Listen to this episode

Ten Cybersecurity Myths You Need to Forget Right Now

0:0041:08

Recorded April 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this April 2022 episode of Encrypted Ambition, Erin, Blake, and Dwight of Petronella Technology Group count down ten common cybersecurity misconceptions drawn from a USA Today article, while Craig is away on vacation. They argue that everyone has data worth protecting because personal information is the digital currency that platforms monetize.

The hosts compare relying on antivirus alone to locking your doors without setting an alarm, noting that hackers trailblaze new threats that existing tools do not yet recognize. They describe phishing scams that skyrocketed during the COVID-19 pandemic, extortion emails built from old breached passwords, and hacks spread through friends' social media accounts. Blake discusses the psychological side of hacking, and Dwight attributes many breaches to human error and negligence. The team also covers hospitals as targets, dwell time, breach notification duties in regulated spaces at the time of recording, and teases a future episode of eye-opening statistics.

Worth remembering

Key takeaways

  1. Blake argues that personal data is valuable digital currency, so everyone has information worth protecting even if they feel they have nothing to hide.
    “All your data's important and you give that away, that is the digital currency today.”
  2. The hosts compare relying on antivirus alone to locking your doors without setting an alarm, since it cannot stop threats that are not yet known.
    “That's like locking your doors, but not setting the alarm.”
  3. Dwight urges listeners to enable two factor authentication and to guard personal information closely, disclosing it only when a request seems legitimate.
    “make sure you have your two factor stuff going on. definitely have that because if they need more than one place to authenticate to get you into an account”
  4. Erin warns that hacked friends' accounts spread malicious messages, and anything seeking a strong emotional reaction is likely a hack, so verify through another channel.
    “Anything that's trying to get a strong, emotional response out of you as likely to be a hack.”
  5. Blake describes finding passwords on sticky notes during onsite visits and urges listeners to use password managers instead of reusing passwords or writing them down.
    “And then I go into their office and what do I see a sticky note on their monitor with their password?”
  6. Erin points out that dwell time matters, because a hacker who sits unnoticed for months gathers far more information than one caught in a day.
    “if you've got a hacker in there. for months versus a day, think about how much more information that they're going to get.”
  7. The team agrees that layered best practices deter attackers, since most hackers look for low hanging fruit rather than spending hours breaking through defenses.
    “but, you know, hackers, they just want to go for the low hanging fruit”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

We have seen and heard it all! On today's podcast, we discuss the most common cybersecurity myths and misconceptions that are out there.

You won't want to miss this!

Links: 10 cybersecurity myths you need to stop believing

Hosts: Blake, Dwight, & Erin

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.