Posts

Showing posts with the label Data Protection

Are you ready for data privacy week?

Image
Data Privacy week is January 24 – 28, 2022. What are you doing to increase data privacy awareness in your business? What about at home? If privacy isn’t one of the topics you include in your current cybersecurity awareness program, this is a great reminder to get it added. What’s the point? Privacy is more than an abstract idea that businesses need to worry about; it’s something you as an individual need to be concerned with too. As this week approaches, I want you to think about: Trading privacy for convenience. We ALL do this. That free app, you're trading your data and privacy for the convenience of getting to use that app for free. When an app asks for permission to access some additional info on your phone, do you read what it’s asking for? Or do you simply click yes and move on? You could give away too much information. If that app is asking for too much access, it’s probably best to uninstall that app and save yourself some grief later on. Learn how to manage your privacy. M...

Has cybersecurity awareness left the building?

Image
October has come and gone. Daylight savings has come and gone. Has your cybersecurity awareness program come and gone? In October we do a great job of spreading the word on the importance of cybersecurity, thinking before you click, and watching out for suspicious websites. But sometimes, cybersecurity awareness disappears just as fast as it appeared for one month of the year. Your cybersecurity awareness program shouldn’t last just one month a year. Your cybersecurity awareness program should be a living thing that’s visible and accessible all year long. Wouldn’t be it great if you could build cybersecurity awareness into your company culture just like safety and no meeting Fridays? What if I told you I could help you do just that? 3 WAYS I CAN HELP IMPROVE YOUR CYBERSECURITY AWARENESS PROGRAM TRAINING AND EDUCATION: Are you tired of watching the same training videos every year? Would you like to have someone break down a recent incident and use it as a teaching opportunity? Or perhap...

Cybersecurity First

Image
The theme for Week 2 of Cybersecurity Awareness Month is Cybersecurity First. We are more connected than ever. The hybrid workplace is here to stay, and for employees, this means relying on connected devices from their home office. Smart home systems will rise to a market value of $157 billion by 2023, and we expect the number of installed connected devices in the home to rise by a staggering 70% by 2025. TIPS FOR SECURING ALL THOSE DEVICES. Remember smart devices need smart security Make cybersecurity a priority when purchasing a connected device. When setting up a new devices and accounts, be sure to set up the privacy and security settings to limit the sharing of information. Default settings often aren’t secure. Once your device is set up, remember to keep tabs on how secure your information is and actively manage location services so you don’t share your location by mistake. Put cybersecurity first in your job Make cybersecurity a priority in your job. Good cyber hygiene shoul...

Fight the Phish

Image
The theme for Week 2 of Cybersecurity Awareness Month is Fight the Phish From the Colonial Pipeline to T-Mobile, cybersecurity attacks have been rampant over the last 12-24 months. However, for all the emerging threats and news that are cropping up, phishing continues to quietly wreak havoc, and remains a major threat to individuals and businesses. Don’t overlook phishing as a cyber risk. It’s been a major threat for decades. In fact, 43 percent of cyberattacks in 2020 featured phishing or pre-texting, while 74 percent of US organizations experienced a successful phishing attack last year alone. Phishing is one of the most dangerous and effective attacks methods used against your organization. As a result, you need to know how to fight the phish. 3 TIPS TO HELP YOU FIGHT THAT PHISH AND WIN Know the Red Flags Phishes are masters of making their content and interactions appealing. From content design to language, it's difficult to determine whether the content is genuine or a po...

Are you ready for cybersecurity awareness month?

Image
Cybersecurity Awareness Month begins tomorrow! Are you ready?  This year’s theme is  “Do Your Part. #BeCyberSmart.”. Here’s a rundown of this year’s  weekly themes  that will help you learn how to protect yourself and your business from cyberattacks through actionable steps. Review the schedule below. Oct 4 - 10: Be Cyber Smart Oct 11 - 17: Fight the Phish Oct 18 - 24: Explore. Experience. Share. (Cybersecurity Careers) Oct 25 - 31: Cybersecurity First You can also catch me speaking live at the  Nebraska Cybersecurity Conference  on October 19. The conference is virtual, and there’s still time to register. So no matter where you’re sitting, you’ll have a great seat. In honor of Cybersecurity Awareness month, I’m switching up my email and blog schedule. During October, I’m going to kick off your week by sending you an email every Monday morning all about the week’s cybersecurity awareness theme. Not on my email list? Join now . Also, you'll want to follow me...

Don't get tricked by the word new

Image
Let’s talk about phishing emails and the techniques used by cyber criminals to get you to click. Today, I’m going to focus on the subject line.   The subject line is super important, and that’s why the bad guys are using it against you. Why is the subject line so important? The subject line is the first and only hint at what the email is about. If you can’t reel ‘em in with the subject line they might never open your email. In fact, the subject line is so important that marketers test different subject lines against each other to see which one will get the most opens.   Cyber criminals try to invoke a sense of urgency and emotions to get you to click. That’s why words like ‘URGENT’ and ‘IMPORTANT’ have appeared in their subject lines for years. But now, there’s a new word in the subject line, and that new word is ‘NEW.’   THE NEW WORD IS NEW.   WHY IS ‘NEW’ SUCH A POWERFUL WORD IN PHISHING EMAILS? Legit emails and alerts contain the word ‘new’ The...

You don't have to memorize all the passwords

Image
  Here’s a tip to help your business stop thinking of cybersecurity as the Department of No.   Help make their life easier!   HOW CAN YOU MAKE EVERYONE’S LIFE EASIER IN THE OFFICE? Give them a password keeper AND teach them how to use it.   HOW PASSWORD KEEPERS MAKE LIFE EASIER No more trying to memorize all the passwords you have No more forgotten passwords No more time wasted resetting passwords No more wasting time trying to think of unique passwords Put an end to tracking your passwords in Excel, post-it notes, and notebooks.   WHY CYBERSECURITY PROS RECOMMEND PASSWORDKEEPERS Passwords stored securely Unique passwords for every account Stronger passwords Secure sharing of passwords Reduce the risk of the business being locked out of an essential app   Help your employees save time and end their frustration by trying to memorize hundreds of passwords. Get them started with a password keeper t...

Cybersecurity Awareness Month is coming

Image
Suddenly summer is over and pumpkin spice everything is out in full force, and that can only mean one thing…   Cybersecurity Awareness Month is coming.   That’s right, October 1 marks the start of Cybersecurity Awareness Month 2021!! Who else is excited?! This year’s theme is Do Your Part. #BeCyberSmart.  This year’s theme brings four new weekly themes, and provides you with some great opportunities to build relationships in your business.   As you’re churning out lots of awesome content and tips for Cybersecurity Awareness Month, I want to share some tips to keep in mind when your creative juices are flowing.   5 TIPS FOR WRITING CYBERSECURITY AWARENESS INFO Speak the language of business Keep it short and sweet Make your content mobile friendly Avoid technical jargon Don’t get lost in the weeds   Finally, if you need a guest speaker for Cybersecurity Awareness Month or need help planning I still have a few openings availab...

How to stop saying no

Image
  Have you ever tried to find any information on ‘how to stop saying no?’ There’s not a lot out there. Most of the information out there is about the exact opposite problem – 'how to stop saying yes to everything.'   Cybersecurity departments often have a ‘No’ problem. Why? In my experience, we’re a suspicious and risk adverse group. Our knee jerk reaction is always to answer ‘No’. Always saying no creates adversity. When faced with constant adversity, people can suffer from tunnel vision, toxic stress, and rash decisions.   HOW DO WE STOP SAYING NO?   LISTEN TWICE AS MUCH AS YOU TALK People want to be heard People want to be understood People need to know that they're heard and understood When it’s time to talk, summarize what you’re hearing Ask open-ended questions to identify their pain Discover their why Why do they need it? What is the impact if approved? What is the impact if denied?   RELATE TO THE STAKEHOLDERS Don’t fake it Feel their pain Empathy is a p...

Death to the Department of No

Image
Have you heard of the Department of No ? Depending on where you’ve worked, your company probably had a Department of No. What is the Department of No? It’s the Cybersecurity Department. When cybersecurity says ‘NO’ to anything and everything the business wants, they quickly get a reputation, and become known as the Department of No. The business wants to do things faster and easier. Cybersecurity wants to eliminate risk and be secure. Often these two agendas go head-to-head, and it ends with frustration. What’s the risk of always saying no? People stop asking Cybersecurity loses the opportunity to help the business reduce risk A culture of ‘us’ versus ‘them’ builds What’s that saying?  Where there’s a will, there’s a way . Truer words have never been spoken when it comes to the Department of No and employees. I saw it all the time when I worked in Data Loss Prevention at GE. Employees need to get their work done, interact with customers, and collaborate with vendors. If there’s not...

The FlyTrap that Caught your Facebook Account

Image
When I say ‘FlyTrap’ what comes to mind? A venus fly trap? ‘The Little Shop of Horrors’? A bug zapper? A strip of sticky tape with a bunch of flies stuck to it? Malware?   I hope you were thinking about malware because there’s some FlyTrap malware taking over Facebook Accounts, and it's been around since March.   How are they doing it? Social Engineering .   The bad guys have placed malicious apps in Google Play and other Android stores to lure you in with offers for free Netflix coupon codes and voting for your favorite soccer player or team. These apps look legit. They are high quality, use great graphics, and are free from grammar and spelling errors.   To get the code or to vote, you have to log in with your Facebook username and password. You are actually using Facebook to login, but unknown to the victim, there is something nefarious going on in the background, and it’s stealing their sensitive info.   WHAT TO DO IF THIS HAS ...

Why phishing emails are bad for business

Image
Have you heard about the UC San Diego Health data breach?   It started with a phishing attack back in December, and now the personal info of patients, students, and employees could be in the hands of cybercriminals. The victims could face identity theft at any time.   A CLASSIC EXAMPLE OF AN EMPLOYEE DOING THE EVIL BIDDING OF THE BAD GUY. Employee(s) took action as directed in the phishing email. Those actions gave the hackers access to employee email accounts. The hackers could access everything in the employee email accounts.   WHY IT’S BAD FOR BUSINESS The hackers can access any password reset links that arrive via email. The hackers can access any multi factor authentication codes that arrive via email. The hackers can send emails directly from your email account and message your contacts requesting information or even changing payment instructions.   WHAT YOU NEED TO KNOW Sometimes maliciou...

Are the bad guys winning?

Image
  What do you think? Are the bad guys winning?   If you’ve been watching the news lately you might think, yes, the bad guys are prevailing over cybersecurity. In under a week over 1,500 businesses got hit with Ransomware thanks to a vulnerability in Kaseya VSA and the cyber gang REvil. Then there’s another cyber gang launching Trojan attacks against the Indian Military.   Sounds bad, right?   Let’s talk about some victories for the good guys . They arrested the suspected hacker Dr HeX for many cyber crimes, including financial fraud that affected thousands. Microsoft finally issues a patch to put an end to the PrintNightMare bug.   Don’t let the news overwhelm you . Businesses of any size can implement a successful cybersecurity strategy that can reduce your risk of cyber attack by 80%. But how...   FIVE TIPS TO PROTECT YOUR BUSINESS Beware of phishing emails Stop and think before you click Protect your accounts Secure your devices ...