
Sign up to save your podcasts
Or


IT Security Tip: REMOVE these from your laptop, tablet or smartphone
Like it or not, device manufacturers LOVE to stuff your brand-new PC, tablet or phone full of “free” applications (they get paid to do it, so you’ve got a slim chance of getting one without a side of spamware). But clutter is the enemy of a speedy PC, and outdated apps are a breeding ground for hackers; so if you’re not using a particular software on a regular basis, it’s best to REMOVE it completely. That way you don’t have it sucking up processing speed AND leaving the door open to hackers and malware.
Subscribe
Spotify | Apple Podcasts | Google Podcasts
Resources
Book A 10-Minute Discovery Call
Backup Plan #1 - Use this FREE tool at www.virustotal.com
IT Security Tip
Here’s a sneaky trick used by many hackers: they purchase and set up a fraudulent website that is a close misspelling of a legitimate one. Example: www.faceboook.com (extra “o”) or www.dropbox.net (instead of .com). All you have to do is accidentally fat-finger ONE letter in the URL and up pops a very legitimate-looking fake copy of the site you were trying to get to – and the login and links are full of keylogger malware and virus landmines waiting for you to click on them. This is particularly important for any social networks you belong to.
Two Tips: One, bookmark key sites you frequently visit. But even better, have us install a web gateway security product that BLOCKS sites that are suspicious and fraudulent. That way, even if you click on a link to a phishing site, get directed to an infected site or accidentally type in the wrong URL, the site will be blocked, protecting you and your employees.
Show Notes
[2:00] - We are going out of order today. Rather than end with our offer, we are going to start with it. The reason is, I feel like over the last couple episodes I’ve gone soft...
Justin asks Joe some questions:
[5:25] - What's STUPID is waiting for the event to happen and then taking preventive measure to prevent the event that just happened.
[9:50] - If something doesn’t cause emotional response in us, we don’t take action. So yes, listeners, we are trying to scare you but trying to scare you in a way that will PREVENT something that is catastrophic.
[11:10] - When I started this off, we are going in a little reverse order, before we even dig into our topic today, we are going to talk about this offer for a free Security Assessment.
How do I get my FREE Business Security Assessment?
During this assessment, I will ask you some very key questions, and in just 10-minutes I can tell you what we need to do... A roadmap to success. 100% free.
Go to www.mastercomputing.com/discovery and book a 10-minute call before it’s too late!
[13:00] - Justin give Joe a POP QUIZ:
[32:55] - What is stupid: Buying a fire alarm after your house is burned down. Guys don’t wait. Please do not wait until you’ve been breached, hit with ransomware, until your business is vaporized. Because a lot of businesses aren't coming back from these attacks. They’re brutal.
A few simple measures. We can provide a roadmap that can protect you from 97% of this stuff.
Subscribe
Apple | Google | Spotify
The “Dark Web” or “Deep Web” is a part of the World Wide Web we know and love that is ONLY accessible via a special software that allows users and website operators to remain completely anonymous and untraceable. That’s why it’s the playground for hackers and cybercriminals.
Because hacking IS a for-profit business, there are criminal entities who steal, combine and sell personal information on the Dark Web, like passwords, social security numbers, bank account information and credit cards. There is a VERY HIGH probability YOUR information is being sold on the Dark Web – so how do you know?
Call us for a free Dark Web scan for your organization. You can also have us monitor the Dark Web so that when the login credentials for someone on your team are “for sale,” we can notify you so you can immediately change your password and avoid a breach. Also, be careful going to various sites OFFERING a free Dark Web scan. Many are scams designed to get your e-mail and potentially verify that your password is correct, where it’s active, etc.
Subscribe
Spotify | Apple Podcasts | Google Podcasts
A phishing e-mail is a bogus e-mail that is carefully designed to look like a legitimate request (or attached file) from a site you trust in an effort to get you to willingly give up your login information to a particular website or to click and download a virus.
Often these e-mails look 100% legitimate and show up in the form of a PDF (scanned document) or a UPS or FedEx tracking number, bank letter, Facebook alert, bank notification, etc. That’s what makes these so dangerous – they LOOK exactly like a legitimate e-mail. So, how can you tell a phishing e-mail from a legitimate one? Here are a few telltale signs…
First, hover over the URL in the e-mail (but DON’T CLICK!) to see the ACTUAL website you’ll be directed to. If there’s a mismatched or suspicious URL, delete the e-mail immediately. In fact, it’s a good practice to just go to the site direct (typing it into your browser) rather than clicking on the link to get to a particular site. Another telltale sign is poor grammar and spelling errors. Another warning sign is that the e-mail is asking you to “verify” or “validate” your login or asking for personal information. Why would your bank need you to verify your account number? They should already have that information. And finally, if the offer seems too good to be true, it probably is.
Schedule a 10-minute Discovery Call
Master Computing will work with your business to develop a strategy that will provide you with peace of mind and will allow you to concentrate on growing your business instead of stressing about cybersecurity and data protection. Just go to www.master-computing.com/discovery and schedule your free consultation.
Subscribe
Apple | Google | Spotify
In today’s episode Justin and Joe get into ransomware. We’re on episode 8 of Stupid or Irresponsible and for 7 episodes now we have been breaking down ransomware. Last week’s episode we talked about the ransomware attack on Garmin Connect, this week we are talking about one that is a little bit older (not making headlines anymore) but still very much out there in the wild. WannaCry Ransomware.
In this episode we discuss...
Not too long ago, the WannaCry ransomware attack was all over the news, infecting over 400,000 computers. The threat was fairly straightforward: Pay us or we’ll erase your files.
Ransomware, like the WannaCry attack, works by encrypting your files to prevent you from using or accessing them. After your files are compromised, the hackers behind the attack then pop up a demand screen asking for payment within a set time frame (e.g., 72 hours, three days, etc.) in order to get the key to decrypt your files. WannaCry forced many business owners to lose data or pay up since there was no other way to decrypt the files – and many paid without getting their files back.
Obviously the best way to foil a ransomware attack is to be incredibly diligent about IT security; but with hundreds of thousands of new attacks being created daily, there are no guarantees that you won’t get infected. Therefore, it’s critical to maintain a full, daily backup of your data so you never have to pay the ransom – AND your backup needs to be a professional-grade backup that is impervious to ransomware since hackers write their attacks to infect BOTH your PC/server AND your backups.
Show Notes:
Book A 10-Minute Discovery Call Today!
Subscribe
Spotify | Apple Podcasts | Google Podcasts
Show Notes:
In this episode we discuss...
So that is the value for me in trying to reverse engineer this situation and find out what went wrong
We are going to give you some hope – we are going to talk about what you can do... What COULD Garmin have done to have prevented this outage? (4:50)
ABOUT THIS RANSOMWARE ATTACK
Why you should NEVER click on popups:
POP QUIZ: if you see an alert to update something what do you do? (12:30)
Ransomware In the U.S.- We have sanctions in the US against paying ransomware – we can’t pay the ransom to a foreign entity, specifically Russia, and SPECIFICALLY we cab't pay the ransom to this guy - (hint: he created Evil-Corp)
BACKUPS: why the normal restore from backups does not cut it anymore. (19:00)
How offline backups could have PREVENTED this attack: (19:15)
TIPS After Breaking Down This Attack: (20:30)
To the theme of our podcast -
When you get breached, are they going to call YOU the victim stupid or irresponsible? The reality is they are calling you one of these two, they are coming after you either way. So how do we deal with it?So how do we deal with it? (26:55)
“We can't do the head in the sand approach; this attack was PREVENTABLE”
Go to www.master-computing.com/discovery book a 10-minute call with me, Justin Shelley, and we will break it down and show you where the glaring holes in your security are, then give you a road map for success. (28:10)
Subscribe to Stupid or Irresponsible Podcast
Spotify | Apple Podcasts | Google Podcasts
Resources:
Go to www.master-computing.com/discovery and book a 10 minute call, and we will talk about this, we will create an action plan for you.
Join our FREE Security Webinar Here
Show Notes
You are probably thinking "100%? That is B.S." right? Listen now...
It is a matter of time before they get in, that’s the bigger point here.
Interesting statistics from this study: [4:07]
Problem #1: The problem we face in security is that it is just rampant, the attacks are everywhere. They are automated. They are relatively easy to pull off. [5:58]
[7:30] – Problem #2:
“As a business owner (theoretically say I do not own an IT company or have any experience in IT). Maybe I own a law firm and I am the managing partner of the Law firm. Maybe I’m the primary doctor or physician at a local clinic. Maybe I own an accounting firm. I am the guy, I started it, I filed all the paperwork and my specialty is in my craft… How do I prevent a cyber-attack, Joe? “
What to look for in IT support:
Point #1: I as a business owner of any industry outside the IT world, I DON'T KNOW HOW to pick a good IT company.
Point #2: Just because I found a good IT company doesn’t necessarily mean I found somebody that knows anything about security.
"The problem here like I said in the beginning, I don’t know how to vet an IT company, and I sure as hell don’t know how to vet a cyber security firm." [13:07]
[13:25] – Let’s say, we hired this firm to come and protect our company. If we were going to make sure they were doing their job properly, what should we be looking for?
[14:00] - So let’s give them a formula:
The reason that we are going to lay this out is so you the listener can understand or hold your guy accountable because we don’t know how to pick them. We don’t know how to vet them, and we sure as hell don’t know how to hold them accountable. What do we really know about holding these guys accountable? [14:25]
[14:57] – Let’s go through a basic checklist of what should be happening behind the scenes to protect a company:
Starting at the top:
You have got to have somebody or some entity that is looking out for security, that stays in on this, that is just living and breathing network security all the time. Like us!
We’ve got policies, procedures, ongoing training, what are some other things that might be maybe more on the technical side? [20:00]
Quick point about Two Factor Authentication:
[20:40] – Here is a great litmus test: If you aren’t annoyed as hell at your IT company for all the security stuff and hoops you are jumping through…you better find a different one!
[21:45] – Justin’s sign off:
Episode 5 of Stupid or Irresponsible with Justin Shelley, CEO of Master Computing and Joe, CTO here at Master Computing.
Subscribe to Stupid or Irresponsible Podcast
Spotify | Apple Podcasts | Google Podcasts
Resources:
Please to take a second and go to: www.master-computing.com/discovery and book a 10-Minute Call with me, Justin Shelley, and we will make sure that you guys are properly protected. We’ll make sure you have a plan in place. And that you will be able to sleep at night knowing that your company is safe, your data is safe, and your people are safe.
Show Notes:
In previous episodes, we’ve broken down some dumb things we see people do. We’ve talked about dumb things we’ve done ourselves, we’re not immune to that. But this episode is a little different. Today we are going to talk about working from home environments. (1:30) We’re going to break down the ramifications of this massive migration to a work from home environment
Here we are. Today as we record this it is June 30th, 2020 and it has been a hell of a year, am I wrong?
[3:20] - Talking about how they were attacked this morning
BUT we’re still potential victims to it… Even Master Computing, Managed Service Provider for many Medical Facilities.
[6:35] - Step 1: What are the events that led up to this thing, what happened when it did Blue Screen, and is that something that we need to patch fix, repair?
[12:04] - DDoS: Stands for Distributed Denial-of-Services
[14:30] – Vulnerabilities in your networks:
[17:00] – The point is: We are an IT / Security Company. This is what we do night and day. And STILL here we are, victims of at least an ATTEMPTED attack. Did they get through, steal any information, did they breach our network? NO… WHY? Because Joe is a badass.
[17:27] – Why you should invest in IT services:
Justin: I’m just going to make this point really quick. I know technology to some extent, I own the company, I started off as a technician, I’ve got the background. I still don’t do my own IT work because I don’t have time.
[18:05] – Example of an Attorney and why you CAN'T mess around when it comes to Security. The guy is $400/hr is his billing rate and he does his own IT work. That’s stupid. I’m sorry, that’s just flat stupid.
[18:55] - We wanted to talk about this mad rush to work from home and the additional security challenges that were introduced to it.
[19:30] –Today we’re leaning on an article that we read that supports this theory that is was not really the best move to push everybody to the work from home environment so quickly even though there wasn’t much of an option. But there was a company that did this and they were hit.. Financial management company
COVID hits, like everybody, there’s this massive rush to tell everybody to take your work home with you.
(21:05) – What happened to this comp...
Stupid...or Just Irresponsible? | Episode 4: The Bank is NOT Your Friend
Subscribe to Stupid or Irresponsible Podcast
Spotify | Apple Podcasts | Google Podcasts
Resources
Security Webinar - Stay ahead of the game! Sign up for our Security Webinar today. We give you FREE tools, FREE training, and we WILL hold your hand throughout the process. BUT when you don’t take our help or our advice that is stupid.
Schedule Your Discovery Call - If you know you've got a problem take us up on this offer! Book a 10 minute call with myself (Justin Shelley) and we’ll go over what we can do to help, get you started on a path to have a solid plan in place, constantly reviewing that plan, and just making sure you are doing the right things to minimize ALL the risk we possibly can.
Show Notes
[1:50] – Justin shares what started his love affair with technology and how he is shocked to be spending most his time fighting crime...
[2:26] - “I got into computers at the rightful age of 12 but did not see myself fighting crime…”
[2:36] - But here we are… Master Computing is an IT company we really pride ourselves of fast response, on processes, on client education, but man we spend most our time fighting crime! Who knew!?
[2:59] The title of this podcast Stupid or irresponsible
[3:50] - Justin came to this conclusion when making this title - If you don’t care enough about your business to care about your business to protect it from cyber crime, I can’t care about your business more than you do. SO, take the advice, take the tools we’re giving YOU, or don’t but if you don’t and you get hit... sorry YOU’RE STUPID.
[4:08] – Today we are going to talk about a BEC Attack that cost a very intelligent very established businessman $400,000 that he DID NOT RECOVER.
[4:20] – What's a BEC Attack?
What does it mean? What can it do?
You are going to want to Keep listening!
“So, if you want my bank account and you aren’t me but happen to have my email then you pretty much have it all.”
[5:47] - So that’s what a BEC, a scam is – it’s when somebody (aka a hacker) gets access to your email by impersonating you or someone in your business.
What is “Spoofing”?
[5:57] - If somebody can PRETEND to have your email address, we call that “spoofing”
[6:09] – Unless you have security set up it’ll look exactly like it’s coming from you
[6:17] – We’re talking about scary stuff “we can’t really get through life believing every little bad thing is going to happen to us.”
[6:30] – one of the human defense mechanisms is to believe that bad things cannot happen to us… Today, in this podcast, we are here talking about things that HAVE happened.
Listen as we shine light on the importance of this growing threat.
[8:00] - Above was talking about Spoofing
[8:16] What Joe recommends to anyone, especially people who have any kind of personal Yahoo or Gmail account: Setting up one or both of these two things:
The most basic of those would be Multi Factor Authentication (MFA). You might also see 2FA out there. Recommendations from Joe:
[8:35] – So let’s get into the nuts and bolts of this one - we are going to talk about a guy named Verne Harnish
STORY
[9:04] – Verne Harnish got hit. But he is not stupid, he had protections in place.
He was in a foreign country, doing a big presentation to 3,000+ CEO's, executives, entrepreneurs. In this article Verne says he used a “public network” and in that process somebody was able to sniff out his emails and now is when the attack begins.
1st – they hack his email, then they start impersonating him
Note: They are not spoofing him. They are actually INSIDE his email account. They are him.
Inside his email account watching messages being sent between Verne and his admin (communicating about wiring money...)
They sit and learn this stuff until they are able to very accurately impersonate him THEN they make the attack. Wiring money to 3-4 different places. By the time Verne (or anyone) figures it out, it’s game over… the money is GONE.
[12:15] – Joe, let’s talk about what Verne did RIGHT what he did WRONG
So Joe, "DO or DO NOT use Starbucks WiFi?
So what could Verne have done as extra security to possibly prevent this?
[15:00] – What could they have done to possibly prevent this?
The BEST thing they could have done:
Show Notes:
In Episode 3 of Stupid or just Irresponsible Justin Shelley, CEO of Master Computing, and Joe Melot, CTO of Master Computing discuss the stupid things we see out in the wild. Last week we talked about slow computers. Today we play and expand on that and talk about outdated software. When is software out of date? In this episode we put a timeline on software.
Subscribe to Stupid or Irresponsible Podcast
Spotify | Apple Podcasts | Google Podcasts
[4:35] – Using out of date software
[5:35] - Look at Microsoft office (this is what we are going to dig into today) – when do you have to replace it? The end of life?
[5:50] - Oldest version of supported Microsoft office today:
[6:45] - When should people update their software?
[9:00] - QBR – (Quarterly Business Reviews)
[10:04] - Budgeting is #1 want to be able to spread that money out, it always costs less, it definitely costs less to do it right once, then do it wrong 2 or 3 times…
[11:43] – Email migrations: Story from a fellow IT guy
[13:15] – Still Using Exchange 2010
This is perfect example of this costs way more ignore versus just to do it up front and do it right.
“Server 2003 still existed in this company… Windows 95...” That is just stupid.
[17:00] - Ransomware, bank fraud, now they have your exchange system, they are faking your emails to any and all of your contacts..
[17:30] - Paying an IT guy and he is promising the world, but how do you know he is giving sound advice, as far as strategy is concerned?
[18:15] - Schedule your online meeting today!
Go to www.master-computing.com/discovery to book your 10-minute discovery call. We'll ask some key questions, you can ask questions, and if we're a match made in heaven we'll build you a custom technology roadmap. Don't wait until you're painted into a corner, take charge of all things technical within your organization.
From the publisher's feed