Prey or Empowered? Small Businesses and IT Security

Now more than ever, small businesses need to be vigilant with their information technology security. Small businesses may not be the big fish in the sea, but there are plenty of them out there to catch. Small businesses tend to make the best targets because they often fail to perform security audits, they may not be willing to invest in the resources needed to protect themselves, and they frequently don’t even carry the right insurance coverages. To hackers, small businesses are easy prey.

“Don’t think you are too small to be affected,” says Erik Knight, the founder and CEO of SimpleWAN. “Every place you have an employee or office is a potential entry point. Take it seriously; if you have something worth taking, a hacker will try to take it.”

https://www.forbes.com/…

There are a few things every business can do to improve the security and privacy of their data. It isn’t an option any longer; these are essential elements in an overall security strategy that can make the difference between staying in business and not.

Use strong passwords, not easy-to-guess words, phrases or sequences (1234 is not a strong password). Passwords should be unique, more than 8 characters in length, and have a mix of numbers, letters, and special characters.

Keep software updated. Whether it is the operating system on your computer or the software you use to write letters, having up-to-date software matters. Developers don’t just upgrade software to fix bugs or introduce new features; software often gets updated because of security issues or vulnerabilities.

Keep networks and connected devices secure to make sure that the computers and connections aren’t introducing weaknesses into your system. Not only are password controls and software updates needed, but firewall security and good anti-virus/anti-malware solutions are also a must. Keeping an eye on the server matters, but the connecting points and end points are where many vulnerabilities exist.

Set up two-factor or multi-factor authentication to further secure logins. 2FA and MFA is like having ID besides just your driver’s license to prove you are who you say you are. Your password, like your DL, is just one factor; you need one more thing to prove your identity for 2FA, like a code from your phone or maybe your fingerprint. The point is that there should be more than just a username and password to access important data.

Restrict use of personal email or social media on work devices. This gets a little trickier with smaller businesses, as many don’t or can’t support providing users with all company-owned devices. There are tradeoffs to allowing users to bring their own devices (byod) versus using company-owned devices. When mobile devices are part of the mix along with desktop and portable computers, it becomes even more complicated and the risk potential increases.

Use encryption for data in transit and data at rest. Encryption is like scrambling the data and then unscrambling it when you access it. In transit, data may be encrypted by a VPN so that it is protected over the wire (in motion) as it is sent and received on the network. RDP is also encrypted, but this remote access method’s main purpose is to keep the data from leaving the server in the first place. At rest, like when it is sitting on a hard drive or other storage location, data can also be encrypted. To open the file or file system, you need a key to decrypt it.

Keep all data backed up and create a way to rapidly recover your server and systems in the event of failure or compromise. Backups are great right up until you find they are as damaged or unrecoverable as your main system, so make sure to have a policy of testing your backups periodically. There are many ways to back up and protect your data, including external drives and cloud storage. If data gets lost or corrupted, you want to be able to restore it from a backup. Regularly audit your backup and data security practices to help identify weaknesses that make the business vulnerable.

Educating employees on the importance of cyber security is among the most important steps a business can take to protect itself. Keeping passwords secure and secret, knowing how to spot a phishing email and what to do and not do with it, not clicking on suspicious links in emails, not sharing personal or confidential information online, and what to do in the event of a breach are all things that should be regularly discussed with workers and supported by written policies.

Managed Azure cloud servers from Noobeh help you keep your business information more secure. Our services demand high levels of security and privacy, and we help our customers keep their data and systems safer and more secure by handling some of the requirements for them.

  1. Strong password policies and MFA is our standard setup, and software updates and patching are part of the service.
  2. Working on the cloud server keeps data on the server and not traversing the network or downloading to individual PCs, so information stays secure and separate from whatever a user runs on their local devices.
  3. Data on the Azure virtual machines is encrypted at rest, and additional encryption is available to add more layers of protection. Data in motion is encrypted, but very little data actually traverses the wire.
  4. Servers and data are backed up regularly with snapshots and file level backups, allowing for simple file restores as well as comprehensive system recovery.

For small businesses, Noobeh has the solution for creating a more secure and better protected IT environment where applications and data can be available to those who need them without compromising the investments already made in training and process development. Moving software and data to a private cloud server allows companies to continue using the software they rely on, just in a better way. Instead of being easy prey to hackers, our customers benefit from higher levels of IT administration, management and protection that empowers them to work the way they need to – any time, anywhere.

jm bunny feetMake Sense?

J

Better QuickBooks Hosting with Noobeh

QuickBooks hosting is a type of service that allows small businesses to access their QuickBooks Desktop accounting software and data from anywhere with an internet connection. QuickBooks hosting fits into the modern cloud computing world by providing small businesses with a flexible and cost-effective way to manage their accounting and financial operations.

In the past, small businesses would need to install QuickBooks software on their own computers and maintain their own IT infrastructure to manage their accounting and financial data. This requires a significant investment in hardware, software, and IT staff, and makes it difficult for the business to scale their accounting operations as their business grows.

With QuickBooks hosting, small businesses can avoid these challenges by moving their accounting operations to the cloud. Yet not all QuickBooks hosting providers offer the same level of service or protection for your data.

Most QuickBooks hosting providers run the QuickBooks software and store the QuickBooks data on their own servers, renting space on the servers to its business customers. In most cases, many businesses will share the servers, which increases risk.

Noobeh works only with private environments where customers do not share servers or other resources. Each customer has their own private account and environment which is accessible to only their users via the Internet. This eliminates the need for small businesses to maintain their own IT infrastructure and allows them to scale their accounting and business operations up or down as needed.

QuickBooks hosting from Noobeh provides businesses with a number of other benefits, including:

Increased Security: Noobeh’s QuickBooks on Azure deliveries have advanced security measures in place to protect customer data from unauthorized access, data breaches, and other security threats.

Enhanced Collaboration: Noobeh’s QuickBooks on Azure allows multiple users to access and work on the same QuickBooks data at the same time, which can improve collaboration and productivity.

Automatic Backups: Noobeh’s QuickBooks on Azure performs regular backups of customer data, which can help ensure that important financial data is not lost in the event of a disaster or system failure.

Anytime, Anywhere Access: Noobeh’s QuickBooks on Azure allows small businesses to access their accounting data from anywhere with an internet connection, which can be especially useful for remote or distributed teams.

Totally Private: Noobeh’s QuickBooks on Azure runs on the Microsoft Azure platform and uses private Microsoft accounts, keeping things absolutely private for your business.

Noobeh’s QuickBooks on Azure hosting is a modern cloud computing solution that can help small businesses streamline their accounting and financial operations, reduce costs, and improve their overall efficiency.

jm bunny feetMake Sense?

J

Intuit Makes Moves to Push Low-End QuickBooks Users to Online Edition

QuickBooks Pro and Premier Subscriptions No Longer Available After July, and It’s Bye Bye for QuickBooks for Mac

 

Final sale date for QuickBooks Pro and Premier

On November 30 of this year, Intuit notified its partners and customers that the final date for new sales of QuickBooks Desktop Pro, Desktop Premier, Mac, and Desktop Enhanced Payroll is July 31, 2024. Starting in August, QuickBooks Pro and Premier subscriptions, along with Mac versions and desktop payroll services, will no longer be available for purchase. QuickBooks Enterprise, which is a desktop edition, is the only QuickBooks version that will remain available for new subscriptions. 

For several years, Intuit has been improving their online version of the product while migrating as many customers as possible to that platform. Now, businesses that have invested years of user training and business process development are forced to decide if the online version of QuickBooks will meet the needs that the desktop editions have for years, and they must look at the realities of potentially re-training users and re-developing workflows and processes. 

QuickBooks Enterprise is a viable alternative 

The alternative is that businesses adopt QuickBooks Enterprise edition and retain the value of user knowledge and process support by remaining in desktop QuickBooks. For businesses that manage multiple company files, QuickBooks Enterprise provides the same multi-company capabilities that Pro and Premier do, something the online edition does not currently support. 

There is no change to QuickBooks Desktop Enterprise subscriptions. All QuickBooks Desktop Enterprise subscriptions (Silver, Gold, Platinum, and Diamond) will continue to be available for purchase for new customers. QuickBooks Enterprise Gold, Platinum, and Diamond subscriptions include integrated payroll. 

Flexibility of Desktop Applications on the Cloud 

With the announcement, many accounting professionals and their clients are not sure what the best path forward is. While there is momentum behind the online application, there are options for staying with QuickBooks Desktop and still take advantage of the cloud. 

For businesses that want the flexibility of using the cloud but that need the features and functionality of desktop QuickBooks, Noobeh cloud offers QuickBooks on Azure services. This empowers businesses to use their QuickBooks Desktop software – Pro, Premier, or Enterprise – along with all their add-ons and integrations, and to run it all securely on the Microsoft cloud. Note that Noobeh’s hosting service also works with Mac devices, so even Mac and iOS users can work in hosted Windows versions of QuickBooks. 

QuickBooks Desktop is Not Dead 

The retirement of QuickBooks Desktop Pro, Premier, Mac and Payroll products currently impacts only new customers looking for those solutions, or existing customers that do not have current subscription licenses. If a business has an existing QuickBooks Desktop Pro Plus, Premier Plus, Mac Plus, or Enhanced Payroll subscription, they can continue to renew their subscription after July 31, 2024. Intuit will continue to provide security updates, product updates, and support for existing subscribers. 

Intuit will also allow accountants to continue purchasing QuickBooks Accountant Desktop Solutions, including ProAdvisor bundles, directly through the QuickBooks Accountant Sales team. 

What to Do 

To avoid losing access to QuickBooks desktop, businesses should purchase a QuickBooks Desktop Pro Plus, Premier Plus, or Mac Plus subscription through the QuickBooks Accountant Sales team before July 31, 2024. Businesses that need a desktop payroll solution should consider purchasing a QuickBooks Enhanced Payroll subscription before July 31, 2024, or upgrade to QuickBooks Enterprise Gold, Platinum, or Diamond, all of which include integrated payroll and can still be purchased after July 31, 2024.  

Mendelson Consulting, Intuit’s first solution provider and the go-to experts on QuickBooks Desktop and QuickBooks Online, are perfectly positioned to provide businesses with the help they need to decide which path to take with their QuickBooks software. Recognized as specialists in working with larger businesses using QuickBooks Enterprise and as top performer with QuickBooks Online, Mendelson Consulting’s team has the depth and breadth of knowledge and expertise to make sure your business makes the best possible choice for its financial systems. 

jm bunny feetMake Sense?

J

MISys Manufacturing Leverages Microsoft Azure Cloud with MISys on Azure

MISys Manufacturing software is designed for small to medium sized manufacturers, providing low cost of ownership and a flexible, modular design. When a business needs to add inventory management, purchasing, MRP, forecasting and scheduling, MISys is the solution that delivers the functionality. Noobeh cloud services has always provided hosting and managed services for MISys and MISys EXT on the Microsoft Azure cloud. Now, MISys Manufacturing has new options to take even more advantage of the power and flexibility of the Microsoft Azure cloud platform:

MISys on Azure

The new cloud deployment options for MISys Manufacturing provide direct support for Microsoft Azure databases and app services. Customers can use their own self-managed Azure subscriptions and the MISys installer can provision the app and database to get it all going. Noobeh helps businesses get started with the Azure cloud, assisting with the setup and deployment of services on the most secure, scalable, and agile platform available. Noobeh services delivered on Microsoft Azure take full advantage of the Microsoft cloud platform and all it has to offer.

While the primary focus of MISys releases starting with v6.4.5.0 have been to have an installer-assisted deployment with Microsoft Azure, the complexity of Microsoft and Azure account and subscription setup can be daunting for even experienced technicians. Noobeh simplifies these processes by assisting businesses with the creation of the accounts and the provisioning and preparation of the services necessary to support a MISys on Azure installation.

Each Noobeh MISys on Azure customer gets their own absolutely private Azure tenant account, which ensures that there is no co-mingling of resources and no possibility of interactions between customer accounts. And Noobeh deploys services with the resources necessary to deliver the right solution for each business client, knowing that adjustments can always be made as business needs change.

MISys Manufacturing can be implemented in a variety of configurations, allowing each deployment to meet the specific needs of the client. Noobeh helps companies deploy MISys Manufacturing software in all its forms, handling the installation and technical configuration whether on-premises, exclusively cloud-based, or hybrid.

Cloud Server | Cloud Database | Cloud Desktops | Cloud Everything

With Noobeh and MISys, you can choose from configurations that keep the desktop/client software local or cloud, have your database on your cloud server or just have a cloud database, or combine the benefits of managed desktops and data by putting the entire system in the cloud.

No matter what accounting solution you use with MISys, Noobeh has an answer for that, too. We’re specialists at hosting QuickBooks and Sage desktop products, and work with businesses using QuickBooks Online, Sage Intacct and other web-based solutions. You need your MISys installation and your accounting software to work together? We’ve got that delivery model.

With MISys on Azure and Noobeh, business owners have the assurance that their software can be deployed in a model that meets with their specific needs and budget, and with the flexibility to change and grow along with the business.

jm bunny feetMake Sense?

J

QuickBooks Desktop Enterprise 2024 Security Improvements: Now with 256-bit encryption

Intuit’s release of QuickBooks Enterprise and other desktop editions for 2024 have a variety of new features, and among them is an improved level of security for your business data. Upgrading from 128-bit encryption, QuickBooks Desktop 2024 now has AES 256-bit encryption.

256-bit encryption is the strongest and most robust encryption standard commercially available. It’s widely used because it’s virtually impenetrable to brute-force attacks. 256-bit encryption is an encryption technique that uses a 256-bit key to encrypt and decrypt data. Plain text is converted to a cipher, and the encryption key is required to decrypt the data and return it to readable plain text.

256-bit encryption is used in most modern encryption algorithms, protocols, and technologies, including AES in wireless security, processor security, file encryption, and SSL/TLS.

According to Intuit, “You can be confident your data is protected with our enhanced security using industry-leading AES 256-bit encryption. QuickBooks safeguards your reputation by protecting critical customer and vendor data, such as business financials, banking information, and credit card details.

This means we translate your information into a code that only we can read to make sure only you and Intuit have access to your information. The type of encryption we use is called AES-256 (Advanced Encryption Standard with 256-bit keys) and it ensures the highest level of cryptographic security.”

With a series of robust security steps and a complex 256-bit decryption key, AES 256-bit standard is nearly impossible to break using brute-force methods and has been approved for the handling of confidential data by the U.S. Government.

A brute force attack is when a hacker tries different combinations until they arrive at the correct combination – the key. The larger the key size, the more difficult it becomes to break the encryption. We’re talking about 256-bit keys. There are 984,665,640,564,039,457,584,007,913,129,639,936 (that’s 78 digits) possible combinations. Even if you use Tianhe-2 (MilkyWay-2), which was the 4th fastest supercomputer in the world in 2022, it will take millions of years to crack 256-bit AES encryption.

In case you’re interested: The fastest supercomputer in the world, ranked in June 2023, is Frontier, an HPE Cray EX system run by the US Department of Energy, Frontier incorporates 3rd Gen AMD EPYC™ CPUs representing 8,730,112 cores that have been optimized for high-performance computing (HPC) and AI with AMD Instinct™ 250X accelerators and Slingshot-11 interconnects. Its HPL benchmark was 1.194EFLOPS (EXA – 1 quintillion – floating point operations per second). (via networkworld.com). Frontier is faster than Tianhe-2, so breaking the key could take a little less time.

Breaking encryption with no known flaws is kind of like guessing a password. If you make enough guesses, you might eventually get the password right. With strong encryption, this can take a long time. AES-256 is the most secure version of AES and is virtually unbreakable by brute force based on current computing power. It’s also considered quantum-resistant, which means that quantum computers aren’t expected to crack the cipher.

How long would it take to crack 128-bit encryption using a brute force attack? Most security professionals would answer “1 billion years”, but that’s just an estimate. A machine that can crack a DES key in a second would take about 149 trillion years to crack a 128-bit AES key. According to researchers, with the right quantum computer, AES-128 would take about 2.6110^12 years to crack, while AES-256 would take 2.2910^32 years. For reference, the universe is currently about 1.38×10^10 years old, so cracking even an AES-128 encryption with a quantum computer could take hundreds of times longer than the universe is believed to have existed.

While Intuit is improving the security of the information it stores and transmits between its systems, your company should be equally concerned with the security and protection of all your business applications and data. Using strong password policies, multi-factor authentication, and SSL for secure web app access, Noobeh’s QBonAzure services provide layers of protection on top of the $20Bn in security investments made by Microsoft.

We take data security seriously, providing solutions to address access, security, privacy and protection for business applications and data. When your QuickBooks Enterprise deployment needs a solid foundation that offers agility and performance as well as strong platform security, we have that.

Visit MendelsonConsulting.com/cloud to learn more.

jm bunny feetMake Sense?

J

QBonAzure: QuickBooks on Microsoft Azure Delivers Great Success for Small Business


For any business, the resilience and agility of IT systems can mean the difference between performing adequately and performing with great success. When a business elects to run their QuickBooks applications and data on the Microsoft Azure cloud via QuickBooks on Azure (QBonAzure) from Noobeh, they gain numerous advantages not available with locally installed IT.

Microsoft Azure is a highly available platform, meaning that it has built-in redundancy to ensure that applications and data are always accessible, even in the event of a hardware failure. Businesses running on the platform never have to worry about whether or not their server is aging and may fail due to hardware issues.

The platform also allows Noobeh to easily scale each client’s system up or down as needed, without the need for additional installation work. This allows each client business to quickly respond to changes in demand and grow their operations as needed.

With Microsoft Azure, Noobeh can provide from a broad range of security features that are built-in as well as enhancing protection with advanced features and services from Azure, Microsoft 365 and more. This all goes to help protect against data breaches and unauthorized access to sensitive information.

Azure has a global footprint, with data centers in multiple regions around the world. Noobeh provides services from all US-based Microsoft Azure regions, allowing businesses to host their QuickBooks in the location closest to their users, reducing latency and improving performance.

Azure also offers a wide range of services that may be integrated with QuickBooks or other business data, such as analytics, artificial intelligence, and machine learning. This allows businesses to gain deeper insights into their financial data and make more informed decisions.

For businesses focused on compliance, Azure meets a wide range of industry standards and regulations, such as HIPAA, SOC 2, and PCI DSS. This can help businesses meet their compliance requirements and avoid penalties.

Overall, hosting QuickBooks on the Microsoft Azure platform can provide businesses with high availability, scalability, security, global reach, integration, and compliance advantages that can help them run their operations more efficiently and effectively.

Noobeh cloud services and QuickBooks on Azure utilize only the Microsoft cloud for their client deployments so that each business client has the benefits of big enterprise technology without the big enterprise price.

jm bunny feetMake Sense?
J