Cyber Marketing Conversation

cyber_security_consulting_ops_overlay_imageHello everybody. This is Becky Daniel’s team, Supplier Diversity Officer at the University of Delaware. Welcome. Today, Mr. Tony will talk with us. He is from Cybersecurity Consulting Apps. He is the CTO; I believe that’s the company’s chief technical officer and owner. So Tony, Welcome. Thank you. So Tony, why don’t we start with you telling us a little bit about yourself and how long you’ve been in the business? Well, thank you for that, and thank you for inviting us to participate in this program. My name is Tony. I’m the owner, Director, and CTO of Cybersecurity Consulting ops. So we’ve been in the technology space since 1996. I started as a technician for Comcast. As I went to college, I became involved with C programming and fell in love with it. And from there, I went on to become their Director of Addressability, which involved some cybersecurity. As a result of our actions, we launched the digital video. And your digital video helps customers, too, by letting them watch it on a two-way box. However, we implemented security measures to prevent customers from hacking the system from the back end.

How Did I Get Into Cyber Security And IT Services?

From there, I went to Cisco to work on Comcast Cloud products. That also helps us with scripting, as a Unix admin, and networking. This allows us to hone our skills. And that’s how we got involved with cybersecurity and technology on the security side. Okay. I understand that technology is your extracurricular activity. That’s correct. That’s the right way to say it. Extracurricular activity, you love technology. But technology. Can you explain this to the audience? Technology and cyber: When I think of technology, your company is a cybersecurity company. That’s correct. Isn’t that technology? What’s the difference between IT and what you’re doing? But why isn’t IT security, right? Yeah. So, IT is the infrastructure that houses cybersecurity. So, think of it this way.

Explanation Of What Part Of The Network Is IT And Cyber Security.

So, IT is responsible for devices, passwords, and the entire infrastructure, including routers and computers. Cybersecurity is responsible for protecting the data within that infrastructure. So, think of it this way. Every IT system should have a database. Therefore, the primary role of cybersecurity personnel is to protect data at rest. That means a backup data system and the data that travels with it. So, we look for ways to ensure that data at rest remains secure. And when the data is moving, the protocols that protect it are safe. That’s basically how it works. You keep freezing up on me. I see that. Let’s say it’s me. I don’t know why it keeps freezing up. Okay. Alright. We can keep going.

All Small Companies Need An IT Department.

So, if I’m a small business with an IT department, I shouldn’t have one. That is correct. Therefore, we recommend that everyone should have an IT company and receive at least an annual assessment from an independent cybersecurity expert. The reason for this is machine-to-machine. There are Machine-to-Machine Protocols. You want to ensure that the protocols between the machines are secure. So, give me an example. There is a protocol called TLS. And so if you’re running TLS one, that’s zero. Because you never had an assessment. That protocol would allow a hacker to drop and steal information. One of the things we do during cyber audits is look for the TLS protocol, specifically TLS 1.0.

What Is TLS? TLS Is Transport Layer Security.

We look for this to ensure the product and protocol are up to date and working as they should. What do we mean by that? If you have TLS 1.0 or TLS 1.2 enabled, it simply means your system is vulnerable. A hacker could perform an action that triggers a man-in-the-middle attack. Does that mean someone could be in Australia, listen in on the traffic between those two servers, and steal that information without being on your system? So we call that a man-in-the-middle attack. And often, we see these types of issues on running websites. They look good and may be great, you know, have great information. However, hackers are looking for ways to intercept the data between the website input and the destination to steal information. It could be credit card information, PII, or any other information that’s important to them.

Why Are Hackers Interested In Small Companies?

Oh, I understand this. But wouldn’t hackers be more interested in potentially large transactions and essential information, such as that of large companies, banks, hospitals, and similar entities? Why would they be interested in small businesses? Small businesses are perfect. If I could ask 1 million small companies for $1 each, that’s $1 million a month. The thing is, you’re looking at it from the perspective of most small business owners; look at it from all angles. What I mean is they, you know, don’t want me. But at the end of the day, if I can make $1 million a month by only taking $1, something you may not miss, that’s a substantial amount of money for me. There’s also another thing to consider when looking at them. Most of the time, when a small business gets hacked, it’s for several reasons.

Hackers Can Use Customer Devices As Botnets.

Number one, they could become a botnet. And what does that mean? It simply means that I can infect 2 million cameras. And by infecting 2 million camera systems. I now want to attack the University of Delaware. I would tell those 2 million cameras to attack Delaware. Given an IP address in Delaware, the server will eventually give up and expose the database. That’s why you hear the term’ botnets. ‘ Botnets mean that you get a bunch of IoT devices and Internet of Things devices, and you use them to Storm, sign on, pay, or do whatever you want. It may be a specific device that you want to hack. This caused a buffer overflow. And by doing that, that system will keep giving me until I give up.

DDOS attack

You could have everything that you want. That’s why hackers create a button, and they can do that. That’s a fact. How would a company compact it? How would they know? Most companies use something that prevents DOS. They call it a DDoS attack. For instance, I use a firewall company to protect our website from DDoS attacks, and I use firewalls for the office. We use a company that protects us against DDoS attacks. And what does that mean? It simply means that if it detects that he’s receiving too many attacks, it stops, becomes your shutdown pin, and says, ‘I’m not talking to anybody else.’ So, with DDoS, you have companies that will protect you from DDoS attacks. And the reason is that if they listen to and accept all the commands, they will give up their database. But how do you ensure that the company you’re working with doesn’t have the same issue? Again, when it comes to technology, there are companies out there that understand how DDoS works. So, give you an example. One of the things we have done is to turn off a feature called Ping. What is ping? So, if you have an IP address for your router, I can ping it. And your IP address will tell me that it’s alive. It can also reveal important information that hackers can use to hack you later.

A regular cybersecurity audit is essential for your business.

So it’s just like calling into the dark. Ms. Daniels, are you there? Daniel doesn’t answer. I wonder if she’s there. So what happened is I turned off the pain. When I turn off ping and a DDoS attack comes in, I won’t respond. So if I don’t answer, there’s nothing you can do, and you don’t know I’m there as a small business. I’m putting myself in the position of an owner of a small business. I have a website. I may have someone host it for me, or I’ll handle it internally. How do I combat this? Is an audit required? How often should I have an audit? What types of things should I be looking for? May I give this to a third party for their use? What would I say? Alright, number one: you need to understand that cybersecurity and IT are different. That’s the first thing. The second thing you must ask yourself is, what data type do you store? If you’re storing medical devices or medical information? You want to ensure a regular cybersecurity audit, as well as any other necessary audits. These are some of the things that a good cybersecurity consultant would advise you to do. The second thing is that if you’re in the financial business, the two highest-hack places, for lack of a better word, will be medical and financial. Financial. It would be best to have an audit every week. Okay. Because again, there’s someone always knocking at the door, and you probably want to do it every quarter for medical providers. But if you have an audit, you want to ensure you’re asking the right question.

Add Data Exfiltration Software To Alert You To Any Problems.

You want to ensure that when you add Smith, particularly if you’re storing a database, you have a mechanism in place to detect data exfiltration. This way, if someone is stealing your data, you can receive an alarm or block them. Therefore, you must ensure proper monitoring is in place. If someone is stealing your database, you get messages or warnings to let you know something is happening. Okay, when you say ‘ finance, ‘I’m thinking of banking. Are you talking about someone with a desk selling products on your website? If you’re selling products on your website, you want to ensure you have inflation. You want to ensure that credit card information on your website is not stored in a third-party database, so you may want to use PayPal and opt for a secure payment method when accepting customer payments. You also want to ensure you’re not storing it in a place where their credit card information can be easily accessed without security protocols. So, there are many ways to look at this. Most people use credit cards, but they also use PayPal or another service that stores that information in a secure location. If you’re handling customer information, ensure that you’re not storing it in an internal database that could be compromised. So, returning to a small business, I’m starting one. It’s one of the first things I need to consider as I think about opening a bank account, forming my LLC, and completing all the necessary paperwork to start the business. Is this something that should be in the top ten things that need to be done? Yes.

It would be best if you Had A Router That Can Create VLANs. This Is Network segmentation.

Another thing you must consider is presenting information about cable companies accurately. However, one thing you should consider is that most cable company routers do not provide adequate protection. That’s quite broad, but they all claim to do so. I’m sorry. They all said, but they were all right. They. However, you want to ensure you have a router to create VLANs. And let me explain what that is. Therefore, you can gain access to any router by sending a phishing email. And you have the coconut effect. Where his heart and the outside soften the inside, softening the insights means you can go from device to device without being hampered. So let me draw a little picture for you inside your house. So, you build a home and then want to install security measures around it. So, for security measures around the house, you want to have lights. Windows? Yeah. Do you have doors? Yes. Do you have cameras? Okay. Yeah. And then you have rooms? Okay. Okay. If someone walks through your house, they can see your bedroom and living room. All at the same time. Was that Talia, Florida? Yeah. That’s right. So, think of it this way. The Internet is the same way. So when someone breaks into your system in your house, you want to have at least a locked door leading to your prized possession. Right. Okay. So that’s what a VLAN is. That’s why you need a router with VLANs and access control. So, if you have a house and a safe, let’s look at it this way now. You have a safe place in your basement, secured by a locked door, and a common area. Before that, come in here; you have a door, so you see that data is buried three levels deep. Okay?

The US government runs the NIST Framework.

Because it’s safe, it is locked, right? So, if you have a system, such as a router, that allows someone to gain access and immediately view your prized possessions, then your system needs to be more secure. An audit will reveal that, when we read that, yes. Is it best to get a quarterly audit? Yearly? How do you know when you need an audit? Every day? The US government runs NIST. They release vulnerabilities. So what is good today may not be good tomorrow. It may not be good tomorrow. In other words, the mission depends on what’s running on the machine. So you may have excellent software today, but harmful software tomorrow. Say you have a Dell computer. That Dell computer could look good now, but won’t be good next week. So, what I mean by ‘evil’ is that the government did release a vulnerability; well, Dell releases a vulnerability that you don’t know about, alright? And so, what an audit will reveal is that you need a more robust system. As the business owner, you need more time to identify these vulnerabilities. The audit will reveal the exposures and provide the necessary fixes. So you have to make sure. And that’s why you need to audit. Because it’s good today, it will likely be good tomorrow. The audit would reveal what you need to do to fix that vulnerability. You’re handling your website in your IT department and can’t do that yourself. So it’s not that they can’t do it. We have yet to find a team that can do all the work they do every day and do the audit correctly.
The mindset for cybersecurity is, How can I get in? The philosophy for IT is to protect cybersecurity, which falls more under NIT. There are two different mindsets. I’m a small business owner, and I’m afraid of being off. Have you had instances like that where you spoke with small-business suppliers and ran into these problems? Yeah, I have a story to share. If you need help understanding the difference between IT and cybersecurity, would this story be PER? It is perfect for you. Because this customer got hacked. The information was being sold on the black market. Someone from another state calls the customer.

People can find their stolen information on the dark web.

If I’m explaining it correctly and telling him they call it ‘your customer,’ then I know my customer is cut. Well, let me back up. We received a call from a local small business. They got hacked. They discovered the hack when a detective from another state called their customer and informed them that their information was for sale on the dark web. The record shows that the onset was for sale. They are tied to a company. Now, they didn’t want a company that got hacked. They want the customers of the hacked company. So what happened? The customer picks up the phone and calls that customer. That customer called us to tell us they’d been hacked. The hackers did the broadcast for them. What am I saying? It simply means customers could face a lawsuit because their information was stolen. Their record was tied to them on the black market. So, there’s no denying that the breach occurred at that company.
With this customer information. Is there a requirement that a business be notified if its data is on the black market in this way, rather than the detective calling the customer and stating they had reached the company? No. However, in some states, there are no actual rules governing this. In New Jersey, if you discover a breach, you should report it to the state. You have to say it, too. You must also notify your customer. Ad
Additionally, you must help the customer understand that they need to implement controls to prevent further damage. So, the refusal to do so. We’ll pause you and your company, and you’ll get fia ne.

What Happens If You Are Breached?

You are responsible for contacting your customers to inform them that your system has been breached. You would also have to notify all of your customers. All of your customers, even if they weren’t impacted by it. But you don’t know if they were affected by it. Because once the database is stolen and its information is stored, they have been impacted. Is it possible that the business contacted you, and the data wasn’t stolen from them? No. It’s a possibility, yes. And is it possible to know now that the record is on the black market? Right? Because, more than likely, there’s going to be some inflammation with your history that will say that it came from your site. Now, you can put your email address on a Have I Been Pwned site. The government can track your email address and tie it to a company that was breached. There. It is likely that once that information is on the black market, the FBI can identify it as coming from you. What you said, would you advise every business owner to visit that website and enter their information? Absolutely. Absolutely. I might have been a pawn. All you have to do is enter your email address, and it will show you all the companies that have lost your email address or are part of it due to a data breach. However, once they were supposed to alert you that they had done so, they probably sent an email. You probably saw the email and thought it was fake. It also depends on the state that you’re in. Therefore, you must report it for Delaware in New Jersey, and Pennsylvania may have different requirements. So, depending on the conditions in which you live and do business, you may be subject to other laws. Therefore, there needs to be a federal law regarding cybersecurity, and what websites and companies are required to do? They are, but they’re not strictly enforced, for instance, with HIPAA, right? So, the HIPAA law is on the federal books but has yet to be implemented. It’s not strictly enforced. So you can get around.

Companies May Hide That They Were Breached From Their Customers.

Many companies discover they’ve been breached through an audit, but they will never disclose it. This is all fascinating and somewhat scary. Is this very interesting and very scary stuff? One thing I want to mention is that I like this, too. So, let me go back to the discussion about small businesses. You know, while they want to, why would you like to worry about protecting the system? We saw this happen very early, when it went up before I entered the cybersecurity consultant operations field. Hackers like to take over our system, particularly a consumer system, and attack the federal government or someone else. And the reason is that if I come to your business website or network and attack, the government can easily steal your identity. Because the government will see the IP address used to make the attack, it will show that it is Ms. Daniel’s IP address, not the attacker’s. And that’s why hackers love to use VPNs, right? Whether it’s an efficient scheme or any other scheme, it is possible because they can quickly and easily hide their IP address. They could rent an Amazon bucket and do all the mystery from it. It may take a few months for Amazon to realize that its particular bucket is doing something nefarious. But by the time they know it, you will already have what you need and be gone. Okay? That’s a lot for a social media presence. A social media presence may be a suitable alternative to not having a website. Here’s another thing you should do: it discusses social media presence. So, when you take a picture of yourself, you want to delete as much information from that picture as possible, because it contains your computer’s IP address and the coordinates of where the photo was taken.

When you post pictures online, please delete as many details as the picture’s properties allow and make a copy.

So you want to produce it. It discusses the option to access the picture’s properties, which is correct. This allows you to delete as much information as possible about your coordinates and the content in your image. By removing coordinates, you can prevent others from determining your location, whether it’s your house or business. The business doesn’t matter; more likely, your home. Eliminating the coordinates will prevent hackers from locating your router,  identifying your location, and performing similar activities. So, here are some things small business owners, especially those working from home, need to be aware of. What about intellectual property? Well, that has to be protected, too.
When we started, we had a team member in India who was working in cybersecurity operations. So you want to talk to a lawyer to interpret that and ensure you’re covering the main points, mainly the slogan. You are the name of a cybersecurity consultant, ops. That’s probably not as easily stolen,n because if you have that information about the tour, you have to store it in a way that no one can access the website. But your slogan is what you must protect. For instance, if you claim to be the first to serve, can someone else take that away if you don’t defend it? Many people don’t understand that.
No, no. Most people put together a website. They may have a slogan. The slogan sounds good; no one else has it, but they need to think, ‘Okay, what if we get huge?’ What is going to happen? Can someone still use slogans and other similar phrases? Again, they could also take over your website. That’s one reason you should always use multi-factor authentication, especially when accessing your website information. But Tony sure gave me the audience. There’s a lot to think about. We may have part two of this conversation later. As you tell me, what’s good today may not be good tomorrow. That is correct. It’s ever-evolving cybersecurity. That’s why we always say if you could fix it today and it’s good tomorrow, you would have fewer than 3 million job openings. Cybersecurity is very, very complicated.