options are of benefit to businesses. For instance, operating system updates, once installed, are automatically shared across your network, reducing the internet bandwidth requirements for subsequent updates. This is just as well, as updates cannot be deferred for downloading and installing as was previously possible. This mandatory application of updates will help to keep Windows machines secure, but reduces the ability of users (and administrators) to schedule download and installation according to bandwidth and usage constraints.
A new “kiosk mode” is available in Windows 10, allowing you to create a user logon which will have access only to one Windows Store application, in full-screen mode, and no access to the rest of Windows. Businesses can use this for demonstration of applications or products, or for security purposes (for example, giving a temporary employee access to a single working application).
With Windows 10, Microsoft comes a step closer to its vision of One Windows, running everywhere. Over the coming months, Microsoft is releasing new hardware devices, including tablets and phones, running Windows 10 – theoretically, a single version of the operating system, running identically on phones, phablets, tablets and computers. Users’ Windows profiles, including logon details, installed apps, cloud file storage, desktop and wifi access details can be instantly and automatically synchronised across devices. At Adams Consulting Group we can attest to the effectiveness of this sharing, having automatically configured new machines through addition of a Microsoft account.
The Microsoft account is key to this vision. Microsoft accounts can use any email address, including Gmail or business addresses, but once you enter the Microsoft ecosystem, it becomes very easy to take advantage of shared cloud storage, synchronised accounts, and personalised settings. The free OneNote application, once experienced, falls naturally into a workflow (and is a killer app on a tablet or phone device). Making cut-down versions of Office applications free for installation on any mobile phone or small tablet (under 10 inches) supports businesses whose operations centre around creating and using Office files. Microsoft’s answer to Siri, its “Cortana” personal assistant software, is not yet available for Australia but will further entrench the company into business and personal daily life. Combined with new subscription offerings for Office (via Office 365 for businesses, or Office subscriptions for personal users), Microsoft’s new approach is to lock users in with convenience and ease. Arguably, Microsoft is late to this approach, as other providers have been using this strategy for many years, but the success or otherwise will determine Microsoft’s future.
If you operate a modern Windows machine either in your office or privately, you will probably have seen notifications from Microsoft letting you know that you are eligible for a free upgrade to this new version of Windows. The upgrade is available free, for a limited time, to current users of home and professional versions of Windows 7 and 8.
Some business users, on the other hand, will need to pay for the upgrade. Windows 10 will be installed by default on new hardware going forward (although Windows 8 will still be available for some time), so businesses will need to come to grips with the new system and the changes it brings to corporate security, ubiquitous computing and new user experience. Adams Consulting Group is able to support your business through the transition to a new operating system and can help smooth the process. Contact us to find out if you’re eligible for a free upgrade.
]]>