Monday, April 24, 2017

Teach your employees well


Small business hacking is becoming more prevalent. The payoff isn’t as big but the opportunity is greater and security is lacking. Security firm Symantec reported in 2016 that 43% of cyber attacks were against small business. Small businesses have little in the way of security and employee training. They often have more to lose in the sense that they have less cash flow or all of their money is tied up in their business. Making them more likely to pay ransoms. (Ransomware is explained in more detail in our post-If you ever want to see your files again…)

Attacks can be as simple as rerouting the web address to a porn site, locking all of the computers for a ransom, all the way to hacking financial data and cleaning out bank accounts. More than half of the companies attacked were forced to go out of business. Maintaining sound computer security cannot be emphasized enough.

The website Small Business Trends, in an article posted January 3, 2017, stated that 48% of attacks are caused by an employee error. In addition to updating security software one of the biggest defenses owners can deploy is educating their employees on cyber attack indicators. The malware has to enter the system somehow. Simply clicking on attachments will send the virus into the network to do its work. The more stealthy viruses will enter the system without a show of existence. These are meant to mine data from the system. By the time you find the virus the bank accounts are fleeced.

Regularly train employees on different types of attacks and how to defend against them. Establish a policy for computer usage. Explain what is acceptable Internet use. Malware can be injected via email attachments or links to websites. These links can be introduced through email or social media. Demonstrate what a suspicious email, link, social media contact looks like. Practice solid password policies and change regularly. Encourage employees to speak up when something is suspicious and do not click on the suspicious activity.

Even if you do not think you store valuable data, although customer records are a valuable commodity, the chance of losing your business data or risking a financial attack is too great a chance to take.

See our blog archive for other posts relating to cyber security:



Wednesday, April 12, 2017

437th sine die


The 437th session of the Maryland General assembly came to a close on Monday, April 10, 2017. Here are the business related laws that were passed.

Paid sick leave: Businesses with 15 or more employees would be required to provide five days of paid sick leave.

Manufacturing: Tax incentives will be offered to companies that add manufacturing jobs and provide related training for skilled workers.

Health care: A commission was formed to monitor federal actions that affect Maryland health care.

Governor Hogan has said that he will veto the paid sick leave bill. Governor Hogan proposed his own paid sick leave bill that set the employee mark for businesses at 50 and included tax incentives for smaller companies that offered paid sick leave. If the bill is vetoed, the legislature does have the necessary votes to override the veto. However, lawmakers will not have an opportunity to override the veto until next year’s legislative session, delaying the implementation of the bill until 2018.

437th session has more business laws January 2017

Tuesday, March 28, 2017

Customer service in the millennial age


Several recent experiences with different companies chat service have proven to be helpful and satisfying interactions. It seems that the customer service experience through chats and emails has been getting better. Either training has improved or companies are finally responding to customer needs. Another possible solution for this phenomenon is that the work force is getting younger.

According to a U.S Census Bureau report from June 2015, millennials represent more than one quarter of the nation’s population at 83.1 million. In comparison, the next largest population are Baby Boomers at 75.4 million. With their defined birth years between 1982 and 2000, they are well into the workforce and setting policy and trends. The economic landscape is adjusting. Millennials have grown up always digitally connected through cell phones, computers, games, and tablets. They tend to have less money to spend and will use their digital resources to scour for deals. The biggest generation in U.S. history is changing our economic landscape and how companies do business.

Companies have had email and chat alternatives for customer service contact for some time. It is reasonable to say that as millennials enter the work force they will bring their values and habits with them. One of those is reluctance to speaking on the telephone. They’d much rather stay within the digital world. They, themselves, use resources such as chat and email to communicate with business. In turn they provide the same service they would like to receive, putting more effort into something in which they believe a valuable resource.

Just a theory.

See our blog archive for other posts relating to millennials:
#IQUIT February 2014

Wednesday, March 15, 2017

Should social media rants get you fired?


Should an employee be fired because of social media rants? Some business experts feel that employees that sound off should be fired because they don’t uphold the character and face of company. The National Labor Relations Board (NLRB) has heard these types of cases since 2010 and began issuing decisions in 2012. The NLRB usually sides with the employee, reasoning that the employee’s social media postings are protected activities under the National Labor Relations Act, specifically-Employee rights to organize and speak out against unfair labor conditions.

If the rants take place on company time, using company resources, the employee could be disciplined for infractions other than the actual posting. But when the postings occur outside of work, the line has been drawn between employee rights and violating policy.

Beyond firing someone for something you don’t like on social media is the policy prohibiting the rant. If the company doesn’t have a policy then little action can be taken. Many businesses, especially small business, have no policy regarding social media. Employee handbooks and company policy need to be  living documents. It seems like there is always a new topic to be covered. Social media policy is an extension of that organism. Although social media and employees going off on their employers are not new, the policies governing how businesses handle it are still evolving. And the NLRB helps draft those policies each time it offers a decision. Businesses have to stay abreast of the issues and the decisions being made.

Defending the honor of the company or getting rid of a bad employee, firing someone for his or her rants on social media can be a dicey situation. Opening up the company as well as the person responsible for the firing to court action.

See our blog archive for other posts relating to social media policy issues:


Wednesday, March 1, 2017

How well do you know someone?


Watching the vetting process for the new presidential cabinet you heard politicians and others vouching for the nominees.  They would qualify their knowledge of the person’s background by stating how long they’ve known the person, “I’ve known this person for five years.” Really? Five whole years?

There is the possibility that you can really get to know someone in a short span of time. But it is highly unlikely, especially if you’re not with the person 24/7. There have been incidents of husbands and wives, who have been married for more than a decade, not knowing of the others “secret” life. So how can you vouch for a person, you have known for five years, and periodically interact with? If your “friend” is forty and you’ve known them for five, or even ten years, that seems like an eternity. However, they’ve had twenty-two years of adulthood before you ever met them.

Then you have the now cliché neighbor of a crime suspect, “[He’s] always been a good neighbor. Quiet. Never bothered anyone.” Chances are the neighbor is basing their assessment on fact. They never really knew the suspect so, of course, they were quiet and never bothered anyone.
If a background investigator has ever contacted you regarding an investigation for a security clearance how well you know someone can become shockingly evident. People obtaining security clearances fill out a questionnaire, part of which includes references. These references have to be non-work, friends and neighbors. Sometimes you have no idea why your name was used. You hardly know the person. But sometimes the investigation is for someone you’ve “known” for ten or more years (Most backgrounds require the reference to be a person you’ve known for five or more). But you don’t hang out with them, you don’t interact socially, you lose touch. But here is your name as a reference. The investigator starts asking the standard questions and you realize that although you’ve known this person since college, you cannot provide one piece of information that can verify anything about the person’s proclivity for cheese or espionage.

So to stand before a congressional committee and state that, “I’ve known this person for five years and they have absolutely the best character”, is little bit of a stretch.

See our blog archive for other posts relating to character association: 


Tuesday, February 14, 2017

Tax [Fraud] Season


Once the calendar year turns over thoughts of filing taxes begin. So do the warnings of tax fraud and prevention tips. Having been the victim of tax fraud I know the inconvenience of proving your true identity to the IRS; now having to file under a number rather than your true name. As the digital world expands, so does tax refund fraud. It’s a good bet that you know someone who has been a victim or that you, yourself, are a victim.

Theft

Most people will file their tax returns electronically, either themselves or through a tax preparer. It’s quick, it’s easy, you get your refund faster. Unless you get an error saying that you have already filed. You’re first reaction is that there is a mistake, but you soon realize that you have been the victim of identity theft. Someone has obtained your name and social security number and filed your taxes on your behalf.

It may not have been a direct theft in the classic sense. It could have happened during an electronic data breach of a larger scale or someone hacked your computer, any number of ways. Your information is uploaded to the dark web (it’s a real thing that criminals use to conduct their business or exchange information) and resold many times. The criminal then fills out an electronic tax return with your information and bogus financial information and has the refund sent to a direct deposit or PO Box. The IRS does compare information against past filings but that doesn’t occur until well after the refund has been issued. Software is in place to try and stop fraud, but, again, the refunds are issued so quickly it happens before any alarms go off.
You then have to go through an arduous process to prove yourself to the IRS, file the fraud report, and wait for the IRS to investigate your claim. If they find that you are a victim they will then issue your return and assign you an identification number to use for future filings. The whole process takes several months. Other than the waiting, it really wasn’t an unpleasant experience and the refund was issued in a timeframe shorter than expected. It’s also interesting to request a copy of the fraudulently filed return from the IRS. You get to see what deductions your other self made and the amount some PO box received.

Prevention

One school of thought of being susceptible to fraud is filing returns late in the season, near the April 15 deadline. This gives the criminals time to file their fake returns and receive the refunds before you file. Tax regulators say to file early to get a refund as quickly as possible, thus beating the criminals to your money. States have even made the effort to streamline the process so that refunds are received as quickly as possible after the return is filed.

Law enforcement doesn’t comment on the timing of the filing, but rather to delay the issuance of the refund so that fraudulent returns can be identified.  At a recent tax security summit, the U.S. Attorney for Maryland, Rod Rosenstein, commented from the panel, “The quicker you are on paying refunds, the greater the risk of not finding fraud.”

Hawaii, Illinois, Louisiana, Minnesota, Montana, North Dakota, South Carolina, and Utah are some of the states that are slowing returns to further prevent fraud. Maryland issues refunds within two days of receipt of the return. The comptroller’s office relying on analytical software to detect digitally filed fraudulent returns. Additionally, Maryland will not issue refunds until the comptroller’s office has a W-2 on file. With these methods in place the comptroller’s office hopes to combat fraud while at the same time efficiently serving the taxpayers.

The Maryland legislature this year is considering a bill named the Taxpayer Protection Act of 2017. This bill would give the comptroller’s office broader authority to build criminal cases against fraud and extend the statute of limitations for prosecution to six years.

There is no way to know if your personal data has been stolen. Regarding taxes it is best to file early. If you do become a victim, report it to the comptroller’s office and IRS as soon as you are aware. Document everything you do and who you speak to. Secondarily, begin looking into your banking and credit cards as they may have been breached as well. Review statements and set up alerts.

Be sure to read our others posts related to identity theft.

Wednesday, February 1, 2017

Which came first …


Read an interesting article about the Maryland marijuana dispensaries. Seems that it is now legal to grow the marijuana for medicinal resale, but remains Illegal to buy seeds or seedlings to start the growing process.

Maryland passed a law in 2014 decriminalizing smaller amounts of marijuana and allowing for dispensaries to grow and dispense medicinal marijuana. In December 2016 the Maryland Medical Cannabis Commission approved 102 dispensaries that have been granted a license to begin growing marijuana. They have 365 days to begin their operations. The problem for these newly licensed businesses is-How do you start a business based on growing an organic product when it is illegal to buy or import the seeds or seedlings?

Once the grow operations have their crop started that crop and further crops are legal under the law.  However, obtaining the startup seeds is illegal under federal and Maryland law, as well as some other states that have approved medical and/or decriminalized marijuana. In Washington, D.C. for example, it is legal to possess and grow marijuana at home but illegal to buy or sell seeds and plants. Mostly state regulators and law enforcement are turning their heads when it comes to the topic. A don’t ask don’t tell sort of thing.

With all the politics that went into decriminalizing marijuana in Maryland and setting up the laws to allow for dispensaries it seems like someone would have taken this conundrum into consideration. Now that the licenses have been granted and the dispensaries are on the clock it will be interesting to see if this legislative session takes up the issue and corrects the legal blockade.

See our blog archive for other posts relating to medical marijuana: