Listen to this episode

Historically Significant Hacks and How YOUR Business Can Avoid This List

0:0041:01

Recorded May 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

Erin and Blake of Petronella Technology Group review some of the largest data breaches in history and what they mean for everyday internet users. They walk through breaches at Yahoo, Facebook, Instagram, Twitter, Adobe, AOL, Apple, AT&T, Ashley Madison, Bank of America, Canva, Capital One, DoorDash, Dropbox, Verizon, eBay, and YouTube, citing record counts and causes such as poor security, stolen devices, and accidentally published data.

Blake shares that his own data was compromised in the Equifax breach, and Erin recalls the Twitter hack in which teenagers posed as company staff to hijack celebrity accounts for a Bitcoin scam. The hosts also wander into a discussion of chemical contamination involving 3M, DuPont, and North Carolina water supplies before returning to cybersecurity. They argue that password reuse multiplies breach damage and recommend multifactor authentication, password managers, and good password hygiene. Erin suggests XDR could have prevented many breaches, while Blake predicts attackers will shift to bigger targets. They close by stressing layered security and personal responsibility online.

Worth remembering

Key takeaways

  1. Never reuse passwords, because a breach at a trivial app can expose the credentials that protect your bank, retirement, or other sensitive accounts.
    “If you have some stupid little app that you play that got breached and you use the same password for your retirement or anything, financial or anything sensitive. Just asking for it.”
  2. Erin urges turning on multifactor authentication everywhere possible, avoiding password reuse, and using a password manager to minimize the impact of inevitable breaches.
    “Multifactor authentication is going to stop a lot of this and also just password hygiene in general, good password hygiene, not reusing it, and also making a secure passwords, having a password manager”
  3. Blake cautions that multifactor authentication cannot protect information a company stores on its own servers when attackers breach the company's database directly.
    “even by having to FFA, and things like that, your information is on their server, what information they keep on what server and where, and how it's stored who knows about that.”
  4. Blake warns that attackers test credentials stolen from one company against other services, so a reused password without multifactor authentication leaves you exposed.
    “a hacker gets your information from X company and sees that you do business, or maybe, have used a Y company they try to use the same credentials from X company on Y company.”
  5. Blake says cybersecurity is about layered approaches, and both hosts agree XDR is a valuable layer but not the end all be all.
    “Cyber security is about layers, right? It's about layered approaches. So the more layers you have, the more secure you are, so is XDR a layer. Absolutely.”
  6. Blake observes that people want an easy button in cybersecurity, and when they cannot find one, they simply do nothing at all.
    “and if they're looking for the easy button and they don't find it, what do they do? They just don't do anything.”
  7. Erin stresses that bad cyber hygiene impacts not just yourself but also your clients, calling it thoughtless, and urges everyone to take precautions.
    “So when your cyber hygiene is bad, you're not just impacting yourself. You're also impacting your clients.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

We've all seen the news and read the headlines - Hackers aren't going anywhere anytime soon! In fact, quite the opposite is true...

So what can YOU do to keep your company's name out of the papers? Listen in and find out!

Hosts : Erin and Blake

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.