
Sign up to save your podcasts
Or


UPDATE to last week's Headlines:
Exchange server Mass-hack – timeline and scope:
This Week's Security Tip:
So you have a big file you need to get over to your printer YESTERDAY and you can’t get it to “send” via e-mail because the file is too big. What should you do? The right thing to do is contact your IT department (us!) so we can assist by installing a secure, commercial-grade file-sharing application. What you shouldn’t do is download a free copy of Dropbox or some other file-sharing software without telling us. Dropbox and other free apps come with a price: SECURITY. These applications are known for security vulnerabilities and hacks. Plus, if we don’t know about it, we can’t manage it or secure it; so the golden rule is this: NEVER download any software or application without checking with your IT department first!
Today's Headlines:
Next Week's Teaser:
It’s disturbing but very real. It’s creepy.
Call to Action: We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE CALL!
www.mastercomputing.com/discovery
UPDATE to last week's Headlines:
This Week's Security Tip:
If you do online banking, NEVER access your online account with a PC or device that you use to log in to social media sites or free e-mail accounts (like Hotmail) or to surf the web. Since these are all highly hackable, keeping one PC dedicated to online banking reduces your chances of getting a bank-account-hacking virus. Of course, that PC should have antivirus installed, be behind a well-maintained and well-monitored firewall, have a strong password and be monitored for suspicious activity.
Today's Headlines:
Next Week's Teaser: It’s tempting to do this and think it’s ok...
Call to Action: We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE CALL!
www.mastercomputing.com/discovery
UPDATE to last week's Headlines:
This Week's Security Tip:
In a recent incident reported in US news, an office secretary unknowingly gave some of her law firm’s most private data to a gentleman who had bought a Comcast Cable polo shirt off eBay. He dressed in khakis with a tool belt, and told the secretary he was there to audit their cable modem specifications and take pictures of the install for quality assurance. She had no reason to suspect he was part of a now-extinct hacker ring who would gain access to a business’s private network by going inside the office and noting the configuration details and passwords for their firewalls and cable modems. In some cases, they actually built a secure VPN private backdoor they later used to steal data. If someone dressed up in a utility-provider uniform, would you let them in?
Ask for identification and who they have spoken with about the service they are performing, and be “gracefully suspicious,” as they say in the South. Keep company policies about how visitors are allowed in the building, if such policies exist. If those kinds of policies don’t exist, work to define them. We can help, if needed – but this is a real problem your office needs to address.
Today's Headlines:
Next Week's Teaser: Bank online? Do this ONE thing…
Call to Action: We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE CALL!
www.mastercomputing.com/discovery
Want to know what every hacker hopes you believe? “We’re small…nobody wants to hack us.” This is the #1 reason why people (companies) get hacked. They dismiss the importance of IT security because they’re only a “small business.” This is a lazy, irresponsible excuse.
One thing is for certain: NO ONE is immune to cybercrime. In fact, one in five small businesses fall victim to cybercrime and that number grows every year. Plus, half of all cyber-attacks are aimed at small businesses BECAUSE they make themselves low-hanging fruit with sloppy or nonexistent security protocols.
And one more critical point to ponder: If YOU aren’t giving IT security the attention it deserves, how do you think your CLIENTS would feel about that? If for no other reason, you need to do it to protect your clients’ data, even if the only information about them you store is an e-mail address. If YOUR system gets compromised, hackers will now have access to your CLIENTS’ e-mail and can use that for phishing scams and virus-laden spam. I’m sure your clients want you to be a good steward of their information and privacy, so stop lying to yourself and get serious about putting essential security practices in place.
Have questions about cybersecurity or the technology at your company? I’m here to help. Fill out a form here to book a quick, 10-minute call with me.
Show Notes:
If you’ve ever said this, you’re ASKING to get hacked!
“We’re small nobody is going to hack us”
“Nobody cares about us or our data”
“We’re not big enough to be hacked”
THIS is the #1 reason companies get hacked. Not because they’re small, but because they use that as an excuse, thinking you’re too small to get hacked. It’s stupid and irresponsible and you’re asking for trouble.
Thinking you’re “too small to get hacked” is stupid.
There are 2 primary targets:
1. The low hanging fruit
2. Great big names
It’s way easier to get the low hanging fruit, because if you’re the company that says “we don’t need that”
FACT: 1 in 5 small businesses fall victim to cybercrime every year.
The last time one of our clients got hacked was over a DECADE ago, and that is when we changed our security ways. We are living proof that if you put security measures in place you can mitigate the risks, at a minimum you can mitigate the risks.
No one is immune from cybercrime…
· 1 in 5 small businesses fall victim to cybercrime every year
· ½ of all cyber-attacks are aimed at small businesses BECAUSE they make themselves low-hanging fruit.
· Non-existing security protocols
· You don’t have policies in place
· The whole culture is backwards, generally it starts at the top. Meaning if you, as a business owner, don’t care about cybersecurity, then I guarantee your employees don’t care. Another thing to consider you get hacked, now you are responsible for all of your clients’ data
What’s Irresponsible: Irresponsible is to not have information about whether your stuff is being monitored and maintained.
Somebody needs to know what kind of firewall you have so when something bad comes up you can go patch that firewall.
Whoever is responsible for security for this company should know this information. I’m looking from a business owner’s perspective. The owner of the company may not know what hardware he has in the IT closet, but better know the name of the person who is monitoring it, patching it, and making sure that guy is doing his job.
Coming up next week: Wait until you hear the story about what this sectary did….
YOU! And your employees. Like it or not, human beings are our own worst enemies online, inviting hackers, viruses, data breaches, data loss, etc., through the seemingly innocent actions taken every day online. In most cases, this is done without malicious intent – but if you as a manager or owner aren’t monitoring what websites your employees are visiting, what files they’re sending and receiving, and even what they’re posting in company e-mail, you could be opening yourself up to a world of hurt.
That’s because employees’ actions can subject the company they work for to monetary loss, civil lawsuits, data theft and even criminal charges if they involve disclosure of confidential company information, transmission of pornography or exposure to malicious code.
Two things you can do: One, create an Acceptable Use Policy (AUP) to outline what employees can and cannot do with work devices, e-mail, data and Internet. That way they know how to play safe. Second, implement ongoing training (like these tips!) to keep security top of mind. We can also run phishing security tests and score your employees. That will truly show if they know how to spot a suspicious e-mail, and will make them realize how easy it is to be duped.
If you need help with setting up an AUP or employee training, give us a call at 940-324-9400.
Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me.
If you’re using any kind of cloud application (and these days, who isn’t?), you are right to be concerned about data privacy and security. The company hosting your data is ultimately responsible for keeping hackers out of THEIR network, but most cloud breaches are due to USER ERROR. So it’s important that you, the user, are being smart about security. Here are a few things you can easily do to improve security in the cloud:
1. Maintain a STRONG password of at least eight characters with both uppercase and lowercase letters, numbers and symbols. Do NOT make it easy, such as “Password123!” While that technically meets the requirements, a hacker could easily crack that.
2. Make sure the device you’re using to access the application is secure. This is an area where you need professional help in installing and maintaining a strong firewall, antivirus and spam-filtering software. Don’t access your cloud application with a device you also use to check social media sites and free e-mail accounts like Hotmail.
3. Back up your data. If the data in a cloud application is important, make sure you’re downloading it from the application and backing it up in another safe and secure location. That way, if your account is hacked, if the data is corrupted OR if the cloud company shuts down your account, you have a copy.
Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me.
No matter how diligent you are about security, there’s always a chance you can get hacked. That’s why you need to put a plan in place NOW to protect yourself and your CLIENTS, so damage is minimized. But what should you do if you find out you’ve been hacked?
First, contact your IT department (us) IMMEDIATELY. The faster we can address the attack – and determine the extent of the data, applications and machines compromised – the better your chances are of preventing much bigger problems. We’ll go to work on containing the attack and conducting a full scan of your network.
Based on what we discover, we may advise you to contact the local FBI office and your attorney. Your legal responsibilities depend greatly on the type of data accessed. For example, if medical, financial or other confidential records were stolen or accessed, you are legally responsible for notifying affected individuals that their data was compromised (your attorney can best direct you on what you need to do and how to do it).
Cybercrime is at an all-time high, and hackers are setting their sights on small and medium businesses who are “low hanging fruit.” Don’t be their next victim!
Have questions about cybersecurity or the technology at your company? I’m here to help. Book a quick, 10-minute call with me here.
If you handle, process or store credit cards in any manner, you are required to comply with PCI DSS, or Payment Card Industry Data Security Standards. This is a set of LEGAL requirements you must abide by to maintain a secure environment. If you violate them, you will incur serious fines and fees.
Are you subject to them if you take credit card payments over the phone? Absolutely! If you have clients that pay you direct by credit card, you’re subject to these laws. However, there are various levels of security standards – but thinking you don’t process enough to matter or that “no one would want to hack us” is dangerous. All it takes is an employee writing down a credit card number in an e-mail or on a piece of paper to violate a law; and then you’ll be left with legal fees, fines and the reputational damage incurred when you have to contact your clients to let them know you weren’t properly storing or handling their credit cards.
Getting compliant – or finding out if you ARE compliant – isn’t a simple matter I can outline in a 1-2-3-step checklist. It requires an assessment of your specific environment and how you handle credit card information.
A great resource is the PCI Security Standards Council, or www.pcisecuritystandards.org. If you want assistance in figuring out if you’re compliant, call us for a free assessment.
Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me.
Show Notes:
[00:00:30] Hey, everybody, I am Justin Shelly, CEO of Master Computing,
[00:00:34] And I'm Joe Melot, CIO of Master Computing.
[00:00:37] Welcome to Episode 15 of Stupid or Irresponsible. Joe, most important thing to happen to you this week?
[00:00:48] That's a good question. I probably should have prepared.
[00:00:50] Well, let me talk while you think about that.
So, listen, it was last week or the week before, maybe both. I talked about getting stood up for a podcasting interview because I've had people start reaching out to me and want me to be on their podcast and stuff like that, which just makes me feel special. And they stood me up. Well, then they came back and they apologized profusely and set the whole thing up again.
[00:01:19] I rearranged my entire schedule so that I can be here and do their 15-minute prescreening, meeting, Web meeting or whatever.
[00:01:28] But I mean, we've been planning this thing talking about it sounds like now also last year they had a really dialed in process. And I mean, I'm at the doctor with my kid shuffling that shit then I get here for this interview. And within 30 seconds they're like, oh, well, we're not interested because the we had the wrong number of employees. And I just thought, are you kidding me right now that with all of the process you had in place, you couldn't have asked me this key question from day one and saved me about four weeks of fretting and hours and hours of prepping and whatever. So, I was I was pretty upset. But I'll tell you what, it it made me realize the importance of process and made me look at my own process as I bring guests and to, you know, some of our other podcasts. We've got DFW rock stars. I'll plug that real quick as we're trying to get more. I mean, that was one that struggled. We haven't had a lot of guests. So, building that back up, getting the process dialed in. But that was the most interesting thing to happen to me, is just yet again getting stiffed by this company that I am not happy about it. So, I hope that gave you enough time, Joe. You still got to come up with something on your end.
[00:02:39] Oh, yeah.
[00:02:40] I guess just this week is kind of playing with the old Christmas ideas of, you know, a lot of our clients are out of the office during this time of the year. So, getting everything set up there, you know, we're a little short staffed here at the office. Even so, just making sure everything's covered. Everybody's got all our rules, make sure all security for all our clients are working and, you know, make sure we're on the pulse. Everyone has time to play catch up, right. I wouldn't call it catch up so much. It's really, you know, move our oranges from one basket to the other, make sure everything's taken care of. Yeah. No rest for the weary.
[00:03:15] Yeah. And I know you already talked about it, but you've got the new house you're getting in. You're settled. You've unpacked all your boxes.
[00:03:20] Oh, yeah. They're all total impact that usually. I think I told you that usually takes me about a year. Well, that's good because we're on pace for about a decade, so.
[00:03:28] Yeah, but it's got to be cool, man. Oh yeah. And the new plants really love it. All right. Excellent. All right.
[00:03:34] Well, let's jump in, Joe.
[00:03:37] You know, we kind of gotten into the habit of reminding people why we call this podcast's Stupid or Irresponsible comes from the marketing campaign. We've already talked about that. But I mean, the gist of it is we ultimately as business owners, executives, managers, we are responsible for the security of our organization. And it's a responsibility that should be taken seriously. And sometimes it's not.
[00:04:03] And, you know, we went on the traveling the speaking circuit for about a year. We're giving away free stuff where we're just begging and pleading people to take this seriously and not getting a great response from it, you know, because unfortunately, if somebody has not had a cybersecurity incident, it's really hard to get them to take it seriously. And so, you know, I went from this kind of coddling, you know, we're all victims here of crime. And it is stupid because we are one of the few places where the government prosecutes the victims. You know that that was kind of my whole pitch before. Like, this is it. If you get broken into in your home, nobody comes in calling you stupid. But if your business gets hit at, you kind of get close to it. You know, I've changed my tune a little bit and there is a level of stupidity to just not paying attention and taking this seriously. So, you know, there we go. The reminder of why we call it that. I don't really think people are stupid, but I do think people get distracted.
[00:05:00] You know, I'll go out on a limb. I guarantee there's a lot of stupid. Well, listen, yeah, you're right. You're right. There absolutely are.
[00:05:11] Maybe we all just have our areas where we're stupid, you know, as I'm kind of trying to defend business owners who have so many things on their plate, you know, and it's easy for me to just jump on here and say they're stupid and they're going to be mad at me and run away and cry or whatever. I don't know. But, you know, there's just there's a lot going on, especially covid like. The world burning down, we've got so many problems, man, we can’t ignore this one. No, no. Yeah, absolutely not. I mean, people get hit. They we'll talk about it. I've got one. You go out of business like it's not recoverable. This isn't you don't get a do over. It's not a video game where you can reset. You know, it's like this is it. If we don't take this seriously, if you get hit hard enough, you're out of business. So there it is.
[00:05:52] Security tip this week, Joe, we're going to talk about, you know, some of these things ar...
Contact us today. Sleep soundly tonight. Schedule a quick 10-minute phone call here - www.mastercomputing.com/discovery
A firewall is a device that acts like a security cop watching over your computer network to detect unauthorized access and activity – and EVERY business and individual needs one.
However, your firewall is completely useless if it’s not set up or maintained properly. Your firewall needs to be upgraded and patched on a continual and consistent basis, and security policies and configurations set. This is not something you want to try and handle on your own – you are best served by letting the pros (us!) handle that for you.
If you’re a managed services client, we’ve got you covered. If not, you should call us immediately to correct the error of your ways: 940-324-9400
Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here - www.mastercomputing.com/discovery - to book a quick, 10-minute call with me.
Hey everybody, welcome to episode 14 of Stupid or irresponsible! We have host, Justin Shelley, CEO of Master Computing and co-host Joe Melot, CIO of Master Computing back with some updates, tips, headlines and more!
Joe:
Justin:
So, Firewalls. It is a device that kind of acts like the security cop that watches over your network. This is going to be like the very end of your network, logically and literally everything. Every Internet activity that happens within an organization of building your house, you name, it goes through this. That is the cop that is watching everything that is going back and forth.
The deal is, though, that your firewall is completely useless if it is not set up if it's not maintained properly. If it is not, you could buy the most top of the line firewall. You might also hear the word router that is kind of street lingo. But really, this is a router, But the technical jargon now is UTM. Basically, it's just the cop. Making sure that only the good stuff comes in.
But now all the bad guys are coming in. None of the good stuff's going out. You have got all kinds of problems, so it's worthless. What is the point? Why even spend the money in the first place? - If you are not going to maintain it, you're not going to get it set up properly. If you’re not going to keep it patched. These things hackers are always looking for the biggest vulnerability, and then once they get, this is basically your front door. If they get in through your front door, they have got full access to all your bedrooms.
Don't just close your browser! When online accessing a banking site or any other application containing sensitive data, make sure you log out of the site and THEN close your browser. If you simply close your browser, some of the session information that a hacker can use to gain entry is still running in the background.
Have questions about cybersecurity or the technology at your company? I am here to help. Access my calendar here to book a quick, 10-minute call with me.
Subscribe:
Spotify | Apple | Google Podcasts
Show Notes:
When online accessing a banking site or any other application containing sensitive data, make sure you log out of the site and THEN close your browser. If you simply close your browser, some of the session information that a hacker can use to gain entry is still running in the background.
Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me. Go to: MasterComputing.com/discovery
Stupid Headlines. Guys, we are a security company, we eat, sleep, and breathe this stuff. Here are a few recent headlines / events that resulted from stupid behavior.
We’ve been covering this Layered approach to the technology / security aspect, but you MUST have the user education aspect also if you want any hope in not being the next victim of cybercrime.
From the publisher's feed