Listen to this episode

Guarding Against the Inevitable: Strategies for Cybersecurity and Prevention

0:0034:22

Recorded October 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this news roundup episode, Craig and Blake Rea of Petronella Technology Group work through recent cybersecurity headlines and the lessons they draw from them. They discuss the SEC's lawsuit against SolarWinds, alleging fraud and weak cybersecurity after the 2019 breach by a Russian-backed group, and argue it shows why customers should audit vendors, demand evidence, and embrace a trustless model.

They note that at the time of recording, the Canadian government has banned WeChat and Kaspersky on government-focused apps, and Craig advises listeners to assume apps from adversary countries could be spying on them, limiting permissions or uninstalling them. At the time of recording, they also note new FTC guidelines requiring car dealerships to adopt encrypted messaging tools and hard drives. Other topics include malvertising aimed at a Brazilian payment platform and the LastPass breach fallout in which 25 users lost more than $4 million in cryptocurrency. Blake recounts a social engineering phone call, and the episode closes with advice on zero trust, backups, redundancy, self-assessment, and treating security as a foundation for business growth.

Worth remembering

Key takeaways

  1. Craig urges businesses to audit their vendors and third parties, push back, and ask for proof and evidence of security standards instead of trusting them blindly.
    “And I think the takeaway is audit your, your vendors, audit your third parties that you're doing business with and push back on them.”
  2. Craig argues that apps from hostile or adversary countries pose a big risk, so assume they spy and limit permissions or uninstall them.
    “You have to assume the worst. You have to assume that, oh, this app's spying on me.”
  3. Craig notes that at the time of recording, new FTC guidelines require car dealerships to adopt encrypted messaging tools and hard drives to protect sensitive customer data.
    “there's a new extension to the FTC where they're requiring the car dealerships to use encryption more heavily, specifically adopting encrypted messaging tools and hard drives.”
  4. After the LastPass breach, Craig argues consumers must take matters into their own hands, changing passwords and monitoring their information rather than relying on breached companies.
    “So assume the worst, assume all of our stuff is out there. What are we doing to monitor it and what are we doing to protect it”
  5. Craig argues that layers like authenticator apps for one-time pins help, though he says they are no excuse for not changing passwords after a breach.
    “had they used Google authenticator or Microsoft authenticator, the software apps for you know one time pins and passwords in addition to the password?”
  6. Blake recommends asking what the worst thing that could happen to your business is, then finding single points of failure and implementing redundancy.
    “Ask yourself the simple question, like what is the worst thing that could happen to my business?”
  7. Blake says there is nothing wrong with being uncompliant; the real wrong is continuing to ignore the right thing once you know better.
    “Don't be embarrassed, you know, like there's nothing wrong with being uncompliant.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Hold onto your security blankets folks! Are we ever secure enough in this digital age? Get a grip on the pulse-raising lawsuit from the SEC against SolarWinds and the unexpected ban from the Canadian government on WeChat and Kaspersky. We harness the power of hindsight, looking back at how this enormous breach happened and what could have been done to prevent it. We delve into the harrowing reality of the threat lurking in every unvetted third-party vendor and the possibility of any app from adversarial countries spying on us.

Brace yourselves as we discuss the dark underbelly of cybersecurity, shedding light on social engineering, smishing, and phishing. The safety net of multiple layers of security measures and the crucial role of backups, are the shields you didn't know you needed. We bring to you the wake-up call to constant self-questioning and understanding the vital steps to secure your business. We take you through the process of identifying business vulnerabilities, discussing proactive security measures, and preparing for disasters. You can't afford to miss this candid conversation about the essence of a data-driven business model and the absolute necessity of being prepared for the worst.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.