What to Do About the Heartbleed Bug
A plain-English explanation of the Heartbleed OpenSSL vulnerability and the steps small businesses should take.
Heartbleed is a serious vulnerability discovered in OpenSSL, the encryption software used by a huge portion of websites and servers to secure data in transit. In simple terms, it allowed attackers to read small chunks of a server's memory — potentially including passwords, private keys, and other sensitive information — without leaving obvious evidence behind.
If your business runs any public-facing servers using OpenSSL, the first step is confirming with your hosting provider or IT team whether they've been patched. Most major hosting providers and cloud services patched their infrastructure within days of the disclosure, but custom or self-managed servers need to be checked individually.
As a precaution, we recommend resetting passwords for any business accounts on services that have confirmed they were affected and have since patched. Changing a password before a service is patched doesn't help — wait for confirmation the fix is in place first.
Related Articles
March 12, 2015
Protecting Your Business From CryptoLocker-Style Ransomware
Ransomware that encrypts your files and demands payment is on the rise. Here's how to reduce your risk.
December 6, 2016
What Is Ransomware and How Locky Spread So Fast
A look at how one of this year's most widespread ransomware campaigns tricked so many businesses.
May 15, 2017
WannaCry Ransomware: What Businesses Need to Know
The global WannaCry outbreak spread through a known, patchable Windows vulnerability. Here's the lesson.
Prefer to have this handled for you?
Our team can take care of this and everything else on your IT plate — no obligation to find out how.