The Rise in Ransomware Attacks and How to Keep Safe

The Rise in Ransomware Attacks and How to Keep SafeCybersecurity experts estimate that there is a ransomware attack every 11 seconds. This makes it a challenge to individuals, businesses and even governments.

In ransomware attacks, cybercriminals encrypt a victim’s network or data, making it inaccessible until a ransom is paid. Despite organizations’ efforts to reduce the attacks, cybercriminals also are advancing their attack methods. For instance, an organization may have backups they can use to restore their systems, but the criminals also demand ransom not to publish the sensitive company information they have in their possession.

Ransomware is not a new cybersecurity threat. It is traced back to 1989 when the first ransomware was released through floppy disks and required a victim to send money to a post office box in Panama. As technology now has advanced to allow for always-on connectivity, the prevalence of ransomwares has grown tremendously. The use of bitcoin and other cryptocurrencies as payment make it more complicated as they are difficult to trace. These attacks such as the WannaCry, CryptoLocker, etc. have resulted in billions in losses through infrastructure and business outages and millions of dollars being paid to the attackers.

Ransomware has grown so much that organized gangs are offering cybercriminals services for hire. This is made more intricate by the availability of ransomware-as-a-service (RaaS) to provide infrastructure to other cybercriminals to escalate their attacks.

Ransomware has become such a global threat that in a joint advisory made up of CISA, FBI, NSA and International Partners, has called for every government, business and individual to be aware of this threat and take necessary action to avoid becoming victims.

President Joe Biden also continuously issues warnings to business leaders to strengthen their companies’ cyber defenses. The risks of cybersecurity are expected to increase with the ongoing invasion of Ukraine by Russia.

On the other hand, there are efforts to reduce the threat scale by various groups. One such group is the Cyber Threat Intelligence League (CTI-League), made up of cybersecurity experts from different countries. They have helped take down malicious websites, detect vulnerabilities, collect and analyze different phishing messages, and assist law enforcement organizations in creating safer cyberspace.

Protecting Against Ransomware

Before a ransomware attack is fulfilled, there are detectable activities that can aid in mitigating an attack. In any case, the attackers target specific user behavior, unchanged default security configurations and common technology vulnerability. This means that ransomware attacks can be avoided. Some ways to keep safe from ransomware include:

  1. Timely patches – ensure to patch operating systems and other software immediately whenever a patch is released. Patching also should apply to cloud environments, including virtual machines, serverless applications and third-party libraries.
  2. Keep backups – it is impossible to fully protect an organization network as one user action may expose the network to attacks. Regularly backing up data is crucial. However, ensure that cloud backups are encrypted and can’t be deleted or altered. Also, always keep a backup version that is not accessible through the cloud to ensure business continuity in case of an attack.
  3. User training – users are considered the weakest link in the line of defense against cybersecurity. An attack can start with a seemingly legit email containing a link or an attachment that downloads malware to a device once clicked. Therefore, continuous user training and phishing exercises will help reinforce user responses to suspicious emails.
  4. Secure and monitor RDP – as more people adopt remote working, they rely on the remote desktop protocol to connect to office computers or colleagues. This has made RDP one of the most commonly used methods for attackers to gain access to a network. Therefore, businesses should use Network Level Authentication (NLA) and use unique and complex passwords for users to authenticate themselves before making a remote connection. Other ways include multifactor authentication, setting time limits to disconnect inactive RDP sessions automatically, and limiting login attempts.
  5. Use up-to-date antivirus software – this should be used to regularly scan the systems and scan files downloaded from the internet before they are opened.
  6. Network monitoring – use network monitoring tools and intrusion detection systems to look out for any suspicious activity.

The CISA, FBI, NSA and International Partners joint advisory discourages paying ransom to cybercriminals and recommends following the CISA ransom response checklist, and reporting to cybersecurity authorities such as the FBI, CISA or the U.S. Secret Service. System administrators should also follow incident response best practices that can aid in handling malicious activity.

Banning Masks, Banning Russian Oil, Making Lynching a Federal Hate Crime and Saving Sunshine

Banning Masks, Banning Russian Oil, Making Lynching a Federal Hate Crime and Saving SunshineConsolidated Appropriations Act, 2022 (HR 2471) – This legislation will fund the federal government through September 2022, but also includes a plethora of other bills folded within for the purpose of quick passage by both the House and Senate. Among them is the reauthorization of the Violence Against Women Act and the allocation of $13.6 billion in additional aid to support Ukraine in its conflict against Russia. The bill was signed into law by President Biden on March 15.

STANDUP Act of 2021 (S 1543) – STANDUP is the anacronym for Suicide Training and Awareness Nationally Delivered for Universal Prevention. It authorizes the Department of Health and Human Services (HHS) to give preference to state, tribal and local educational agencies when awarding certain grants for priority mental health needs. Specifically, plans must include evidence-based suicide awareness and prevention training policies. The bill was introduced by Sen. Maggie Hassan (D-NH) on May 10, 2021. It passed in the Senate on Dec. 14, 2021, the House on Feb. 28 and was signed by the president on March 15.

Suspending Energy Imports from Russia Act(HR 6968) – This bill was introduced by Rep. Lloyd Doggett (D-TX) on March 8. It is the bill that bans the import of Russian oil in response to the country’s invasion of Ukraine. The act also gives the president permanent authorization to impose visa- and property-blocking sanctions based on violations of human rights. In addition to oil, the act blocks importation of other Russian products such as mineral fuels, mineral oils and products of their distillation, bituminous substances and mineral waxes, with the exception of prior contracts or agreements. Subject to congressional approval, the president may waive this prohibition for national interest reasons. The bill also takes initial steps to suspend Russia’s participation in the World Trade Organization. The legislation passed in the House on March 9 and is currently under consideration in the Senate.

Sunshine Protection Act of 2021 (S 623) – The purpose of this legislation is to make daylight savings time the new, permanent standard time. The bill states the change would begin on Nov. 5, 2023, in order to give airlines and other industries time to adjust their schedules and processes. States that currently contain areas exempt from daylight savings time will have the option to choose standard time for those areas. The bill was introduced by Sen. Marco Rubio (R-FL) on March 9 and passed in the Senate on March 15. It is currently under consideration in the House.

Postal Service Reform Act of 2022 (HR 3076) – This bipartisan act was introduced by Rep. Carloyn Maloney (D-NY) on May 11, 2021. It passed in the House on Feb. 8, the Senate on March 15 and is awaiting the president’s signature to become law. The bill will repeal the annual prepayment requirement for future retirement health benefits; establish a Postal Service Health Benefits Program to offer health benefit plans for USPS employees and retirees; coordinate enrollment for retirees under this program and Medicare; and develop a publicly available dashboard that tracks service performance and reports on USPS operations and financial conditions.

Emmett Till Antilynching Act (HR 55) – This act was introduced by Rep. Bobby Rush (D-IL) on Jan. 4, 2021. This act designates lynching as a federal hate crime, and imposes the criminal penalties of a fine, a prison term of up to 30 years, or both. It applies to anyone who conspires to commit a hate crime offense that results in death or serious bodily injury; kidnapping or an attempt to kidnap; aggravated sexual abuse or an attempt to commit aggravated sexual abuse; or an attempt to kill. The bill passed in the House on Feb. 28 and the Senate on March 7. It is awaiting the president’s signature to become law.

A joint resolution providing for congressional disapproval under chapter 8 of title 5, United States Code, of the rule submitted by Centers for Disease Control and Prevention relating to “Requirement for Persons To Wear Masks While on Conveyances and at Transportation Hubs” (SJRes 37) – The purpose of this joint resolution is to nullify the CDC rule issued in February 2021 to require face masks on planes, trains, buses, and other public transportation systems and hubs in order to prevent the transmission of COVID-19. It was introduced by Sen. Rand Paul (R-KY) on Feb. 10 and passed in the Senate on March 15. It is currently in the House for consideration.

Taxation of Legal Settlements and Fees

Taxation of Legal Settlements and FeesThe taxation of legal settlements and fees is a complex topic. While the mechanics to make a proper claim are now easier, the rules are still complex. Below we look at six rules to consider when it comes to the taxation of legal settlements and the deduction of legal fees on your taxes.

  1. Taxes depend on the origin of the claim; or in plain English, according to why you are seeking recovery. For example, in a case where the plaintiff is suing another business for losing profits, the settlement would be considered lost profits, and therefore would be ordinary business income. If a worker sues for unlawful termination, then the settlement would be considered wages and taxed accordingly. Another example is where a plaintiff sues a negligent builder; here the damages won’t be classified as income, but instead will reduce the purchase price of the real estate.

    The big difference in the above examples is that in the first two cases the settlements are taxable; in the third, they are not. As with many things in tax law, be aware that the rules are full of nuance and exceptions.

  2. Some recoveries are tax free, even if they wouldn’t appear to be on the surface. One example here is cases of personal physical injuries, like a car accident. While you may be suing for lost wages due to the inability to work, the damages should be tax free due to section 104 of the tax code that shields damages for personal physical injuries and physical sickness.

    The important distinction here is the physical requirement. The IRS is unclear exactly what constitutes physical harm, but generally requires that you can physically see the injury.

  3. Medical expenses are tax free. Regardless of the type of harm (physical or emotional), payments for medical expenses are tax free. Moreover, the definition of medical expenses is rather broad.
  4. Allocating damages can save on taxes. Most legal disputes involve multiple issues, and as a result the total settlement amount will involve several types of considerations. The parties in suit can agree to the allocation of the settlement according to the issues – and therefore its tax treatment. While these agreements aren’t binding to the IRS, they’re rarely ignored and can provide a good defense for your tax position.
  5. Attorney fees can be a trap. However you pay your attorney – whether hourly or on a contingent fee basis – legal fees will affect your net recovery and your taxes. Plaintiffs who use contingency fee arrangements are typically treated (for tax purposes) as receiving 100 percent of the money recovered. In other words, you’re taxed on the part of the money your attorney takes out of the settlement.

    To understand this a little better, take an example suit for emotional distress where you recover $200,000 in damages, with a 40 percent contingency fee arrangement with your attorney. Here, the plaintiff is going to have $200,000 in taxable income even though they only received $120,000 (with $80,000 going to the attorney). Not all lawyers’ fees face this draconian tax treatment, but this is the general rule in contingency fee cases.

  6. Punitive damages and interest are always taxable. This is true even if the injuries are 100 percent physical. Take a case of a car crash where you get $30,000 in compensatory damages (for the car damage) and $2 million in punitive damages. The $30,000 is tax free, but the $2 million is fully taxable.

Conclusion

These are some of the basic rules surrounding the taxation of legal fees and settlements. There are many nuances and subtleties, but what you should take away from this article is that, in many cases, there are ways to structure both any settlement received and how you pay your attorney to minimize your tax burden.

How Businesses Can Stay Current with the Digital Economy

Digital EconomyAccording to the U.S. Chamber of Commerce, the level of usage and data swirling around the internet is expanding at an accelerating pace. The amount of data on the internet globally during 2020 amounted to 3 trillion gigabytes; and 2022’s traffic is expected to increase to 4.5 trillion gigabytes. As a result, the U.S. Chamber of Commerce is concerned about the challenges American companies will have when it comes to business competitiveness.

According to a survey from Statista titled “Challenges encountered as a result of digital transformations in global organizations as of 2020,” there are common challenges that businesses are facing, such as:

  • 51 percent of respondents said that “skill gaps have opened up on traditional teams as top talent moves to digital teams or products”
  • 48 percent said that “cultural differences or conflicts have arisen between traditional and digital teams”
  • 41 percent also mentioned that “traditional teams have struggled to keep up with the pace of how digital teams work”

With so many issues businesses face as technology races ahead, it’s important for organizations to recognize and adapt to the dynamics of digital commerce. According to Harvard Business Review (HBR), it’s important to align the business and its goals correctly, especially when it comes to getting the most out of software development. For example, when companies buy software, they generally use third-party software for all their needs. While accounting and human resources functions may be fine for standardized uses, there are often situations when a personalized approach is needed to provide customers with a memorable experience.

HBR suggests businesses take certain steps that can make the journey easier and more effective in the long run. The first thing to do is identify current information technology-focused employees, because they’re the most closely aligned and ready for the transition. Along with looking for outside talent, it’s important to let internal software developers have an active role in the process.

It’s also important to let developers be stakeholders (along with accountability for failure) for solving organizational challenges versus giving them rigid assignments. Don’t focus exclusively on punishing failure; instead, encourage developers to analyze, pick apart reasons why failure happened and how future experiments can incorporate learning from past failures. Include developers in discussions with the people who will be using the software (other employees and customers who will be using it in the future).

Let’s look at Domino’s mobile application development as a case study. They were able stand out by improving their app with a feature that gave customers the ability to track their order from when it was being prepared to delivery. This process included increasing the efficiency of its systems, practices and techniques, along with having employees who performed advertising related functions work closely with software developers. It helped their stock price increase dramatically, performing better than many publicly traded technology companies.  

One challenge for businesses going forward is since there are still tens of millions expected to come online with broadband, the amount of data and traffic will only increase. When it comes to broadband service requirements set by the Federal Communications Commission (FCC), they are at least 25 Mbps to download and 3 Mbps to upload. According to the FCC, approximately 14 million Americans lack broadband, with as many as 42 million reporting lack of access, according to Broadband Now Research. New York City’s Mayor’s Office of Technology reports that 18 percent of NYC residents lack broadband, making it problematic to work from home, access government services online, make doctor appointments, etc.

According to a December 2021 Digital Trade and U.S. Trade Policy report from the Congressional Research Service, there’s no stopping the expansion of trade in the digital world. It found statistics from the Department of Commerce for the “digital economy,” where 9.6 percent of GDP was generated from this sector. It also found that 7.7 million workers were employed because of this approach to commerce. However, unless businesses take care to ensure the same level of communication is accessible, formally and informally, there may not be the same level of efficiency for remote workers.

According to MIT Sloan Management Review, remote workers are at a disadvantage when it comes to indirect types of learning employees have compared with in-person settings. Whether it’s before work starts, during break or lunch time, or interacting with or observing a customer or client, employees working virtually have little to zero of these types of passive opportunities to learn on the job. Be it an additional comment after signing off an email, having a few opportunities to chat or talk online during breaks or similar, this type of passive informal communication needs to be addressed to make up for the in-person experiences other employees have.

While the way work will be conducted in the future can’t be predicted, it will certainly include using the internet – and for many employees, it will involve some time away from the office.

Sources

https://www.uschamber.com/international/ten-trends-in-2022-global-perspectives-for-business

https://www.statista.com/statistics/1133436/challenges-digital-transformation/

https://hbr.org/2021/01/in-the-digital-economy-your-software-is-your-competitive-advantage

https://docs.fcc.gov/public/attachments/FCC-21-18A1.pdf

BroadbandNow Estimates Availability for all 50 States; Confirms that More than 42 Million Americans Do Not Have Access to Broadband

https://sgp.fas.org/crs/misc/R44565.pdf

https://sloanreview.mit.edu/article/overcoming-remote-work-challenges/

How Soon and Fast Will the Fed Raise Rates?

Will the Fed Raise RatesThere’s much uncertainty surrounding if, how and when the Federal Reserve will raise its rates, end its bond and mortgage-backed security purchases, and wind down its balance sheet. For the March 16 Fed Meeting, the CME FedWatch Tool has a 47.9 percent probability of a 25 to 50 basis point increase, and a 52.1 percent probability of a 50 to 75 basis point increase for their Target Rate. There are many expectations for the Fed to raise its Federal Funds rate, or the so-called overnight lending interbank rate. However, there’s a lot of uncertainty as to how many times the FOMC will increase it.

John Williams, Federal Reserve Bank of New York president, mentioned at a recent event that the Federal Open Market Committee (FOMC) will start raising rates at its March 2022 meeting,  but he isn’t advocating for a particularly hawkish approach. Rather, Williams expects inflation to drop due to supply-chain bottlenecks being naturally worked out, along with the Fed’s measured policy actions moderating inflation. However, James Bullard, Federal Reserve Bank of St. Louis president, is more hawkish and has expressed a desire for a 50 basis point rate hike.

Lael Brainard, a member of the Federal Reserve’s Board of Governors, believes six rate hikes are an appropriate course for monetary policy, starting in March 2022. Charles Evans, Chicago Fed president, blames inflation on the pandemic and echoes that supply chain issues will resolve on their own as the world returns to its new normal. Evans also believes that hiring won’t be slowed with higher rates, compared to past rate hike cycles. However, this could change if inflation grows too high as 2022 progress, necessitating more rate hikes.

The Fed has communicated clearly that it will let 1) evolving economic data, in conjunction with 2) maximum employment, and 3) 2 percent longer-term inflation expectations, guide its monetary policy. Noting there’s been a strengthening labor market, it’ll continuously look at how the pandemic is managed healthwise, how global developments unfold and how inflation is expected to and materializes.

It’s important to note that during August 2020, the Fed took a new approach to inflation. Previously, the approach would be to increase borrowing rates during good economic times to prevent inflation from becoming a problem. However, as of August 2020, the Fed’s new approach is to maintain low rates until inflation actually materialized, permitting economic conditions that drive inflation above and below 2 percent. This would thereby create a longer-term average inflation rate of 2 percent when considering monetary policy adjustments.

This is within the perspective of inflation reaching 7.5 percent year-over-year in January 2022, according to the Labor Department. Month-over-month inflation readings include electricity rising 4.2 percent from December 2021 to January 2022. Food costs rose by 0.9 percent in January 2022, up from another 0.5 percent increase in December 2021.

According to the FOMC’s Jan. 26 meeting minutes, there’s much to be contemplated for any potential rate changes. The members found that inflation was elevated, with economic indicators showing inflationary pressures increased in the back half of 2021. In December, the 12-month change in the consumer price index (CPI) was 7 percent, while core CPI inflation was 5.5 percent over the same period.

The year-over-year November 2021 total personal consumption expenditures (PCE) price inflation was 5.7 percent, with the core PCE coming in at 4.7 percent for the same timeframe. When it comes to the unemployment rate, it fell from 4.2 percent in November 2021 to 3.9 percent in December.

Impact of Russia-Ukraine Conflict

Looking at the price of crude oil alone shows how inflation is fluctuating. On Feb. 24, futures contracts at one point had oil hitting $100 and $105 per barrel for West Texas Intermediate and Brent, respectively. While prices retreated, prices are still elevated and subject to international tensions, increasing demand due to the economy reopening from COVID and uncertainty over future output. Undoubtedly, the Fed will take inflation into account – both its new definition of longer-term 2 percent inflation and how it might impact the economy. Some speculate with the high volatility beginning in 2022, the Fed may raise rates by only 25 basis points, not the 50 basis points more hawkish FOMC members have mentioned.

With increased volatility since 2022 began and global uncertainty increasing by the day, it seems the FOMC will have the final say on how many rate hikes will eventually happen.