MGM Cyber Attack, Personal and Business Cybersecurity Tips and Tricks
Recorded September 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.
Key takeaways
- Blake argues that security awareness training is a simple layer of defense that might have helped MGM avoid the attack.
“you need to have some type of security awareness training. Everybody needs to be aware of the possible threats”
- Blake contends that Caesars paying its ransom opens the floodgates for more incidents because hackers simply want the quickest path to monetization.
“by you know Caesar's paying this ransom, it's just opening up the floodgates for more incidents to happen”
- Craig argues that security is not optional and that people should assume they have already been hacked and plan accordingly.
“This stuff isn't optional anymore. You have to assume that when you wake up in the morning, you've been hacked. And what are you going to do about it?”
- Craig warns that cyber insurance companies have gotten smarter and will not pay claims without evidence backing the application answers.
“They're not paying the claims anymore unless you have all the evidence to prove that you did what you said that you were going to do on the application.”
- Blake recommends manually checking phones and computers for updates at least once a week because hackers exploit older backdoors.
“I make it a habit to check my phone at least once a week and make sure my software is up to date.”
- Craig stresses that email is not secure and sensitive information should be shared through portals or encrypted apps instead.
“email's not secure. It's a fact. So, don't click or do anything or send anything that's sensitive with email.”
- Blake shares personal habits such as locking unused credit cards and switching off Wi-Fi and Bluetooth whenever he leaves home.
“I I lock all my credit cards like whenever I'm not using them, like they're always locked.”
The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.
From the show notesAbout this episode
MGM Cyber Attack, Personal and Business Cybersecurity Tips and Tricks. According to Okta, Hackers who breached MGM and Caesars also hit 3 other firms. Learn cybersecurity tips and tricks you can use to security harden yourselves and your business.
Episode transcript
Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.
This is Encrypted Ambition, a podcast about the builders rewriting the rules. Join Petronella Technology Group as we decode the ideas, challenges, and momentum behind tomorrow's business, technology, and leadership breakthroughs. All right, welcome to another podcast. Got Blake Gray.
We're back. It's been a while. My apologies. I had a lot going on. Yeah, we're wearing multiple hats here, so, so yeah. Sorry, guys. Very sorry. Well, there's no shortage of news. We wanted to talk about the MGM hack. Yeah, yeah. Here in Vegas, everything is shut down.
Pretty much, especially from all the MGM properties. So, yeah. So, I guess give a short version of what happens from your side. So, obviously, MGM was hacked, and essentially, it took out most of the digital infrastructure for MGM. So, MGM properties is essentially Bellagio.
Aria, the Cosmo, um, essentially, it disrupted people like checking in, people checking out, like any type of digital room keys, any type of electronic payments. Um, essentially, MGM has kind of not really put anything out publicly, but they have told the told news outlets that they're.
That they're not going to pay the ransom, and it's been going on for about a week now, and it's obviously disrupted any of their their loyalty programs, you know, any type of online channels they have, and even such as the phone lines from the rooms has been been affected. So it was.
Pretty massive, and I heard that it was costing MGM. I think it was like eight, almost eight million dollars a day. Let me confirm that number before we blast it out. But I think it's, yeah, so eight point four million dollars per day in lost revenue. That's just how.
Yeah, yeah. Do you know if it was caused by a business email compromise or a phishing email? Do we know anything like that yet, or still being investigated? I think they're very careful about what they put out. There has been like a hacking group called the the Scattered Spider. They are the ones claiming responsibility.
Um, but but they they suggested, or some of the articles that I've read, um, alluded to it being some type of malware repository that that was was the the compromise compromised. Um, that that essentially is how they compromised the system. So, interesting.
Yeah, I have to say, I mean, I was quite surprised that an industry that is usually so on the cutting edge of security, especially with physical security and cameras and surveillance, I just would have thought that there would have been more in place to, you know, see a headline that was like, "Oh, the good guys maybe."
Thwarted this attack instead of suffered from it. Yeah, I mean, you would think you know Caesar's obviously had a pretty recent attack as well. Caesar's ended up paying the ransom, but you would think they would use opportunities like this at at the cost of another casino to learn from.
You know, and not having to cost them, I'm not. I'm not sure. I'm really not sure why. I mean, if they're not taking customer data seriously, or I mean, there's a lot of money that goes through these casinos. You would think that be they they'd have more resources to to thwart this, or I mean, we've always talked about this before on some of our other podcasts, but.
You know, good cyber hygiene and good knowledge - you know - from your staff is pretty simple. A simple layer of defense that that people, you know, you need to have some type of security awareness training. Everybody needs to be aware of the possible threats, and a simple program, you know, a simple a simple course, you know, lecture can.
May have avoided this. Who knows, right? So, yeah, I think that's the million-dollar question. I think the other side is, I think that most companies they don't think it's going to happen to them, and I think with the training aspect, they may have purchased training or they may have training, but I bet there wasn't enough testing to ensure that people actually did it. Or, you know, I think that it's, I think in and you know this, Blake, it's it's the world we live in where.
People don't really wake up and think, "Oh, I'm going to do security and compliance today," or "I'm going to go take my security training and and you know do good for my job." I I think it is just kind of looked at like this like thorn in your side, you know, like, "Oh, I need to do that," and I got all this other stuff to do. I'm not going to do that. You know what I mean? Like, so it's like, I feel like.
You know, maybe the company had good interest, and maybe the company had bought training or you know, whatever had some layers in place. But I think that nowadays, with everything going on in the world, I think that obviously the human element's the weakest element. But it's almost like you have to assume the worst and assume that okay, we have this training, but we we're going to assume that nobody's going to take it and do it. So what else? What other layers can we add?
You know, if this was a case of business email compromise or a phishing email, you know, obviously there's training to decipher and be able to pick apart. Hey, this is a phishing email. I'm not going to click on that kind of thing. But maybe have other layers in place that assume they are going to click on it. What defenses do you have to contain that? You know, what if you assume that everybody's bad?
And you assume a trustless approach, and we talked about this many times too. You know, then you need to think about it in that, like I said before, in kind of like a hacker's eyes, a hacker's view view of what your network and what your computer systems look like. And I think that that's probably the best path forward with a lot of the. I mean, I don't know if you heard about the Clorox hack yesterday.
Yeah, so that was all over CNN, and I was on the news about that. But you know, they were talking about supply chain issues and ramifications. And this, the hack didn't happen yesterday. It was just talked about yesterday. It happened actually over a month ago, and they're still having ramifications from it. And they're they're basically saying that there's going to be shortages on the shelves of Clorox products because of this, and the.
The interview is about how some of these attacks affect consumers. You know, and obviously with MGM, people on vacation can't get - they're either locked out of their rooms, they can't get into their rooms, they can't enjoy some of the entertainment that they paid for. So it's just - you know - it's - it's - it's almost like the worst possible publicity that you can have when this kind of thing happens.
So I don't know enough about it to really kind of comment on you know what happened, or I guess we'll find out the details of that whenever it's made public. But I think that the point to drive home here is it's it's what we've said for a long time: you can't trust one type of solution, one vendor. There's no silver bullet in any of the stuff. We've said this many, many times on our podcast and our other channels.
This stuff isn't optional anymore. You have to assume that when you wake up in the morning, you've been hacked. And what are you going to do about it? That's really the viewpoint, at least from my perspective, because I I still feel people are not going to put money towards this. It's not something that they're excited about. It's it's just like I said before. It's the thorn in their side. You know. What do you think?
Yeah, I mean, we've also talked about this, I think, before. But you know, Caesar's right. Caesar's paid, paid the ransom. So, I mean, when you pay the ransom, you're kind of condoning this activity. Like hackers are not complicated individuals. They they go through complex processes to gain your data.
But surprisingly, they're super simple-minded. At the end of the day, their time is worth money, right? And that's what they're trying to do. They're trying to monetize their time. So, so by you know Caesar's paying this ransom, it's just opening up the floodgates for more incidents to happen. You know if.
If every corporate entity took a stance and said, "We are never," or even the you know the FBI said, "If you pay hackers, you you we're gonna find we're gonna find the hell out of you, whatever," right? But if if they implemented some type of standard where no matter what happens, you can never pay the the attackers, the hackers.
Will this happen? Probably not, right? Because they're spending so much time, energy, effort, you know, to go after, you know, these companies, and and to they just want the quickest path to monetization. And if they spend time, energy, effort hacking, you know, databases, information, customer profiles, you know, the trifecta of of customer information.
And then they post it on the dark web and sell it in little bites. Or somebody who's trying to buy a credit card, or buy an, you know, an address, or buy some type of little small piece of information. You know, they're going to get ten dollars here, twelve dollars there, whatever. Credit cards are going for on the dark web. I have no idea, but you know, that is not very profitable. Then they're looking to get a huge, large of money, a huge, large sum of money, immediately as quickly as possible.
And get rid of the data, right? Because the data is the fingerprint, the evidence, and that's what they're trying to. Or use the data for extortion and blackmail. That's too. But I think we all agree that if if these companies were to not pay, then this probably wouldn't happen, and it probably wouldn't be as common as it is. You know. Well, I think. I think.
So I heard from, and I don't know if this is still true or not, but I heard that it's harder to pay nowadays. Meaning, there are laws that were put in place that you can't, you know, if you get, if you pay, and let's say the attackers came from an adversarial country that we have sanctioned.
And you get caught paying, you're funding a terrorist group. You can get in big trouble. So I've heard that. So I don't think it's so easy to pay anymore. But I I agree with you, Blake. I understand what you're saying, and I understand your perspective. However, I think that the problem now, versus just maybe a couple years ago, is that countries, adversarial countries, have pretty much set up shop and business that this is their new business.
You know they're they're this is their job. You know they're recruiting people and training them on how to scout and how to trick people. In this case, corporations and try to drop that malware. And so it's almost like you know digital soldiers, right? So if you if you recruit a thousand people hitting the phones and doing smishing and phishing and all this stuff on social media to target, right?
You've got pretty much these almost like lemmings that try to distribute the the payload, right? And if any one of those, again, this is their punch in, punch out day job. That's their job. They wake up, and their job is to get somebody on the phone and scam them, or get them on email chat. However, get that payload to them, and that's their job. Well, it only takes one.
Right, and then runs there. Now it's on the endpoint, and they know from statistics that once they're inside, it's hard for them unless they have the right technology and the right layers. It's hard for them to recover from that. You know, I've said before that with ransomware, you know, there's there's two types of ransomware. There's the ransomware that locks all the computers up.
And you can't function digitally anymore. So your business continuity is pretty much toast. It comes to a screeching halt. So I've talked about redundancies and different paths, and testing, and penetration testing, and training, and all this stuff. Right? All these different things that.
But I don't think that a lot of that is taken seriously enough, and I don't think it's being drilled and and actually being done enough. And I I think I hear about budgets getting cut for cyber and compliance, and I just shake my head. And it's like they can't even keep their head. Most people can't keep their head above the water now. So how are they going to cut this stuff when it's, in my opinion, the most important thing to invest in now?
Because, like I said before, I think people are just almost numb to it, and I don't think people are thinking that it's going to happen to them. And I think that until it does, that's when they think about, oh, well, how do I recover from this? And then it's like hurry up and panic. But like you mentioned, you know, people get hacked and they pay, or and sometimes they get the key, and sometimes they don't. There's no guarantee on that. There's people that have paid and they didn't get anything.
And they, you know, the hackers, you know, just stole the data. And there's been other issues where the hackers have posted the information online. So it's just, you know, what is the the saying? An ounce of prevention is worth a pound of cure, right? It's, I think that it's going to get to a point where, like I said earlier, you have to think about it as everybody's an adversary.
It's it's a sad way to to think about it, you know. But the point is that you we're just there's just so many arrows pointed at us, you know. So it's like you have to do everything possible to protect yourself. Yeah, I mean, I think we've talked about this before and some of our other podcasts. But there's a really surprisingly simple solution.
To preventing this from happening to any company, and it's just like you do for taxes - you take a portion of your revenue, you put it in an account that says, "Hey, here's the tax money." Like we're going to pay the tax man, right? Like religiously. Like you, everybody, every company does that. And if you look at that in the exact same eyes, like the same lens as cybersecurity.
Here is a portion of our revenue. I think we suggested anywhere from twelve to eighteen percent, depending on. I think we've talked about this before. Yeah, I think that that that's the maintenance percentage, though. I think that the the reality or the stark reality for most is that let's just assume you have nothing. You know, you have like the the bare bones, if anything. You know.
So the mountain is high; is it's a high, you know, trail to climb, right? So I think that that percentage, that's after the big work is done. So I, I mean, that's just the reality of it. There's a lot of work to be done, and I think that's where people just stick their head in the sand, and companies do the same. It's just like, this is too much. We can't do this. We'll just, we'll just pay cyber insurance.
Well, guess what? The cyber insurance companies have gotten smarter. They're not paying the claims anymore unless you have all the evidence to prove that you did what you said that you were going to do on the application. And if they investigate and they do analysis and find you don't have the supporting evidence to say yes to this question, your claim doesn't get paid. So, I mean, we talked about that too, where.
Companies just pretty much sit on the sidelines and don't do anything, and and think that they can rely on insurance. So, I think that, unfortunately, for most companies and most people, it's and it's going to be an expensive catch up. And unfortunately, it's just, you know, you could do some of it yourself, but it's. I've used the analogy before. It's like building a house.
Could you build the house? Sure, you can go build the house, but it might take you a really long time. Or you can hire people and get help. You know, and the more people, the more resources you put in it, the more money you invest in it, the faster you're going to get that house built. And I think it's the same kind of analogy with this. That if if you're going from a zero with security, you know, we talked about the Spur score for defense industrial based companies and the CMMC, and you know how.
When that order came out, and the the D far seventy twenty executive order came out, and they were like, "Okay, you need to upload your Spur score." Well, there is still people that haven't even uploaded their score, and and I would say, I don't know what the the real numbers are. I would say still most people have gaps and deficiencies from that one ten, and they don't even know what their gaps are fully because they haven't paid to have an external test done.
So I think that there's still a mess there, and I think the hackers know this, and that's why this stuff is on the headlines all the time. Yeah, I mean, we've been pushing a lot of our security focused computers or security focused clients into you know cloud environments, right? Like it's much easier for you to assign all your endpoints, or you know have somebody bring their own device, whatever policy you guys have in place.
We've been pushing a lot of people into cloud environments because you know it's much easier for us. It's the pure cloud environment, not a public cloud. Right, right, right. Yeah, private, private cloud, cloud computing, and and and so it's much easier for us to throw a bunch of resources at a server that we manage already. We have already all of the you know equipment in place, the hardware, the firewall, everything is kind of already built up, and then just say.
Hey, let's just host you, right? And so all of your users will log in from whatever endpoint they have. They get the exact same desktop, you know. They access the exact same piece of hardware, and they're dividing those resources. And it's so much easier because even from the HR perspective, where you know, unfortunately, a lot of companies have turnover, and think about what it takes for you to get.
Your your your device is back. Like, okay, Johnny got fired last week. Johnny is still using the computer we gave to him, you know, a while ago, right? But even from the the HR perspective, all it takes is for you to lock them out of Microsoft and you know Active Directory, and then they can't access their computer, and then they're like, oh, okay, you know, so.
Um, it just makes things a lot easier, right? You know, you're securing one piece of hardware versus, you know, seventy nine laptops. Like, you know, we've been pushing a lot of to kind of stem off of that. I think the picture that you're trying to paint here is that instead of having seventy five endpoints out there scattered across the world on all different home networks or corporate networks, just all over the place.
And routing all that through different firewalls and routers and different equipment, put it all in a data center that is a secure cloud, custom-built environment that has all these layers that we're talking about. That's certainly an option, and that makes administration and management, maintenance, everything easier because it's all in that secure bunker, and it's all you know controlled, and you have all these layers in place to protect it.
And it makes management, like Blake was saying with that example, you know, if you hire or fire somebody, you're not talking about data being out there on equipment somewhere. It's all protected in that that area bunker. And you know, with public cloud solutions like Microsoft Azure or Amazon has a Gov Cloud option, Microsoft has a GCC High option. There are certainly options there, but.
You know, we talked about vendor risk management too. You know, if you put all your eggs in a public cloud like Microsoft, and you're using something like GCC High, that might be a fit for your company. It's expensive, whereas a secure private cloud option still be still should be a contender to look at seriously because.
You can still have redundancy layers built into your plan and continuity, where you're not just all reliant upon that cloud solution. You could have a hybrid solution, and this is how you have to think. You have to, you know, Microsoft's gone down. You know, they've had outages. So I'm not saying not to go with Microsoft. What I'm saying is that you can't just trust that. Oh, Microsoft's going to always be available. You have to prepare for the worst and assume the worst.
Wake up one morning and Microsoft, you know, they're offline. I mean, think about it. The hackers are probably trying to hack Microsoft and Amazon as we speak now, right? So it's you can't think about it as a matter of I'm not going to get hacked anymore. You have to think about it as I've either been hacked or I'm going to get hacked, and how am I going to handle the situation? So, from a business perspective, if you're investing or trusting that, hey, I'm going to put all my my my systems with this cloud provider.
You need to think about a redundant design. Where what happens if that provider isn't available? What redundant paths do you have? You know, and that's that's one of the things that we do in in consulting. We we help evaluate the scope of the business and the different redundancy options that are available to the company. That if this happens, then you can do this, or this is how you work. You know, you're not just waiting because if you're a really big company and you've got all these people on payroll.
And you have a big outage like that. That's huge as far as outages and money lost. Like you were saying, eight point four billion. I think you said for MGM. Eight point four million million a day, right? Eight point four million, not billion, million. Yeah, I mean, and there was even talk about circling back. There was even talk about people not being being paid. Like there there was talk about that. I think they were able to figure it out.
But imagine that if you've got thousands of employees, something happens. You know, you're not able to pay to pay your your best employees that work super hard for you every day. What do you think is going to happen? They're going to be pissed. They're not going to be able to pay their bills, and they may possibly even leave. You know, to somebody that will pay them. And I mean, obviously, is.
I mean, it all goes back to to right. Who's at fault, right? Obviously, you know, we could point the finger at the hacker, saying, "Hey, they should have been doing the right thing, and they should have," you know, you know, we've never we've never said that, but, um, you know, MGM, like, what are you doing? You know, this is your your most important asset, and.
Your your most important, you know, profit your your your profitability lives with your customer data nowadays. You know, it used to be different, right? Your intellectual property was what created the value of your company. But look at a company like Facebook, who has you know very little intellectual property, but has so much customer data, or Google. Google has a lot of IP now, but.
You know, Google was valued because of how much information they had about their customers, and that is totally hundred percent Facebook's model. They want to know who you are. They want to know everything about you. That you are their product, right? And having your data is priceless because, with understanding the data that they collect from you, they understand.
What motivates you? Your buying patterns, your habits, all of that - it's like you know an infinite streamline of profitability. Because you know they can understand who you are, what drives you, what your decisions - you know your what processes you make and your decision-making abilities - and I mean that's where the money is, right? Your your customer data is now the product and the profit.
Well, you yeah, you are the product, right? Yeah, yeah. Sorry, sorry. Your customer data is the product, and you are the reason why they profit. Yeah, and I mean, like you said, with Facebook and some of these other social platforms, I mean, why do you think the memberships are free? Because you're in the policy. You're basically saying.
You can track me. You can do all this stuff, and it's all buried in the terms and conditions. And that they're harvesting and mining all that data on you to create a profile, a social profile. I don't know if you remember Blake, but when the last election, I think that there was a a stat. I think it was over five thousand data points. I'm sure it's way more now. But the stat was over. These companies, social media companies, have over five thousand data points.
On people, that's constant. That's insane. It's insane. I mean, and and it's that was years ago. So I'm sure it's like fifteen or twenty thousand or more. You know, and it's like there. I think Google. I saw a headline. They got fined. I think it was in California for their location tracking. Did you see that? I yeah. There's so much to keep up with. I I probably saw it. Just probably.
Yeah, another one. Yeah, well, it's you know, like I said before, even from a personal perspective, you as a consumer, as a listener, there's more that you can be doing. And assume that you've been hacked and prepare yourself, because if one of if your information's out there.
And it most likely is from one of these big company breaches, Equifax, and all you know, all these big IRS. You know, all of our stuff is out there. So you have to have technology, and again, layers on your your social security number and your date of birth, and all these personal components, as well as your health information.
You have to take control of that information, and ultimately, you can't trust a provider or a company to keep it secure. Because, I mean, look at the headlines. I mean, these are big companies that are getting hacked and breached. So, you have to assume the worst. And, you know, one of the things that was interesting to me with the the with a lot of the popular breaches, including Equifax, they weren't even using encryption. I mean, I don't know enough about the.
The forensic outputs of it, but my point is that there was a lot of people that wrote about this and said if they were just using encryption, then the hackers would have got an encrypted payload. Well, think about that from your email perspective. You know, people still send sensitive information with plain text email or unencrypted text messages. You know.
So, if you're a consumer, you need to be using encrypted products. That encryption should be something that you standardize on for yourself, and obviously for your company if you have one. But you need to do your part too, and make. And a lot of this stuff doesn't cost money. You know, a lot of it's free to harden yourself and and make yourself more secure. So it's just boggling to me that some of these businesses that are just household recognizable brands.
Are getting hammered, and yeah, I understand the target is bigger on their back, but I feel like there should just be so much budget to help do more for security and just have as many layers as possible. And hopefully, one day we get there. But I don't know; it's it's just it's pretty alarming to see all these headlines.
Yeah, I mean it's scary, and there's there's a lot of probably listeners out there that probably aren't Fortune 50, Fortune 500, maybe small businesses, mom and pops, or even home users. And there's a number of things that typically I will follow and implement to keep yourself secure that really don't cost really anything or a lot of money at all.
You know, one of them is obviously, you know, making sure that you know you have a firewall, right? That's pretty important. Things that I consciously do, you know, habits, is whenever I leave home, I turn my Wi-Fi off, right? Turn my Bluetooth off, right? Unless I'm utilizing it. There's other things that you can do, such as go to, I think it's privacy.com.
Um, and you can go there, and essentially it'll generate like a fake credit card, debit card, whatever that. Essentially, you can charge back to right your real your real debit card, credit card. So, you know, be careful about how you use your credit card information online. I I lock all my credit cards like whenever I'm not using them, like they're always locked. So, like if anybody tries to run my card, they're gonna be like, oh, declined until I physically.
Toggle it on my phone, and then of course just being conscious. Just to add to that, you can get like an RFID wallet or a fader bag. You know, these are things that that were so like foreign to most people. I don't know if a lot of our listeners know what those things are, but the point is that there are products out there that are very inexpensive.
That will secure you on your person, like what Blake was mentioning with credit cards. RFID wallet protects from somebody trying to sniff the credit card in close proximity to you. You know, using a Faraday bag, you could put your car keys in it. If you have a car fob, you know, there's there's repeaters out there now that'll take that signal if it's not in a Faraday bag and unlock your car. You know, there's all these things that we have to think about.
I don't know if you saw Blake the the NSO Pegasus malware resurfaced a few weeks ago. Yeah, Apple had a huge rush to patch a bunch of zero days. Google rushed to patch a bunch of zero days. Microsoft. What what I thought was cool was Apple released their new lockdown mode. Did you see that?
I did. You know, they don't charge for that. That's free. You can use that, and I've been testing it for a while now. Is it? Does it make your life a little bit less convenient? Yeah, it does. But again, would you rather have less convenience and much harder for yourself to get hacked, or do you want ultimate convenience and have no security? It's always that balance, right? Of security. Same thing at your house. You know, you can have.
All these locks and cameras, and I call them layers. You know, you could have alarm stickers and alarm sign. You could have a dog. You could have all these different layers to protect yourself. And the more stuff you have, when you're getting profiled, and believe me, you are. I mean, we're all getting profiled all the time. People are driving by looking for the lowest hanging fruit and the easiest house to break into.
But hopefully, you are listening to us, and you're taking some of this information seriously, and you're making yourself more secure, so that when they drive by or when they're next to you in line, they can't use their tactics on you. So you made yourself more secure by implementing some or more of these layers, or in in my opinion, as many layers as possible. Yeah, yeah, and I I was even going to add to like.
Everybody communicates with somebody through some digital means every day. You know, whether you're writing your wife or husband or friend or whatever. You know, even using communication methods such as WhatsApp, Signal. You know, those are super important. You know, obviously, be conscious of sending passwords. You know, or anything like that. Credit card information.
Um, and then you know the easiest way that will take effort, but but think of yourself as like, what message am I sending out to you know these bad actors? Um, you know if you have a you know an expensive vehicle and it's parked in your driveway and it's not parked in your garage, right? You know, like what?
Message are you sending, and then, you know, of course, if you, you know, just look at those things and and you know the things that you wear. Even you know if you're wearing expensive jewelry or you know designer clothes, and and I mean, think about that. You know, that's where it all starts. Like you know, reverse psychology. Think about what you're what message you're sending out. Am I a target?
You know, I'm wearing a literally a Target T-shirt, but I'm not a Target. You know, so, um, so thinking thinking backwards, right? You know, like what messages am I sending out? You know, like do I stick out? Right? Do I look like I would be an interesting target? We talked about this. It's almost like self assessment, a self assessment of yourself, and then a self assessment of your house or your family, and a self assessment of your network at home.
Your habits, yeah, yeah. Your company. I mean, obviously, self assessment is going to be a lot cheaper and not as effective as a third party, you know, professional. But you know, you you could do your own plumbing at how at home if you watch some YouTube videos. And sure, yeah, you can make yourself a little bit more secure. But if you hire a professional, it's a whole other level, right? Um.
And that's why we talk about this all the time around testing and filling your gaps and retesting to make sure that you really fix something that was found. And it's just this constant improvement of security hardening. And that's what you know we're talking about. It doesn't necessarily mean a constant spending of money. I mean, yeah, fortunately, it does cost money. You know, to to put certain layers in place that are vetted and tested solutions.
But some of the solutions, the most powerful ones, don't cost any money, and it's just a matter of proper implementation and testing that they're they're put into place well. You know, like a simple setting that you can change in your email is to use h is it's not no longer use HTML and use text, plain text. You know, obviously, don't click on links in emails.
Even if it looks like it came from a trusted source, you know, if you see a link in an email and it says to go to your bank, don't click the link to the email to go to your bank. Go manually to your bank using a known, you know, shortcut or something that you know that is perfectly typed, so that you don't get, you know, tricked into typing something wrong, and then that's how you get into trouble.
Even looking at the headers, you know, as we go to topics of emails, like looking at the headers, like you know, sometimes they'll spoof the headers. That'll say, "Hey, it's from this person," but then here's the email that it comes from. So, you know, if you're getting an email from your bank and you didn't request any emails from your bank, okay, that should be red flag number one. Red flag number two is it says it's from your bank, but it's from John Doe thirty two at Gmail, right? Or
Um, you know, even something. Um, I've even read a lot of these corporate companies are addressing their customers and and and the headers. So it's like, hey, Craig, hey, Blake. Um, instead of saying hello, slash, da da da da. You know, I mean, it's it's those small little things.
That you know the de the devil is really in the details. But see, that's a huge training component. Like we know, and we've said this many times to all of our listeners and fans: email's not secure. Okay, so if if again we assume the worst, and we assume that you know, if you go to a reputable physician and they um.
Try to communicate to you. If they're HIPAA compliant, they should be using a patient portal or an encrypted patient app. They don't email you saying, "Here's your test results." They make you log into your portal. So, if we assume that, hey, look, this is a training or an educational component to our listeners, email's not secure. It's a fact. So, don't click or do anything or send anything that's sensitive with email.
And use portals and use these systems, and just know in your head, drill and test yourself that my bank is not going to communicate to me via email. So, so you know when you get an email that looks like it came from your bank, it's a phishing email, and you know what I mean. Like, so it's again, it goes back to training as far as like mindset, right? Same thing on your iPhone or your Droid device, you know.
It's it's about constant training and testing yourself, and this is obviously at the people level, but but also with your business. To elaborate, too, and to to push a final point, like something that really nobody talks about is updates. Like this is the simplest one: Microsoft, Apple.
Tells you you need to update. Oh, I'll do it later. I'll do it, and then you forget about it, right? Because it's not really at the top of your priorities list. I make it a habit to check my phone at least once a week and make sure my software is up to date. In my computers, of course, you know, all my computers - Windows, Mac, whatever - check them at least once a week.
Um, and then go through and update your apps, right? Because hackers are getting in through those older backdoors, not the newer ones that are being built. Every app, every every software application on your phone, every every software application on your computer, your endpoint, everything's a door, you know. And if you don't.
Update those apps and keep those doors secure. That's how these hackers get in from, you know, an infected library from this app or from this software vulnerability. And like Blake was saying, you can't. You have to manually do this. You can't rely on the auto updates to work. I mean, sometimes they work, but they're not perfect. I've met. I don't know about you, Blake, but many times I've manually checked, and I have auto updates turned on on certain devices.
And I'll find an update, and I'll be like, "Well, thanks, auto update." You know, right? You know, yeah. You have to manually do this and get into that that habit of doing that. And like you said, not just for your phone or your endpoint, but for your operating system, for all your applications. And you know, one tip that I think is a good one is if you're going to do banking on a computer.
Make sure that that computer is super secure and updated and patched, and do these things before you do your banking. Like, if you Chrome, for example, and you're about to log into your bank, make sure Chrome's up to date. Like, check it, check the update before you log on to the bank. You know what I mean? Like, this is your part. Like, if you want to do this on your own and you want to roll your own kind of solution that's inexpensive or free.
Then these are things that you have to get in the habit of doing. If you want to pay a company to do it for you, then that's that's up to you. That's that's your option. But my point is that a lot of this stuff it doesn't cost money, and it's a it's a habit that you have to just constantly do. And you can make yourself a checklist of all these things that, and then maybe maybe you're able to pallet that that checklist.
Or maybe it gets too long, and you're just like, I just can't keep up with this anymore to do all these things. And that, but again, that's your choice, you know. It's not, it's not really designed like it used to be anymore, where you'd have to go in and check manually for updates, you know, like Craig alluded to. But if you're downloading apps through the App Store or the Microsoft Store, or even the Google Store, whatever, I can't even think what they call it right now.
Um, but it it tells you and it checks the inventory on what you have on that device, and will tell you what you need to update. And you just press one button, one button update all, boom, done. You know, and then of course you'd have to press another button, boom, check the operating system. All right, here's the system updates.
Run those. It's really that simple, you know. I mean, it's not designed to be complicated anymore. But it's also a rinse and repeat operation. When you do all those updates, you need to restart your device and then check for updates again. Because guess what? There could be updates to the update, and we've talked about that. And you keep doing this over and over and over until it finally says there's no updates, and you double check all your apps, all your OS, everything on that thing, and.
Obviously, if you've got a hundred apps on your device or your endpoint, your computer, your phone, and you're doing banking on that, well, I mean, that might still not be the best idea because now you have a hundred windows that you're having to secure. You might want to use a different device that maybe has a handful of apps that you make more manageable to keep secure because it's a whole lot easier to keep a a device that has five apps or software applications on it, just like core applications.
Than something that has a hundred or more, and I mean, think about it. If you guys are using modern firewalls at home or in your business, I mean, do you unless you have that technology, do you really know how many devices are on your network? I mean, it's pretty scary how many devices want to connect to the to your network nowadays to get online and get updates. So it just kind of snowballs into this huge job.
Yeah, yeah, a thousand percent. And it goes a little beyond that, right? Like just alluding back to good practice, good knowledge, good awareness. Not everything costs money, you know. It's just more about how you think about security.
You know, you're not gonna go outside. You know, wearing your most expensive jewelry. You know, if you're going to a a third, you know, a third world country or a country maybe you've never been, or you're traveling overseas, you're going to Los Angeles where anything uh below nine hundred dollars can be stolen with you know with zero repercussions. You know, um.
It's just thinking about those things, training yourself, having good cyber hygiene. You know, like you're not gonna go garden, you know, and then come inside after gardening for two hours and then eat a piece of pizza with your dirty garden hands. You know, you're gonna wash your hands, right? You know, just looking and thinking about these things.
It really comes back down to your health, you know. Your health, your financial well-being, like all of these things, kind of circle back to one little harmony of of how you present yourself on the internet. And you know, there's a really simple solution. It's just don't have internet, right? You know, but that's not possible anymore, right? So, well, and I think, like I said before, I think the theme of the podcast has been kind of.
Try to do more on your own, but also test, test, and retest. You know, like with the example we use with the house. You know, back in the day, padlocks or or deadbolts used to be the big thing, right? But you have to think about security as what is it really buying you? Is it if you have a lock on your front door?
And you have a lock on the back door, and wherever other entry points you have, we're talking physical security. If somebody kicks in the door, does your lock stand up to that type of attack, or does it just get kicked in and then you know the the criminals are in your house? What other layers do you have? Like we talked about cameras, you know, we talked about the dog, we talked about.
Stickers and just all these different layers. Well, if you have a weak layer in this analogy or scenario, the lock, and you have something else like a tap on the door that triggers the alarm, and then you also have a camera. Well, you're more likely to catch that criminal than if you just relied on the lock. And that's kind of my point. Like.
With email and with the internet and surfing the internet and doing banking online, assume you're infected. Assume that you have malware on your computer that's watching you through your camera without your knowledge, and assume that you've got malware that's capturing your keystrokes that you're typing in. Assume that your passwords are compromised.
What are you doing to number one, monitor and detect that type of activity, and what are you doing to again add more layers into that? I mean, there's very, very inexpensive technology that'll scramble and encrypt your keyboard inputs, which is super powerful. There's hackers that have been known to turn on the camera and snoop and turn on your microphone.
But if you don't have the technology to detect that, how do you really know if somebody is not looking at you, or spying on you, or listening to your conversations? If you don't have the software or the technology to detect that, how do you really know? You can't just trust. Again, we're talking trustless, right? We're talking we're in a world now where you can't trust a certain company, vendor, whomever. You have to take this into your own hands and do more yourself. So.
Just know that there are solutions that we've worked hard to vet and test, and we have a stack of solutions that's over thirty-nine layers long now. And we're not vendor-tied, and we're not paid to say we have to recommend this one thing because it doesn't work that way. You know, we only recommend and we only use what works, and we have a lab that we test our solutions there. And sadly, they all don't cost; they're not all free. You know, unfortunately, we didn't make or manufacture all of them, and so.
We're not the sole provider of them either, but part of our job is to help our listeners and help our customers, and we want to give you guys the best options available. So that's why we do it. We do it to try to make you as unhackable as possible. Yeah, yeah, and sadly, it it it takes one of you listeners out there to experience something like we're talking about.
For you to shift your mind into, hey, I need to think like Blake and Crag are talking about. I need to think more of a security-focused mindset. Um, you actually don't have to wait. Like, you can you can do this now. It's better to be proactive than it is to be reactive, right? And everybody thinks about it in the same. We talk a lot about health, you know.
You're going to your yearly checkups. You're going to your dentist. You know, you're doing these things so that way they can catch something early, right before it becomes too late, right? So, thinking about that in technology, in cybersecurity, obviously, we're here to help. Like, you know, we're we're there's no.
There's no monetization on this podcast. We are here to dedicate our time. We are here as a resource. We are here to be helpful. Um, you know, if there's anybody out there that has any questions, our contact information. There's a, you know, you can fill out the form on our website. It'll go directly to me. Go go directly to Craig. Um, you know, we're religious. We check our emails every two seconds. You know, we'll reply back as as soon as we can.
And, um, and if you need some type of custom solution, you know, we can of course architect that, right, and and build something for you. Or if not, you know, we'll just say, hey, look, here's a few resources that you can use, um, that we would suggest, and that only really costs nothing, you know, to a degree. It.
It just takes you reaching out, you know, and having the courage to reach out. Like, like we promise. Like, it's not like we're gonna say, "Oh, Judy, Judy here isn't secure, right?" You know, ha ha ha. Like, yeah, I hate that. It's really like that. But there's no shame in being insecure, right? Because a lot of you aren't.
Sadly, but you have to recognize what you're doing, and you know. I take pride in helping people that realize that something's wrong. We both do, you know. And and coming to terms that you're not doing enough, you know. And you know, I'd say 99 of you aren't. Sadly, I hate to say it, and I'm not.
Being spiteful or bashful, but it goes back to the same thing we talk about: health. You know, like it takes going to a good doctor. You know, it takes understanding your body. It's much easier for you to understand your body than it is for you to understand your your computers and your your cybersecurity, your your your technology infrastructure. It's just not something that a lot of people.
Know how to do, and sadly, everybody that that goes to school, you know, we're we're an understaffed industry. Like, there's not enough cybersecurity professionals in this world to prevent incidents like MGM from happening. You know, like there's just not enough of us, and you know, we we are literally a dime a dozen. You know, so.
We're here, you know. Just all it takes is for you just to click one of the links and and send us a message, and and go from there. You know, we are surprisingly affordable for for what our our customer needs. We always are assessing market values of of services and how can we figure out how we can provide the same solution.
At a smaller cost, like that's Craig does that almost every day. Looking at new vendors, looking at new technology, testing. I know he's always testing new technology, new software updates, patches, bugs, and and just figuring out what is the best solution for not only a small business such as yours.
Um, or even a home user, right? There is technology out there that is affordable, that is reliable, that isn't hard to set up, that doesn't take complex knowledge of networking and IT systems to get going. It only starts with you and having that mind frame of I need to do something about this. So here's your chance.
Yeah, and and don't wait. I mean, there's always something that you can do or improve right now, and make yourself as unhackable as possible. Yep, and I promise, guys, I'm going to keep beating Craig up for for doing more podcasts. We're going to keep this going. We we really love doing these. You know, there's been a great response, and we appreciate everybody who's.
Who's an avid listener? Who's who sent us emails and messages and asked where we were? Right, we're we're back. I think for sure. It's just hard, you know, because of the same thing I just talked about. You know, we are a small team. You know, we have a good portion of clients that rely on us almost every hour of every minute. So.
So yeah, we we definitely need to to focus here as well and help help more people. Um, and and that's what we're going to continue to do. I think. Absolutely. Well, thank you guys. Thanks for listening. It was a good one. Yeah, yeah. Maybe I don't know. Let's maybe once a week. Is that the goal? That is the goal. Yeah, and maybe even sprinkle in some shorter episodes too, like.
You know, short five, ten, fifteen minutes. We might do something like that too, to kind of cater to the the folks that want a shorter, more concise episode. If if we're not uploading, guys, send us those emails too. You know, just keep keep let us know you want us to keep going, right? So that's right. All right, guys. All right, until until the next time. All right, take care.
Alright, that's a wrap on this episode of Encrypted Ambition. Subscribe wherever you listen, and if today's guest inspired you, leave us a review or share the show with someone in your circle. To learn more about how we support innovators with AI, cybersecurity, and compliance, head to PetronellaTech.com. Thanks for listening, and remember, the future favors the bold.
Never miss an episode
New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.