
Bigger Name, Bigger Target
(And we're not referring to the name of the municipality or official!)
Ever notice that many of the email hacking headlines, like Sarah Palin, and recently, Jeb Bush, involve some of the largest email providers out there:
GMail, Yahoo, et al? Why is that? Well, for two reasons:
1. The most obvious is that these providers are
high on hackers' radar. Everybody knows them and knows how to use their systems, and there is a bigger payoff for compromising them.
2. Hackers recognize that people using these providers are often
less technically sophisticated, and likely don't have skilled IT personnel helping them out. So, they're more apt to fall for
phishing scams, or use weaker passwords that are
easier to crack.
It's kind of like the old observation about there being more viruses for Microsoft's operating systems than for Apple's: more users and more opportunities for malice.
Size Matters
Whether the size of your security team, or the skillset possessed, a high level of expertise is crucial. Just because your organization has an "IT Manager," or even a small team, doesn't mean they have all of the skills and resources necessary to
successfully thwart hackers.
Even if Bill Gates is your IT Manager, does he have all of the tools he needs to adequately lock down, monitor attacks against, and mitigate compromises of, all your exposed servers, workstations, and so on?

As both the Lake and Glades County Sheriffs' Departments learned the hard way, it is very difficult to cover all of the bases with in-house resources. Larger organizations, and service-specific providers are able to leverage economies of scale that smaller organizations' budgets just don't allow.
For example, many organizations operate an in-house Microsoft Exchange Server for their email. However, everything is typically run from a single server - including Outlook Web Access, if they've configured it for their users. Even if they have this server behind a firewall, it's not enough to secure it properly!
These organizations are not aware that proper security involves multiple layers to prevent not only compromise of the server itself, but also intrusion into their network by viruses and other malicious content - these are security breaches as well! For Vistalogix's own email hosting, we use an 8-layer approach to protecting our clients email service, implemented in 3 key ways:
1. 256-bit SSL encryption on connections to all devices, including webmail, desktops and mobile phones.
2. 4-stage virus detection and removal, starting with restricting malicious attachments, then identifying message formatting vulnerabilities, Analyzing ZIP attachments, and finally scanning with industry-leading ClamAV.
3. 3-level Spam/phishing filtering, beginning with gateway scanning, followed by screening with scanning by ARM Research Lab's Message Sniffer.
These items all require servers of some sort or another - not only because of the processing horsepower they need, but to isolate their functions from one another. As you can see from the diagram below, if your organization is like most, you're far from properly secured!

Keep 'Em Separated
Jean-Marie Mark, Town Manager for Hillsboro Beach made an interesting statement recently, while being interviewed about the hacking of her town's website: "If I shut it down, it will cut off e-mail access to our employees."
Among others, this is one of the reasons Vistalogix keeps our email hosting
separated from our web servers - separated by several states, in completely
different datacenters! Even if a hacker were able to compromise one of our clients' sites, this would not affect email service, and vice versa.
Hacking is not the only concern when all of your eggs are in one basket. What happens if your facilities become unusable, say, due to disaster?
Or, many
low-cost web hosting providers house email on the same server as your website, along with
100-250+ other websites. What happens if one of those other websites is hacked, or that server fails for some other reason?
Shift Accountability
Everybody likes to have someone to blame, or as one of our clients refers to it, having a "
throat to choke," when things go wrong. It's far easier to have a provider whose sole purpose in life is delivering, say, email, and who has the resources to throw at an issue when it arises.
More and more, organizations are realizing the value of taking responsibility
off of their own shoulders for things others have much more expertise in. Not only are they taking advantage of economies of scale, but they now have a much more credible resource to blame if things go wrong.
If your organization is managing its own IT, what looks more
credible to your stakeholders in the event of a major problem: that you were hit by it with your limited skills, or that Microsoft itself was hit by it?
You get the picture.
One-Man Wolfpack
What should the aforementioned sheriff's departments do after their email servers were hacked? Have the same IT manager use the same inadequate tools to try and fix it? If he had
ALL of the necessary skills and tools to fix the problem, why was it not secured in the first place?
Moreover, what if there was another failure in another critical IT system at the same time? Which should should he fix first?
The worst part? Your county, city, town, or even business can avoid being targeted, without spending a fortune. If you need guidance on how, simply call (or email) us - we'll point you in the right direction.