Security & RansomwarePublished May 10, 2014

What to Do About the Heartbleed Bug

A plain-English explanation of the Heartbleed OpenSSL vulnerability and the steps small businesses should take.

Heartbleed is a serious vulnerability discovered in OpenSSL, the encryption software used by a huge portion of websites and servers to secure data in transit. In simple terms, it allowed attackers to read small chunks of a server's memory — potentially including passwords, private keys, and other sensitive information — without leaving obvious evidence behind.

If your business runs any public-facing servers using OpenSSL, the first step is confirming with your hosting provider or IT team whether they've been patched. Most major hosting providers and cloud services patched their infrastructure within days of the disclosure, but custom or self-managed servers need to be checked individually.

As a precaution, we recommend resetting passwords for any business accounts on services that have confirmed they were affected and have since patched. Changing a password before a service is patched doesn't help — wait for confirmation the fix is in place first.

Prefer to have this handled for you?

Our team can take care of this and everything else on your IT plate — no obligation to find out how.