Posts

I hate this word

Image
Have you ever heard of the word Forensicator?   I hate this word.   I am not on trend by hating this word. It continues to gain popularity, and I’m seeing it more and more. Speakers and attendees introduce themselves as Forensicators at training and conferences I attend. I should be using this word, but I just can’t.   So what’s a Forensicator anyway?   It’s someone who works in computer forensics and digital investigations, so what I used to do in the FBI. Back in my day, my formal job title was Information Technology Specialist – Forensic Examiner. I’m glad I didn’t have the job title Forensicator. Heck, this word is so popular that SANS even has a Lethal Forensicator Challenge Coin. But, I’m still not going to use it.   I can’t use this word. It makes me cringe. It also makes me think of other words that I don’t like either. So I’m just not going to use this word.   What word makes you cringe? Drop a comment below and let me know....

5 hot topics to include in your cybersecurity awareness program

Image
You've heard me say this before, and I'm saying it again… your cybersecurity awareness program needs to be built with purpose. When you build your program with purpose, your program will be different from mine, Bill's, and Sally's. BUT… There are some topics that every cybersecurity awareness program needs to address, and I've got 5 HOT TOPICS YOU NEED TO INCLUDE IN YOUR PROGRAM Building a culture of cybersecurity – it's YOUR responsibility Cybersecurity isn't just my responsibility. It' isn't everyone else's responsibility. It's YOUR responsibility. Each person in your business makes a difference, and everyone needs to be invested in creating and maintaining a secure environment, and it starts with culture. Humans are the key to defending your business Tell your humans that they matter to you and why they matter. Social engineering Tell your humans what social engineering is, why it's being used, and how it's being used against them ...

Why can't you resist clicking?

Image
If you’ve been following me for a while you’ve heard about phishing, but have you ever wondered how the email was crafted? Perhaps you’ve been duped before and didn’t realize it until it was too late, because it felt like a Jedi mind trick.   I think we do a really good job of telling everyone to watch out for phishing emails, and not to click on them. But I think as an industry we fall short when it comes to sharing how those emails are crafted, why they’re so dang irresistible, and what they can do to reduce their risk of receiving those super slick emails.   To close this knowledge gap I now offer an on-demand video training class called “ Social Engineering: The Art of the Click”   During this video training, you’ll learn • What social engineering is • How cybercriminals create an irresistible offer  • Why you want to click • How cybercriminals come after you AND • What you can do today to stop cybercriminals from preying on you   ...

Keep cybersecurity awareness simple

Image
Cybersecurity might be complicated, but does your cybersecurity awareness program have to be complicated as well? Nope, you can keep your cybersecurity awareness program simple. Here's an example. Widgets R Us finally created an option for employees to share files securely outside the organization. The employees are excited, but here's what they find: They have to log in with yet another username and password The website is difficult to remember, and there are no links to it on the Intranet Once logged in, they have to follow a 20 step process to upload and share the file They can only share one file at a time, so they must repeat the 20 step process for each file They can only share with one person at a time, so the 20 step process must be repeated for each person that needs to send to file Do you think your employees will complete 180 steps to send three files to 3 people?? This is what I mean by keeping it simple. Sometimes those of us who work in tech are shooting ourselves...

Here’s to cheating, stealing, fighting, and drinking

Image
 I'd like to share this Irish toast with you in honor of St. Patrick's Day. Here’s to cheating, stealing, fighting, and drinking. If you cheat, may you cheat death. If you steal, may you steal a woman’s heart. If you fight, may you fight for a brother. And if you drink, may you drink with me What are your St. Patrick's day plans? Comment below - I need ideas!

Secure the humans

Image
 Did you know I'm here to help you secure the humans in your business?   What does it mean to secure the humans? It's more than a catchy way of saying I do cybersecurity awareness training. To secure your humans, you need to give people the knowledge, training, and tools necessary to stay safe in a digital world. It's building habits that are substantial and lasting, not fleeting.   Why should we secure the humans? Humans are the last line of defense. Old school thinking was humans are our greatest weakness when it comes to cybersecurity. Today, humans are your best bet at preventing a cyber attack.   Why are humans so important? Technology is getting better all the time, so why should you focus on your humans? Because all the technology is getting better at preventing attacks, hackers are looking for ways to get around it. The easiest way to get around that technology is to go after people and have them do the attacker's evil bidding.   Ho...

will the real slim shady please stand up?

Image
Let’s talk about phishing emails and impersonation. Hackers often use impersonation to get you to open their phishy emails. If the email is from someone you know you’re more likely to open it. For many years, Microsoft was the most impersonated company in phishing emails. It makes sense, I mean, what big business doesn’t use Microsoft? But there’s a new winner, and it’s DHL. In Q4 of 2021, DHL was the most impersonated company in phishing emails, thus dethroning Microsoft? Why the spike? Bad guys follow the money. Q4 means shopping, and with spikes in online shopping again last year, it only made sense that even more cherished Christmas presented would be shipped. How does it work? The attacker used a from name of ‘DHL Customer Support’ The Subject contains ‘DHL Shipment Confirmation…’ It works, because who doesn’t want to know where their package is?! Beware, DHL wasn’t the only shipping server that’s impersonated. FedEx entered the top 10 list as well. How can your cybersecurity awar...