Author: J. Mesa

  • Data Protection for Small Business: 11 Ways to Keep Hackers Out of Your Data

    Data Protection for Small Business: 11 Ways to Keep Hackers Out of Your Data

    By J. Mesa

    Your business runs on data. Customer records, invoices, payroll, contracts, and email let you sell, serve, and make decisions. The same data pays well on criminal markets, and attackers know small businesses guard it less than large ones.

    This post explains what attackers want, what a breach costs, and the steps that protect your most valuable asset.

    What data do hackers want from a small business?

    • Customer personal information. Names, addresses, birth dates, and ID numbers feed identity theft.
    • Payment data. Card numbers and bank details turn into cash fast.
    • Login credentials. A working email password opens the door to invoices, contacts, and password resets for other accounts.
    • Health and financial records. These carry legal protections and high resale value.
    • Business documents. Contracts, price lists, and plans help a competitor or support an extortion demand.

    If you would hate to see it posted online, an attacker can use it against you.

    What happens to stolen data?

    Attackers do one or more of four things with it. They sell it in bulk to other criminals. They use it to commit fraud against your customers. They threaten to publish it unless you pay. And they use it to craft convincing phishing emails to your clients, sent in your name.

    What does a data breach cost?

    • Direct financial loss. Legal fees, forensic investigation, customer notification, and credit monitoring.
    • Regulatory penalties. Rules such as HIPAA for health data, GLBA for financial data, and PCI-DSS for card payments carry fines for failures.
    • Lost customers. People move their business after a breach.
    • Downtime. Staff can’t work while systems are locked or under investigation.

    Most US states also require you to notify affected people after a breach of personal information. Planning for that before it happens saves time and money.

    How do I know what data I have?

    You can’t protect what you haven’t listed. Start with a data inventory.

    1. List every type of data you collect and where it lives: laptops, phones, cloud storage, email, paper files.
    2. Classify each type by sensitivity. A simple scale works: public, internal, confidential.
    3. Note who can access each type today.

    One afternoon of this work shows you where your risk sits.

    What are the best practices for data protection?

    1. Inventory and classify your data. Put your strongest controls on the most sensitive records.
    2. Limit access. Give each employee access to only what the job requires. Security teams call this least privilege, and role-based access control is the common way to apply it.
    3. Require multi-factor authentication. Turn it on for email, cloud storage, banking, and remote access.
    4. Encrypt data. Turn on full-disk encryption on laptops and phones, and use services that encrypt data in transit and at rest. A stolen encrypted laptop is a lost device, and an unencrypted one is a breach.
    5. Train your people. Teach staff how phishing works and how to handle sensitive records. Repeat the training through the year.
    6. Assess your security on a schedule. Run vulnerability scans and review your controls at least once a year.
    7. Plan for incidents. Write down how you will contain a breach, who you will call, and how you will notify customers.
    8. Back up your data. Follow the 3-2-1 rule: three copies, on two types of storage, with one copy offsite or offline. Test a restore.
    9. Check your vendors. Ask the companies that hold your data how they protect it. Their breach becomes your breach.
    10. Collect less. Don’t gather data you don’t need. Attackers can’t steal what you never stored.
    11. Set retention and disposal rules. Decide how long you keep each record type, then destroy it for good. Shred paper and wipe drives before you recycle a device.

    Is cloud storage safe for business data?

    Cloud storage from a major provider is often safer than a server in your office closet, as long as you configure it well. Most cloud leaks come from settings, and three checks prevent them:

    • Turn on multi-factor authentication for every account.
    • Review sharing links, and remove any set to “anyone with the link.”
    • Remove access for former employees and old vendors.

    Which laws apply to my business?

    That depends on the data you hold.

    • Health information: HIPAA applies to healthcare providers and the vendors that serve them.
    • Financial information: GLBA and the FTC Safeguards Rule apply to financial institutions, which include tax preparers and auto dealers that arrange financing.
    • Card payments: PCI-DSS applies to any business that accepts cards.
    • State law: Breach notification and privacy laws apply based on where your customers live.

    This is general information, and it is not legal advice. Ask an attorney how these rules apply to you.

    What should I do first?

    1. Turn on multi-factor authentication for email and cloud storage.
    2. Encrypt every laptop and phone.
    3. Run a backup and test a restore.
    4. Remove access for anyone who no longer needs it.
    5. Delete data you no longer need.

    These five steps take days, and they close the gaps attackers use most.

    How do I know if my data is already exposed?

    Three signs point to exposure: customers report phishing emails that look like yours, staff see login alerts from unfamiliar locations, or your company email addresses appear in a breach lookup such as haveibeenpwned.com. Any of them calls for a password reset and a closer look.

    Does cyber insurance replace data protection?

    No. Cyber insurance helps pay for recovery after an incident. It does not prevent one, and insurers now ask about your controls before they write a policy. Expect questions about multi-factor authentication, backups, and employee training. A business that can’t answer them pays more or gets declined. Good data protection lowers your premium and your risk at once.

    Who in my business should own data protection?

    Name one person. In a small company that is often the owner or the office manager. That person keeps the data inventory current, checks that backups and updates run, and makes sure new hires get trained and departing staff lose access on their last day.

    Your next step

    Data protection comes down to knowing what you hold, limiting who can reach it, and preparing for the day something goes wrong. Cerberus Cybersecurity helps small businesses with risk and compliance assessments and with the policies that put these practices in writing. Contact us to find out where your data stands.

  • What Is a Digital Footprint? How to Check and Shrink Yours

    What Is a Digital Footprint? How to Check and Shrink Yours

    By J. Mesa

    Every post, purchase, search, and sign-up leaves a mark. Put together, those marks form your digital footprint, and criminals read it like a file on you.

    This post explains what a digital footprint is, how criminals use it, how to check your own, and how to shrink it.

    What is a digital footprint?

    Your digital footprint is the record of what you do and share online. It includes your social media profiles, the accounts you created, the sites you visited, what you bought, and the information other people and companies published about you.

    What is the difference between an active and a passive footprint?

    • Active footprint. Data you share on purpose: posts, photos, comments, reviews, and forms you fill out.
    • Passive footprint. Data collected without your direct action: your IP address, location, browsing history, and the tracking that follows you between websites.

    You control the active part with your choices. You limit the passive part with settings and tools.

    Who collects this data?

    Businesses collect it to improve services and target ads. Data brokers gather it from public records and other companies, then sell profiles. Criminals collect it from social media, breached databases, and the same broker sites that anyone can search.

    How do criminals use my digital footprint?

    • Targeted phishing. A message that names your employer, your bank, or your recent trip is far more convincing than a generic one.
    • Identity theft. A full name, birth date, and address are enough to open accounts or file fraudulent claims.
    • Account takeover. Security questions ask for your first pet, your school, or your mother’s maiden name. Your profile often answers all three.
    • Physical risk. A post announcing your vacation also announces your empty house.
    • Impersonation. Criminals copy your photos and name to scam your friends and family.

    One birthday post, one tagged location, and one old forum account add up. Attackers combine small details that look harmless on their own.

    How do I check my digital footprint?

    1. Search your full name in quotation marks, with your city, on more than one search engine. Check the image results too.
    2. Search your email addresses and phone number.
    3. Enter your email at haveibeenpwned.com to see which breaches included it.
    4. View your social media profiles while logged out, or use the “view as public” feature.
    5. List the old accounts you no longer use.

    Write down what you find. The surprises tell you where to start.

    How do I reduce my digital footprint?

    1. Think before you post. Leave out your home address, phone number, birth date, and financial details.
    2. Tighten privacy settings. Limit your profiles to friends, and hide your friend list and contact details.
    3. Use strong, unique passwords. A password manager makes this practical.
    4. Turn on two-factor authentication. It protects an account when its password leaks.
    5. Watch for phishing. Treat unexpected links and attachments with suspicion.
    6. Monitor your accounts. Review bank and card statements, and report charges you don’t recognize.
    7. Limit app permissions. Deny access to contacts, location, and photos unless the app needs it.
    8. Delete old accounts. Close the ones you no longer use.
    9. Post about trips after you return.
    10. Use a VPN on public Wi-Fi. It encrypts your traffic on networks you don’t control. It does not make you anonymous, and it does not hide what you post.

    Can I delete my digital footprint?

    Not all of it. You can remove a great deal.

    • Delete old posts and close unused accounts.
    • Ask search engines to remove results that show sensitive personal information. Google offers a request form for this.
    • Opt out of data broker sites. Each one has its own process, and some services handle the requests for a fee.
    • Ask companies to delete your data. Privacy laws in several US states give residents that right.

    Information that others have copied or archived can persist. Reducing what is out there still lowers your risk.

    Should I freeze my credit?

    A credit freeze stops anyone from opening new credit in your name. It is free in the United States, and you place it with each of the three credit bureaus: Equifax, Experian, and TransUnion. You lift it when you apply for credit yourself. If your personal information has appeared in a breach, a freeze is one of the strongest protections you have.

    How do I protect my family’s footprint?

    • Ask before you post photos of children, and leave out school names and locations.
    • Help older relatives set their profiles to private.
    • Agree on a family rule about what stays offline, such as travel plans and home addresses.

    Does my business have a digital footprint too?

    Yes. Your website, staff listings, social media, and job posts tell an attacker who works for you, who handles money, and which software you use. Criminals use that to write emails that pose as your owner or your vendors.

    • Don’t publish direct emails for staff who handle payments.
    • Train employees on what they share about work online.
    • Set a rule that any payment change gets a phone call to confirm.

    How often should I check?

    Review your footprint twice a year, and again after any breach notice. Managing your footprint is an ongoing habit, because you add to it every day.

    What do data brokers know about me?

    Data brokers are companies that collect personal details from public records, apps, loyalty programs, and other businesses, then sell the combined profile. A typical profile holds your current and past addresses, phone numbers, relatives, age, and property records. People-search websites are the public face of this trade, and anyone can look you up on them for a few dollars.

    To push back, search your name on the larger people-search sites and use each site’s opt-out page. The process takes time, and listings can return, so repeat it once or twice a year.

    Your next step

    Run the five-step check above this week and fix the two biggest surprises. If you want your team to learn how attackers use public information against a business, Cerberus Cybersecurity covers it in our cybersecurity training. Contact us to learn more.

  • The MOVEit Breach Explained: What Happened and What It Teaches

    The MOVEit Breach Explained: What Happened and What It Teaches

    By J. Mesa

    In late May 2023, a criminal group began stealing files from organizations around the world through a single piece of software. The software was MOVEit Transfer, and the attack became one of the largest data theft events on record.

    I first wrote about it in our June 2023 Cyber Bytes. This post is the full explanation: what happened, who was affected, and what a small business can learn from it.

    What is MOVEit?

    MOVEit Transfer is a managed file transfer product made by Progress Software. Organizations use it to send large or sensitive files in a secure way, such as payroll data, health records, and financial reports. Banks, governments, universities, and the vendors that serve them relied on it.

    That is the reason the breach spread so far. The product existed to move the most sensitive files an organization had.

    What happened in the MOVEit breach?

    Attackers found a flaw in MOVEit Transfer that the vendor did not yet know about. A flaw like that is called a zero-day, because the vendor has had zero days to fix it.

    The flaw is tracked as CVE-2023-34362. It was a SQL injection vulnerability, which means an attacker could send crafted input to the application and make its database run the attacker’s commands. Through it, the attackers installed a hidden backdoor on MOVEit servers and downloaded the stored files.

    Progress Software disclosed the flaw and released a fix on May 31, 2023. By then the attackers had already been at work for days.

    Who was behind the attack?

    A ransomware group known as Clop, also written Cl0p, claimed responsibility. In this campaign the group did not encrypt its victims’ files. It stole the data and then threatened to publish it unless each victim paid.

    Security teams call this data extortion. It works on organizations that have good backups, because a backup does not undo a leak.

    How many organizations were affected?

    Researchers who tracked the campaign counted more than 2,500 organizations and tens of millions of individuals. The victims included government agencies, banks, universities, healthcare providers, and large employers.

    Many of them never ran MOVEit. Their payroll provider, pension administrator, or other vendor did. The attackers reached those organizations’ data through a supplier.

    Was my data exposed in the MOVEit breach?

    If it was, the affected organization should have sent you a notice. You can also:

    • Search your email address at haveibeenpwned.com
    • Review letters from your employer, bank, health plan, or state agencies from 2023 and 2024
    • Take up any free credit monitoring those notices offered

    If your data was exposed, place a free credit freeze with Equifax, Experian, and TransUnion, and treat unexpected messages about your accounts with suspicion.

    Why did the attack spread so fast?

    • The software faced the internet. MOVEit servers accept connections from outside, so attackers could reach them directly.
    • Nobody had a patch. A zero-day leaves defenders with no fix until the vendor releases one.
    • The attackers prepared. They struck many servers in a short window, before word spread.
    • The data was concentrated. One server held files from many clients.

    What is a supply chain attack?

    A supply chain attack reaches you through a company you trust. You hand your data to a vendor, and the attacker breaks into the vendor.

    MOVEit showed how far that reaches. Your security depends on your own controls and on the controls of every company that holds your data.

    What should a business do after an incident like this?

    1. Find out if you run the affected product. Check your own systems, then ask your vendors.
    2. Apply the vendor’s fix right away. If you can’t, take the system offline until you can.
    3. Look for signs of intrusion. Follow the vendor’s guidance on what to check.
    4. Reset credentials that the system stored or used.
    5. Notify affected people as the law requires.

    What does MOVEit teach a small business?

    • Patch fast. Install security updates as soon as vendors release them, and start with anything that faces the internet.
    • Know your vendors. Keep a list of who holds your data and what they hold. Ask each one how they protect it and how they will tell you about a breach.
    • Limit what you share and store. Send vendors only the data they need. Delete files from transfer systems once they have arrived.
    • Control access. Use multi-factor authentication and give each account the least access it needs.
    • Train your people. After a breach, criminals send phishing emails that use the stolen details. Staff who expect that are harder to fool.
    • Plan your response. Decide now who you will call and how you will notify customers.

    What questions should I ask my vendors?

    1. Which of our data do you store, and for how long?
    2. How fast do you install security updates?
    3. Do you require multi-factor authentication for your staff?
    4. How will you notify us of a breach, and within what time?
    5. Do you have an independent security report, such as a SOC 2?

    A vendor who answers these without hesitation takes security seriously. One who can’t answer has told you something too.

    Could this happen again?

    Yes. Attackers have hit other file transfer products with the same playbook before and since. Any widely used tool that holds sensitive data and faces the internet is a target. You can’t prevent a zero-day. You can limit what an attacker finds, and you can respond fast.

    Does good backup protect me from data extortion?

    No. Backups protect you from losing access to your files. They do nothing once an attacker holds a copy. The defenses against data theft are different: store less, encrypt sensitive files, restrict who and what can reach them, and watch for large transfers leaving your network. Plan for both kinds of attack, because criminal groups now use both.

    Should a victim pay the ransom?

    The FBI advises against paying. Payment does not guarantee the criminals delete the data, and it funds the next attack. Each case carries legal and business questions, so involve your attorney, your insurer, and law enforcement before you decide.

    Your next step

    Make a list of every vendor that holds your customer or employee data. If the list surprises you, that is useful to know. Cerberus Cybersecurity helps businesses review vendor risk as part of our risk and compliance assessments. Contact us to get started.

  • How Does Ransomware Get In? 6 Entry Points and How to Close Them

    By J. Mesa

    Ransomware does not appear out of nowhere. Someone clicks, a password leaks, or an old system sits exposed to the internet. Each attack starts at an entry point, and you can close most of them.

    Today, let’s explore the ways ransomware gets into an organization and what to do about each one.

    What is ransomware?

    Ransomware is malware that encrypts your files and demands payment for the key to unlock them. Many groups now steal a copy of your data first and threaten to publish it. That tactic is called double extortion, and it puts pressure on victims who have good backups.

    Ransomware hits businesses of every size. Small companies are frequent targets because they have fewer defenses and less time to recover.

    How does ransomware get into a network?

    1. Phishing emails. The most common route. An email that looks legitimate carries a malicious link or attachment. One click installs malware or hands over a password.
    2. Stolen or weak passwords. Attackers buy leaked credentials or guess weak ones, then log in like an employee.
    3. Exposed remote access. Remote Desktop, VPN gateways, and remote management tools that face the internet give attackers a direct door, above all when they lack multi-factor authentication.
    4. Unpatched software. Attackers scan for known flaws in operating systems, firewalls, and applications, and exploit the ones nobody updated.
    5. Malicious downloads. Fake software updates, pirated programs, and booby-trapped ads install malware when someone runs them.
    6. Compromised vendors. An attacker breaks into your IT provider or software supplier and uses that trusted connection to reach you.

    Unsecured public Wi-Fi adds risk as well. An attacker on the same network can intercept unprotected traffic or steer you to a fake login page.

    What happens after ransomware gets in?

    The encryption is the last step, and the attacker spends the time before it preparing.

    1. Foothold. The attacker gains access to one computer or account.
    2. Exploration. They map your network and look for file servers, backups, and administrator accounts.
    3. Escalation. They steal more powerful credentials.
    4. Theft. They copy your data out.
    5. Encryption. They lock everything at once, often at night or on a weekend.

    This can take days or weeks. That gap is your chance to catch them, if someone is watching for the signs.

    What are the warning signs of a ransomware attack?

    • Logins at odd hours or from unfamiliar locations
    • Security software switched off without explanation
    • New administrator accounts nobody created
    • Backup jobs that fail or get deleted
    • Large amounts of data leaving your network
    • Files with strange extensions that won’t open

    Report any of these right away. Early action can stop the attack before encryption starts.

    How do I protect my business from ransomware?

    • Think before you click. Don’t open attachments or links you did not expect. Verify requests through a channel you trust.
    • Keep software up to date. Install security patches for computers, servers, firewalls, and applications.
    • Use strong, unique passwords. Never reuse a password across accounts. A password manager makes this workable.
    • Turn on multi-factor authentication. Require it for email, remote access, and administrator accounts.
    • Lock down remote access. Don’t expose Remote Desktop to the internet. Put remote access behind a VPN with multi-factor authentication.
    • Back up your data. Follow the 3-2-1 rule: three copies, two types of storage, one offline or offsite.
    • Use security software. Run reputable antivirus or endpoint protection on every device.
    • Limit access. Staff should reach only the files their job needs. Everyday accounts should not have administrator rights.

    Do backups stop ransomware?

    Backups don’t stop an attack. They let you recover without paying. Three rules make them count:

    • Keep one copy offline or in storage the attacker can’t reach from your network. Ransomware looks for backups and destroys them.
    • Test a restore on a schedule. An untested backup is a guess.
    • Know how long a full restore takes, so you can plan for the downtime.

    Backups do not help with stolen data. For that you need to limit what you store and who can reach it.

    Should I pay the ransom?

    The FBI advises against paying. Payment does not guarantee you get your files back, and it funds more attacks. Some victims who paid received a broken decryption tool or a second demand.

    The decision carries legal and business weight. Involve your attorney, your cyber insurer, and law enforcement before you choose.

    What should I do if ransomware hits?

    1. Disconnect affected computers from the network. Unplug the cable and turn off Wi-Fi. Don’t power them off unless your responder tells you to, because that can destroy evidence.
    2. Call for help. Contact your IT provider, your cyber insurer, and an incident response firm.
    3. Report it. Notify the FBI at ic3.gov. CISA also takes reports.
    4. Preserve evidence. Keep the ransom note and any logs.
    5. Check your backups before you restore, to confirm they are clean.
    6. Reset passwords from a clean device.
    7. Notify affected people if data was stolen, as the law requires.

    How do I train employees to stop ransomware?

    Your people see the phishing email before any tool does. Teach them:

    • What a phishing email looks like, with real examples
    • How to report a suspicious message in one click
    • That reporting a mistake fast earns thanks, not blame

    Run short sessions through the year. A single annual lecture fades within weeks.

    Do I need an incident response plan?

    Yes. A one-page plan beats none. List who makes decisions, who you call, where the backups are, and how you reach staff if email is down. Print it. You can’t open a file on a locked computer.

    Is antivirus enough?

    No. Antivirus is one layer. Attackers who log in with a stolen password look like normal users, and antivirus has nothing to flag. You need the full set: patches, multi-factor authentication, backups, limited access, and trained people.

    Your next step

    Walk through the six entry points above and ask which ones are open at your business. If you’d like help, reach out to our team. Cerberus Cybersecurity builds training and awareness programs that equip your staff to defend themselves and your customers. At Cerberus, it’s people first. Contact us today.

  • Log4Shell Explained: What It Is, Who Is at Risk, and How to Check

    Log4Shell Explained: What It Is, Who Is at Risk, and How to Check

    By J. Mesa

    In December 2021, security teams around the world spent their holidays hunting for one small piece of software. A flaw in a logging tool called Log4j let an attacker take over a server by sending it a single line of text. The flaw got the name Log4Shell, and attackers still use it today.

    You may never have heard of Log4j. Your business may still run it. This post explains what happened, who is at risk, and what to check.

    What is Log4Shell?

    Log4j is a free, open-source logging library for the Java programming language. Developers use it to record what an application does: who logged in, what a user searched for, which errors occurred. Thousands of commercial products include it, from web applications to network appliances.

    Log4Shell is the name for a vulnerability in Log4j tracked as CVE-2021-44228. Researchers disclosed it on December 9, 2021. It received a severity score of 10 out of 10, the highest rating possible.

    How does the Log4Shell attack work?

    Log4j had a feature that looked up information whenever it found a special instruction inside a log message. An attacker could place that instruction anywhere the application would log it: a username field, a search box, a web request header.

    1. The attacker sends text containing a lookup instruction that points to a server the attacker controls.
    2. The application writes that text to its log.
    3. Log4j reads the instruction, connects to the attacker’s server, and downloads code.
    4. The application runs that code. The attacker now controls the system.

    The attacker needs no password and no account. The industry calls this remote code execution, and it is the reason the score reached 10.

    Why was Log4Shell so serious?

    • It was everywhere. Log4j sat inside products from hundreds of vendors. Many companies did not know they used it.
    • It was easy. Working attack code spread within hours of disclosure.
    • It was hidden. Log4j often sits several layers deep inside other software, so finding it took weeks.

    The director of the US Cybersecurity and Infrastructure Security Agency (CISA) at the time called it one of the most serious vulnerabilities she had seen in her career. Criminal groups and nation-state actors both used it. Botnets such as Mirai and Kinsing scanned the internet for vulnerable servers and installed malware, cryptocurrency miners, and ransomware.

    Is Log4Shell still a threat?

    Yes. Many organizations patched in 2021 and 2022. Many forgotten or unmanaged applications still run vulnerable versions, and attackers keep scanning for them. In 2022 the US Cyber Safety Review Board called Log4Shell an “endemic vulnerability” and warned that vulnerable copies would stay in systems for a decade or longer.

    Old software does not fix itself. The server someone set up in 2019 and forgot is the one an attacker finds.

    Am I affected if my business doesn’t write software?

    You can be. You don’t need a developer on staff to run Java software. Log4j shipped inside products that small businesses buy and install, including:

    • Network and security appliances
    • Remote access and virtual desktop products
    • Backup, monitoring, and help desk tools
    • Line-of-business applications from smaller vendors

    Cloud services you subscribe to were the vendor’s job to patch. Software and devices in your own office or server room are your job.

    How do I check if I am vulnerable to Log4Shell?

    1. List what you run. Write down every server, appliance, and business application you own, with its version. You can’t patch what you don’t know about.
    2. Check vendor advisories. Search each vendor’s site for “Log4j” or “CVE-2021-44228.” Most published a statement and a fixed version.
    3. Scan. A vulnerability scan finds known-vulnerable versions of Log4j on your network. This is a standard part of a vulnerability assessment.
    4. Look for old systems. Pay attention to anything installed before 2022 that no one has updated since.

    Vulnerable versions of Log4j run from 2.0-beta9 through 2.14.1.

    How do I fix Log4Shell?

    • Update the affected product to the vendor’s fixed release. For Log4j itself, that means version 2.17.1 or later on Java 8.
    • If a vendor no longer supports the product, replace it or take it off the network.
    • Limit which servers can make outbound connections to the internet. The attack depends on your server reaching out to the attacker.
    • Watch your logs for the text ${jndi:, the marker of an attempted attack.

    What did Log4Shell teach us?

    • Know your software supply chain. You depend on code you never chose. Keep an inventory of the products you run and the components inside them.
    • Patch fast. Attackers began exploiting Log4Shell within hours. A patch process that takes months leaves the door open.
    • Detect and respond. You need a way to see an attack in progress and a tested plan for what to do next.
    • Train your people. Staff who know how to report something odd shorten the time an attacker spends inside your network.

    What should a small business do now?

    1. Build or update your inventory of systems and software.
    2. Turn on automatic updates wherever a product offers them.
    3. Schedule a vulnerability assessment at least once a year.
    4. Write a one-page incident response plan and walk through it with your team.

    What is a software bill of materials, and do I need one?

    A software bill of materials (SBOM) is an ingredient list for a piece of software. It names every component inside the product, including libraries such as Log4j. When the next Log4Shell arrives, a company with SBOMs can search them and know within minutes which products to patch.

    You don’t need to build one yourself. Ask your software vendors whether they provide an SBOM, and ask how they notify customers about security fixes. A vendor with clear answers to both questions handled Log4Shell faster than one without. Add those two questions to your checklist when you buy new software.

    Your next step

    If you don’t know whether a vulnerable system sits on your network, find out before an attacker does. Cerberus Cybersecurity runs risk and compliance assessments that include vulnerability scanning and a plain-language report. Contact us to schedule one.

  • 4 Common Causes of Data Breaches (and Real Cases That Show Them)

    4 Common Causes of Data Breaches (and Real Cases That Show Them)

    By J. Mesa

    Most data breaches trace back to a short list of causes. April 2023 delivered a clear example of four of them in a single month. I covered those incidents in our May 2023 Cyber Bytes, and the lessons still apply.

    This post walks through each cause, the real case behind it, and what your business can do.

    What is a data breach?

    A data breach is any incident where someone gains access to information they have no right to see. It can result from an attack, a configuration mistake, a lost device, or an insider. The data may be customer records, employee files, login credentials, or business documents.

    Cause 1: How do attackers steal data from healthcare providers?

    The case. Shields Health Care Group, a medical imaging provider, reported the largest breach of the month. An intruder accessed its systems and exposed the personal data of about 2.3 million people.

    Why it happens. Healthcare records hold names, birth dates, insurance details, and medical history in one place. That makes them valuable for fraud. Providers also run many connected systems, which gives an intruder room to move.

    How to prevent it.

    • Limit each account to the records its user needs
    • Require multi-factor authentication
    • Monitor for unusual access to patient or customer files
    • Encrypt sensitive data

    Any business that holds health information for a provider falls under HIPAA as well, so the same rules reach billing companies and IT vendors.

    Cause 2: What is a cloud misconfiguration?

    The case. ICICI Bank, a major Indian financial institution, faced a data leak tied to misconfigured cloud storage. Researchers reported that sensitive files, including bank statements and card details, sat open to the internet.

    Why it happens. Cloud storage is secure when its settings are right. A storage folder set to public, a sharing link open to anyone, or an account without multi-factor authentication exposes everything inside. No attacker has to break in, because the data is already out.

    How to prevent it.

    • Review who can see each cloud folder and remove public access
    • Turn off “anyone with the link” sharing for sensitive files
    • Require multi-factor authentication on every cloud account
    • Check settings again after any change in staff or vendors

    Cause 3: How does ransomware lead to a data breach?

    The case. Capita, a business services company in the United Kingdom, suffered a ransomware attack. Staff lost access to Microsoft Office applications, and the attackers also stole data.

    Why it happens. Modern ransomware groups copy your files before they lock them. The outage is the visible damage. The stolen data causes the longer problem, because it leads to notifications, legal exposure, and extortion.

    How to prevent it.

    • Train staff to spot phishing, the most common way in
    • Patch systems, with internet-facing ones first
    • Keep an offline backup and test it
    • Limit how far one compromised account can reach

    Cause 4: Why are old systems a security risk?

    The case. The American Bar Association disclosed a breach that exposed the login credentials of about 1.4 million members. The data came from a legacy system the organization had decommissioned in 2018.

    Why it happens. Retired systems still hold data. Nobody patches them, nobody watches them, and the credentials inside often still work elsewhere because people reuse passwords.

    How to prevent it.

    • Keep an inventory of every system, including the ones you no longer use
    • Delete or archive the data when you retire a system
    • Shut old systems down for good and remove them from the network
    • Require password changes when old credentials may be exposed

    What do these four breaches have in common?

    None of them needed an exotic technique. Each came from a basic gap:

    • Too much access
    • A wrong setting
    • A successful phishing email or an unpatched system
    • A forgotten server

    Attackers look for the easy way in. Closing the basic gaps removes most of their options.

    How do I know if my business has been breached?

    • Customers or staff receive phishing emails that use real details about them
    • Accounts show logins from unfamiliar places
    • You find new user accounts or mail forwarding rules nobody created
    • A vendor, a bank, or law enforcement contacts you
    • Your data or credentials appear in a breach lookup such as haveibeenpwned.com

    Many organizations learn about a breach from an outside party, months after it began. Monitoring shortens that gap.

    What should I do after a breach?

    1. Contain it. Disconnect affected systems and reset passwords from a clean device.
    2. Call your IT provider, your cyber insurer, and your attorney.
    3. Find out what data was involved and whose it was.
    4. Notify affected people and regulators as the law requires.
    5. Fix the cause before you bring systems back.

    What are the takeaways for everyone?

    • Be careful with online interactions. Treat unexpected emails and links with suspicion, at work and at home.
    • Use strong, unique passwords. A different password for every account means one breach does not open the others. Add multi-factor authentication.
    • Stay current. Keep systems updated with security patches, and stay informed about new threats.

    How can a small business lower its breach risk this month?

    1. List every system and cloud account you own, including old ones.
    2. Remove access for former staff and vendors.
    3. Check cloud sharing settings.
    4. Turn on multi-factor authentication everywhere it is offered.
    5. Run a phishing awareness session.

    Who is responsible when a vendor causes the breach?

    You are, in the eyes of your customers. If a payroll company, an IT provider, or a cloud service loses data you gave it, the people affected still gave that data to you. Most breach notification laws put the duty to notify on the business that collected the information.

    Lower that risk before it arrives. Ask each vendor how it protects your data, write security and notification terms into the contract, and share only what the vendor needs to do its job.

    Your next step

    Staying informed and practicing the basics lets us all reduce the impact of cyberattacks. If you want to know which of these four gaps exist in your business, Cerberus Cybersecurity can show you with a risk and compliance assessment. Reach out to us to see how we can help you defend against cyberattacks.

  • What Is Tech Debt? How Small Businesses Can Manage It Before It Bites

    What Is Tech Debt? How Small Businesses Can Manage It Before It Bites

    By J. Mesa

    Technology is the lifeblood of most small and medium-sized businesses. Like any powerful tool, it carries hidden costs. One of the largest is technology debt.

    This post explains what tech debt is, how to spot it, what it costs, and how to pay it down without replacing everything at once.

    What is tech debt?

    Technology debt, or tech debt, is the buildup of outdated systems, postponed upgrades, and quick fixes that make your technology harder and riskier to run. The term comes from software development, where a shortcut taken today creates extra work later, the way a loan creates interest.

    Think of website maintenance you keep putting off. Over time the site gets slow, buggy, and open to attack. Tech debt does the same thing across your whole business.

    What are examples of tech debt in a small business?

    • A server or PC running an operating system that no longer receives security updates
    • Accounting or point-of-sale software several versions behind
    • A spreadsheet that runs a critical process and that only one person understands
    • A firewall or router nobody has updated in years
    • Shared passwords and accounts for staff who left long ago
    • Custom software written by a contractor you can no longer reach

    What are the signs my business has tech debt?

    • Outdated systems. You rely on aging hardware or old software. That brings compatibility problems, security holes, and trouble adopting newer tools such as cloud services.
    • Workarounds. “Duct tape” fixes hold your systems together. Each one adds another piece that can break.
    • Frequent outages and errors. Crashes, lost data, and slow performance show an infrastructure under strain.
    • Trouble scaling. Your systems can’t handle more clients or more staff.
    • Security concerns. Your software has known vulnerabilities that the vendor has stopped fixing.

    Two or more of these means the debt is already costing you.

    Why is tech debt a security risk?

    Attackers scan the internet for systems with known flaws. Software that no longer receives updates keeps every flaw found after its end date, forever. Each month adds to the list.

    Outdated systems also tend to lack modern protections such as multi-factor authentication and encryption. They fail compliance checks for standards such as PCI-DSS and HIPAA. And they often sit forgotten, which means nobody notices when someone breaks in.

    What does it cost to ignore tech debt?

    Ignoring tech debt is like ignoring a leaky roof. It looks manageable at first, and the repair bill grows the longer you wait.

    • Lost productivity. Slow, unreliable systems waste staff time every day.
    • Higher costs. Old systems need special skills and hard-to-find parts. For our island community the problem is sharper, because everything is imported and shipping adds cost and delay.
    • Security breaches. One breach can bring financial loss and lasting damage to your reputation.
    • Lost opportunity. You can’t adopt tools that would help you compete, such as automation and data analytics.

    How do I measure my tech debt?

    Run a simple technology audit. A spreadsheet works.

    1. List every device, application, and online service you use.
    2. For each, record its age, its version, and whether the vendor still supports it.
    3. Note what business process depends on it.
    4. Mark what would happen if it failed tomorrow.

    The items that are unsupported and critical go to the top of your list.

    How do I manage tech debt on a small budget?

    You don’t have to replace everything overnight. Follow five steps.

    1. Prioritize and plan. Use your audit to rank the issues by severity and business impact. Start with security risks and the systems that block growth. Set a realistic roadmap with milestones.
    2. Decide between modernizing and replacing. Compare the cost of updating a system against the cost of a new one. Cloud-based services can lower maintenance and include ongoing support.
    3. Invest in employee training. New tools only help when your team knows how to use them.
    4. Put security first. Update software, maintain your firewall, and encourage safe online habits.
    5. Seek expert help. An IT consultant can build a plan that fits your business and your budget.

    Should I repair or replace an old system?

    Ask four questions:

    • Does the vendor still provide security updates?
    • Can it support multi-factor authentication and encryption?
    • Does keeping it cost more per year than replacing it, once you count downtime?
    • Does it hold up a process the business depends on?

    If the vendor has ended support, plan a replacement. If you can’t replace it yet, isolate it from the rest of the network and limit who can reach it.

    How do I avoid new tech debt?

    • Budget for replacement when you buy. Plan on three to five years for computers.
    • Turn on automatic updates wherever you can.
    • Document how your systems work, so the knowledge does not sit with one person.
    • Review your technology list once a year.
    • Before you add a tool, check how long the vendor will support it.

    How long does it take to pay down tech debt?

    It depends on how much has built up. Most small businesses can fix their highest risks within a few months and spread the rest across one to two budget years. Tackling tech debt is an ongoing process. You maintain technology the way you maintain a building.

    What is end of life software, and why does it matter?

    End of life means the vendor has stopped releasing updates, including security fixes. From that date the product gets less safe every month. Vendors publish these dates years ahead. Add them to your technology list so a deadline never surprises you.

    Can cyber insurance cover problems caused by outdated systems?

    Do not count on it. Insurers ask about your systems when you apply, and many policies exclude or limit claims tied to unsupported software. An honest application that lists old systems can raise your premium. Replacing them can lower it.

    Your next step

    Start your audit this week with the ten systems your business depends on most. By facing tech debt and taking steady steps, a small business gains efficiency, stronger security, and room to grow. Contact Cerberus Cybersecurity to learn how we can support your organization with a risk assessment that shows where outdated technology puts you at risk.

  • Social Media Safety: 10 Ways to Spot Scams and Fake Friends

    By J. Mesa

    Social media is great for catching up with friends, watching funny pet videos, and picking up a kådu recipe or two. Like any busy place, it has a few shady characters. They want your personal information, your money, or your account.

    You can outsmart them. Here are ten habits that keep you safe, plus what to do if something goes wrong.

    What are the most common social media scams?

    • Fake friend or follow requests from copied or invented profiles
    • Phishing messages that link to fake login pages
    • Marketplace and shopping scams with deals that never ship
    • Giveaway and prize scams that ask for a fee or your details
    • Romance and investment scams that build trust over weeks, then ask for money
    • Impersonation of someone you know, asking for urgent help

    Every one of them works by getting you to trust the wrong person.

    1. How do I spot a fake friend request?

    Don’t accept requests from people you don’t know. Check the profile first.

    • Few photos, or photos that look like stock images
    • An account created in the last few weeks
    • No friends in common
    • A second request from someone who is already your friend

    That last one means a scammer copied your friend’s profile. Decline it, and tell your friend through another channel.

    2. What do phishing messages look like?

    Scammers send private messages that look real. Be careful with any message that:

    • Pressures you. “Act now” and “limited time offer” are meant to stop you from thinking.
    • Has odd spelling or grammar. Real companies proofread.
    • Contains a link. Hover over it on a computer, or press and hold on a phone, to see the real address before you open it.
    • Asks for your password or a code. Real platforms never ask for these in a message.

    3. Should I trust a deal that looks too good?

    No. A price far below normal, a seller who wants payment by gift card or wire, or a buyer who “overpays” and asks for a refund are all scams. Pay through the platform’s own checkout, which offers buyer protection.

    4. How do I check before I share?

    False stories travel fast. Before you share a post that makes you angry or afraid, look for the same story on a news source you trust. If you can’t find it, don’t pass it on.

    5. Why should I avoid clickbait?

    Headlines built to shock often lead to sites that install malware or collect your data. If a headline looks too wild to be true, it is. Skip the link.

    6. How do I lock down my profile?

    • Privacy settings. Control who sees your posts, your friend list, and your contact details. Set them to friends only.
    • Passwords. Use a strong, different password for each account. A password manager helps.
    • Two-factor authentication. Turn it on. It works like a second lock on your door.
    • Personal details. Keep your birthday, address, and phone number off your public profile.

    7. How much sharing is too much?

    Posting where you are in real time tells strangers when your house is empty. Details such as your pet’s name, your school, and your hometown answer common security questions. Share trip photos after you get home, and keep the answers to security questions to yourself.

    8. Are quizzes and giveaways safe?

    Be careful. “Which character are you?” quizzes often ask for the same facts banks use to verify you. Giveaways with huge prizes collect personal details or ask for a “shipping fee.” Research any contest before you enter, and never pay to claim a prize.

    9. What is like-farming?

    Scammers post content designed to collect likes and shares, such as “Share if you love your mom.” Once the page has a large audience, they change it to promote scams or sell it. Don’t like or share suspicious posts to help someone gain followers.

    10. How do I report a scam or a fake account?

    Every major platform has a report button on profiles, posts, and messages. Use it. Reporting gets fake accounts removed and protects the next person. You can also report fraud to the Federal Trade Commission at reportfraud.ftc.gov.

    What should I do if my account gets hacked?

    1. Change your password right away. If you can’t log in, use the platform’s account recovery page.
    2. Log out of all other devices in the security settings.
    3. Turn on two-factor authentication.
    4. Check for changes: a new email address or phone number on the account, new posts, new messages.
    5. Tell your friends, so they ignore messages the attacker sent as you.
    6. Change the password on any other account that used the same one.

    What should I do if I sent money to a scammer?

    Act fast. Call your bank or card company and ask to stop or reverse the payment. Report the scam to the platform, to reportfraud.ftc.gov, and to the FBI at ic3.gov. Keep screenshots of the profile and the messages. The sooner you report, the better your chance of getting money back.

    How do I help kids and older relatives stay safe?

    Teach your friends and family, and pay special attention to our Manåmko’. Scammers target older adults with fake family emergencies and prize notices.

    • Agree that any request for money gets a phone call to confirm, on a number you already have.
    • Set up privacy settings and two-factor authentication on their accounts with them.
    • Remind them that a real friend will not mind waiting while they check.

    For kids, keep accounts private, know who they talk to, and make it easy for them to tell you when something feels wrong.

    Is it safe to log in to other sites with my social media account?

    It is convenient, and it ties those sites to one account. If someone takes over that account, they reach everything connected to it. Protect it with a strong password and two-factor authentication, and review the list of connected apps in your settings once or twice a year. Remove the ones you no longer use.

    What habits keep me safe over time?

    • Trust your gut. If something feels off, ignore the message or block the person.
    • Stay updated. Platforms change their security settings often. Check yours a few times a year.
    • Spread the word. The more people who know these tricks, the fewer victims scammers find.

    Your next step

    Spend ten minutes today on your privacy settings and turn on two-factor authentication. If your business uses social media, your team needs these skills too. Cerberus Cybersecurity teaches them in our cybersecurity training. Contact us to set up a session.

  • 4 Major Data Breaches of 2023 and What Small Businesses Can Learn

    4 Major Data Breaches of 2023 and What Small Businesses Can Learn

    By J. Mesa

    March 2023 was a rough month for cybersecurity. A financial company, a pharmacy services provider, a phone carrier, and a school district all disclosed breaches within weeks of each other. I covered them in our April 2023 Cyber Bytes.

    The details differ. The lessons repeat, and they apply to a business of any size.

    What happened at Latitude Financial?

    Latitude Financial, an Australian consumer lender, disclosed a breach that reached about 14 million customer records. The stolen data included driver’s license numbers, passport numbers, and financial statements.

    The lesson: keep less data. Many of the records belonged to past customers and applicants. Data you no longer need is risk with no benefit.

    • Set a retention period for each type of record
    • Delete or destroy records when the period ends
    • Collect ID documents only when the law requires it

    What happened at PharMerica?

    PharMerica, a large US pharmacy services provider, suffered a ransomware attack. The attackers took personal information on nearly 6 million people, including names, addresses, Social Security numbers, and health data.

    The lesson: ransomware is also data theft. Attackers steal first and encrypt second. Healthcare organizations of every size, including small clinics, hold the kind of data they want.

    • Patch systems, and start with those that face the internet
    • Keep an offline backup and test it
    • Encrypt sensitive records
    • Limit each account to the data its user needs

    What happened at T-Mobile?

    T-Mobile started 2023 by disclosing a breach that affected about 37 million customer accounts. In the spring it disclosed a second, smaller incident that affected 836 customers and exposed account PINs and personal details.

    The lesson: one fix is not the end. A company that has been breached once stays a target. Security needs steady attention, with regular reviews and monitoring.

    • Review access and security settings on a schedule
    • Monitor for unusual activity on customer accounts
    • Treat every incident as a reason to look for related gaps

    What happened at Minneapolis Public Schools?

    A cyberattack disrupted the district’s computer systems for days. The attackers later published student and employee data online.

    The lesson: attackers go where defenses are thin. Schools, local governments, and nonprofits hold sensitive records and run on tight budgets. The same is true of many small businesses.

    • Know what sensitive data you hold and where
    • Have a response plan before you need one
    • Decide in advance how you will communicate with the people affected

    Were small businesses hit too?

    Yes. Small business breaches seldom make national news, and reports from the same period describe many of them. Most involved phishing or ransomware, and they exposed financial data, customer information, and internal documents.

    A small company faces the same attackers with fewer resources. It also has one advantage: fewer systems and fewer people make the basics easier to get right.

    What do these breaches have in common?

    • Valuable data in one place. Each victim held large volumes of personal information.
    • A gap in the basics. Access controls, patching, and monitoring matter more than advanced tools.
    • Costs beyond the attack. Notification, legal work, and lost trust followed each one.

    How do breaches like these affect me as a customer?

    If your data was in one of these breaches:

    1. Read the notice the company sent and accept any free credit monitoring.
    2. Place a free credit freeze with Equifax, Experian, and TransUnion.
    3. Change your password and PIN on the affected account, and anywhere you reused them.
    4. Watch for phishing that mentions the breach. Criminals use stolen details to look legitimate.

    What should a small business do now?

    1. Invest in employee training. Teach staff to recognize and avoid phishing.
    2. Use strong passwords and multi-factor authentication. Make it harder for attackers to log in.
    3. Back up your data on a schedule. Have a tested plan to restore it after an attack.
    4. Reduce what you store. Delete records you no longer need.
    5. Consider outside help. A security firm can find gaps you don’t see.

    How much does a breach cost a small business?

    The bill has several parts: recovery work, legal advice, notification, lost sales during downtime, and customers who leave. Businesses that hold regulated data can also face fines. For many small companies, the downtime alone threatens the business.

    Does cyber insurance help?

    It can. A policy can pay for forensic investigation, legal help, notification, and business interruption. Insurers expect controls such as multi-factor authentication and backups, and they ask about them on the application. Insurance works alongside good security. It does not replace it.

    How do I prepare before a breach happens?

    • Write a one-page incident response plan with names and phone numbers
    • Keep a printed copy
    • Know your notification duties under state law and any industry rules
    • Run a short tabletop exercise once a year: walk through a pretend breach and see where the plan falls short

    How can I tell if a breach notice is real?

    Scammers send fake breach notices to steal more information. A real notice does not ask you to click a link and enter your password or Social Security number. If you receive one, go to the company’s website by typing its address yourself, or call a number you already have, and confirm the notice there.

    Which industries do attackers target most?

    Any industry that holds personal or financial data draws attention. Healthcare, finance, education, retail, and professional services such as law and accounting appear in breach reports year after year. Attackers follow two things: data they can sell and organizations that can’t afford downtime. If your business fits either description, plan as though you are on the list.

    How long do I have to notify people after a breach?

    It depends on the law that applies. US state laws set their own deadlines, and many call for notice without unreasonable delay. Rules for health and financial data add their own timelines. Learn your deadlines now, and keep your attorney’s number in your response plan.

    Your next step

    Organizations must keep adapting their defenses to protect their money, their reputation, and the people who trust them. If you want to know how your business would hold up, Cerberus Cybersecurity can help with training, policy, and risk assessments. Visit our contact page to get in touch.

  • State-Sponsored Hackers: Lessons From a North Korean Espionage Campaign

    State-Sponsored Hackers: Lessons From a North Korean Espionage Campaign

    By J. Mesa

    Biba Mes CHamoru! This post looks at a cybersecurity incident that shows how malicious actors backed by a national government operate, and what the rest of us can learn from it.

    What happened in this campaign?

    In February 2023, security researchers reported that a North Korean hacking group had run an espionage campaign from August through November 2022. The group broke into organizations in medical research, healthcare, defense, energy, and chemical engineering, along with a leading research university.

    The attackers took large volumes of data from their victims and stayed undetected for months.

    Who was behind it?

    Researchers at the security firm WithSecure attributed the campaign to the Lazarus Group, a hacking organization linked to the North Korean government. Lazarus has a long record. Governments and researchers have tied it to the 2014 attack on Sony Pictures, the 2016 theft from Bangladesh Bank, and the 2017 WannaCry ransomware outbreak.

    What is a state-sponsored hacking group?

    A state-sponsored group works for, or with the support of, a national government. Its goals differ from those of ordinary criminals:

    • Espionage. Stealing research, defense information, and trade secrets
    • Money. Funding the government through theft, including cryptocurrency theft
    • Disruption. Preparing to damage another country’s critical services

    These groups have time, funding, and patience. Security teams often call them advanced persistent threats, or APTs.

    How did the attackers get in?

    According to the researchers, the group entered at least one victim through an unpatched email server. A fix for the flaw existed. The victim had not installed it.

    That detail matters. A well-funded government group did not need a secret technique. It used a known flaw in software that someone forgot to update.

    How did they stay hidden for months?

    Once inside, the attackers moved with care.

    • They used legitimate administration tools already present on the network, so their activity looked normal.
    • They created their own accounts and used stolen credentials.
    • They moved data out in pieces over time.

    It is common for attackers to remain inside a network for a long time before anyone notices. If that makes you uneasy, you have the right mindset.

    Why did they target these industries?

    • Medical research and healthcare. These organizations hold patient data and valuable research. Stolen health information harms the people it describes.
    • Defense and energy. These hold information tied to national security. An attack on them could compromise government operations or disrupt energy supply, a serious outcome for island communities that depend on a small number of providers.
    • Universities. Research institutions produce new technology with commercial and military value. Stealing it gives a sponsor an advantage it did not earn.

    Would a state-sponsored group target a small business?

    It can happen, for three reasons.

    • You are a route to someone else. Small suppliers, contractors, and IT providers connect to larger targets.
    • Scanning is automated. Attackers look for vulnerable systems across the whole internet. An unpatched server gets found regardless of who owns it.
    • Tools spread. Techniques built by government groups reach criminal groups within months.

    If you hold contracts with government, healthcare, or infrastructure clients, treat this as a direct risk.

    How do I detect an intruder who is already inside?

    • Collect logs from servers, firewalls, and cloud services, and keep them for months
    • Alert on new administrator accounts, logins at odd hours, and large outbound data transfers
    • Review who has administrator rights every quarter
    • Run a vulnerability scan on a schedule
    • Consider a managed detection service if you have no staff to watch alerts

    No system is fully secure. Assume a breach is possible, and build the means to see it.

    What is zero trust?

    Zero trust is a security approach that assumes any user or device could be compromised. Nothing gets access because of where it sits on the network. Each request must prove who it is and that it is allowed.

    In practice, zero trust means:

    • Multi-factor authentication for every user
    • Access limited to what each role needs
    • Network segments that keep one compromised computer from reaching everything
    • Continuous monitoring

    A small business can start with the first two this month.

    Why does employee training matter against advanced attackers?

    Many attacks, including those from government groups, start with a person. Lazarus is known for fake job offers sent to employees on professional networking sites. Staff who can spot social engineering, and who report it, close that door.

    Train your team to:

    • Question unexpected messages, job offers, and file attachments
    • Verify requests through a second channel
    • Report anything suspicious right away, without fear of blame

    What should my business do now?

    1. Patch internet-facing systems first: email servers, VPNs, and firewalls.
    2. Turn on multi-factor authentication for all accounts.
    3. Review administrator accounts and remove the ones you don’t need.
    4. Turn on logging and keep the logs.
    5. Train your staff on social engineering.
    6. Write an incident response plan and test it.

    Where can I report suspected state-sponsored activity?

    In the United States, report to the FBI through your local field office or at ic3.gov, and to CISA at cisa.gov/report. Both agencies share warnings that help other organizations defend themselves.

    How long do attackers stay inside a network before anyone notices?

    Security teams call this dwell time. Industry reports put the typical figure at days to weeks, and espionage groups often stay far longer because they work to avoid attention. In this campaign the intruders operated for months.

    Long dwell time gives an attacker room to find your most valuable data and your backups. Every day you cut from it limits the damage. Logging, alerting, and regular reviews of accounts are the tools that shorten it.

    What is the difference between espionage and ransomware?

    Ransomware announces itself, because the attacker wants payment. Espionage stays quiet, because the attacker wants to keep access. You may never see a ransom note from a spy. The first sign is often a call from law enforcement or a security researcher, which is one more reason to keep good logs.

    Your next step

    This campaign is a reminder that determined attackers succeed through ordinary gaps. Review your defenses and make sure your employees know how to identify and report suspicious activity. Cerberus Cybersecurity offers risk assessments and training built for small and mid-sized organizations. Contact us to start.