Listen to this episode

MGM Cyber Attack, Personal and Business Cybersecurity Tips and Tricks

0:0053:17

Recorded September 2023. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode of the Petronella Technology Group podcast, Craig and guest Blake Rea examine the recent MGM cyber attack, which disrupted digital infrastructure across major properties and reportedly cost the company millions daily. They discuss how threat actors exploit human vulnerability and phishing to bypass defenses, emphasizing that security awareness training is often neglected despite its critical importance.

Craig argues against paying ransoms, noting that it merely incentivizes attackers seeking quick financial gains. Blake Rea advocates for a trustless, defense-in-depth approach where organizations assume breaches are inevitable. The hosts explore how private and hybrid cloud environments can streamline endpoint management and reduce exposure, while also offering practical personal cybersecurity habits. These include disabling unused wireless features, manually updating software, verifying email headers, and utilizing encrypted communication tools. The conversation underscores that protecting sensitive data requires continuous testing, layered defenses, and a proactive mindset rather than reliance on insurance or single vendors. Ultimately, the discussion reinforces that cybersecurity is an ongoing discipline demanding both technical implementation and consistent user education.

Worth remembering

Key takeaways

  1. Security awareness training is essential but often neglected because employees view it as a burden.
    “Everybody needs to be aware of the possible threats, and a simple program, you know, a simple a simple course, you know, lecture can.”
  2. Paying ransoms encourages attackers because they prioritize quick monetization over complex data sales.
    “At the end of the day, their time is worth money, right? And that's what they're trying to do.”
  3. Organizations must assume breaches are inevitable and implement multiple containment layers.
    “You have to assume that when you wake up in the morning, you've been hacked.”
  4. Centralized cloud environments simplify endpoint management and reduce the risk of scattered devices.
    “It's much easier for us to throw a bunch of resources at a server that we manage already.”
  5. Individuals can significantly reduce risk by manually updating software and verifying communication sources.
    “You have to manually do this and get into that that habit of doing that.”
  6. Cyber insurance no longer guarantees payouts without verified security evidence and compliance documentation.
    “They're not paying the claims anymore unless you have all the evidence to prove that you did what you said that you were going to do on the application.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

MGM Cyber Attack, Personal and Business Cybersecurity Tips and Tricks. According to Okta, Hackers who breached MGM and Caesars also hit 3 other firms. Learn cybersecurity tips and tricks you can use to security harden yourselves and your business.

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.