{"id":13238,"date":"2019-06-30T03:00:33","date_gmt":"2019-06-30T03:00:33","guid":{"rendered":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/?p=13238"},"modified":"2022-10-14T18:28:40","modified_gmt":"2022-10-14T22:28:40","slug":"call-center-cybersecurity","status":"publish","type":"post","link":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/security\/call-center-cybersecurity.html","title":{"rendered":"Call Center Cybersecurity"},"content":{"rendered":"\n<p>Contact centers deal with credit cards, personal and healthcare information. This is some of the most lucrative data hackers could steal.<\/p>\n\n\n\n<p>In addition, they can encrypt your files with ransomware and try to get you to pay. Because of the critical nature these contact centers play in an organization, companies often have to pay the ransom if they don&#8217;t have the realtime backups ready to restore.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"970\" height=\"350\" src=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/06\/Mckay-Bird.jpg\" alt=\"\" class=\"wp-image-13240\" srcset=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/06\/Mckay-Bird.jpg 970w, https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/06\/Mckay-Bird-768x277.jpg 768w\" sizes=\"(max-width: 970px) 100vw, 970px\" \/><figcaption> Mckay Bird, CMO of <a href=\"https:\/\/www.tmcnet.com\/query\/searchresults.aspx?searchstring=tcn&amp;Action.x=0&amp;Action.y=0\">TCN <\/a> <\/figcaption><\/figure>\n\n\n\n<p>To get a sense of the pitfalls you should watch out for in your organization and specifically the contact center, we had an exclusive interview with Mckay Bird, CMO of <a href=\"https:\/\/www.tmcnet.com\/query\/searchresults.aspx?searchstring=tcn&amp;Action.x=0&amp;Action.y=0\">TCN  <\/a>a leading provider of cloud contact center technology for enterprises, contact centers, BPOs and collection agencies worldwide.<\/p>\n\n\n\n<p>In case you aren&#8217;t aware of the company, they won a Customer<a href=\"http:\/\/www.customerzone360.com\/topics\/customer\/articles\/441634-recipients-the-2019-customer-products-the-year-award.htm#\"> Product of the Year award<\/a> this year for their Cloud Contact Center Platform and we broke the news last month that they teamed with Envision on WFM.<\/p>\n\n\n\n<p>Here is the interview:<\/p>\n\n\n\n<p><strong>Why are contact centers big targets for hackers?<\/strong><\/p>\n\n\n\n<p>It\u2019s not necessarily the contact\ncenters that are being hacked, but organizations that operate consumer- based\ncall centers for specific products. In order to help consumers resolve disputes\nand other customer inquiries from their CRMs, sensitive personal data is\navailable to agents (i.e. birthdate, SSN, balances and possibly credit card\ninformation, etc.). This type of customer data is often appealing to hackers. <\/p>\n\n\n\n<p><strong>What are the compliance implications of a breach?<\/strong><\/p>\n\n\n\n<p>Often times the implications are\nmonetary (i.e. fines). When a breach occurs, it can be damaging to a brand.Over time, we have seen consumers vote\nwith their wallets and change contact center providers who have been flagged as\nrepeat offenders. <\/p>\n\n\n\n<p><strong>What about customer trust?<\/strong><\/p>\n\n\n\n<p>Customer trust is built over a\nlifetime and lost in a day. Organizations need to implement security measures both\nat the call center and agent levels to ensure customers when calling in to\nresolve an issue. Some security measures to consider include: two factor\nauthentication, security phrases and SMS text verification codes. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1170\" height=\"660\" src=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/05\/hospital-1170x660.jpeg\" alt=\"\" class=\"wp-image-12214\"\/><\/figure>\n\n\n\n<p><strong>How can they stay continuously secure?<\/strong><\/p>\n\n\n\n<p>Undergo regular audits and third-party\nchecks. This is the only way to stay ahead of the changing security\nrequirements needed for any organization handling consumer data. <\/p>\n\n\n\n<p><strong>What should we know about your company and its capabilities?<\/strong><\/p>\n\n\n\n<p>At TCN, we regularly undergo independent verification of our\nsecurity, privacy, and compliance controls, to further help our clients meet\nits regulatory and call center operational objectives. TCN\u2019s comprehensive,\ncloud-based contact center platform has achieved Payment Card Industry Data\nSecurity Standard (PCI-DSS) Level 1 certification and U.S. Federal Health\nInsurance Portability and Accountability (HIPAA) compliance. TCN\u2019s cloud contact center platform is secure.<strong><\/strong><\/p>\n\n\n\n<p><strong>What preventative\nmeasures can be taken? <\/strong><strong>&nbsp;<\/strong><\/p>\n\n\n\n<ul><li>Do regular audits. Most audits should be automated.&nbsp; There exists whole suites of tools automating things such as password rotation, sensitive data leaks, configurations, change management, and other categories.&nbsp; Run these tools. Have qualified individuals review the reports. Additionally, audit things manually from time to time.&nbsp;<\/li><li>Add authentication to secure systems and employee access to email. Email access and all administrative tasks on the backend should be done through two-factor authentication. Utilize tooling such as key rotation and certification based logins to automatically create rules and policies to grant and deny employee access to administrative systems.&nbsp;&nbsp;<\/li><li><strong>Train employees.<\/strong> Knowledge is power.&nbsp; Train your employees to look for suspicious and suspect activity in emails. Require developers have secure coding training. Provide site reliability engineers and system administrators with training on system hardening and other site security policies and practices.&nbsp;<\/li><li><strong>Scan and Pen Test. <\/strong>Run automated scans for known vulnerabilities. Run a web application firewall.&nbsp; Do white hat fuzzing on applications. <\/li><li><strong>Layer access to and compartmentalize security.<\/strong> No one layer is secure.&nbsp; Layer best practices upon best practices.&nbsp; Internal applications should not, for example, relay on being internal and ignore security standards.&nbsp;<\/li><\/ul>\n\n\n\n<p>We have also put together&nbsp;<a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/06\/baltimores-bill-for-ransomware-over-18-million-so-far\/\">cybersecurity be<\/a><a href=\"https:\/\/www.apextechservices.com\/topics\/articles\/442289-cybersecurity-essentials-every-business.htm\">st practices<\/a>&nbsp;for every organization. We urge you to read the document&nbsp;<strong>and live by it<\/strong>.<\/p>\n\n\n\n<p><em>Want more?<\/em><\/p>\n\n\n\n<p><em>Learn about the latest in everything you need!&nbsp;<strong>Cybersecurity<\/strong>,&nbsp;<a href=\"https:\/\/cvxexpo.tmcnet.com\/east\/\">the Channel<\/a>,&nbsp;IT, IOT,&nbsp;<a href=\"http:\/\/www.intelligentedgeexpo.com\/\">Edge<\/a>, AI,&nbsp;<a href=\"https:\/\/www.sd-wanexpo.com\/east\/\">SD-WAN<\/a>,&nbsp;and the&nbsp;<a href=\"https:\/\/www.futureofworkexpo.com\/\">Future of Work<\/a>&nbsp;at the world\u2019s only&nbsp;<strong><a href=\"http:\/\/www.mspexpo.com\/\">MSP Expo<\/a><\/strong>, part of the&nbsp;<\/em><strong><em><a href=\"http:\/\/www.itexpo.com\/\">ITEXPO<\/a><\/em><\/strong><em>&nbsp;#TechSuperShow,&nbsp;Feb 12-14, 2020 Fort Lauderdale, FL.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"600\" src=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/05\/itexpo-2019-hall-7.jpg\" alt=\"\" class=\"wp-image-12172\" srcset=\"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/05\/itexpo-2019-hall-7.jpg 800w, https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-content\/uploads\/2019\/05\/itexpo-2019-hall-7-768x576.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Contact centers deal with credit cards, personal and healthcare information. This is some of the most lucrative data hackers could steal. In addition, they can encrypt your files with ransomware and try to get you to pay. Because of the critical nature these contact centers play in an organization, companies often have to pay the<\/p>\n","protected":false},"author":44,"featured_media":13239,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[156],"tags":[280,1079,1796,2177,2176,226,2175],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/13238"}],"collection":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/comments?post=13238"}],"version-history":[{"count":3,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/13238\/revisions"}],"predecessor-version":[{"id":13243,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/13238\/revisions\/13243"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media\/13239"}],"wp:attachment":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media?parent=13238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/categories?post=13238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/tags?post=13238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}