Author: J. Mesa

  • Small Business Cybersecurity Checklist: 20 Things to Review Every Year

    By J. Mesa

    The start of a new year is a good time to check your locks. Staff changed, you added software, a vendor came and went. Each change can leave a gap.

    This checklist covers twenty items in five groups. Set aside an afternoon, work through it, and write down what you find.

    Why review your security every year?

    • People join and leave, and their access lingers
    • Software reaches the end of its support
    • New services get added without a security review
    • Backups fail without anyone noticing
    • Insurers and clients ask for proof

    A yearly review catches what daily work misses.

    Accounts and access

    1. List every account and who can use it. Include email, banking, cloud storage, your website, your domain, and social media.

    2. Remove access for former employees and vendors. Check shared mailboxes and shared passwords too.

    3. Confirm multi-factor authentication is on for every account that offers it. Start with email, banking, and administrator accounts.

    4. Check for shared or reused passwords. Give each person their own login and a password manager.

    5. Review administrator rights. Few people should have them, and nobody should use an administrator account for daily work.

    Devices and software

    6. Inventory your devices. List every computer, phone, tablet, server, router, and printer.

    7. Confirm automatic updates are on for operating systems, browsers, and applications.

    8. Identify anything that no longer receives security updates and plan its replacement.

    9. Check that security software is installed and current on every computer.

    10. Confirm laptops and phones are encrypted and lock after a few minutes.

    Network

    11. Update your router and firewall, and change any default password.

    12. Check your Wi-Fi. Use WPA2 or WPA3 with a strong password, and keep guests and smart devices on a separate network.

    13. Review remote access. Close anything exposed to the internet that you don’t need, and require multi-factor authentication for the rest.

    Data and backups

    14. Know where your sensitive data lives. Customer records, employee files, and financial information.

    15. Test a restore from backup. Time it. Confirm one copy sits offline or offsite.

    16. Delete data you no longer need, and dispose of old devices and paper securely.

    17. Review cloud sharing settings and remove public links.

    People and plans

    18. Train every employee on phishing and safe data handling, and record who attended.

    19. Review your incident response plan. Update the names and phone numbers, and print a copy.

    20. Review your vendors, your insurance, and your compliance duties. Confirm who holds your data, what your cyber policy requires, and which rules apply to you.

    How long does the checklist take?

    For a business with fewer than 25 people, plan on three to four hours for the first pass. It goes faster each year, because you keep the lists you made.

    Who should do it?

    Name one person to lead, often the owner or the office manager, and involve whoever handles IT. Ask your IT provider for the device and update reports. The person who leads does not need to be technical. They need to ask each question and write down the answer.

    What should I do with the results?

    Sort what you find into three groups:

    1. Fix now. Missing multi-factor authentication, active accounts for former staff, failed backups.
    2. Fix this quarter. Unsupported devices, missing training, an outdated plan.
    3. Plan and budget. Larger replacements and projects.

    Assign each item an owner and a date.

    What are the most common problems this review finds?

    • An email account without multi-factor authentication
    • A former employee who can still log in
    • A backup that stopped running months ago
    • A router that has never been updated
    • A shared password that everyone knows
    • An incident plan with phone numbers for people who left

    Any one of these is an open door.

    How do I prove I did the review?

    Keep a dated copy of the completed checklist, with notes on what you found and fixed. Insurers, clients, and auditors accept this kind of record as evidence of a security program.

    Should I review more than once a year?

    Some items deserve a shorter cycle.

    • Monthly: confirm that updates and backups ran
    • Quarterly: review who has access to what
    • Yearly: the full checklist, training, and the plan
    • After any change: a new system, a new vendor, or a departing employee

    Is a checklist the same as a risk assessment?

    No. A checklist confirms that basic controls are in place. A risk assessment looks at your specific business: what data you hold, what could go wrong, how likely it is, and what it would cost. The checklist is the starting point. An assessment tells you where to invest next.

    What if I find something I can’t fix?

    Write it down with the reason, and reduce the risk another way. An old system you can’t replace yet can be taken off the internet and restricted to the people who need it. A documented risk with a plan is far better than an unknown one.

    Does this checklist cover compliance?

    It covers the basics that most standards share. If you accept payment cards, handle health information, or provide financial services, you have added duties under PCI-DSS, HIPAA, or the FTC Safeguards Rule. Use this list as a foundation and check the specific requirements that apply to you.

    Where do I start if I am short on time?

    Do these five first. They take under an hour.

    1. Turn on multi-factor authentication for email.
    2. Disable accounts for former staff.
    3. Check that your last backup succeeded.
    4. Confirm automatic updates are on.
    5. Print your emergency contact list.

    How long does this checklist take?

    Plan for one working day. Most owners finish the account review and the backup test before lunch, then spend the afternoon on updates and the phone call to the bank. Put the date on your calendar now and invite the person who handles your IT. A checklist you schedule gets done. A checklist you save for a slow week waits until after the breach.

    Your next step

    Put the review on your calendar this month and work through all twenty items. If you want an outside view, Cerberus Cybersecurity performs risk and compliance assessments that cover this checklist and go deeper into the risks specific to your business. Contact us to schedule yours.

  • What Is Business Email Compromise? How to Stop Invoice and Wire Fraud

    By J. Mesa

    A bookkeeper gets an email from a longtime vendor. The vendor has changed banks, the message says, and future payments should go to a new account. The email looks right. The bookkeeper updates the record and pays the next invoice. Weeks later the real vendor calls to ask about the overdue payment.

    That is business email compromise. It needs no malware, and it costs businesses more than any other online crime reported to the FBI.

    What is business email compromise?

    Business email compromise (BEC) is a scam in which a criminal uses email to pose as someone you trust, such as an owner, an executive, a vendor, or an attorney, and asks an employee to send money or sensitive information.

    The message may come from a look-alike address or from a real account the criminal has taken over.

    How does a BEC scam work?

    1. Research. The criminal studies your website and social media to learn who handles payments and who your vendors are.
    2. Access or imitation. They break into an email account through phishing, or they register a domain one letter off from the real one.
    3. Watching. Inside a mailbox, they read invoices and learn how people write.
    4. The request. They send a payment request or a change in bank details at a believable moment.
    5. The transfer. The money goes to an account they control and moves again within hours.

    What are the common types of BEC?

    • Vendor or invoice fraud. A fake notice that a supplier’s bank details have changed.
    • CEO fraud. A message from “the owner” asking for an urgent wire.
    • Payroll diversion. A request to change an employee’s direct deposit account.
    • Gift card requests. “The boss” needs gift cards for clients right away.
    • Attorney impersonation. A message about a confidential deal that requires a fast payment.
    • Real estate fraud. Fake closing instructions sent to a buyer.
    • Data theft. A request for employee W-2 forms or customer lists.

    Why does BEC work?

    • It uses trust in people you know
    • It arrives during real transactions
    • It contains no malicious link or attachment for a filter to catch
    • It creates urgency and asks for secrecy
    • Employees want to be helpful and fast

    What are the warning signs?

    • A change in bank account or payment details
    • Pressure to act today
    • A request to keep the matter confidential
    • A sender address that differs by a letter or uses a different domain
    • A reply-to address that differs from the sender
    • A request outside the normal process
    • Writing that sounds unlike the person
    • A message that says the sender can’t take calls

    How much does BEC cost?

    The FBI’s Internet Crime Complaint Center reports losses from BEC in the billions of dollars each year, more than ransomware by a wide margin. A single incident at a small business can run from a few thousand dollars to several hundred thousand.

    How do I prevent BEC?

    Technology helps, and process stops it.

    • Verify by phone. Confirm any new or changed payment details by calling a number you already have on file. Never use the number in the email.
    • Require two people to approve wire transfers and new payees.
    • Set a waiting period for payments to a new account.
    • Turn on multi-factor authentication for all email accounts.
    • Train your staff to recognize these requests, with real examples.
    • Limit what you publish about who handles finance.
    • Review mailbox rules. Attackers create forwarding rules to hide their activity.

    What technical controls help?

    • SPF, DKIM, and DMARC records on your domain, which make it harder to send email that appears to come from you
    • External sender warnings that flag messages from outside your company
    • Email filtering with impersonation protection
    • Alerts for new forwarding rules and logins from unusual locations
    • Registration of look-alike domains, so criminals can’t use them

    What is the single most effective control?

    The phone call. A two-minute call to a known number defeats almost every version of this scam. Write it into your payment procedure, and make it mandatory for every bank detail change, no matter who asks or how urgent it sounds.

    What should I do if I sent money to a scammer?

    Move fast. Recovery depends on hours.

    1. Call your bank at once and ask for a recall of the wire or a reversal of the transfer.
    2. File a complaint with the FBI at ic3.gov. Include the bank and account details of the recipient. The FBI can sometimes freeze funds when a report arrives soon after the transfer.
    3. Change the passwords on the affected email accounts, and check for forwarding rules.
    4. Notify your cyber insurer and your attorney.
    5. Tell the vendor or person who was impersonated.
    6. Keep the emails. Don’t delete evidence.

    Can I get the money back?

    Sometimes. The chance is best when you report within a day or two, before the money moves overseas. After that, recovery becomes unlikely. Speed is the reason every employee should know who to call.

    Does cyber insurance cover BEC?

    Some policies do, often under a “social engineering” or “funds transfer fraud” section with its own lower limit. Many require proof that you followed a verification procedure. Read your policy and ask your broker before you need it.

    How do I protect my customers from criminals posing as me?

    • Set up DMARC on your domain
    • Tell customers that you will never change bank details by email alone
    • Put that statement on your invoices
    • Give customers a phone number to verify any request

    How is BEC different from phishing?

    Phishing casts a wide net and aims to steal credentials or install malware. BEC targets one person in one business with a request for money. Phishing often comes first: a stolen email password gives the criminal the mailbox they use for the BEC attempt.

    How often should I train staff on BEC?

    Train everyone who touches money at hire and at least once a year, and send a reminder before busy periods such as year end and tax season. Include the owner. Criminals impersonate the owner because staff hesitate to question the boss.

    Your next step

    Write one rule into your payment process today: every change in bank details gets a phone call to a known number. Cerberus Cybersecurity can train your finance staff and document your payment controls through our cybersecurity training and policy development. Contact us to protect your business from invoice fraud.

  • What Is Multi-Factor Authentication? A Small Business Guide to MFA

    By J. Mesa

    If I could convince every business owner to do one thing this week, it would be to turn on multi-factor authentication. It costs little or nothing, it takes minutes, and it stops the attack I see most often: someone logging in with a stolen password.

    This guide explains what multi-factor authentication is, how the different types compare, and how to put it in place across a small business.

    What is multi-factor authentication?

    Multi-factor authentication (MFA) is a login method that asks for two or more proofs of identity. After you enter your password, you confirm it is you with a second step, such as a code from an app or a tap on your phone.

    The proofs come from different categories:

    • Something you know: a password or PIN
    • Something you have: a phone, an authenticator app, or a security key
    • Something you are: a fingerprint or your face

    A login counts as multi-factor when it uses at least two categories.

    What is the difference between MFA and 2FA?

    Two-factor authentication (2FA) is MFA with exactly two factors. Most people use the terms to mean the same thing. Two-step verification is a close cousin that some services use for the same idea.

    Why do I need MFA?

    Passwords leak. They leak through data breaches, phishing emails, and malware, and people reuse them across sites. An attacker who buys a list of leaked passwords can try them against your email in seconds.

    With MFA on, the password alone is not enough. The attacker also needs your phone or your security key. Microsoft has reported that MFA blocks the vast majority of automated account attacks.

    How does MFA work?

    1. You enter your username and password.
    2. The service asks for a second proof.
    3. You approve a prompt, enter a code, or touch a key.
    4. The service lets you in.

    Many services remember a trusted device, so you see the second step only on a new device or after a set period.

    What are the types of MFA?

    • Text message codes. The service sends a code to your phone number.
    • Authenticator apps. An app such as Microsoft Authenticator or Google Authenticator generates a code that changes every 30 seconds.
    • Push notifications. You approve a prompt on your phone, sometimes by matching a number shown on the login screen.
    • Hardware security keys. A small device, such as a YubiKey, that you plug in or tap.
    • Passkeys. A login stored on your device and unlocked with your fingerprint, your face, or a PIN.
    • Biometrics. A fingerprint or face scan, often used to unlock one of the methods above.

    Which type of MFA is the most secure?

    From strongest to weakest:

    1. Hardware security keys and passkeys. They check that you are on the real website, so a fake login page can’t capture them.
    2. Authenticator apps and push prompts with number matching.
    3. Text message and phone call codes. A criminal can intercept these by taking over your phone number, a fraud called SIM swapping.

    Any MFA is far better than a password alone. Use the strongest option each service offers, and don’t wait for the perfect one.

    Which accounts should I protect first?

    1. Email. Password resets for every other account go there.
    2. Banking and payroll.
    3. Remote access, such as a VPN or remote desktop.
    4. Administrator accounts for your computers, network, and cloud services.
    5. Cloud file storage.
    6. Your domain registrar and website.
    7. Social media.

    How do I set up MFA?

    1. Open the security or account settings of the service.
    2. Look for “two-step verification,” “two-factor authentication,” or “multi-factor authentication.”
    3. Choose an authenticator app or a security key when available.
    4. Scan the QR code with your app, or register your key.
    5. Save the backup codes somewhere safe, away from your computer.
    6. Add a second method, so one lost device does not lock you out.

    What if I lose my phone?

    Plan for it before it happens.

    • Keep the backup codes each service gives you
    • Register two methods, such as an app and a security key
    • Use an authenticator app that backs up its accounts
    • At work, name an administrator who can reset MFA for staff after confirming their identity

    Can MFA be bypassed?

    Yes, and it still stops most attacks. Know the tricks:

    • MFA fatigue. An attacker who has your password sends prompt after prompt, hoping you approve one to make it stop. Deny any prompt you did not start, and change that password.
    • Real-time phishing. A fake login page passes your password and code to the real site as you type them.
    • SIM swapping. A criminal moves your phone number to their SIM and receives your text codes.
    • Stolen session cookies. Malware copies the token that keeps you logged in.

    Number matching, security keys, and passkeys defeat the first three.

    How do I roll out MFA across my business?

    1. Start with email and administrator accounts.
    2. Tell staff what is coming and why.
    3. Give them a short guide with screenshots.
    4. Set a deadline, and help anyone who gets stuck.
    5. Turn on enforcement, so MFA is required and not optional.
    6. Check each month that new accounts have it.

    Microsoft 365 and Google Workspace both let an administrator require MFA for every user.

    How do I handle employees who resist?

    Explain the reason in plain terms: one stolen password could expose every customer. Show how little time it takes. Let people choose between an app and a security key. Offer a key to anyone who does not want to use a personal phone.

    Do insurers and regulations require MFA?

    More and more, yes. Cyber insurers ask about MFA on applications and may decline coverage without it. PCI-DSS requires it for access to card data environments. The FTC Safeguards Rule requires it for covered financial businesses. Clients often ask for it in security questionnaires.

    Does MFA cost money?

    The MFA features in Microsoft 365, Google Workspace, and most online services are included. Authenticator apps are free. Hardware keys cost a modest one-time amount per person. The time to set it up is the main cost.

    Your next step

    Turn on MFA for your own email account today, then set a date to require it for everyone in your business. Cerberus Cybersecurity helps small businesses roll out MFA and write the policy that goes with it, as part of our policy and documentation development. Contact us to get started.

  • Why Cybersecurity Matters: A Plain-Language Guide for Small Businesses

    By J. Mesa

    Your customer list, your payroll, your email, and your bank login all live on computers. Someone who gets into one of them can empty an account, lock your files, or pose as you to your clients. Cybersecurity is the work of keeping those people out and recovering fast when one gets in.

    This guide answers the questions business owners ask me most. It skips the jargon and ends with a short list you can act on this week.

    What is cybersecurity?

    Cybersecurity is the practice of protecting computers, networks, accounts, and data from theft, damage, and misuse. It covers three goals that security professionals call the CIA triad:

    • Confidentiality. Only the right people see the information.
    • Integrity. Nobody changes the information without permission.
    • Availability. The systems work when you need them.

    A stolen customer list breaks confidentiality. A changed bank account number on an invoice breaks integrity. Ransomware that locks your files breaks availability.

    Why is cybersecurity important today?

    Almost every business process now runs through software. You bank online, store records in the cloud, and take orders by email. Each of those conveniences is also a door.

    Criminals have noticed. Cybercrime runs as a business, with tools for rent and stolen passwords for sale. An attacker no longer needs skill to launch an attack. They need a credit card and a list of targets.

    Why do hackers target small businesses?

    Owners tell me, “We’re too small to matter.” Attackers see it the other way.

    • Small businesses hold valuable data. Payment details, tax records, and client files sell well.
    • Defenses are thinner. Few small companies have a security team or a tested backup.
    • Attacks are automated. Software scans the whole internet for weak passwords and unpatched systems. It does not check your revenue first.
    • You connect to bigger targets. A vendor’s email account is a trusted way into a larger client.

    You don’t have to be chosen to be attacked. You only have to be reachable.

    What happens when an attack succeeds?

    Three well-known cases show the range.

    • Equifax, 2017. Attackers used a known flaw in web software that the company had not patched. They took personal data on more than 147 million people.
    • WannaCry, 2017. Ransomware spread across the world in days through an unpatched Windows flaw. It locked hundreds of thousands of computers and disrupted hospitals in the United Kingdom.
    • SolarWinds, 2020. Attackers hid malicious code inside a trusted software update. Thousands of organizations installed it, including US government agencies.

    Two of those three began with a missing software update. The third began with trust in a supplier. Neither cause is exotic, and both apply to a ten-person office.

    How much does a cyberattack cost a small business?

    The ransom or the stolen money is only the first bill. Count these too:

    • Days of lost sales while systems are down
    • Fees for IT recovery, legal advice, and customer notification
    • Fines if you handle regulated data such as health or payment card information
    • Higher cyber insurance premiums
    • Clients who leave because they no longer trust you with their data

    For a small company, a week offline can do more damage than the theft itself.

    What are the most common cyber threats?

    • Phishing. A fake email or text tricks someone into clicking a link, opening a file, or typing a password.
    • Business email compromise. A criminal poses as an owner or vendor and asks staff to send money or change payment details.
    • Ransomware. Malware encrypts your files and demands payment to unlock them.
    • Stolen passwords. Attackers reuse passwords leaked from other sites.
    • Unpatched software. Attackers use known flaws that an update would have fixed.

    Notice how many of these start with a person. That is the reason I say cybersecurity is people first.

    What are the basics every business needs?

    Five principles cover most of the risk.

    1. Risk assessment. List what you have, what could go wrong, and what would hurt most. Spend your effort there.
    2. Access management. Give each person access to only what the job requires. Turn on multi-factor authentication for email, banking, and remote access.
    3. Patch management. Install updates for operating systems, applications, and network devices on a schedule.
    4. Employee training. Teach your team to spot phishing and to report anything odd without fear of blame.
    5. Incident response planning. Write down who to call and what to do when something goes wrong. Test your backups before you need them.

    Do I need antivirus, or is that enough?

    Antivirus helps, and it is not enough. It catches known malware on a device. It does not stop an employee from typing a password into a fake login page, and it does not restore files you never backed up. Treat it as one layer among several.

    Do I need a cybersecurity consultant?

    You can do the basics yourself. Bring in help when you handle regulated data, when a client or insurer asks for proof of your security, or when you don’t know where your gaps are. An outside assessment shows you what an attacker would find first.

    Where should I start?

    1. Turn on multi-factor authentication for your email today.
    2. Check that your backups run and that you can restore a file.
    3. Turn on automatic updates on every computer and phone.
    4. Hold a 20-minute talk with your team about phishing.
    5. Write a one-page plan that lists who to call in an emergency.

    None of these steps needs a large budget. Each one closes a door attackers use every day.

    What is the difference between IT and cybersecurity?

    IT keeps your systems running. Cybersecurity keeps them safe. The two overlap, and they are different jobs. Your IT provider sets up email and fixes the printer. Security work asks a different question: how would someone break in, and how would we know? Many small businesses assume their IT provider covers both. Ask yours which security tasks sit in the contract, and get the answer in writing.

    Your next step

    Cybersecurity protects your money, your clients, and your reputation. If you want a clear picture of where your business stands, contact Cerberus Cybersecurity. We start with your people and build from there.

  • Secure Our World: CISA’s 4 Steps to Stay Safe Online

    Secure Our World: CISA’s 4 Steps to Stay Safe Online

    By J. Mesa

    The Cybersecurity and Infrastructure Security Agency (CISA) is the US government’s lead agency for cyber defense. Its public campaign, Secure Our World, became the theme of Cybersecurity Awareness Month in 2023 and has carried through each October since.

    The campaign asks everyone to adopt four habits. They are simple and free, and together they block the most common attacks. This post explains each one and how to put it in place at home and at work.

    What is Secure Our World?

    Secure Our World is CISA’s cybersecurity awareness program for the public, small businesses, and families. It replaces a long list of advice with four actions:

    1. Use strong passwords and a password manager.
    2. Turn on multi-factor authentication.
    3. Recognize and report phishing.
    4. Update your software.

    CISA chose these four because most successful attacks exploit one of them. A weak password, a missing second step at login, a convincing email, or an old piece of software gives an attacker the way in.

    Step 1: How do I use strong passwords?

    A strong password is long, random, and unique to one account. CISA’s guidance sets the bar at 16 characters or more.

    Nobody can remember dozens of passwords like that, so use a password manager. It creates a strong password for each account, stores them, and fills them in for you. You remember one long passphrase that unlocks the manager.

    • Make the master passphrase four or more unrelated words.
    • Never reuse a password across accounts.
    • Change a password when a site reports a breach.

    Step 2: What is multi-factor authentication, and why turn it on?

    Multi-factor authentication (MFA) asks for a second proof that you are you. After your password, you approve a prompt in an app, enter a code, or touch a security key.

    MFA matters because passwords leak. With MFA on, a stolen password alone does not open the account.

    The options rank like this, from strongest to weakest:

    1. A physical security key or a passkey
    2. An authenticator app
    3. A code sent by text message

    Any of them beats a password alone. Turn MFA on first for email, banking, and social media, then for every account that offers it.

    Step 3: How do I recognize and report phishing?

    Phishing is a message built to trick you into clicking a link, opening a file, or giving up information. It arrives by email, text, phone call, or direct message.

    Look for these signs:

    • Pressure to act right now
    • A request for a password, a code, or a payment
    • A sender address that is close to a real one and slightly off
    • A link that goes somewhere other than what the text says
    • An attachment you did not expect

    When you spot one, don’t click and don’t reply. Report it with the “Report phishing” button in your email program, tell your IT contact at work, and then delete it. Reporting helps your email provider block the same message for other people.

    If a message claims to come from your bank or a vendor, contact them through a phone number or website you already trust.

    Step 4: Why do software updates matter?

    Software has flaws. Vendors fix them with updates. Attackers read those update notes too, and they build tools to attack anyone who has not installed the fix.

    • Turn on automatic updates for your computer, phone, and browser.
    • Update apps, routers, and smart devices as well.
    • Replace devices that no longer receive security updates.
    • Restart when an update asks you to. Many fixes don’t take effect until you do.

    How does this apply to a small business?

    The same four steps work for a company. They need a little structure.

    • Passwords. Give every employee a password manager and set a minimum length.
    • MFA. Require it for email, payroll, banking, and remote access.
    • Phishing. Train your team at least once a year and make reporting easy and blame-free.
    • Updates. Assign one person to check that devices and software are current each month.

    CISA also offers small businesses free resources, including guides and a vulnerability scanning service for internet-facing systems.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month takes place every October. The President and Congress first declared it in 2004, and CISA leads it with the National Cybersecurity Alliance. Schools, businesses, and agencies use the month to teach safe online habits.

    You don’t have to wait for October. The four steps work on any day of the year.

    Do these four steps stop every attack?

    No. They stop the common ones. A determined attacker has other methods, and businesses with sensitive data need more: backups, access controls, monitoring, and an incident response plan. The four steps are the floor. Build on them.

    Where can I learn more?

    CISA publishes tip sheets, videos, and a toolkit at cisa.gov/secure-our-world. The materials are free to share with your staff, your family, and your community.

    What mistakes do people make with these four steps?

    • Using a strong password twice. One breach then exposes both accounts.
    • Approving an MFA prompt they did not start. Attackers send repeated prompts and hope you tap “Approve” to make them stop. Deny any prompt you did not trigger, then change that password.
    • Trusting a message because it looks polished. Criminals copy logos and signatures. Judge the request, not the design.
    • Postponing the restart. An update that waits for a restart protects nothing.

    How long does it take to set up all four?

    Plan on an hour for one person. Install a password manager and move your most important accounts into it, which takes about 30 minutes. Turn on MFA for email and banking in 10 minutes. Switch on automatic updates in 5. Spend the rest learning where your email’s “Report phishing” button lives.

    Your next step

    Pick one of the four steps and do it today. Turning on MFA for your email takes five minutes and blocks the attack I see most often.

    If you want training for your team built around these habits, Cerberus Cybersecurity offers cybersecurity training for every audience, from the sales floor to the executive team. Contact us to set up a session.

  • Cybersecurity Awareness Month: What It Is and How to Take Part

    Cybersecurity Awareness Month: What It Is and How to Take Part

    By J. Mesa

    Every October, governments, schools, and businesses set aside time to talk about staying safe online. Cybersecurity Awareness Month is the reminder most of us need, because the habits that protect us are simple and easy to put off.

    This post explains what the month is, which threats deserve your attention, and how to use four weeks to make your home or business harder to attack.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month is an annual campaign held each October in the United States. The President and Congress first declared it in 2004. The Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance lead it together.

    The goal is to give everyone practical steps to protect their accounts, devices, and data. Many other countries run similar campaigns in the same month.

    Why does it matter?

    Technology sits in the middle of daily life. You bank, shop, work, and talk to family through it. Criminals follow the money and the data, and they count on people being too busy to take precautions.

    An awareness month works because security depends on habits. One person who pauses before clicking a link can stop an attack that software missed.

    What are the biggest cyber threats right now?

    • Phishing. Fake emails, texts, and calls trick people into clicking malicious links, opening files, or sharing passwords.
    • Ransomware. Malware encrypts your files and holds them until you pay.
    • Data breaches. Attackers steal personal and financial records, which leads to identity theft and fraud.
    • Supply chain attacks. Attackers break into a supplier to reach that supplier’s customers.
    • Internet of Things weaknesses. Cameras, smart appliances, and industrial controls often ship with weak security and rarely receive updates.

    What can a cyberattack cost?

    • Money. Stolen funds, ransom payments, recovery fees, and lost sales add up fast.
    • Reputation. Customers leave a business that loses their data.
    • Essential services. Attacks on hospitals, utilities, and local government put public safety at risk.

    Island communities feel this more than most. When a single hospital, utility, or bank serves everyone, an outage reaches every household.

    What are the best practices to follow?

    1. Use strong, unique passwords. A password manager creates and stores them for you.
    2. Turn on multi-factor authentication. A second step at login blocks most attacks that use stolen passwords.
    3. Update your software. Install updates for your operating system, apps, and devices as soon as they arrive.
    4. Watch for phishing. Treat unexpected messages with suspicion, and verify requests through a channel you trust.
    5. Use security software. Keep antivirus and anti-malware protection running and current.
    6. Back up your data. Keep a copy offline or in a separate cloud account.
    7. Teach someone else. Share what you know with family, coworkers, and neighbors.

    How can I take part? A four-week plan

    Week 1: Passwords. Install a password manager. Replace your email and banking passwords with long, unique ones.

    Week 2: Multi-factor authentication. Turn it on for email, banking, social media, and any account that holds payment details.

    Week 3: Phishing. Learn the warning signs. Find the “Report phishing” button in your email and use it. Talk with older relatives about scam calls and texts.

    Week 4: Updates and backups. Turn on automatic updates on every device. Run a backup and test that you can restore a file.

    By the end of the month you have closed the four doors attackers use most.

    How can a business take part?

    • Send a short weekly tip to all staff.
    • Run a 30-minute lunch session on phishing with real examples.
    • Send a simulated phishing email and use the results to teach, never to punish.
    • Review who has access to what, and remove accounts for people who have left.
    • Check that your backups work.
    • Recognize employees who report suspicious messages.

    Keep it positive. People report problems when they feel safe doing so.

    How can I teach kids and older relatives?

    • Keep the rules short: don’t share passwords, don’t click links from strangers, ask before you download.
    • Set up their devices with automatic updates and a password manager.
    • Agree on a family rule: any request for money or gift cards gets a phone call to confirm.
    • For our Manåmko’, practice hanging up on a caller who creates pressure, and calling back on a known number.

    Is cybersecurity only an IT problem?

    No. Cybersecurity is a shared responsibility. IT staff install the tools. Every person who uses a computer decides whether to click, whether to reuse a password, and whether to report something strange. Attackers aim at people because people are easier to fool than software.

    What happens after October?

    The risk does not stop on November 1. Pick two habits from the month and make them permanent:

    • A monthly ten-minute check that updates and backups ran
    • A yearly training session for everyone in the business

    What should I do if I think I have been scammed?

    Act fast. Speed limits the damage.

    1. Change the password on the affected account, and on any account that shares it.
    2. Call your bank or card company if you sent money or shared payment details.
    3. Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and to the Federal Trade Commission at reportfraud.ftc.gov.
    4. At work, tell your manager or IT contact right away. A fast report gives them time to contain the problem.

    Do not feel embarrassed. Scammers fool careful people every day, and a quick report protects the next person.

    Is cybersecurity training worth the time?

    Yes. Most attacks need a person to click, reply, or pay. Training teaches people to pause at that moment. Short sessions repeated through the year work better than one long session, because the reminders arrive before the habit fades.

    Your next step

    Use this October to build your skills. Cerberus Cybersecurity runs cybersecurity training and workshops that cover current threats and the habits that stop them. Contact us to schedule a session for your team. When you understand the risks and practice the basics, you help build a safer digital world for your whole community.

  • SPF, DKIM, and DMARC Explained: How to Stop Email Spoofing of Your Domain

    By J. Mesa

    Anyone can send an email that claims to come from your business address. The original design of email never checked. Criminals use that gap to send fake invoices to your customers in your name. Three DNS records close it: SPF, DKIM, and DMARC. Since February 2024, Google and Yahoo have required them from bulk senders, and mail from domains without them lands in spam more often each month.

    What is email spoofing?

    Email spoofing is forging the “From” address of a message so that it appears to come from someone else. A spoofed message from your domain needs no access to your mailbox. The sender simply types your address into the From line.

    What is SPF?

    SPF, or Sender Policy Framework, is a DNS record that lists the servers allowed to send email for your domain. When a message arrives, the receiving server checks whether it came from a server on your list.

    An SPF record for a business that sends through Microsoft 365 looks like this:

    v=spf1 include:spf.protection.outlook.com -all

    The ending matters. “-all” tells receivers to reject senders that are not listed. “~all” tells them to treat such mail as suspicious. A domain can have only one SPF record, and that record may trigger no more than ten DNS lookups, so adding every service you have ever tried will break it.

    What is DKIM?

    DKIM, or DomainKeys Identified Mail, adds a digital signature to each message you send. Your mail system signs the message with a private key. You publish the matching public key in DNS. The receiving server uses it to confirm that the message came from your domain and that nobody altered it on the way.

    DKIM survives forwarding better than SPF does, which is one reason you need both.

    What is DMARC?

    DMARC, or Domain-based Message Authentication, Reporting, and Conformance, ties the other two together. It does three jobs.

    • Alignment. It checks that the domain in the visible From address matches the domain that passed SPF or DKIM. Without this check, a criminal could pass SPF with their own domain while showing yours to the reader.
    • Policy. It tells receiving servers what to do with mail that fails: nothing, quarantine it, or reject it.
    • Reporting. It asks receivers to send you reports of who is sending mail in your domain’s name.

    A starting DMARC record looks like this:

    v=DMARC1; p=none; rua=mailto:[email protected]

    What do the DMARC policies mean?

    • p=none. Monitor only. Receivers deliver failing mail as usual and send you reports. This protects nobody, and it is the right place to begin.
    • p=quarantine. Receivers send failing mail to the spam folder.
    • p=reject. Receivers refuse failing mail outright. This is the goal.

    What do Google and Yahoo require?

    Since February 2024:

    • All senders to Gmail and Yahoo addresses need SPF or DKIM.
    • Bulk senders, which Google defines as those sending about 5,000 or more messages a day to Gmail accounts, need SPF, DKIM, and a DMARC record with a policy of at least p=none. Marketing messages need a one-click unsubscribe, and spam complaint rates must stay low.

    A small business sending a few hundred messages a day is not a bulk sender. The direction is still clear. Unauthenticated mail is getting filtered, and your invoices and appointment reminders are not exempt.

    How do I set up SPF, DKIM, and DMARC?

    1. List every system that sends email as your domain. Your mail provider, your website’s contact form, your invoicing or accounting software, your newsletter service, your scheduling tool, your CRM, the office copier that scans to email.
    2. Publish one SPF record that includes each legitimate sender.
    3. Turn on DKIM in each sending service. Each one gives you DNS records to add. In Microsoft 365 and Google Workspace, DKIM for your own domain is off until you enable it.
    4. Publish a DMARC record at p=none with a reporting address.
    5. Read the reports for two to four weeks. They arrive as data files that are hard to read by hand. A DMARC reporting service, several of which offer free tiers, turns them into a chart of who is sending as you.
    6. Fix what you find. Add the legitimate senders you forgot. Note the ones you do not recognize.
    7. Move to p=quarantine, then watch for a few more weeks.
    8. Move to p=reject.

    You make these changes wherever your DNS is hosted: your domain registrar, your web host, or a DNS provider.

    How do I check my domain?

    Free lookup tools from MXToolbox, dmarcian, and others show your current records. You can also send a message to a Gmail account, open it, and choose “Show original.” Gmail displays a pass or fail result for SPF, DKIM, and DMARC.

    What are the common mistakes?

    • Staying at p=none forever. Monitoring mode stops no spoofed mail. Many businesses publish the record to satisfy a checklist and never move on.
    • Two SPF records. That counts as an error, and SPF fails.
    • Too many lookups in the SPF record.
    • Ending SPF with “+all,” which authorizes the entire internet.
    • Forgetting a sender. The invoicing system gets left out, and customer invoices go to spam once enforcement begins.
    • Skipping DKIM on third-party services.
    • Jumping to p=reject without reading the reports first.
    • Ignoring domains you own and do not use for email. Criminals spoof those too. Publish “v=spf1 -all” and a DMARC record of p=reject on each parked domain.

    Does DMARC stop all phishing?

    No. DMARC stops exact spoofing of your domain. It does not stop:

    • Look-alike domains, such as a version of your name with one letter changed
    • Display name tricks, where the name shows your boss and the address belongs to a free mail account
    • A hacked mailbox, which sends real, authenticated mail. See how to tell if your email has been hacked.

    You still need mail filtering, multi-factor authentication, a payment verification procedure, and trained staff who can spot a phishing email.

    Why should a small business bother?

    • Protection for your customers and vendors. A fake invoice from your address damages your name even though you did nothing.
    • Deliverability. Authenticated mail reaches the inbox more reliably.
    • Compliance and insurance. PCI DSS version 4 calls for anti-phishing controls, and insurance applications ask about email authentication.
    • Visibility. The reports show you every service sending mail as your company, including ones nobody remembers setting up.

    How long does it take?

    The DNS changes take an hour. Reaching p=reject safely takes four to eight weeks for most small businesses, because you need time to see all your legitimate senders in the reports.

    What comes after DMARC?

    Two optional additions. MTA-STS tells other servers to deliver mail to you only over an encrypted connection. BIMI displays your logo next to authenticated messages in some inboxes and requires a DMARC policy of quarantine or reject first. Both help. Neither matters until the first three records are in place and enforced.

    Your next step

    Look up your domain’s DMARC record today. If you find none, or you find p=none with no plan to move forward, start with step 1 above. Cerberus Cybersecurity checks email authentication as part of our risk and compliance assessments and guides small businesses to an enforced policy without losing legitimate mail. Contact us to get started.

  • The CrowdStrike Outage: Business Continuity Lessons for Small Businesses

    By J. Mesa

    On Friday, July 19, computers around the world crashed to a blue error screen and would not restart. Airlines grounded flights. Hospitals postponed procedures. Banks, retailers, and 911 centers lost systems. No criminal caused it. A routine update from a security company did. Microsoft estimated that 8.5 million Windows devices went down. The event offers the cleanest test in years of a question every owner should answer: how does my business run when the computers do not?

    What happened in the CrowdStrike outage?

    CrowdStrike makes Falcon, a widely used endpoint security product. Early on July 19, 2024, the company released a content configuration update for the Falcon sensor on Windows. The update contained a defect. Windows computers that received it crashed and then crashed again on every restart.

    CrowdStrike withdrew the update in a little over an hour. By then, every online Windows machine running the sensor had received it. The fix required a person to start each affected computer in a recovery mode and delete one file, which CrowdStrike identified as Channel File 291. For an organization with thousands of machines, many of them encrypted with BitLocker and spread across locations, that meant days of hands-on work.

    Was the CrowdStrike outage a cyberattack?

    No. CrowdStrike and government agencies confirmed that the outage came from a faulty update and not from an attack. Mac and Linux computers were not affected.

    Why did one update cause so much damage?

    Three reasons.

    • Deep access. Security software runs at the core of the operating system so that it can stop malware. An error at that level crashes the whole machine.
    • Speed. The update went to all customers at about the same time, with no staged rollout that would have caught the defect on a small group first.
    • Concentration. Thousands of large organizations use the same product, so one mistake landed everywhere at once.

    Were small businesses affected?

    Many were, in two ways. Some run CrowdStrike directly or through their IT provider, and their own computers crashed. Many more felt it second-hand: a canceled flight, a payment terminal that stopped working, a supplier who could not ship, a cloud service that went offline.

    That second group holds the broader lesson. You can be knocked out by a failure in a product you have never heard of.

    What is business continuity planning?

    Business continuity planning is the work of deciding, in advance, how your business keeps operating during a disruption and how it returns to normal. Disaster recovery is the part that restores your technology. Continuity covers the whole operation: people, processes, suppliers, and communication.

    The cause can be an outage, a ransomware attack, a fire, a typhoon, or a vendor failure. A good plan does not care which.

    How do I write a business continuity plan?

    A small business plan can fit in five to ten pages.

    1. List your critical functions. Taking payments, serving customers, paying staff, ordering stock, answering the phone.
    2. Set a tolerance for each. How long can it stay down before real damage begins: an hour, a day, a week?
    3. Map what each function depends on. Systems, vendors, people, and locations.
    4. Write a manual workaround for each. Paper forms, a card imprinter or a backup payment app, a printed schedule, a phone tree.
    5. Set recovery priorities. Decide which systems come back first.
    6. Build the contact list. Staff, vendors, the bank, the insurer, key customers. Include personal phone numbers.
    7. Assign roles. Name who decides, who talks to customers, and who calls the vendors.
    8. Store it offline. Print copies. Keep one at home.
    9. Test it once a year.

    How do I prepare for a mass computer outage?

    The July outage exposed gaps that are cheap to close.

    • Keep your BitLocker recovery keys where you can reach them. Many organizations could not repair their computers because the recovery keys lived on servers that had also crashed. Know where yours are stored, and keep a copy that does not depend on the systems it unlocks.
    • Keep an offline list of administrator credentials in a safe or a password manager you can open from a phone.
    • Make sure at least two people can perform a recovery. One of them should not be an outside vendor who will be swamped with every other client that day.
    • Print the essentials. The day’s appointments, key customer phone numbers, price lists, and emergency procedures.
    • Have a second way to take payments and a second way to communicate if email is down.
    • Keep a spare laptop that is set up and updated.
    • Ask your IT provider how many clients it would have to restore at once, and where you sit in that line.

    Should I turn off automatic updates after this?

    No. Unpatched software causes far more harm than bad updates do. Most ransomware and data theft exploits flaws for which a fix already existed. One faulty update in a decade does not change that math.

    What you can do is stage updates when a product allows it:

    • Apply security updates to a few test machines first, then the rest a day or two later.
    • Avoid updating every server in the same hour.
    • Keep operating system and security definition updates automatic on ordinary workstations.

    After the outage, CrowdStrike committed to more testing, staged rollouts, and giving customers more control over when content updates arrive.

    What should I ask my software vendors?

    1. How do you test updates before release?
    2. Do you roll updates out in stages?
    3. Can I control when updates install, or delay them?
    4. How do you notify customers of a problem, and how fast?
    5. What is your process for withdrawing a bad update?
    6. What does our contract say about outages?

    Ask these of your security vendor, your IT provider’s remote management tool, and any software with deep access to every computer you own.

    Does insurance cover an outage like this?

    Sometimes. Some cyber policies include “system failure” coverage for outages that are not attacks, and “dependent” or “contingent” business interruption coverage for a vendor’s failure. Many policies exclude one or both, cap them with low limits, or apply a waiting period of 8 to 12 hours before coverage starts. Read your policy or ask your broker. Software license agreements usually limit the vendor’s liability to the fees you paid.

    What scams follow a major outage?

    Criminals moved within hours. Government agencies warned of phishing emails, fake “fix” files that carried malware, phone calls from people posing as CrowdStrike or Microsoft support, and newly registered look-alike websites. The pattern repeats after every large event.

    During any outage, take instructions only from the vendor’s official website and from your own IT provider, reached at a number you already have. Tell your staff the same. Our guide to spotting a phishing email covers the signs.

    Is relying on one vendor a mistake?

    Not by itself. A small business can’t run two of everything, and a single well-run product is easier to keep secure than a patchwork. The mistake is depending on one vendor with no plan for the day it fails. We made the same point after the Change Healthcare attack. Know your single points of failure, and have a workaround written down for each.

    How do I test my plan?

    Run a tabletop exercise. Gather the owner, the office manager, and your IT contact for an hour. Pose the scenario: it is 8 a.m. on a Friday, every computer shows a blue screen, and your IT provider’s phone is busy. Walk through the day. How do you open? How do you take payments? Who calls customers? Where is the recovery key? Write down every answer that begins with “I don’t know.” Those are your action items.

    Your next step

    Find out where your BitLocker recovery keys are stored and whether you could reach them with every company computer down. Then print your contact list. Cerberus Cybersecurity writes business continuity and incident response plans for small businesses and runs the exercises that test them. See our services or contact us.

  • How to Tell If Your Email Has Been Hacked, and What to Do About It

    By J. Mesa

    A customer calls to ask why you sent a strange link. A password reset arrives for an account you did not touch. Messages you never read show up as opened. Any one of these can mean a stranger is inside your email. Act the same day, because your mailbox is the master key: nearly every other account you own sends its password reset there.

    How do I know if my email has been hacked?

    Watch for these signs.

    • Contacts report messages from you that you did not send.
    • Your Sent folder holds messages you did not write, or the folder has been emptied.
    • You stop receiving mail you expect, such as replies from a customer or bank notices.
    • Password reset emails arrive for other accounts.
    • Your password no longer works.
    • You receive sign-in alerts from places you have never been.
    • You get multi-factor prompts you did not start.
    • Your recovery phone number or backup email address has changed.
    • You find rules or forwarding settings you did not create.
    • Unread messages appear as read, or mail turns up in odd folders.

    How do email accounts get hacked?

    • Phishing. You typed your password into a fake sign-in page. See our guide to spotting a phishing email.
    • Reused passwords. A breach at another website exposed a password you also use for email. Attackers test those in bulk, an attack called credential stuffing.
    • Malware. An information-stealing program on your computer copied saved passwords and browser sessions.
    • Session theft. A phishing page relayed your sign-in to the real site and captured the session token, which works even on accounts with basic multi-factor authentication.
    • Malicious app permission. You approved an app that asked to read your mail.
    • Weak or guessable passwords.
    • A sign-in on a shared or infected computer.

    What do hackers do with a hacked email account?

    • Reset your other passwords. Banking, shopping, payroll, and social media all send reset links to email.
    • Read your history. Old messages hold tax documents, ID scans, contracts, and invoices.
    • Watch quietly. In a business account, an attacker may read mail for weeks to learn who pays whom and when.
    • Redirect payments. The attacker replies inside a real email thread and tells your customer that your bank details have changed.
    • Phish your contacts. A message from your real address gets opened and trusted.
    • Hide the evidence. Inbox rules move replies and security alerts out of sight.

    What should I do first?

    Work from a device you trust. If you suspect malware on your computer, use a different one or your phone.

    1. Change the password to a long one you have never used anywhere.
    2. Sign out of all sessions. In Gmail, open your Google Account, then Security, then “Your devices.” In a Microsoft account, use “Sign out everywhere.” This ejects anyone already inside.
    3. Turn on multi-factor authentication, or reset it if it was already on. Remove any phone number, authenticator, or security key you do not recognize.
    4. Check your recovery options. Confirm that the backup email address and phone number are yours.
    5. Remove forwarding and rules. See the next section.
    6. Review connected apps and remove any you do not recognize or no longer use.
    7. Scan your computer for malware before you sign in from it again.

    How do I find hidden forwarding rules?

    Attackers count on you skipping this step. A rule they created keeps working after you change the password.

    • Gmail. Open Settings, then “See all settings.” Check “Forwarding and POP/IMAP” for a forwarding address, “Filters and Blocked Addresses” for filters you did not make, and “Accounts and Import” for unknown “Send mail as” addresses or delegates.
    • Outlook and Microsoft 365. Open Settings, then Mail. Check “Rules” and “Forwarding.” Look for rules that move messages to RSS Feeds, Conversation History, or Deleted Items, or that mark mail as read. Rules that match words such as “invoice,” “payment,” or “wire” are a strong sign of payment fraud in progress.
    • Yahoo and others. Look under mail settings for filters, forwarding, and connected accounts.

    Check your signature and your automatic reply as well. Attackers sometimes plant a link or a phone number there.

    What should I do after I regain control?

    1. Change the passwords on your important accounts, starting with banking, payroll, and anything that uses the same password. Check each for changes to contact details.
    2. Warn your contacts. Tell them to ignore recent messages and not to act on any payment instructions.
    3. Read your Sent and Deleted folders to see what the attacker sent and to whom.
    4. Check what your mailbox held. If it contained Social Security numbers, tax forms, or financial statements, freeze your credit.
    5. Watch your accounts closely for the next few months.

    What if I am locked out?

    Use the provider’s official recovery process: Google’s account recovery page, Microsoft’s recovery form, or the equivalent for your provider. Answer from a device and a location you have used with that account before, which improves your odds. Recovery can take days.

    Never pay a “recovery service” you found through a search or a social media comment. Those are scams that target people who are already locked out. The provider does not charge for recovery.

    What if it is a business email account?

    A hacked work mailbox is a security incident for the whole company. Bring in your IT provider at once, and add these steps.

    1. Reset the password and revoke all sessions from the admin console.
    2. Review sign-in logs for the account and for other accounts from the same addresses.
    3. Search the audit log to learn which messages the attacker opened and sent.
    4. Check every other mailbox for the same malicious rules.
    5. Call your bank if invoices, wires, or payroll were discussed in the mailbox. Call customers and vendors by phone to confirm that no payment instructions have changed.
    6. Call your cyber insurance carrier and your attorney. A mailbox that held customer, patient, or employee data can trigger breach notification laws.
    7. Preserve the evidence. Do not delete the account or its logs.

    Our guide to securing Microsoft 365 lists the settings that prevent most of these takeovers.

    How do I prevent the next one?

    • Use a unique, long password for email, stored in a password manager.
    • Use strong multi-factor authentication. An authenticator app or a security key beats text message codes.
    • Never approve a sign-in prompt you did not start.
    • Keep your devices updated and avoid pirated software, a common source of password-stealing malware.
    • Review your account security page twice a year: devices, recovery options, connected apps, and rules.
    • Avoid signing in on shared computers.
    • Reach your mail by typing the address or using a bookmark, not through a link in a message.

    Should I just create a new email address?

    Rarely. Once you remove the attacker and secure the account, the old address is safe to keep. Abandoning it creates new risks: other accounts still send resets there, and some providers recycle unused addresses. Clean it and lock it down.

    Your next step

    Open your email settings now and check two things: the forwarding address and the list of rules. It takes two minutes, and it is the check most people have never made. For help securing business email and training your team, see our cybersecurity training and services, or contact Cerberus Cybersecurity.

  • I Got a Data Breach Letter: What Should I Do Now?

    By J. Mesa

    On May 31, Live Nation told regulators that someone had accessed a database holding Ticketmaster customer data. A criminal group claims to hold records on 560 million customers. The data sat in a cloud environment hosted by Snowflake, and on June 10 the security firm Mandiant reported that about 165 Snowflake customers may have been exposed in the same campaign. The attackers used stolen logins on accounts that lacked multi-factor authentication. If you bought a concert ticket in the last few years, expect a letter. This guide tells you what to do with it.

    What is a data breach notification letter?

    A data breach notification letter is a notice a company must send when someone gains unauthorized access to your personal information. Every US state has a law that requires it. The letter usually states what happened, when, what types of information were involved, what the company is doing, and what it offers you.

    How do I know the letter is real?

    Scammers send fake breach notices to collect the very details a real breach exposes. Check before you act.

    • Search for news of the breach and for a notice on the company’s official website.
    • Many state attorneys general publish the breach notices filed with them.
    • Do not call the phone number, scan the QR code, or tap the link in a notice you have doubts about. Find the company’s contact details yourself.
    • A real notice does not ask you to confirm your Social Security number or pay a fee.
    • To accept free credit monitoring, type the monitoring company’s web address yourself and enter the enrollment code from the letter.

    What should I do first?

    Read the letter for one fact: which types of your information were exposed. The right response depends on that list. Then work through the matching section below.

    What if my password or login was exposed?

    1. Change the password on that account now.
    2. Change it on every other account where you used the same or a similar password. Criminals test stolen logins on other sites, an attack called credential stuffing.
    3. Turn on multi-factor authentication.
    4. Start using a password manager, so each account gets its own password.

    What if my Social Security number was exposed?

    1. Freeze your credit at Equifax, Experian, and TransUnion. It is free and blocks new accounts in your name.
    2. Get an IRS Identity Protection PIN at IRS.gov to stop a false tax return.
    3. Create your own account at ssa.gov before someone else does.
    4. Accept the free credit monitoring the company offers.
    5. Check your credit reports at annualcreditreport.com.

    You can’t change a Social Security number in any practical sense, so treat this exposure as permanent and keep the freeze in place.

    What if my credit or debit card number was exposed?

    • Review recent transactions and report anything you do not recognize.
    • Ask the issuer for a new card number.
    • Turn on alerts for every transaction.
    • For a debit card, act faster. Fraud on a debit card takes money straight from your bank account, and your legal protection shrinks the longer you wait to report it.
    • Update the new number with the services that bill you automatically.

    What if my bank account number was exposed?

    Call the bank. Ask about fraud monitoring on the account, and whether it recommends a new account number. Turn on alerts. Watch for small test withdrawals, which criminals use to check that an account works.

    What if my driver’s license or passport number was exposed?

    • Ask your state motor vehicle agency whether it will flag or reissue the license. Policies differ by state.
    • Freeze your credit, since a license number helps a thief pass identity checks.
    • For a passport, the State Department generally does not require a replacement when only the number is exposed. Watch for misuse and report it.

    What if my medical or insurance information was exposed?

    • Read every explanation of benefits statement from your insurer. Look for visits, prescriptions, or equipment you never received.
    • Ask your insurer and your providers for copies of your records, and dispute entries that are not yours. Another person’s information in your chart can affect your care.
    • Ask the insurer whether it will issue a new member number.

    What if only my name, email, phone, or address was exposed?

    This sounds minor, and it carries a real risk: targeted phishing. A criminal who knows you bought tickets, which hospital you used, or which bank you hold an account with can write a convincing message. For months after a breach, treat any email, text, or call about that company with suspicion. See our guides to phishing emails and scam texts.

    Should I accept the free credit monitoring?

    Yes. It costs you nothing and alerts you to new activity on your credit file. Enrolling does not usually waive your legal rights, though you should read the terms. Monitoring reports a problem after it happens. A credit freeze prevents the most damaging kind. Do both.

    What should I not do?

    • Do not ignore the letter.
    • Do not pay anyone who offers to remove your data from the dark web. Nobody can.
    • Do not respond to follow-up calls or texts that ask you to “verify” your information.
    • Do not assume one breach is the end of it. The same data gets resold for years.

    How do I check what has been exposed about me?

    Search your email addresses at haveibeenpwned.com. The free service lists known breaches that included each address and can notify you of new ones. Many password managers and browsers also flag saved passwords that appear in breach data.

    Can I sue, or join a class action?

    Large breaches often lead to class action lawsuits and settlements. You will normally receive a separate notice by mail or email with a claim form and a deadline. Verify that notice the same way you verified the breach letter. Keep your breach letter and records of any time and money you spent responding, since settlements sometimes reimburse those losses.

    What does this mean if I own a business?

    Three things.

    Your customers will get letters from you one day if you are unprepared. Every state requires notification, and the deadlines are short. Know what personal data you hold, where it lives, and which laws apply. Write an incident response plan before you need one.

    The Snowflake cases carry a plain lesson. According to Mandiant, the attackers did not break Snowflake’s own systems. They signed in to customer accounts with usernames and passwords that information-stealing malware had captured from infected computers, some of them years earlier. The affected accounts had no multi-factor authentication. A stolen password should never be enough to reach your customer data.

    • Require multi-factor authentication on every cloud service that holds business data.
    • Change passwords after any malware infection, including infections on a contractor’s or an employee’s personal computer.
    • Keep work logins off personal and shared home computers.
    • Limit cloud access to known networks or managed devices where the service allows it.
    • Ask your vendors the same questions.

    Your employees are breach victims too. A staff member dealing with identity theft loses time and focus. Share this guide, and consider it part of your security awareness training.

    Your next step

    If you have a breach letter on the counter, read it tonight and list what was exposed. Then freeze your credit. If you own a business, list every cloud service that holds customer data and confirm each one requires multi-factor authentication. Cerberus Cybersecurity helps small businesses assess their data protection and write breach response plans. See our services or contact us.