Stupid... or Just Irresponsible?

Stupid... or Just Irresponsible?

By Master ComputingBusinessTechnology
Download on the App Store

Stupid... or Just Irresponsible? episodes

  • 22. Shadow IT. Where does your data live?

    UPDATE to last week's Headlines:
    Exchange server Mass-hack – timeline and scope:

    • Early January Microsoft was made aware of active exploits; patch available in March
    • Made free patch available to Exchange Server 2010, both showing flaw is in base code 10yrs old, and how prevalent this is
    • Confirmed 30,000+ US servers, 100's of thousands worldwide have active backdoors.
    • CISA announces “widespread domestic and international exploitation of Microsoft Exchange Server flaws.” campaign blaming China, saying it's a China state-run exploit.  Security researchers confirm at least 4 other state actors currently exploiting, including Russia and North Korea
    • 82k US servers still not patched as of Friday, backdoors still in patched servers
    • Concern that second wave of backdoor use still to come

    This Week's Security Tip:
    So you have a big file you need to get over to your printer YESTERDAY and you can’t get it to “send” via e-mail because the file is too big. What should you do? The right thing to do is contact your IT department (us!) so we can assist by installing a secure, commercial-grade file-sharing application. What you shouldn’t do is download a free copy of Dropbox or some other file-sharing software without telling us. Dropbox and other free apps come with a price: SECURITY. These applications are known for security vulnerabilities and hacks. Plus, if we don’t know about it, we can’t manage it or secure it; so the golden rule is this: NEVER download any software or application without checking with your IT department first!

    Today's Headlines:

    • US DOJ indicted CEO of Sky Global (Sky ECC encrypted messaging app) for allegedly aiding criminal enterprises avoid detection by law enforcement."According to the indictment, Sky Global’s devices are specifically designed to prevent law enforcement from actively monitoring the communications between members of transnational criminal organizations involved in drug trafficking and money laundering. "As part of its services, Sky Global guarantees that messages stored on its devices can and will be remotely deleted by the company if the device is seized by law enforcement or otherwise compromised,"
    • Latest Windows 10 update causes BSOD when trying to print for all versions (1803, 1809, 1909, 2004, 20H2)
    • Molson Coors (Coors light, Miller Lite, Blue Moon, Killians, Foster's) March 11 ransomware attack, causing signifigant disruption to operations.

    Next Week's Teaser:
    It’s disturbing but very real. It’s creepy.

    Call to Action: We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE CALL!

    www.mastercomputing.com/discovery 

    32 min
  • 21. Do this ONE Thing...

    UPDATE to last week's Headlines:

    • FireEye discovered a new "sophisticated second-stage backdoor"(SunShuttle) on the servers of an organization compromised by the threat actors behind the SolarWinds supply-chain attack.
    • If you're keeping track – 1.SunSpot (Orion backddor) 2. Sunburst (second Orion backdoor), 3.Teardrop (memory-dropper for Cobalt Strike beacon installs) 4. RainDrop (TearDrop alternative if it didn't work) 5. SuperNova (delivered through Orion trojan)


    This Week's Security Tip:
    If you do online banking, NEVER access your online account with a PC or device that you use to log in to social media sites or free e-mail accounts (like Hotmail) or to surf the web. Since these are all highly hackable, keeping one PC dedicated to online banking reduces your chances of getting a bank-account-hacking virus. Of course, that PC should have antivirus installed, be behind a well-maintained and well-monitored firewall, have a strong password and be monitored for suspicious activity.

    Today's Headlines:

    • QNAP devices are being hacked to mine cryptocurrency - 4,297,426 potentially vulnerable QNAP NAS devices online.  Need to be patched with firmware after August 2020
    • Microsoft Exchange (2013, 16, and 19) servers patch 4 zero-days, at least 4 state-sponsored hacking groups now exploiting published un-patched machines.  30,000 confirmed US exploits (100's of thousands worldwide), including hospitals, banks, telecoms, utilities, police.

    Next Week's Teaser: It’s tempting to do this and think it’s ok...

    Call to Action: We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE CALL!

    www.mastercomputing.com/discovery 

    26 min
  • 20. What a Secretary Did...

    UPDATE to last week's Headlines:

    • SolarWinds hackers had access to over 3,000 US DOJ email accounts 
    • A website named 'SolarLeaks' is selling data they claim was stolen from Microsoft (source code and repositories $600k), Cisco (source code multiple products $500k), FireEye (security tools – $50k), and SolarWinds (source code and customer portal $250k), or everything for $1mill.
    • Microsoft security teams release report on how Solarwinds hackers stayed hidden (nothing new)

    This Week's Security Tip:
    In a recent incident reported in US news, an office secretary unknowingly gave some of her law firm’s most private data to a gentleman who had bought a Comcast Cable polo shirt off eBay. He dressed in khakis with a tool belt, and told the secretary he was there to audit their cable modem specifications and take pictures of the install for quality assurance. She had no reason to suspect he was part of a now-extinct hacker ring who would gain access to a business’s private network by going inside the office and noting the configuration details and passwords for their firewalls and cable modems. In some cases, they actually built a secure VPN private backdoor they later used to steal data. If someone dressed up in a utility-provider uniform, would you let them in?

    Ask for identification and who they have spoken with about the service they are performing, and be “gracefully suspicious,” as they say in the South. Keep company policies about how visitors are allowed in the building, if such policies exist. If those kinds of policies don’t exist, work to define them. We can help, if needed – but this is a real problem your office needs to address.

    Today's Headlines:

    • Ticketmaster fined $10mil after hiring competitor's employee, then used his credentials that were still active to "choke-off" business and steal one of their high-end contracts
    • Nissan NA source code leaked after server hacked using default admin/admin login
    • Ubiquiti – security breach may have exposed all user data – sent mass email to reset pw – force you to create cloud login, which portal was breached,  instead of local account
    • Hacker leaks full database of 77 million Nitro PDF user records (email addresses, full names, bcrypt hashed passwords, titles, company names, IP addresses, and other system-related information
    • VLC Media Player 3.0.12 fixes multiple remote code execution flaws – very poular traffic cone icon for playing media,  "could trigger either a crash of VLC or an arbitrary code execution with the privileges of the target user."

    Next Week's Teaser: Bank online? Do this ONE thing…

    Call to Action: We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE CALL!

    www.mastercomputing.com/discovery 

    27 min
  • 19. You're ASKING to be hacked!

    Want to know what every hacker hopes you believe? “We’re small…nobody wants to hack us.” This is the #1 reason why people (companies) get hacked. They dismiss the importance of IT security because they’re only a “small business.” This is a lazy, irresponsible excuse.

    One thing is for certain: NO ONE is immune to cybercrime. In fact, one in five small businesses fall victim to cybercrime and that number grows every year. Plus, half of all cyber-attacks are aimed at small businesses BECAUSE they make themselves low-hanging fruit with sloppy or nonexistent security protocols.

    And one more critical point to ponder: If YOU aren’t giving IT security the attention it deserves, how do you think your CLIENTS would feel about that? If for no other reason, you need to do it to protect your clients’ data, even if the only information about them you store is an e-mail address. If YOUR system gets compromised, hackers will now have access to your CLIENTS’ e-mail and can use that for phishing scams and virus-laden spam. I’m sure your clients want you to be a good steward of their information and privacy, so stop lying to yourself and get serious about putting essential security practices in place.

    Have questions about cybersecurity or the technology at your company? I’m here to help. Fill out a form here to book a quick, 10-minute call with me.

    Show Notes:
    If you’ve ever said this, you’re ASKING to get hacked!

    “We’re small nobody is going to hack us” 

    “Nobody cares about us or our data”

    “We’re not big enough to be hacked” 

     

    THIS is the #1 reason companies get hacked. Not because they’re small, but because they use that as an excuse, thinking you’re too small to get hacked. It’s stupid and irresponsible and you’re asking for trouble.  

     

    Thinking you’re “too small to get hacked” is stupid. 

     

    There are 2 primary targets: 

    1.     The low hanging fruit 

    2.     Great big names

     

    It’s way easier to get the low hanging fruit, because if you’re the company that says “we don’t need that”

     

    FACT: 1 in 5 small businesses fall victim to cybercrime every year. 

     

    The last time one of our clients got hacked was over a DECADE ago, and that is when we changed our security ways. We are living proof that if you put security measures in place you can mitigate the risks, at a minimum you can mitigate the risks.

       

    No one is immune from cybercrime…

    ·      1 in 5 small businesses fall victim to cybercrime every year

    ·      ½ of all cyber-attacks are aimed at small businesses BECAUSE they make themselves low-hanging fruit. 

    ·      Non-existing security protocols

    ·      You don’t have policies in place

    ·      The whole culture is backwards, generally it starts at the top. Meaning if you, as a business owner, don’t care about cybersecurity, then I guarantee your employees don’t care. Another thing to consider you get hacked, now you are responsible for all of your clients’ data

     

     

    What’s Irresponsible: Irresponsible is to not have information about whether your stuff is being monitored and maintained. 

     

    Somebody needs to know what kind of firewall you have so when something bad comes up you can go patch that firewall.

     

    Whoever is responsible for security for this company should know this information. I’m looking from a business owner’s perspective. The owner of the company may not know what hardware he has in the IT closet, but better know the name of the person who is monitoring it, patching it, and making sure that guy is doing his job.

     

    Coming up next week: Wait until you hear the story about what this sectary did…. 

    21 min
  • 18. The Number One Threat to Cybersecurity


    YOU! And your employees. Like it or not, human beings are our own worst enemies online, inviting hackers, viruses, data breaches, data loss, etc., through the seemingly innocent actions taken every day online. In most cases, this is done without malicious intent – but if you as a manager or owner aren’t monitoring what websites your employees are visiting, what files they’re sending and receiving, and even what they’re posting in company e-mail, you could be opening yourself up to a world of hurt.


    That’s because employees’ actions can subject the company they work for to monetary loss, civil lawsuits, data theft and even criminal charges if they involve disclosure of confidential company information, transmission of pornography or exposure to malicious code.


    Two things you can do: One, create an Acceptable Use Policy (AUP) to outline what employees can and cannot do with work devices, e-mail, data and Internet. That way they know how to play safe. Second, implement ongoing training (like these tips!) to keep security top of mind. We can also run phishing security tests and score your employees. That will truly show if they know how to spot a suspicious e-mail, and will make them realize how easy it is to be duped.

    If you need help with setting up an AUP or employee training, give us a call at 940-324-9400.


    Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me. 

    31 min
  • 17. Three Essential Rules for the Cloud


    If you’re using any kind of cloud application (and these days, who isn’t?), you are right to be concerned about data privacy and security. The company hosting your data is ultimately responsible for keeping hackers out of THEIR network, but most cloud breaches are due to USER ERROR. So it’s important that you, the user, are being smart about security. Here are a few things you can easily do to improve security in the cloud:


    1. Maintain a STRONG password of at least eight characters with both uppercase and lowercase letters, numbers and symbols. Do NOT make it easy, such as “Password123!” While that technically meets the requirements, a hacker could easily crack that.


    2. Make sure the device you’re using to access the application is secure. This is an area where you need professional help in installing and maintaining a strong firewall, antivirus and spam-filtering software. Don’t access your cloud application with a device you also use to check social media sites and free e-mail accounts like Hotmail.


    3. Back up your data. If the data in a cloud application is important, make sure you’re downloading it from the application and backing it up in another safe and secure location. That way, if your account is hacked, if the data is corrupted OR if the cloud company shuts down your account, you have a copy.


    Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me.

    48 min
  • 16. You've Been HACKED! Now what?

    No matter how diligent you are about security, there’s always a chance you can get hacked. That’s why you need to put a plan in place NOW to protect yourself and your CLIENTS, so damage is minimized. But what should you do if you find out you’ve been hacked?

    First, contact your IT department (us) IMMEDIATELY. The faster we can address the attack – and determine the extent of the data, applications and machines compromised – the better your chances are of preventing much bigger problems. We’ll go to work on containing the attack and conducting a full scan of your network.

    Based on what we discover, we may advise you to contact the local FBI office and your attorney. Your legal responsibilities depend greatly on the type of data accessed. For example, if medical, financial or other confidential records were stolen or accessed, you are legally responsible for notifying affected individuals that their data was compromised (your attorney can best direct you on what you need to do and how to do it).

    Cybercrime is at an all-time high, and hackers are setting their sights on small and medium businesses who are “low hanging fruit.” Don’t be their next victim! 


    Have questions about cybersecurity or the technology at your company? I’m here to help. Book a quick, 10-minute call with me here.

    34 min
  • 15. A Warning if you Handle, Process, or Store Credit Cards


    If you handle, process or store credit cards in any manner, you are required to comply with PCI DSS, or Payment Card Industry Data Security Standards. This is a set of LEGAL requirements you must abide by to maintain a secure environment. If you violate them, you will incur serious fines and fees.


    Are you subject to them if you take credit card payments over the phone? Absolutely! If you have clients that pay you direct by credit card, you’re subject to these laws. However, there are various levels of security standards – but thinking you don’t process enough to matter or that “no one would want to hack us” is dangerous. All it takes is an employee writing down a credit card number in an e-mail or on a piece of paper to violate a law; and then you’ll be left with legal fees, fines and the reputational damage incurred when you have to contact your clients to let them know you weren’t properly storing or handling their credit cards.


    Getting compliant – or finding out if you ARE compliant – isn’t a simple matter I can outline in a 1-2-3-step checklist. It requires an assessment of your specific environment and how you handle credit card information.


    A great resource is the PCI Security Standards Council, or www.pcisecuritystandards.org. If you want assistance in figuring out if you’re compliant, call us for a free assessment.


    Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me.

    Show Notes:

    [00:00:30] Hey, everybody, I am Justin Shelly, CEO of Master Computing,

     

    [00:00:34] And I'm Joe Melot, CIO of Master Computing.

     

    [00:00:37] Welcome to Episode 15 of Stupid or Irresponsible. Joe, most important thing to happen to you this week?

     

    [00:00:48] That's a good question. I probably should have prepared.

     

    [00:00:50] Well, let me talk while you think about that.

     

     So, listen, it was last week or the week before, maybe both. I talked about getting stood up for a podcasting interview because I've had people start reaching out to me and want me to be on their podcast and stuff like that, which just makes me feel special. And they stood me up. Well, then they came back and they apologized profusely and set the whole thing up again.

     

    [00:01:19] I rearranged my entire schedule so that I can be here and do their 15-minute prescreening, meeting, Web meeting or whatever.

     

    [00:01:28] But I mean, we've been planning this thing talking about it sounds like now also last year they had a really dialed in process. And I mean, I'm at the doctor with my kid shuffling that shit then I get here for this interview. And within 30 seconds they're like, oh, well, we're not interested because the we had the wrong number of employees. And I just thought, are you kidding me right now that with all of the process you had in place, you couldn't have asked me this key question from day one and saved me about four weeks of fretting and hours and hours of prepping and whatever. So, I was I was pretty upset. But I'll tell you what, it it made me realize the importance of process and made me look at my own process as I bring guests and to, you know, some of our other podcasts. We've got DFW rock stars. I'll plug that real quick as we're trying to get more. I mean, that was one that struggled. We haven't had a lot of guests. So, building that back up, getting the process dialed in. But that was the most interesting thing to happen to me, is just yet again getting stiffed by this company that I am not happy about it. So, I hope that gave you enough time, Joe. You still got to come up with something on your end.

     

    [00:02:39] Oh, yeah.

     

    [00:02:40] I guess just this week is kind of playing with the old Christmas ideas of, you know, a lot of our clients are out of the office during this time of the year. So, getting everything set up there, you know, we're a little short staffed here at the office. Even so, just making sure everything's covered. Everybody's got all our rules, make sure all security for all our clients are working and, you know, make sure we're on the pulse. Everyone has time to play catch up, right. I wouldn't call it catch up so much. It's really, you know, move our oranges from one basket to the other, make sure everything's taken care of. Yeah. No rest for the weary.

     

    [00:03:15] Yeah. And I know you already talked about it, but you've got the new house you're getting in. You're settled. You've unpacked all your boxes.

     

    [00:03:20] Oh, yeah. They're all total impact that usually. I think I told you that usually takes me about a year. Well, that's good because we're on pace for about a decade, so.

     

    [00:03:28] Yeah, but it's got to be cool, man. Oh yeah. And the new plants really love it. All right. Excellent. All right.

     

    [00:03:34] Well, let's jump in, Joe.

     

    [00:03:37] You know, we kind of gotten into the habit of reminding people why we call this podcast's Stupid or Irresponsible comes from the marketing campaign. We've already talked about that. But I mean, the gist of it is we ultimately as business owners, executives, managers, we are responsible for the security of our organization. And it's a responsibility that should be taken seriously. And sometimes it's not.

     

    [00:04:03] And, you know, we went on the traveling the speaking circuit for about a year. We're giving away free stuff where we're just begging and pleading people to take this seriously and not getting a great response from it, you know, because unfortunately, if somebody has not had a cybersecurity incident, it's really hard to get them to take it seriously. And so, you know, I went from this kind of coddling, you know, we're all victims here of crime. And it is stupid because we are one of the few places where the government prosecutes the victims. You know that that was kind of my whole pitch before. Like, this is it. If you get broken into in your home, nobody comes in calling you stupid. But if your business gets hit at, you kind of get close to it. You know, I've changed my tune a little bit and there is a level of stupidity to just not paying attention and taking this seriously. So, you know, there we go. The reminder of why we call it that. I don't really think people are stupid, but I do think people get distracted.

     

    [00:05:00] You know, I'll go out on a limb. I guarantee there's a lot of stupid. Well, listen, yeah, you're right. You're right. There absolutely are.

     

    [00:05:11] Maybe we all just have our areas where we're stupid, you know, as I'm kind of trying to defend business owners who have so many things on their plate, you know, and it's easy for me to just jump on here and say they're stupid and they're going to be mad at me and run away and cry or whatever. I don't know. But, you know, there's just there's a lot going on, especially covid like. The world burning down, we've got so many problems, man, we can’t ignore this one. No, no. Yeah, absolutely not. I mean, people get hit. They we'll talk about it. I've got one. You go out of business like it's not recoverable. This isn't you don't get a do over. It's not a video game where you can reset. You know, it's like this is it. If we don't take this seriously, if you get hit hard enough, you're out of business. So there it is.

     

    [00:05:52] Security tip this week, Joe, we're going to talk about, you know, some of these things ar...

    31 min
  • 14. Your Firewall is USELESS unless...

    Contact us today. Sleep soundly tonight. Schedule a quick 10-minute phone call here - www.mastercomputing.com/discovery 


    A firewall is a device that acts like a security cop watching over your computer network to detect unauthorized access and activity – and EVERY business and individual needs one.

    However, your firewall is completely useless if it’s not set up or maintained properly. Your firewall needs to be upgraded and patched on a continual and consistent basis, and security policies and configurations set. This is not something you want to try and handle on your own – you are best served by letting the pros (us!) handle that for you.

    If you’re a managed services client, we’ve got you covered. If not, you should call us immediately to correct the error of your ways: 940-324-9400

    Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here - www.mastercomputing.com/discovery - to book a quick, 10-minute call with me.

    • Intro. 

    Hey everybody, welcome to episode 14 of Stupid or irresponsible! We have host, Justin Shelley, CEO of Master Computing and co-host Joe Melot, CIO of Master Computing back with some updates, tips, headlines and more!

     

    • What’s the most interesting thing that happened to you this week?

    Joe:

    • Different for sure. Been diving into CMMC Framework, excited about that for the SPRs for the DOD. Basically, a new PCI, stuff for the Department of Defense contracts, contractor vendors and that kind of stuff. Nothing exciting there. A lot of pencil pushing a lot of paperwork. My personal life, fixing things in the new house, fix some broken shit, some fun, some not so much.

    Justin:

    • The most exciting thing that happened to me last week – was I got stood up for a podcast interview!

     

    • Reminder why we call it “Stupid or Irresponsible”. 4:50
       
      • It started with an ad campaign, saying how when you get hit or WHEN You Get Breached, Are They Going To Call Your Stupid…or Just Irresponsible?? 
        • I used to subscribe to the victim mentality, but that will get us nowhere. Also, I tried for a full year to give this away free of charge and very few took me up on the offer. That is stupid. If we are not giving this our full attention, we are stupid. We should know better. We should be ashamed of ourselves. Even BASIC security measures could be the difference of going out of business or not. 


    • Stupid Update. 
      • Justin’s stupid update “You’re looking at it…” I clicked on a stupid email this week, and sure enough it was a phishing email. 
        • We broke down phishing scams a few episodes ago and talked recently about just how outrageous they are becoming, and here I am, falling for one. Fell for the subject like “Check Number 01328” and I opened it. It got through numerous spam filters, It came from someone who I am acquainted with, and their email got breached. So, then open email and an there is this image of a check that is small enough that you do not really see it, so I click on it trying to figure out what the hell it is, and now THERE WE GO. The portal to login to your Microsoft account…stupid move on my part. 
        • LUCKILY, we have been talking about this week after week during our podcasts and I was able to save it before it went any further. It could have been just as easily a link that I clicked and downloads malicious payloads, but luckily it was not. 

     

    • Security/Productivity tip. 9:45:  
      • Joe, we are talking about firewalls today and the title is kind of interesting. Your firewall is useless. Start Joe, break it down for people. What's a firewall? 
    • What is a firewall joe?

    So, Firewalls. It is a device that kind of acts like the security cop that watches over your network. This is going to be like the very end of your network, logically and literally everything. Every Internet activity that happens within an organization of building your house, you name, it goes through this. That is the cop that is watching everything that is going back and forth. 

     

    The deal is, though, that your firewall is completely useless if it is not set up if it's not maintained properly. If it is not, you could buy the most top of the line firewall. You might also hear the word router that is kind of street lingo. But really, this is a router, But the technical jargon now is UTM. Basically, it's just the cop. Making sure that only the good stuff comes in. 

    But now all the bad guys are coming in. None of the good stuff's going out. You have got all kinds of problems, so it's worthless. What is the point? Why even spend the money in the first place? -  If you are not going to maintain it, you're not going to get it set up properly. If you’re not going to keep it patched. These things hackers are always looking for the biggest vulnerability, and then once they get, this is basically your front door. If they get in through your front door, they have got full access to all your bedrooms. 

    • So, making sure that it is up to date that it has got the newest patches got the newest updates. It is set up correctly. You have got the right filtering engine, you have got the right, you are blocking the right things, etc.

     

    • Stupid Headlines:
       
      • Spam email campaigns – they are just going crazy. Like all over the place. I've been scouring all of our client’s spam filters kind of seeing, you know, because the fact that it got to your mailbox, it just that intrigued me. That is interesting because we have got so many filters, is so many blocks and stuff. But these guys are getting so smart. The latest thing they have been doing is having a website where it's just a link. There are no malicious payloads. There is no anything. All it is a redirect. 
        • Problem is - You cannot make hyperlinks; you know warning flag for your spam filter. 
        • Why? -  Because half of the world uses in their signature. They have a link to their Facebook, their website, you name it. 
        • How hackers do this? - A lot of this times they are like legitimate links. Maybe it's a OneDrive. Or maybe it's, you go the OneDrive, and then THAT is the actual fake. So, it has been a breached OneDrive, page or OneDrive document that they make the look like a page really is just a credential steel or something like that. Asking you to log in.
    • How do you fix that? 
      • So, it is really down to user training. End user training. 
        • We have really been pushing that hard and again speaking to what I was talking about earlier. What I have been jumping into is, this CMMC this Department of Defense contracting stuff, and they require
    28 min
  • 13. Don't Just Close Your Browser

    Don't just close your browser! When online accessing a banking site or any other application containing sensitive data, make sure you log out of the site and THEN close your browser. If you simply close your browser, some of the session information that a hacker can use to gain entry is still running in the background.

    Have questions about cybersecurity or the technology at your company? I am here to help. Access my calendar here to book a quick, 10-minute call with me.

    Subscribe:
    Spotify | Apple | Google Podcasts

    Show Notes:

    • Intro.  Hey everybody, welcome to episode 13 of Stupid or irresponsible! I’m Justin Shelley, CEO of Master Computing and my co-host Joe Melot, CIO of Master Computing. 
    • Get to know us. Joe and Justin share a quick window into their personal lives, personality, what makes them tic, this week...  
    • Justin reminds listeners of why we call it “Stupid or Irresponsible” 
      • I used to subscribe to the victim mentality. But that will get us nowhere. Also, I tried for a full year to give this away free of charge and very few took me up on the offer. That’s stupid. If we aren’t giving this our full attention, we’re stupid. We should know better. We should be ashamed of ourselves. 


    • Stupid Update - [9:00]. We are introducing a NEW segment to this podcast called the Stupid Update. The update here is we are going to follow-up on any previous episodes where we might’ve left you hanging. For example, last week's episode there was an issue, and we promised we would follow up. So here it is:  
      •  UHS, a Giant Hospital System in America – Since last week, Oct. 12, they said they got all systems restored, users confirmed phones working again! However, does not say if they paid the ransom, a third party is believed to have paid the ransom for them. Because of this, a big announcement was made by OFAC requiring you to get permission through them, and if you go through third party – they are going to prosecute.   

     

     

    • IT Security/Productivity Tip of the week - [15:12].  Don’t just close your browser! 

    When online accessing a banking site or any other application containing sensitive data, make sure you log out of the site and THEN close your browser. If you simply close your browser, some of the session information that a hacker can use to gain entry is still running in the background. 

    Have questions about cybersecurity or the technology at your company? I’m here to help. Access my calendar here to book a quick, 10-minute call with me. Go to: MasterComputing.com/discovery


    • [21:30] - The different Layers of Security: 
    1. Have an antivirus 
    2. Have a spam filter that’ll block spam from even getting to your email in the 1st place! 
    3. Make sure someone is monitoring that, and that it is blocking the RIGHT level of security. Make sure someone has your back and watching this 24/7 (like us!). 


    Stupid Headlines. Guys, we are a security company, we eat, sleep, and breathe this stuff. Here are a few recent headlines / events that resulted from stupid behavior.  

    • EMOTET and the Trickbot campaigns are on overdrive. 
    • Iran is going nuts, they hacked the BIG DOGS and have been sending the same email spam campaign 
    • So much spam going on right now, trying to trick people into giving credentials, and succeeding.  
    • Whale Phishing attack – this is a certain type of spear phishing   
    • Vote from Home Ballots – if you know someone's mailing address and last name... you can change their vote. Print it out, mail it in and change their vote. [24:20] 

    We’ve been covering this Layered approach to the technology / security aspect, but you MUST have the user education aspect also if you want any hope in not being the next victim of cybercrime.  

    • Stupid Teaser [ 26:10]. What’s coming up next week. The next stupid thing we’re going to break down is your router!  What to do, what not to do, and why you may have a giant false sense of security going on. 

     

    • Joe’s Key Takeaways [ 26:45]: Turn on two-factor authentication! Keep your eyes peeled for these spam emails, they are EVERYWHERE. Unless you have someone like us blocking spam and monitoring the security levels, then probably just don’t open your emails...  

     

    • Smart Call to Action [27:35]. We talk a lot about stupid (nothing bad ever happens to me; head in the sand; too busy; I’ll do it later). So, what’s smart? Taking this seriously TODAY. Book a 10-minute Discovery Call right now. I’ll ask some key questions and give you a quick score. If you’re doing everything right, you can sleep better at night. If there’s room for improvement, we’ll discuss options. NO PRESSURE, NO STRINGS. JUST BOOK THE DAMN CALL! 
    30 min

About Stupid... or Just Irresponsible?

From the publisher's feed

People do the dumbest things! (Myself included) And then get so upset when it blows up in their face. We're here to break down the stupid, the irresponsible, the reckless, and the absurd where…