5 signs you've been hit with an advanced persistent threat
By Roger A. GrimesCreated 2012-10-16 03:00AM
Hackers who employ APTs (advanced persistent threats) [1] are a different breed. A real and constant threat to the world's companies and networks, APT hackers tend to be well organized, working together as part of a professional team. Their goal, typically, is to steal valuable intellectual property, such as confidential project descriptions, contracts, and patent information.
Generally, APT hackers employ familiar methods, using phishing emails or other tricks to fool users into downloading malware. But the ultimate objective tends to be very ambitious. If you discover a break-in where the only apparent intent was to steal money from your company, then it probably wasn't an APT hack. Those who deal in APTs are trying to be your company.
[ Brace yourself for IT's 9 biggest security threats [2]. | Find out how to block the viruses, worms, and other malware that threaten your business [3]. | Learn how to protect your systems with InfoWorld's Security Central newsletter [4]. ]
Because APT hackers use different techniques from ordinary hackers, they leave behind different signs. Over the past decade, I've discovered the following five signs are most likely to indicate that your company has been compromised by an APT. Each could be part of legitimate actions within the business, but their unexpected nature or the volume of activity may bear witness to an APT exploit.
APT sign No. 1: Increase in elevated log-ons late at night
APTs rapidly escalate from compromising a single computer to taking over the whole environment. They do this by reading an authentication database, stealing credentials, and reusing them. They learn which user (or service) accounts have elevated privileges and permissions, then go through those accounts to compromise assets within the environment. Often, a high volume of elevated log-ons occur at night because the attackers live on the other side of the world. If you suddenly notice a high volume of elevated log-ons while the legitimate work crew is at home, start to worry.APT sign No. 2: Finding widespread backdoor Trojans
APT hackers often install backdoor Trojan programs on compromised computers within the exploited environment. They do this to ensure they can always get back in, even if the captured log-on credentials get changed when the victim gets a clue. Another related trait: Once discovered, APT hackers don't go away like normal attackers. Why should they? They own computers in your environment, and you aren't likely to see them in a court of law.These days, Trojans deployed through social engineering provide the avenue through which most companies are exploited. They are fairly common in every environment -- and they proliferate in APT attacks.
APT sign No. 3: Unexpected information flows
If I could pick the single best way to detect APT activities, this would be it: Look for large, unexpected flows of data from internal origination points to other internal computers or to external computers. It could be server to server, server to client, or network to network.Those data flows may also be limited, but targeted -- such as someone picking up email from a foreign country. I wish every email client had the ability to show where the latest user logged in to pick up email and where the last message was accessed. Gmail and some other cloud email systems already offer this.
Of course, in order to detect a possible APT, you have to understand what your data flows look like before your environment is compromised. Start now and learn your baselines.
APT sign No. 4: Discovering unexpected data bundles
APTs often aggregate stolen data to internal collection points before moving it outside. Look for large (we're talking gigabytes, not megabytes) chunks of data appearing in places where that data should not be, especially if compressed in archive formats not normally used by your company.APT sign No. 5: Detecting pass-the-hash hacking tools
Although APTs don't always use pass-the-hash attack [5] tools, they frequently pop up. Strangely, after using them, hackers often forget to delete them. If you find pass-the-hash attack [5] tools hanging around, it's OK to panic a little or at least consider them as evidence that should be investigated further.If I had to think of a sixth indicator -- there's no charge for this one -- it would be focused spear-phishing campaigns against a company's employees using malformed Adobe Acrobat PDF files. This is the original causative agent in the vast majority of APT attacks. I didn't include it in the original five signs above because Adobe Acrobat is exploited [6] all over the place. But if you hear of a focused spear-phishing attack, especially if a few executives have reported being duped [7] into clicking on an attached PDF file, start looking for the other five signs and symptoms. It may be your canary in the coal mine.
That said, I hope you never have to face cleaning up from an APT attack. It's one of the hardest things you and your enterprise can do. Prevention [8] and early detection will reduce your suffering.
This story, "5 signs you've been hit with an advanced persistent threat [9]," was originally published at InfoWorld.com [10]. Keep up on the latest developments in network security [11] and read more of Roger Grimes' Security Adviser blog [12] at InfoWorld.com. For the latest business technology news, follow InfoWorld.com on Twitter [13].
Source URL (retrieved on 2013-03-19 07:42PM): http://www.infoworld.com/d/security/5-signs-youve-been-hit-advanced-persistent-threat-204941Links:
[1] http://www.infoworld.com/d/security-central/how-advanced-persistent-threats-b...
[2] http://www.infoworld.com/d/security/its-9-biggest-security-threats-200828?sou...
[3] http://www.infoworld.com/d/security/download-infoworlds-malware-deep-dive-rep...
[4] http://www.infoworld.com/newsletters/subscribe?showlist=infoworld_sec_rpt&...
[5] http://www.infoworld.com/d/security/stop-pass-the-hash-attacks-they-begin-167997
[6] http://www.infoworld.com/d/security/adobe-patches-two-vulnerabilities-in-read...
[7] http://www.infoworld.com/d/security/how-stop-your-executives-being-harpooned-946
[8] http://www.infoworld.com/d/security/prepare-advanced-persistent-threats-or-ri...
[9] http://www.infoworld.com/d/security/5-signs-youve-been-hit-advanced-persisten...
[10] http://www.infoworld.com/?source=footer
[11] http://www.infoworld.com/d/security?source=footer
[12] http://www.infoworld.com/blogs/roger-a.-grimes?source=footer
[13] http://twitter.com/infoworld
Tuesday, March 19, 2013
5 signs you've been hit with an advanced persistent threat
Unseen, all-out cyber war on the U.S. has begun
Unseen, all-out cyber war on the U.S. has begun
By Bob ViolinoCreated 2013-01-28 04:00AM
There's a war going on, and it's raging here at home -- not in the streets or the fields, but on the Internet. You can think of it as a war on the digital homeland. If you work for a power company, bank, defense contractor, transportation provider, or other critical infrastructure type of operation, your organization might be in the direct line of fire. And everyone can become collateral damage.
A cyber war has been brewing for at least the past year, and although you might view this battle as governments going head to head in a shadow fight, security experts say the battleground is shifting from government entities to the private sector, to civilian targets that provide many essential services to U.S. citizens.
[ When in China, it's not safe to leave your laptop alone [1]. Bob Violino explains why. | Find out how to block the viruses, worms, and other malware that threaten your business, with hands-on advice from InfoWorld's expert contributors in InfoWorld's "Malware Deep Dive [2]" PDF guide. ]
The cyber war has seen various attacks around the world, with incidents such as Stuxnet [3], Flame [4], and Red October [5] garnering attention. Some attacks have been against government systems, but increasingly likely to attack civilian entities. U.S. banks and utilities have already been hit [6].
"The cyber war has been under way in the private sector for the past year," says Israel Martinez, a board member of the U.S. National Cyber Security Council, a nonprofit group composed of federal government and private sector executives.
"We're finding espionage, advanced persistent threats (APTs) [7], and other malware sitting in networks, often for more than a year before it's ever detected," Martinez says. He says U.S. entities are being targeted on multiple fronts by China and Iran for espionage and intellectual property theft, by interests in Russia and Eastern Europe for syndicated crime such stealing cash and identities, by social-agenda "hacktivist" groups such as Anonymous [8], and by increasingly skilled individual criminal hackers.
The cyber war now raging in the digital homeland
Such attacks have been going on for years, but what's new is the cyber war brewing between the United States and Israel on one side and Iran in the other, says Emilian Papadopoulos, chief of staff at Good Harbor Security Risk Management, a consulting firm focused on cyber threats.Stuxnet, for example, was developed by Israel with U.S. support to hobble Iranian nuclear facilities [9], according to the New York Times and several security experts who spoke to InfoWorld off the record. Iran also accuses the United States and Israel of the cyber attacks that took Iran's Oil Ministry and a major oil terminal offline, Papadopolous says.
Iran or its proxies has apparently hit back with cyber attacks on U.S. banks, government officials say. Iran may have also been behind the Shamoon virus [10] that wiped 30,000 hard drives and took computer networks offline for weeks at the oil producer Saudi Aramco, Papadopoulos says.
A 2011 attack on European certificate authority DigiNotar [11] compromised the certificate system that underlies the Internet and enables users to trust in the identity of websites they visit and the source of communications they receive, Papadopoulos says.
"We have seen cyber attacks evolve from espionage attacks that steal intellectual property or monitor communications to disruptive or destructive attacks. ... Destructive and disruptive cyber attacks are relatively uncharted -- and troubling -- territory," he says.
The private sector owns and operates the infrastructure and systems that form the backbone of the Internet, and attacks on that system could break down trust in the Internet, with major economic and operational impact, Papadopolous says.
"In the past six months, we've seen foreign attacks on oil and gas companies in the Middle East and on U.S. banks, including Bank of America, PNC Bank, Wells Fargo, Citigroup, HSBC, and SunTrust. How will we react if the next attack is against the electric grid, or our food and water supply?" he asks.
In recent months, cyber attacks have become much more sophisticated, says the Cyber Security Council's Martinez. In some cases, overseas attackers have taken over servers in the United States that they then used to launch secondary attacks, making it appear as if one U.S. company was attacking another.
"The good news is [security] teams in most Fortune 500 companies are able to detect this and reverse it, but this type of threat is going to be a very big problem for us over the next 12 months," Martinez says.
Another battleground in the cyber war is the software industry. Much as we saw with the APT attack against Adobe Systems' software last year and with the attacks using weaknesses in Oracle's client-side Java [12] over the last several years, we can expect to see more attacks against trusted software providers such as antivirus vendors, says Pat Clawson, CEO of security products vendor Lumension. "The attackers want to get to the unparalleled access they have to their customers," he says. "Once the antivirus vendors' payloads are compromised, the devastation could be staggering." Such fears explain why the feds recently advised all Americans to disable the compromised Java in their browsers [13].
Such cyber attacks on U.S. companies and their overseas partners, as well as on the Internet infrastructure, could be as devastating as the 9/11 attacks [10] on the World Trade Center and the Pentagon, warned Leon Panetta, the U.S. Secretary of Defense. And Janet Napolitano, the Secretary of Homeland Security, warned just last week that a cyber 9/11 attack could happen at any time [14].
Cyber attacks and counterattacks are escalating
With the digital homeland now a cyber battlefield, "the paradigm in the U.S. must shift from defense to offense -- within internationally appropriate rules of engagement, of course. But offense will be necessary because a pure defensive strategy is not sustainable," says the Cyber Security Council's Martinez.The U.S./Israeli cyber attacks on Iran are an example of such an offensive. But they likely unleashed attacks on the digital homeland in response. "It is nearly impossible for us to really know cause and effect here, but there has definitely been an escalating pattern of attacks," Papadopoulos says.
The escalation of attacks against private-sector targets is extremely troubling, he says. "If the attacks keep escalating and happening with more frequency and against more private-sector companies, we are putting at risk the stability and security of cyber space."
Nations have been testing each other's armor for long time, more quietly than not, Lumension's Clawson. Knowing your opponents' weaknesses is an important part of any defensive strategy, he says. That drives some of the offensive actions. Stuxnet, for example, "is a heavy engineering exercise that crossed never-seen-before-boundaries ... malware that could do new things."
But such offensive tests can also help the governments attacked respond more effectively, Clawson says. "That massive engineering effort is now being reengineered against us." Martinez concurs: "In the case of Stuxnet, an offensive maneuver engendered an offensive cyber response." As another example, Clawson notes that the apparently Iranian attack on Saudi Aramco had elements of the allegedly Israeli/U.S. Flame in its architecture.
Breaking the cycle of attacks and counterattacks
Ultimately, the solution to the cycle of cyber violence must be political, Martinez notes. Such attacks "are symptoms of a larger problem that must be resolved between ideologies of two very different cultures and people. ... In some cyber incidents, it's about the perceived or maybe true imbalance between corrupt power and common people. Balancing between these parties, toward the best interest and security of the common people, is a difficult task."Until the conflicts are resolved, "almost everyone becomes a victim of unintended consequences during war, even cyber war," Martinez says. "Cyber war may be digital, but it is still a form of war."
Because cyber conflict is relatively new, interested parties need to focus more energy and attention on developing international norms that will say what is acceptable behavior and what is not, advises Good Harbor's Papadopolous. That is crucial for maintaining a stable, secure, and trusted Internet, he says.
Although some experts are trying to apply international law to curtail cyber war, these efforts are advancing slowly, and each new attack and counterattack implicitly establishes norms about what is acceptable, he says.
Clearly, the private sector has a vested interest in a stable, secure cyber space and needs to advocate for international norms that will rein in cyber conflict and attacks on critical infrastructure and other companies, Papadopolous says.
Playing defense at home until the cyber war ends
In the meantime, government policymakers and corporate CEOs alike need to think about and plan for escalating cyber conflicts and for disruptive and destructive attacks, not just espionage or intellectual property theft -- the major focus undertaken against advanced persistent threats and hack in recent years. After all, more countries and groups will gain the ability to launch sophisticated attacks, Papadopoulos says.Policies such as the 2012 Securities and Exchange Commission's Guidance on Cyber Disclosure [15] now require many Fortune 500 companies to report any type of meaningful cyber threats in their organizations, Martinez says. This is leading to an "age of transparency -- whether we like it or not -- which is a good thing because we now share more information about attacks, which allows us to more easily target bad actors," he says.
Still, Papadopolous says the cyber attacks on the private sector raise difficult questions: "What kinds of companies are fair targets? What kinds of attacks are acceptable?" Also, are companies liable when their services are disrupted by foreign attack? And who pays for clean-up, repairs, and compensation to affected customers?
Another key question: What is the government's role in protecting critical companies? In October 2012, Secretary of Defense Panetta said it was not the DoD's mission to provide for the day-to-day security of private and commercial networks, although he acknowledged the Pentagon had a role in the event of a "crippling cyber attack," Papadopoulos says.
Recently, there were reports of banks seeking help from the National Security Agency, Papadopoulos says. "How will the government's role change if we see more and more attacks against companies and they are more and more disruptive or destructive?" he says. That's a question many more people may ask if the world cyber war indeed escalates.
One thing is clear: The era of cyber warfare is here, and it's happening on the homefront.
This story, "Unseen, all-out cyber war on the U.S. has begun [16]," was originally published at InfoWorld.com [17]. Follow the latest developments in information security [18] at InfoWorld.com. For the latest developments in business technology news, follow InfoWorld.com on Twitter [19].
Source URL (retrieved on 2013-03-19 07:31PM): http://www.infoworld.com/d/security/unseen-all-out-cyber-war-the-us-has-begun-211438Links:
[1] http://www.infoworld.com/d/security/when-in-china-dont-leave-your-laptop-alon...
[2] http://www.infoworld.com/d/security/download-infoworlds-malware-deep-dive-rep...
[3] http://www.infoworld.com/d/security-central/stuxnet-marks-the-start-the-next-...
[4] http://www.infoworld.com/t/malware/flame-stashes-secrets-in-usb-drives-195455
[5] http://www.infoworld.com/d/security/java-exploit-used-in-red-october-cyberesp...
[6] http://articles.philly.com/2012-09-28/business/34128297_1_gholam-reza-jalali-...
[7] http://www.infoworld.com/d/security/5-signs-youve-been-hit-advanced-persisten...
[8] http://www.infoworld.com/t/cringely/what-we-learned-anonymous-188239
[9] http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cybe...
[10] http://www.infoworld.com/d/security/future-cyber-attacks-could-rival-911-crip...
[11] http://www.infoworld.com/t/cyber-crime/debacle-deepens-hacked-ssl-certificate...
[12] http://www.infoworld.com/t/java-programming/how-kill-java-dead-dead-dead-210860
[13] http://www.infoworld.com/t/web-browsers/disabling-java-in-internet-explorer-n...
[14] http://news.yahoo.com/u-homeland-chief-cyber-9-11-could-happen-215436518.html
[15] http://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm
[16] http://www.infoworld.com/d/security/unseen-all-out-cyber-war-the-us-has-begun...
[17] http://www.infoworld.com?source=footer
[18] http://www.infoworld.com/d/security?source=footer
[19] http://twitter.com/infoworld
Sunday, March 3, 2013
Shiva & Mourning
Judaism, with its long history of dealing with the soul of man, its intimate knowledge of man's achievements and foibles, his grandeur and his weakness, has wisely devised a system of graduated mourning periods. During this time, the mourner may express his or her grief and release, with calculated regularity, the built-up tensions caused by bereavement.
The Jewish religion provides a beautifully structured approach to mourning which is divided into five stages.
1. First Stage – Aninut
This is the period between death and burial when despair is most intense. At this time, not only the social amenities, but even major positive religious requirements are canceled in recognition of the mourner's troubled mind.
2. Second Stage – Lamentation
This period consists of the first three days following burial, days devoted to weeping and lamentation. During this time, the mourner does not even respond to greetings, and remains in his home (except under certain special circumstances). It is a time when even visiting the mourner is usually somewhat discouraged, for it is too early to comfort the mourners when the wound is so fresh. During this time, the mourner remains within the house, expressing his grief through the observances of wearing of a torn garment, sitting on the low stool, wearing of slippers, refraining from shaving and grooming, and recital of the Kaddish (see below).
3. Third Stage – Shivah
This stage covers the seven days following burial and includes the three-day period of lamentation. During this time, the mourner emerges from the stage of intense grief to a new state of mind in which he is prepared to talk about his loss and to accept comfort from friends and neighbors.
The world now enlarges for the mourner. He continues the observances outlined in the second stage above, but he is able to interact with acquaintances who come to his home to express sympathy in his distress.
A sacred obligation devolves upon every Jew to comfort the mourners.A sacred obligation devolves upon every Jew – no matter his relationship to the deceased or to those mourning – to comfort the survivors – these being father, mother, wife (or husband), son, daughter, (married or unmarried), brother, and sister (or half-brother and half-sister) of the deceased.
In Judaism, exercising compassion by paying a condolence call is a mitzvah, considered by some of our greatest scholars to be biblically ordained. It is a person's duty to imitate God: as God comforts the bereaved, so man must do likewise.
The fundamental purpose of the condolence call during shivah is to relieve the mourner of the intolerable burden of intense loneliness. At no other time is a human being more in need of such comradeship.
The inner freezing that came with the death of his relative now begins to thaw. The isolation from the world of people and the retreat inward now relaxes somewhat, and normalcy begins to return.
4. Fourth Stage – Shloshim
This period consists of the 30 days (counting the seven days of shivah) following burial. The mourner is encouraged to leave the house after shivah and to slowly rejoin society, always recognizing that enough time has not yet elapsed to assume full, normal social relations.
Shaving and haircutting for mourners is still generally prohibited, as is cutting the nails, and washing the body all at once for delight (as opposed to washing for cleanliness which is required).
5. Fifth Stage – Year of Mourning
The fifth stage is the twelve-month period (counted from the day of burial) during which things return to normal, and business once again becomes routine, but the inner feelings of the mourner are still wounded by the rupture of relationship with the loved one.
The observance that most affects the daily life of the mourner during the twelve-month period is the complete abstention from parties and festivities, both public and private. Participation in these gatherings is simply not consonant with the depression and contrition that the mourner experiences.
It is absurd for the mourner to dance gleefully while his parent lies in a fresh grave.It borders on the absurd for the mourner to dance gleefully while his parent lies dead in a fresh grave.
Thus, the Sages decreed that, while complete physical withdrawal from normal activities of society lasts only one week, withdrawal from joyous, social occasions lasts thirty days in mourning for other relatives, and one year in mourning for one's parents. Joy, in terms of the mourning tradition, is associated largely with public, social events rather than with personal satisfactions.
At the close of this last stage, the bereaved is not expected to continue his mourning, except for brief moments when yizkor or yahrzeit (see below) is observed. In fact, Jewish tradition rebukes a man for mourning more than this prescribed period.
Saying Kaddish
The Kaddish is recited at every prayer service, morning and evening, Shabbat and holiday, on days of fasting and rejoicing.
The period that the mourner recites the Kaddish for parents is, theoretically, a full calendar year. The deceased is considered to be under Divine judgment for that period. Some communities, therefore, adhere to the custom that Kaddish be recited for 12 months in all cases.
However, because the full year is considered to be the duration of judgment for the wicked, and we presume that our parents do not fall into that category, the practice in most communities is to recite the Kaddish for only 11 months.
The Kaddish is to be recited only in the presence of a duly constituted quorum, a minyan, which consists of ten males above the age of Bar Mitzvah. If there are only nine adults and one minor present, it is still not considered a quorum for a minyan.
Yizkor and Yahrzeit
Yizkor is a ceremony recalling all the deceased during a communal synagogue service. Yahrzeit is a personal memorial anniversary; it may be observed for any relative or friend, but it is meant primarily for parents.
The Yizkor service was instituted so that the Jew may pay homage to his forebears and recall the good life and traditional goals. This service is founded on a vital principle of Jewish life, one that motivates and animates the Kaddish recitation.
It is based on the firm belief that the living, by acts of piety and goodness, can redeem the dead. The son can bring honor to the father. The "merit of the children" can reflect the value of the parents.
This merit is achieved, primarily, by living on a high ethical and moral plane, by being responsive to the demands of God and sensitive to the needs of one's fellow man. The formal expression of this merit is accomplished by prayer to God and by contributions to charity.
Yahrzeit is a special day of observances to commemorate the anniversary of the death of parents. Though the word is of German origin, the custom is outlined in the Talmud.
This religious commemoration is recorded not as a fiat, but as a description of an instinctive sentiment of sadness, an annual rehearsing of tragedy, which impels one to avoid eating meat and drinking wine – symbols of festivity and joy, the very stuff of life.
Soul Talk - Kaddish and memorial: aiding the soul's ascent - Death & Mourning
What is it that we can give to a loved one who is no longer physically amongst us? With our limited, filtered, compromised, spiritually blind existence in this world, what can we give to the souls who inhabit the transcendent places of the next world?
The answer is, a great deal. We can give them life.
For what is life in its most essential form, life fulfilling the purpose which G-d created it to fulfill? Life, in the ultimate sense, is a soul in a physical body causing the stuff of this world to be revealed as G-dly. This is what we achieve every time we do a mitzvah, a good and G-dly deed. And when our positive actions are inspired by the life of one who has passed on to a more spiritual state of life, and are motivated by the desire and goal that they be in his or her merit--we give life and growth to a soul of the next world. Through our actions, the souls of those who passed on can attain something they could not achieve on their own. They can "live," in the ultimate sense of what life is about--affecting this world, making G-dliness felt in this world.
This is the main idea behind the recital of the Kaddish in merit of a departed soul. While Kaddish is commonly known as the "mourners prayer," a reading of the text reveals that it is not about death or mourning, but the public proclamation of G-d's greatness. By rising from the depths of anguish and loss to offer praise to G-d, we transform the event of death into an act of life.
Even more important than the recitation of Kaddish is the Torah we study, the mitzvot that we accept upon ourselves, the charity that we give, the good that we do, with the intention that it be l'iluiy nishmat, for the sake of the "elevation of the soul." If the desire to give to the one who has passed on is what impels us to learn something we would not have otherwise learned, to do a mitzvah we otherwise would not have done, to go higher and further than we would have otherwise gone, then this soul lives in us. Our hands and feet, mind and heart and mouth become the hands, feet, mind, heart and mouth of the departed soul.
For more about Kaddish -- including a practical guide to the Kaddish, and the "Kaddish Pro," an interactive trainer -- visit our comprehensive Kaddish Site.
Saturday, March 2, 2013
15 Lessons from Shiva
It was 4 a.m. when the call came, but we slept through it. Then it came again at 5:45 a.m. and I let it go to voice mail. The third time the phone rang I ran for it. It was New York calling. My wife's family was on the line. I knew the words before they spoke them. My mother-in-law had passed away a few hours ago.
Shock, disillusionment, disorientation, regret, frustration. These emotions and more flowed through us as we scrambled to arrange the funeral and flights, and assemble a small army to tend to our children while my wife and I would be away.
Throughout the flight I felt terrible pangs of regret. Had I been too selfish by not championing my wife to visit her mother more often? Should she have red-eyed it more to New York to see her ailing mother, who was a widow and alone in a beautiful assisted living facility? I pondered these thoughts in the dark plane cabin, enveloped within my gnawing guilt. My poor wife, had I added to her mournful state?
I decided that I would do whatever necessary to ease my wife through the mourning process.
Shiva is the seven-day mourning period that follows burial. The purpose is to grieve intensely, and prepare to move on. During that week, friends, neighbors and colleagues come for a short visit to comfort the mourner. Here are my lessons learned from my wife's week of sitting shiva:
Lesson 1: Shiva is not for anything but mourning. Yes, if you are a mom you must do things no one else can, like give emotional deposits, guidance, and lunch instructions to your kids. Otherwise defer, postpone, and reschedule. Change your voicemail, have an auto-responder on your email, and post a sign on your office door.
Lesson 2: We posted visiting hours on our front door and made sure people understood they could not come after 9:30 p.m. Otherwise people will come in, whenever, for however long. In any event, leave a pad on the front door so people can leave notes. Some people traveled a long distance, only to find out they missed out on the hours and wanted to give their condolences.
Lesson 3: Contact everyone and let them know what happened. You have circles of friends and acquaintances that are bigger than you think. There are work circles, family circles, school circles, community circles, distant relative circles, etc. Think them through and have others help get the word out. I sent out notices on three different email lists and still missed a swath of people. If there ever was a week that things fall through the cracks, this is it. Worse than not coming to visit shiva, is forgetting to inform someone that would have come to visit. On the flip side, everyone forgives you for everything.
Lesson 4: Give your spouse everything you can. She has only one mother. The best advice a colleague gave me was to take the week off from work. I did. I ran errands and tried to make life pleasant with lunches and coffee drink surprises. It definitely brought us closer together. Normally I work long hours, so to take off work meant a lot to my wife. She knew I was giving her my all. And our neighbors knew something was amiss when, the first day back from the New York burial, I was spotted at 10 a.m. wheeling a baby stroller.
Lesson 5: Write down the names of everyone who delivers a meal, does you a favor, watches the kids for an hour, anything. It means a lot to people to be thanked, and my wife wanted to express her gratitude to all those who eased her loss. At first you think you will remember everyone, but then it becomes too overwhelming. Also, compile all letters and notes received. It makes for a comforting read months down the line.
Lesson 6: When you come to visit, remember that it is for the benefit of the mourner. This is the last place on earth you want to talk about yourself as interesting as you may be. It takes tremendous psychic energy for the mourner to entertain your ego. Also, never argue about anything with the mourner. Never. Leave it at the door. At least wait till the shiva week is over.
Lesson 7: When making a shiva call, don't expect food and entertainment. The "deli platter concept" every evening is really not conducive to the shiva process. Just focus on the mourner, not your appetite. The coffee clutch that sometimes develops in the kitchen is just out of place with the mourner holding court in the living room. There should be only one conversation going on. That is giving real honor to the deceased and the mourner. Obviously in other quarters of the house homework and other matters can be discussed as long as they are not heard. But it's not party time. [If there is a morning minyan in the house, you can put out coffee, juice, fruit, danish, etc., for those who need to go straight to work.]
Lesson 8: It seems to me that anything less than a 10-minute visit, unless you're the President of the United States or something like that, is too quick. God will forgive your time management goals this day, unless of course you left a child in the bath tub. And please, make sure to turn off your cell phone.
Lesson 9: So what should you talk about? Ask to see pictures of the deceased's life. Ask the mourner to describe the decease's finest hour. What will they want to have been remembered for? How will you remember them?
Lesson 10: Never assume the mourner has taken care of anything. They are spaced out and disoriented. I have literally seen mourners go without lunch because everyone thinks they are taken care of. Don't assume that at all. Mourners are preoccupied. They may need shopping, errands, car pools, letters mailed, a phone call or three made, the dog walked, the baby diapered, etc. Who is doing the laundry and cleaning the floors and bathrooms? These are big jobs. Mourning is physically taxing and they are locked down with visitors. Assume nothing was done. Don't ask "Do you need something?" Instead, just do something. Better yet, do something and then ask, "Can I do anything else?"
Lesson 11: Make sure someone is on hand to rearrange chairs, clean up, direct traffic, take deliveries, etc. Someone has to be the head referee and crowd controller. I walked everyone out and welcomed everyone in. It helped create movement to keep the rotation flowing. It also helped those who felt self-conscious about entering and exiting.
Lesson 12: When the shiva period has ended, don't expect the mourner's relief to suddenly break forth or sadness to evaporate. That takes time. So when you see the mourner participating in the world again, treat them with care. Constantly be checking in with the mourner. They will still like to talk about their loss. It is an awful feeling to be abandoned after the shiva, even for introverts. Spend some private time later on with the mourner, "just because." Getting back to normal could take a year or more.
Lesson 13: Make sure Kaddish is said every day. Kaddish fills the spiritual void that is now missing from the world and is an enormous merit for the deceased. We arranged on Aish.com for someone to say Kaddish by the Western Wall. We also arranged for the entire Oral Law to be learned in my mother-in-law's memory and merit. That is a big mitzvah and a big comfort to the soul of the deceased.
Lesson 14: Take on one good deed in the deceased's memory. My son and I learn small, concise pieces of Torah each day. We recite his grandmother's name before we start. It also has bonded us like glue.
Lesson 15: Write out an ethical will that the deceased would have left behind for their children, grandchildren, spouse, and friends. I asked my wife to write out what her mother would have told the children if she knew she would never see them again. It can be a very powerful and cathartic experience.
If you have additional advice, please post it in the comments box below, to help others deal with this difficult time of life.
Written for the elevation of the soul of Sheina Rishah bas Noach Leib