Stupid... or Just Irresponsible?

Stupid... or Just Irresponsible?

By Master ComputingBusinessTechnology
Download on the App Store

Stupid... or Just Irresponsible? episodes

  • 12. Bloatware Nightmare

    IT Security Tip: REMOVE these from your laptop, tablet or smartphone

     

    Like it or not, device manufacturers LOVE to stuff your brand-new PC, tablet or phone full of “free” applications (they get paid to do it, so you’ve got a slim chance of getting one without a side of spamware). But clutter is the enemy of a speedy PC, and outdated apps are a breeding ground for hackers; so if you’re not using a particular software on a regular basis, it’s best to REMOVE it completely. That way you don’t have it sucking up processing speed AND leaving the door open to hackers and malware.

    33 min
  • 11. Fire Alarms and Bookmarks

    Subscribe
    Spotify | Apple Podcasts | Google Podcasts

    Resources
    Book A 10-Minute Discovery Call

    Backup Plan #1 - Use this FREE tool at www.virustotal.com

    IT Security Tip
    Here’s a sneaky trick used by many hackers: they purchase and set up a fraudulent website that is a close misspelling of a legitimate one. Example: www.faceboook.com (extra “o”) or www.dropbox.net (instead of .com). All you have to do is accidentally fat-finger ONE letter in the URL and up pops a very legitimate-looking fake copy of the site you were trying to get to – and the login and links are full of keylogger malware and virus landmines waiting for you to click on them. This is particularly important for any social networks you belong to.


    Two Tips: One, bookmark key sites you frequently visit. But even better, have us install a web gateway security product that BLOCKS sites that are suspicious and fraudulent. That way, even if you click on a link to a phishing site, get directed to an infected site or accidentally type in the wrong URL, the site will be blocked, protecting you and your employees.

    Show Notes 

    [2:00] - We are going out of order today. Rather than end with our offer, we are going to start with it. The reason is, I feel like over the last couple episodes I’ve gone soft...  

    Justin asks Joe some questions: 

    • What’s the title of this podcast?  
    • Do you remember why we name it Stupid or Irresponsible? 


    • [3:35] - When I decided to call the podcast “Stupid or Irresponsible” I did it on purpose. To be inflammatory with the topic. I wanted to get people's attention, because this is one of those things we CAN’T take lightly.  We can’t just sit around and hope we don’t get hit with ransomware, hope we don’t get hacked by criminals in China and Russia.  


    • [5:10] - Here’s what’s stupid: Putting fire alarms in your house AFTER having a fire. The most frequent sales of fire alarms are after people had a fire. 
    • When we are selling cybersecurity services, unless someone has had some sort of a cyber security event, they are very unlikely to buy...   

    [5:25] - What's STUPID is waiting for the event to happen and then taking preventive measure to prevent the event that just happened.  

    [9:50] - If something doesn’t cause emotional response in us, we don’t take action. So yes, listeners, we are trying to scare you but trying to scare you in a way that will PREVENT something that is catastrophic. 


    [11:10] - When I started this off, we are going in a little reverse order, before we even dig into our topic today, we are going to talk about this offer for a free Security Assessment.  


    How do I get my FREE Business Security Assessment?    

    • Book a 10-Discovery call – jump on the phone, spend 10 minutes with Justin Shelley, CEO of Master Computing.  

    During this assessment, I will ask you some very key questions, and in just 10-minutes I can tell you what we need to do... A roadmap to success. 100% free.  

    • What is a Key Question I will ask you in this Discovery Call? 
      • One of the very first questions I ask is if you are doing a regular consistent end-user education? Are your employees constantly going through some sort of cyber security program, and if they are, who is running it? When was the last time you went through an employee training program?  

    Go to www.mastercomputing.com/discovery and book a 10-minute call before it’s too late! 


    [13:00] - Justin give Joe a POP QUIZ:

    • How much does this Security Assessment I offer cost?  
    • How many strings are attached?  
    • Will we try to sell you something you don’t need? 
    • Does anyone ever complain about me, Justin, being a high-pressure salesperson? 

     

    [32:55] - What is stupid: Buying a fire alarm after your house is burned down. Guys don’t wait. Please do not wait until you’ve been breached, hit with ransomware, until your business is vaporized. Because a lot of businesses aren't coming back from these attacks. They’re brutal. 


    A few simple measures. We can provide a roadmap that can protect you from 97% of this stuff.  

    • Take 10-minutes go to www.mastercomputing.com/discovery we’ll write a custom plan for you and we will help you put it into place if you’d like.  

     

    35 min
  • 10. What is the Dark Web?

    Subscribe

    Apple | Google | Spotify

    The “Dark Web” or “Deep Web” is a part of the World Wide Web we know and love that is ONLY accessible via a special software that allows users and website operators to remain completely anonymous and untraceable. That’s why it’s the playground for hackers and cybercriminals.


    Because hacking IS a for-profit business, there are criminal entities who steal, combine and sell personal information on the Dark Web, like passwords, social security numbers, bank account information and credit cards. There is a VERY HIGH probability YOUR information is being sold on the Dark Web – so how do you know?


    Call us for a free Dark Web scan for your organization. You can also have us monitor the Dark Web so that when the login credentials for someone on your team are “for sale,” we can notify you so you can immediately change your password and avoid a breach. Also, be careful going to various sites OFFERING a free Dark Web scan. Many are scams designed to get your e-mail and potentially verify that your password is correct, where it’s active, etc.

    32 min
  • 9. Phishing For Dummies

    Subscribe
    Spotify | Apple Podcasts | Google Podcasts

    A phishing e-mail is a bogus e-mail that is carefully designed to look like a legitimate request (or attached file) from a site you trust in an effort to get you to willingly give up your login information to a particular website or to click and download a virus.


    Often these e-mails look 100% legitimate and show up in the form of a PDF (scanned document) or a UPS or FedEx tracking number, bank letter, Facebook alert, bank notification, etc. That’s what makes these so dangerous – they LOOK exactly like a legitimate e-mail. So, how can you tell a phishing e-mail from a legitimate one? Here are a few telltale signs…


    First, hover over the URL in the e-mail (but DON’T CLICK!) to see the ACTUAL website you’ll be directed to. If there’s a mismatched or suspicious URL, delete the e-mail immediately. In fact, it’s a good practice to just go to the site direct (typing it into your browser) rather than clicking on the link to get to a particular site. Another telltale sign is poor grammar and spelling errors. Another warning sign is that the e-mail is asking you to “verify” or “validate” your login or asking for personal information. Why would your bank need you to verify your account number? They should already have that information. And finally, if the offer seems too good to be true, it probably is.

    47 min
  • 8. How to Protect Against Ransomware

    Schedule a 10-minute Discovery Call
    Master Computing will work with your business to develop a strategy that will provide you with peace of mind and will allow you to concentrate on growing your business instead of stressing about cybersecurity and data protection. Just go to www.master-computing.com/discovery and schedule your free consultation. 

    Subscribe

    Apple | Google | Spotify 

    In today’s episode Justin and Joe get into ransomware. We’re on episode 8 of Stupid or Irresponsible and for 7 episodes now we have been breaking down ransomware. Last week’s episode we talked about the ransomware attack on Garmin Connect, this week we are talking about one that is a little bit older (not making headlines anymore) but still very much out there in the wild. WannaCry Ransomware. 

    In this episode we discuss...

    • What NOT to do if you want any hope at protecting against ransomware.
    • The background story of this virus (P.S. this is almost as interesting as the actual exploit itself) 
    • How ransomware works - paralyzing machines and demanding bitcoin ransom, WannaCry jumping from one machine to the next
    •  and the 5 different stages of this malware spread 
    • Why cybersecurity researchers named the worm "WannaCry"


    Not too long ago, the WannaCry ransomware attack was all over the news, infecting over 400,000 computers. The threat was fairly straightforward: Pay us or we’ll erase your files. 

     

    Ransomware, like the WannaCry attack, works by encrypting your files to prevent you from using or accessing them. After your files are compromised, the hackers behind the attack then pop up a demand screen asking for payment within a set time frame (e.g., 72 hours, three days, etc.) in order to get the key to decrypt your files. WannaCry forced many business owners to lose data or pay up since there was no other way to decrypt the files – and many paid without getting their files back.


    Obviously the best way to foil a ransomware attack is to be incredibly diligent about IT security; but with hundreds of thousands of new attacks being created daily, there are no guarantees that you won’t get infected. Therefore, it’s critical to maintain a full, daily backup of your data so you never have to pay the ransom – AND your backup needs to be a professional-grade backup that is impervious to ransomware since hackers write their attacks to infect BOTH your PC/server AND your backups. 


    Show Notes:

    • 5:00 - Joe tells the story of WannaCry Ransomware 
    • 5:50 - How did this worm get the name "WannaCry"?  
    • 6:10 - The background story of this virus (listen - this is almost as interesting as the actual exploit itself!) 
    • 6:25 - How did this virus start? (Hint: your employees are your weakest security link!)
    • 6:50 – The different stages of ransomware: 
      • 1. Initial access
      • 2. Execution 
      • 3. Escalation 
      • 4. Defense evasion – hiding around from your antivirus  
      • 5. Then the exploit, the impact
    • Stupid: When it comes to cyber security stupid is thinking you can DIY. Thinking you can protect your business from these hackers by yourself. “Thinking you can do this yourself, that cyber security is a DIY type activity is flat stupid” - (16:00)
    • Irresponsible: Is trusting your IT company / cyber security firm WITHOUT VERIFYING. - (16:55)
    • The DIY approach to security - we are going to talk about DIY first to make the point we are giving this formula NOT as a formula to do it yourself, but to rate your current support system. Then, if these things aren't happening you know you’ve got to do something different now! - (20:00)
    • 20:17 – If you can't easily answer these questions about the things happening in your company YOU HAVE A PROBLEM!
      • For example – Is your backup running? Are there test restores going on? 


    • Top 9 ways to protect against ransomware: - (21:40)
    • #9 - Data Backup (test restore) 
      • Have a solid backup  - this used to be #1 most important on the list and the get out of jail free card
      • Now a backup alone is NOT ENOUGH!
    • #8 - Get a good, enterprise-grade firewall  
      • Get a good firewall, that is current, up-to-date security subscriptions, somebody monitoring the firewall. Get a good firewall make sure somebody's watching it. 
    • #7 – Password Management in place  
      • (Listen to Episode 1: The Stupid things people do with passwords) 
    • #6 - Policies and Procedures
      • If your IT company isn’t doing this for you and doesn't have this place then you’ve got some questions to ask! 
    • #5 - Two factor authentication (2FA) in place
      • If your IT company isn’t annoying you to death, then they aren’t doing their job!  
    • #4 - SOC 24/7/365 
    • #3 – Behavior-based anti-malware
      • You have to have a behavior-based anti-malware in place, but all this does when it finds something suspicious is it raises an alert. Which goes back to our point that someone needs to be watching this, getting alerts all day every day!
      • Most businesses don’t have the capacity to do this on their own, both in time & expertise.  
      • Generally, this is something that is outsourced. 
    • #2 – End User Training 
      • This is the 2nd most important thing you can do, it is CRITICAL! (28:30)  
      • Things are changing every day. Something new is going on, something changed, hackers are getting smarter (28:30) 
      • By training your end-users, employees, this creates a culture of awareness and gives them refresher.
      • Phishing simulated attack – we have a security piece that will send us a fake email that says click this link – when we do click on it, it locks our computer down and makes us take a training course 
      • If you don’t have that in place you have questions to ask your IT company guys 
    • #1 - 3rd Party Review
      • This is the NUMBER 1 thing you NEED to do that is absolutely critical to protecting your network. Have a 3rd party audit and extra set of eyes checking others work. (30:10) 

     


    36 min
  • 7. Popups Cause Global Outage and Impact Millions

    Book A 10-Minute Discovery Call Today!

    Subscribe
    Spotify | Apple Podcasts | Google Podcasts

    Show Notes:  

    In this episode we discuss... 

    • A confirmed WastedLocker Ransomware attack on Garmin Connect  - A GPS software, they run GPS infrastructure for a whole lot of devices all around the world
    • We are going to reverse engineer this ransomware attack on Garmin Connect and tell you exactly what hope we have for preventing this! (5:10)  
    • Joe is going to break this down for us with inside info from a couple discrete cyber security forums that he’s in. (3:30) 
    • Disclaimer: Official word from Garmin was that they’re having a network outage, doing some emergency repairs, something like that - 
    • By default, we are not inclined to talk about our dirty laundry nobody wants to do that. But the tragedy in the industry is that we don’t get to learn from other’s mistakes because it’s always so hidden.  
    • Listen as we reverse engineer this situation with insider information and find out what went wrong and what can we do, what could Garmin have done to prevent this.

    So that is the value for me in trying to reverse engineer this situation and find out what went wrong  

    • What most people will say in a case like this is: “Well if Garmin is going to get breached, and they have all the resources in the world what hope do I have?” (4:30) 

    We are going to give you some hope – we are going to talk about what you can do... What COULD Garmin have done to have prevented this outage? (4:50)  


    ABOUT THIS RANSOMWARE ATTACK 

    • Confirmed WastedLocker ransomware attack - the new fancy name for this strain of ransomware (10:25) 
    • They engineered this software for Garmen – it was a personal, TARGETED attack. It was so targeted that they knew specifically what users they were targeting. (11:00) 

    Why you should NEVER click on popups: 

    • They knew specifically what users they were targeting - This particular hack is from clicking on a java script code (so a pop-up on a website) and they knew this particular user would go to this particular website pretty frequently and would possibly click on a popup. (11:10) 

    POP QUIZ: if you see an alert to update something what do you do? (12:30)  

    Ransomware In the U.S.- We have sanctions in the US against paying ransomware – we can’t pay the ransom to a foreign entity, specifically Russia, and SPECIFICALLY we cab't pay the ransom to this guy - (hint: he created Evil-Corp)  

    BACKUPS: why the normal restore from backups does not cut it anymore. (19:00) 

    • What you normally do is restore from backups, but this was intelligent enough to get in and wipe out their backups too (19:00) 
    • Cool thing about backups, if you are doing it right there are other, additional preventative measures that could have prevented this attack.... 

    How offline backups could have PREVENTED this attack: (19:15) 

    • Offline backups – this is an additional preventative measure that we take here at Master Computing and therefore this would NOT have affected us or our clients. Because we keep offline backups for them.  

    TIPS After Breaking Down This Attack:  (20:30) 

    1. Don’t do updates that are pushed to you – go to the website/app directly and do it from there – initiate it yourself. 
    2. It starts with the site that they clicked on – so, make sure you have security on your website and someone looking out for these things.  
    3. When you are hiring an IT firm to do your security – you may not want to go to the cheapest bidder - (23:55)   
    4. Communication is KEY for the IT security world.  

    To the theme of our podcast - 

    When you get breached, are they going to call YOU the victim stupid or irresponsible? The reality is they are calling you one of these two, they are coming after you either way. So how do we deal with it?  


    So how do we deal with it? (26:55)  

    • Put a plan in place,  
    • Follow industry standards,  
    • Follow best practices, 
    • If you do this, then you’ve got to know what they are and stay up to date on them.  

    “We can't do the head in the sand approach; this attack was PREVENTABLE” 

    • This attack was preventable – with the right software, it was PREVENTABLE – So, get a plan in place, check your plan on a regular basis  and for the love of all things, get someone else to check your plan. 
    • You CANNOT ASSUME that even if you hire the best IT company / Cyber security company out there that they know what they’re doing. You better get somebody to check their work.  
    • At a minimum get someone to come in to look at what you're doing for security, your plan, your approach to protect your network, your customers, your employees.  

    Go to www.master-computing.com/discovery book a 10-minute call with me, Justin Shelley, and we will break it down and show you where the glaring holes in your security are, then give you a road map for success. (28:10) 

     

    30 min
  • 6. 100% of Law Firms Targeted by Cyberattacks

    Subscribe to Stupid or Irresponsible Podcast
    Spotify  | Apple Podcasts | Google Podcasts

    Resources:
    Go to www.master-computing.com/discovery and book a 10 minute call, and we will talk about this, we will create an action plan for you.

    Join our FREE Security Webinar Here

    Show Notes

     

    • Today’s episode we talk about this article by an info security magazine study.  In this study they show that 100% of law firms have been attacked or targeted between January - March of 2020. [2:30]

    You are probably thinking "100%? That is B.S." right? Listen now...

    • In this study they are talking, specifically, about the Legal Industry is under attack. They make it sound like more so than anybody else. [3:40]
    • We could do our own study and show that EVERYBODY is under attack 100% of the time 

    It is a matter of time before they get in, that’s the bigger point here.

     

    Interesting statistics from this study: [4:07]

    • 15% of law firms were likely compromised (that’s a lot)
    • Nearly HALF of law firms had some other form of suspicious activity on their network.

     Problem #1: The problem we face in security is that it is just rampant, the attacks are everywhere. They are automated. They are relatively easy to pull off. [5:58] 

    • “If I’m an amateur hacker and I want to break into your network what do I have to do? How hard is it? What is the learning curve on this?”[6:25]  


    [7:30] – Problem #2:

    “As a business owner (theoretically say I do not own an IT company or have any experience in IT). Maybe I own a law firm and I am the managing partner of the Law firm. Maybe I’m the primary doctor or physician at a local clinic. Maybe I own an accounting firm. I am the guy, I started it, I filed all the paperwork and my specialty is in my craft… How do I prevent a cyber-attack, Joe? “

    What to look for in IT support:

    •  Businesses operate on some pretty slim margins. So, when I’m out looking for tech support and 3 people show up at my door saying hey, we can all do the same thing, how do I choose? [8:20] 

    Point #1: I as a business owner of any industry outside the IT world, I DON'T KNOW HOW to pick a good IT company.

    Point #2: Just because I found a good IT company doesn’t necessarily mean I found somebody that knows anything about security. 


    Cyber Security is more of a specialty. Whereas IT consultants are kind of generalist – think of your family physician.

     

    • “Like Joe said in the beginning, statistics could be made up, could be manipulated, BUT Every time I look at the statistics it’s about 20% of businesses get hacked.”
    • I’ve seen it a bunch of different ways, but...The reality is, if you play the odds long enough, the real likelihood of some sort of a breach is probably approaching that dreaded 100%.


    As a business owner, as a managing partner at a law firm, as the practice manager who is responsible for the clinic. When somebody gets hit, that falls on YOU. 

     

    "The problem here like I said in the beginning, I don’t know how to vet an IT company, and I sure as hell don’t know how to vet a cyber security firm." [13:07]

     

    [13:25] – Let’s say, we hired this firm to come and protect our company. If we were going to make sure they were doing their job properly, what should we be looking for? 

    • How do you vet an IT company if you don’t know anything about IT? 

    [14:00] - So let’s give them a formula:

    • NOTE: If you try to implement this yourself, that is flat stupid. Because you can’t. It is like me trying to do heart surgery myself. Please for the love of god don’t do that. 

    The reason that we are going to lay this out is so you the listener can understand or hold your guy accountable because we don’t know how to pick them. We don’t know how to vet them, and we sure as hell don’t know how to hold them accountable. What do we really know about holding these guys accountable? [14:25]

     

    [14:57] – Let’s go through a basic checklist of what should be happening behind the scenes to protect a company:

     

    Starting at the top:

    • We want to make sure they have strict policy on of use of company devices.
    • Procedures – have a document in place 
    • Have some sort of regular training or education for employees for safest and best practices.
    • Ongoing education
    • Letting the client know if information has been compromised immediately.
    • You SHOULD have an incident response plan for if and WHEN you get hit. What are the proper procedures? 
    • Constantly updating security and hiring digital security firm if needed. 
    • Like we mentioned earlier, if you have an IT guy that’s great, but you NEED a security guy. 

    You have got to have somebody or some entity that is looking out for security, that stays in on this, that is just living and breathing network security all the time. Like us!

    • If you were to be compromised: 1. There should be a policy and 2. It should be enforced. [18:05]

     

    We’ve got policies, procedures, ongoing training, what are some other things that might be maybe more on the technical side? [20:00] 

     

    Quick point about Two Factor Authentication:

    • If your IT guy if your security guy isn’t talking to you and beating you up over Two Factor Authentication (2FA) then you probably better find a new one!

     

    [20:40] – Here is a great litmus test: If you aren’t annoyed as hell at your IT company for all the security stuff and hoops you are jumping through…you better find a different one!

     

    [21:45] – Justin’s sign off:

    • The stupid answer here is to not be prepared. To not be paying attention to this. To thinking that you are invulnerable. 
    • To think that this isn’t going to happen ...
    25 min
  • 5. Blindsided by the COVID

    Episode 5 of Stupid or Irresponsible with Justin Shelley, CEO of Master Computing and Joe, CTO here at Master Computing.

    Subscribe to Stupid or Irresponsible Podcast
    Spotify  | Apple Podcasts | Google Podcasts

    Resources:
    Please to take a second and go to:
    www.master-computing.com/discovery and book a 10-Minute Call with me, Justin Shelley, and we will make sure that you guys are properly protected. We’ll make sure you have a plan in place. And that you will be able to sleep at night knowing that your company is safe, your data is safe, and your people are safe. 

    Show Notes:

    In previous episodes, we’ve broken down some dumb things we see people do. We’ve talked about dumb things we’ve done ourselves, we’re not immune to that. But this episode is a little different.  Today we are going to talk about working from home environments. (1:30) We’re going to break down the ramifications of this massive migration to a work from home environment

    Here we are. Today as we record this it is June 30th, 2020 and it has been a hell of a year, am I wrong?

    • "Initially when the COVID lock down hit everybody just did this mad dash to work from home… Our clients all wanted to work from home immediately, and many of them are still doing it." (1:40) 
    • "Nobody saw this coming – so it’s not that we couldn’t have done a better job at pushing people into the home, working environment. It’s that there wasn’t TIME. And a lot of time there wasn’t resources – cameras for example you still can’t buy a webcam – not a good one." (2:33) 
    • " We’re going to break down the ramifications of this massive migration to a work from home environment" (3:10)

    [3:20] - Talking about how they were attacked this morning


    • We are a security company! It’s we eat, breath, and sleep this stuff. We’re always talking about it. We record podcasts on it, and listen… When we do this, we’re taking our own notes, improving our own security every day. At least every week we’re meeting about it, talking about it.

    BUT we’re still potential victims to it… Even Master Computing, Managed Service Provider for many Medical Facilities. 



    [6:35] - Step 1: What are the events that led up to this thing, what happened when it did Blue Screen, and is that something that we need to patch fix, repair?

    • Port Scanning – looking for holes and exploit vulnerabilities.
    • Geo-blocking: We generally Geo-block meaning we can block separate countries with our firewall, we have an enterprise grade firewall that can block stuff from Russia, block stuff from the known perpetrators. [9:02]


    • So, I just wanted to point that out. And I wanted to publicly thank you, for taking this seriously and digging in and protecting, not only our network and our business but the work you do behind the scenes for our clients. So that, people can rest at night knowing that this has been taken care of" (11:00) 



    [12:04] - DDoS: Stands for Distributed Denial-of-Services

    • DDoS: When you have a large collection of computers (very large – that’s what makes it a DDoS vs just a DoS) a large number of computers that just try to ask your server or network questions – they just ask billion and billions of questions until your computer can not handle any more. There are vulnerabilities when something is at MAX capacities. 
    • Botnet Attack: a large collection of computers that are trying to just, you know, bug us. And trying to slam our systems. 


    [14:30] – Vulnerabilities in your networks: 

    • Turns out there WAS a vulnerability – call a “zero-day patch” – meaning it’s exploitable today, it’s known, and it’s out in the wild in production. This very well could be going on with Office 365. Any of your normal day-to-day applications. 
    • "Any of your normal day-to-day applications. They could just throw a new update out on the web, expecting you to look at it. But, if you don’t and have no idea about it then you now become the most vulnerable target in the world just because of that. " (16:30)
    • You can definitely imagine that a freeware version – maybe Google Chrome, Firefox, any of those kinds of things. Keep your eyes open! 

    [17:00] – The point is: We are an IT / Security Company. This is what we do night and day.  And STILL here we are, victims of at least an ATTEMPTED attack.  Did they get through, steal any information, did they breach our network? NO… WHY? Because Joe is a badass.  



    [17:27] – Why you should invest in IT services:

    Justin: I’m just going to make this point really quick. I know technology to some extent, I own the company, I started off as a technician, I’ve got the background. I still don’t do my own IT work because I don’t have time. 

    • I cannot put the time, energy and focus into doing what you do Joe, because of all the distractions I have.
    • When I’m out talking to business owners who tell me they do their own IT… Guys THAT is stupid. 
    • (17:50) - "You do not have the time, the ability, the experience, the day-to-day, in the trenches, knowledge. To be able to do this on your own. You just don’t!


    [18:05] – Example of an Attorney and why you CAN'T mess around when it comes to Security. The guy is $400/hr is his billing rate and he does his own IT work. That’s stupid. I’m sorry, that’s just flat stupid. 

    • (18:05) "What’s smart: hire us, hire somebody (like Joe!) who is always in the trenches, sleeves rolled up, preventing this kind of attack. 
    • This could’ve been bad had it gotten through. It could’ve been life ending for the business if it weren't for Joe.
    When you’re invested in good IT security, you shouldn’t even know it’s there. It runs in the background like a quiet but powerful electric motor. It’s there when you need it, and it’s there when you’re not even thinking about it. 

     

    [18:55] - We wanted to talk about this mad rush to work from home and the additional security challenges that were introduced to it. 


    [19:30] –Today  we’re leaning on an article that we read that supports this theory that is was not really the best move to push everybody to the work from home environment so quickly even though there wasn’t much of an option. But there was a company that did this and they were hit.. Financial management company 


    COVID hits, like everybody, there’s this massive rush to tell everybody to take your work home with you. 


    (21:05) – What happened to this comp...

    32 min
  • 4. Your Bank is NOT Your Friend

    Stupid...or Just Irresponsible? | Episode 4: The Bank is NOT Your Friend



    Subscribe to Stupid or Irresponsible Podcast
    Spotify  | Apple Podcasts | Google Podcasts

    Resources
    Security Webinar -  Stay ahead of the game! Sign up for our Security Webinar today. We give you FREE tools, FREE training, and we WILL hold your hand throughout the process. BUT when you don’t take our help or our advice that is stupid.

    Schedule Your Discovery Call - If you know you've got a problem take us up on this offer! Book a 10 minute call with myself (Justin Shelley) and we’ll go over what we can do to help, get you started on a path to have a solid plan in place, constantly reviewing that plan, and just making sure you are doing the right things to minimize ALL the risk we possibly can.
     

    Show Notes

     

    [1:50] – Justin shares what started his love affair with technology and how he is shocked to be spending most his time fighting crime...

    • Justin’s love affair with Technology began at the rightful age of 12 with the Apple 2E 


    [2:26] - “I got into computers at the rightful age of 12 but did not see myself fighting crime…”

    [2:36] - But here we are… Master Computing is an IT company we really pride ourselves of fast response, on processes, on client education, but man we spend most our time fighting crime! Who knew!?

    [2:59] The title of this podcast Stupid or irresponsible 

    • Title Background -  We send out the this letter called the “Stupid or Irresponsible” letter and people got offended or squeamish about calling someone Stupid.. So, they would play it down to sound less harsh. But the fact is, not taking basic security measures and educating yourselves, employees, then you are stupid. 


    [3:50] - Justin came to this conclusion when making this title - If you don’t care enough about your business to care about your business to protect it from cyber crime, I can’t care about your business more than you do. SO, take the advice, take the tools we’re giving YOU, or don’t but if you don’t and you get hit... sorry YOU’RE STUPID. 


    [4:08] – Today we are going to talk about a BEC Attack that cost a very intelligent very established businessman $400,000 that he DID NOT RECOVER.

    [4:20] – What's a BEC Attack?

    • BEC Attack – Business email compromise attack:
      • It’s when someone has access to or is faking that they have access to your email account.

    What does it mean? What can it do? 

    You are going to want to Keep listening!

    • A BEC attack begins with cyber criminals hacking and spoofing to gain access to your email. 
    • If they have access to your email or at least the end user they’re talking to (which could be your bank or any financial institution you name it) … If they think they’re talking to you and your email account, the hacker, now they’ve got your world. 


    “So, if you want my bank account and you aren’t me but happen to have my email then you pretty much have it all.” 

    [5:47] - So that’s what a BEC, a scam is – it’s when somebody (aka a hacker) gets access to your email by impersonating you or someone in your business.


    What is “Spoofing”?         

    [5:57] - If somebody can PRETEND to have your email address, we call that “spoofing”

    [6:09] – Unless you have security set up it’ll look exactly like it’s coming from you 

    [6:17] – We’re talking about scary stuff “we can’t really get through life believing every little bad thing is going to happen to us.” 

    [6:30] – one of the human defense mechanisms is to believe that bad things cannot happen to us… Today, in this podcast, we are here talking about things that HAVE happened. 

    Listen as we shine light on the importance of this growing threat.

    [8:00] - Above was talking about Spoofing 

    • A “spoofed email” would set off alerts, but if you logged into my email account it’s NOT triggering those alerts – THIS is what we really must be careful of. 
    • We have all kinds of protections we can put against spoofing but sounds like we’ve got to work on our email... 


    [8:16] What Joe recommends to anyone, especially people who have any kind of personal Yahoo or Gmail account: Setting up one or both of these two things:

    1. MFA 
    2. 2FA

    The most basic of those would be Multi Factor Authentication (MFA). You might also see 2FA out there. Recommendations from Joe: 

    •  I would highly recommend anybody, if you have any kind of Yahoo, Gmail, personal account, you name it!
    • I would 100% set up MFA – It will save you so much time, headache and effort. 

    [8:35] – So let’s get into the nuts and bolts of this one - we are going to talk about a guy named Verne Harnish

    STORY

    [9:04] – Verne Harnish got hit. But he is not stupid, he had protections in place.

    He was in a foreign country, doing a big presentation to 3,000+ CEO's, executives, entrepreneurs. In this article Verne says he used a “public network” and in that process somebody was able to sniff out his emails and now is when the attack begins. 

    1st – they hack his email, then they start impersonating him 

    Note: They are not spoofing him. They are actually INSIDE his email account. They are him. 

    Inside his email account watching messages being sent between Verne and his admin (communicating about wiring money...)

    They sit and learn this stuff until they are able to very accurately impersonate him THEN they make the attack. Wiring money to 3-4 different places. By the time Verne (or anyone) figures it out, it’s game over… the money is GONE.

    [12:15] – Joe, let’s talk about what Verne did RIGHT what he did WRONG

    • Rule #1: Just don’t get on public WiFi. 
      • We highly suggest that if you do get on public WiFi you’ve got a proxy VPN, or a VPN set up. 
      • Why? If you don’t have that, any hacker is reading words verbatim off your computer. 


    So Joe, "DO or DO NOT use Starbucks WiFi? 

    • NO do not… 
    • Safe alternative like the VPN set up is to 100% use your mobile hotspot if you need WiFi.  

    So what could Verne have done as extra security to possibly prevent this?
     

    [15:00] – What could they have done to possibly prevent this? 
    The BEST thing they could have done: 

    • In this case one KEY component that was missing is – 
      • Don’t ever allow money to be authorized over email. 
      • Or at least not over the initial form of communication. 
    • Example:
      • If email is where it initiated, get another form of communication in there (like a direc...
    33 min
  • 3. Painted Into a Corner

    Show Notes:


    In Episode 3 of Stupid or just Irresponsible Justin Shelley, CEO of Master Computing, and Joe Melot, CTO of Master Computing discuss the stupid things we see out in the wild. Last week we talked about slow computers. Today we play and expand on that and talk about outdated software. When is software out of date? In this episode we put a timeline on software.

    Subscribe to Stupid or Irresponsible Podcast
    Spotify  | Apple Podcasts | Google Podcasts

     

    [4:35] – Using out of date software 

    • Additional problems introduced when you use old software
    • As far as hacking is concerned, software is the Name of The Game!
    • Hardware, hard to break into without having to deal with the software behind it
    • Software side has to be CONTINUALLY updated because with every update to this thing and that thing can cause security vulnerabilities to any given software at any given time 
    • The name of the game for hackers is to figure a way to get into software, to get into computer to steal your stuff

    [5:35] - Look at Microsoft office (this is what we are going to dig into today) – when do you have to replace it? The end of life?

     

    [5:50] - Oldest version of supported Microsoft office today:

    • End of life Office 2010 is October this year (2020) 
    • So “technically” it is still ok today…
    • But if you are running windows 7 you are so much more likely to get hit with a virus than windows 10

     

    [6:45] - When should people update their software?

    • Joe always advises to upgrade “on your own terms”, last thing anyone wants is to be smashed into a corner
    • Doesn’t make sense financially, everything is always going to break, so many roadblocks
    • Financially, it costs SO much more to wait until last minute
    • Don’t wait until you’re painted into a corner… 
    • Want it to be on your terms, so you can prepare, and when those roadblocks come up you have wiggle room, and probably end up saving you some money. 
    • Have a plan, get some solid advice!

     

    [9:00] - QBR – (Quarterly Business Reviews)

    • Once a quarter we go and talk to the person who makes business decisions
    • Discuss future of your company looking like
    • Do we Expect any grand expansions?
    • I noticed your phone system is going out of date, maybe last year I would’ve come to you saying we need to upgrade office 10 

     

    [10:04] - Budgeting is #1 want to be able to spread that money out, it always costs less, it definitely costs less to do it right once, then do it wrong 2 or 3 times… 

     

    [11:43] – Email migrations: Story from a fellow IT guy

    • This company has been neglected for 10 years
    • Still running exchange 2010 and Office 2010…
    • Exchange is the actual office mail server itself (done back in January, no longer supported by Microsoft)
    • Stupid – using exchange 2010
    • Irresponsible – using office 2010 

     

    [13:15] – Still Using Exchange 2010 

    • Can we migrate exchange server from 2010 to the current version exchange server directly? The answer is NO.
    • Have to have a 3rd party
    • Download all emails to hard drive
    • Convert to other form
    • Upload those into the cloud
    • There is not a direct migration path from 2010 to a newer server 

    This is perfect example of this costs way more ignore versus just to do it up front and do it right. 

     
    “Server 2003 still existed in this company… Windows 95...” That is just stupid. 

     

    [17:00] - Ransomware, bank fraud, now they have your exchange system, they are faking your emails to any and all of your contacts..

     

    [17:30] - Paying an IT guy and he is promising the world, but how do you know he is giving sound advice, as far as strategy is concerned? 

    [18:15] - Schedule your online meeting today!
    Go to www.master-computing.com/discovery to book your 10-minute discovery call. We'll ask some key questions, you can ask questions, and if we're a match made in heaven we'll build you a custom technology roadmap. Don't wait until you're painted into a corner, take charge of all things technical within your organization.

     

    20 min

About Stupid... or Just Irresponsible?

From the publisher's feed

People do the dumbest things! (Myself included) And then get so upset when it blows up in their face. We're here to break down the stupid, the irresponsible, the reckless, and the absurd where…