Datto Blue Diamond Partner Status

Hill Country Tech Guys Achieve Blue Diamond Partner Status with Datto

Blue Diamond Partner Status with Datto

Hill Country Tech Guys is proud to announce that we have achieved Blue Diamond Partner status with Datto, a global provider of cloud-based software and technology solutions purpose built for delivery by managed service providers. 

 

Datto Blue Diamond status represents the top 2% of the company’s partners worldwide. 

 

Hill Country Tech Guys has been a Datto partner for more than a decade now and has championed Datto as its solution of choice for backup disaster recovery and business continuity needs. During this time HCTG has outpaced performance standards to reach Blue Diamond within Datto’s Global Partner Program, the highest classification provided by Datto.  

 

Whit Ehrich, CEO and Founder of Hill Country Tech Guys had this to say about being a part of the prestigious Blue Diamond partnership: “We are excited to be Blue Diamond partners with Datto but also excited to be working with Datto over the last 10 years since they are committed to building and improving the MSP community up through continuous refinement in their hardware and software offerings. Datto has displayed the same values as HCTG: innovation, ongoing education, reliability, and serving the community. It is for these reasons that we are proud to call Datto our ‘Partner’.” 

 

More about Datto: 

As the world’s leading provider of cloud-based software and security solutions purpose-built for delivery by managed service providers (MSPs), Datto’s proven Unified Continuity, Networking, and Business Management solutions drive cyber resilience, efficiency, and growth for MSPs. Delivered via an integrated platform, Datto’s solutions help its global ecosystem of MSP partners serve over one million businesses around the world. From proactive dynamic detection and prevention to fast, flexible recovery from cyber incidents, Datto’s solutions defend against costly downtime and data loss in servers, virtual machines, cloud applications, or anywhere data resides. Datto has won awards for its rapid growth, product excellence, superior technical support, and for fostering an outstanding workplace. (https://www.datto.com/about/) 

 

Office365 2022 Price Insights

Office 365 Blog 2

Office365 2022 Price Insights

At Hill Country Tech Guys we strive to keep all our customers in the loop with the latest updates in the IT industry. Recently Microsoft announced that they will be increasing their Office365 pricing for the first time in a decade on most of their Office 365 products in March of 2022. This comes on the heels of continuous improvement and additions to their product line. Most of the innovation has circled around Communication & Collaboration, Security & Compliance, and AI & Automation to supply a complete suite of secure easy-to-use products for your business that save you time and money.  

What they’ve added to warrant an Office365 pricing increase:

When it comes to Communication and Collaboration Microsoft created its Teams software in 2017 to offer a complete package for video, chat, project management, tasks, and calls.  

In terms of security, Microsoft 365 added features such as message encryption, DLP (data loss prevention) for documents and emails, and sensitivity labels.  

With the rise of AI and automation in our day-to-day lives, Microsoft did its part to make our lives easier with the development of AI-powered real-time translation, caption, and transcription.  

A note to our Clients:

For some of our users, Hill Country Tech Guys will be reaching out with cost-saving opportunities. Specifically, customers who are currently on an E3 license with mailboxes under 50 GB. These users will be eligible to transfer their license to a Business Premium, saving $1 a user per month. We will be reaching out to these clients shortly to help facilitate this move in order to continue to provide you with the best products possible at the lowest cost.  

 

The subscription prices will increase as follows: 

As always, you can reach out to us for more information regarding Office365

Cybersecurity Awareness Month!

October is Cybersecurity Awareness Month!

cybersecurity awareness month

As the 18th year of National Cybersecurity Awareness month rolls around, we should all take a look at what we’re doing to help combat and prevent cyberattacks and cyber theft. This is a month-long effort brought to life through a collaboration between the National Cyber Security Alliance and the U.S. Department of Homeland Security. It is a joint effort between industry, government, and the public in order to raise awareness of the importance of keeping sensitive information safe and secure online.

 

Since the past 2 years has essentially forced a shift to a remote or hybrid workspace, the threat of security issues have risen to a chance you may not have been prepared for. In the rush to digitally transform, organizations are moving workloads to the Cloud, adopting new technologies and expanding third-party networks to enhance their offerings.

 

In the month of October, HCTG will be producing weekly content around the CISA’s themes of the month. You will not only be able to find this content on our blog, but also our LinkedIn, Instagram, and Facebook.

Our Favorite Cybersecurity Tips:

To kick off cybersecurity month we’ve picked four of our favorite cybersecurity best practices from CISA’s cybersecurity awareness month toolkit (LINK) to highlight:

  • Shake up your password protocol and use multifactor authentication (MFA). According to the National Institute of Standards and Technology (NIST), using the longest possible password is best. Most sites will require capitals, numbers, and characters. Use this to your advantage to create the most secure password you can. Partner a strong password with using MFA to double down on your security.
  • Be aware of and report phishing. Phishing is an attempt by hackers to pass as an internal or external information source that looks familiar to the receiver. Phishing attempts are endemic, and hackers continue to evolve their creativity when it comes to attacks. When you suspect a phishing attempt, don’t respond, report the phish, and delete the email from your inbox.
  • Limit what information you post on social media. CISA states to limit posting everything “…from personal addresses to where you like to grab coffee.” Additionally, CISA. Recommends  to keep sensitive information safe such as: “Social Security numbers, account numbers, and passwords private, as well as specific information about yourself, such as your full name, address, birthday, and even vacation plans.”
  • Keep tabs on your apps. Mobile devices, while convenient and nearly necessary to modern life, are accompanied by a list of risks. Stay up to date on app permissions to avoid compromising personal data.

Ransomware Attacks

According to research done by tripwire, the average ransomware payout has increased in the past year by 171%. The research reveals that the average ransom demand in 2020 was $847,344. If hearing this puts a pit in your stomach, this should be motivation to up your cybersecurity game.

Ransomware is a serious problem that can have significant impacts – both financial and operational – on companies of all sizes. Ensure that your business is following best practice advice and tips on how to reduce the chances of an effective ransomware attack.

 

Click here for more information on cybersecurity

Remote Work Essentials

WFH essential blog

As Hospital numbers climb and a global workforce shortage in place, companies need to get creative as to how they will keep employees on board, keep employees safe, and keep their businesses going.  Work from Home environments will surely top the list of the ways that they can accommodate all three of those items.  Companies will have their list of lessons learned from the mandates in 2020. Here at HCTG, have a list from “What lessons we learned that impacted companies in their IT?” The following blog will outline some remote work essentials we suggest for a more productive work from home environment. 

IT Impacts of Work From Home and Recommended Remote Work Essentials

Home Internet

There is no IT that can make home internet better. When working from home, employees have found that their internet is not used to the draining hours put on it. Therefore, their internet has performed insufficiently when in terms of VPNs and video conferencing.  Working with your employees to evaluate their internet, and offering stipends for upgrading their internet, will increase an employee’s flexibility to be able to work from home.   

Measuring Performance

If you don’t have clear performance indicators, or a way to track employees’ productivity, this could lead to lowered productivity levels. Your company should invest in a monitoring software to report on the employees’ computer utilization.  Teramind is a software we have recommended during the lock downs in 2020.  Also, we would encourage dispatching this software by departments, so you can offer a comparison in productivity.   

Cloud Applications

Infrastructures that are not 100% in the cloud will not be able to send employees’ computers home with them, and it work effectively without assistance.  Servers need VPNs or log in applications to gain access to the server applications, storage, etc.  A plan should be collaborated with your IT professionals and rolled out in phases to decrease impact on company productivity and security.   

Collaboration Tools

The utilization of a Collaboration tool, such as Office 365’s Microsoft Teams, is an essential tool for a fully remote or hybrid environment.   When these tools are implemented, they make a team that works well at the office work just as well remote.   Companies that have a collaboration tool, but are not fully leveraging the tool, should assign a Champion to learn more about the tool, and how their company can move their internal company dialogues, documentation, issue tracking, project tracking, etc., into the tool.   

 

These four items will drastically increase your peace of mind and keep your company moving forward.   It is important to note, that hardware, such as laptops and video conferencing cameras, were hard to get in 2020.  Fast forward to now, and we are facing a hardware shortage from lack of production in 2020. This has not helped any when it comes to the high demand for hardware.  It will not be possible to get an emergency laptop purchased, or any other hardware.  If the need is there, invest now (it will still take months to get it in).   

 

These are our biggest recommendations for remote work essentials. For more information on Work from Home, visit our webinar series during the beginning of 2020 lock downs which are all linked below. 

Create a Remote Work Plan

Remote Work Force Webinar

Monitoring Work From Home Progress Webinar

Navigating Remote Work Leadership Webinar

Work From Home Policies Webinar

 

Cybersecurity Maturity Model Certification (CMMC) Basics

CMMC Blog 2

CMMC Compliance Basics and Need to Know Information

CMMC (Cybersecurity Maturity Model Certification) is a standard that is being implemented across Defense Industrial Base (DIB). The standards are exactly what it sounds like, a framework that both effects the security of a company within its technical infrastructure as well as the business’ operational structure. These compliance standards address the issue that one of the Department of Defense’s (DoD) highest vulnerabilities is the civilian companies that support the DoD.  

Who Will Need to Comply? 

Any company that does business with the DoD (except for those handling COTS) will need to reach compliance, by compliance auditors’ standards, at one of the 5 CMMC levels. This standard will be enforced for primary contractors, subcontractors, and even suppliers to the primary contractors.  

What Level Will I Need to Achieve? 

The information for which level will need to be achieved will be directly in the contract requests. The theory is the level will be dictated by the sensitivity of the information handled in the contract. An evaluation of which level will be needed may be discussed with a consultant.  

What is Our First Step? 

The first step is to assemble your team to help your reach your compliance. In this team, you will need a Cybersecurity Consultant. CMMC is fairly new, however the frameworks of which it originates, NIST 800-171 and a few others, are not. Finding a Cybersecurity Consultant who is familiar with CMMC and has experience in HiTrust, SOC2, or Financial Compliance is important. This person should be knowledgeable to help with any questions or issues that may incur.  

In addition, your team will need a Team Lead, or someone who is responsible for keeping the plan moving. This person will need to be detail-oriented, understand how the departments works together, and will act as a liaison for all the other members and the Cybersecurity Consultant, and later the CMMC 3rd party Auditor.  

To complete your team, you will need Human Resources, Financial Lead, Operations Lead, and someone thoroughly knowledgeable about the IT infrastructure, including but not limited to the security roles within the organization and the data storage. In smaller organizations these roles usually will be shared. All roles just need to be accounted for.  

What Can We Expect? 

CMMC standards will be a series of standards and processes that will affect all departments within the organization. In structure, there will be standards placed in the IT infrastructure itself. There will also be processes and procedures that will need to be built, tested, taught to the teams, and then checks on if the processes and procedures are being followed. CMMC is not a one-time stamp, but a new way the business will need to operate moving forward.  

What is the Timeframe to Compliance? 

There are too many variables to know how long this process will take. Where did the company start, what level are they trying to achieve, how fast the company is prepared to move, and how effective they are at implementing new processes.  

  

Hill Country Tech Guys has a history of working with clients toward their compliance needs, including ourselves. Internally, we have promoted Jared Vinson to Director of Cybersecurity, so he can focus his time, energy (and his Masters in Cybersecurity) to aiding companies in their security and compliance goals. His consulting hours work in a block hour arrangement but are filling up fast.  

 

Wire Transfer Scams

wts

All About the Wire Transfer Scam

 

If you have not heard of the Wire Transfer Scam, consider yourself lucky.  In our world, we hear about these scams weekly.  Unfortunately, once the scammer has succeeded, there is not much that our company can do except for work with the FBI on the investigation. While this is troubling to think about, there are many things you can do TODAY to prevent the success of this scam.  

 

What is the Wire Transfer Scam: 

At its basic level, a Wire Transfer Scammer will spoof an email from inside your organization. Generally, they will target C-Level employees or the equivalent, that are usually on the website. They use this spoofed email to contact someone else in the organization, or outside the organization, who has access to the checking account. The email will request a wire transfer of a certain amount of funds.  

This scam is remarkably similar to the Gift Card Scam that originated many years ago. Instead of a wire transfer of funds, they requested online purchase of gift cards and sending the codes to them, via email.  

An important thing to note, is that these scammers are real people, that have access to watch behaviors within the organization. They do this to speak the same jargon that is used within the organization. They will also correspond with you via email if you ask them a question.  

Ways to Prevent:  

Internal Policies –

We’d first suggest creating policies, documenting those policies, training those with access, and getting signatures confirming those with access to accounts are on the same page with how money is handled within the organization.  Money requests, such as wire transfers, should have a secondary “real conversation” authentication.  For instance, a phone call from the wire transferer to the person requesting the wire transfer, confirming the amount and where they money is going. We do not advise any email or faxing to be used as the secondary authentication. These are real people on the other side and they can easily complete these types of requests. Also, double check with your bank about how they handle wire transfer requests.  The policy should include a secondary “real conversation” authentication so that these scammers cannot successfully complete the authentication.  

Review Permissions –

Companies tend to have more people than is necessary with permissions in their accounting platform.  Review who has access to see if there is a possibility to reduce these numbers. The larger the number of people with access, the larger your vulnerability. In addition, review those who have credit cards and look for how you can reduce those numbers. Speak to your credit card company about setting limits on the cards. If there is a vulnerability present, the amount at risk will be lower. All of this is really about reducing the liabilities for the scammer to use.  

Phishing Training

Phishing training platforms today are a necessity in any organization. Today, the biggest scam is this wire transfer scam. Tomorrow there will be a new one. Phishing training uses the information the end users are reporting back to create new phishing education and training to ensure that their clients are getting the most up-to-date threat training. The internet and dark web have joined hacker intelligence, and therefore we must join our intelligence to combat their attempts.  Phishing training allows for that to happen.  

All in all, there is no true way to fully prevent phishing emails and being a target of the wire transfer scams. However, if you implement internal policies, review permissions, and perform phishing training you can keep your company and employees the most prepared to combat these scams.

For information regarding phishing training, reach out to us today 

 

 

IT Support Options for Your Business 

bf vs msp

Break/Fix   

Pay-as-you-go,” “Cash Basis,” “Block Hours,” or as the industry calls it, “Break/Fix,” are all the same idea. Something in the IT realm breaks, you create a ticket with your IT Company, and they fix it. Then, the hours used to fix the issue is charged to you, either in a pay-as-you-go model or charged to a bank of block hours.  

  

Who this is best for:  

Break/Fix hours are best for companies that have internal IT knowledge that supports the size of their company. In this model, the business is the leader in the IT relationship. They are making the choices for the company and utilizing the IT Support as a resource in these choices. This works well with companies under 10 employees, in non-regulated industries. In regulated industries, such as healthcare, financial institutions, etc., the need for compliance knowledge usually creates a higher demand for IT knowledge that a small company of that size can afford. Their choices are to pay for consultants to go alongside their Break/Fix, or to convert to a Managed Service Provider.  

  

How much this will typically cost:  

Typically, Break/Fix charges will amount to anywhere between $95-$175 per hour. This varies by business depth (the variety of resources they have), and skill level of the technician doing the work. It is usually billed in 15-minute increments for remote work and 1-hour increments for onsite work. The client has control over when they call and use the hours, but they do not have control over how much time is used. 

  

How to choose a Break/Fix Company:  

A more mature Break/Fix IT support will be transparent with how many hours they estimate a project or issue will take, before working on the issue. For example, they may say, everything under 2 hours we will resolve and bill out, but everything over 2 hours will estimate for you prior to working.  

So, ask them about what their life cycle of an issue looks like.  

  • Is there a ticketing system, so that issues do not get forgotten? 
  • What is the triage process for the tickets? 
  • How are tickets prioritized? 

 

 How billing issues are handled:  

Mature Break/Fix companies will rarely discount invoices because the client questions how many hours it took something to fix. They will have a review process that will deem its validity internally, prior to invoicing.  

 KPIs to request:  

Average Time to Resolution, Average Time to Response  

  

Managed Service  

Flat fee,” “All-you-can-eat,” or “Outsource IT” are all terms used to describe the Managed Service model. For one monthly flat fee, the IT support will take care of all maintenance and day-to-day support of your network. Most Managed Service Providers exclude project work such as new offices, network upgrades, major hardware upgrades, etc. To be able to include client requested projects, the monthly fee would have to be large enough to support a fluctuation in work. Typically, these contracts will run $100 per user or device to support the variety of work done.  

Managed Service is incentivized to diminish the disruptions in your network. If they get the same flat fee every month, the only way for them to make more money within that framework is to reduce the amount of work needed to support your infrastructure. Basically, the healthier the infrastructure, the lower amount of disruption, or issues, for the client. This equals less hours that the IT support needs to utilize.  

  

Who this would be best for:  

Managed Service is best for companies with 15-150 users. It is also great for companies in regulated industries, provided that the IT company they choose has experience in that. Managed Service providers will have a variety of staff that will bring experience and skill to support a network and end-users.  

  

Managed Service works wonders for companies who need the IT company to take the lead in providing a healthy infrastructure, because their internal IT knowledge does not meet the demand that their company has. Managed Service aligns great when the company is needing an IT partner to aide in aligning their business goals with their IT needs.  

  

How much does Managed Service typically cost:

Managed Service will bill per user or per device. In many industries, like manufacturing, not everyone works at a computer and therefore would fit better on a per device model. These prices can vary due to what the Managed Service Provider (MSP) is including in the price, and the infrastructure of the client. In addition, many MSPs use outsourced resources (meaning they are not internal, but a 3rd party providing support) and are able to have significantly lower prices. These MSPs may have prices as low as $50-$75 per user. Typical MSPs will be $100-$200 per user, again, depending on what they are including within the flat fee (i.e., Security, managed hardware, etc.)  

  

How to choose an MSP: 

Meet the team – A good MSP has depth to their support, and key players that offer extensive knowledge. It is hard to get that with just one or two key technicians.   

Account Management – Ask who your account manager will be and ask to meet them. This person will be responsible for setting the pace for your relationship with the company. They will be your partner in IT by providing budgets, regular meetings to assess your business goals and IT alignment, and one of the points of escalation for service issues.  

Reporting tools – What reporting tools do they have to provide you on your IT infrastructure performance, and how often will you receive these?  

Lifecycle of a ticket –   How is ticket triaged? How are the tickets prioritized (usually a form of urgency/number of users impacted, but sometimes you will find companies that give higher priority to VIP clients/users or larger paying clients).  

  

KPIs to request:  

Ticket per User or Device – This is a valuable number because you can cross reference it by industry to see if you get more disruptions than other companies like yourself. A good MSP is trying to reduce the number of disruptions for you, and therefore should be watching this number carefully. 

Average Time to Resolution, Reactive tickets (sometimes called End-user tickets) vs. Proactive tickets (a good MSP should be doing a fair amount of proactive work)  

 

 Managed IT Services

Securing Your Network With Multi-Factor Authentication

2 Factor Blog Banner

All companies want to ensure that their data is secure and private. While we do not imagine that a cyberattack could happen to our business, it is extremely possible without the proper security measures in place. Therefore, you should focus on your cybersecurity and secure your network with multi-factor authentication.

Cyberattack on The Colonial Pipeline

At the beginning of May, a malicious hacker group focused on advanced persistent threats infiltrated the Colonial Pipeline’s computer network. Their intent was to extort the massive company for ransom money. This cyberattack forced them to shut down the entire pipeline to save them from any further damage. The pipeline CEO was forced to pay the ransom of $4 million in cryptocurrencies to regain access and get operations back to work. After further investigation, it was found that one account did not utilize multi-factor authentication, thus giving the hackers access to the systems through this account. And now a month later they are still working to bring some of their systems back online.  

This story is an important learning experience for companies to become more aware and increase their security practices. Cyberattack of large and small scales happen every day; and you never know when or if it will happen to you until it happens.  

 

Multi-Factor Authentication

Multi-factor authentication is one of the few minimum-security practices that we recommend all companies should have in place. Two-factor authentication requires users to have a second device connected to their accounts. Typically, they are in the form of an app or a code sent to a  connected phone number. PIN numbers are the most common form of two-factor authentication in most everyone’s day-to-day operations. When using two-factor authentication, someone attempts to login, the system will flag it, and require either a code, fingerprint, or faceID from either an app or a text. When the ‘hacker’ does not have the code, they will be kicked from the login and the original account owner will be notified. The codes typically reset after 30 seconds so no two codes will be the same, ensuring even more security.  

Without two-factor authentication hackers can simply use a password cracking code to hack into the account; which is exactly what happened to the Colonial Pipeline systems.  

 

If you would like to read more about the Colonial Pipeline Cyberattack or Multifactor Authentication, we have included some links that contain more information below. 

Colonial Pipeline Ransomware Attack

Colonial Pipeline – Less Secure Than Your iPhone

More Information on Multi-Factor Authentication

Active Security

The CEO and COO of Hill Country Tech Guys, Whit and Sara Ehrich, discuss security needs, the cyber-attack lifecycle, and some examples of what this looks like. Whit’s 20 years of experience in a variety of IT infrastructures gives him insight as to what security measures a company needs to protect their data from cyber-attacks.

 

Whit goes into depth of the minimum “core” protection a business should have when protecting their sensitive materials, and talks more about the advanced, or “active” protection which are options our company offers.

 

This webinar is free and available to anyone who needs it.  Please provide it to any business owners or managers who may be needing assistance on this topic. We are more than happy to help.