Posts

Showing posts with the label Cybersecurity

They Say Change is for the Better

Image
Since you’ve read my blogs for a while, you know my passion for cybersecurity and the services I offer.   But did you know that I also offer digital forensics services? In the past, it’s been a tiny portion of my business in the past, and I didn’t speak about it much or even market it. That’s all changing this year.   Last year, I returned from maternity leave and immediately dove into working on a substantial digital forensics case. The case was infamous. The problem was daunting. The work was definitely interesting.   Working on this case reminded me how much I enjoyed forensics and how much I missed it. Digging for information. The hunt for the smoking gun. The quest for truth.   Why am I telling you all this? I want to let you know that I’m expanding the portion of my business that focuses on digital forensics. This also means that I am limiting my cybersecurity services. Here’s a rundown of my current service offerings:   Digital Forensi...

How important is your cybersecurity culture?

Image
 Do you have a culture of cybersecurity in your business? When you send out a simulated phishing email, is there a buzz in your office? Are people competing against each other, trying to get the perfect score, and never clicking? Or are they rolling their eyes and complaining about having to take more cybersecurity training?   Did you know that humans are the most significant attack surface in your business? The bad guys are coming for your humans, too, not just your tech. Because your humans have a big target on their backs, you need to build a culture of cybersecurity within your business where everyone understands the vital role they play in staying safe from cyber attacks. Getting all of your humans engaged in cybersecurity is so important NIST even released a guidebook called "Cybersecurity is Everyone's Job."   The guidebook is worth a look. It breaks business functions into seven categories and addresses how each person can do their part to secure the busin...

What's your 2022 cyber resolution?

Image
Here are 5 Cybersecurity Resolutions that you can put to use in 2022 at work AND at home.   1.       Fight Phish Keep your eyes peeled for phishing emails. That means checking the sender’s email address (not just the from name), hovering over links, and not falling for tricks that demand urgency.   1.       Enable Multi Factor Authentication (MFA) This adds a second layer of security to your accounts. Even if the fraudster has your password, he can’t access your account because he doesn’t have your code. Get MFA codes via an app, text, or email. Turn it on everywhere!    3.       Use a unique password on every site (hint: use a password keeper) Unique passwords are awesome. If a bad guy gets your password for one account, he can only access that one account. Now, if you were still using one password everywhere, he could get into all your accounts AND you have to change the passwo...

Black Friday and Cyber Monday Secure Shopping Tips

Image
Have you seen the Black Friday and Cyber Monday ads that started Nov 1 st ? The black Friday shopping that started Nov 4 th ? Clearly, businesses want you to spend your money shopping with them. And that means cyber criminals are just a few steps behind, and ready to snag your cash instead. In order to help you keep your money safe and receive the gifts you want this holiday season, I’m sharing… 10 TIPS FOR A SAFE AND SECURE HOLIDAY SHOPPING SEASON 1.  Turn on MULTI-FACTOR AUTHENTICATION Add that extra layer of security to all of your accounts by adding an extra step to your login-procedure. This is a code you enter after you submit your username and password. The code can arrive via an app (such as Google Authenticator), text, or email. It may also called to as dual-factor or two-factor and is abbreviated as MFA or 2FA. Enable it everywhere possible -especially on password keepers, email, and financial accounts. 2.  Avoid FREE WIFI That FREE WiFi you're using might ...

Has cybersecurity awareness left the building?

Image
October has come and gone. Daylight savings has come and gone. Has your cybersecurity awareness program come and gone? In October we do a great job of spreading the word on the importance of cybersecurity, thinking before you click, and watching out for suspicious websites. But sometimes, cybersecurity awareness disappears just as fast as it appeared for one month of the year. Your cybersecurity awareness program shouldn’t last just one month a year. Your cybersecurity awareness program should be a living thing that’s visible and accessible all year long. Wouldn’t be it great if you could build cybersecurity awareness into your company culture just like safety and no meeting Fridays? What if I told you I could help you do just that? 3 WAYS I CAN HELP IMPROVE YOUR CYBERSECURITY AWARENESS PROGRAM TRAINING AND EDUCATION: Are you tired of watching the same training videos every year? Would you like to have someone break down a recent incident and use it as a teaching opportunity? Or perhap...

Are you a bad phisher or a good phisher?

Image
Phishing emails, they’re a big deal. That’s probably because ~91% of data breaches start with a phishing email. In response to the sheer volume of phishing emails out there, many companies include sending simulated phishing emails to their employees as part of their cybersecurity awareness program. The frequency, content, and punishment for failure can run the gambit. A few bad phishers have made headlines, and now the question ‘to phish or not to phish’ your employees is a hot topic. What did they do? They sent simulated phishing emails to their employees promising big bonuses (up to $10,000) as a thank you for all their hard work during COVID. They said their company had been receiving similar phishing emails IRL, and it made sense to simulate these types of emails. The worst phisher of all didn’t even tell employees for TWO DAYS that they failed the test. Many of those employees spent their ‘bonus money’ during those two days. What happened next? The employees got pissed. The employ...

Cybersecurity First

Image
The theme for Week 2 of Cybersecurity Awareness Month is Cybersecurity First. We are more connected than ever. The hybrid workplace is here to stay, and for employees, this means relying on connected devices from their home office. Smart home systems will rise to a market value of $157 billion by 2023, and we expect the number of installed connected devices in the home to rise by a staggering 70% by 2025. TIPS FOR SECURING ALL THOSE DEVICES. Remember smart devices need smart security Make cybersecurity a priority when purchasing a connected device. When setting up a new devices and accounts, be sure to set up the privacy and security settings to limit the sharing of information. Default settings often aren’t secure. Once your device is set up, remember to keep tabs on how secure your information is and actively manage location services so you don’t share your location by mistake. Put cybersecurity first in your job Make cybersecurity a priority in your job. Good cyber hygiene shoul...

Cybersecurity Careers

Image
The theme for Week 2 of Cybersecurity Awareness Month is Explore. Experience. Share. (Cybersecurity Careers) Cybersecurity is one of the hottest sectors today, with new threats and challenges emerging daily. There is a huge push in the business and education sectors to attract individuals to a cybersecurity career. Are you or someone you know interested in joining this exciting workforce? Here are a few reasons to pursuing a career in cyber. Hot Job Market To say that the cybersecurity jobs market is hot is a vast understatement. According to the U.S. Bureau of Labor Statistics, the job market for information security analysts will grow by 32 percent by 2028 -- making it one of the fastest growing job sectors -- there will be 3.5 million unfilled cybersecurity jobs in 2021. This means that cybersecurity professionals are among the most in-demand around the world and will be for years to come. Infinite Room for Personal and Professional Growth Beyond the ability to get a cybersecurity j...

Fight the Phish

Image
The theme for Week 2 of Cybersecurity Awareness Month is Fight the Phish From the Colonial Pipeline to T-Mobile, cybersecurity attacks have been rampant over the last 12-24 months. However, for all the emerging threats and news that are cropping up, phishing continues to quietly wreak havoc, and remains a major threat to individuals and businesses. Don’t overlook phishing as a cyber risk. It’s been a major threat for decades. In fact, 43 percent of cyberattacks in 2020 featured phishing or pre-texting, while 74 percent of US organizations experienced a successful phishing attack last year alone. Phishing is one of the most dangerous and effective attacks methods used against your organization. As a result, you need to know how to fight the phish. 3 TIPS TO HELP YOU FIGHT THAT PHISH AND WIN Know the Red Flags Phishes are masters of making their content and interactions appealing. From content design to language, it's difficult to determine whether the content is genuine or a po...

Be Cyber Smart

Image
The theme for Week 1 of Cybersecurity Awareness Month is Be Cyber Smart. Being cyber smart means getting familiar with cyber basics. When we are more connected than ever, being “cyber smart” is super important. This year we’ve already seen the number of attacks and breaches skyrocket, including the SolarWinds and Kaseya breaches and high-profile attacks on the Colonial Pipeline and critical infrastructure. What do these recent breaches teach us? Cyberattacks are becoming more evolved and sophisticated with new cybercriminals popping up daily. Luckily, there are several steps that everyone can take to reduce their risk and stay one step ahead of the bad guys. Here’s a few quick tips to get you started. Enable MFA Multi-factor authentication (MFA) adds a necessary second check to verify your identity when logging into your account. By requiring multiple methods of authentication, your account is further protected even if the bad guy knows your password. You can use MFA by enteri...

Are you ready for cybersecurity awareness month?

Image
Cybersecurity Awareness Month begins tomorrow! Are you ready?  This year’s theme is  “Do Your Part. #BeCyberSmart.”. Here’s a rundown of this year’s  weekly themes  that will help you learn how to protect yourself and your business from cyberattacks through actionable steps. Review the schedule below. Oct 4 - 10: Be Cyber Smart Oct 11 - 17: Fight the Phish Oct 18 - 24: Explore. Experience. Share. (Cybersecurity Careers) Oct 25 - 31: Cybersecurity First You can also catch me speaking live at the  Nebraska Cybersecurity Conference  on October 19. The conference is virtual, and there’s still time to register. So no matter where you’re sitting, you’ll have a great seat. In honor of Cybersecurity Awareness month, I’m switching up my email and blog schedule. During October, I’m going to kick off your week by sending you an email every Monday morning all about the week’s cybersecurity awareness theme. Not on my email list? Join now . Also, you'll want to follow me...

Don't get tricked by the word new

Image
Let’s talk about phishing emails and the techniques used by cyber criminals to get you to click. Today, I’m going to focus on the subject line.   The subject line is super important, and that’s why the bad guys are using it against you. Why is the subject line so important? The subject line is the first and only hint at what the email is about. If you can’t reel ‘em in with the subject line they might never open your email. In fact, the subject line is so important that marketers test different subject lines against each other to see which one will get the most opens.   Cyber criminals try to invoke a sense of urgency and emotions to get you to click. That’s why words like ‘URGENT’ and ‘IMPORTANT’ have appeared in their subject lines for years. But now, there’s a new word in the subject line, and that new word is ‘NEW.’   THE NEW WORD IS NEW.   WHY IS ‘NEW’ SUCH A POWERFUL WORD IN PHISHING EMAILS? Legit emails and alerts contain the word ‘new’ The...

You don't have to memorize all the passwords

Image
  Here’s a tip to help your business stop thinking of cybersecurity as the Department of No.   Help make their life easier!   HOW CAN YOU MAKE EVERYONE’S LIFE EASIER IN THE OFFICE? Give them a password keeper AND teach them how to use it.   HOW PASSWORD KEEPERS MAKE LIFE EASIER No more trying to memorize all the passwords you have No more forgotten passwords No more time wasted resetting passwords No more wasting time trying to think of unique passwords Put an end to tracking your passwords in Excel, post-it notes, and notebooks.   WHY CYBERSECURITY PROS RECOMMEND PASSWORDKEEPERS Passwords stored securely Unique passwords for every account Stronger passwords Secure sharing of passwords Reduce the risk of the business being locked out of an essential app   Help your employees save time and end their frustration by trying to memorize hundreds of passwords. Get them started with a password keeper t...