Author: J. Mesa

  • Why Cybersecurity Is Good for Business: 6 Ways It Supports Small Business Success

    By J. Mesa

    Most owners think of cybersecurity as a cost. I’d ask you to see it as part of how a small business succeeds. Your company runs on technology and the internet to operate and to reach customers. That reliance brings risk, and managing the risk well gives you an edge over competitors who ignore it.

    This post lays out the business case.

    Why does cybersecurity matter for a small business?

    Without effective security, a small business faces financial loss, damage to its reputation, and legal penalties. With it, the business keeps running, keeps its customers’ trust, and can take on work that less prepared companies can’t.

    1. How does cybersecurity protect revenue?

    A breach or a ransomware attack stops sales. Staff can’t take orders, send invoices, or reach customer records. Each day offline costs money you don’t get back.

    Security measures reduce the chance of an incident and shorten the outage when one occurs. Protecting customer data and financial records prevents direct theft as well.

    2. How does cybersecurity build customer trust?

    Customers hand you their names, addresses, payment details, and sometimes their health or financial history. They expect you to protect it.

    A business that handles data with care keeps its customers. One that loses data loses them, and word spreads. Trust takes years to build and one incident to damage.

    3. How does cybersecurity keep operations running?

    Security prevents the disruptions that malware and other incidents cause. Updated systems crash less. Tested backups turn a disaster into an inconvenience. A written plan means your team knows what to do when something goes wrong.

    Reliable operations are a form of productivity. Your staff spend their time on customers and none of it on recovery.

    4. Can cybersecurity help me win contracts?

    Yes. Larger companies and government agencies now check the security of their suppliers. Expect to see:

    • Security questionnaires before a contract is signed
    • Requirements to follow a framework or standard
    • Requests for proof of cyber insurance
    • Contract terms about breach notification

    A small business that can answer those questions with confidence wins work that competitors lose. Security becomes a selling point.

    5. Does cybersecurity lower insurance and legal costs?

    Cyber insurers price policies by the controls you have. Multi-factor authentication, backups, and training lower your premium and make you insurable at all.

    Security also keeps you on the right side of the rules that apply to your data:

    • PCI-DSS for businesses that accept payment cards
    • HIPAA for health information
    • GLBA and the FTC Safeguards Rule for financial information
    • State privacy and breach notification laws

    Meeting these rules avoids fines and the legal fees that follow a failure.

    6. How does cybersecurity let me adopt new technology?

    Strong security lets a small business adopt tools such as cloud computing, online payments, remote work, and automation with confidence. You can move fast because you know how to do it safely.

    Businesses that fear technology fall behind. Businesses that adopt it without security get hurt. The ones that do both stay competitive as the market changes.

    Is cybersecurity a cost or an investment?

    It is an investment, and you can measure it. Compare the yearly cost of your security measures with:

    • The revenue you would lose in a week of downtime
    • The cost of notifying every customer of a breach
    • The value of contracts that require proof of security
    • The difference in your insurance premium

    For most small businesses, the basics cost a small fraction of a single incident.

    What does good cybersecurity look like in a small business?

    • Every account has a unique password and multi-factor authentication
    • Devices update automatically
    • Backups run daily and get tested
    • Employees receive training at least once a year
    • Access matches each person’s job
    • A written plan says what to do in an incident
    • Someone owns the responsibility

    None of this needs a security department. It needs attention and follow-through.

    How do I show customers that I take security seriously?

    • Publish a clear privacy policy
    • Use HTTPS on your website
    • Explain how you will contact customers, so they can spot impostors
    • Respond fast and openly if something goes wrong
    • Mention your security practices in proposals

    Customers notice when a business treats their data with respect.

    How does cybersecurity support my employees?

    Training gives staff skills they use at work and at home. Clear rules remove the worry of not knowing what to do with a strange email. A culture that thanks people for reporting problems makes the whole team more confident.

    What does it cost to get started?

    The first steps cost little. Multi-factor authentication and automatic updates are free with the tools you already own. A password manager and cloud backup run a few dollars per user each month. Training and a short written plan take time more than money.

    What mistakes should I avoid?

    • Treating security as a one-time project
    • Buying tools without training the people who use them
    • Assuming your IT provider handles everything
    • Waiting for an incident before you act

    How do I measure whether it is working?

    Track a few simple numbers each quarter:

    • The share of accounts with multi-factor authentication
    • The share of devices that are up to date
    • The date of your last successful backup restore test
    • The share of staff who completed training
    • The number of suspicious emails your team reported

    Rising numbers show a business that is getting harder to attack.

    Where should I start?

    1. Turn on multi-factor authentication for email and banking.
    2. Turn on automatic updates.
    3. Set up and test backups.
    4. Train your team.
    5. Write a one-page incident plan.

    Is my business too small for this to matter?

    No. Attackers automate their work, and their tools test every business they can reach. Size offers no protection. Small companies also have less room to absorb a week of lost sales. The smaller the business, the more one incident matters.

    Your next step

    Cybersecurity protects against threats, keeps operations running, and opens new opportunities. Small businesses that put it in place set themselves up for long-term success. Cerberus Cybersecurity helps with training, policy, and assessments sized for small and mid-sized businesses. Contact us to talk about your goals.

  • Cybersecurity Training for Employees: Why It Matters and What to Teach

    By J. Mesa

    One of the most important steps a small business owner can take against cyber threats is to educate employees. Staff who can recognize phishing and other common tactics reduce the chance that your systems get compromised.

    This guide explains why training matters, what to teach, and how to make it stick.

    Why is employee cybersecurity training important?

    Attackers target people because people are easier to fool than software. An employee who clicks a malicious link or shares a password can undo the best security tools.

    Training turns that weakness into a defense. An employee who spots a suspicious email and reports it protects the whole company.

    What are the benefits of training?

    • A stronger defense. Even with the best security systems and software, attackers get in through employees. Trained staff catch attacks that technology misses.
    • Fewer costly mistakes. A small business faces real risk from an employee who clicks a phishing link or gives a password to the wrong person. Training on best practices prevents those mistakes.
    • Better morale and productivity. Training shows your employees that you value their safety. That supports a positive workplace, and people use the same skills to protect their families.
    • Protection for your customers and your reputation. A breach brings financial loss and lost trust. Staff who know how to protect your systems prevent incidents.

    What topics should training cover?

    1. Phishing and social engineering. How to spot fake emails, texts, and calls, with real examples.
    2. Passwords and multi-factor authentication. How to use a password manager and why the second step matters.
    3. Safe handling of data. What counts as sensitive, where to store it, and how to share it.
    4. Device security. Updates, screen locks, and what to do with a lost phone or laptop.
    5. Safe browsing and downloads. Which sites and files to avoid.
    6. Remote work and travel. Public Wi-Fi, home networks, and working in public places.
    7. Payment and invoice fraud. How to verify a request for money or a change in bank details.
    8. Reporting. Who to tell, how, and how fast.

    Match the topics to each role. Staff who handle money need more on payment fraud. Managers need more on impersonation.

    How often should employees be trained?

    • At hire, before they get access to systems
    • At least once a year for everyone
    • In short refreshers through the year, such as a monthly five-minute tip
    • After any incident or near miss

    One long annual session fades within weeks. Short, frequent lessons keep the habits alive.

    What makes training effective?

    • Keep it short. Ten to twenty minutes per session.
    • Make it relevant. Use examples from your own industry and your own inbox.
    • Make it practical. Show people what to do, not only what to fear.
    • Practice. Simulated phishing emails give staff a safe place to make mistakes.
    • Explain the reason. People follow rules they understand.
    • Include everyone. Owners and executives are frequent targets and need the training most.

    What is a phishing simulation?

    A phishing simulation is a harmless test email that imitates a real attack. It shows who clicks and who reports. Run one every month or quarter, and use the results to guide your next training.

    Never use a simulation to embarrass or punish. Staff who fear blame stop reporting, and silence is what attackers count on.

    How do I build a security culture?

    • Thank people who report suspicious messages, including false alarms
    • Treat an honest mistake as a chance to learn
    • Talk about security in staff meetings
    • Make the safe way the easy way, with tools such as a password manager
    • Lead by example. If the owner skips the rules, so will everyone else.

    Culture decides what people do when nobody is watching.

    How do I measure whether training works?

    • The click rate on simulated phishing emails over time
    • The number of suspicious emails staff report
    • How fast people report after a test or a real attempt
    • Training completion rates
    • The number of incidents caused by human error

    A falling click rate and a rising report rate tell you the training is working.

    Is training required by law or by insurers?

    Often, yes. Standards such as PCI-DSS and HIPAA call for security awareness training. The FTC Safeguards Rule requires it for covered financial businesses. Cyber insurers ask about it on applications, and some clients write it into contracts. Keep records of who completed training and when.

    How much does training cost?

    Costs range from free resources published by CISA and the FTC to paid online platforms and live sessions with a consultant. Compare the price with the cost of one wire fraud or one ransomware incident. Training is among the cheapest protections you can buy.

    What mistakes should I avoid?

    • Running training once and never again
    • Using generic material that has nothing to do with your business
    • Relying on fear
    • Skipping contractors and part-time staff
    • Leaving out the reporting process
    • Treating a completed quiz as proof of changed behavior

    How do I train a remote team?

    • Deliver sessions by video and record them
    • Use short online modules people can complete on their own schedule
    • Cover home network basics, such as router passwords and updates
    • Give remote staff a clear way to report problems outside office hours

    How do I get started?

    1. Pick the three topics that matter most to your business. Phishing belongs on every list.
    2. Schedule a 20-minute session this month.
    3. Set up a simple way to report suspicious messages.
    4. Plan short refreshers for the rest of the year.
    5. Record attendance.

    Who should run the training?

    A trusted manager can deliver the basics with free material from CISA. An outside trainer adds current examples, answers hard questions, and gets attention that an internal memo does not. Many small businesses combine the two: a consultant leads one live session a year, and a manager sends short reminders in between.

    Your next step

    Employee education on cybersecurity is essential to the security and success of your small business. Training and support give your team the means to protect your systems against cybercriminals. Contact us or write to [email protected] to see how our cybersecurity training can meet your goals. At Cerberus Cybersecurity, we believe in people first.

  • 12 Cybersecurity Awareness Month Activities for Your Workplace

    12 Cybersecurity Awareness Month Activities for Your Workplace

    By J. Mesa

    October is Cybersecurity Awareness Month, a time to raise awareness about cybersecurity and to encourage people and organizations to protect themselves online. It is a great opportunity to learn and to turn good intentions into habits.

    If you want to take part and don’t know where to begin, here are twelve activities that work for a business of any size.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month runs every October. It began in the United States in 2004 and is led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. Organizations use the month to run activities and events that teach people about current threats and how to guard against them.

    Why should my business take part?

    • Most attacks begin with a person, and awareness changes behavior
    • A dedicated month gives you a reason to start
    • Shared activities build a culture where people report problems
    • Free materials make it low cost

    How do I plan the month?

    1. Pick one person to coordinate.
    2. Choose four themes, one per week: passwords, multi-factor authentication, phishing, and updates.
    3. Pick two or three activities from the list below.
    4. Tell your team the schedule in advance.
    5. Keep each activity short.

    1. Kick off with a message from the owner

    Start with a short note or talk from leadership. Explain why security matters to the business and to each person’s job. When the owner takes part, everyone else does too.

    2. Send a weekly tip

    Email one practical tip each Monday. Keep it to three or four sentences with one action to take. Examples: turn on a screen lock, check your email’s “Report phishing” button, update your phone.

    3. Run a phishing drill

    Send a harmless simulated phishing email. Afterward, share the warning signs it contained. Praise the people who reported it, and teach the ones who clicked without naming them.

    4. Hold a lunch-and-learn

    Spend 30 minutes on one topic with real examples. Show actual scam emails your business received. Invite questions. Food helps attendance.

    5. Host a password manager day

    Help every employee install a password manager and move their most important accounts into it. Set aside an hour and have someone available to assist. This one activity fixes weak and reused passwords across the company.

    6. Run a multi-factor authentication check

    Ask each person to confirm that multi-factor authentication is on for work email and any system that handles money or customer data. Turn it on where it is missing.

    7. Hold an update and cleanup day

    Have everyone install pending updates on computers and phones and restart them. Use the same day to:

    • Delete files and apps nobody needs
    • Remove accounts for former employees
    • Review who has access to shared folders

    8. Test your backups

    Restore a file from backup and time how long it takes. A backup you have never tested is a hope, not a plan.

    9. Walk through an incident

    Run a 30-minute tabletop exercise. Describe a scenario, such as ransomware on a Monday morning, and ask the team what they would do. Write down the gaps you find and fix them.

    10. Play a quiz or a game

    Use a short quiz with a small prize. Friendly competition between teams raises interest. Keep the questions practical.

    11. Share family resources

    Give employees tips they can use at home: setting up a child’s device, spotting scam calls aimed at older relatives, freezing credit. People who practice security at home bring the habits to work.

    12. Recognize a security champion

    Thank the employee who reported the most suspicious emails or helped coworkers the most. Recognition tells everyone that reporting is valued.

    How do I keep activities engaging?

    • Keep them short
    • Use real stories, not abstract warnings
    • Stay positive. Fear makes people hide mistakes.
    • Vary the format: email, video, discussion, hands-on
    • Involve managers

    Where can I find free materials?

    • CISA publishes a toolkit, tip sheets, and videos for its Secure Our World campaign at cisa.gov.
    • The National Cybersecurity Alliance offers guides and sample communications at staysafeonline.org.
    • The Federal Trade Commission publishes small business cybersecurity guides at ftc.gov.

    All of them are free to use and share.

    What are this year’s core messages?

    CISA’s campaign centers on four habits:

    1. Use strong passwords and a password manager.
    2. Turn on multi-factor authentication.
    3. Recognize and report phishing.
    4. Update your software.

    Build your activities around these and you cover the attacks that hit small businesses most.

    How do I measure results?

    • How many people took part in each activity
    • The click rate and report rate on your phishing drill
    • How many accounts gained multi-factor authentication
    • How many devices were updated
    • What your tabletop exercise revealed

    Record the numbers and compare them next year.

    What if my team is small or remote?

    Every activity on this list works for a team of three. For remote staff, hold sessions by video, send tips by chat or email, and give people a set time to complete the password manager and update tasks at home.

    What about the rest of the year?

    One month is a start. Keep two habits going after October: a short monthly tip and a quarterly phishing drill. Schedule formal training at least once a year.

    How do I get leadership support?

    Present it in business terms. One wire fraud or one ransomware incident costs far more than a month of short activities. Many insurers and clients also ask whether you train your staff, and this month gives you an answer and a record.

    What should I avoid?

    Skip the hour-long slide deck and the scare tactics. Avoid any activity that singles out a person who made a mistake. People remember how the month made them feel, and you want them to feel capable.

    Your next step

    Pick three activities from this list and put them on the calendar for October. This month is a chance to learn more about cybersecurity and to protect yourself and your organization from attacks. If you want a live session for your team, Cerberus Cybersecurity offers cybersecurity training for every audience. Contact us to book one.

  • How to Write a Small Business Cybersecurity Plan in 7 Steps

    By J. Mesa

    As a small business owner, you protect your company from many threats. You lock the doors, buy insurance, and keep the books in order. Many small businesses skip the same care for cybersecurity.

    Every small business needs a cybersecurity plan to protect its data, its customers, and its bottom line. Without one, you are open to criminals who look for weaknesses to exploit. This guide shows you how to write a plan that works and that you can put in place.

    What is a cybersecurity plan?

    A cybersecurity plan is a written document that states what your business needs to protect, how you protect it, who is responsible, and what you do when an incident occurs. For a small business, a few pages is enough.

    Why does every small business need one?

    • It sets priorities. You spend time and money on your biggest risks first.
    • It prevents panic. In an incident, people follow the plan and don’t improvise.
    • Clients and insurers ask for it. Contracts and policy applications now request proof.
    • Rules require it. The FTC Safeguards Rule, HIPAA, and PCI-DSS all call for a written security program.

    What should the plan include?

    • An inventory of your assets and data
    • Your main risks
    • Policies and procedures
    • The security measures you use
    • A training schedule
    • An incident response section
    • A schedule for review

    The seven steps below build each part.

    Step 1: Identify your assets

    List what you need to protect:

    • Computers, phones, servers, and network equipment
    • Software and online services
    • Customer data, employee records, and financial information
    • Accounts: email, banking, domain, social media

    Note where each item lives and who can access it. You can’t protect what you haven’t listed.

    Step 2: Identify your vulnerabilities and risks

    For each asset, ask three questions:

    1. What could go wrong? Think of theft, ransomware, loss, or an honest mistake.
    2. How likely is it?
    3. How badly would it hurt?

    Rank the results. The items that are both likely and damaging go to the top. A simple high, medium, low scale works.

    Step 3: Develop policies and procedures

    Write short, clear rules for how your business protects its assets. Start with these:

    • Password policy. Unique passwords, a password manager, and multi-factor authentication.
    • Acceptable use. What staff may do on company devices and networks.
    • Access control. Who gets access to what, and how you remove it when someone leaves.
    • Data handling. How you store, share, and dispose of sensitive information.
    • Remote work. Rules for home networks, personal devices, and public Wi-Fi.
    • Vendor management. How you check the companies that hold your data.

    Keep each policy to a page. People follow rules they can read in five minutes.

    Step 4: Implement security measures

    Put the tools in place that carry out your policies:

    • Multi-factor authentication on email, banking, and remote access
    • Automatic updates on all devices
    • A firewall and security software
    • Encryption on laptops and phones
    • Backups that follow the 3-2-1 rule: three copies, two types of storage, one offsite
    • Email filtering

    Start with the measures that address your top-ranked risks.

    Step 5: Train your employees

    Your plan depends on the people who follow it.

    • Train every employee when they join and at least once a year
    • Teach them to recognize phishing and other common scams
    • Explain each policy and the reason for it
    • Make reporting simple and free of blame

    Step 6: Plan your incident response

    Decide now what you will do when something goes wrong. Write down:

    • Who leads the response
    • Who to call: IT provider, cyber insurer, attorney, bank
    • How to isolate affected systems
    • How to reach staff if email is down
    • How and when you notify customers and regulators
    • Where the backups are and how to restore them

    Print this section. You can’t open a file on a locked computer.

    Step 7: Monitor and update the plan

    A cybersecurity plan is a living document. Review it:

    • Once a year
    • After any incident or near miss
    • When you add a new system, vendor, or location
    • When laws or contract requirements change

    Check each quarter that the measures in the plan are still running: updates, backups, and access reviews.

    How long should the plan be?

    For a business with fewer than 50 people, five to ten pages covers it. A short plan that people use beats a long one that sits in a drawer.

    Who should write it?

    The owner or a senior manager should own it, with input from whoever handles IT. A cybersecurity consultant can speed the work and bring experience from other businesses. The plan must reflect how your company operates, so someone inside has to be involved.

    What frameworks can I use as a guide?

    You don’t need to start from a blank page.

    • NIST Cybersecurity Framework. A widely used structure built around identifying, protecting, detecting, responding, and recovering.
    • CIS Critical Security Controls. A prioritized list of safeguards, with a starter group suited to small organizations.
    • FTC guidance for small business. Plain-language guides at ftc.gov.

    Pick one and adapt it to your size.

    What mistakes should I avoid?

    • Copying a template without changing it to fit your business
    • Writing the plan and never testing it
    • Leaving out the incident response section
    • Forgetting vendors and cloud services
    • Assigning no owner

    How do I test the plan?

    Run a tabletop exercise once a year. Gather the people named in the plan, describe a realistic incident, and walk through each step. You will find missing phone numbers and unclear roles. Fix them while the stakes are low.

    Is a cybersecurity plan the same as an incident response plan?

    No. The incident response plan is one section of the larger document. The cybersecurity plan covers prevention, training, and review as well as response. A business needs both, and writing the full plan produces the response section along the way.

    Your next step

    Start with Step 1 this week. List your assets and data on a single page. Following these seven steps gives you a plan that protects your small business from the growing threat of cyberattacks. Don’t wait until it’s too late. Cerberus Cybersecurity offers policy and documentation development to help you write a plan that fits. Contact us or write to [email protected].

  • Online Safety for Students: A Guide for Parents and Teachers

    By J. Mesa

    As students head back to school, parents and educators worry about the risks that come with more time online. Cyberbullying, scams, and strangers with bad intentions make the internet a dangerous place for young people.

    Students stay safe when adults teach them the risks and give them the tools to protect themselves. This guide covers both.

    What are the biggest online risks for students?

    • Cyberbullying. Harassment through messages, posts, and group chats
    • Online predators. Adults who pose as peers to build trust
    • Scams and phishing. Fake prizes, game currency offers, and messages that steal accounts
    • Oversharing. Personal details and photos that can’t be taken back
    • Inappropriate content. Material that is not suited to their age
    • Sextortion. Criminals who trick or pressure a young person into sending an image, then demand money or more images

    How do I set rules for internet use?

    Before students use the internet for school, set clear boundaries.

    • Agree on screen time limits and device-free times, such as meals and bedtime
    • Decide which websites, apps, and games are allowed
    • Keep devices in shared rooms for younger children
    • Explain that you will check on their activity, and why

    Write the rules down as a family agreement. Children follow rules they helped create.

    How do I teach students to protect personal information?

    One of the largest risks for young people is that others misuse their personal information. Teach them to keep these private:

    • Full name, home address, and phone number
    • School name and schedule
    • Passwords, even from friends
    • Photos that show their location or school uniform

    A simple test helps: “Would I be comfortable if a stranger, my teacher, or my grandmother saw this?”

    What is cyberbullying, and what should I do about it?

    Cyberbullying is repeated, hurtful behavior carried out through technology. Signs that a child is a target include avoiding their device, a sudden change in mood after being online, and reluctance to go to school.

    If it happens:

    1. Listen, and stay calm. Don’t take the device away as a first response, because children then hide problems.
    2. Save the evidence with screenshots.
    3. Block the person and report them to the platform.
    4. Tell the school if other students are involved.
    5. Contact the police if there are threats of violence.

    How do I talk to children about online predators?

    Use plain language that fits their age.

    • People online are not always who they say they are.
    • Never agree to meet someone you know only from the internet.
    • An adult who asks you to keep a secret from your parents is a warning sign.
    • If anyone asks for a private photo, stop, and tell a trusted adult.

    Make sure they know they will not be in trouble for telling you. Predators and extortionists rely on a child’s fear of punishment.

    If a child is threatened or pressured for images, do not pay and do not delete the messages. Report it to the platform and to the National Center for Missing and Exploited Children at CyberTipline.org, or contact the FBI.

    How do I encourage open communication?

    A student who sees something that makes them uncomfortable needs to feel safe talking about it.

    • Ask about their online life the way you ask about their day
    • Learn the apps and games they use
    • Thank them when they bring you a problem
    • React calmly

    Remind them that they can report any concern to a trusted adult: a parent, a teacher, or a school counselor.

    What parental controls should I use?

    Parental control tools and filters help you monitor activity and block inappropriate content.

    • Device settings. Screen Time on Apple devices and Family Link on Android set limits and content filters.
    • App and game settings. Most platforms offer restricted modes and privacy controls.
    • Home network. Many routers include filtering and schedules.
    • App store approvals. Require permission before a download or purchase.

    Tools support your conversations. They do not replace them.

    What is the right age for a phone or social media?

    There is no single answer. Most social media platforms set a minimum age of 13 in their terms. Consider your child’s maturity, their need to reach you, and your ability to supervise. A basic phone or a device with strong limits is a reasonable first step.

    How do I teach students about scams?

    Young people see fake giveaways, offers of free game currency, and messages from “friends” whose accounts were stolen. Teach three rules:

    1. Nobody gives away valuable things for free online.
    2. Never enter a password on a page you reached from a link in a message.
    3. Check with an adult before you buy, download, or sign up.

    What is a digital footprint, and why does it matter to students?

    Everything a student posts builds a record that can last for years. Colleges, scholarship committees, and employers look. Encourage students to post what they would be proud of later, and to ask before they post photos of friends.

    How do I secure a student’s accounts and devices?

    • Use a strong, unique password for each account, with a password manager for older students
    • Turn on two-factor authentication
    • Set profiles to private
    • Turn on automatic updates
    • Turn off location sharing in apps that don’t need it
    • Cover or disable webcams when not in use

    What should schools do?

    • Teach digital citizenship at every grade level
    • Publish clear rules for school devices and accounts
    • Give students and parents a simple way to report problems
    • Protect student data, and check the privacy practices of educational apps
    • Train teachers and staff on current online threats

    Are AI chatbots and image tools a risk for students?

    They can be. Remind students not to share personal details with a chatbot, and that anything a tool produces may be wrong. Explain that fake images and videos of real people are easy to create, that making them of classmates causes real harm, and that it carries serious consequences.

    Your next step

    Have one conversation with your child this week about what they do online, and set up the family agreement together. With the right knowledge and tools, students enjoy the benefits of the internet and stay safe from its risks. If your school or organization wants a session on online safety, contact Cerberus Cybersecurity about our cybersecurity training.

  • Cyber Hygiene Checklist: 12 Habits for Remote and Hybrid Work

    By J. Mesa

    When the COVID-19 pandemic sent people home, hackers and scammers followed. They sent fake health alerts, targeted home networks, and took advantage of people doing their banking and their jobs from the kitchen table.

    Remote and hybrid work stayed. So did the threats. This checklist gives you the habits that keep you and your information safe.

    What is cyber hygiene?

    Cyber hygiene is the set of routine habits that keep your devices, accounts, and data healthy. Like washing your hands, each step is small and works because you repeat it.

    Why does remote work raise the risk?

    • Home networks are less protected than office networks.
    • Personal and work devices mix. Family members share computers and Wi-Fi.
    • Coworkers are not nearby. You can’t lean over and ask, “Did you send this?”
    • Attackers adapt to the news. Any crisis produces scams within days.

    1. How do I spot crisis-related scams?

    Scammers use emergencies to trick people into giving up information or money. During the pandemic they posed as government agencies and healthcare organizations. They do the same after storms, during tax season, and around benefit programs.

    • Be cautious with emails, texts, and calls that claim to come from a government agency or a health organization
    • Never click links or give personal information unless you have confirmed the source
    • Go to the agency’s official website by typing its address yourself

    2. Use strong, unique passwords

    Using one password for many accounts lets an attacker open all of them at once. Use a different, long password for each account. A password manager stores them, so you don’t have to remember them all.

    3. Turn on multi-factor authentication

    Add a second step at login for email, banking, and work accounts. A stolen password alone then fails.

    4. How do I secure my home Wi-Fi?

    • Change the router’s default administrator password
    • Use WPA2 or WPA3 encryption with a strong Wi-Fi password
    • Update the router’s software, or replace a router that no longer gets updates
    • Set up a guest network for visitors and smart devices
    • Turn off remote management if you don’t use it

    5. Keep every device updated

    Turn on automatic updates for computers, phones, tablets, and browsers. Restart when asked. Update smart home devices too.

    6. Separate work and personal use

    • Use your work device for work only
    • Don’t let family members use it
    • Keep work files in the systems your employer approves, not in personal email or cloud accounts

    7. Use a VPN when your employer provides one

    A virtual private network encrypts your connection to company systems. Use it on public Wi-Fi and wherever your employer requires it.

    8. Be careful with personal information

    Scammers look for ways to collect your name, address, Social Security number, and card details. Before you give personal information online, confirm who is asking and why.

    9. Watch for shopping and financial scams

    More shopping moved online, and scammers stepped up their efforts to steal payment data.

    • Buy from retailers you can verify
    • Pay with a credit card
    • Be wary of fake investment offers and requests for payment up front

    10. Secure your video calls

    • Use a meeting password or a waiting room
    • Don’t post meeting links in public
    • Check who is in the call before you discuss anything sensitive
    • Look at what is visible behind you and on your shared screen

    11. Lock your screen and protect your devices

    • Set a screen lock that starts after a few minutes
    • Encrypt laptops and phones
    • Don’t leave devices in a car or unattended in public
    • Report a lost or stolen work device right away

    12. Back up your work

    Save work files in the company’s approved storage, where backups run. For personal files, keep a copy on an external drive or in a cloud service.

    How do I verify a request from a coworker or boss?

    Attackers pose as managers and ask for gift cards, wire transfers, or login details. When a message asks for money, credentials, or a change in payment details, confirm it by phone or video with a number you already have. A two-minute call stops the most costly fraud a business faces.

    What should an employer do for remote staff?

    • Provide company devices with security software and encryption
    • Require multi-factor authentication and a VPN
    • Write a short remote work policy
    • Train staff on home network security and scams
    • Give people a way to report problems outside office hours
    • Remove access as soon as someone leaves

    Is it safe to work from a café or an airport?

    It can be, with care. Use a VPN or your phone’s hotspot. Sit where nobody can read your screen, or use a privacy filter. Don’t take sensitive calls where others can hear. Never leave your device unattended.

    How do I dispose of work documents at home?

    Shred printed papers that carry customer, employee, or financial details. Don’t put them in household recycling. Return old company devices to your employer for secure wiping, and never sell or donate a personal device before you erase it.

    How often should I run through this checklist?

    Review it every three months. Check that updates ran, that your router is current, and that you still recognize every device on your home network.

    What should I do if something goes wrong?

    1. Disconnect the device from the network.
    2. Tell your employer’s IT contact right away.
    3. Change your passwords from a different device.
    4. Call your bank if money or card details are involved.
    5. Report scams at reportfraud.ftc.gov.

    Do smart home devices put my work at risk?

    They can. Cameras, speakers, and TVs often run old software and share the network with your work laptop. Put them on a guest network, change their default passwords, and update them. That way a weak device can’t reach your work computer.

    Your next step

    Pick three items from this checklist and do them today. Start with your router password, multi-factor authentication, and automatic updates. No security measure is foolproof, and these habits go a long way toward keeping your personal and financial information safe. If your business has remote staff, Cerberus Cybersecurity can help with policies and training for a distributed team. Contact us to learn more.

  • How to Protect Your Financial Information Online: 10 Steps

    By J. Mesa

    You bank, pay bills, invest, and shop online. That convenience puts your financial information within reach of hackers and scammers, who keep finding new ways to get at your data and your money.

    Here are ten steps that keep your eye on the money, followed by what to do if something goes wrong.

    How do criminals steal financial information?

    • Phishing. Fake messages from “your bank” lead to fake login pages.
    • Data breaches. A company you do business with loses your details.
    • Reused passwords. Attackers try leaked passwords on banking and payment sites.
    • Malware. Malicious software records what you type.
    • Phone scams. A caller poses as your bank’s fraud team.
    • Card skimmers. Devices on gas pumps and ATMs copy your card.
    • Account takeover. A criminal resets your password through your email.

    1. Use strong, unique passwords

    Using the same password for several accounts lets an attacker open all of them with one leak. Use a different, long password for every financial account. A password manager creates and stores them.

    2. Turn on multi-factor authentication

    Add a second step at login for your bank, card, investment, and payment accounts. Add it to your email too, because password resets go there. An authenticator app is stronger than a code sent by text.

    3. Set up account alerts

    Turn on alerts for every transaction, login from a new device, and change to your contact details. An alert lets you catch fraud in minutes.

    4. Be careful with personal information

    Scammers try to collect your name, address, Social Security number, and card details. Before you give personal information online, confirm the person or company that is asking. Your bank will not ask for your password or a one-time code by phone, text, or email.

    5. Keep software and devices up to date

    Hackers exploit flaws in outdated software. Use the latest versions of your operating system, browser, and banking apps, and turn on automatic updates.

    6. Use security software and a firewall

    Security software and firewalls help block malware and unwanted connections. Run them on all your devices and keep them updated.

    7. Shop with care

    • Buy from retailers you can verify
    • Check that the site uses HTTPS before you enter card details
    • Pay with a credit card or a digital wallet
    • Avoid saving your card on sites you seldom use

    8. Use secure networks for banking

    Don’t log in to financial accounts on public Wi-Fi. Use your home network, your phone’s mobile data, or a VPN.

    9. Freeze your credit

    A credit freeze blocks anyone from opening new credit in your name. It is free. Place one with each of the three bureaus: Equifax, Experian, and TransUnion. Lift it for a short time when you apply for credit.

    10. Review your accounts and credit reports

    • Check bank and card statements every week
    • Get your free credit reports at annualcreditreport.com
    • Look for accounts and inquiries you don’t recognize

    How do I know if my financial information was stolen?

    • Charges or withdrawals you did not make
    • Bills or collection notices for accounts you never opened
    • A drop in your credit score with no cause
    • Missing mail, or statements that stop arriving
    • A notice that your information was part of a data breach
    • A rejected tax return because someone already filed with your number

    What should I do if my card or account is compromised?

    1. Call your bank or card issuer using the number on the back of your card. Ask them to block the card and dispute the charges.
    2. Change your passwords for the affected account and your email.
    3. Place a fraud alert or a credit freeze with the credit bureaus.
    4. Report identity theft at IdentityTheft.gov, the Federal Trade Commission’s recovery site. It gives you a step-by-step plan.
    5. Report the fraud to the FBI at ic3.gov.
    6. Keep records of every call and letter.

    Report fast. Your legal protections depend on how soon you notify the bank.

    Is online banking safe?

    Yes, when you take the steps above. Banks invest in security, encrypt your connection, and monitor for fraud. Most losses happen when a customer is tricked into giving away credentials or approving a transfer. Your habits are the layer the bank can’t supply.

    Are payment apps safe?

    Apps such as Zelle, Venmo, and Cash App are safe for paying people you know. They move money fast, and a payment you authorized is hard to reverse. Scammers know this.

    • Send money only to people you know and trust
    • Confirm the recipient’s phone number or username before you send
    • Turn on a PIN or biometric lock in the app
    • Never send a payment to “verify” your account or to receive a refund

    Is a credit card safer than a debit card?

    For online purchases, yes. US federal law caps your liability for unauthorized credit card charges at $50, and most issuers waive even that. With a debit card the money leaves your bank account, and your protection shrinks the longer you wait to report.

    How do I protect my business finances?

    • Use a dedicated computer or browser for online banking
    • Require two people to approve wire transfers and new payees
    • Confirm any change in a vendor’s bank details by phone, using a number you already have
    • Turn on multi-factor authentication and alerts for every business account
    • Review account activity every day
    • Train staff who handle money to spot invoice and payroll fraud

    Business email compromise, where a criminal poses as an owner or vendor to redirect a payment, costs businesses more than any other online fraud. The phone call to confirm is your best defense.

    How do I spot a fake call or text from my bank?

    • It asks for your password, PIN, or a one-time code
    • It tells you to move money to a “safe account”
    • It pressures you to act right now
    • The caller ID shows the bank’s name, which criminals can fake

    Hang up, and call the number on your card.

    Should I pay for identity theft protection?

    A paid service watches for your data and helps with recovery. It can’t prevent theft. You can do the most effective steps yourself for free: freeze your credit, turn on alerts, and review your reports. Consider a paid service if you want the monitoring handled for you.

    Your next step

    Turn on transaction alerts and multi-factor authentication for your main bank account today. Following these steps protects your financial information and lowers your risk of becoming a victim. If your business wants to protect its accounts and train the staff who handle payments, contact Cerberus Cybersecurity about our cybersecurity training.

  • Travel Cybersecurity: 12 Tips to Protect Your Data on the Go

    By J. Mesa

    More people travel for work and leisure each year, and each trip puts your devices and data in unfamiliar places. Airports, hotels, and cafés are where attackers look for easy targets.

    Here are twelve tips to protect your privacy and personal data while you travel, organized by what to do before, during, and after the trip.

    What are the biggest cybersecurity risks when traveling?

    • Public Wi-Fi in airports, hotels, and cafés
    • Lost or stolen devices
    • Shoulder surfing, where someone reads your screen or watches you type
    • Public charging stations and shared computers
    • Travel scams, such as fake booking sites and phishing emails about your reservation
    • Card fraud at unfamiliar ATMs and shops

    What should I do before I leave?

    1. Update your software. Install updates for your operating system, apps, and security software. Updates fix known flaws that attackers exploit.
    2. Back up your devices. If a phone or laptop is lost, you keep your data.
    3. Turn on device encryption and a strong screen lock.
    4. Turn on “Find My” tracking and remote wipe for phones and laptops.
    5. Tell your bank and card issuer about your travel dates if they ask for notice, and turn on transaction alerts.
    6. Travel light. Leave devices and data you don’t need at home.

    1. Use a VPN

    A virtual private network encrypts your internet connection. That makes it harder for others on the same network to see what you do. Use one on any network you don’t control.

    2. Use a password manager

    A password manager creates and stores a strong, unique password for each account. If one account is exposed during your trip, the rest stay safe.

    3. Avoid public Wi-Fi

    Public networks are often unsecured, and attackers set up fake hotspots with names like the real one. Use your phone’s mobile data or hotspot when you can. If you must use public Wi-Fi, confirm the network name with staff and connect through your VPN.

    4. Be cautious with email

    Be wary of unexpected messages with links or attachments. Travelers get phishing emails that pose as airlines, hotels, and booking sites. Check your reservation in the company’s own app.

    5. Turn on two-factor authentication

    Two-factor authentication requires a second proof, such as a code from an app, along with your password. It blocks access even when a password is stolen. Use an authenticator app. Text-message codes can fail when you are abroad without service.

    6. Use a firewall

    A firewall blocks incoming connections from unknown sources. Make sure the one built into your computer is on, and set the network type to “public” when you join a network away from home.

    7. Keep your software updated

    Install updates before you leave. Don’t accept an update offered through a hotel or airport network pop-up. Attackers have used fake update prompts to install malware.

    8. Pay with a credit card

    Credit cards offer stronger protection than debit cards. Under US law your liability for unauthorized credit card charges is capped at $50, and a debit card puts your bank balance at risk. Use ATMs inside banks, and cover the keypad.

    9. Guard your personal information

    Be careful about sharing your full name, date of birth, or Social Security number while you travel. Don’t post your location or travel dates in real time.

    10. Use a privacy screen

    A privacy screen narrows the viewing angle of your laptop or phone, so the person in the next seat can’t read it. It prevents shoulder surfing on planes and in lounges.

    11. Keep your devices with you

    • Never leave a device unattended in a café, a conference room, or a car
    • Carry laptops in your hand luggage
    • Use the hotel safe for devices you leave in the room
    • Lock your screen every time you step away

    12. Avoid public charging ports and shared computers

    A USB port can carry data as well as power. Use your own charger and a wall outlet, or carry a power bank. Don’t log in to personal or work accounts on a hotel business center computer.

    Is hotel Wi-Fi safe?

    Treat it as public. Many guests share it, and you can’t see how it is managed. Use a VPN or your phone’s hotspot for anything sensitive, such as banking and work.

    What should I do if my device is lost or stolen?

    1. Use “Find My” to locate it, lock it, or erase it.
    2. Change the passwords for accounts you used on it, starting with email.
    3. Report it to your employer if it holds work data.
    4. Report it to local police and get a report number for insurance.
    5. Tell your mobile carrier, so they can suspend the SIM.

    What should business travelers do?

    • Follow your company’s travel policy
    • Use the company VPN for all work
    • Carry only the data the trip requires
    • Don’t discuss confidential matters where others can hear
    • Be careful with devices and USB drives handed out at conferences
    • Report any lost device or suspicious activity to IT right away

    Do I need to worry about Bluetooth and file sharing?

    Turn off Bluetooth, AirDrop, and similar sharing features when you are not using them. In a crowded place, an open setting lets strangers send you files or try to connect to your device.

    What should I do when I get home?

    • Change the passwords you used on public networks
    • Review bank and card statements for unfamiliar charges
    • Run a security scan on your devices
    • Remove travel apps you no longer need
    • Post your trip photos now

    How do I avoid travel booking scams?

    Fake travel sites and listings take your payment and disappear. Book through companies you can verify, and type their web address yourself. Be wary of a price far below every other listing, a host who asks you to pay outside the booking platform, and any request for payment by wire or gift card.

    Your next step

    Before your next trip, run through the “before I leave” list and install a VPN. Protecting your privacy on the road takes attention and good habits. If your team travels for work, Cerberus Cybersecurity can add travel security to your cybersecurity training and your written policies. Contact us to learn more.

  • The Top 5 Cyber Threats to Small Businesses, by the Numbers

    By J. Mesa

    Small businesses face growing risk from cyberattacks and organized digital crime. Hacking tools are easy to obtain, and attackers use them to steal sensitive information, disrupt operations, or extort payment.

    Numbers make the risk concrete. This post walks through five common threats, what studies say each one costs, and how to defend against it.

    A note on the numbers

    The cost figures below come from industry reports published around 2020, and several of them measure organizations larger than a small business. Use them to compare the threats and to see the scale. Your own costs will depend on your size, your data, and how prepared you are.

    1. What is ransomware, and what does it cost?

    Ransomware encrypts a company’s data and demands payment for the key to unlock it. A victim faces financial loss and damage to its reputation.

    Datto’s Global Ransomware Report 2020 found an average ransom of $5,600 among small businesses, and an average downtime cost of $274,200. The downtime cost nearly fifty times the ransom.

    How to defend:

    • Keep offline, tested backups
    • Patch systems, and put internet-facing ones first
    • Require multi-factor authentication on remote access
    • Train staff to spot phishing

    2. What is phishing, and what does it cost?

    Phishing tricks people into giving up login credentials or financial information through fake emails and messages that appear to come from legitimate sources. Attackers use what they collect to enter company systems or steal data.

    PhishMe’s 2017 Enterprise Phishing Resiliency and Defense Report put the average cost of a successful phishing attack on a mid-sized company at $1.6 million.

    How to defend:

    • Train employees with real examples
    • Turn on multi-factor authentication
    • Use email filtering
    • Confirm payment requests by phone

    3. What is malware, and what does it cost?

    Malware is software built to damage or disrupt a computer system or to steal from it. The category includes viruses, spyware, trojans, and ransomware.

    Accenture’s research in 2020 put the average cost of a malware attack at $2.6 million.

    How to defend:

    • Run security software on every device
    • Keep software updated
    • Limit administrator rights
    • Block downloads from untrusted sources

    4. What is a denial of service attack, and what does it cost?

    A denial of service (DoS) attack floods a website or network with traffic until legitimate users can’t reach it. When the traffic comes from many sources at once, it is a distributed denial of service, or DDoS, attack.

    Estimates from 2020 put the cost at $20,000 to $40,000 per hour of outage.

    How to defend:

    • Use a hosting or DNS provider that includes DDoS protection
    • Put a content delivery network in front of your website
    • Know who to call at your provider when an attack starts

    5. What is an insider threat, and what does it cost?

    An insider threat comes from inside the organization. It can be an employee who steals data on purpose, or one who exposes it by accident.

    The Ponemon Institute’s Cost of Insider Threats study found an average annual cost of $8.76 million in 2018, rising to $11.45 million in 2020.

    How to defend:

    • Give each person access to only what the job requires
    • Remove access on an employee’s last day
    • Log and review access to sensitive data
    • Train staff on safe data handling

    Which threat is most common for small businesses?

    Phishing. It is cheap to send, it reaches every employee, and it opens the door to most other attacks, including ransomware and payment fraud. If you can fund only one defense, make it phishing training with multi-factor authentication.

    Why do attacks cost so much?

    The ransom or the stolen money is a small part of the bill. The larger costs come from:

    • Downtime. Sales and work stop.
    • Recovery. Investigators, IT labor, and replacement equipment.
    • Legal and notification costs.
    • Lost customers and damaged reputation.

    The Datto figures show the pattern. Being down costs more than the ransom.

    What is organized digital crime?

    Many attacks come from organized groups that run like businesses. They have developers, support staff, and affiliates. Some sell ransomware as a service: one group builds the tool, and others rent it and share the profits.

    That model means an attacker needs little skill to hit a small business. It also means the attacks are well tested.

    Who is behind attacks on small businesses?

    • Criminal groups seeking money
    • Individual opportunists using rented tools
    • Insiders, through intent or error
    • Automated scanners that look for weak systems across the whole internet

    Most of them are not targeting you by name. They are looking for any business with an open door.

    How does a small business protect itself?

    Technology:

    • A firewall and security software
    • Multi-factor authentication
    • Automatic updates
    • Tested backups
    • Monitoring for suspicious activity

    People:

    • Regular cybersecurity training
    • A simple way to report suspicious messages

    Process:

    • Strict rules for who can access company information and systems
    • A written incident response plan
    • A review of access and controls every quarter

    How do I estimate my own exposure?

    1. Work out what one day of downtime costs you in lost sales and wages.
    2. Count the customer and employee records you hold.
    3. Ask how long a full restore from backup would take.
    4. Multiply the daily cost by the restore time.

    That figure is a floor. It leaves out legal costs and lost customers.

    Are these numbers still accurate?

    The reports cited here date from 2017 to 2020, and costs have risen since. Newer editions of the same studies show higher figures each year. The ranking and the lesson hold: downtime and recovery cost far more than the attack itself, and prevention costs far less than either.

    Should I work with a cybersecurity consultant?

    A consulting service gives a small business a direct route to protection. A consultant identifies the threats that apply to your operations, ranks them, and helps you fix the most serious ones first. That saves you from buying tools you don’t need.

    Your next step

    Small businesses face a rising threat from hackers and organized digital crime. Investing in effective security and educating your employees protects you. Cerberus Cybersecurity offers risk and compliance assessments that show which of these five threats put your business at the most risk. Contact us to schedule one.

  • IRS Scams: How to Spot Fake IRS Calls, Emails, and Texts

    By J. Mesa

    Every tax season, criminals pretend to be the Internal Revenue Service. They use email, phone calls, texts, and social media to trick taxpayers into handing over a Social Security number, bank details, or money. A victim faces identity theft or financial loss.

    Here is how to recognize an IRS scam, what to do about it, and how to keep your tax information safe all year.

    What is an IRS scam?

    An IRS scam is any attempt to steal money or personal information by posing as the IRS or a tax professional. The most common forms are:

    • Phishing emails that link to fake IRS pages
    • Text messages about a refund or a problem with your return
    • Phone calls that threaten arrest or demand immediate payment
    • Fake letters that copy IRS notices
    • Social media messages offering help with refunds or credits
    • Fraudulent tax preparers who steal refunds or client data

    How does the IRS contact taxpayers?

    The IRS contacts most taxpayers first by a letter sent through the US Postal Service. The agency does not initiate contact by email, text message, or social media to ask for personal or financial information.

    The IRS does make phone calls and visits in some situations, such as an overdue bill or an audit. Those follow letters you have already received.

    What will the IRS never do?

    • Demand immediate payment by gift card, wire transfer, payment app, or cryptocurrency
    • Threaten to have you arrested or deported by local police
    • Ask for your card or bank details over the phone, by email, or by text
    • Demand payment without giving you the chance to question or appeal the amount
    • Send an email or text asking you to “verify” your identity through a link

    Any message that does one of these is a scam.

    How do I spot a fake IRS email or text?

    • It arrives without warning and mentions a refund, a penalty, or a locked account
    • It contains a link or an attachment
    • The sender’s address does not end in irs.gov
    • It pushes you to act within hours
    • It asks for your Social Security number, bank details, or login

    Don’t reply, and don’t click anything.

    How do I spot a fake IRS phone call?

    Scam callers sound official. They give a badge number, know part of your Social Security number, and show “IRS” on the caller ID, which criminals can fake. They then threaten arrest or a lawsuit unless you pay right now.

    Hang up. If you think you owe taxes, call the IRS yourself at 1-800-829-1040, or check your account at IRS.gov.

    How do I report an IRS scam?

    • Email: forward it to [email protected], then delete it.
    • Text: forward the message to [email protected] with the number it came from.
    • Phone call: report it to the Treasury Inspector General for Tax Administration at tigta.gov and to the Federal Trade Commission at reportfraud.ftc.gov.

    Reporting helps the IRS shut down fake sites and warn other taxpayers.

    What is an Identity Protection PIN, and should I get one?

    An Identity Protection PIN (IP PIN) is a six-digit number the IRS issues to you each year. Nobody can file a tax return with your Social Security number without it.

    Any taxpayer who can verify their identity can request one at IRS.gov. It is free, and it is the strongest protection against someone filing a fraudulent return in your name.

    How do I verify a request for information?

    Be careful any time someone asks for personal details. The IRS does not ask for your Social Security number or bank details by email. If you are unsure whether a request is real, contact the IRS directly at 1-800-829-1040, or log in to your account at IRS.gov. Don’t use the phone number or link in the message.

    How do I protect my tax information?

    • Use strong, unique passwords for your tax software, your IRS online account, and your email
    • Turn on multi-factor authentication wherever it is offered
    • File early. A criminal can’t file a fraudulent return after yours is accepted.
    • Use a secure network. Don’t file taxes on public Wi-Fi.
    • Keep your devices updated

    How do I choose a tax preparer I can trust?

    Give your tax information only to trusted sources, such as a qualified tax preparer or financial advisor.

    • Check that the preparer has a Preparer Tax Identification Number (PTIN). Paid preparers must have one and must sign your return.
    • Ask how they store and send your documents
    • Avoid preparers who base their fee on the size of your refund
    • Never sign a blank return
    • Make sure your refund goes to your account, not theirs

    How do I dispose of tax documents?

    Shred any paper that carries sensitive information, including old tax returns, W-2s, and 1099s, once you no longer need to keep it. The IRS suggests keeping returns and supporting records for at least three years in most cases. Erase old computers and drives before you recycle them.

    Is tax software safe?

    Reputable tax preparation software files your return electronically over an encrypted connection, and e-filing is safer than mailing paper. Download the software from the company’s own website, use a strong password, and turn on multi-factor authentication.

    What should I do if I gave information to a scammer?

    1. If you sent money, call your bank or card issuer right away.
    2. Change the passwords on your email and financial accounts.
    3. Place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion.
    4. Report identity theft at IdentityTheft.gov for a recovery plan.
    5. Request an IP PIN from the IRS.
    6. If someone filed a return in your name, the IRS will ask you to complete Form 14039, the Identity Theft Affidavit.

    How do tax scams target small businesses?

    Criminals target payroll and human resources staff.

    • W-2 scams. An email that appears to come from the owner asks for copies of all employee W-2 forms.
    • Fake payroll changes. A message asks to change an employee’s direct deposit account.
    • Fake IRS notices about business tax accounts or new “registration” fees.

    Protect your business with one rule: confirm any request for employee tax data or a payment change by phone, using a number you already have. If you prepare taxes for others, federal law requires you to have a written information security plan.

    When do tax scams peak?

    Scams rise from January through April and again around extension deadlines in the fall. They also follow the news. New credits, relief payments, and disaster declarations each bring a wave of fake messages. Stay alert all year.

    Your next step

    Request an IP PIN at IRS.gov before you file this year. Protecting yourself from IRS impersonators takes attention and a commitment to guarding your personal information. If your business handles employee tax or payroll data, Cerberus Cybersecurity can train your team to spot these scams. Contact us about our cybersecurity training.