Listen to this episode

GoDaddy In The News Again + Massive Fines for Breach

0:0036:02

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Craig of Petronella Technology Group is joined by Erin, BJ, and Blake to discuss recent cybersecurity news. The group examines the GoDaddy backdoor breach involving WordPress, with Craig explaining that WordPress is a prime hacker target because of its popularity and that its underlying Linux, Apache, MySQL, and PHP stack must be patched and secured by users, since budget hosting providers disclaim security responsibility in their fine print.

He warns that a compromised website can expose every visitor to infection. The panel also discusses the FTC seeking, at the time of recording, roughly half a million dollars from CafePress over a 2019 breach that was not reported in time, noting the database held more than 23 million records of personal information. Craig argues that small businesses are at high risk because they lack the defenses of larger firms, and the group also discusses identity theft affecting children and compliance costs for defense contractors. BJ argues the Russia-Ukraine war proves cyber war is how war will be fought going forward, and the episode closes with a conversation about the metaverse and quantum computing.

Worth remembering

Key takeaways

  1. Craig explains that a WordPress site's underlying stack components must be properly secured, maintained, and patched, or hackers will exploit the loopholes.
    “But all of those components in the stack. Must be properly secured, maintained, and patched.”
  2. Craig notes that budget hosting providers disclaim responsibility for security in their fine print, leaving users to properly secure and configure their sites.
    “They hold themselves harmless to any kind of security or configuration. And they leave that up to the user to properly secure and configure.”
  3. Craig warns that a website infected with ransomware puts every visitor at risk of becoming a victim.
    “every visitor that hits your website is now a potential victim.”
  4. BJ reports that, at the time of recording, the FTC was seeking a half million dollar fine from CafePress for not reporting its 2019 breach in time.
    “it looks like a half, a million dollars is the fine that the FTC is seeking in regards to that breach.”
  5. BJ cautions that encryption is not a catch-all, arguing that even quantum safe encryption has reportedly been broken.
    “So even the quantum safe encryption is not safe. Encryption is not a catch all.”
  6. Craig argues that small businesses are actually at high risk because they lack the defenses that larger companies have.
    “The little guys are at high risk because they don't have near the defenses of the big guys.”
  7. Craig tells the others that compliance, even at the CMMC level, is not that expensive and often costs less than hiring another employee.
    “The reality is it's not that expensive to get compliant and do the right thing.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

In this episode, we discuss why GoDaddy is in the news (again) and why a t-shirt company, CafePress, was fined $500,000 by the U.S. Federal Trade Commission for a data breach they experienced.

Host: Craig Guests: BJ, Erin, and Blake

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.