Q1
Q1

Anywhere.  The great part of how this works is that the majority of the work can be done from anywhere by utilizing remote access and VPN technology.  We can work on your network from anywhere just as if we were sitting in your data center.  If your business is not in a location where we have an office, we have partners throughout the country who will work as a part of our team to deliver On-Site Service when necessary.  We supervise them very closely and have done the research to ensure our partners have the knowledge and experience necessary to meet our high standards of service.  This arrangement is seamless to our customers.

Q2
Q2

Because of the high-level access we will have to your network, yes.  However, Outsource IT has very  strict policies regarding the abuse of this privilege.  It is written in our service contract as well, we will never  access a client's private data without prior authorization.

Q3
Q3

Upon initiation of service we will install a small box called an OIT Core into your network.  The OIT Core establishes an encrypted connection with our network, sends us real-time monitoring data, and allows our network engineers access to work on your system.  It is configured to block all incoming connections and will only initiate a connection to our system, so no one else can use it as a tool to gain access to your network. 

Because we have designed such a system, your network is completely independent of Outsource IT and will not ever be dependent on our equipment to function.

Q4
Q4

Through the use of Remote Desktop technology.  When a customer calls in and needs assistance, we will stay on the phone with them and share control of their desktop through the Internet.  Since we can see exactly what they see, we can quickly troubleshoot the problem and walk the user through every step.

Q5
Q5

There are many benefits to outsourcing technology that every company, large or small, can gain from.  Click Here for some good pointers. 

Here's something else to consider: when you outsource your technology to Outsource IT, it is a 100% deductible operating expense.

Q6
Q6

Inside attacks are often the most dangerous because attackers are already familiar with your organization's computers, applications and security measures and know which actions might cause the most damage.  They have the advantage of working from the inside-out, so firewalls may not stop them! 

The National Threat Assessment Center of the U.S. Secret Service recently completed an Insider Threat Study, consider a few of the sobering facts this study uncovered:

  • Most insider events were triggered by a negative event in the workplace.
  • Most perpetrators had prior disciplinary issues.
  • Most insider events were planned in advance.
  • Only 17% of the insider events studied involved individuals with administrator access.
  • 87% of the attacks used very simple user commands that didn't require any advanced knowledge.
  • 30% of the incidents took place at the home of the insider using remote access to the organization's network.

In fact, a recent report from Ernst & Young reported that insider attacks against large companies cause an average of $2.7 million in damages, whereas the average outside attack costs only $57,000. 

Our point: most companies focus so much on securing the outside-in level of their network, that they forget about their most vulnerable area: the inside.  Network security is a very fast-paced world, and unless this is your core business it's hard--if not impossible--to keep up.  The two most common culprits of internal network breaches are:

  • Disgruntled workers.  If you have current or former employees who hold a grudge against your company, they may decide to take revenge into their own hands. These individuals likely know the inner workings of your organization and may retain system access due to weak security policies. This concern has escalated in recent years because of increased outsourcing and organizational downsizing in both public and private sectors -- both of which can leave individuals bitter and hostile.  Keep in mind, not all insider threats come from current employees. They could also be consultants, contractors, temporary employees and close-knit business partners who have detailed knowledge of your company's information technology systems. They may also know how to hit your organization where it hurts -- by stealing, deleting or altering sensitive information or otherwise sabotaging your systems.
  • Non-malicious employees.  When Jane's friend suggested she use a new software program to generate more sales leads, she was thrilled. She didn't know, however, that downloading this unauthorized software program from the internet onto her company laptop could do a lot more harm than good. Unfortunately, Jane not only downloaded the software, but also some hidden malware and phishing ploys that were quickly transmitted to the company network.  Unfortunately, those who use your company IT resources in ways they shouldn't (i.e., by storing content or playing games) comprise the vast majority of your employees.  Chances are, there are many people in your company today who take small liberties with your company network. They may check their personal e-mail, play games and do some online shopping while on the clock. While they can pose a significant security threat, it is rarely intentional.  As a general rule, these employees have a very limited knowledge of security practices and can put your company at risk simply through some bad habits or improper training. Others may come to work armed with a variety of devices and gadgets, all of which get plugged into their PC.  As harmless as their intentions may be, they still represent a security threat that needs to be harnessed. 

So what can you do to reduce the risk? 

Most of the time, simply implementing and enforcing policies, backed up by system-driven control will eliminate most of your risk.  The rest can be eliminated by a smart, well-planned network design.  It doesn't necessarily have to be a huge investment.  Here are some examples:

  • Restrict accounts that access resources remotely. The majority of insider attacks use some type of remote access mechanism. If you offer VPN or dial-up access to your employees, consider limiting remote access accounts to those with a legitimate business need.
  • Restrict the scope of the remote access. Don't automatically grant remote access users the same level of privilege that they would have in the office. You'll not only be protecting yourself against the insider threat, but also against the increased risk of malware propagation through a remote access link.
  • Enforce the principle of "least privilege" throughout your organization. Every security professional knows the least-privilege mantra. Each user should have the minimum necessary set of permissions required to fulfill his/her job responsibilities.
  • Perform regular security patch remediation. Believe it or not, many security vulnerabilities already have existing patches. By using them, you'll greatly reduce the likelihood of security threats -- from insiders as well as outsiders.
  • Create effective security policies. After you set up the business rules that guide both human behavior and system settings, gain signatures from all employees, and strictly enforce those policies.
  • Stress employee awareness and education. Educate your employees on what constitutes dangerous and/or unacceptable behavior, and reinforce these guidelines through regular security awareness campaigns. These efforts may include posters, seminars, and e-mail reminders of existing security dangers and how to avoid them.
Q7
Q7

Absolutely!  In fact, we can even remotely view the screen of Windows Mobile and Blackberry devices and provide remote help desk support in the same way that we do regular PC's!

Q8
Q8

Immediate.  Since we continuously monitor your network, we know about most problems before you even do!  We respond within minutes to begin fixing problems.  Help Desk is available 24x7, and hold times average less than 1 minute

Requests for on-site service are lightning fast too... You can expect a qualified technician to be at your door the same day!

Q9
Q9

Yes.  We are fully capable of offering service with a full-time IT presence at your location.  Some companies benefit from a fully-outsourced arrangement, others simply need to augment their existing manpower.  Pricing arrangements are determined on a case-by-case basis, depending on the needs of your company.  Click here for more details. 

The benefits of a company with such needs outsourcing their technology to Outsource IT are still very clear:  we will still offer you all of our services, including 24x7 help desk and network monitoring, as a part of the package; and we will augment the assigned engineers when additional manpower is needed for projects or upgrades--without accumulating extra charges!