Employ best practices to keep your systems running smoothly.
As someone who has been in the IT game for a while now, trust me when I tell you that “updates” is a word that comes up a lot. From business networks to cybersecurity, technology never stays the same for long.
Software programs frequently require updating to the latest version. Businesses need to have a plan for keeping software current and staff apprised of workflow changes.
A quick note on software updates
I’m willing to bet that you have some experience keeping your devices current. But what really goes on during a software update?
A software update can be viewed as a sort of “patch” for the current iteration of a program. Updates typically include a set of changes designed to fix or improve upon pre-existing software, including:
- Removing bugs from code
- Fortifying security
- Providing new tools or features
- Improving effectiveness
As you can see, updating consistently is important to maximizing your software’s value. But perhaps nowhere are updates more essential than for cybersecurity. When an update comes out designed to address security vulnerabilities, time is of the essence for implementing it. If you don’t, the software may become vulnerable to malicious actors, which can jeopardize the overall effectiveness of your business.
Putting it into practice
With so much riding on keeping systems and programs current, what exactly is the best approach for ensuring that each new update is promptly installed?
There are several strategies that can keep you and your team moving forward without creating a lot more work for yourself in the process.
- Automatic updates: Whenever possible, enable automatic updates. These will keep your systems running efficiently and safeguard your business from security breaches.
- Create an inventory: While it may require some heavy lifting up-front, establishing an inventory of all programs and systems can be incredibly helpful for staying on-top of security updates and software patches.
- Stay apprised of update schedules: To avoid surprises, it never hurts to have familiarity with when certain vendors push out updates. Microsoft, for example, consistently puts out updates on the second Tuesday of each month. Adobe follows a similar pattern.
- Create a personal schedule: When you are running a small agency, it may be difficult to find time to take care of necessary updates while overseeing everything else that goes into a successful enterprise. One strategy to overcome this is to set aside designated time each week for carrying out this work. Be sure to make it consistent week-to-week, month-to-month, and year-to-year, and don’t waver once it is established.
- Communicate clearly: No one is an island in business, and changes to your systems and programs will impact the workflows of others. Clear and consistent information delivered before, during and after an update is critical when performing an update. Employees need to know what types of updates are going on, how long they might take and how it will ultimately impact their day-to-day activities.
- A solution for your solutions: There is an old saying that the best laid plans of mice and men often go awry, and that holds true for something like software updates. If that sounds familiar to you, it may be worth considering adopting a technological solution for your software solutions.There are many tools that can make tracking and managing your critical software updates easier. Check out this article for more on getting started.
- Hiring help: It is never a bad idea to seek out help from a professional for your IT-related needs, even if you have a small shop and minimal technology requirements. Of course, this can pose challenges for the small business owner, in that you must assess whether to bring on a full-time worker or outsource your needs to a third party like a managed service provider (MSP). Luckily, you don’t need to make this decision alone! Check out Alliant National’s blog about this topic, which you can read here.
Enjoy a secure system
The work of IT never ends, and this poses real challenges when it comes to software updates. Yet like anything else, solutions exist. Carefully planning your updates, staying hip to the latest changes and getting assistance when needed can help you strengthen the IT systems on which your business success relies.
What does it mean to get hacked? And how might we mitigate cybercrime?
Hacking is unfortunately far from uncommon. By some counts, more than 2,200 cyberattacks occur per day, which means that one cyberattack occurs every 39 seconds.[i] These hacks carry a tremendous financial cost, with some estimates putting them as high as $6 trillion per year or $500 billion per month, $115.4 billion per week, $16.4 billion per day, $684.9 million per hour, $11.4 million per minute and $190,000 every, single, second.[ii]
The figures are mind-boggling and scary, which is why it is more important than ever to understand what can occur when a business network is hacked. Without grasping the basics, it becomes more difficult to assess your risk and start proactively protecting your company.
What is the origin of the term “hacking”?
The use of the term “hacking” in a computer science context began all the way back in the 1950s at MIT. In those days, hacking simply meant dealing “with a technical problem in a creative way.”[iii] It wasn’t until the late 1970s that hacking started to refer to illicit activity, a definition it retains to this day.
These days, hacking primarily revolves around the compromising of digital devices and networks. While there is “ethical hacking,” which focuses on improving security systems and keeping data safe, most is “black hat,” which means that it is often motivated by money, such as:
- Wanting to sell private network information on the black market.
- Obtaining access to sensitive information and then attempting to coerce victims into paying money.
- Desiring to obtain confidential data and use it for financial benefit.
- Holding data hostage until a payment is made.
How do hacks occur?
Typically, business networks are targeted through the multiple endpoints that are vulnerable to criminal activity. Just think about it. Every day, employees access business networks with numerous devices that may or may not be secure. But that’s not all businesses need to be concerned about. Similarly vulnerable areas include:
- Any cloud-related services
- Unsecured WiFi
- Malicious websites
- Email accounts
Hacks come in every shape and style
There is no “one way” that hacking occurs, which makes it important to cover the different variations of hacking to gain a more complete understanding of the threat landscape. Here are seven distressingly common strategies that cybercriminals routinely employ:
- Phishing: By far, phishing is one of the most popular forms of hacking today – in part because it is so effective. To better understand the prevalence of phishing, look no further than to recent data that shows 1 in 99 emails is a phishing email.[iv] There are several different types of phishing emails, such as:
- Malware delivery emails, where malware is unleashed if the email recipient clicks on a malicious link.
- There are also credential harvesting emails, where the sender will impersonate someone the recipient knows to get them to hand over sensitive information.
- Denial of Service (DoS): DoScyberattacks occur when cybercriminals make an online property or service unavailable by inundating it with requests. This attack will frequently result in your website crashing or becoming unusable.
- Spyware: Spyware involves malicious code being embedded to monitor email correspondence or worse. Keying (key-logging) to obtain passwords is just one example.
- Malware: You’ve likely heard of malware before – and for good reason. Referring to any computer virus, worm, trojan horse, spyware, ransomware, adware or other malicious software, malware has been sneaking into user devices and business networks since the beginning of the computer age.
- Brute Force Password Decoding: In this type of hack, finesse or secrecy go out the window. The cybercriminal simply attempts to force his or her way inside your devices or network through automated tools that seek to decode your network passwords.
- DNS Attacks: With Domain Name Server (DNS) attacks, cybercriminals utilize an elaborate strategy where they take domain names and transform them into IP addresses, which often results in the domain name server redirecting web traffic to fake websites controlled by the criminal.
- Social Engineering: Social engineering cyberattacks are exceptionally difficult to guard against because they focus on manipulating human attributes like empathy, fear and urgency to gain access to personal information or a corporate network. Phishing is one example of such an attack, but there are many others that fall into this bucket.
Are we powerless against hacking?
With such a wide range of illicit cyber activity, it can feel almost impossible to keep up. However, there are numerous things business owners and employees can do to protect themselves and reduce the possibility of harm or financial loss. From following password best practices, to keeping your systems updated, to deploying new techniques like security awareness training (SAT), even the smallest firm can dramatically increase its security posture. The situation is not hopeless. In fact, by following expert advice and remaining vigilant, we all have the power to reduce our risk profile and stay safe online in both our personal and professional lives.
Keep learning! Read more about 2022 cybersecurity trends, the rise of ransomware and how to streamline your password use.
We also encourage agents to continue to explore and implement best practices to combat cyber fraud. Download Alliant National’s white paper – Escrow Fraud/Social Engineering: Recent Schemes and Prevention Tips to begin your own internal assessment.
[i] Clare Stouffer, Norton, “115 cybersecurity statistics and trends you need to know in 2021,” 9 Aug. 2021, 115 cybersecurity statistics and trends you need to know in 2021 | Norton
[iii] ECPI University, “What is Hacking and Cracking in Cybersecurity?”, What is Hacking and Cracking in Cybersecurity? (ecpi.edu)
[iv] Michael Guta, SmallBiz Trends, “1 in 99 Emails is a Phishing Attack, What Can Your Business Do?,” 4 May 2021, Phishing Statistics: What an Attack Costs Your Business [INFOGRAPHIC] – Small Business Trends (smallbiztrends.com)
Every wire fraud defense expert says the number one factor in recovering diverted funds is time. Every minute counts when fraud has been detected, and hesitations or delays can impede efforts to track down and restore lost funds.
That’s why a Wire Fraud Response Plan is imperative for every title agent.
Before you create your plan, or if you are undergoing a review of your current plan, we encourage you to download Alliant National’s recently updated Escrow Fraud/Social Engineering: Recent Schemes and Prevention Tips white paper. This 23-page guide provides an in-depth review of the current schemes and offers a wealth of tools and resources for building a strong defense against fraudsters.
Here are some things to consider when creating your response plan.
Elements of a Wire Fraud Response Plan
The first step in preventing wire fraud is to maintain policies and procedures for verification of wire instructions for the protection of everyone involved in the real estate transaction.
But should the unthinkable happen, remember that the most successful response strategies are those established well in advance and communicated to staff members and your bank.
Like a well-trained sports team, every member of your team must know their role and be prepared to leap into action.
- Establish a close relationship with your bank representatives and continually dialogue regarding updated fraud threats.
- Discuss wire retrieval scenarios and establish emergency contacts in the bank’s fraud department, whom you can call at a moment’s notice day or night.
- Download and fill in the Wire Fraud Contacts form in our Escrow Fraud/Social Engineering white paper and provide it to staff members charged with addressing suspected fraud.
- Notify management the moment suspicion arises that a wire may have been misdirected.
- If funds have been transferred to the receiving bank and cannot be recalled, ask your bank (the sending bank) to formally request that the receiving bank freeze the funds.
- Agents may also attempt to directly contact the receiving bank to ask that the funds be frozen.
- Contact local police in your jurisdiction and the jurisdiction of the receiving bank.
- Report the fraud immediately to your local FBI office.
- File a complaint with the FBI’s Internet Crime Complaint Center (IC3).
- Contact the underwriter involved in the transaction. Alliant National is available to help you evaluate the situation.
- Contact your corporate attorney to let him or her know about the events taking place.
- Depending on the nature of the fraud, contact the appropriate insurance provider (Cyber-Liability, Escrow Security Bond or Errors & Omissions).
Putting all of these resources in motion immediately can be extremely useful, as anyone of these professionals or organizations may have information that could assist you in recovering your funds.
IC3 may be one of your most important contacts. In 2018, IC3 established its Recovery Asset Team (RAT) to streamline communications with financial institutions and FBI field offices to assist freezing of funds for victims.
In 2021, RAT initiated the Financial Fraud Kill Chain (FFKC) on 1,726 Business Email Compromise (BEC) complaints involving domestic to domestic transactions with potential losses of $443,448,237. A monetary hold was placed on approximately $329 million, which represents a 74% success rate.
The efficiency of this organization’s work is largely dependent on the speed with which they are advised, so it’s critical that they be an important part of your Wire Fraud Response Plan.
Even the most vigilant companies may fall prey to fraud, but putting protocols in place can greatly reduce your exposure and give you a pathway to recovering lost funds.
As always, call your Alliant National underwriting team if you have any questions or concerns. We are here to help!
Alliant National’s Crime Watch Program creates a formidable partnership to fight fraud.
There is no other way to say it: Real estate fraud is a major problem in the United States. According to the National Association of Realtors, nearly 14,000 people were victimized by real estate fraud in 2020 alone.[i] Combatting this growing threat requires strong partnerships, and Alliant National’s Crime Watch Program seeks to foster such partnerships by rewarding Alliant National agents who prevent fraudulent closings.
The program has produced real results over the years. In this blog, we will look at a recent detection and prevention of a fraudulent transaction by Siesta Title and Escrow Services LLC.
Alliant National Agents on Crime Watch
Alliant National offers a $1,000 reward to Alliant National agents who help prevent a fraudulent transaction from closing. The company created the program to help raise agents’ awareness of potential fraudulent transactions and to reduce the overall cost of claims.
To qualify for consideration to receive a reward under the Crime Watch Program, an agent must satisfy a few requirements:
- The reporting agent must be an active Alliant National agent in good standing.
- The agents must prevent a fraudulent transaction or forgery involving a real estate transaction that was intended to be insured by Alliant National.
- In the case of forgery, the intended forgery must include the falsification of a signature with an intent to defraud.
- The Crime Watch Nomination form must be executed by an owner/manager.
- All available and relevant documentation – including evidence showing that the transaction was to have been insured by Alliant National – must be submitted to the appropriate Alliant National State or Regional Agency Manager along with the Award Nomination form.
The submission form and all relevant documentation will be reviewed by the company and a final determination will be made.
Siesta Title Spots Suspicious Activity
Siesta Title and Escrow Services LLC, a title agency headquartered in Port Charlotte, Fla., recently submitted a suspected fraud to Alliant National. Their story underscores the importance of Alliant National’s Crime Watch Program and how collaboration between agents and underwriters can help stop fraud.
The property in question was a vacant lot in Port Charlotte that had been owned by a Canadian man for 30 years. Quite quickly there were communication problems and other warning signs that something about the transaction was amiss.
“The seller was hard to reach from the beginning, did not respond to emails and only called once, but it was a horrible connection,” said Amanda Pertuch, the submitting agent.
Some of the other indicators that tipped Amanda off to the questionable nature of the transaction included:
- The purported seller having suspicious-looking ID
- The purported seller’s wiring instructions going to a foreign bank
- The purported seller’s letterhead having an address associated with a vacant lot
- The purported seller not having a bank account in the same country where he holds citizenship
- The notary on the closing documents was already on Siesta’s fraud alert list
- The purported seller not showing up in any Google searches
Following verification by Amanda’s manager and Alliant National, the suspected fraud was confirmed, and the transaction was cancelled. The proposed liability amount for the transaction was $160,000.
“I’m glad and relieved that we were able to catch this fraud attempt,” said Pertuch. “Anti-fraud programs are important for our industry to keep claim costs under control. I’m happy Alliant National and Siesta Title were able to take care of this quickly and efficiently.”
If you suspect fraud, notify your manager immediately. Your manager may investigate further and will determine next steps. Under no circumstance should suspicions be communicated to outside parties without prior approval from your manager.
Fraudsters will often attempt to speed the transaction along; do not let them succeed. If you suspect fraud or forgery, conduct a full investigation before proceeding to close the transaction and issuing the policy.
Managers should contact Alliant National underwriting or claims for further assistance.
Working Together, We Can Limit Fraud
Alliant National is committed to limiting fraud and lowering claim costs. However, we can’t do it alone. Just as our ability to deliver high-quality title insurance hinges on our partnerships with agents, so too does our capability to detect and thwart fraud. And as Siesta Title and Escrow Services’ work shows, when those partnerships work, real results that reward agents and protect transactions are indeed possible.
[i] Wire Fraud (nar.realtor)
The FBI’s Internet Crime Complaint Center (IC3) 2021 report released in March highlighted an “unprecedented increase in cyberattacks and malicious cyber activity” resulting in a dramatic escalation in financial losses.
In 2021, IC3 received 847,376 complaints from consumers and businesses – a 7% increase from 2020 – with potential losses exceeding $6.9 billion. Most significantly for the title insurance industry, business email compromise (BEC) schemes resulted in losses of nearly $2.4 billion, up 33% from 2020.
In its report, the IC3 identified Russia as a hot spot for cyberattack actors in 2021. In recent weeks, the risk of those cyberattacks has grown exponentially in retaliation for the many sanctions imposed on Russia following its invasion of Ukraine on Feb. 24.
On March 21, President Biden released a statement highlighting the imminent threat to our nation’s cybersecurity. That same day, Deputy National Security Advisor Anne Neuberger said in a press briefing, “We’ve previously warned about the potential for Russia to conduct cyberattacks against the United States, including as a response to the unprecedented economic costs that the U.S. and allies and partners imposed in response to Russia’s further invasion of Ukraine. Today, we are reiterating those warnings, and we’re doing so based on evolving threat intelligence that the Russian government is exploring options for potential cyberattacks on critical infrastructure in the United States.”
These imminent threats are a reminder of how important it is to take the necessary steps to protect your agency and your customers.
Alliant National has just released a white paper titled Escrow Fraud/Social Engineering: Recent Schemes and Prevention Tips to provide our agents with information, risk factors and protocols that will help you partner with consumers, real estate agents and lenders to defend against the fraudsters.
In addition, the Biden Administration released a Fact Sheet, urging companies to take immediate steps to protect their systems, including:
- Mandate the use of multi-factor authentication on your systems to make it harder for attackers to get onto your system
- Deploy modern security tools on your computers and devices to continuously look for and mitigate threats
- Check with your cybersecurity professionals to make sure that your systems are patched and protected against all known vulnerabilities
- Change passwords across your networks so that previously stolen credentials are useless to malicious actors
- Back up your data and ensure you have offline backups beyond the reach of malicious actors
- Run exercises and drill your emergency plans so that you are prepared to respond quickly to minimize the impact of any attack
- Encrypt your data so it cannot be used if it is stolen
- Educate your employees on common tactics that attackers will use over email or through websites
- Encourage employees to report if their computers or phones have shown unusual behavior, such as unusual crashes or operating very slowly
- Engage proactively with your local FBI field office or CISA Regional Office to establish relationships in advance of any cyber incidents
The Biden Administration also encourages IT and security leaders at all companies to visit the websites of CISA and the FBI to access technical information and other useful resources. These heightened threats represent a clear and present danger for all of us. We encourage all of our agents to download the Alliant National Escrow Fraud/Social Engineering today and share this information with your staff and customers.