The Cyber Savvy Cafe: Recent Episodes

The Cyber Savvy Cafe

A visit to the Cyber Savvy Cafe is like a really great coffee break discussing topics relevant to cybersecurity and technology: Business tech, cyber training, remote workstations, IoT, and more. Join us every week.

View Details

Ssn 2 Ep 15 Zero Trust Pt 3

Beyond the basic, foundational things you should already have in place, what’s the next thing you need to do to implement a Zero Trust approach to network security?

1:04: It starts with the regulatory requirements a company must meet, then layer in policies and procedures.

3:07: Every time a user wants to access resources, they are going to need to prove their credentials.

3:16: NIST has developed a standard for Zero Trust, 800-207, which lays out what an enterprise needs to do to meet the zero trust model.

4:58: Access to individual enterprise resources is granted on a per session basis and determined by policies.

5:42: This can be geographically related and can also be determined by the user’s normal behaviors.

7:25: Is AI involved in determining a user’s normal behavioral patterns?

8:07: What specific changes need to be made to the architecture of your network?

10:01: HR Management system, segmented on its own server.

11:38: Is zero trust accessible to most companies?

14:12: What is the first step in getting started with zero trust?

14:48: A managed services provider is a good first step in starting the documentation process, defining policies, pushing it through to the user community.

15:38: Getting the employees’ buy-in is important.

16:57: Begin to expand segmentation out to the workstations.

18:10: What level of importance would you rate this for companies to make this happen?

18:38: If you depend on technology and you have data that you don’t want sold on the dark web, you must take a look at zero trust.

18:48: A good service provider will help you with a logical roll-out plan

20:04: Make sure you think this through first, implement your policies, and then start rolling it out in a logical manner.

Zero Trust Architecture: https://www.nist.gov/publications/zero-trust-architecture

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 14: Zero Trust, Pt 2

Cybercrime is projected to cost the world 10.5 trillion annually by 2025. Hackers are looking for the easiest targets, make sure you’re not one of them. Zero Trust is a layered approach to cybersecurity that structures your network so you can do just that.

Today's episode looks at foundational elements you better already have in place.

Show Notes:

:37: The big business of hacking

1:13: Why and how cybercrime has accelerated since the pandemic

1:42: Some of the reasons home workstations are vulnerable to cyber attacks

2:00: DNS filtering

4:07: The business cost of a cyber breach and some of the recent stats

4:20: Threat actors live on your network for 280 days before they’re identified

4:55: What happens when you’ve been hacked and held for ransom

5:55: EDR—Endpoint Detection Response

7:15: Some indicators of threat actors can have other causes

8:23: Cloud configuration—and how it can pose a risk

Business Cost of Cybercrime

https://cobalt.io/blog/business-cost-of-cybercrime

9:47: Cyber awareness training

11:05: What happens to the stolen data from random individuals on home networks

12:09: What happens to a company’s data

12:30: Encryption

14:25: Backups—a two-fold process for backing up to the cloud

16:07: Zero Trust is a much deeper dive than the foundational things we’ve talked about today.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 12: Zero Trust

Cybercrime is projected to cost the world 10.5 trillion annually by 2025. Hackers are looking for the easiest targets, make sure you’re not one of them. Zero Trust is a way of structuring your network so you can do just that.

Show Notes:

:42: An overview of Zero Trust

1:25: What is Zero Trust Network Architecture?

2:15: Make sure you know who is accessing your data and how and when

2:42: What is the normal way companies have their network structured? A look at flat networks

3:13: Bare minimum—segment your network

3:37: On premise servers vs. the cloud

4:13: Flat network example using email in a cloud environment—how is your data accessed and how easy is it to break in?

5:03: How a malicious actor can move easily around your flat network

6:07: Phishing attacks and other ways threat actors can invade your network, and how an individual might be targeted and attacked

7:15: Entry points: smart devices and other devices that are on your network—that may be infected with malware—and other entry points

8:37: What would a Zero Trust environment look like?

12:55: What happens if you don’t implement this? You’re going to get hacked and held for ransom. It’s not about if but when.

14:00: Is it enough to just segment your network?

14:39: But all this time I’ve never been compromised so what I’ve been doing must be good enough.

15:25: Hacking is big business-- probably reaching the trillions. Hackers are looking for the easiest targets.

https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 12

What's Up With the Chip Shortage?

You’ve undoubtedly encountered the shortage of microchip availability, as this has affected nearly every industry. In today’s episode we’re going to discuss how it happened, how long it’s going to last—and what you can do in the meantime.

Show Notes:

1:30: What caused the shortage?

1:57: Some of the issues that factored into the shortage.

3:06: How employee shortages compounded the shortage and how this snowballed through the supply chain.

3:30: How long is the shortage going to last and when can we expect it to start getting better?

4:35: How to make your phone last for another year.

5:15: Black Friday sales—did not extend to phones this year!

7:10: How to be first in line to purchase the few available devices and products

7:53: Purchased refurbished tech.

9:50: Take care of the items you have and repair rather than replace.

11:30: Best practices for taking care of your computers.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 11: Popular Techy Gadgets for Gift-Giving 2021

A look at some of the most popular tech-related gadgets, perfect for gift-giving.

23 Hottest Cool Gadgets That Are Going to Sell out This December

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 10: Navigating the Holidays, Cyber-Safely

Cyberattacks increase during the holiday season--not just online scams and cyber theft but phishing attacks, as well (watch your inbox!). Awareness is the key to avoid becoming a victim.

View Details

Ssn 2 Ep 9: Guess Who’s Accountable

New regulations coming for cybersecurity providers: accountability, liability—and what that means for you.

Show Notes:

1:15: Discussion of new regulations that are coming for the managed services industry

1:40: What is the difference between MSPs and MSSPs?

3:10: How much trouble can you get into if you’re overselling your services?

4:30: Up until now, this industry has been without regulations

4:58: Service providers currently may not realize they don’t have the skill set required to work in this space

5:45: Other service providers and contractors have to go through continuing education and certification, but this has not been required for the managed services industry

6:48: Self-assessment forms from your cybersecurity insurance broker can help you determine what kind of cyber security measures you need to have in place

9:07: What kind of disclaimer should an MSP/MSSP have in place for clients who are refusing certain services: Signed Denial of Service letter

10:45: The importance for service providers to be aware of changing laws and regulations for their industry—keep breast of services that are no longer optional

12:12: Dept of Justice’s new regulations for MSP/MSSPs

13:46: Businesses may no longer be able to pick and choose what services they need

14:18: When filling out the questionnaires, don’t check “yes” if you’re not doing something

17:35: Special requirements and regulations for public or quasi-public companies

21:31: What’s the easiest way to keep your ear to the ground on changing regulations that will affect your business?

22:42: Current administration is pushing zero trust and Amazon’s offer of free security training

Links:

DOJ Vows to Prosecute Cybersecurity Fraud by MSPs, MSSPs and Government Contractors

https://www.msspalert.com/cybersecurity-markets/americas/doj-vows-to-prosecute-cybersecurity-fraud-by-msps-mssps-and-government-contractors/

Acting Assistant Attorney General Brian M. Boynton Delivers Remarks at the Cybersecurity and Infrastructure Security Agency (CISA) Fourth Annual National Cybersecurity Summit

Washington, DC

Wednesday, October 13, 2021

https://www.justice.gov/opa/speech/acting-assistant-attorney-general-brian-m-boynton-delivers-remarks-cybersecurity-and

Deputy Attorney General Lisa O. Monaco Announces New Civil Cyber-Fraud Initiativehttps://www.justice.gov/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative

Amazon Security Training:

https://aws.amazon.com/security/amazon-security-initiatives/

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 8: Bring Your Own Environment: Working From Anywhere And The Accompanying Security Risks

Show Notes

:30: Top Trends in Technology

1:18: Exciting opportunities for businesses that embrace a work-from-anywhere business model.

1:30: People can leave a larger city and live anywhere they want to

4:55: Bring Your Own Environment: Using a secure client that allows services to be accessed safely by all users

5:30: Blocks phishing attempts

6:05: Zero Trust Environment eliminates your physical space and enables working from anywhere safely

6:35: How can people go about setting up a client or VPN?

8:45: Hackers at the coffee shop can’t get in because you’re on your own separate server

9:04: Can all employees access shared equipment and/or each other’s devices?

11:20: A growing problem with VPN providers—not all are secure.

13:00: Statistics why mobile work environments support business growth

14:08: One challenge with mobile work environments—the loss of “accidental knowledge”

15:50: Coffee pot chatter and building relationships—how to make that happen in a remote work environment

18:42: Other reasons why remote working increases a business’ growth opportunities

19:25: Discussion of companies cutting employees’ salaries if they choose to work from home, and paying based on where you’re working (geographically)

Link: Technology Visions 2021

https://www.accenture.com/us-en/insights/technology/technology-trends-2021?c=acn_us_technologyvisiogoogle_11975584&n=psgs_0221&gclid=CjwKCAjwiY6MBhBqEiwARFSCPgfWPD84sS1hjxcS7HhUU1U8mc9mcaHIjgKlZRfcEHTah7DrxsCbRxoCyC0QAvD_BwE&gclsrc=aw.ds

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 7: Will AI Replace Us?

With the exponential advances in AI technology, we can’t help wondering if one day our jobs will become obsolete. In today’s episode we talk about some of the issues surrounding AI and how to keep relevant in a rapidly changing work environment.

Show Notes

:45: Lighthearted discussion about self-driving cars.

5:25: Will AI replace us?

5:34: Predictions and discussions about AI tech from college professors.

6:50: Throughout time, technology has replaced people and will continue to do so: automation is the trend of the future.

7:24: Benefits of AI to business owners and forecasting for the future.

9:30: The biggest use of AI today is mined from social media, where large amounts of data are required.

10:19: Potential use of AI in the field of medicine and health care.

11:40: Looking at your industry and foreseeing what skills you might need to be developing now so you can remain employable.

12:24: The use of AI in screening job applications and resumes.

13:03: Technology has changed the face of business and we’re competing in a world-wide marketplace.

14:15: SWOT analysis: analyzing internal strengths and weaknesses and external opportunities and threats.

14:29: Paying attention to where your job is headed. Story about a company offering a voluntary severance package prior to layoffs.

16:30: Analyze your skill set; if jobs dried up in your industry, what industry could you transfer into—and diversify your skill set accordingly.

17:57: Brief discussion of the importance of soft skills vs. hard skills

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 6: Don’t Die on Me Now!

You know the signs. The signs that your computer or mobile device is not going to last much longer--but you’re not ready to invest in a replacement. You may be able to get a little more life out of your aging devices and buy yourself some time!

Show Notes

:30: How can we get a little more life out of our devices?

:53: Hard reset: Resetting your phone to factory settings.

1:21: Make sure you run backups of all your important data first.

2:26: Clearing your storage and freeing up space. Make sure you delete the cache for your photo gallery—those files can remain for a week before being permanently deleted.

4:28: Operating systems and software updates are larger and larger and requires more memory and speed from aging hardware.

4:57: SSDs, and rebuilding your hard drive

5:40: Upgrade memory/RAM to 16GB

6:26: Defragmentation

7:17: Upgrading to an SSD and 16GB of RAM could possibly buy you another year.

7:47: Budgeting for new hardware needs to be an ongoing part of your long-term plan.

9:06: CCleaner for keeping the registry clean, clearing the cache, and keeping performance up

10:32: Be aware that if you frequently install and uninstall apps on your mobile device, that can degrade performance over time.

11:40: A rebuild will help clear out excess junk on your devices, quick overview of how to do that.

12:42: Windows Virtual Desktop, and how that can increase performance.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 5: Warning Lights

Signs your computer is having problems—and what those signs might mean

:35: Your computer is suddenly going really slow—what’s up with that?

:50: Drive failure and rebuilding your computer, should performance be comparable to what it was before, with a new drive?

2:30: What happens to your computer when you install and uninstall programs too frequently?

3:16: Microsoft’s feature releases for Windows 10 vs. service packs or patches and the impact on your computer’s performance

4:36: Brief discussion of Windows 11 release and a user’s current TPM (Trusted Platform Module)

5:38: Other reasons why your computer might be going slow due to malware

6:05: Using task manager to figure out where an issue of sluggishness might be coming from

10:12: Case study of a company whose system was running sluggish and discovered a trojan horse style virus

12:03: With upgrades to system software, performance naturally goes down

12:16: How long does the average computer last, in a business setting?

13:25: How does an IT manager make the decision of when to replace computers (preferably before they die)?

13:54: Monitoring the age of your computers and the lifecycle of those machines

15:22: Moving quickly when you begin experiencing degradation of performance

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/ then navigate to the Cyber Savvy Café page

View Details

Ssn 2 Ep 4: Lock it Down

Protecting your data.

View Details

Ssn 2 Ep 3: Recognize This?

The 10 Most Common Passwords—Is Yours on this List?

In today’s episode, we have fun discussing the 10 most common passwords and safe (and unsafe) password practices. We take a look at how cyber-criminals hack unsecure passwords and review best practices for password safety.

Most Common Passwords: 2021 Latest Statistics

https://cybernews.com/best-password-managers/most-common-passwords/

  1. 123456
  2. 123456789
  3. qwerty
  4. password
  5. 12345
  6. qwerty123
  7. 1q2w3e
  8. 12345678
  9. 111111
  10. 1234567890

:46: How common is it for people to be using easy-to-guess, common passwords?

2:41: Let’s dive in to the top 10 passwords: sequential digits and patterns

5:41: Password safes—what they are and how to use them

9:01: Why is a password safe more secure than using your browser to remember your passwords?

9:09: The problem with browsers

10:16: How do you know if you’re running plugins or extensions—how do you locate those easily and disable them?

12:24: What about Chrome apps?

13:16: The most popular years that are used in passwords

13:52: Using significant years in your passwords and social engineering

14:25: Favorite name as a password, common sports, common cities, and the most popular cusswords

14:55: Password length—how using the most commonly used lengths can help hackers break in

16:00: What is brute force, and how exactly do hackers break in?

16:45: How long does it take to crack a 24-character password with today’s technology?

17:08: Online tools that test your password strength: DON’T USE THEM!

18:45: How often should you change your passwords?

19:00: Multi-factor authentication

19:37: In summary, best password practices reviewed

20:05: Other threats, phishing attacks, SIM swapping, and the use of authenticator apps.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 2: 3 Reasons Why Remote Workstations are the Target, Pt 2

Remote working has been on the rise in recent years and exploded in 2020 during the pandemic. Find out why remote workstations are a popular target for hackers--and what you need to do to protect the corporate network from a breach through this mostly-unprotected back door.

The conclusion...

Show Notes

SHOW NOTES

1:17: Next step after segmentation, a Zero Trust approach to network security

1:45: The big topic of Phishing—still the #1 way of breaking into your network

3:07: Keeping phishing issues top-of-mind with phishing simulations.

4:06: Inevitably, someone in your company is going to click on something and is going to get infected. Are you going to be able to stop the lateral movement and stop it from spreading to other machines

4:40: Limited accessibility so employees have access only to the things they need

5:20: Zero Trust technology helps mitigate this

5:30: Multifactor authentication

5:45: How to prioritize the things that need to be handled first

6:00: Running a Risk Assessment

7:42: More about Phishing and Acceptable Use Policies

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 2 Ep 1:

Top 3 Issues that Make Remote Workstations a Juicy Target and How to Solve Them, Pt 1

Remote working has been on the rise in recent years and exploded in 2020 during the pandemic. Find out why remote workstations are a popular target for hackers--and what you need to do to protect the corporate network from a breach through this mostly-unprotected back door.

SHOW NOTES:

:47: Let’s define what we mean by “remote working”.

1:18: We were working remotely for years before the pandemic, but remote working has changed since 2020.

2:36: We’re making an assumption that people are working on a company-provided equipment that’s managed by an IT dept.

3:43: Why do remote workstations put corporate networks at greater risk than a traditional office environment?

3:50: Discussion of article about a number of laptops that were unknowingly infected with malware, and what happened when those laptops went home during the pandemic.

4:43: What are the top 3 reasons why remote workstations are a hot target?

4:55: Number One, No corporate firewall.

6:23: Discussion of best practices—and inherent dangers—when setting up your router, setting the password, and hiding the SSID.

9:25: What do people need to do in order to know if their firewall is secure?

10:00: If you have employees working remotely, what do you need to do?

10:59: What if your employees are working remotely using public wi-fi?

Downloadable pdf from media.defense.gov, "Securing Wireless Devices in Public Settings":

https://media.defense.gov/2021/Jul/29/2002815141/-1/-1/0/CSI_SECURING_WIRELESS_DEVICES_IN_PUBLIC.PDF

12:34: VPNs and inherent challenges. What is an “always on” product?

14:18: Number Two: Segmentation; dividing your network into separate networks that don’t allow lateral movement, and what is lateral movement?

16:10: What happens if you’re not segmented and your VPN is activated?

17:20: Discussion of an article about hackers who targeted government employees through an active online aerobics presence.

18:45: How much effort and time are hackers willing to put into gaining access into your network?

19:00: Discussion of today’s hackers. Gone are the days of the solitary hacker working out of a basement.

20:20: Discussion of a guy that built a machine for reverse hacking and how he uses it.

End of Part 1. Catch Part 2 for the rest of the discussion!

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/cyber-savvy-cafe/

View Details

Ssn 1 Ep 24

Is Your Refrigerator Running? IoT on the Move

Did you know those smart devices are hackable? Learn how to enjoy the advantages of modern IoT without compromising the security of your network.

SHOW NOTES

1:54: If a device is just Bluetooth connected, is it still considered a “smart device” and could it be hacked?

2:50: How can you improve your office environment with IoT devices and do so safely?

3:04: Some of the top reasons why businesses would consider using IoT devices in the office.

6:06: Alexa for Business

7:56: Some of the security risks with IoT.

8:15: Patching and updates.

9:36: Percentage of cyber attacks using IoT devices and number of households and offices that have IoT.

11:05: Come up with a plan to segment your network so you can use IoT safely and test it on a regular basis.

12:10: Let’s talk about the smart coffee machine that got hacked (in a test environment).

14:04: What does “out of the box” mean in relation to IoT devices and how do you configure your settings.

14:42: A lot of these devices have manufacturer defaults—and how a cyber criminal can capitalize on those.

16:26: Is there a way to make your IoT devices non-searchable?

17:25: If you’re at work and not checking your notifications, how someone could hack into your IoT devices before you can stop them.

17:43: How a refrigerator could be used for a Distributed Denial of Services attack (DDOS).

19:30: Everything comes with a cost; convenience and privacy issues.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Ssn 1 Ep 23

Shopping Online

Avoiding the common security pitfalls of online shopping, and desktop vs. mobile security issues.

SHOW NOTES

:52: What are the potential pitfalls in placing orders on your smart phone?

2:41: If you are already signed onto Amazon on your smart phone and someone gets ahold of your phone, can they gain access to your payment information on your Amazon account?

3:59: Amazon is fairly safe to use, what about an online company you’ve never purchased from before—protocols for entering payment information and purchasing safely on your smart phone.

5:20: Is your desktop a more secure environment to purchase from than your smart phone?

6:43: Using paypal or venmo with your smart phone.

7:40: Case incident of how easily you can pick up a virus or malware on your phone.

9:37: Case incident of an ad company that the Weather Underground app was using, that was pushing unwanted downloads to Weather Underground’s users.

12:40: Basic recommendation for safe online shopping.

13:35: Discussion of PayPal usage on your phone.

13:50: Alerts from PayPal and Amazon if someone is trying to log in from unusual geographic locations.

15:18: Brief review on current protocols for safe passwords and multi-factor authentication.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/ then navigate to the Cyber Savvy Café page

View Details

Ssn 1 Ep 22

Knock Knock, Who’s There?

How security awareness training and phishing simulations can save your business from a catastrophic breach.

SHOW NOTES

1:01: Let’s talk about why security awareness training is so important and how many businesses may or may not be doing that already.

1:48 Your employees are the first line of defense in your organization.

2:19: Phishing is now the primary access point into your network, discussion of changes in company security over the years.

3:10: The importance of phishing simulations and follow-up training.

4:33: How does a company find cyber awareness training?

5:16: How do you measure the success of a cyber awareness training program?

6:10: The importance of documentation in providing cyber awareness training.

6:18: Most cyber security insurance requires cyber awareness training, check your policy to make sure you’re in compliance with your insurance company’s requirements.

6:48: What kind of time investment is needed when providing cyber security awareness training?

8:19: How ongoing awareness training keeps phishing threats front-of-mind.

9:00: Going back to cyber insurance, are you in compliance, what happens if you’re not, and making sure you’ve checked all the boxes to keep yourself secure.

11:52: What happens after a hack, what your insurance company will do to investigate the breach.

13:00: Two areas to watch out for: a false sense of security that you have insurance and you’ll be covered in case of a breach, and failure to provide cyber awareness training for your staff.

13:18: The easiest thing to do to prevent a breach.

14:01: What steps to take to begin training your staff.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at voices.com

You’ll find the downloadable version of these show notes at: https://eastatlanticsecurity.com/cyber-savvy-cafe/

View Details

What happens to your data after a breach?

View Details

Ssn 1 Ep 20

Don’t Bother Me: Why You’re Not “Too Small” to Be Noticed

Why small businesses are desirable targets—and why cyberattacks against SMBs are on the rise.

SHOW NOTES

:46: Alarming statistics of cyber attacks against small businesses.

1:15: What are Denial of Service attacks?

2:42: Why do hackers bother with small businesses? How lucrative could that be?

3:30: No one is 100% secure; if someone wants to breach your network, it’s just a matter of time until they do.

4:15: Big paydays vs. smaller, easier prey.

5:06: How can you estimate what a cyberbreach might cost, were you to get breached?

7:15: 60% of businesses never recover from a single cyberattack, discussion of the cost of a breach.

8:07: What makes small and medium businesses such easy prey?

9:27: Discussion of cyber insurance and what you can expect should you be breached.

12:13: Top things you need to be doing in order to prevent a cyberattack

12:30: Cyber awareness training for your employees.

12:56: Understand your risk profile.

13:40: Acceptable Use Policies

14:30: Story about leaving a review on Google Play Store and receiving an email from, supposedly, the developer of the app.

16:23: Any time you receive a link you have to make sure the link is going to the right place before clicking on it.

16:52: Example of how cyber awareness training can keep cyber security risks front-of-mind to your staff.

18:10: How ransomware attacks occur.

If you’d like to hear us cover a topic you’re interested in, contact us! Leave a message on our website, or on our podcast page at Spotify, iTunes, or Google Podcasts.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://eastatlanticsecurity.com/cyber-savvy-cafe/

View Details

Ssn 1 Ep 19

The Easiest Way to Get Hacked

How social engineering puts you at risk for one of the easiest ways to breach your network.

SHOW NOTES

:15: An example of how a hacker uses social engineering to trick the help desk into helping them breach a corporate network.

1:20: One of the easiest ways to gain access to a corporate executive’s email password.

2:30: The social dynamics that make people more susceptible to falling prey to this kind of trick.

3:03: What a hacker does after they gain access to the executive’s email password.

4:15: How multifactor authentication can protect you.

6:20: How an executive might get targeted to begin with.

7:15: What kind of protocols need to be established for the help desk to authenticate personnel when they call in.

8:23: Other ways of getting hacked, most common phishing attacks.

8:40: Installing malware through phishing attacks and what happens afterwards.

10:05: Other type of common phishing email, bogus alert for a problem with your account at a financial institution.

12:05: How creating a sense of urgency in a phishing email can make you more prone to click their link.

12:27: Phony pages that are created to look exactly like your PayPal or bank page.

12:50: Substituting characters or misspellings in a legitimate URL to make a bogus page look legit.

13:35: When a hacker targets a company, they’re typically after your Office365 or G Suite credentials, and what they do with those credentials afterwards.

14:30: Chase Cunningham and ethical hackings, and how social engineering increases his chances of hacking into a company to 100%.

15:47: Why human nature makes us prone to falling victim to cyber breaches.

16:30: How one hacker’s attempts were foiled by sitting at the wrong desk and how a nosy co-worker saved her company from a breach.

17:49: A situation that happened at a Black Hat conference in Las Vegas and how a reporter locked an inquirer out of their phone account as a demonstration.

If you’d like to hear us cover a topic you’re interested in, contact us! Leave a message on our website, or on our podcast page at Spotify, iTunes, or Google Podcasts.

Cybersecurity Stats:

  • https://www.comparitech.com/vpn/cybersecurity-cyber-crime-statistics-facts-trends/
  • https://cybersecurityventures.com/cybersecurity-almanac-2019/
  • https://www.varonis.com/blog/cybersecurity-statistics/
  • https://techjury.net/blog/cyber-security-statistics/

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://eastatlanticsecurity.com/cyber-savvy-cafe/

View Details

Ssn 1 Ep 18

Detecting an Imposter

How to know if an online company is legit and safety protocols for purchases.

SHOW NOTES

1:10: How do you know if an online company is reputable to buy from?

1:36: Search engine ranking, ads and organic results

2:06: Are the ads that appear at the top of the SERPs (Search Engine Results Pages) reputable companies?

2:15: How Google treats outrageous claims.

2:59: Google’s attempts to screen out questionable websites on the SERPs

3:28: How to pre-screen ads that pop up on your FB newsfeed

4:00: Check their website and look for the following items to make sure the website looks legit.

4:48: Search for a company with the help of the search engine

5:27: Google My Business’ verification process

5:53: Check their FB page for an authentic page, good engagement rates, good feedback and reviews

7:45: Check Google reviews

8:11: Check Reddit conversations to search for comments about a company, service, or product

8:56: Analyze ads and check against reviews about the product itself

10:06: If you have any doubts about an unfamiliar company, check Amazon and see if it’s available for purchase there

11:00: You’ve checked their website, fb page, and online reviews and you still have qualms about the company, you can research their IP address and look for discrepancies in the owner of the domain name and their geographic location.

11:38: Reasons why a company may choose to hide information about their domain, spam controls

12:30: Check the IP address. You’re looking for a discrepancy in the shop’s location.

Go to nslookup.io and get the IP address, and go to arin.net and see where they’re registered.

nslookup.io--enter the URL address and copy the IPv4 adress

Then go to arin.net and enter the IPv4 address

This will give you information about the domain.

13:00: How to interpret those results

14:18: Shopify and godaddy sites, payment gateways, and how to look for discrepancies of what you would expect to find.

16:16: Payment options for purchases: debit vs. credit cards and paypal payments, risks and caveats for use

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at voices.com

You’ll find the downloadable version of these show notes at: https://eastatlanticsecurity.com/cyber-savvy-cafe/

View Details

Strategies for Cutting Costs Series

Ssn 1 Ep 17

Who Has the Remote?

How to leverage remote workstations, build a competitive edge, and make your company one of the most sought-after places to work.

SHOW NOTES

1:10: Let’s start with overall ways people can save money and reduce expenses through the use of technology.

2:54: Let’s talk about VoIP in relation to remote workstations, how does VoIP support remote working, conference calls, zoom-type meetings, chat bots, etc.?

4:55: For companies who are planning to retain remote work options for their employees, how can they reduce their physical office space and restructure the office for a more progressive work environment?

6:31: Work bars, in-office coffee bars, meeting spaces, and shared workstations.

7:12: How to use virtual desktop technology for remote working.

7:49: What other ways might there be to reduce overhead expenses?

8:30: Work-from-anywhere options and what that means for employee retention, job satisfaction, and the employees’ work-home life balance. Discussing instances where employees are able to sell their house in the city and relocate into a more rural area and stay with the company, working remotely.

9:18: Ways employees who are working remotely can collaborate and have meetings or get-togethers in person or have a shared workspace where they can work occasionally.

10:35: Creative new work environments, work bars, in-office coffee shop for employees to meet co-workers over coffee and work on a project together.

11:48: Improve morale and have a more collaborative environment; the things employees are looking for in job satisfaction have changed.

12:10: Small work rooms with white boards for breakout sessions are a creative use of floor space.

12:52: Remote working’s rise in popularity over the past few years and especially since the pandemic. Companies are weighing out the option to continue to offer remote work options to those employees who want it, while reducing expenses and creating unique workspaces for in-office work.

14:10: Remote working moving into the future, growing number of communities with a large population of remote workers, and the need for companies to embrace this direction or risk getting left behind.

At the end of the Strategies for Cuttings Costs series, we’ll be putting all the highlights together into a mini eBook that you can download. We’ll make it available in the show notes for each of the episodes in the series, so check back on that!

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://eastatlanticsecurity.com/cyber-savvy-cafe/

View Details

Ssn 1 Ep 16: The New Kid in Town Pt 3

Today·s episode concludes the discussion about co-managed IT and compares a Co-MIT approach with traditional Managed IT services.

Strategies for Cutting Costs Series

Ssn 1 Ep 16

The New Kid in Town, Part 3

Today’s episode concludes the discussion about co-managed IT and compares a Co-MIT approach with traditional Managed IT services.

SHOW NOTES

01:07: How many companies are typically running with an in-house IT department only

2:02 Some of the problems that arise when a tech-savvy employee without IT training is serving as your in-house IT person

3:28: A recap of some of the challenges facing an in-house IT department and how your security might suffer

5:12: Is cost the main reason why companies are hesitant to hire professional IT support?

6:00: How technology can be used to push your business forward, vs. focusing tech support on network security only.

6:40: How specifically you can leverage technology and be more competitive in your industry.

7:50: Cost comparison of co-managed IT vs. fully managed IT services

12:10: East Atlantic Security’s approach to co-managed IT, for example.

13:15: How, specifically, does co-managed IT support an in-house IT department?

At the end of the Strategies for Cuttings Costs series, we’ll be putting all the highlights together into a mini eBook that you can download. We’ll make it available in the show notes for each of the episodes in the series, so check back on that!

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/Cyber-Savvy-Cafe

View Details

Some of the signs your internal IT department is overworked, the fallout you could face, and how co-managed IT can support your team in a cost-effective way.

Strategies for Cutting Costs Series

Ssn 1 Ep 15

The New Kid in Town, Part 2

Some of the signs your internal IT department may be overworked, and how co-managed IT can assist.

SHOW NOTES

Today’s episode continues on with the discussion about a new approach to IT support, co-managed IT.

00:50: Some of the signs that your IT department is overwhelmed

2:32: Multiple locations, remote working, and the effects on an IT team

4:15: Financial and security fallout from an over-stretched IT team

5:50: Missed patches and falling behind on routine maintenance, and the extensive damage and downtime that can cost a company.

6:15: The average amount of time a threat actor is living on your network before you find out they’re there, and what they’re doing during that time.

6:58: How much does your cyber-insurance protect you? How much do they pay out if you suffer a breach?

8:40: Reputational damage if you suffer a breach, and other effects on your company.

9:15: Lawsuit of a company in the UK that sued an American company

9:38: Are government fines, fees, and lawsuits covered by your insurance company if you weren’t at fault in a breach?

10:35: Average cost of a data breach

11:03: The HIPAA Wall of Shame

12:10: The goal is to make your network so difficult to break into, that a threat actor will give up and go somewhere else.

12:56: Further fallout: Supply Chain Attack, what is it and how can if affect you?

13:55: The new compliance, CMMC, what it is and how it protects the supply chain and what it means for smaller companies

14:55: When is co-managed IT NOT a good solution for a company?

At the end of the Strategies for Cuttings Costs series, we’ll be putting all the highlights together into a mini eBook that you can download. We’ll make it available in the show notes for each of the episodes in the series, so check back on that!

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/Cyber-Savvy-Cafe

View Details

Strategies for Cutting Costs Series

Ssn 1 Ep 14: The New Kid in Town, Part 1

There's a new kid in town, Co-Managed IT, and it's changing the face--and the cost--of IT security.

In this first episode of the Strategies for Cutting Costs series, Rex and Penny discuss why Co-Managed IT is an advantageous solution for many of the IT problems facing today's companies.

SHOW NOTES

Ssn 1 Ep 14

The New Kid in Town, Part 1

How Co-Managed-IT is changing the face—and the costs—of IT security.

Intro: If you’re like a lot of the companies we work with, your IT department is significantly understaffed and overwhelmed and has a hard time keeping up with the constant demands placed upon it.

Today’s episode is about a new approach to IT support and kicks off the “Strategies for Cutting Costs” series.

00:46: What exactly is Co-Managed IT and how does this differ from managed IT services?

3:15: Benefits of access to a shared tool suite that most companies cannot afford to implement on their own.

4:42: How automated tools assist with regular patching.

6:56: Customizing and blending Co-MIT with an IT department’s regular day-to-day tasks.

7:45: What are some of the reasons CEO’s are moving towards a Co-MIT approach?

9:15: Reduce expenses and free training: How Co-MITs can be customized for each company’s needs so a company is only paying for what they need, and how an MSP works side-by-side with an IT department.

10:49: The benefits of having access to an MSP who is keeping abreast of the latest cyber threats and innovative IT solutions.

11:10: The freedom for IT professionals to have time off and take vacations without worrying about their network.

11:30: For what kinds of situations is Co-MIT an ideal solution?

13:28: The benefits of Co-MIT for remote workstations.

15:18: Case study of one client who has an interesting configuration of their IT services.

17:03: Closing. Don’t miss next week’s episode, “The New Kid in Town, Part 2,” where we discuss telltale signs your IT department is overworked and the ramifications that can have on your company and your network security.

At the end of the Strategies for Cuttings Costs series, we’ll be putting all the highlights together into a mini eBook that you can download. We’ll make it available in the show notes for each of the episodes in the series, so check back on that!

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/Cyber-Savvy-Cafe

View Details

Rex and Penny talk about Windows Virtual Desktop: utilizing latest technologies to turn your team into a dynamic mobilized workforce.

The Cyber Savvy Café: Ssn 1 Ep 13

Virtual Desktop: Take it on the Road

Utilizing latest technologies to turn your team into a dynamic mobilized work force.

SHOW NOTES

Why and how a virtual desktop environment can take your business to the next level--especially if you have people working from home.

0:56: What is Windows Virtual Desktop? (WVD)

1:35: How does this differ from working locally, on a desktop or laptop and how does it increase work performance for employees working remotely?

4:23: Discussion of some of the risks that remote working poses to corporate networks, and the solutions WVD offers.

5:55: Pay for what you use: the cost-savings of WVD.

8:25: Solution for older computers with poor performance; aging hardware can still access the virtual desktop and perform well.

9:30: Using Microsoft’s internet connection, as opposed to your home network’s connection.

10:16: Discussion of how to migrate to WVD

11:20: How popular is the WVD environment?

12:07: We have a testimonial from a client on our Business Restructuring page on the website, who switched to WVD during Covid 2020.

For more information about the process of switching over to WVD, visit the link and scroll down to Barry E's video: https://eastatlanticsecurity.com/business-restructuring/

12:51: Why some companies use WVD exclusively.

14:00: Info on the internet you can peruse, and Microsoft has a “Get Started Today” button on their website that you can look into.

14:26: Great solution for some of the issues companies are facing right now, discussion of further benefits of WVD.

14:42: Additional benefit: Good exit strategy for employees who leave the company, helps ensure that your data stays secure.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/Cyber-Savvy-Cafe

View Details

What if your phone got infected with malware or hit with a ransomware attack? What is the immediate fallout? In this episode we talk about some of the best steps to take NOW to secure your device so hopefully you won’t ever have to answer those questions.

The Cyber Savvy Café: Ssn 1 Ep 12

Life or Death of an Android

9 Easy Ways to Safeguard Your Android Device

SHOW NOTES

Unexplained data usage, crashing apps, popups, battery drain, or any other unexplained changes, these are some of the symptoms that your phone is infected with malware. What are some of the steps you can take now, to safeguard your phone before it’s too late?

0:45 Discussion of viruses and malware on mobile, increasing ransomware attacks, and the need to bring this to the forefront of people’s attention.

1:31 Best steps to take now to secure your device.

2:40 Be sure to get a good phone and from a reputable vendor and keep it updated.

3:10 Be sure to keep apps updated.

5:12 Don’t leave your device unattended—even around your co-workers, and keep your phone locked.

5:52 Download apps from Google Play and Apple Stores only.

7:33 Use Google Play Protect, a malware scanner.

8:30 Use anti-virus and anti-malware apps for android and iphone.

9:30 Encrypt your data, be sure to turn on encryption for added protection in case your phone is lost or stolen.

10:46 Use a VPN (Virtual Private Network).

13:05 Protect your accounts (Google, Apple, etc.) with multi-factor authentication.

For more information on this topic, check out our blog, “9 Ways to Safeguard Your Android Device,” at: https://eastatlanticsecurity.com/2021/03/20/9-ways-to-safeguard-your-android-device/

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/Cyber-Savvy-Cafe

View Details

The Cyber Savvy Café: Ssn 1 Ep 11

The Little’s

Kids Online and Network Security: A Cyber-Breach Waiting to Happen

How much does your kids' online usage impact the security of your home network? Find out how and why you may be at risk of a cyberbreach when children are using the network--and what you can do about it.

SHOW NOTES

You do everything you can to keep your network secure—but when one of your kids is online and they click on click-bait…bam! You can get infected with malware just like that.

1:05 Can you keep your network secure when you have limited control when your kids are online? “Secure” vs. “Trust” and a Zero Trust policy

2:22 Network Segmentation; Check out Ssn 1 Ep 4: IoT Devices for a more detailed discussion on Network Segmentation

3:43 What is Zero Trust Policy?

5:05 How do you protect your network if you only have one computer that the whole family shares?

12:50: Discussion of a company that was breached and faced a devastating ransomware attack due to the compromised home network of a remote employee.

15:05: Dedicate one computer in your household for sensitive personal information and financial data, and keep it separated from every other device in the household.

16:00: Four bullet items for best practices

16:35: Discussion of social media pitfalls and how to use it safely if you must do so on a work device.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

You’ll find the downloadable version of these show notes at: https://EastAtlanticSecurity.com/Cyber-Savvy-Cafe

View Details

Acceptable Use Policies: The Whys, Whats, and Whatnots

Why it’s important to have an AUP in place, how it protects you, and how to make one.

Ssn 1 Ep 10

The Problems It Solves

Acceptable Use Policy: The Whys, Whats, and Whatnots

Why it’s important to have an AUP in place, how it protects you, and how to make one.

SHOW NOTES:

An Acceptable Use Policy (AUP) defines how your employees are to use the corporate network and associated technology; what they can and can’t do.

00:28 Why is it important to have an AUP in place?

01:19 What can potentially happen if you don’t have one?

02: 04 What’s in an AUP?

03:45 What kind of policies do you recommend?

06:12 What fallout have you seen that came from not having an AUP in place?

07:50 How Do You Make One?

  • Sample AUPs are available on the internet to use as a starting point.
  • Ask others in your industry what they use, where they got it, or how they designed it.
  • Hire a professional to assist; look for an experienced MSP who includes AUPs in their services

08:32 Any other problems an AUP solves?

09:52 Where do you post an AUP so it’s accessible to your employees?

10:59 How imperative is it to make one now and not put it off?

Additional Notes:

General Sections in an AUP Can Include:

  • An overall purpose statement: an overview of the reason for the AUP and key takeaways.
  • Definitions: Make sure any confusing terms are clearly defined, and explain any lingo that may be unique to your industry or your company.
  • Scope: To whom and to what situations does the policy apply?
  • Policies: This covers use, access, behavior, and general company policies for each section.
    • Passwords, sharing of passwords, acceptable use of network, authorized use of voice mailbox, premises, personal devices while at work, etc.
  • Personal Use: Are employees allowed to use the network or devices for any personal use; if so, how and when
  • Enforcement: What happens if a policy is violated. Be very clear about the steps that are to be taken, including sanctions or termination of employment.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Think you’re safe, hooking your devices up to public Wi-Fi and public charging stations? Think again. In today’s episode we talk about the sneaky cyber back doors you open every time you connect a device in a public space.

Show Notes for Ssn 1 Ep 9

Spies at the Coffee Shop:Public Wi-Fi, Charging Stations, and Other Cyber Traps

SHOW NOTES

1.Public Wi-Fi

  • All public Wi-Fi should be considered unsafe, and untrusted.
  • Solution: When at a place like Starbucks, access via your own hot spot or VPN if you have one on your company laptop.
  • DO NOT access at Starbucks or any public Wi-Fi unless you have one of these options.

2.Charging Stations

What Is Juice Jacking?

When using a public charging station, cybercriminals can potentially access all the information on your device or initiate a full backup of your phone. Cybercriminals can also inject malware into your phone.

Solution: Don’t use public charging stations.

  • Keep your battery full.
  • Carry an external battery pack.

If you absolutely must use a third-party power source, use a USB data blocker or power-only USB cables. These cables are missing the two wires necessary for data transmission, ensuring that they can only be used for charging.

Blog Post: https://eastatlanticsecurity.com/2021/01/05/why-you-shouldnt-use-public-charging-kiosks/

3.Flash Drives and Data Sharing

Flashdrives can easily be infected with malware. If your flashdrive becomes infected—this can happen at any shared computer—and you insert it back into your computer, it only takes a moment to transfer that malware onto your device.

Solution: Use a commercial-grade cloud-based system for transferring data.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Remote workstations are here to stay, but lax home network security is putting corporate networks at risk. Here are some steps to help secure your network and close the doors to a cyber breach.

You can get your copy of "8 Security Threats for Remote Workstations and How You Can Mitigate Your Risk," at:

https://eastatlanticsecurity.com/hackers-go-phish/

Why Remote Workstations Put You at Risk of a CyberBreach

Show Notes for Ssn 1 Ep 8

  • Remote workstations pose specific risks and require additional security measures, staff training, and work-from-home protocols to keep the corporate network secure.
  • Many companies have not yet set aside time and resources to set up secure workstations, company devices, and protocols for remote employees.
  • Employees working remotely are more vulnerable to falling prey to phishing emails and other scams, potentially giving cybercriminals direct access to the corporate network.

What do employers need to do to secure their employees’ remote workstations and protect company data?

  1. Company Device

  2. When possible, a company-issued laptop is the safest workstation:

  3. A foundational caveat for using a company laptop: DO NOT USE FOR ANY PERSONAL USE.
  4. There are times when a personal device is being used at work, and those need special protocols.

  5. Public Wi-Fi

  6. All public Wi-Fi should be considered unsafe, and untrusted.

  7. We'll be covering this in-depth in Ssn 1 Ep 9: Spies at the Coffee Shop

  8. Accessing Company Resources and VPNs

  9. Users will probably need to access resources that are in their corporate offices.

  10. Employers have the ability to implement a sophisticated VPN from an untrusted workstation back to the corporate network, allowing that user access to specific resources from restricted channels.

  11. Passwords and Two-Factor Authentication

  12. Turn off autocomplete, and any saved passwords.

  13. Better solution: Use a password management app, like LastPass.
  14. Follow current industry recommendations for secure, unique passwords. (LastPass will generate secure passwords for you!)
  15. Enabling multi-factor authentication is an easy way to tighten security and should be used for all accounts.
  16. Check out Ep 5, Password Secrets and the Book of Codes for a deeper discussion of this topic.

  17. Firewalls

  18. Use firewalls for personal networks. Always have your provider firewall enabled, like Windows. Depending on how many devices you have on your home network, you should go even deeper than an anti-virus like Webroot.

  19. Don’t rely on your ISP access point or anything it provides. Go out and buy your own security device or firewall and plug it into theirs--and then keep it updated. Some recommendations:

    • Sonicwall Tz105 UTM
    • Cisco RV110W
    • Ubiquity UniFi USG
  20. Get a hardware firewall hooked up that allows you to create virtual networks. Put your primary computer on one, and IOT devices on a separate network with no access to the computer in case an IOT device gets compromised.

  21. Listen to: Ep 4 IoT Devices and Network Security for more on this topic.

  22. Phishing emails

  23. Phishing is the #1 way of getting inside your network.

  24. Check out our back episodes on phishing, #2 and #3, and Ep 7: The Perimeter is Dead, for more information.
  25. Don’t open PDFs, Word docs, images, or any attachments that come in an email without first verifying with the sender.

  26. Beware of Bogus Websites, Apps

  27. Phishing emails and bogus websites centered around information about current events can crop up by the thousands (e.g. apps with global tracking maps during the pandemic containing spyware and malware.).

  28. Do not seek information from untrusted sources. Doing so can compromise your device and the company network.

  29. Personal Devices

  30. An employee’s personal device can be managed through a Bring Your Own Device policy

  31. Use a VPN when connecting remotely, or use Microsoft’s cloud offering.
  32. Best Practice: Use Microsoft Windows Virtual Desktop in the cloud.
  33. Using your personal phone or tablet to check work emails, files, etc. is a big NO when working from home.
  34. In the event an employee’s device is infected with malware, spyware, etc., Mobile Device Management sets up a "business space" and will keep that area separated and protected from the rest of the items on the device.

You hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

In today's episode we dive into the current cyber landscape and discuss why you need more than just a great firewall to protect your network.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Rex and Penny talk about the radical changes to the work environment and the need for flexible IT systems that can accommodate a mobile workforce.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/cyber-savvy-cafe

Voiceover Artist: Paul Kadach at www.voices.com

View Details

How to make passwords that take a hundred years to crack and storing passwords securely with minimal hassle. This week's episode dives into the secrets of password security.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/cyber-savvy-cafe

Voiceover Artist: Paul Kadach at www.voices.com

View Details

In today's episode, we talk about the ever-growing popularity of IoT devices and how to ensure you or your employees' use of IoT is not putting your network at risk.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/cyber-savvy-cafe

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Continuing on with the discussion of how to guard against phishing attacks.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/cyber-savvy-cafe

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Rex and Penny discuss the growing rates of phishing attacks and how to avoid being a victim.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/cyber-savvy-cafe

Voiceover Artist: Paul Kadach at www.voices.com

View Details

Rex and Penny discuss the top 3 methods hackers use to breach your network security.

Your hosts: Rex Nance and Penny O'Halloran of East Atlantic Security, LLC @ https://EastAtlanticSecurity.com/cyber-savvy-cafe

Voiceover Artist: Paul Kadach at www.voices.com