<?xml version="1.0" encoding="UTF-8" ?><!-- generator=Zoho Sites --><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><atom:link href="https://www.buffalosentinel.com/blogs/security/feed" rel="self" type="application/rss+xml"/><title>Buffalo Sentinel - Blog , Security</title><description>Buffalo Sentinel - Blog , Security</description><link>https://www.buffalosentinel.com/blogs/security</link><lastBuildDate>Fri, 15 May 2026 00:12:09 -0700</lastBuildDate><generator>http://zoho.com/sites/</generator><item><title><![CDATA[Creating Separate Work and Personal User Profiles]]></title><link>https://www.buffalosentinel.com/blogs/post/creating-separate-work-and-personal-user-profiles</link><description><![CDATA[At Buffalo Sentinel, we take cybersecurity seriously—especially when it comes to protecting sensitive data and meeting regulatory requirements like th ]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_Ln1m_HCbTwaE1RnWcd3llQ" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_BwzDtbY-SkK7eCubM9f09g" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_4zgZGJviRR-lYUGRr0DR2w" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_CbZRb2YATTWnpvZwlZlpjw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center zptext-align-mobile-center zptext-align-tablet-center " data-editor="true"><p><span><span></span></span></p><div><div style="text-align:left;">At Buffalo Sentinel, we take cybersecurity seriously—especially when it comes to protecting sensitive data and meeting regulatory requirements like the New York Department of Financial Services (NY DFS) 23 NYCRR 500. One simple but powerful practice we encourage all clients and internal users to adopt is creating separate user profiles for work and personal use on their computers.</div></div><div style="text-align:left;"><br/></div><div style="text-align:left;"><span>Here’s why it matters and how to do it right.</span></div><div style="text-align:left;"><span><br/></span></div><p></p></div>
</div><div data-element-id="elm_w-DXpBlrP9LXFiOqK3mLiQ" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span>Why Separate User Profiles Matter</span></h2></div>
<div data-element-id="elm_3QB7lQw5VnlfSjlBLHUIkQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p>Most cybersecurity incidents stem from human error: clicking on a phishing link, downloading an unsafe file, or mixing personal and business data. Having distinct work and personal user profiles helps mitigate these risks by:</p><p><br/></p><ul><li>Isolating business-critical apps and data</li><li>Reducing the attack surface of sensitive systems</li><li>Maintaining a clear audit trail for compliance and monitoring</li><li>Supporting role-based access control (RBAC) with more precision<br/><br/></li></ul><p>This approach aligns directly with NY DFS’s mandates for access controls, audit trails, and data protection.</p></div>
</div><div data-element-id="elm_1iCCjEvOfpUXP4mXQx7qdQ" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span>&quot;But We're Small&quot; Doesn't Exempt You</span></h2></div>
<div data-element-id="elm_3rdJBXtVYpkofhO8CvYCbA" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><div>It’s a common misconception that small businesses or solo practitioners are exempt from cybersecurity regulations. That’s simply not the case.</div><div><br/></div><div>NY DFS Cybersecurity Regulation (23 NYCRR 500) applies to all covered entities, regardless of size. Whether you’re a solo financial advisor, a boutique insurance agency, or a startup fintech firm—you are still expected to implement robust cybersecurity controls.</div><div><br/></div><div>The regulation recognizes that threats can come from anywhere, and even one compromised account can lead to a breach that triggers reporting obligations, fines, and reputational damage.</div><div><br/></div><div>Pro tip: Creating distinct user profiles is a low-cost, high-impact way to begin aligning with compliance—no expensive software required.</div></div><p></p></div>
</div><div data-element-id="elm_I0L7JXA_tnRrjtUZVbrRww" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span>Step-by-Step: Creating Two User Profiles</span></h2></div>
<div data-element-id="elm_D9eZ9ZsZNHtBdT3GLMvfbg" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>Whether you're on Windows, macOS, or a Linux-based system, the steps are similar:</p><h3><span style="font-weight:normal;">1. Create a Work Profile</span></h3><p>This account will:</p><ul><li><p>Have elevated privileges only as needed (e.g., admin tools for MSP techs)</p></li><li><p>Be governed by cybersecurity policies (enforced through Group Policy or MDM)</p></li><li><p>Include business apps only: RMM agents, ticketing systems, finance apps, etc.</p></li><li><p>Enforce strong authentication: password + MFA (multi-factor authentication)</p></li></ul><h3><span style="font-weight:normal;">2. Create a Personal Profile</span></h3><p>This account should:</p><ul><li><p>Be non-admin</p></li><li><p>Have restricted access to any work folders or software</p></li><li><p>Be used only for personal browsing, media, or email</p></li><li><p>Be sandboxed with browser isolation or application control if possible</p></li></ul></div><p></p></div>
</div><div data-element-id="elm_V_yzU64NAByMmcv1iR_4lA" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span>Implementing Policies &amp; Controls</span></h2></div>
<div data-element-id="elm_Q-5QjwiFWvwO2PRtjzIMCw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>Once the two profiles are created, apply the following policies and controls:</p><h3><span style="font-weight:normal;">Access Controls</span></h3><ul><li><p>Use least privilege principles on both profiles.</p></li><li><p>Prevent the personal profile from accessing mapped business drives or software.</p></li></ul><h3><span style="font-weight:normal;">Application Whitelisting</span></h3><ul><li><p>On the work profile, only allow business-critical software.</p></li><li><p>Block installers and unknown executables via software restriction or AppLocker.</p></li></ul><h3><span style="font-weight:normal;">Audit &amp; Monitoring</span></h3><ul><li><p>Log login events and application usage on the work profile.</p></li><li><p>Use your RMM or SIEM to set alerts for anomalies (logins at odd hours, failed MFA attempts).</p></li></ul><h3><span style="font-weight:normal;">Data Protection</span></h3><ul><li><p>Enable BitLocker or FileVault for full-disk encryption.</p></li><li><p>Block USB drives or encrypt them by policy.</p></li><li><p>Prevent clipboard sharing between user profiles (especially in virtualized environments).</p></li></ul><h3><span style="font-weight:normal;">Personal Device Use (BYOD)</span></h3><p>If a personal device is being used for business, Buffalo Sentinel recommends:</p><ul><li><p>Using a VDI (Virtual Desktop Infrastructure) or secure browser session instead of local apps.</p></li><li><p>Separating business and personal spaces with MDM tools like Microsoft Intune or Zoho Endpoint Central.</p></li></ul></div><p></p></div>
</div><div data-element-id="elm_PySLQmy5PgTJlIUcICB-tA" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span>Staying NY DFS Compliant</span></h2></div>
<div data-element-id="elm_zhwtaNrsG-Zi8inWhQsYqA" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>These user profile strategies help directly with several NY DFS Cybersecurity requirements, including:</p><p><br/></p><div><table><thead><tr><th>NY DFS Section</th><th>Compliance Area</th><th>How This Helps</th></tr></thead><tbody><tr><td>500.3</td><td>Cybersecurity Policy</td><td>Supports access control and device security</td></tr><tr><td>500.7</td><td>Access Privileges</td><td>Enforces least privilege for each profile</td></tr><tr><td>500.12</td><td>Multi-Factor Authentication</td><td>Enables profile-specific MFA</td></tr><tr><td>500.13</td><td>Limitations on Data Retention</td><td>Keeps business data out of personal use areas</td></tr><tr><td>500.14</td><td>Training and Monitoring</td><td>Enables better tracking and user awareness</td></tr></tbody></table></div></div><p></p></div>
</div><div data-element-id="elm_gIM4Oq840FPZ2pF7C2exkg" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-style-none zpheading-align-left zpheading-align-mobile-left zpheading-align-tablet-left " data-editor="true"><span>Final Thoughts</span></h2></div>
<div data-element-id="elm_1ck-x5Bt4Bz-6KuOSmggvw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p></p><div><p>At Buffalo Sentinel, we don’t just secure systems—we empower users to build strong digital habits. By simply separating work and personal activity, you create a security buffer that protects your business and helps you stay in full compliance with NY DFS regulations.</p><p>Need help setting this up for your team or clients? Our cybersecurity experts can help audit your current environment, roll out policies, and configure profiles for maximum protection.</p></div><p></p></div>
</div><div data-element-id="elm_2eRgCKUCRny9k9EuGSqw2Q" data-element-type="button" class="zpelement zpelem-button "><style></style><div class="zpbutton-container zpbutton-align-center zpbutton-align-mobile-center zpbutton-align-tablet-center"><style type="text/css"></style><a class="zpbutton-wrapper zpbutton zpbutton-type-primary zpbutton-size-md " href="javascript:;" target="_blank"><span class="zpbutton-content">Get Started Now</span></a></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Mon, 07 Apr 2025 17:57:49 -0400</pubDate></item><item><title><![CDATA[Why You Should Think Twice About Using In-Browser Password Managers]]></title><link>https://www.buffalosentinel.com/blogs/post/why-you-should-think-twice-about-using-in-browser-password-managers</link><description><![CDATA[Most modern browsers—like Chrome, Edge, Safari, and Firefox—offer built-in password managers. They prompt you to save your login credentials, autofill ]]></description><content:encoded><![CDATA[<div class="zpcontent-container blogpost-container "><div data-element-id="elm_aSsGYf6HQYCM42bBG9LTrA" data-element-type="section" class="zpsection "><style type="text/css"></style><div class="zpcontainer-fluid zpcontainer"><div data-element-id="elm_C1SqMOD1QreHkMOyhcPg2g" data-element-type="row" class="zprow zprow-container zpalign-items- zpjustify-content- " data-equal-column=""><style type="text/css"></style><div data-element-id="elm_ZJ_pUdy7QAawQaicghz5Mg" data-element-type="column" class="zpelem-col zpcol-12 zpcol-md-12 zpcol-sm-12 zpalign-self- "><style type="text/css"></style><div data-element-id="elm_y4d26gLZTl2OV2sykmOo5Q" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-center zptext-align-mobile-center zptext-align-tablet-center " data-editor="true"><p></p><div><p></p><div><p>Most modern browsers—like Chrome, Edge, Safari, and Firefox—offer built-in password managers. They prompt you to save your login credentials, autofill them on future visits, and even generate strong passwords. It sounds convenient, right? But here’s the problem: convenience often comes at the cost of security.</p><p><br/></p><p>Let’s dig into why relying on your browser’s built-in password manager might not be the safest choice—and look at better alternatives like Bitwarden, Proton Pass, and 1Password.</p></div><p></p></div><p></p></div>
</div><div data-element-id="elm_Xdd9EkO7SX2M7iv0Y5viXg" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-align-center zpheading-align-mobile-center zpheading-align-tablet-center " data-editor="true"><span>The Problem with In-Browser Password Managers</span></h2></div>
<div data-element-id="elm_Gtzi9IP8AlSh1IvV79pMZQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><div><p><span>Browser-based password managers are designed for ease-of-use, not enterprise-grade security. While they do provide encryption and syncing across devices, they’re often deeply integrated into your browser profile—making them a prime target for attackers.</span><br/></p><p><span><br/></span></p><p><span><span>Here’s how your passwords can be stolen:</span><br/></span></p><p><span><span><span></span></span></span></p><div><span></span></div><p></p><ul><li>Malware like RedLine or Raccoon can extract browser-stored credentials in seconds.</li><li>Profile theft allows an attacker to clone your browser and access everything you’ve saved.</li><li>JavaScript injection by shady extensions or compromised websites can grab autofilled credentials.</li><li>Weak encryption linked to your device login means if someone gets access to your PC, your passwords are exposed.</li></ul></div></div>
</div><div data-element-id="elm_nsxTCj9ADjL-Wb5iCemeVg" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-align-center zpheading-align-mobile-center zpheading-align-tablet-center " data-editor="true"><span><span><span>Need Help Making the Switch?</span></span></span></h2></div>
<div data-element-id="elm_N5Kq587mzwgphhXe7nR4KQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><div><span style="font-weight:bold;"><a href="https://bitwarden.com/" title="Bitwarden" target="_blank" rel="">Bitwarden</a></span></div><p></p><div><div></div><div>An open-source, end-to-end encrypted password manager. Offers browser extensions, secure sharing, TOTP, and even self-hosting.</div><div><br/></div><div><div><span style="font-weight:bold;"><a href="https://proton.me/pass" title="Proton Pass" target="_blank" rel="">Proton Pass</a></span></div></div><div>Built by the privacy-first Proton team, this manager offers advanced encryption and protects even metadata (who you log in as, where, when).</div><div><br/></div><div><div><span style="font-weight:bold;"><a href="https://1password.com/" title="1Password" target="_blank" rel="">1Password</a></span></div></div><div>Popular with both individuals and businesses. Features include breach monitoring, secure vaults, Travel Mode, and biometrics.</div><div><br/></div><div>Each of these tools:</div></div><ul><li>Encrypts data before it leaves your device.</li><li>Never stores plaintext passwords.</li><li>Supports MFA and password health reports.</li><li>Works across browsers, phones, and operating systems.</li></ul></div>
</div><div data-element-id="elm_9TPfv1OryI-Z7qD6XmPrNw" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-align-center zpheading-align-mobile-center zpheading-align-tablet-center " data-editor="true"><span><span>Safer Alternatives: Use a Dedicated Password Manager</span></span></h2></div>
<div data-element-id="elm_MdRGI_GUJQ4nDdKxap6UFw" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p><span>If you're currently relying on your browser's built-in password manager and aren’t sure how to disable it or migrate your data safely—you’re not alone.</span></p><p><span><br/></span></p><p><span><span>Buffalo Sentinel can help you:</span><br/></span></p><ul><li>Disable password saving in Chrome, Edge, Firefox, and Safari.</li><li>Export your saved passwords securely.</li><li>Set up and configure Bitwarden, Proton Pass, or 1Password.</li><li>Train your team on best practices for password hygiene.</li></ul><p><span><span><br/></span></span></p></div>
</div><div data-element-id="elm_1pxEQQHOoVG1NkarDsblhA" data-element-type="heading" class="zpelement zpelem-heading "><style></style><h2
 class="zpheading zpheading-align-center zpheading-align-mobile-center zpheading-align-tablet-center " data-editor="true"><span><span><span>Got Infected? We’ve Got Your Back</span></span></span></h2></div>
<div data-element-id="elm_CjWbdi4f4PjIu8uD7fTmzQ" data-element-type="text" class="zpelement zpelem-text "><style></style><div class="zptext zptext-align-left zptext-align-mobile-left zptext-align-tablet-left " data-editor="true"><p><span><span>If you ever do get infected by malware or spyware designed to steal browser-stored credentials, Buffalo Sentinel can help detect it fast.</span></span></p><p><span><br/></span></p><p><span><span>With advanced Endpoint Detection and Response (EDR) tools and a Security Information &amp; Event Management (SIEM) platform, we monitor for:</span><br/></span></p><p></p><div><div><ul><li>Suspicious password extraction behavior</li><li>Malicious command-line tools (like LaZagne or Mimikatz)</li><li>Unusual login patterns or data exfiltration</li><li>Indicators of compromise in real time</li><li>Early detection means faster response—and less damage.</li></ul></div></div></div>
</div></div></div></div></div></div> ]]></content:encoded><pubDate>Mon, 31 Mar 2025 21:40:47 -0400</pubDate></item></channel></rss>