Skip to main content

MFP Copier Blog

Two severe Windows vulnerabilities addressed, another two unpatched

Windows users might have noticed that on the morning of Nov. 13, they were greeted with a large number of updates for their systems. This is all too common of a problem for IT departments as they scramble to patch servers, desktop computers and laptops in one day. If an organization was quick to act and lucky enough, it may have successfully avoided an intrusion through one of the reported 40 vulnerabilities. According to ComputerWeekly, this Microsoft software update is almost double the size of an average security patch, and it will certainly keep IT teams busy all week. However, despite the high quantity of patched vulnerabilities, two specific updates were delayed. Ultimately, any organization supporting Windows-based devices or servers are at risk.


One massive vulnerability

A specific bug in all versions of Windows poses a threat to any business that has yet to update its systems. According to Ars Technica, all Windows operating systems that access the Internet are subject to attack due to a vulnerability inside the Microsoft Secure Channel security component that implements the transport layer security and secure sockets layers. If the system does not filter maliciously-formed packets, attackers will have the ability to send any executable attack code through malicious traffic directly to a Windows-based server.


While this poses a massive risk to all data centers, the vulnerability can affect any version of Windows. Amol Sarwate, director of engineering at Qualys, told Ars Technica that as long as the computer runs any type of software that communicates with the Internet and accepts encrypted connections, then a cybercriminal can exploit the flaw. The worst part is that this severe vulnerability has existed for the whole year and impacted every major TLS stack, according to the source. Essentially, hackers could bypass every encrypted network, which is the reason why Heartbleed was considered to be so dangerous. If the vulnerability is not patched, anyone well-versed in technology could find their way into corporate servers to steal data or execute malicious code.


How it works

The main way that a hacker can exploit the severe vulnerability is through an Internet browser on an unpatched, end-user machine. Wolfgang Kandek, chief technology officer at Qualys, explained to ComputerWeekly that cybercriminals can gain access to computers and eventually servers through a malicious website with two basic techniques, one of which requires the end user to visit any website over which a hacker has gained control. The cybercriminals can plant malicious content on such sites in the form of downloads or links to other dangerous web pages. The source provided an example of this occurring in the past, referring to the recent vulnerability in the Drupal content management system that resulted in 12 million websites falling victim to hackers.


"A second scenario has the attacker set up a new site and then direct traffic to it through search engine manipulations, such as sites purporting to have the latest pictures on a recent event of general or specific interest," Kandek told ComputerWeekly.


The good news is that a fix is available in the latest Microsoft patch under the moniker MS14-066. Organizations that do not act now could be at risk of experiencing a data breach, and right now it is unknown if any businesses were affected by the patch. According to the source, however, Kandek said that MS14-066 is the second most important patch out of the 40 in the latest Microsoft system update bulletin.


What could be worse?

The patch identified as MS14-069 will address concerns in Microsoft Word 2007 and fix a remote code execution vulnerability. Kandek explained to the source that malicious documents can be used by cybercriminals to exploit a problem in the 2007 edition of Microsoft Office. Hackers can send a document directly to their potential victims, and when the message is opened, the cybercriminals will be able to execute malicious code on that system which can travel back to servers, giving them complete control over an organization.


The two that disappeared

Once IT teams implement those two fixes, MS14-066 and MS14-069, they can rest assured knowing that corporate data centers will be secure. However, two other patches were announced in Microsoft's bulletin, but not actually released, according to ComputerWeekly.


MS14-068 and MS14-075 were both delayed, and the effects of the postponement are currently unknown. Tyler Reguly, manager of security research at Tripwire, said that this is not uncommon, but because the numbering scheme was unchanged, Microsoft must be still ironing out the quality of the patches. This means that organizations could still be at risk of intrusion through unknown vulnerabilities. However, if those companies are partnered with a third-party security provider, this can help to ensure that until the official patches are released, their systems will be secure and safe from any cybercriminals with knowledge of the existing vulnerabilities.

 

David Bailey is Senior Vice President at Protected Trust. 

Protected Trust is a sponsor of the Print4Pay Hotel. I urge members and readers to visit their site to see their full line of products and services.  More and more we need to provide well rounded strategic solutions for our customers. Protected Trust offers some unique solutions that can help us in our day to day efforts. Check them out here.

This Week in the Copier/Office Equipment Industry 10 Years Ago Fourth Week of November 2004

Not a big week for news 10 years ago, but I did come up with this!

 

Ken Jennings ends his 75-episode streak on Jeopardy!, becoming the foremost game show contestant in international television history.

 

          11/22/04 7:44 PM
 
          Topic by Guest
          originally developed AutoStore for HP, but the exclusivity of this arrangement expired last year. NSI has since added a partnership with Kyocera Mita, which will soon offer its own version of AutoStore, and created integrations for Xerox, Ricoh, Sharp and
 
ricohrick ricohrick is offline. Click for Member Snapshot.
Senior P4P'er
 
          11/22/04 1:21 PM
 
          Topic by Guest
          color matching with pinpoint precision  Availability The new DocStream 5 color print server for Canon's Color imageRUNNER C3220 color digital imaging system is now available through authorized Canon U.S.A. Dealers and Canon Business Solutions subsidiaries
 
          11/23/04 8:24 PM
 
          Topic by Guest
          provision of four 105ppm high speed production machines in 2002 and has now won the contract to supply multifunction devices across all campuses. In addition to product quality, performance and Ricohs flexible service offerings, one of the key reasons Ricoh
 
          11/28/04 4:06 PM
 
          Topic by pcb0960 pcb0960 is offline. Click for Member Snapshot.
          hi, I have a problem with the doc feeder skewingslightly I think I figured it out it has to do with the metal bar, or the plastic turn guide right before the metal plate (hope I am describing this correctly) also the machine then started feeding two...
 
          11/23/04 3:45 PM
 
          Topic by Guest
          will move the project toward the finish. If your workload can handle it, take on additional responsibilities. Not only will you be someone's hero, you will gain experience and quite probably learn or sharpen some skills. Great job, (name). I've never met
 
          11/24/04 7:06 AM
 
          Reply by Neal Neal is offline. Click for Member Snapshot.
          Great solutions selling....we have such a broad line of Ricoh US products to be able to help our customers in their total document production and management needs. If we aren't talking to them about it, someone else will.
 
          11/24/04 4:06 PM
 
          Reply by Guest
          your local ricoh rep.  i have seen the error show up when the print key is pressed and it was laser adjustment that corrected it.  remember dont trust anyone elses work try these checks and you should be fine
 
          11/24/04 7:19 PM
 
          Reply by Guest
          for the sync detection.  then try replacing the LD unit.  if you still have the problem you should bring out your local ricoh rep.  i have seen the error show up when the print key is pressed and it was laser adjustment that corrected it.  remember dont
 
          11/24/04 7:59 PM
 
          Reply by v-tec v-tec is offline. Click for Member Snapshot.
Ricoh want you to BEND OVER to get your copies when you can get 25 sheets stacked neatly standing up???
 
          11/29/04 12:33 PM
 
          Reply by Old Glory Old Glory is offline. Click for Member Snapshot.
          pay next months mortgage. Do I really care if my Ricoh MFP is set as the default printer? Do I follow-up every month to see that prints are being driven to my unit? Am I attacking the back-room legacy printing and persistantly working until I get that
 
          11/29/04 2:58 PM
 
          Topic by dmurrah dmurrah is offline. Click for Member Snapshot.
          We are having problems getting this set up to print.  It will print a test page from the machine but wont print one from the PC.  Ricoh says replace the controller but thought I would see if anyone has had these same issues with the UC5e.
 
          11/22/04 7:51 PM
 
          Topic by Guest
Ricoh will be introducing new 40 ppm B2C and 60 ppm B2C system sometime in the 2 to 3rd quarter of '05.
 
          11/23/04 5:03 PM
 
          Reply by Old Glory Old Glory is offline. Click for Member Snapshot.
          So you were referring to calender year rather than Ricoh's year because June is still 1st qtr in Ricoh's fiscal year?
 
          11/23/04 7:02 PM
 
          Reply by Guest
          If the customer is running 36 inch paper, then every linear foot is 3 sqaure feet. There is no square foot meter for the Ricoh's. The KIP product that I saw has a square foot meter. Service is also billed by the square foot.
 
          11/24/04 7:02 AM
 
          Reply by Neal Neal is offline. Click for Member Snapshot.
Xerox also can read in square feet. best practice is to jsut make sure you see the maintenance contract to determine what you are dealing with.
 
          11/24/04 5:50 PM
 
          Reply by Guest
There is an updated PDF driver disc that can only be ordered through the Ricoh service dept that has and does infact cure this problem. If I remenber correctly it is 3.3 ver. Note the 240W I am refering to did have 'PS' print option installed.
 
Good Selling

16 Tips to Help You Sell More Production Print Systems #4 of 16

It's all about the prospecting, bout the prospecting not the leads!

 

There's been much talk in the industry about the research that is performed by the customer via the web before they make their first phone to a potential supplier.  In fact, if you're not one of those dealers, direct branch, or rep that is not providing informative content about your systems, then you probably won't get the call that xyz company wants additional info on xyz system.

 

Now, you can probably help your quest for leads by providing that type of content.  But, who really has time for that!  Better yet, how many of us work for dealers that have a dedicated person for content marketing on the web?  Not marketing but content marketing solely dedicated to blogging, and social media.

 

Leads are good and bad, in most cases I find that the customer is already focused on a specific model, has done the research and only needs me for the pricing.  In fact, they've probably called three or four other reps and requested pricing also.  Most of us can't or don't want to play that price game.  Yet, we most of us succumb to playing the game.

 

What I need to do is too add more prospects to my list for production.  I'm the one that needs to get them excited about a new product or feature. I need to make first contact and follow through with establishing my self and my dealership as the company they want to do business with.

 

Alright, you're probably wondering what the tip is right?  Right now I figure I have a twenty prospects for production equipment.  This year, hopefully I'll finish at 6 units. Which is basically .5 system per month.  I need 3 per month. Having forty prospects will get to me to one per month, thus if I have 120 prospects I should be able to hit the mark of three per month.

 

The tip is two fold. One that we need to engage the prospect before they have the need to replace an existing unit, or get them interested in system that might allow take back any outsourcing and move it in house.  The other is that we need to increase amount of prospects to call on, in my case I need to increase production prospects by 600%.

 

I might as well give a plug for Dealer Marketing also, especially since I'm a fan of what Darrell Any has been preaching about social strategy.  You can reach Darrel at damy@dealermarketing.net.

 

This Blog is #4 in a series of 16 blogs dedicated to help you sell more production gear.  I've listed the links for the previous three below, and since winter has set in here in the NE, I'll be back to writing two of these per month.

 

 

          10/16/14 11:50 PM
 
          Blog Entry by Art Post Art Post is online. Click for Member Snapshot.
          were upgraded to even larger A4 or A3 devices. We were sowing the seeds for additional placements. So, lets that this a step further. Production Printing is BIG, and even getting BIGGER from what I see. Production Printers can range from a low of $30k and
 
 
          3/31/14 9:39 PM
 
          Blog Entry by Art Post Art Post is online. Click for Member Snapshot.
          Where to start....hmmmmm, many years ago I had my first introduction into the Print4Pay Industry via the Minolta 450Z BETA copier.   The 450Z was launched back in the mid eighties and the most unique feature of the 450Z is that this was one of...
 
 
          4/28/14 9:06 PM
 
          Blog Entry by Art Post Art Post is online. Click for Member Snapshot.
It's no surprise to us old timers that in order to be successful we need to change. Case in point is production printers aka big iron. Many of us realize that Segment 3,  4 systems won't pay the bills anymore and the mere thought of chasing pc's for MNS

 

 

-=Good Selling=-

 

Color Cost Per Page Poll for Segment 4 (produce 41 to 69 pages)

Do you need to stay ahead of the curve, or just curious what the curve looks like?  We've introduced a new color cost per page poll for Segment 4 Color MFP's here.

 

How the heck can you fight the cost per page battle with either your dealership/direct branch or the customer if you're not sure where the rest of the industry is?

 

Take a minute or so to view the current votes and then take the survey yourself.  Check back in a few week and I'm sure you have an excellent sampling if you're too high, too low or just right!!

 

Color Cost Per Page Poll for Segment 4 (produce 41 to 69 pages)

 

-=Good Selling=-

 

Print4Pay Hotels Top Ten Likes for the new Ricoh MP 2554/3054 & 3554

I'm going crazy with all of these similar model numbers!!  Can't we just give them a name?

 

WOOHOO!  There's a whole lot to like with these new monochrome (black) Multifunctional Copiers from Ricoh.

 

Each one of these systems will copy, print or color scan up to 11x17.  The MP 2554 print speed is 25 pages per minute, the 3054 is 30 pages per minute and the 3554 is 35 pages per minute. 

 

1).  Scan speed has increased up to 79 images per minute for color or black & white.

 

2).  The 100 Page Document Feeder will allow you to used mixed sized originals of up to 11x17.

 

3).Remember the stapleless finisher that was introduced on the color series back in the spring?  Well, it's now available on these models also. 

 

4). The black toner cartridge is huge (good for about 24,000 pages) and it's located smack dab in the middle of the system.  Can't miss this, plus it can be inserted or removed with one hand!

 

5). Everyone is going to love this (dealers and customers), drum & developer yield of about 120,000 pages. Yes, that's based on the test charts, but it's still awesome.

 

6).  There's four different finishers that are available!  Take your pick from the 500 Sheet Internal Stapleless Finisher, the 500 Sheet Internal Finisher, the 1,000 Sheet Finisher and even a 1,000 Sheet Booklet Finisher.  The 1,000 Sheet Booklet Finisher will come in handy for many churches that are low volume but would like to produce their own bulletins.

 

7). How about paper weights?  Standard paper trays plus by-pass  will support up to 300 gsm, along with auto two sided print or copy of up to 256gsm. Not bad eh?

 

8). Connect to second network simultaneously, that's right, with the new optional USB Device Server Type m12.

 

9). Need to pre-view a scan? How about an image on the USB drive? With enhanced display, users can now single or double to move the image or zoom to 200%.

 

10).  Number 10, saving the best for last!  Can you say NFC?  Near field communications is the technology that allows the Smart Device Connector app and the new optional Smart Operation Panel to work in tandem and bring you a entire new experience with your Smart Device.  Of course you need to have an NFC enabled smart device, but I'm already thinking about a ton of cool apps for this. In fact, while talking about the technology with of one of my customers,  they mentioned a great application!  Ty Mike!!, if I ever develop it, you're in there!

 

There are many additional features, and the 2554/3054/3554 is just half of the picture. Soon, we'll have an additional three higher end systems that has some a few additional bells & whistles that can help to drive costs lower and increase processes.

 

Thus, if you're in New Jersey, and you need one of these, please call, send me an email or just reply here. If you're not in New Jersey, we have a tremendous network of Print4Pay Hotel members that can help. Just let me know where you're located and I'll get you to one of our professionals.

 

-=Good Selling=-

Data breaches in healthcare costing millions

The healthcare industry is undeniably a target of cybercriminals. With the increased usage of electronic health records, healthcare organizations have large volumes of data stored in data centers, on employee devices and sent through email. However, these businesses should not be expected to stop what they are doing and find new methods. Instead they need to find solutions to data breaches such as email encryption programs, third-party security services and, most importantly, invest in new computer systems with up-to-date security features.

Even if healthcare organizations take all the precautions necessary to mitigate intrusions, cybercriminals will still launch attacks in an attempt to steal patients' information. The key is prevention, building up a defense that cannot be breached. What is strange, however, is that just under a majority of intrusion attempts are on healthcare organizations. The Identity Theft Resource Center found that 43.8 percent of reported data breaches occurred in the healthcare sector during 2013. Compared to 2012 findings, attacks are only increasing in frequency. This leaves many questioning why the healthcare industry is so prone to intrusion attempts.

Why are hackers targeting healthcare organizations?
While there might be many reasons behind attacks on the healthcare sector, a few stand out. Opportunity plays a large role. Dark Reading contributor Lysa Myers reported that healthcare organizations just do not spend enough on security. Their role in society is to provide for patients, not protect their medical information. So, spending is more likely to be focused on improving medical equipment, hiring doctors and purchasing cutting-edge medications. MRI machines are not exactly cheap, but they are required for large healthcare providers. Myers wrote that many of these organizations follow the Health Insurance Portability and Accountability Act exactly as it states, but they only do this to avoid fines post-data breach, rather than implementing security measures above and beyond HIPAA compliance.

Old computers and operating systems are another reason why opportunities to steal data from healthcare organizations are perfect. Information Security Buzz cited a NetMarketShare study that found 30 percent of healthcare employees' PCs were still running Windows XP as of February 2014. If that is how many computers use the 13-year old operating systems, just consider what medical devices could be based on. To add insult to injury, Microsoft no longer provides support for Windows XP, which means any vulnerabilities are there to stay. Cybercriminals could focus on creating viruses, spyware and malware for Windows XP, and there is little healthcare organizations can do to protect themselves outside of constantly monitoring every medical device and computer.

All about the money
The combination of a lack of brevity and legacy systems is perfect for cybercriminals, but that does not explain why they would even bother trying to infiltrate healthcare systems. No, it is not for street - or Internet - credibility. Hackers can make a lot of money off patient records, even more than credit card numbers. Reuters reported that stolen health credentials can be sold for around $10 each, while a U.S. citizen's credit card information will only net approximately $1 or even 50 cents. Now, consider how long it took the public to be notified of the Community Health Systems data breach. There is ample time for cybercriminals or their cohorts to use the stolen information, while credit cards are typically canceled right away. Community Health Systems experienced a breach of 4.5 million patients. This means that the successful hacker could have earned up to $45 million. That right there is why cybercriminals target healthcare organizations.

Losing data and revenue
While hackers are earning large sums of money, the healthcare providers that they steal from are experiencing massive fees due to intrusions. The Ponemon Institute recently conducted a study that discovered the costs of a data breach have increased 96 percent in the past five years. Now, the average amount of revenue spent on a single cybercrime incident is $12.7 million, and depending on the amount of information stolen and the time it took to find out about the breach, the cost can vary from $1.6 million to $61 million. Additionally, it seems that cost of trying the prevent the breach is money much more well spent than that invested after an intrusion. The Ponemon Institute found that detection and recovery are the most costly internal activities, as they account for 49 percent of the total spending associated with data protection.

"Business disruption, information loss and the time it takes to detect a breach collectively represented the highest cost to organizations experiencing a breach," said Larry Ponemon, chairman and founder of Ponemon Institute.

Working with cloud and email security providers is best way to avoid experiencing a data breach and the massive fees that these cause. Action rather than reaction will be a healthcare organization's easiest method for mitigating the chances of an intrusion.

 

David Bailey is Senior Vice President at Protected Trust. 

Protected Trust is a sponsor of the Print4Pay Hotel. I urge members and readers to visit their site to see their full line of products and services.  More and more we need to provide well rounded strategic solutions for our customers. Protected Trust offers some unique solutions that can help us in our day to day efforts. Check them out here.

This Week in the Copier/Office Equipment Industry 10 Years Ago Third Week of November 2004

Ten Years ago, this grabbed the top Headline on the Print4Pay Hotel forums.

 

Konica Minolta Business Solutions, Windsor, Conn., recently introduced the bizhub PRO 1050, a 105 page-per-minute (ppm) printer/copier, which contains over 150 patent-pending items in engine design, paper handling, finishing, imaging and user interface. The segment 6 machines accommodate documents up to 12.36. X 18.1 inches. The manufacturer's suggested retail price, including the document feeder and print controller, is $57,000. Konica Minolta plans customized accessory packages for in-plant, quick print and data center markets.

 

Rest of the links are below:

 

          11/16/04 8:58 AM
 
          Topic by Guest
          feeder and print controller, is $57,000. Konica Minolta plans customized accessory packages for in-plant, quick print and data center markets.  The Canon Digital Solutions Forum in Las Vegas in latter October introduced the color-enabled imageRUNNER C
 
          11/16/04 5:53 PM
 
          Topic by Guest
Kyocera Mita America Strengthens Sales Organization for Future Growth November 11, 2004  Fairfield, New Jersey  Kyocera Mita America, one of the world's leading document imaging companies, today announced the promotions of two key executives and the
 
          11/19/04 7:53 PM
 
          Reply by jswinberlin jswinberlin is offline. Click for Member Snapshot.
          contribute on the benefits of the Ricoh machines, I've found the Konica-Minolta machines look good on paper, but put them side by side and you'll see the difference. Push for a demo if you can!
 
ricohrick ricohrick is offline. Click for Member Snapshot.
Senior P4P'er
 
          11/15/04 8:31 AM
 
          Topic by Guest
RICOH TEAMING WITH EFI TO INTRODUCE  ROBUST JOB SUBMISSION AND WORKFLOW MANAGEMENT  SOLUTIONS FOR AFICIO PRINTER LINE West Caldwell, NJ, and Foster City, CA, November 12, 2004  Ricoh Corporation, the leading provider of digital office equipment, is
 
          11/17/04 3:05 PM
 
          Topic by Guest
Xerox Nuvera 100 RIP Scanner standard finsiher $58,700 cpc (200K min) .0049 each
 
          11/17/04 3:10 PM
 
          Topic by Guest
Canon iR 105 used Fiery RIP saddle stitch paper deck $25,100 cpc .005
 
          11/21/04 3:52 PM
 
          Topic by Guest
          iR 3200 w/Fiery C-1 (ARDF, saddlestitcher, paper drawer) $18,760 cpc .007
 
          11/22/04 1:21 PM
 
          Topic by Guest
          color matching with pinpoint precision  Availability The new DocStream 5 color print server for Canon's Color imageRUNNER C3220 color digital imaging system is now available through authorized Canon U.S.A. Dealers and Canon Business Solutions subsidiaries
 
          11/17/04 2:55 PM
 
          Topic by Guest
canon iR105 fiery large paper deck staple/finsiher $36,501 cpc .0039 no minimum!
 
          11/17/04 2:58 PM
 
          Topic by Guest
canon iR7200 Fiery M2 Saddlestitch Finisher $28,400 cpc (200K min) .004 each
 
          11/17/04 2:59 PM
 
          Topic by Guest
canon iR8500 Fiery M2 K1 Finisher Large Paper Deck cpc .0045 each freeze for 60 months
 
          11/17/04 3:02 PM
 
          Topic by Guest
canon iR 8500 Fiery saddlestitch and hole punch $29,701 cpc (100K min) .0045
 
          11/17/04 6:12 PM
 
          Topic by Guest
          Congratulations to new Virtual Copier Reseller Mike Kaprinski, Vice President Sales/Connected Products, Fairfax Communications, Inc., Bedford Hills, NY. Mike closed his first bundled sale today. Ricoh 2035eSP and 15 Virtual Copier licenses. "Knocked out
 
          11/17/04 3:09 PM
 
          Reply by Guest
Canon iR 105 Fiery M2 K2N finisher Trade of Ricoh 1085 $34,200 cpc (100K) .004  (200K) .0038  (300K) .0035!
 
          11/20/04 1:18 PM
 
          Reply by Neal Neal is offline. Click for Member Snapshot.
          I would also try to get the Konica/Minolta in the client to demo. The fiery is a pain in the....well, you know where. I have gone against the bizhub a number of times and have lost once and that was the only deal that the customer went to the office to
 
littlerascal littlerascal is offline. Click for Member Snapshot.
Junior P4P'er
 
          11/16/04 5:57 PM
 
          Reply by Guest
          . Madision claims this is a "Ricoh problem" aRT
 
          11/17/04 3:07 PM
 
          Reply by Guest
Canon iR 7200 Fiery M2 RIP saddle stitcher & inserter $27,600 cpc (100K min) .0045
 
          11/17/04 4:38 PM
 
          Topic by Guest
          on the same day. The sales included a Ricoh Aficio Color Copier 2232C, a Ricoh Aficio B/W 2045ESP and 17 Virtual Copier Software licenses. Way to go Dave! Steve Breault VircoSoft
 
          11/17/04 10:56 PM
 
          Topic by Guest
          : goodpals select p4pusers cabinet, then wideformat folder, then ricoh folder, them wide format, then 240w (whew!)
 
          11/18/04 9:26 PM
 
          Topic by pcb0960 pcb0960 is offline. Click for Member Snapshot.
          two questions why on a ricoh aficio color 6010 labels stop before the fuser...when printing....but will pass through when copying and the ricoh 1105 are these machines good to work on? just sold one and I am the service tech what parts should I carry
 
          11/15/04 4:19 PM
 
          Reply by jswinberlin jswinberlin is offline. Click for Member Snapshot.
          .documentmall.com Accountname: art_post username: p4pusers passcode: goodpals select p4pusers cabinet, then wideformat folder, then ricoh folder, them wide format, then 240w (whew!)
 
          11/16/04 11:08 PM
 
          Reply by Jayson Gilbertson Jayson Gilbertson is offline. Click for Member Snapshot.
          What I posted was for one of my guys at Ricoh who has a guy at HP so the story gos.  He (my guy) is a good guy and has provided me good info in the past.  What I posted was his exact email.  Just thought I throw it out there and see what comments or
 
          11/17/04 8:29 AM
 
          Reply by Guest
          't know if I;ll ever do it, however its just a thought. I did a few comparisions with a Ricoh 600N, extra paper draw, duplex unit and then added the new IS 300e scanner from Ricoh. We still cam out a few thousand over. However it may be a solution that may

UC Davis Health System experiences another email breach

Another healthcare organization has experienced a data breach, and this time it had nothing to do with electronic health records. Instead, the incident was caused by unauthorized access to an email account. The University of California at Davis Health System has notified 1,326 patients who had their personal and medical information included in an email sent or received by the compromised account, according to the organization's press release.


The intrusion was only caught when an unidentified member of the UC Davis IT team noticed abnormal activity in a doctor's email account. The healthcare provider hired data security experts, but so far their research into the cause has been inconclusive. The source of the compromise is also unknown, and they have yet to determine which, if any, email messages were read.


UC Davis Health System has an email encryption program in place as well as cyber surveillance protocols and measures to protect against email filtering. In the short-term, the hospital has blocked access to the user accounts and changed the associated credentials to prevent any further data leaks. For additional assistance with the data breach, the healthcare organization has reached out to numerous government agencies including the California Department of Public Health, California Attorney General's office and the federal Office for Civil Rights.


Not the first time While this email breach does not seem to be too pressing of a matter, this is the second time in under a year that UC Davis Health System has experienced an intrusion to its email system. Health IT Security reported that malicious software affected three physicians' email accounts in December of 2013, and the breach was announced in January. The source stated that doctors opened an email disguising itself as a message from the UC Davis IT department, a type of attack that is known as a phishing attempt.


When the message was accessed, the attackers sent emails to others outside of the healthcare organization using the compromised accounts. Hospital representatives told Health IT Security that no patient records had been directly infiltrated, but some emails sent and received by the three accounts contained patient names, medical record numbers and information in regard to past hospital visits.


UC Davis Health System reacted in the same manner to the December breach as it did to the recent intrusion, sending a statement detailing how preventative measures should have stopped the attempt before it succeeded. The relationship between the two email breaches is unknown.


Preventing email intrusions with technology

While UC Davis Health System stated that it has email encryption software and trained employees, the healthcare organization could have implemented a few more security protocols. TechTarget contributor and information security consultant Kevin Beaver wrote that all it takes is one unencrypted email to cause an issue, as evidenced by the UC Davis incident, and offered three suggestions to ensure email compliance:

 

• Consider third-party services: Beaver explained that IT departments should not claim encryption until all the necessary tools have been implemented and validated. If using Exchange, Transport Layer Security should be combined with a third-party email content filtering tool and easy-to-use encryption mechanism for all email and attachments containing sensitive information. Beaver suggested using this setup for all messages regardless of their contents.

 

• Train employees: IT administrators need to think beyond the technology, Beaver recommended. End users should have working knowledge of the email encryption process, and expectations in regard to security should be set. Beaver wrote that this will be half the battle toward preventing email breaches.

 

• Monitor the network: Beaver estimated that somewhere in every organization, an employee or system is sending or receiving emails that contain sensitive information using POP3, SMTP or webmail via HTTP. IT administrators can benefit from using a network analyzer in order to find and stop unencrypted email from being sent.
Learn about phishing The December UC Davis Health Systems email breach was caused by phishing. It is crucial that every healthcare organization provides employees with knowledge about phishing, such as how to identify it and how to avoid it. Tony Bradley, PCWorld contributor, gave a few tips that should be relayed to all staff members. For example, if anyone receives a peculiar message, he or she should reach out to the sender via an instant messaging service or phone call before opening the email. These strange emails can be identified by simple, imperative subject lines or unrecognizable URLs. Bradley also wrote that phishing messages usually have consequences or rewards implied in the body of the text. Other recommendations from Bradley included double-checking the return email address and looking for poorly worded language. Chances are that banks or colleague physicians know the difference between "their" and "there."


Protecting against email threats can be easy for IT departments if the proper measures are taken. However, with so much on their plates already, IT professionals should not be responsible for ensuring that every email is encrypted. Businesses can consider installing encryption software or outsourcing IT security teams to help out their IT departments.

 

David Bailey is Senior Vice President at Protected Trust. 

Protected Trust is a sponsor of the Print4Pay Hotel. I urge members and readers to visit their site to see their full line of products and services.  More and more we need to provide well rounded strategic solutions for our customers. Protected Trust offers some unique solutions that can help us in our day to day efforts. Check them out here.

 

Print4Pay Hotel Adds New Copier Survey Feature

Just about two weeks ago we released a new survey feature for the site. 

 

There is a link for the main survey page on the gray header bar (the one that has the pull downs), and there is also a widget on the left side of the site that allows you to see the "the last 5 surveys at a glance". 

 

These surveys are the real deal, because they are coming from the sales people that have the feet on the street.  Personally, I believe that if you're a Print4Pay Hotel member, then you're one of the best in the industry today!

 

My take on the surveys,  for me it's the thought that many Principals and bean counters have no of what is happening on the street, especially when it comes to cost per page and what other companies are going to hide the cheese. 

 

Knowledge is power right?  How can we be competitive in the industry if we don't know what the industry average?

 

In the next week or so, we'll be posting additional surveys in reference to the "sales process" in conjunction with Dealer Marketing and Darrell Amy.  For those of you that take part in these surveys, we'll email you the study for free. Our way of saying thank you for taking the time to cast your thoughts.

 

In addition, there's a cool thread that Darrell Amy posted today about Changing Buyer's Habits.  Please take the time to convey your thoughts about the sales process.

 

We all come to this site for many reasons, however, I believe that most of us come to the site in order to gather additional knowledge about the industry and increase our sales.

 

-=Good Selling=-

This Week in the Copier/Office Equipment Industry 10 Years Ago Second Week of November 2004

Researchers claim to have found the lost city of Atlantis on the bottom of the east Mediterranean, 80 kilometers southeast of Cyprus. The Cypriot government disputes the claim, saying more evidence is needed.

 

          11/11/04 7:53 PM
 
          Topic by Guest
          strategy to focus on large enterprise users. Arima was quoted as saying that Fuji Xerox' competitive edge lies in its large enterprise users, with "mission-critical, large-scale, document management systems via the network." Ricoh and Canon, the company's two
 
          11/15/04 8:31 AM
 
          Topic by Guest
RICOH TEAMING WITH EFI TO INTRODUCE  ROBUST JOB SUBMISSION AND WORKFLOW MANAGEMENT  SOLUTIONS FOR AFICIO PRINTER LINE West Caldwell, NJ, and Foster City, CA, November 12, 2004  Ricoh Corporation, the leading provider of digital office equipment, is
 
          11/8/04 10:33 PM
 
          Topic by Guest
          Japan's Ricoh to take full control of women's clothing unit Sanai , 11.05.04, 11:37 AM ET AFX News Limited TOKYO (AFX) - Ricoh Co Ltd, an office equipment maker, said it will take full control of Sanai Co Ltd, its women's clothing and digital contents
 
          11/8/04 8:53 PM
 
          Topic by Guest
          NEW DRIVER COMPATIBILITY West Caldwell, NJ, November 8, 2004  Ricoh Corporation, the leading provider of digital office equipment, today announced its agreement with Bentley Systems, Incorporated, to develop printer drivers that enhance Ricohs wide format
 
          11/9/04 6:20 PM
 
          Reply by Guest
          Gregg: There is no attachment from Ricoh or any other third party vendor. All you can do is change the feed tires (they should be replaced every 200K), you can also instruct the customer to fan the envelopes, run them at a lower speed (60 cpm). If paper
 
          11/8/04 1:33 PM
 
          Topic by Guest
          Does anyone out there have any information about Embedded Software Architecture? Any tech mans or tutorials? What about a pn# from Ricoh to order the SDK/J? All I have been able to find are a general brochure and white paper. Thanks for any info and help!
 
          11/15/04 4:19 PM
 
          Reply by jswinberlin jswinberlin is offline. Click for Member Snapshot.
          .documentmall.com Accountname: art_post username: p4pusers passcode: goodpals select p4pusers cabinet, then wideformat folder, then ricoh folder, them wide format, then 240w (whew!)
 
-=Good Selling=-
 

Cloud security considerations for healthcare organizations

Cloud computing has numerous benefits for organizations in the healthcare industry, as many departments can find applications and data to host in the cloud environment, making resource provisioning easier and allowing employees to use less physical hardware to complete tasks. However, it is still common for some of these organizations to cite security as a major factor keeping them from adopting cloud services. With malicious attacks such as Heartbleed, Shellshock and a threat newly discovered by The Security Factory, it is crucial to pay attention to what is hosted in cloud environments and what security services are necessary to protect that data.
A Healthcare Information and Management Systems Society survey found that almost half of the respondents cited security as a key concern with cloud computing. Fortunately, only about 6 percent of the survey-takers told HIMSS researchers that they would not use a cloud service. The solution to working with sensitive information and applications in the cloud lies with security services. These partners can help reduce cloud computing concerns and allow IT departments to focus on protecting the organization's internal network to ensure security on all levels.


What goes into the cloud?

Before considering a cloud security service, organizations need to first understand that all applications do not belong in the cloud. By determining which programs and information can be stored in a public or private cloud, they will already reduce the risks associated with hosting Heath Insurance Portability and Accountability Act-compliant data.


Applications that are flexible in nature, which are programs that will see various amounts of users and data depending on the time of day, month or year, should be the first choice for cloud computing. On the other hand, data can and should be backed up or stored on cloud servers in order to reduce congestion on a local level, as some applications will need information transferred quickly and immediately, such as email, while others, such as user data, do not require fast and easy access.
While it is important to consider what will be hosted in a cloud environment, organizations should take full advantage of their cloud services. However, by only focusing on critical applications and data, the security risks of the cloud can be reduced and the security provider partner can dedicate even more resources to protecting that information.


Looking for a provider with access controls

A cloud security service is an ideal solution for healthcare organizations with large amounts of data in the cloud, preoccupied IT departments and HIPAA compliance requirements. The first aspect of cloud protection might be one of the most important: Limiting access for certain users.


With critical applications and information stored in the cloud, giving all employees access to everything could be detrimental. This also applies to providing and taking away access based on the task in which a staff member is engaging. The Security Factory, a Belgian cybersecurity firm, recently discovered a coding vulnerability that would allow a normal user to gain control over Windows-based servers through the creation of a directory name in any of the directories that the employee has access to.
Being a command-shell script, this vulnerability is very similar to Shellshock, and with correct placement, any user can cause malware to spread throughout a file server. Limiting employee access to servers hosting HIPAA-compliant data can prevent this, but many internal IT departments do not have the time or ability to constantly search for new vulnerabilities, while a cloud security firm will be up to date on new threats and able to patch them immediately.


Choosing the best technology

Another benefit of cloud security services is that they have the latest, cutting-edge technology. Finding a security firm with multi-tiered defense strategies will ensure that companies with high numbers of attacks will be safe. IT Pro Portal reported that with the best technology, coverage will include real-time threat monitoring, log management and denial-of-service attack mitigation. Firewalls will not be enough to stop constant threats that healthcare organizations face on a daily basis.
Additionally healthcare providers and companies will want a cloud security provider that is flexible. With innovations and trends in technology coming and going, it is crucial to have a service that can scale with the organization's needs. It can be hard to predict the future of cloud activity, and in this way security should be able to follow cloud infrastructure as it moves from being based on a public cloud to hybrid or from hybrid to private. A solution that is agile will reduce growing pains and allow the organizations to change in regard to demands.


Healthcare organizations are correct to be picky when looking for cloud solutions. Finding the best cloud host is just the beginning. By paying attention to those considerations, organizations can guarantee working with the best cloud security services for their needs.

 

David Bailey is Senior Vice President at Protected Trust. 

Protected Trust is a sponsor of the Print4Pay Hotel. I urge members and readers to visit their site to see their full line of products and services.  More and more we need to provide well rounded strategic solutions for our customers. Protected Trust offers some unique solutions that can help us in our day to day efforts. Check them out here.

Print4Pay Hotel Adds 4 New Forum Moderators

I'm really excited to have these Print4Pay Hotel members on board as moderators.  Our moderators will be there to post industry press releases, answer manufacturer product related questions,  and drive content on the respective forums.  

 

In addition becoming a moderator also gives them the option to sell advertising on the Print4Pay Hotel site.

 

I'm excited for all of our members that we've covered these four additional major brands (Sharp, Canon, Kyocera & Konica Minolta). There is no where else on the web, where you can get real answers to your questions about hardware, software, features and solutions!!!

 

I'm not sure if they want their names mentioned here, so just take a trip to the forums, post a question and I'm sure your have a response in no time!!

 

Congrats guys and thank you for making the Print4Pay the best site for Imaging Professionals in the WORLD!!

 

Art

Little Story About a Man Named Jed

My turn for a rant!!!

 

It's late, I'm going to go through this rather quickly so please stay with me. I had an existing account that was shared with a Direct Branch. The Direct branch had the majority of the placements, while we had three units in a satellite office.  One of those placements was a 135 page per minute production system.

 

I had been in touch with the manager about the end of lease and had a good relationship with him for eight years. 

 

My guy told me that Direct would also be quoting for a new production system, since they also had a color unit at the same location.  I knew my chances to hold the account were slim to none, however I put my best foot forward, submitted a very aggressive proposal 5 months before the end of the term (as did my competitor).

 

After hearing nothing for quite sometime I followed up with my guy.  I was told that Jed in IT is making all of the decisions. My guy had heard nothing and suggested I follow up with Jed.  He gave me his contact number and off I went.

 

I left my first call with a message that we submitted a quote and I need to follow up with him about the end of term obligations for the existing system and to get an idea of where we are at with the new lease. Waited a week, and nothing, placed another call a week later with the same message. Nothing.....no return call. A few days later the same message, of course there was no call back.  All in all I placed at least 7 calls to Jed. I got nothing!!!!  Typical I thought.

 

About a month later, I had a dream that I had lost the deal. Lo and behold the next day, I received notification from our service dispatch that he had received a call from "my guy" about removing the system.  I thought, that SOB has my number and he couldn't call me?  Then I thought that he didn't want to tell me directly because I would ask him "what happened"?

 

The next day, WTF, I get a call from Jed the IT guy.  He's asking me for a copy of the cost per page lease, and looking to see if we can remove the equipment. I stated I would be more than happen to comply, however you need to call the leasing company and schedule that with them. However, I do have a question for you.  "Why, did you buy from the other company", I was told it was a price thing. Ok, I can live with that, I then asked, "why did you not return any of my phone calls".  The answer, "I'm not obligated to call anyone back".  I blew my stack!!!!!  We're an existing vendor and we wanted to tell you about the end of the lease obligations and you tell me you're not obligated to return a phone call? He went on to state that he doesn't check his phone because they are all sales calls!  However, I do check emails. I thought, you rotten $#%!!!!  I called this facility many times and you can't even get a person to pick up the dam phone, let alone find an or ask for an email address.

 

Thinking about it, you know what, I probably should have asked my guy for his email address also. But who knew that this worker was not obligated to call an existing vendor back.

 

Moral of the story, they entered into a new contract, because they didn't call me their cost per page lease went into a year roll over with some 2.5 million pages attached! I wish I could be a fly on the wall went that conversation took place that they now have to pay for two production systems for at least a year!!!!! But, I'm thinking they may just have the system forever, because their ineptness will cause them to fail to notify the leasing company when the renewal comes due again!

 

-=Good Selling=-

 

 

Selling Copiers & MFP's "Running With the Big Dogs"

What's the Golden Rule when selling office equipment? Know your competition or least what they are quoting.

Ever notice every time you walk your dog that he or she stops at every tree, telephone pole and fire hydrant, ever wonder what they're doing?

They're checking out the competition. Who's who, whose doing what, who was here and where ya been! Amazing that dogs can find all of that out in a few whiffs .

We as sales people need to know the competition as well, what they're up to, what's their current maintenance pricing, leasing rates (did you know you can figure out the lease rate by backing out the payment), special promo's, or just how they are positioning themselves with the client.  I just had a quote given to me a few days ago and there was some good value statements from a competitor that I'll change it up a bit and use for my quotes and proposals.  Thus being able to read the quotes and proposals from the competition you may be able to tweak your proposal and borrow from others!

Here's some threads I've uploaded to the P4PHotel Message Boards, click the links and you'll be brought to the page.

proposal Canon C5235.pdf

Konica Minolta bizhub c654e pricing.pdf

W3601 pricing from bid.pdf

Ricoh MP C305SP proposal quote.pdf

Sharp MX-M453N Pricing_Proposal.pdf

The Print4Pay Hotel includes boards for Ricoh Family Group, Kyocera, KonicaMinolta, Sharp, Toshiba, Canon, Muratec and Xerox.

-=Good Selling=-

5 End of Year Tips to Help You Sell More

Geesh, I should have written this the last week of September and not the first week of November!  Well, it's still good and if you put these tips in practice you'll not wind up with the end of the year blues! 

 

Ah, the last quarter of the year leads us to Halloween, Thanksgiving, Christmas and a host of excuses of why NOT to Buy! But, where this is a will there is a way to get to President's Club.!

 

1) Kick up your prospecting, don't dial it up a notch, dial it up BIGTIME and don't stop. Increased prospecting during the early months will give you the opportunities needed to sustain you during the excuse weeks of Thanksgiving and Christmas.

 

2) Ask and ye shall receive, there are many companies that will post a profit for the year and those companies may be looking to reduce their tax liability by making additional purchases before the end of the year. They won't tell you, you need to ask!!!

 

3) Focus on bigger takedowns, look for higher revenue opportunities. It's been stated that you can spend as much time closing a multi system segment 4 opportunity as you would a single segment 4 opportunity.  Take special note of Production, Wide format and multi systems.

 

4) Explain your timeframe to your prospect, make sure there is no doubt with the customer that you are working a certain closing time frame.  A customer asked me the other day, "why, should I do this now".  I was honest and told him that it would help my end of year numbers and I would in turn help him with reducing their costs.  One hand can wash the other!

 

5) Add extra selling hours to your quarter!  Adding one hour a day for prospecting, researching, developing a quote, emailing or making calls will add twenty hours per month.  That's 60 hours in a quarter, or a week and a half that you've gained over your peers!

 

Plain & simple, if you want it, you can do it!

 

-=Good Selling=-

Post
×
×
×
×
×