Young and Profiting (YAP) with Hala Taha: Entrepreneurship and Self-Improvement Podcast
Young and Profiting (YAP) with Hala Taha: Entrepreneurship and Self-Improvement Podcast

Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

2h ago1:13:3813,467 words
0:000:00

Entrepreneurs often assume hackers only target big companies, but small businesses can be easier targets than they realize. A weak password, compromised vendor, or poorly managed access point can expo...

Transcript

EN

There's a really famous story on the news, they created a dating app for wome...

but then turned out that app they took their passport details and all their information turned out this app was vime-coded with zero security, it got hacked and it put women's safety in danger. Wow. Usually women get targeted, like someone leaks explicit videos of an individual.

And well, that video is completely deep fake and it has been happening. They're always targeted.

The vulnerable, they always target the young. It is a problem. And we need some kind of a strict regulation. We're joined today by Abed Hamden, founder of GRC Mastery and content creator who's known as the Unix guy online. He brings more than two decades of experience in cyber security and risk. So we want to use AI, we want to be on top of the new technology,

but we also need to stop and think, what is it that we're using AI for? What does AI have access to?

And more importantly, where's my data going? What's one thing that entrepreneurs are doing where a hacker is going to say, this is just way too easy. Something I see frequently is a founder says, oh my god, we won't live last week. He wouldn't believe it. We expected 200 clients. And now we have 2000. This tells me that this team is extremely busy. They can barely keep up. This is a really quick tale tale that are other things that... How worried do we have to be

about AI agents and their ability to hack our companies or their cyber security threats? There are many issues with AI agents. The first one is... This episode is brought to you by Bit Defender, a global leader in cyber security. Have you ever received an email that looked like it came from a bank or a trusted vendor asking you to wire money immediately? Small business owners get hit by scams like this all the time. And one click can cost your

business everything. Bit Defender, ultimate small business security keeps your devices, passwords and team safe. Even if you don't have an IT team. Protect your business with Bit Defender ultimate small business security. Save 30% when you go to bitdefender.com/propheting. That's BITdefender.com/propheting. Now to help us better understand the business of cyber crime and how organizations can protect themselves. We're joined today by a bed hamden. A bed welcome to

Young Improveding Podcast. I am really looking forward to having this conversation about cyber security. I feel like all business owners need to protect their businesses. And with AI, cyber security is becoming more important than ever. But let's start at the very basics for the entrepreneurs tuning in. What is something that you think they fundamentally don't understand about

cyber security? Entrepreneurs usually make a couple assumptions about cyber security. I think first

the first assumption they make is about that attacker. So they think the hacker is this person in a hoodie in some basement or they go the other extreme and they think that attacker is suddenly sophisticated sort of spy agency or foreign government. And as a result of these two assumptions, they usually think, well, I'm an entrepreneur. I run a small agency or a small business. Why would anyone attack me and unfortunately of the businesses that I help,

usually after the fact? So they get attacked and they really sometimes underestimate the consequences of some cyber attacks. Some of them, unfortunately, can be business ending or it can have such a large cost that it may even be cheaper to just shut the business down. And this is huge everywhere across from small business to even medium size and in some instances, even large businesses.

Yeah, I always think of like really big companies like Meta getting hacked or big of America or

something like this. But small businesses actually can be attractive targets. Why is that?

100% in fact, think about it. If you were a hacker, if let's say you've just learned how to hack and you want to start legally hack, you naturally wouldn't go after Meta because that's such a difficult target. They invest so much in cyber security. They are at the forefront of everything technology. However, when it comes to small businesses and entrepreneurs, usually they're just focused on getting their product at, their overworked and most instances also underfunded.

So they can be caught and caught easier targets. But they also hold something really valuable. They hold what we refer to as privately identifiable information. So that's something that we

classify as a critical asset. For example, a lot of entrepreneurs will have something like

a customer database where they have the names and last names and phone numbers and sometimes the addresses. This is extremely valuable because what attackers can do, they can get that information and sell it on the dark web. It's actually extremely valuable. So that's a really key critical asset that lots of small businesses have. Unfortunately, sometimes they don't have the knowledge or the resources to protect that. The other thing and probably the more important

Thing that small businesses have is that, well, like I said earlier, it's may...

something like a big bank or something like Meta as you alluded to. However, the way to get into those companies is usually you hack their suppliers. So if that small business is a supplier for a bigger business, usually it's easier to attack that small business and use it to pivot or use it to trust. So if you can compromise the email account of a small business, will you can start sending

malicious stuff using their email address. In fact, that's how most big businesses get compromised

through their suppliers. And they're usually on the smaller side. So interesting. I never thought about

that. So he not only have to worry about our own security. We have to worry about the security that our vendors are doing for their own companies, which is just so crazy to think about. What are the main ways that small businesses are compromised? So we just talked about vendors for bigger enterprise businesses. How about small businesses? What are the main ways that they're compromised? So look, the way sort of hacking or compromise happened, that are actually so

so many ways. Most of them aren't even known to the public. They tend to be complicated, but the most common ways for, let's say, an attacker to gain foothold and tends to be the easiest way. It's what we refer to as social engineering. This is where the attacker pretends to be someone that

the business owner knows or pretends to give them something that they trust. So we really use

the old age sort of trust relationship that we humans rely on. For example, as a small business,

I could pretend to be one of their employees and send an email urgently say, "Hey, floss my account urgent, please click on that link and help me out." So we apply time pressure. So we call that social engineering or fishing, which falls on the social engineering. There are other sinister ways as well, but it all goes to all comes back to really pretending to be someone else. So fellow entrepreneurs and YouTubers, a really common reason to one is actually

pretending to be a brand and offering a brand deal. Yes, I get so many of those. I've even helped cyber security professionals who got hacked this way. And that's not a no shade on them. This is just a testament to how good some of those attacks are. They can really pretend to be a legitimate brand and a website look exactly the same. They might be just a slight variation on the URL. And sometimes it's something that your eye cannot see.

So some of the alphabets we can replace it with special characters and it's really hard to detect. So that's really common way. There are more and more ways. For example, if you have physical access to the business, there are things you can install, but that's a whole other story. But when it comes to sort of the most common ones, it tends to be 100% social engineering. So let's really unpack this with a real example. If you could really just walk us through.

Let's say there's a company that has like 20, 30 employees. They're using the typical things, Slack, cloud storage, zoom. They might have vendors, different SaaS tools. Walk us through how they could get attacked and some of the things that could happen and how could escalate. Yeah, I mean just before I say anything, just disclaimer hacking is illegal. What I'm about to say is for educational purposes. So please don't do it.

But hypothetically, if I was to attack this imaginary business, the first step I would do is

always reconnaissance. So I'll try to collect as many information as I can about that business.

This includes their linked impulse. So how many people work there? I'll even draw like an orcs chart. See who's who's the employee go on Instagram. They usually share everything. So I'll get a list of the individuals who work there, but more importantly, I'll get a list of the technologies that they use and also the product that they have. So once I get a list of that, the next step would be I'll start to craft things that they trust. I'm trying to social

engineer my way there because it's a lot easier for me like I said to get an employee to do something for me as opposed to me trying to hack Microsoft and get inside their email. So what I will do is I'll try to mimic what their email looks like. And now that's really easy. I can literally

vibe code that in like five minutes. You should take a lot more time. The second thing is I'll see

what vendors they use. So if they use so many SaaS applications, well, I could hypothetically go to the dark web and see if there is any information about those services. If there is a new vulnerability, it may not be patched. So I could directly go on hack one of their SaaS services and get into their network. But let's say everything they use is secure. Well, I'll try to then attack sort of target the employees individually. I'll usually target who may appear to be more vulnerable.

Usually it's very busy individuals, very busy founders. They are more likely to click on something really fast. Sometimes I'll even not I, but the hypothetically attack I may look at

Elderly parents and try to tell them they've won something because what happe...

is if the elderly parent gets their email compromised, well, I can use their email to send

stuff to sort of their kids. And they're more likely to click on them than if it comes from

an unknown individual. Now, the final one that is very, very effective with entrepreneurs and all the startups that I don't recommend anyone to do. But I could simply purchase the product that they have and be a legitimate customer and just give their customer support help. I'm like, it's not working, help me open a Zoom call. So the customer support individuals are very likely to say, well, I tell them my Zoom's not working, please click on this. So I can get them to click

on something and, unfortunately, support individuals usually have a lot of access. So as soon as they

click on something, I mean, and I can continue pretending to be a legitimate customer, which I am

close everything so they don't suspect that something's happening and then I'm in the network. Then I'll start to slowly and surely take over everything. But that's more or less how I guess a lot

of hackers would actually approach it. That's so frightening. It's so frightening that this could be happening.

And I guarantee you that so many entrepreneurs tuning in are now realizing how big of a deal this is and how little they're probably protected. So what is one thing that with our cybersecurity, when you're looking at small businesses, what's one thing that entrepreneurs are doing where a hacker is going to say, this is just way too easy. I mean, there are a number of things and I'm going to start with the big business and then go down to the small one. I really big tell

till even for me as a consultant. If a company is hiring me to check their security,

the first thing I go on linked in and I just see who works there. If that organization is sort of

mid-sized to large size and I see that they have like one person that's called Kotankot IT person that's doing everything. This is a short sign that this person is overworked, probably doesn't have enough time

to do everything security why. So I know there is a high chance that they may not be doing

everything they need to do. So that's a quick tell tale for me. The other one would be, I'll believe it or not, I'll go on Instagram and something I see frequently is a fan that says, oh my god, we won't live last week. You wouldn't believe it. We expected 200 clients and now we have 2000. This tells me that this team is extremely busy. They can barely keep up and it's a lot easier to do things with them that you know. But the time pressure, hey I'm a customer and the apps

down help me. Login to my computer, do something for me. This is a really quick tell tale. Now more than that, there are other things that I wouldn't say small business owners sort of do used to be more common in the past. So things like not having to factor authentication or like old practices that they still exist but not so much nowadays. So systems have gotten data. Thankfully, what as a result, because we have better systems, better IT setups, we can produce a lot faster

and with speed comes compromise. And not just in cybersecurity, you probably have seen a tale away organizations or entrepreneurs or small businesses. They release something but they haven't done their due diligence from a legal point of view. They haven't gotten everything reviewed and they say we'll do it after the fact. So these kind of things may have large impact and in some cases, large consequences. This episode is sponsored by Bit Defender, a global leader in cyber

security. Many small business owners lack dedicated IT support making them easy targets for cyber criminals who steal data money or sensitive information. Bit Defender ultimate small business security is built specifically for business owners like you. It protects all of your team's devices, scans for fishing and scams, manages passwords and even checks the dark web for leaked info. Unlimited VPN allows your team to work securely from anywhere. The dashboard is super simple.

I set it up in just minutes. I add my whole team. I now, everybody is covered whether they're in the office or the studio or working remotely. Bit Defender makes cyber security easy so you can focus on what really matters, growing your business and serving your customers. Protect your business today with Bit Defender Ultimate Small Business Security. Safety 30% when you go to bitdefender.com/propheting. That's BIT Defender.com/propheting for 30% off. Bitdefender.com/propheting.

I want to understand how you know so much about cyber security and hacking and I learned from studying you that you got into this when you were like a teenager and you were really exploring how does hacking work and I'm curious to understand where did this all begin? Tell us a story. Yeah, I mean not to show my age but I'd say I started perhaps late 90s, early 2000s and at that time and especially what I was living in internet was new. It was a novelty, it's then you think

Internet for those my age internet cafes where I think so it got to an intern...

a paper hour and you start exploring and there wasn't much to explore. So it really started with chat rooms called the IRC chat rooms and within that I discovered well people were sharing files. You can download. There is music file that was new to me and then there was this thing called hacking. It coincided with me watching a movie called Hackers. It was early Angelina Jolie movie. It is fiction but it really opened my like hold on. This is a thing like you can actually do that.

So as a teenager and as you do as a teenager you start imagining things. Oh my god, I could hack an airplane and fly myself everywhere. These imaginary scenarios that are not real but like as a 15 years old this is everything. Then as I sort of quote and quote do research to find movies I find another movie about someone called Kevin Mithnic. Late Kevin Mithnic is

the most famous hacker in the world at that time there was movie not just one I think more than one

movie one was in German one was in English. Of course a lot with subtitles. He the things he

did were incredible. He would hack phone lines. He would jam radio signals. He was on the run by

the FBI and the movies of course made it so glamorous. So all I could think of like oh my god and that was a time when we would call people on phone line. Some like oh I could hack my friends phone line. I could do these pranks. So I wanted to learn everything. I go to these chat rooms and at that time hella things were a bit different in the sense if you ask for help people start swearing at you that it was not a friendly time unlike today. So I had to learn certain things

the hard way. I got myself to hack multiple times but long story short my sort of went into the right direction started learning and operating system called Unix. Hence where my nickname came and

actually a fun sort of useful anecdote my website Unix Guide.com is few months older than google.com

so I go way back. So that's where it all started then I got my first job started study things

that university that were completely useless. That's my first job but I continued learning and I still do that to this day even after consulting for so many years. I enjoyed I like to learn I stay curious and experience of course. I've done this so many times so much so that sometimes I can look at something and like have an educated guess that maybe you can look here let's just start this way and take it from there but yeah it's been a continuous learning and experimenting journey and

it's a lot of fun. Your entrepreneurship journey is like really interesting so we're going to spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business and you've done such a great job like really owning this niche and the slain and helping so many people in their IT careers especially in Australia. So since we have this incredible consultant in front of us a lot of the people tuning in are entrepreneurs.

For small business owners we don't have endless budgets. We have a lot of information that might be vulnerable but you know we're not this huge company but like he said that makes us actually pretty attractive. So what are the few things? Let's say three things that we should absolutely not compromise on when it comes to our security. What should we be investing in and where do we begin? This is challenging because it's may slightly vary between businesses but I'd say

the first one non-negotiable is always two factor authentication. Luckily we live in a day

and age everyone knows what that is. So when you log into your email sometimes you get an SMS says that you enter a code the preference is always to use something like a pesky or the authenticator app. Even few years ago this wasn't all the app to everyone we had to have difficult conversations

tends to really reduce the risk of cyberattacks not to zero but it's really important and within

that no exceptions. So if you have a busy executive or someone precious in the team that says I hate that tough luck. This is an negotiable. This is like having a building and having a fire exit. It's not a conversation that businesses should have so this should be there. Roll that for everyone. That's number one. For every single platform that we're using or just email. Excellent point. It is meant to be for every single platform however with platforms now as you log in Hela you notice

that it tells you use your Gmail to like use the same client like if you log in use. So that's this is called single sign on which is essentially you've already logged into your email your email is trusted so we use that as a trusted token to get into apps. So that is that's perfectly fine. You're still considered as someone who used that as long as the app is not asking you

For username and password and you're just entering and getting in.

email that you've already logged in that is this is the same thing. So single sign on have made

that a lot easier. So instead of having an authenticator app for everything some of them will use your email however like even for me my authenticator app is really large so it happens I have it with everything unless I can reuse my email which is fine it's just to get out to get us out of just using the name and password because if the hacker has the username and password it's game over. So just make it a lot harder. The second one which is also related to credentials is a password manager.

So having a password manager is really really important. No matter how complicated we make our passwords

the human tendency is for us to reuse the password everywhere and that's extremely dangerous because your company may be secure, not hacked, but the local cinema might get hacked and guess what people use their work email and work password to log into the cinema. So hackers usually when we do their reconnaissance step when we try to collect information we actually see if your password is out there doesn't matter if someone has the same name we try to first use that and see if

we can get in. So a password manager really essential as a business have some sort of

enterprise solution with these passwords where you have a complex password everywhere and they're really convenient because you can have it out of your browser so it's literally just copying the password that you want to reuse. This is the second one. The third one if you're just not

a way down to three is our key critical assets we need to understand. It's could be customer

information it could be intellectual property. For example you're on a podcast I'm sure you have the safe and method to make an amazing podcast so that's intellectual property let's say it's in a word document I would restrict access to that and that even includes employees make it on a need to know basis if someone needs to access it we ask why you get a time restricted access but that's it it shouldn't be free access to everyone and that could get more complicated like

I worked with the beverages organization here in Australia and some of their intellectual property was recipes for their drinks and those recipes needed to be in a secure vault with encryption and with really secure passwords but also once you log in and get access to that you shouldn't have that login indefinitely it should be time restricted. So those would be the three things and if you allow me a bonus one like I said yeah give me I was gonna say what's the four and five because

clearly I can tell it's not just three things we need to worry about. The fourth one is similar to it's just get a professional opinion for example small businesses when they draft a contract they get legal advice right so you get someone to review it as solicitor likewise with with cyber security it doesn't have to be something massive I'm gonna get a small company preferably something local where you can reach out to them if things go bad and say I just like guys couple hours

whatever $2,000 or could be less could be more check make sure we're doing everything right give us a recommendation and sometimes all they do is just check that you're doing everything you may miss something so they just give you professional advice you know what you're doing 99% that's perfectly fine and as the business grow that sort of consultation or that assessment can grow with you if you have a software application you're releasing to the market obviously that needs more scrutiny

but if someone is just let's say an Instagram content creator and they just share advice they might

not need that I hope that gives the small business owners a thing to talk towards it does and I think

because one of the most important things like you said is password safety and there's some

really I know bit defender I believe has like a password feature that you can get and it's really cost effective but you mentioned this thing this concept concept of least privilege and I'd love to understand like what is this concept of least privilege help break it down for the people that aren't in cybersecurity yeah the concept of of least privileges or least privilege is falls under the umbrella of what we refer to as identity and access management it really is you have a resource

that could be an application it could be intellectual property you want to you want to restrict access to that and make it so that the individual or the system or the software that have access to that they just have access to the minimum amount of resource required for them to do their job with the time restriction for example we go back to let's say a customer database you have a customer database you have all your clients details and let's say you have a marketing officer

marketing officer need to run a campaign for some of those individuals so what I do is the marketing officer will only get access to that database for like 30 minutes so they get a

Temporary password and they will only get access to those individuals and the...

to revoked this reduces the impact of a cyber attack for example if two weeks later this marketing

officer gets hacked well the hacker will not have access because the access has been revoked and

you you mentioned bit defender they have this their enterprise sweet solution so they will have that password manager where you can provide a temporary password access so it can definitely

access to that but that's more or less the principle of least privilege we always assume that for

cyber security needs to be this complex expensive piece of technology what no it's really people process and technology so it starts with the process which is defined this is how we access things from now on and then we enforce it with technology if possible if not he can even do it manual when it comes to customer data like for example my business we don't collect that much data like we have everyone's email but that's pretty much it so like is that really sensitive customer data

or does it get more sensitive when you're collecting people's like addresses and their social

security and like that kind of stuff so it's like what customer data is the most desirable

yeah this is where there is a fine line between cyber security and the legal profession because

here we're going into the territory of privacy or some people say privacy depends on how you pronounce it but this is where we sort of even sometimes consult with a legal professional or a solicitor email address on its own it's not really what we refer to as PI or privately identifyable information it really is not why privately identifiable information is something that can uniquely identify you this would be your full name, hermadress, date of birth but also things we don't think about such as

sexual orientation, political views these things because they can be used against you to target you okay and within that there comes a whole lot of laws and regulations a simple one that

many people don't know is your business is based in the United States so you're in the US

however if some of your customers are EU citizens so their Europeans and their country is part of the EU citizens and they sort of trade with you you actually need to comply with a standard

called the GDPR which is the privacy standards for Europeans citizens so you need to do certain

activities to make sure that you're not breaking their privacy laws even though you're naturally a European Union organization likewise there is that California privacy act and there is the China act so there is all of these things and this is where as cyber security professional we provide advice but then we we consult with as well as it sometimes could be just just please review this make sure our policy is up to scratch so as far as emails I would treat it with absolute care because like I

said it may not be a huge legal liability but it's very attractive people on the dark web they purchase email addresses they use it for spam campaigns they use it to scam people it's a very attractive thing and even I'm not sure if you like have an interest and say paid ads email addresses are really attracted to you for paid ads so there is commercial value for them and as a result we encrypt them we make sure that our newsletter provider is doing their due diligence when it comes to security

which the majority of the big ones are so helpful you are just like a wealth of information so for the entrepreneurs tuning in who still don't feel like there is much of a risk with cyber security or still aren't scared enough talk to us about what could go wrong like reputation wise revenue wise you mentioned earlier that sometimes cyber attacks can be so bad that the business actually has to shut down I'd love to hear some examples of the way that these types of

attacks can actually impact businesses yeah what we try to find line here hello of being an alarmist versus just encouraging individuals and entrepreneurs to really really do their due diligence and just do what needs to be done when it comes to security it can definitely be career ending in the sense the biggest one we've just alluded to which is breaking privacy laws there are hefty fines so the European Union is really strict with fines when it comes to

the privacy of their citizens so accompanying the US that's providing services globally and somehow they get hacked and European citizens get their data out there there might be a big fine and it can be in the seven figures and that can have huge financial impact the other one is let's say you have an application and subscribers and that application gets hacked now what subscribers are paying they need their money back and you really don't know what to do you're

revenue stopped so all of these things can and do have significant financial impacts which isn't

A good segue to also make sure you have the cyber insurance or talk to your i...

organization and make sure that insurance against cyber attacks is there it's a sort of controversial topic it may or may not help but it's best to have it then not to have it so those are things

that are important there are I've never heard of cyber security insurance and then nobody talks

about this stuff cyber security insurance yes I think it it really is important and look that

the good news is you may already have it as an example so if you have insurance for your business depends on your provider you can talk to them and say is cyber attacks are included under that and within that there is a threshold and there is a limit and however I've had mixed experiences with cyber insurance but to summarize it's better to have it than not to have it and the good insurance providers usually it's there in the fine print so it's worthwhile just checking that

that it's already there the other thing is also like I said if if the organization or the business and like you had a consultation with a cybersecurity company that's preferably local also

if things go bad you have them on speed dial you can call them and then get them in

so having that relationship also is really helped and they can also give you an advice when it comes to cyber insurance as well so these things help but when it comes to just things going wrong for small businesses hell up and like I said it does go a bit more sinister and there are things that most of us don't hear about because it's sort of bad news and really bad news we don't want to hear about it for the most part but there are cases of extortion

there are cases and this is really really common so as a small business on a someone could target one of your employees and you're kind of responsible for them and because your business got tacked and it's really complicated and the implications are sometimes your employees could be that target or your customers could be that targets and as you mentioned earlier it could also be your brand reputation and we call it brand equity well as people signed up to your

application it's hot stuff but the next day everything is hacked and everyone is complaining again but that can that can be carried ending unfortunately so let's go back to the entrepreneur who has no budget now you mentioned the three to four things that we should pay attention to but what if I literally had just $1,000 to invest in cyber security and let's say I don't know maybe this isn't just not enough I guess $1,000 for the year or do we want to say $1,000 for the month like

what is the bare minimum that we can be spending on cyber security let's say we just have a thousand dollars let's just say the business has just started and look and there's good news here

is that it's not always like that amount of money I think as humans when we see a problem

like I'm gonna throw money at the problem and make it disappear it doesn't always work that way

especially with entrepreneurship the good news is a lot of the services that we used to have are really built in a solid way so let's say if someone is using the gee let's all their email and everything is from Google for example using the G Suite that is an inherently really secure platform if it's used properly so if I just have $1,000 and which tells me I'm early in business I'm and let's say content creator or I have a small agency this also I will guess that

we're not building an email system from scratch we're not building we're just using popular services whether it's from Google, Microsoft, etc etc this can be good news I would honestly get that $1,000 and like I said reach out to a local trusted company say hey this is our budget can you just give us advice what can we do and they can literally just have one hour look at your stuff and just tell you you know what you're doing everything right maybe do this one thing that's

you know will give you 80% of the value so I would yeah I would get a professional opinion like similar to I think the example of getting legal advice you may not have the budget to hire a lawyer that works full time but all you need is someone to review employment contract that $1,000 can do it may not do it all the time but it's better than doing what a lot of business is doing out which is charity things and AI is telling you yep you're doing a great job

your fantastic you're the best thing since last bread so I think just getting a human who know

what they're doing is a lot better I didn't think you were going to go that way I didn't think you were going to say get like a consultation and have somebody tell you what you need to be doing how about a solution like bit defender it's super affordable I just went on their website and it's like less than 200 bucks a month to get all these different tools it'll like scan your slack and or like your messages for anything that looks like fishing your emails it will send

warnings if it looks suspicious so I feel like that's also like just a great layer to be adding on 100% and like I said that could be also the outcome of that consultation that said hey you're doing

Everything right now you're ready for an enterprise solution which like the o...

bit defender and the good news is these things hello they weren't available for us few years ago

so we are living in a good time where like a company like bit defender have something targeted for

the enterprise small businesses to medium sized businesses where yes they do scan your emails so you get rid of them spam headaches they they offer you some kind of password manager and monitoring

it's always better to have these things in place it also like from a I had to go that way but

from a legal perspective if you know things go south it's also proved that as a founder or as a business owner you're doing you do diligence they can't say well you've done everything but you still got hacked that can still happen even massive organizations but in this case you will be a victim of criminals who really know what they're doing they're you know criminals do criminal things and sometimes we're just victims of that but that's a different story than someone who you

know they've done nothing there's a really famous story on the news of those company that they

created the dating app for women to protect women's safety but then turned out that that's

app because it needed to verify women they took their passport details and all their information

turned out this app was vibened coded with zero security it got hacked and it put women's in safety in danger but that was an example of an organization that didn't do their due diligence whereas a small organization like we said okay they've got the consultation they've got that but defender enterprise security they're doing stuff will you do what you can right it's like having a building you have your fire exits you have everything sure disaster can happen but

you've done what you can do with what you have you've described cybersecurity as defense and depth I'd love for you to walk us through what that actually looks like for a normal small business how can we practice that yeah defense and depth is a concept that's surprisingly even cybersecurity professionals can and frequently do get strong defense isn't in depth is in a nutshell having more than one layer of defense stack to one on top of the other so if one layer

of defense fails the other one can sustain so it just makes it a lot harder a lot more expensive

to get to what we call the crown jewel or the important as it a walk you through an example

let's say let's say you have your customer database that's the most important thing that we have

we want to protect that and then we have our attacker and the first thing they do they send the fishing email okay so the fishing email comes but you have your anti spam filters so the spam filter block that so that's layer one of defense so you didn't even see the email that attack failed now let's say a more sophisticated attacker they crafted their email in such a way that it even passed that spam filter and it went into your inbox so you looked at it and you said well you

know what this looks like spam sorry reports spam so the second layer of defense here was your awareness so that's another strong layer of defense right let's say they were you know the email came from a trusted supply so they hack the supply they can't use you're like oh this is a legitimate email I need to do something you click on that link and but when you click on that link well your anti malware solution your endpoint security system blocked it from being executed so

that's another layer so it failed here and that can you know go on go on like for for longer and but you get the concept right so we have multiple layers of security and in the in the like late nineties and in even early up to the 2000 let's say 2005 to 2010 there were organizations that didn't have firewall so they didn't have nothing so the fact that we put one layer was a huge thing but nowadays you'll find these layers work in tandem this and it's controversial I keep saying

defense in depth because when it comes to marketing of the marketing of cybersecurity people say human is the weakest link I can have all the defenses but if human makes a mistake and click on something it's game of well it's not as we explained earlier there are multiple layers of defense and I say that in defense of the human in defense of the employee that's overworked like clicked on something sorry if if someone clicked on something and it's game over then your security will

fundamentally wrong so yes a way cyber security is approached nowadays how it should be multiple layers of defenses let's move on to AI because I feel like AI is such a hot topic in cyber security how has AI changed the landscape what is new now that's AI is here yeah everyone stop it again I've been labeled sort of anti-AI which is not true AI has definitely made cyber security professionals a lot easier because every business now have an AI and they call us and say hey is this okay

is it's not okay and then we need to go and look look it definitely has changed things and it's here

To stay but also it's not the sort of doom and gloom and the movie Hollywood ...

read on the news of these AI is escaping and hacking things that this is just marketing look that

truth is always a bit more nuanced AI I mean the most obvious one that we only need to be careful

and be aware of is the deep fakes so deep fakes huge huge problems and I know we talk about entrepreneurs and small businesses but even for children and in schools it's been an absolute nightmare and law enforcement deals with that all the time so deep fakes faking voice faking video is something we need to be really careful of but even as I said earlier you can I can really create our website really quickly that looks exactly like a replica of a real one now that wasn't overly

difficult before AI but now it's even faster that makes sense so in the hands of a skilled hacker AI can make certain aspects faster now is AI this really advanced thing that's going to do go on hack things that's not true and the big AI companies have actually sort of save guards against making AI do these things ways around it but let's say if someone is completely unskilled and

they're trying to do something this is just not happening so that's one aspect of it the second

aspect which is what keeps us busy is businesses are really quick to sort of want to use AI and this is where things get a bit more complicated because when we say AI so what are we really using are we just prompting Chad GPT or are we giving AI access to everything and making it talk to customers and do finance for us or are we even not even using AI but we have the SaaS service or this product and then all of a sudden this product on the website says we're AI

enabled or AI power do what does that mean do you feed our information to your AI is it going to the AI company which is really a private company if you think about it so all these things are making life but more interesting for cybersecurity professionals and small business owners so we want to use AI we want to be on top of the new technology but we also need to stop and think what is it that we're using AI for what does the AI have access to and more importantly

where is my data going is it going to a private company why do I trust that private company this private company could get hacked or they could do something like sell my data somewhere big tech companies have done that and we love to see news and this big tech company got suit for selling election information well they don't care the hundreds of millions of dollars

find that they pay this is just you know one week's earnings so these things I think we need to

keep in mind when we when we use something like AI just why we use it and how we're using it is fundamental yeah are we getting to a point where we literally just can't trust anybody is face or voice digitally unfortunately yes it happened to me I thought I was this great AI detector up until someone among the Melbourne Australia and yeah I thought I was like this you know a great video guide that I know I can detect it and one of my fellow youtubers he visited me

on Australia and he was just showing me what he doesn't like oh this actually was AI so why he does he recordings of talking and then for his Instagrams it's him but it's really an AI of him that looks exactly I couldn't tell I'm nobody could tell up until he pointed it out it looks like him talking it says voice but the videos in child life fabricated and it looked real and with the like the short form videos because the resolution is low I couldn't tell like a few months ago

AI would give you a few more fingers or things will be obvious not anymore and um to the human

eye my eye at least it's not always detectable so absolutely and stingy enough I got an email from

Microsoft saying yesterday that then they won a rely on past keys which is a more secure way for authentication so no longer you know the voice authentication and all of these things are going I don't know longer secure so absolutely seeing a video and and usually women get targeted like with explicit luck you someone leaks caught and got leaks explicit videos of an individual and well that video is completely deep fake and it has been happening and yeah it's something

I actually had to deal with with law enforcement where they talk they always talk at the vulnerable they always talk at the young and it is a it is a problem and we need some kind of a strict regulation on you know putting someone face on a body that doesn't belong to them or do these things it's crazy because as a creator you actually see a lot of opportunity in this like my team is actually

creating an AI avatar for me I just did like the whole turning my head a million ways

and walking towards the camera and turning my body every which way so that they can create an AI avatar for me is there risk in having an AI avatar that you actually create for yourself and for

Your content um that look this is a difficult thing to sort of answer and gue...

let's think about look what could go wrong because you and I are content creators so

if someone wants to impersonate me there is thousands of footage of me speaking and whoa it's

it's really straightforward and and exactly for yourself as well and we could say well it's illegal well I'm in the hack doing something illegal I don't think they're gonna stop and say oh hold a second I'm not gonna do that because it's illegal there's still do it so for me I don't think

there's any risk from a point where we are out there and you know like I always say I tell people

if someone wants to hack me and I want to just go and hack me my phone is full of food pictures and so like it's completely useless but like I'm aware as I said my stuff could be used to harm someone else um I don't think there is a risk from a content here shown perspective which is not really a cyber security thing for me I actually went a complete opposite of that I do everything physical and analog now even a photo has to be photographer um I'm a strictly not a fan of of

AI however it's a technology it's a new thing there is a vital needs to be danced video that people photo was AI but then it was real but it is the world we live in and as an entrepreneur there's no reason why you shouldn't jump onto these technologies um a lot of like we said in the conversation

as long as you know you know your critical assets or private information or stuff or financial

information don't feed that into AI you should be fine if it's avatar if it's fun stuff it's

why not I think one of the the new things coming up in AI and cyber security is is for a couple years AI was mostly like chatting chatting to chat GBT getting help writing emails but now we've got AI agents that are jumping from tools to tools that are kind of like AI digital employees how worried do we have to be about AI agents and their ability to hack our companies or their cyber security threats AI I mean a genetic AI agent is exactly what you describe where you have

the AI but instead of it just being a prompt or a chat but you're actually giving it um access to stuff and it can do things for you for example you can program the AI to send an email from your email or have given access to your calendar or in some instances it can be you know chat button your website AI agent is something that needs to be treated with absolute care it shouldn't be just just because it exists doesn't mean we need to use it there are many issues with AI agents the

first one is obvious one is is access will you're giving a piece of software access to things so we need to assess that access will go back to the principle of least privilege does the AI really need access to everything in my email or does need access to a copy of certain emails does it need access to calendars of everyone or perhaps you can create a dummy calendar for certain things and that can access that so the first one is you know don't don't be too generous with

access treated like you know it's just another piece of software I don't want to say it's another employee it's an employee or it's just really a software so we don't really get software access

to everything just because we can I think that that craze or or the history that we we

face now is is oh AI can do this therefore I need to do I need to do that not as a business do you really need that and if not then why and that could be also costly in terms of tokens and and with her lots of stories of companies paying so much on AI tokens I famous one of the fan companies they laid off so many employees just so they're afford paying for the tokens and it's

not all the smart business decision this is one and the the most important one as well is

well accountability so as a fountain just because the AI is doing something doesn't mean the AI is accountable for it I'm still accountable so if I get the AI to review my legal contract great but if you may be accurate or may not be accurate who's accountable if I get into legal trouble I can't say oh well oops AI did it no it still mean so we need to really stop and and think well I'm still accountable AI is just software doing something I'm still accountable just like an

normal employee just the employee can make a mistake or so but ultimately the accountability falls on leadership or on the CEO or on the board of directors so these are the things we need to really be careful about so I do think one of the things that we need to be worried about with our employees and AI is actually we might be rolling out specific company AI tools but because AI is kind of popping up everywhere employees are probably using all these like disparate AI tools or

like whatever tool they think is fine and they're probably using their company computer and thinking it's harmless is there a risk in people just using like not approved AI tools absolutely and this is not a new problem we used to call what we still call this shadow IT or unsanctioned software

Which is really what AI is what you just described we had this problem even b...

say the marketing team they just found this online tool and they start using it they didn't tell everyone

and they put customer data in it with that sort of a cybersecurity team doing an assessment and saying

hey this is approved we can monitor we can do that same thing with AI if we have an employee opening their own personal charity putting company information in it yeah we haven't we didn't really approve that so they did something that the business didn't approve of it is really hard and it's it's something that we need to like I said do our due diligence we need to have clear policies that say do not put company information into AI tools also the other thing I saw even in big tech companies

where they really skilled so they have built a different agents to do different tasks they always

have someone sort of verifying and validating the output of AI so really skilled programmers they do this cloud code they the AI's producing code before it goes to production it needs to be reviewed needs to be tested by a vetted senior program so this way we have safeguards against what goes into AI but what comes out of AI that is really essential that is the other thing of course like I said in terms of privacy and stuff that is a setting and all these AI chat puts that says

something along the lines of don't use my data to train AI I think we should all toggle that

and this way allegedly our data doesn't go in there so that's something that we need to do but

there has been instances a really famous one early days chat GPT the source code some

Samsung employees really leaked the source code not leaked that's posted to chat GPT and it's a huge problem because chat GPT will use it to learn but that source code is massively massively pricey and important intellectual property that should not have gone there so these things happened yeah so we do need safeguards against who uses AI what do we use it for and exactly like any other piece of software an employee shouldn't be just using the random software's

and use it for business purposes on business laptop if we have like a company version of chat GPT and cloud is it safe to upload certain financial information or code or whatever it is is it safe to upload those types of things or is it still not safe so when we say a company version that is like a rag which is a local AI that you can have absolutely where the data is not going elsewhere and also if depends on the solution that you use a data against safeguards that just

doesn't doesn't get that your data leaving the organization and then the word safe we need to also really put it under the microscope safe in the sense okay so it's not leaving but is it safe from mistakes that get hacked or yeah sure but also is it safe from mistakes if I'm doing financial data and I get the AI to be my finance officer I'm still accountable when when a mistake happens and this is the problem that inherent problem with AI is it makes mistakes you know humans make

mistakes but they're accountable where AI the software it will make mistakes and that's a problem so if it's doing financial data financial analysis for me I need to validate that so if I can validate that no worries it can really save time if I have a finance officer they use AI in some sort of way but then they review everything that is fine it's just it's just us validating and verifying that things are fine also like I said like need to know basis or least privileges meaning I'll

use AI just because AI can do certain things and I'm giving certain amount of data doesn't mean I need to give them access to everything just give it access to what needs to happen and then revoke that access so I'd like to talk about aside from the technology and AI the people who actually have keys to your business like a lot of us think that the only way that our business is vulnerable is through a stranger a hacker is going to come hack our company but it turns out that our employees

can actually be a really big risk especially employees maybe disgruntled employees who have left the business is that right absolutely then that technical name we use for it is inside of threat although some people don't like the word inside of threats like where humans are in threat it could be exactly what you said so one scenario is at the scrumptile employee they know all the

business secrets everything they leave and six months later they said hold on a second I'm not

happy with that business let's do some damage and the way we reduce the attack surface we reduce the

impact is back to basics they shouldn't have access to everything so when they hold the key to the

business well they need to hold the key to certain aspect that they need for their job and this way if they do damage will that damage is restricted that's that's one to come and mistake that happens even with large businesses in fact probably more with large businesses than smaller ones is when someone leaves we call it the offboarding process they don't take all of their access out so

They may still have access certain applications or certain things that they l...

problem so we need to have a process of just like we onboard employees we need to know how we

onboard them and that includes revoking access the third one is also on our contract legally

and we need to say that you know if you leave please don't go on social media and just spell out all our secrets that's illegal but having it in the contract doesn't hurt there's been many instances of that happening a really popular one a big take of the Australian organization that has laid off people and they laid off one of their very senior software engineers

and the next day he creates I think I want our YouTube video explaining everything he's done

for them everything he's built it's online it got millions of views so yeah that that's really valuable information that the employees built that and you know how awkward it is for an organization to legally go after someone so these things we need to be careful of the inside of

that there is other aspect that we forget when it comes to inside that third is the employees are

humans they make mistakes so I even not early in my career as an example I made a mistake early early in my career as I was going working fast on faster I ended up deleting stuff that were really important files I did that by mistake and I had to go find backups and restore backups so mistakes can happen it could be a really genuine unintended mistake which again goes back to why didn't even have access to that stuff why was I able to delete without someone looking over my

shoulder without a chain of approvals all of these things that sometimes we may think of as

tedious or unnecessary we want to be fast we want to be lean well there is a cost that comes with that this has been such a valuable session like I feel like I've got to like do so much work and make this like a core initiative for my business severe hacker please leave me alone but um I want to play game with you it's called find the back door so I want you to find the back door I want you to break it

down and then close back door so basically how can somebody hack this company I'll give you scenario

and then how do we actually fix that what is the solution to that okay so the first one is the media company the company works with freelancers around the world some use personal laptops and personal email accounts to access company files where's the back door there are about three back doors in here the first one is offshore employees we need to vet those employees especially if they have access so have some kind of vetting process and that could be something as simple as

use an agency that does the vetting for you so make sure they're you know hiring criminals that's as a basic sanity check the second one of course if you can't give them laptops then restrict what they can access absolutely restrict what they can access don't give them what we call as a right so read access maybe less damaging but right access which gives you the ability to delete stuff that that should absolutely be restricted on a need to know basis with strict approval processes

the fourth one is a personal email address this is a huge no no because when they leave the company they own the data that's on their email so if there's anything sensitive they'll take it with them and that's precisely why organizations have emails on the company domain because the company owns that as soon as they're using personal emails will be on the data so you're really handing over their data and you're as vulnerable as any one of them one of them could be criminal one of them

could be hacked or you just really don't know so you're overly exposed if you want to use

if offshore employees or contractors really restrict them to a very specific task and have in mind that if that person gets compromised what's the impact and do I accept the impact and consequences if no then find alternatives the fast finance team this is a next scenario the founder and the finance team approve urgent payment requests through Slack because it's faster and more convenient yep so anything that we do fast it just means we're gonna make more mistakes

so with speed the compromise is not mistakes yeah I think I big really red flag here is approving things over Slack should not happen this way we need to have a chain of approval that's really clear because the strong use case is if one of your employees get hacked and they have that account gets hacked so the hacker is using their your employees account and well everyone have access to Slack they're gonna ask you to approve something and fast means it's just gonna approve it

so that's a call for disaster you will you will lose money so that's what you're compromising

You need to have the fix for that is have a proper approval process and that ...

may just mean you it will take an extra five minutes it's not really it's not really warm piece it's this is just a proper approval process that will save you a lot of headache and we'll save you time in the long run yeah potentially a lot of money exactly okay the last scenario the sass heavy e-commerce brand the company uses dozens of third party applications connected to customer and payment information that is that everything is wrong with this this is dangerous one

at surprisingly very common hala okay the first one is women they use a so many sass applications

what you need to know who owns that set service because there has been cases where it's

foreign government operating from a different country having this amazing sass application that

does amazing things and it's surprisingly cheap well the purpose of that application was to collect information so you need to really vet and know who you're dealing with so the first thing is we call it supply chain management supply chain meaning your suppliers in this case is your sass providers just make sure you know who you're doing business with instead of just randomly signing up for things because they are cotton code cheap and fast and they they do the job so

because it's a legal liability if you're leaking customer information to somewhere that shouldn't go say huge problem this is one to again know who you're dealing with a small sass app what if you want to provide those get hacked and they have access to all your customers so and therefore

once you know who you're dealing with the second one is manage access why do all of them have

access to everything really common in the real world sadly but manage your access again need to know basis least privilege all these three time list principles meaning you restrict access pretty sure that business whatever it is doesn't require everyone to have access to everything the only reason why businesses usually do that where they give everyone access to everything is just lazy they just it's easier take everything on and and that's a call for disaster so

that these are the two fixes manage your supplier is number one number two manage your access. I love those principles I'm sure everybody tuning in is learning so much and getting so many

ideas like where they need to start first let's say unfortunately our company gets hacked what

is something that we shouldn't do we get hacked somebody just stole bunch of money from our bank accounts what shouldn't we do in that moment. Really difficult because the first reaction that happened to all of us myself includes we panic and to tell someone not to panic it's unreasonable so I'd say panic but don't act it's just like you know when I'm sure as an as a business owner and even as someone on the internet sometimes you get angry and the advice is

just don't reply to an email when you're angry or don't take action just like just sit back it happened it's a problem we're gonna deal with it in a systematic way so I'd say the first thing is don't interact with the hackers that reply to emails which leave everything as it is and in some instances I'd say don't actually close the laptop or don't just leave everything as it is reach out to an expert right away and there is levels to that so reach out to law enforcement

that it's a sort of contested thing to do because usually enforcement are sort of overworked

underfunded and may not be always able to help but you'd be surprised low enforcement can help

having that consulting company sort of you have them on speed dial you have their number get an expert right away to do it that's the that's the most important thing but the biggest one is what we said earlier do not interact with the hackers because the first thing they will do is try to get more access so they'll say sorry mistake I'll just do this one more thing because they're trying to get as much a foothold as possible so don't interact with them they're really skilled at getting

you to do what they want you to do and they're gonna use the fact that you're panicking to their advantage so yeah this gonna completely disconnect get an expert to deal with it right away like don't take

actions and the worst thing that businesses do is they'll have like an IT support person who's

really they don't have the expertise and look okay go deal with it and that person end up being ends up making things a lot worse so I think this is the big no no get some get an expert to deal with it right away such great advice about this has been such an awesome interview before we go now I do want to talk to you about your entrepreneurship journey your business so you actually started creating content and you've created a business out of educating people and it all started

because people would just ask you questions your colleagues would ask you questions and you just wanted away to not have to answer the same thing over and over again so just talk to us about your story how you ended up growing this content business how you make money today and hopefully

You can inspire somebody else who's a thought leader in their space to become...

start their own business too yeah absolutely I mean it's funny I still don't think of myself as

a business or even a content creator but the story started it was during the lockdowns and I was

working at PWC which is a consulting firm and as a senior manager part of our job is to coach consultants and senior consultants so I'd have these one-on-one calls with them and I really don't like zoom or online meetings so I prefer it to be in person and I remember one day I had like three or four back to back calls with junior consultants and they were asking exactly the same question over and over so I got this idea where I'm like no what I'm just gonna fill myself and

setting those questions and I'm just gonna send it to them so they watch it and I just put it on YouTube as somewhere to upload the video on like not as a sort of discoverability flat one so I thought I thought no one would find it I thought it's like I watched YouTube but it didn't occur to me that the video that I'll put strangers will watch it so I send them I told them before you do the meeting just watch this video and then you can ask your questions and I left it and

then I think months later so I saw there was comments and likes and there's strangers watching

it look like oh well let's just answer more questions I guess and I started answering them and it wasn't like it wasn't a sort of a business or I had no idea that YouTube pays me you money and while it's it's a small amount but I didn't I didn't know that was a thing and

when I got the first paycheck from YouTube it was like 50 bucks on that but I don't mistake or like

how I didn't put them together it's not the universe then I'm a part of I had no idea so that was YouTube but then I started getting messages from people and individuals like from all over the world and the first one was like I could see in the picture it was a dad and kids and it's like commenting on my videos he was somewhere in an African country and then it's like actually I got a job and for him a job is they changed their life so got a full-time job

completely new field highly paid so to improve their life and then it started to spiral I started getting these success stories either in a comment and sometimes in an email saying I actually followed your advice I got a job actually in my life thank you so much and the more I posted the more I get now a days every time I look at my inbox there's at least one message a day from someone somewhere in the world says actually followed your advice

which my advice is really just do these practical things learn and apply yourself and you'll get a job it will take time it's challenging but it's possible so this really gave me the drive to continue I felt that I was making a difference and I felt that I just felt responsible I felt responsible that people watch my stuff now I need to get really the most accurate advice I need to do what I can time management became really difficult my job is really really demanding as a consultant

what I enjoy it and because I do it I've been doing it for so long um like it doesn't require a lot

of thinking from my end so I was able to manage but then I've always wanted to do consulting on

my own so I started a cyber security consulting company and I have long-term clients so I'm active in the field I do that but at the same time I create YouTube videos I'm not very good at creating a lot of content so I create one video a month really that's my average so in 12 months I have like 13 maybe 15 videos of YouTube that's all I can I can do within my advice because cyber security is a range of jobs it's not just one job there was one nation cyber security called

government so it's gonna compliance at the time I didn't feel comfortable recommending what wasn't the market so I thought I'm gonna take three months and just try to create something it took me a year and a half and I created my certification got it accredited and I just put it out there and thank God it's been it's been really successful in the sense of people started to recommend and that's the GRC mastery right yeah and people started recommending it to each other through

world of mouth so every time I go to a conference and someone says hey someone did it in the teams and all of us did it in the team so it became bad so really my time now is like between consulting I help um usually large organizations I've got long-term relationships with them I do have some consultants that work under me and yeah the occasional YouTube video where I talk about what's happening inside the security and how to land the job you got a full

plate of clients you have a team and then you're able to create content and give back I mean

that's an incredible career that you have so um okay let's bring you back to cyber security and

wrap this up so if you're a young and profiter listening right now what are the three things that we should do tomorrow morning to protect our company number one two factor authentication

use your authenticator app or a pass key this is not an negotiable no exception this includes all

of your employees number two a password manager I know it will take you some time to get used to

Using a password manager I can promise you it's a lot more convenient for you...

to use a trusted password manager it will save you time in the long run it will save you so much

headache and number three is we talked about it a lot is manage your access just because someone

works for you doesn't mean they need to have access to everything in your company provide this

access give them access only to the things they need and know more and have fun as an entrepreneur amazing

beautiful recap thank you so much event for spending time with us on young and profiting podcasts

thanks for having me and thank you so much for your time this has been an absolute pleasure

big thanks to Bit Defender for sponsoring this episode and for keeping small businesses safe

protect your team your data and your business from scams ransomware and fishing get 30% off

bit defender dot com slash profiting that's bit defender dot com slash profiting and if you enjoyed this episode and learned something valuable we'd greatly appreciate a five star review on apple podcast or spotify reviews help us reach more listeners and continue bringing you these conversations that educate inspire and empower you can also connect with me on instagram tik tok or x at yap with hola or find me on LinkedIn by searching hola ta ha this is your host hola ta ha aka the podcast

Princess signing off.

Compare and Explore