Community home
Menu
  • PEXA Certified Expand

    PEXA Certified

    This program will give you an introduction to PEXA, how it works and how it can help you transform your business processes.

    Discover More
    • Getting Business Ready
    • System Set Up
    • Transacting in PEXA
  • Help Centre Expand

    Help Centre

    Here you’ll find more than 230 help articles and videos to assist you.

    Discover More
    • Help Articles
    • Help Videos/PEXA TV
    • PEXA Interactive Demos
    • FAQs
    • Ask a Question
    • PEXA Certified
  • Ask a Question
  • Share your Experience
  • Raise an Idea
  • Blogs Expand

    Read the latest in our blogs.

    Keep up to date with the latest PEXA product releases, and read up on the property blog.

    Discover more
    • Community Blog
    • The Property Blog
    • Security Updates
    • PEXA Product Releases
    • Announcements | Outages etc
    • The Bank Blog
    • Workspaces
      Community
      Register
      Log in
    Apps menu
  • Register / Login

Community Home
since ‎29-01-2019
2 weeks ago
DavidWillett
DavidWillett Star Employee
Star Employee
Register / Login

About DavidWillett

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Ice Breaker
Much Appreciated
Conversation Starter
Round of Applause
Thumbs up
Crowd Sourcer
PEXA Employee Group
Welcome to the PEXA Community
View All
Latest Contributions by DavidWillett
  • Topics DavidWillett has Participated In
  • Latest Contributions by DavidWillett

Security Alert - Phishing Messages via PEXA Commun...

by DavidWillett Star Employee in Raise a Security Concern
2 weeks ago
1 like
2 weeks ago
1 like
Hi Community,   In recent days, you may have seen spam messages posted on our Community forum. These have since been removed and the user accounts subsequently banned.   Additionally, we have been advised that some members have received private messages containing spam content. An example that has been reported is a member receiving a message with an offer to make money via cryptocurrency.   As always, if you receive a communication you believe to be suspicious, please:   Do not respond Do not click links or download attachments Delete the message/email Report it to your relevant security administrator or email PEXA’s security team at security@pexa.com.au. If you have any questions, please reach out to us.   David Willett PEXA General Manager for Information Security  ... View more

Security webinar | recording and FAQs

by DavidWillett Star Employee in Raise a Security Concern
‎09-10-2020 11:38 AM
‎09-10-2020 11:38 AM
Hi Community,   Thank you to everyone who attended our security webinar on Wednesday. For those who couldn’t attend or would like to re-watch the webinar, you can view the recording below. We received a lot of fantastic questions on the day, and unfortunately couldn’t answer all of them before the end of the webinar. Instead, we’ve posted the questions and answers below - underneath the webinar recording.   Attached, you’ll also find some additional resources provided by our fantastic panellist, Laura Hartley, Head of Public/Private Partnerships, Enterprise Security, NAB: Top tips for business customers; and NAB security toolkit. Ryan Janosevic, COO & Co-founder of RetrospectLabs, has also shared this interesting read about password complexity after some great questions from attendees about password protection.   If you have any further questions, please don’t hesitate to ask PEXA’s security team here or contact us at security@pexa.com.au. And don’t forget the five things PEXA will never do, regarding you and your security: PEXA will never: Call you from unverified phone numbers Ask for your MFA code Request files or information from you via a third-party service Email you from unofficial addresses Send you an email advising you to click a link to log in to the platform   Do you have a security question? Ask the experts   Q&A How safe are pin passwords? PINs (Personal Identification Numbers) usually consist of a series of randomly generated numbers, via an app or sent via SMS. They are very secure and commonly used as a second factor of authentication.   Is Google password saver secure? We always recommend using a reputable password manager when selecting a service. Remember to read the terms and conditions to make sure it meets your requirements before making your decision.   Is PEXA looking at extending its residential settlement guarantee (PRSG) to cover the same risk that is associated with commercial property transactions as well? The PRSG does not apply where the seller is a commercial vendor, such as a developer. The reason for this is that a commercial vendor would not be made homeless as a result of a fraud which the PRSG is intended to cover. For more information, visit our PRSG FAQs.   When we send a form to a client to complete via email, the client completes and sends it back, can we trust that information? Email phishing or business email compromise (BEC) is one of the most common ways for cybercriminals to procure sensitive information. Where possible, don’t use email and avoid this channel for the exchange of sensitive material. Instead, use apps like PEXA Key that is purposely built to protect the communication of bank and trust account information. If you have no other option than to communicate information via email, always validate the details verbally before taking any action.   When you get "oops try again" when trying to log into PEXA, is it okay to press try again? Yes, it is.  Always check the URL after you refresh and make sure a green padlock sign is in place before inserting confidential information.   Can password managers be hacked and in that case are all passwords at risk? Password managers are a great way of keeping all of your passwords safe. Make sure to use a reputable service which has robust security measures built into the application and read the terms and conditions before proceeding. There are no reports of data breaches attributed to well-known password managers in market. In Cybersecurity we often say that there are no 100% risk free applications. There is always a portion of unknown. The important thing is to make sure these risks are minimised by following the instructions.   PEXA checklists require us to confirm a DocuSign ID and unique number. What are some concerns PEXA has regarding electronic signing such as DocuSign? Digital signing should be approached with the same protective measures and rigour as physically applying your wet signature on paper documents. As with any method of signing, to mitigate risk, make sure to:      Verify the request, any information exchanged, the involved parties and documentation being signed; and Ensure the appropriate, authorised person signs.   Can you please advise why I keep getting asked if I want to update my password when I enter a payment in PEXA?   This prompt occurs if you have selected to save your password on the web browser. We do not recommend saving passwords to browsers. Instead, remember your password or use a password manager, and only save your user ID if required.   Are apps safer than websites? For both, it’s important to always validate the source. For a website, always type the address instead of clicking on links from emails and other websites. For apps, make sure to download them from the Google Play Store or Apple App Store. Check the ratings and the developer information before you download.   What is the best "internet cyber security" firm?    Cybersecurity needs are different from one firm to another. These needs and requirements must be assessed before selecting a provider.  The Australian Cyber Security Centre (ACSC) website has great recommendations for individuals and businesses to gain more information. https://www.cyber.gov.au/acsc/small-and-medium-businesses https://www.cyber.gov.au/acsc/individuals-and-families   What is the best anti-virus software on the market? The PEXA Subscriber Security Policy, section 4.2.3, refers to some leading providers of anti-virus software.   Does PEXA have a firewall integrated within its software to prevent cyber fraudsters gaining access? PEXA is protected with multiple layers of security. We maintain the highest standard of security measures to safeguard our members and their clients’ property transactions. Our security portfolio is aligned with international standards and we continue to operate by complying with the requirements set by the e-Conveyancing regulator, Australian Registrars National Electronic Conveyancing Council (ARNECC). Today, more than six million transactions, with a total value of more than $1 trillion, have safely been processed by PEXA.   When will Secure-messages and E-signable documents be able to be sent via PEXA-secure portal maybe even build into PEXA Key app? We are always working with our members and industry to evolve our services. All enhancements will be communicated with our members before they are launched, and we’ll continue to keep you up-to-date with our security developments.   What is your strategy for a zero-day vulnerability? A zero-day vulnerability refers to a software security flaw that is known to the software vendor but doesn’t have a patch in place to fix it yet. PEXA works with the best cyber security organisations in the industry to mitigate this sort of a risk by taking proactive and advanced measurements.   Does PEXA retain the information given by clients on PEXA KEY? Yes, personal information is collected when clients use PEXA Key. PEXA will not disclose your client’s personal information to any third party without their express consent. To read the Terms and Conditions in full, click here.   Can PEXA help small businesses to look at their computer system to see if they are fully equipped, at a small fee? This type of service is currently not available through PEXA. However, the ACSC has some great resources to assist small-to-medium sized businesses.   Will you use blockchain technology for its immutable nature and security? What would be some of the disadvantages? Blockchain is transformational, but not always the only solution. In Australia, we benefit from mature technology systems, with property transactions clearly supported by sound regulation. Therefore, blockchain may not necessarily create additional value.   How soon will you let your customers know if a security breach occurred? PEXA will promptly notify subscribers upon being made aware of any security breach that PEXA considers material to the security and integrity of the PEXA system or relates to unauthorised disclosure, use, access or loss of PEXA System Data. ... View more

Re: A web browser, the internet, and PEXA walk int...

by DavidWillett Star Employee in Raise a Security Concern
‎08-10-2020 08:56 AM
3 Likes
‎08-10-2020 08:56 AM
3 Likes
Hi There,   Thanks for reaching out.    Microsoft is no longer actively supporting Internet Explorer with the latest security patches, which could potentially put you at risk from cyber attack. I would suggest you immediately update to a supported browser such as Microsoft Edge, Google Chrome or Firefox.    Whichever browser you choose to go with, it is a good idea to turn on automatic updates in the browser's settings. This will help to ensure you always get the latest updates as they become available.    Kind Regards,   David W (PEXA General Manager, IT Security)  ... View more

PEXA Security Awareness Week – webinar, daily tips...

by DavidWillett Star Employee in Raise a Security Concern
‎01-10-2020 01:34 PM
4 Likes
‎01-10-2020 01:34 PM
4 Likes
Hi Community,   At PEXA, safeguarding Australia’s property transactions is our highest priority. With cybercrime costing Australian businesses $29 billion each year and email phishing attempts increasing exponentially since the onset of COVID-19, we are dedicated to supporting our members however we can to combat this threat.   Join our security webinar On 7 October 2020 at 12pm AEDT, as part of PEXA’s Security Awareness Week, I’ll be hosting a security webinar with Security Advisory and Awareness Manager at NAB, Laura Hartley and COO and Co-founder, Retrospect Labs, Ryan Janosevic.   Together, we will share our insights into the cyber-security landscape, tips on how to protect your business and finally, answer your questions. Click here to RSVP. Our socials will also be live with daily security tips and, for everyone who can’t wait, our new resource ‘Five things PEXA won’t do” is now live.   See you at the webinar!   David Willett PEXA, GM IT Security ... View more

Security Alert - WeTransfer Email Phishing

by DavidWillett Star Employee in Raise a Security Concern
‎21-08-2020 03:25 PM
3 Likes
‎21-08-2020 03:25 PM
3 Likes
Hi Community,   I’d like to advise members of an email phishing scam targeting PEXA Exchange users. In this instance, an email was sent to a practitioner, purporting to be from PEXA via WeTransfer, asking the recipient to open/download files.   Malicious emails being sent via WeTransfer is an ongoing cyber-threat affecting Australian organisations. Please note PEXA does not use WeTransfer for any email correspondence or service.   What to do   If you receive an email appearing to be sent from PEXA via WeTransfer, do not click any links and delete immediately.   As always, if you receive a similar phishing email or another communication you believe to be suspicious, please:   Do not respond Do not click links or download attachments Delete the e-mail Report it to your relevant security administrator or e-mail PEXA’s security team at security@pexa.com.au.   PEXA will never send you an email advising you to click a link to access the PEXA Exchange, and will always direct you to login to access your account via pexa.com.au.   Learn more about phishing e-mails here.   Kind Regards,   David Willett General Manager, IT Security ... View more

Security Update - High Profile Twitter Accounts Ha...

by DavidWillett Star Employee in Raise a Security Concern
‎16-07-2020 11:36 AM
2 Likes
‎16-07-2020 11:36 AM
2 Likes
Hi Community,   As you may be aware, this morning several high-profile Twitter accounts were targeted by cyber-criminals. You can read about this here.   While this incident has no impact on PEXA or the broader network, it’s a timely reminder to be cyber-aware when working or browsing online – particularly on social media.   As always, only seek information from known, trusted sources and remember that PEXA will never send you links requesting your sensitive login or financial details. If you have any questions or would like to flag suspicious material, please get in touch with our friendly team at  security@pexa.com.au . Kind regards, David Willett General Manager, IT Security ... View more

Remote working | Advice on how to keep property tr...

by DavidWillett Star Employee in Raise a Security Concern
‎25-03-2020 11:50 AM
5 Likes
‎25-03-2020 11:50 AM
5 Likes
Hello Community   With many businesses asking their teams to work remotely, security experts are warning of spikes in cyber-crime attempts. The global COVID-19 pandemic has sparked a surge of phishing attempts on unsuspecting individuals. One such attack used the logo of the CDC Health Alert Network claiming to provide a list of local active infections, before stealing confidential information from the unprepared victims. Cyber criminals are looking to take advantage of this period of global uncertainty, reinforcing the urgent need for everyone to be extra vigilant when it comes to cybercrime. We strongly recommend Australian lawyers and conveyancers utilise the tools and processes available to them to mitigate this risk, including: Install and update your anti-virus software Ensuring your anti-virus software is up-to-date is critical. Cyber-criminals can use a number of different methods to try and attack your devices, anti-virus should always be your first line of defence in protecting you and your business.   Keep operating systems (OS) and browsers up-to-date Updated OS and browsers add protection from security issues that could be used to compromise your information. Restart your devices regularly to make sure updates are fully installed. Cyber-criminals use weaknesses in outdated software to scam individuals and businesses. The best way to keep you and your business safe is to action software updates the instant they become available.   We also recommend that you shut down and restart your device frequently for automatic updates to proceed.   Do not use public WiFi If outside of the home or office, we do not recommend the use of free WiFi.  Instead, use your mobile as a hotspot (or purchase a 4G mobile router). This will provide you with a safer connection online. Public WiFi is easily compromised by hackers and your personal information easily obtained.    Virtual Private Network (VPN) When you’re working from home for an extending period of time, use your company’s VPN to make sure that you maintain a secure connection to all your corporate services and applications, away from the prying eyes of cyber-criminals.   Phishing – protect you and your clients’ information With reported email phishing attacks on the rise and the risk becoming more tangible across the world, it has never been more important for us and the broader e-Conveyancing network to use the tools available to us to protect against this threat. While you’re working remotely and limiting face-to-face client meetings, bank and trust account details can be communicated safely via the free PEXA Key app between you and the homebuyer or seller. The app removes the need to use email, mitigating any risk of succumbing to email phishing attacks in the sharing of critical transaction information. Lawyers and Conveyancers who use InfoTrack can also use Securexhange to communicate sensitive information with real estate agents.   Multi-factor Authentication (2FA/MFA) Check the security and privacy settings of all your essential services and make sure they have 2FA/MFA available. When logging into PEXA, members must use MFA to access their accounts. Although users have the option of receiving their MFA code via SMS or the smartphone app, we find the most reliable option to be the latter – via the PINGID application. The code is generated immediately in the smartphone app for users to transcribe into PEXA.  The SMS option can experience latency issues with some telecommunication providers, meaning the code is not received by the user for some time. If you’d like assistance moving from SMS to the smartphone app, please contact PEXA’s Support Centre on 1300 084 515.   Protect your passwords Keep your passwords and pin codes safe. Now might be a good time to change your passwords and use a password manager e.g. LastPass and 1Password to ensure you have unique passwords for all your different accounts. This ensures that if one of your accounts is compromised, the others are protected, and the impact is minimised.   Kind regards   David Willett Head of IT Security, PEXA ... View more
Category:
  • cyber security

Scam Alert - Scammers using COVID-19 to steal info...

by DavidWillett Star Employee in Raise a Security Concern
‎11-03-2020 12:10 PM
‎11-03-2020 12:10 PM
Hi Community,     Whilst businesses around the country and indeed the globe are making important preparations to respond to COVID-19 (Coronavirus), it is important to understand that cyber criminals can use a situation like this to their advantage.   Targetted phishing attacks, with malicious content disguised as Coronavirus notices, may be launched to capitalise on the public's desire to learn more about the outbreak. There have already been reports in the media about scams attempting to steal personal information or infect people's devices with malware that distributes false information or scam products.    In one example, a phishing email that used the logo of the CDC Health Alert Network claimed to provide a list of local active infections. Recipients were instructed to click on a link in the email to access the list. Next, recipients were asked to enter their email login credentials, which were then stolen by scammers.   What to do to protect yourself  If you want to educate yourself further on COVID-19, only look at reputable sources like the World Health Organisation, Centre for Disease Control or the the Australian Governments Department of Health websites.  Always be on the lookout for tell-tale signs of email phishing from emails that appear to come from reputable sources. Remember, you can look at the sender’s details – specifically the part of the email address after the ‘@’ symbol – in the ‘From’ line to see if it looks legitimate.  Be weary of social media posts that attempt to bait you to click on links to gain more information. Social media is notorious for being used to spread misinformation despite the review processes that have been implemented by these sites in recent times. As per point number 1, go direct to reputable or government sources to get information on COVID-19.  You can check out our link on phishing emails here to get more general information on how to spot scams.  Finally make sure you have good anti-virus protection installed on your device, whether it be a laptop or mobile.    Kind regards   David Willett Head of IT Security ... View more
  • Tags:
  • phishing
  • scam alert
  • security

(LPLC) Beware the risk that your clients email may...

by DavidWillett Star Employee in Raise a Security Concern
‎20-02-2020 11:02 AM
5 Likes
‎20-02-2020 11:02 AM
5 Likes
Hello   The Legal Practitioners Liability Committee has recently posted an insightful article that details a use case of email compromise leading to funds being transferred to a fraudster.   Be alert and get to know the warning signs that your client may have been compromised. A request to change account details at the last minute? This should always be followed up with a phone call to confirm it is legitimate.   Take a look at the LPLC article here to learn more! ... View more
  • Tags:
  • security

Tips to protect your mobile device & its data

by DavidWillett Star Employee in Security Updates
‎10-10-2019 03:55 PM
6 Likes
‎10-10-2019 03:55 PM
6 Likes
We  use  our  mobile device and its installed apps  every day . T he apps  we download  make it  easy  for us t o  do  everyday  things like  check  our  mail, tap onto the tram /train /bus , update  our  Instagram story, pay for coffee, track our calories  and now  even  to track   our  property settlement  ( s hameless plug of  PEXA Key ).  All  co nveniently completed   on our way in to work .     With  all  this   private  information  available at the touch of a button ,  keeping our phones and  chosen  apps secure  has become   increasingly  important.    Here are some handy  tips  to  assist you  in  doing so .     1. Download from official stores   Cybercriminals are known to create  rogue mobile apps  that mimic trusted brands in order to obtain users’ confidential information.  To avoid  these type s  of scam s ,  a lways download new apps from the official app stores , check the publisher  is  f rom the official supplier e.g. Property Exchange Australia Ltd)  and when  the  app  w as  last updated .  For example ,  PEXA Key  is  available exclusively on  the  Google Play St ore  and Apple App store .        2. Use device security     All smart phones have multiple methods  of  authentication  available. We advise you to:   Not leave your phone unlocked .  Make sure your phone is set to auto lock within 30-60 seconds of inactivity ; and   Use at least one of the authentication methods available to unlock your device e.g. facial recognition etc.    If using a pin code  to access your phone, do not use the same pin for your apps  or write the m  down  on a piece of paper . Try using  a  password manager   app  to  store ,  keep track of  and generate new  passwords  and  pin codes.      3. Call your provider    If you  lose  or  m isplace  your phone, call your provider  to ensure your SIM is deactivated  to protect your  phone and the apps on it from potential criminals.  This is good advice for your clients who use PEXA Key . It is also important that they remember to  notify you in the  unlikely  event  that they lose their phone.     4. Anti-virus on your phone    Your  hand-held  device is no different to your laptop  o r  PC and  is similarly  susceptible to scams such as phishing .  Consider installing  anti-virus software  onto your mobile device.   ... View more
Latest Tags
  • security
  • phishing
  • scam alert
View All
Likes From
User Likes Count
DandyCandy
DandyCandy
5
jdeen
jdeen Star Employee
1
DMc
DMc Community Superuser
3
HeatherC
HeatherC Gold Star Employee
2
JonTeh
JonTeh Star Employee
1
View All
PEXA

|

Facebook Twitter LinkedIn
  • Support
  • Privacy Policy
  • Terms of Service