September 2022 Newsletter - If you’d like to read this newsletter at the same time as our subscribers, please sign up here.
Cyber Security Impacts Your Business Valuation and Creditworthiness
Welcome to the September issue of the Protect Now newsletter. I’m kicking this month off with the answer to a question that many small-business owners fail to consider: What are the financial benefits of cyber security?
If you want to grow your business, you need capital, either from investors or banks. Everyone on the capital side now asks the same question, and they ask it early: What kind of cyber security do you have? Your answer needs to be better than, “We have an IT guy,” or “We use secure passwords,” if you want to see the money. Bankers and investors have all been burned by cybercrime at least once, and they won’t talk to you unless you have real cyber security and real training protecting your operations.
In this month’s featured story, I explain how your business valuation depends on cyber security and offer some ways to meet financiers’ expectations.
BREAKING: What You Need to Know About the New Uber Hack
Uber was breached recently, allegedly by a teenager who posted to internal forums and shared screenshots of his work with The New York Times. There are two things you need to know about this "hack.
- Your information is probably safe. Everything shared with The New York Times suggests that this was an ethical hacker interested in generating bad publicity for Uber, rather than someone trying to steal usernames and passwords. (It’s also college application season, and this teen might be trying to impress a selection committee.) There is no evidence that end user passwords or personal information were stolen, though the hacker apparently managed to access all of Uber’s back-end systems and potentially could have stolen that information if he wanted. Change your Uber login anyway. It’s a good practice to update logins regularly.
- This attack was not a hack. The “hacker” used social engineering techniques to gain access. He found the phone number of an Uber employee with systems access, pretended to be from the IT department and got the employee to provide a VPN account and his password.
This is another reminder that all the cyber security in the world does nothing if you don’t train your employees to recognize and resist social engineering and phishing attacks.
Stat of the Month
$1,000,000,000
The amount of money the U.S. Government will make available, in grants, over the next 4 years to support state, local, territorial and tribal governments assess and secure their systems against cyber threats.
Learn how to apply here: https://www.cisa.gov/cybergrants.
Phishers Roll in on the Evening Tide
Credential phishing attacks were up 48% in the first six months of 2022, according to research from Abnormal Security. Large enterprises get hit at least once a week by attackers looking for access to the organization’s financial partners.
One particular element of this research stands out: Phishers increasingly launch their attacks at the end of the business day. They’re counting on you being tired, wanting to go home and wanting to quickly finish any last-minute business. If your mind isn’t focused on security and you’re not looking closely enough at their fake websites, they win.
We are advising all of our clients to do two things to prevent these types of attacks. First, whenever possible, avoid financial websites at the end of the day. If it’s past 5PM, your transaction probably won’t get posted until the next day, anyway. You’re better off waiting until morning, when your eyes are fresh and you can easily spot the telltale signs of a fake.
Second, no matter what time of day, never click on email links that claim to come from a financial services provider. Always open a new browser window and log in to your financial provider directly. Then you can check for anything that needs your attention.
Remember that you only need to be compromised once to wind up with years of headaches and attacks. Treat the information in emails with importance, but treat emails as possible threats.
Is Your Email Compromised?
Phishers often begin their criminal attacks with lists of emails bought, sold and traded on the dark web. The first step in protecting your organization is to know whether the emails of key staff members have been leaked.
Use the Hacked Checker Now
The Protect Now Hacked Checker is a searchable online database of millions of emails that have been posted to Dark Web forums, often with additional personal information. You will learn not just whether your email has been listed, but where it was stolen from and what other information hackers may have compromised. The FBI recently warned of hackers impersonating employees via deepfake technology to steal credentials. Knowing if emails have been exposed is the first step to knowing if you’re at risk.
If you have any additional questions, we're here to help: (800) 658-8311
Stay safe out there, and see you September the 6th.
Robert & the Protect Now Team