5 Tips To Prevent Cyber Attacks

Listen to learn why bringing work computers home and social engineering make for a disastrous combination.

Updated:  
October 12, 2023

SecurityMetrics Podcast | 16

5 Things You Can Do Now to Prevent Cyber Attacks and Data Breach Damage

“It’s our friends and family–our moms and dads–who shop online and are affected when a bad guy gains access. So we take it personally,” said SecurityMetrics SOC/SIEM Director, Heff.

Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) continues this sentiment by saying “When businesses go down, people suffer. Every business we can protect helps elevate the quality of life for the people who are associated.”

At SecurityMetrics, we monitor the threat landscape around the clock. And currently, that landscape is not only vast, it’s complex. Never have companies faced so many challenges, and hackers know it. Data protection measures need to be based on our new global landscape and the latest threats.

Heff (SOC/SIEM Director) and Forrest Barth (SOC Analyst) sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss the threat landscape in depth and cover the five most important things you can do now to prevent an attack. Listen to this episode to learn:

  • What the “Fujiwhara Effect” is and why it can make cybersecurity feel overwhelming.
  • New terms and trends demystified: cyber empathy, vishing, endpoint definition, and Zero Trust architecture.
  • Why bringing work computers home and social engineering make for a disastrous combination.

Resources:

Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide

Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

5 Things You Can Do Now to Prevent Cyber Attacks and Data Breach Damage Transcript

Hi, and welcome back to the Security Metrics podcast. I am so excited today because I have back with me again, Heff and Forrest. We've talked to them before their wealth of knowledge about security from a SOC perspective. And given all of the craziness with COVID right now, given all the people that are working remotely and some of the threats and vulnerabilities that have changed because of it, well, most well, no. Both threats and vulnerabilities have changed because of it. We have a whole list of things that we wanna talk about that are gonna help people who are at home, trying to make sure that their home setups are secure.

So Yeah. We tried to put well, first of all, thank you for inviting us back. We're we're we love talking to everybody. And and it's Forrest and I have been very busy. And it's, it's been pretty exciting, the changes that we've seen since this whole pandemic has started.

Sure. And I forgot to you know, there are people who are just joining us for the first time today. Please do introduce yourself.

Sure. I I'm Heff. I am the director of the SOC operations, which is a acronym for Security Operations Center. And, essentially, we have a team of folks here, and we're looking for bad guys. We're looking for threat actors and on behalf of our clients.

And and we have Forrest. Forrest, do you wanna introduce yourself as well, Forrest?

Yeah. I am an analyst in the security operation center. So I, on the daily, am trying to to find the nefarious goings on, and nip it in the bud, help, alert our our clients to, anything fishy going on in their environment. So I get to dig through a lot of, really fun logs and try and find where things are going awry.

Such a great job living on the side of the angels. For people who who really are tuning in for the first time this week, I'm Jen Stone. I'm principal security analyst for Security Metrics.

And I love being able to do this podcast because, you know, there's writing reports and then there's talking to cool people.

And today Thank you for the coolness.

Excited to be here with cool people. So we have some, a few really key things that we can tell people about how do we protect. What would you state as the number one way to protect from threats right now?

I'll have to tell you that Forrest and I have seen a lot of things, and there's, there's there's a lot of trends going on right now in in the world of cybersecurity.

If I had to put number one out there I I don't know about you, Forrest. What would you say is number one right now going on in the world?

Personally, just from what I'm I've seen far too frequently is installing updates for me.

That is that is the thing that I'm going to hammer home the most.

Make sure you're staying on top of your updates, and the software that you're running does have updates available. You know, is it still supported, or is this some abandonware that has been, you know, not in service for the last decade? You find some crazy stuff that way.

And, Jen, you know, the thing that's really coming up time and time again, especially in twenty twenty, right now, is just the huge number of patches that that just keep coming out from all these big name companies. Right. And we we actually there's a really cool term called Fujiara effect, and it's when two hurricanes collide.

Oh, Fujiara. Fujiara. Yes. I've never heard of this. Okay.

I probably I probably butchered the saying, folks. But it's this where you have, you know, these major corporations, they're just putting out all these updates and patches. And for a lot of organizations and businesses, just trying to keep ahead of that stuff Right. Is a challenge. And if you could, you know, get to the point where you can automate some of that patching, and that helps.

Absolutely. I I talk to a lot of people who one of the things that I have to look at is where's your what's your patch state? You know, on the on your critical items, show me what what your, you know, history of patching is. And a lot of times, they'll say, well, we didn't patch because we thought it would break things, or we don't need this new functionality. Like, they don't understand that updates actually have to do with security. There's a there's a disconnect there.

Big time. Big time. And, you know, to kinda wrap up this this whole patching thing is we're we're really excited from a cyber perspective, the the future. And you talk so much about self healing endpoints, and, oh my gosh, if we could just automate all this patching, it wouldn't be such a burden on on businesses. But I think Forrest is right. It's just really getting that patch management under control. That really just seems to be the number one thing that we keep seeing time and time again with our clients.

So And do you think it's because it really is just a big job and really needs the the manpower at the job at the organizations just isn't there? Or do you think it's more of a misunderstanding about patching or what should be patched? Where do you think that disconnect comes from?

I'll I'll pivot to Forrest. What are your thoughts, Forrest?

I actually encountered a a really neat discussion about this just within the last week or so. I'm I'm trying to remember. It was somewhere online. Anyway, the the discussion was, a lot of the time, people are really hesitant to install updates because things have a tendency to break when they're installing updates.

And the hardest part of being a system administrator is if you're installing updates and everything is broken that, you know, is, an incentive to avoid it. You know, you everything's been humming along nicely, and you, you know, you don't wanna have to interfere anytime you can. So, a lot of the the discussion, evolved into, well, the only time that people are rebooting machines is once they've installed updates. So was it the reboot that broke it or was it the update?

Having the resources available, especially, trying to contact, say, like Microsoft or somebody. It's like, oh, your update broken. And it's like, okay, then Microsoft's will prove it. You know? And so it's a lot of headache for people, and, they just find it easier to avoid it.

And so in that sense, if it it does come as part of, like, regular maintenance and, kinda going into some, like, business continuity stuff, in the event of a restart, is everything going to recover from that? So, kind of some interesting points there.

And and to your point, some of the most successful groups that I've seen dealing with this have an actual sandboxing area where they say, alright. This is similar to our production environment or our our organizational work environment. We're going to start it there first and see what happens.

But it's really hard to have a sandbox environment that is super similar to your production environment because then you have additional people that need to to support that additional resources and licensing all of that. So, the whole patching problem, it it gets fed a lot of issues from different directions.

It cascades. And that's really what it comes down to.

So To the which effect was that?

The Fujairah effect. Yeah. Two hurricanes colliding. Yeah.

So Alright.

So so takeaway from that, patch your systems. It's really important.

You make a plan. Yeah. And absolutely you know, you get that patch management going, and it's this cascading effect. And that kinda leads us into number two in our opinion.

And if I had to choose number two and and tell everyone out there, organizations, businesses, no matter what size you are, it's about having a plan for business continuity Right.

And and getting that business resiliency, the the planning around that under control.

So Right.

And so what's what do they need to do to start that? What's let's say a company doesn't have any kind of business continuity. They haven't thought about resiliency. What do they do?

Forrest, do you wanna you wanna take that one?

My my opinion, focus on what you can't possibly stand to lose. A a great example of this is, I have a a family member that runs a small business, and they run everything off of a single computer with QuickBooks.

And, probably about every three years or so, I'll get a call from them completely panicked.

Their their QuickBooks is inaccessible, and they've lost, like, an entire year's worth of financial information. And, you know, what are they gonna do, kind of, you know, though that real panic scenario.

And so I've I've gone through multiple times and set up, backup systems and, you know, made sure that in the event something goes awry, we have a way to get that back. And so, you know, that safety net is very important.

You know, identifying what is absolutely irreproducible, you know, what is what is unique, and what, you know, is gonna take a week's worth of work to get back, but you can at least get it back. So identifying those things where it's like, we absolutely cannot afford to lose this. Otherwise, we just cease to exist as a company, versus, okay. This is gonna be more painful, but at least we can recover from it.

It. Exactly. Exactly. And there's there's terms for it, the RTO and the RPO, and I forget what exactly they're they stand for right now.

Sorry. But the two the two key metrics are how much information can we stand to lose if things go down? How how quickly do, like and the second one is how quickly do we need to reestablish? So, some some groups can stand to go for a long time, but they can't stand to lose any information.

And some are vice versa. Some of them have a little more latitude, and some of them we can't stand to lose any information, and we can't be down for any time at all. And those are the groups that do the the hot failovers as opposed to, hey. You've got your QuickBooks machine that if it fails, and then they can call for us, and you can get it going again in, a few days.

You know the quote that comes to mind so much in this category is failing to plan means planning to fail.

And or or is that right? Did I did I get it right?

Yeah. That's right.

Yeah. I mean, you know, if if you you're asking where to start. I mean, it really is about it is about knowing your crown jewels. It's about knowing which data in your organization is so important, and then you can start to build that resiliency and that planning all around there. You know, in twenty twenty, we've had a lot of changes globally because of the pandemic, because of all these other things. And so many organizations, they they put the business planning, the continuity planning, and the resiliency to the side. But now's the perfect time to start be thinking about things like doing your tabletop exercises.

Right.

Get your get your folks into the room and just start, planning on what happens if this server goes down? What happens if if this critical piece of data gets exposed?

Mhmm.

That's I think that's a key place to start. And it's and it's not just the tabletop exercises and and knowing that you're doing your backups and you're scheduling that stuff, But it's also looking at your your playbooks and your processes and your policies. Do we have policies or processes in place that could potentially cover if we get breached? And and a lot of companies don't have those answers.

I I and and I think that the key to that is not just having your security people in the room, but making sure the business is involved. And so a lot of times, I see where there is a gap of, well, we we did all this planning for the systems themselves, but we don't know enough about the business processes to know what's important, how quickly, or how much we can lose.

I think a a really great way of of, kind of simplifying that and easing your way into it is, instead of making it this big horrific ordeal, you know, just just presenting it as a, an across the organization exercise by looking at the headlines. What went horrifically wrong with some other company? What made the news? And then try and put yourself in that position if what would happen, for instance, if we were to get hit with ransomware, or what would happen if, you know, our shipping network was no longer available? Things like that where it's it's easy to just kinda drop yourself in place and say, how do we adapt to that? Can we adapt to that? Mhmm.

Yeah. Yeah.

So then you're not thinking of them all on your own. You can actually use real world scenarios that that are readily available to find.

Yeah. Exactly. Exactly.

It's not just a matter of if it will happen. It's a matter of when it will happen. So so just just that business continuity planning is so critical, and that's why we put it at number two on our list.

So So moving on to number three.

What would you say well, we have in our list. So maybe and not not to pressure you to go in order anymore, but let's just go along with our list. What's the third here that we can talk about?

Forrest, what do you think?

What is your external exposure?

Okay.

What what does, you know, what does the Internet see? What is what is some script kitty on the other side of the globe running scans? Do they are you are you, showing that you have an old camera system exposed somewhere? Are they gonna try and poke at it and hack that?

Or do you have a web server that hasn't been patched going back to number one? Is that gonna be their their point of leverage? So knowing what you have, on on that broad perspective of a a global view, that's that's exposed. And there the the barrier, is very low because anyone in the world would be able to see that potentially.

Right. With that with not even very much experience or knowledge or and and some pretty limited tools, you can find out what what is open there on the Internet. Right?

And that's what's amazing about all of this is that the threat actors love scanning, and they love scanning, and you should too in your organization.

Mhmm. Make that a priority. And it it may seem like it's not a big deal, but it really is. I mean, if you're not scanning and looking at your external exposure, it could really cascade into something real nasty real quick.

And I like what you said just now. I'm sure that you've seen this, Forrest, as well as people might have scanning, but do they look at the actual results?

Right? So that disconnect between having a report that you can read and is anyone actually reading it and responding to it?

Yeah. And, you know, it's, I would even categorize in there under external exposures. It's not just those, the scanning piece, but it's looking at your third party relationships, looking at your vendor contracts.

Right.

Do you have language in those contracts to protect you from breach notification language? Right. You know, now's the time. Before those contracts expire, start to be thinking about, do we how do we protect our data at rest?

Is it in the contract? Right. Data encrypted? Is it in the contract? I think that's really critical.

And that cyber due diligence is all part of that external exposure. So Sure.

And and, it's interesting to me, especially working with new customers. Sometimes I'll go in and I'll say, alright. Who are your service providers? Who are the vendors that we have to care about in terms of your security? And a lot of times, I'll say, we really don't have any.

Yeah.

It's not a problem.

And my and my response is, shut up. You have, like, six or seven. I I'll I'll list I'll start listing some that I think you have, and you tell you stop me when I'm right. And Right.

Because we can't do things in a vacuum anymore. Right? We we have the, we're in the cloud that there's a service provider. We have shredding companies that come in.

We have, third party SIMs. We have, all sorts of, tools that reside somewhere else on the Internet that we're relying on for our security and our environments.

And so realizing that, yes, those exist and that every single vendor and third party that we deal with is a potential risk for us Big time.

Then that has to be factored in.

And, you know, that kinda leads that's a nice segue into probably one of our other top things that businesses should be looking at, and that's just having an inventory. Mhmm. And the inventory is not just of what apps are in your environment. It's not just an inventory of what services are in your environment. It's what devices are there, which contracts do you have in place, which policies do you have about security. I mean, knowing just just starting off with an audit of what you have Mhmm. Is critical.

This is really hard.

It's it's not to be, poo pooed in any way. Especially, I go into a lot of, health care organizations, and I'll say, okay. Can you get me a list of your inventory? Like, just the beginning edges of let's start scoping your environment so we know exactly what we're looking at, what exists in it, what needs to be protected, and they don't know even where to start to find an inventory. Do you have any recommendations for figuring that out?

Boy, Forrest, I'll I'll lean on you here for just a second.

There was there was an app that I I had seen a few months back, and I wish I could immediately remember it offhand. But it's essentially, just a way of doing, network scans and and trying to map up those those relations.

There there's a few different options. There's some that are, like, port scanner based. There's some that, depending on the perspective, you could, for instance, collect, like, ARP tables from your your networking equipment, traffic flows, watching what traffic is going across your network and, you know, to where, from where, trying to get a a better idea that way.

There's there's so many different approaches you could go through and and try and track it down physically.

There's there's so many different ways, that that you could try and and, approach that problem because it's, it's multifaceted. And not just from a, like a computing equipment perspective, but also from, like, services.

You know?

You're you're gonna have to talk to, you know, multiple departments across the board, like, even your your receptionist, you know, who's familiar with people that are coming in and out regularly in the business. So, we have, you know, our our printer guy that comes in and drops off paper, and that's that's a potential, point. There's a cleaning crew, you know. Do you have a a business that comes in and does your cleaning for you? That's that's a a potential avenue.

There's there's so many aspects where, yeah, we're very interconnected, and and no business is an island for sure.

It's mind blowing how many different services are running in a business that they don't know about, how many different apps, how many diff even just your, knowing the end of life of your assets. I mean, so many businesses don't realize that Windows seven, not supported anymore, but yet we continually see that in our scans.

But we've always used Windows seven. Why are you telling us we can't use it anymore?

We didn't plan.

We didn't know. So now you know, and it's definitely time to take action.

But but beyond all those two, you know, again, that cyber governance piece. So inventorying your policies or procedures, do we have playbooks in place? Do we know what's going on? Have they been updated?

I mean, some some we well, we have a policy, but we haven't looked at it in three years, so we have no clue. So now is the time. Get the inventory do started. Look at everything that's going on.

So I like to ask people about their policies and procedures. I'll ask people, who actually are supposed to be implementing the the procedures, following the procedures, implementing the policies. And I ask them, how inaccurate is this? How far is this from how you actually do it?

And and a lot of times, they'll tell you it is night and day. And so trying to get them to update it so that it's an actually a usable document. So one of the ways I found that that makes it useful is you say, alright. Let's say that you were not able to come in for a month or six weeks, two months.

You're out of the picture, but you're coming back. You want the person who is there doing your job for you to do it so they don't mess up everything you've got going in, so you don't have a big ball of knots to to to come back to you. Right?

And it's a ball. It's a ball. It's a mess.

Yeah. Right. So if they have the right procedures to follow, it's gonna be less work for you when you come back. And so if you if you kind of think of it in those terms of how do I look at policies and procedures so that they would potentially be useful in some scenario somewhere.

If they're just an exercise to satisfy an auditor, nobody's gonna do them. Right? So think of it in a way that is actually going to be useful and make your job easier at some point. Could be useful to training, bringing new people on.

Right? So so just kind of a mindset about policies and procedures can make them a better document.

Absolutely. Absolutely. Yeah. Yeah. I I this is one area that I think having a terrible memory is actually a huge benefit.

My memory is utter garbage, and I will forget something, you know, in a in a couple weeks, and it's it's, you know, it's gone because I just have so much information that I'm trying to, you know, go through on a day to day basis that I can't just I can't just pick things out of the air and, oh, yeah. I remember that thing. So in in those cases, like, having that documentation there is a huge boon for me. It's like, what you know, I don't remember this particular thing. Let me go look it up. Yeah.

Having having those those playbooks, the way you can just go down the checklist is amazing, especially if you're in a very, like, high stress scenario.

Going back to that business continuity, if your, you know, server racks are down and your business is bleeding money, you're gonna be in a very high stress, state of mind. So being able to recall everything at at, you know, drop of a hat is, nigh impossible task. There's gonna be something that you miss. So having that written out so you never need to worry about it in the event that, you know, you you panic and you freeze. It's like, okay. What do I do?

Grab the book. It will tell me what to do. Awesome.

Right. And it creates consistency too For the people just doing day to day, it's best if you can automate things, all the things. Absolutely. Yes.

But there are still manual procedures that people follow. There was a company that I worked for, quite a few years ago that, had a very, very hours and hours long, release process. And and when we started digging into it, it was because different people were doing the release each week. It was a weekly release.

And they were doing it in different ways. And I said, all I want you to do is the next person who does this release write down step by step exactly what you do. And then next week, the guy who does it that time, tell me where there is a differential in in how you do it opposed to how the other guy did. So we were able to do a consistent procedure that reduced the amount of rollbacks that were happening regularly every time.

Oh, that didn't work. Dang it. Let's roll it back and, oh, what step did we miss? Oh, here we go.

Put it in there. Right? So these types of activities are super helpful and these are your procedures that and suddenly, it's not just a compliance thing. It's something that actually helps people with their jobs, takes the burden, of off of them because consistency is created.

That is a good segue into our next our next top favorite one. Excellent. I think the audience is gonna like this one more than anything.

It's all about digital empathy, in our opinion. And and if you had to ask Forrest and I, what are what is probably the most important thing? And it would probably be the digital empathy and your day to day cyber hygiene.

Mhmm.

And if, you know, if you have to categorize that, that's things like your passwords and, you know, multifactor authentication. And I I guess there's a perception out there. When people think of cyber, what do you think of?

Cold. It's cold. Difficult. Difficult. Yes. So hard. Why are you talking to me about these words that I can't remember?

And how am I even doing this job? What? Who hired me?

Why are they making it difficult?

Right?

You know, these cyber things, technology. And and and yet we've been in this for years and years and years, and we feel this way.

Just imagine how people who are not on the technical side of things day to day to day, how did they feel about this?

It's those cyber people. They're making our jobs difficult again.

Don't even come around. I don't wanna talk to you.

And, you know, I feel awful at times when you hear that from people. And that's not the job of cybersecurity. It's not there to make the business more difficult. We're not there to be the police department.

Sure.

We're there to to lift off. You know, we want the businesses to succeed Yeah. But we wanted to do it securely.

And and that's the challenge here. And I think if you asked Forrest and I to go down a list of cyber hygiene, your day to day Mhmm. You know, things that if you did these things with all these employees potentially working remotely, what would make a difference in their lives?

Right. So how do we bridge that gap? How do we bring more digital empathy into the, the hygiene side of things? Which hygiene we're talking about passwords.

Right? We're talking about multifactor. We're talking about the the regular day to day things that make everybody go, oh, why are you talking to me about this again? Right.

I've heard this a million times. I know I have to change my password.

Right. So how how does digital empathy help with that?

I I would refer to Forrest. What do you think? Because I've got a couple ideas here too.

I I I think it's it's interesting that I I I see a lot of people get very burnt out, when it comes to anything tech related.

I I, a great example is, my fiancee. I love her to death.

Anytime I I go to use her phone, I see she has, you know, three thousand plus notifications and instantly just my heart rate goes through the ceiling. How can you how can you keep track of everything that's going on with that? It's it's very overwhelming.

And, trying to to make sure that all of that stuff is okay is, a very tall order for sure.

And I think it's all about incremental. You know? It's not, how do you how do you eat the elephant? You know?

One bite at a time. You know? You just gotta take it bit by bit. And if that's, unsubscribing from some junk junk mail list and knowing that you're never gonna have to deal with that, you know, again, you know, any more emails from that provider, you know.

What takes two minutes now can save you ten minutes down the road.

Yes.

Yes. And, just just little baby steps, you know.

Like you, I live that zero inbox lifestyle, and it makes me so I can sleep at night. I'm not kidding you. I don't go to bed until I have ten or fewer messages in all my inboxes That's impressive. Which I have probably ten, eleven inboxes because I I need I need to have side hustles. Right? Of course. Of course.

And so, but the only way to do that is what Forrest was saying. But then when I try and explain that to other people, they're like, what are you tell I don't know how to get rid of this other like, they don't even know it. They don't even know that these tools are available to automate that whole zero inbox experience. Right?

So just like with multifactor, just like with passwords, just like with, you know, how do I get rid of all of this in my inbox? These are little things that people have to do every day, day to day, that if you give them a little bit of knowledge that's not frightening or overwhelming, that's I think that was a good word was overwhelmed. Yeah. If you give them a little bit of knowledge so that they can self manage things that previously were overwhelming, that it makes it, that elephant is just that much smaller.

And, you know, for an organization perspective, enabling multifactor authentication, that's the start of the journey and and ensuring the passwords are complex. But again, you know, you think about putting myself in the shoes of the users of every organization of business. And that's a struggle because I want the business to be secure, but I also don't wanna cause more undue burden and bureaucracy and and all those other things that go into not having digital empathy. And Right. But, you know, that's that's critical. This day to day cyber hygiene, doing the little baby steps to get your organization more secure, it starts with that digital empathy.

So Yeah.

I I'm glad that we talked about you know, I think we could spend a whole hour on digital empathy, the concept, and how do we, in real life, take action to to close that gap and make it so people are less overwhelmed and less burdened by cybersecurity. So cybersecurity is here to stay and, making it so that people can have it a seamless part of their business life and their non you know, regular lives. Yeah.

I think that's a it's a tall order, but I think it's something we could discuss at some point. So I think, hey, Hunter.

We should put that on our list. What do you think?

Right. He said, don't break that fourth wall, Jen.

So yeah. In a future time, let's talk more about digital empathy. I think it's an important topic. So, you know, that that kind of takes us to something else here, Arnold, which is the human side of things.

Let's talk about vishing. Alright. Do we have to call it vishing? Isn't it just fishing with another avenue?

Or Oh, we add another we add another letter in front of it.

Okay. You know, which we probably have maybe in ten years from now, we'll have all the letters of the alphabet in front of the word fishing. So we'll have vishing, zishing, dishing, mishing, nishing. I don't know. We'll just keep coming up with them.

Feel like I'm Doctor Seussing here. That's okay. Tell people what vishing is in case they haven't heard the term.

So this is this has been a huge trend, and vishing is really all about that combination of voice and fishing.

Have you got any vishing attachments on the phone?

Answer my phone.

Oh, see. That's the solution right there for you.

So I also haven't set up my voice mailbox.

If you wanna talk to me, you kinda have to either really know me well so that I'll recognize your number or send me an email because it's too easy to fall for things. Right? So I'm not gonna answer every phone call that comes through. I figure if it's an emergency, they know me well enough.

If it's an emergency that I have to be involved in, there's other ways that they can get to me. Right? Right. But if they're going to call me and be like, here's an emergency you need to respond to, I don't need that kind of energy in my life.

Well, what the threat actors are doing right now and and this has been ongoing for a long time, but it's only been recently because of the pandemic and all of these people working from home, working remote, is they're masquerading their caller ID. So you're getting a call, and you're thinking it's coming from grandma or somebody that you you do business with, and it's not.

Or it looks really similar to your own phone number. And so you think, oh, this looks a lot like my number. It must be a neighbor.

Right. Right? You know? Or they're they're even masquerading eight hundred numbers. So you think it's your doctor calling, and it's not. You know? And and what they're trying to do is essentially gain a doorway into your life.

Mhmm.

And the more doorways that the threat actor has into your life, that is what they're after. And, you know, for a lot of folks, the challenge is they think in their mind, I don't have anything of value. There's nothing on my personal computer or on my phone that has value. But the reality is what a lot of threat actors do is they'll they'll pivot from your personal life into your work life.

And that's where the trick becomes, where you need to be aware of that. So you may not think you have anything of value on your home computer, but the bad guy is doesn't know that. And he's gonna use whatever tool he can. And in this case, the human side of things is the vishing, the social engineering piece to try to pivot from that personal life into your work life.

Right. We And do you know why social engineering works? That that because it makes you feel a thing. Right?

Emotionally.

It makes you feel a thing, and you and you get a sense of urgency to do a thing because you feel a thing. I had a really good conversation with one of my nieces just this week about that, and because she was asking me great kid. And but a lot of the that generation, they have some knowledge of cybersecurity. They have some knowledge of what social engineering is, but it's still new.

Even for the cyber generation, they still are not familiar with how is it a negative thing. What are the bad guys doing? Right? We all need to learn this.

So I was talking to her, and it morphed into a conversation about, also, how do I use this to to to to understand what my friends are saying to me, to understand what social media is saying to me, to to understand what the news is saying to me.

So let me give you a great use case. So imagine, you know, you have a LinkedIn profile.

I do.

And I'm a recruiter from a fake company. I'm the threat actor. What I'll do is I'll set up a fake, PDF file. I'll pretend I'm from a major corporation.

I wanna hire you. Hey. I found your profile on LinkedIn. I'm gonna send you a LinkedIn I'm gonna send you a PDF.

Mhmm. Go ahead and, fill it out for me. Send it back to me. You didn't know that that PDF had some malware in it.

Right.

And the next thing you know is the bad guy now has a doorway into your life. And and that's the challenge for any business out there is helping educate your employees that everyone is the human firewall Mhmm. And we all are security experts. No matter if you're a line level employee, you're a manager, you're on the board of directors, everyone is a part of that cybersecurity team.

So the the the goal here on under human side of things is really focusing on the training piece, the education piece, the awareness piece. And, again, just because you don't think you have anything of value on your computer, the reality is the bad guys may think you do. And Yeah. And that's that's the key here.

Yep. You know, once you're aware of it, that's half the battle.

And once your employees are aware of it, so And and just remember, if something makes you feel something and you need to respond right away, that's social engineering.

Somebody got you. So just back away. Get some perspective on that. Don't respond right away.

Whatever avenue that that kind of, push came at you from Right. Right. Don't react to it. Set it aside.

And then later, when you're not upset about whatever it was or wherever it came from, you can come back to it and reevaluate it later.

Yeah. Yeah. A lot of, a lot of really successful social engineering usually, we'll, we'll try and feed off of our innate desire to help others or, reciprocity. So reciprocality.

There we go. Right?

Right. No. Yeah. That works. They're both right. It's good. It's fine.

The the whole thing is is reciprocal.

Right? So, so you get a you get a call from somebody and they're like, hey. I'm with your insurance. You know? We have this this, these documents that need to be submitted to make sure that your coverage continues.

You know, so the automatically, the stage has been set that this person is there to help you, and then you want to then help them help you. It really is exploiting our our, you know, desire to do good, with others. I mean, that's it's it's something that you see, with like, for example, with our car sale.

You know, I'll scratch your back if you scratch mine kind of thing. And, just playing off of those those relationships.

Right. That's why the Nigerian prince worked for as long as and it still does some place sometimes.

You help me and I will give you money for it. So, you know, it kind of what what we're talking about with the social engineering and you might not think anything is important on what you have, it kind of feeds into that endpoint protection concept. Right? So people are like, well, I'm on my home computer and it's not I can just I'm curious.

I'm gonna or I'm, you know, you know, worked up or whatever. I'm gonna click on this thing. It's fine. It's not connected to work.

But, sometimes people use their work computer for home at home now. It's more of a problem because we are all working from home. So how does endpoint protection help protect us from some of these, social engineering issues?

You know, there's a lot of security features. I think it's Cree, though. We probably should define what is an endpoint.

Yes.

And, you know, a lot of people are probably wondering what the heck is an endpoint? What does it do? I'm hearing the term. It seems like it's this new thing. It's been around for a while.

You're seeing it a lot at the enterprise level in big corporations, and now it's starting to kinda trickle down into small businesses and medium sized businesses.

Forrest, do do you wanna help me describe it in your most beautiful language that you can?

Any any number of things could be considered an endpoint, you know, your phone, especially with bring your own device things. You have a a company that, you then set up your work email on your personal phone. But are is your personal phone secure?

You know, the the work laptop that you've been issued, that's definitely an endpoint. What about, you know, the the home computer that you've been using to VPN in?

That is now brought in under the umbrella of endpoint as far as your company's concerned. So, there's there's a lot of things that could be considered endpoints. It's it's amazing the number of different devices that I see in some of these environments. People will have Internet jukebox.

Is there is there anything going on there? Why is that on the same network as, some of your cache registers? Things like that. That's a little scary sometimes.

I've seen, gaming consoles in in people's business environments, stuff that people have no idea, you know.

All kinds of, smart speakers, whether it's a a Google Home or an Alexa, things, you know, that's you start looking and you find all kinds of really interesting devices in these environments.

And and so, basically, an endpoint is anything that can communicate to the Internet.

And it can help the the each each of the boxes become more secure. I mean, that's the that's really the summary.

I mean, if you have unsecured browsers in your environment, a web browser that's unsecure, if you need to get antivirus updates pushed out and and get them on all the machines, If you need some sort of automation to get some of that patch management done Mhmm.

That's really where the endpoint shines. And you're seeing more and more growth in this market. It's gonna continue. You're gonna hear a lot more about it. Now with everyone working remote, and they they've got all these computers at their house, and they're they need that endpoint protection. So you're gonna hear a lot more about it. I I the key though with endpoints is realizing that for an IT department, they're very they don't have a lot of staff.

Mhmm.

They don't have a lot of people on the team to help them update and do all that kind of stuff. So anything that a business can do to help automate and, again, have that digital empathy to not create an undue burden on everyone's computers, that's where the endpoint really shines.

So And, Forrest, you you you briefly touched on something that I think is an interesting concept that I'd like to try to explain a little bit.

And that is if you have a gaming computer or a or a gaming system that can reach out to the Internet, and it's on the same network as your work computer.

So the security of this gaming device might not be the same as the security of your, work device. Why does it matter? Well, let's say you get a virus or some type of malware on this, gaming device.

It can possibly, trans transmit to the same to your work device if it's on the same subnet. Right? So think about let's say you have a Sharpie in your pocket and you put your pants through the wash. And then in the dryer, the the lid comes off and all of a sudden, your pants get all marked up, and then your shirt gets marked up, and then your wife's, dress gets marked up because they all happen to be in the same dryer together. Right? So it's like, malware on one device in a subnet can transmit to other devices on that subnet just like a Sharpie in the dryer.

I use the Sharpie in the dryer because I did I've I've done that a few times with actual Sharpies in my drawer. I'm sorry to hear that. So I know. Yeah. More than I like to admit. But, but a lot of people don't know that having them on the same network, if they're not both protected, can open them both up to possible issues. So it's important to really make sure you have protections on those endpoints.

But it also kinda makes us think about another concept that you, that you also had on your list, which was those zero trust networks. What if we didn't care about the subnet itself? What if we were so protected in our endpoints that we didn't have to to care about that subnet and and all being in the dryer together? Yeah. Can you speak to that a little bit?

Sure. The the whole idea of zero trust and and this is really just it's a term that's really been taking off as well. And you're gonna hear a lot more about this going forward.

And and Zero Trust is this, security model. And, essentially, it's for a lot of organizations, it's, we don't trust our employees.

But I don't wanna call it that. But but, you know, at the end of the day, you wanna do what's best for the business, and you you wanna kinda have that mindset of, nothing is secure. Nothing is secure. Inside of our network. Yeah. Even if it's behind our firewall, in the perimeter or not, nothing is secure. And that zero trust model then, it's a mindset, it's an approach, it's a a model, it's a form of architecture, it's a lot of things.

But, you know, for businesses that have never heard that term before, now's the time to kinda start thinking about it because you're gonna hear a lot more about it.

Coming up with a, a strategic plan Right.

For zero trust. And even if you're not planning on on purchasing any devices, buying any services, at least getting it on your radar to start having those conversations, now's a good time. And and, you know, part of that is that's that's what's nice about endpoints.

The future is you're gonna hear a lot more about self healing endpoints Right.

And things like configuration drift, which is a really cool term.

But at the end of the day, here here's what Forrest and I see. And what we see is we see advanced persistent threat actors. They're getting into environments. And once they're getting in, they're doing a lot of lateral movements.

Mhmm.

They get in. They make these lateral movements. They find something of value, and then they try to ex exfiltrate it off the network. And how they exfiltrate it off, they use a lot of different tools.

But once they find that thing of value and once that data's out there, you can't get it back. Once your crown jewels are exposed, boy, it's really hard to show it back. So and and seeing how long some of these threat actors, when they get on the network, they just sit there.

They Yeah.

They just wanna hang out, and they wait and they wait until they find a target of value. So, I guess the challenge to everyone in the audience is that everything we've talked about today, it's a lot. Yeah. But, you know, you start like Forest said, you eat an elephant and bites, and you just start picking off these things off of a checklist.

Yeah.

What what can you control and change and try to improve upon without creating undue burden or bureaucracy to the business, having that that digital empathy.

Right. So And and I don't and we joked a little bit about it. Zero trust is not really about not trusting your employees.

Right. Right.

It's real it's more about we don't trust old ways that we secured things.

Beautiful. Right?

Yeah. That's beautiful. So we had some old patterns where we would say, hey, if you have access to this group, you have access to this system and this system and this system and this system, they all get to talk to each other. Now we don't trust that they should be able to talk to each other. We don't trust that having a group is sufficient. Right?

So so creating, Segmentations.

Segmentations, microsegmentation, and and making sure that, access control is is just really nailed down, that's really more where we're where we're headed. So so just thinking about some of these new paradigms in I can't believe I just used the word paradigm. Somebody just yelled bingo out there.

We should do that. We should podcast bingo. Every time Jen says a certain word, you guys get a prize of all.

But but being able to look at how do we protect things and what's the new ways that we have to protect things based on new threats, based on new the new landscape. Right?

And that's a good point too. You know, you talk about role based protection and the zero trust. If you know a certain department in your company or your business has the potential to be attacked more Mhmm. Than other departments, that's where that zero trust can really be beneficial.

I mean, if you have a certain department that handles a lot of cash transactions or a lot of Sure.

HIPAA data, you know, you can segment them off and do some really amazing things to to stop threat actors.

So So when I travel, I take a a secured laptop that, I don't I don't leave any information on it.

But there are a couple of countries I travel to that are inherently more risky because of geolocation. And I don't take my laptop.

I take, a completely fresh, like, a Chromebook. Right? This is not about trusting me with the device. It is about the level of risk based on where I'm at and what I'm doing. But but but, Forrest, I wanted to hear about your perspective on that.

Yeah. I I like to look at the the whole zero trust model as, essentially, planning for the worst case scenario and trying to preemptively implement damage control.

If this were to get exposed, what could possibly go wrong, and how can we reduce the impact of it? So, a good example I like to use is, like loyalty cards or something. So you you sign up for a loyalty card, and now they've got their phone number. And what do they are they gonna sell that to a marketing list? Like, what's gonna happen with that information?

So, does the a lot of it is, trying to scope it as, is this necessary?

To what extent does it need to be, a thing and and evaluating the benefit. Is this even worth, whatever benefit we're getting from it?

Does the does it outweigh the risk?

So a good example, that I've I've recently started implementing is a catch all email address. So I have a I have a, an email address where essentially I can, send it to whatever at my domain dot com. So, gas card at my domain or, grocery card at my domain. And then if I start seeing spam rolling in, I know where that came from, and I I can then decide, okay. Well, I'm ending that relationship with you because you've violated my trust.

Right.

That's a good point.

Well, this is a really good list, that we've, gone through today for people. Is there anything that I've missed?

We could probably do four to five hours.

We I'm We don't have that kind of time.

We absolutely could. We would have to order pizza.

But it's always fun. And, you know, obviously, we'll do a lot more of these with you. Thank you for inviting us into your home and and letting us talk. And and we really we love finding threat actors.

We love finding bad guys, and and we love protecting you know, it's not just the businesses that we protect. It's we love just that passion to protect. You know, it's our mom and dad's. It's our family that shops at a lot of these Yeah.

These places that, you know, we take it personal when a bad guy gets Yeah. Access.

So And for the businesses too because businesses are people.

Businesses go down, people suffer.

Yeah.

And and so I take my my job very personally that way because I know that every individual who we can protect through better cybersecurity, every business that we can protect through business better cybersecurity, it elevates, the quality of life that the people associated have.

Yeah. I know that sounded super fancy, but I actually really meant it.

Well, thank you both for coming in. Forrest, always a great time time talking to both of you and have really appreciate it. Thank you for joining us once again here on the the Security Metrics podcast.

I hope you tune in again and also, I'm sure that you have people in your life who could benefit from knowing some of these things. I want you to think of who that is right now that needs to hear what we talked about just now. Send it to them. Share this with them. It's okay. Talk to you later. Bye.

Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.