Author: J. Mesa

  • IT Security for Small Businesses: 8 Layers of Protection

    By J. Mesa

    As a small business owner, protecting your company against hackers and ransomware is essential to its security and success. Attacks keep getting more capable, and no single product stops them all.

    Good IT security works in layers. If one fails, the next one catches the problem. This guide explains each layer in plain language and tells you where to begin.

    What is IT security?

    IT security is the set of tools, rules, and habits that protect your computers, networks, and data from unauthorized access, damage, and theft. For a small business it covers your devices, your accounts, your network, your data, and the people who use them.

    Why do small businesses need layers?

    Security professionals call the approach defense in depth. An attacker who gets past your email filter still has to fool a trained employee. If the employee clicks, security software can still block the malware. If the malware runs, limited access keeps it from reaching everything, and a backup lets you recover.

    Each layer is imperfect. Together they are hard to beat.

    Layer 1: What does a firewall do?

    A firewall controls the traffic that enters and leaves your network. It blocks connections you did not ask for.

    • Use the firewall in your router or a dedicated business firewall
    • Keep its software updated
    • Change the default administrator password
    • Turn on the firewall built into each computer

    Layer 2: Do I need antivirus and anti-malware software?

    Yes. Security software on each device detects and blocks known malware. Newer products, called endpoint detection and response, also watch for suspicious behavior. Install protection on every computer, keep it updated, and make sure someone reviews its alerts.

    Layer 3: Why do updates and patches matter?

    Attackers use known flaws in outdated software. Updates close them.

    • Turn on automatic updates for operating systems and applications
    • Update routers, firewalls, printers, and other network devices
    • Replace hardware and software the vendor no longer supports
    • Subscribe to security alerts from your key vendors and from CISA to hear about urgent fixes

    Layer 4: What are intrusion detection and prevention systems?

    An intrusion detection system watches network traffic for signs of an attack and raises an alert. An intrusion prevention system also blocks the traffic. Many business firewalls include both. They help you spot an attacker who is already inside.

    Layer 5: How do I control access?

    Set strict rules for how people reach company information and systems.

    • Give each employee a unique account
    • Require long, unique passwords and a password manager
    • Turn on multi-factor authentication for email, remote access, and financial systems
    • Give each person access to only what the job needs
    • Remove access on an employee’s last day

    Current guidance from NIST recommends changing a password when there is evidence it was exposed, in place of forced changes on a fixed schedule.

    Layer 6: Why train employees?

    Your staff see phishing emails before any tool does. Training teaches them to recognize and avoid the tactics hackers use to get into your systems.

    • Train at hire and at least once a year
    • Use real examples
    • Make it easy and safe to report a suspicious message

    Layer 7: How should I back up my data?

    Backups mean that if your systems are compromised, you still have your information and files.

    • Back up on a schedule
    • Follow the 3-2-1 rule: three copies, two types of storage, one offsite or offline
    • Store a copy in a secure offsite location, so a disaster can’t destroy every copy
    • Test a restore every few months

    Layer 8: Do I need a security plan and outside help?

    A written plan ties the layers together. It names who is responsible, what you protect, and what you do in an incident.

    A trusted cybersecurity provider or consultant can help you build the plan and put it in place. They bring advice on the right solutions for your needs and help you stay ahead of new threats.

    What security does a small business need at minimum?

    1. Multi-factor authentication on email and banking
    2. Automatic updates on every device
    3. Tested backups with one copy offline or offsite
    4. Security software on every computer
    5. Phishing training for all staff

    These five block the attacks that hit small businesses most often.

    What is the difference between IT support and cybersecurity?

    IT support keeps your systems working. Cybersecurity keeps them safe. Many IT contracts cover setup and repair and leave out security monitoring, risk assessment, and incident response. Ask your provider which security tasks are included, and get the answer in writing.

    How do I secure Wi-Fi in the office?

    • Use WPA2 or WPA3 encryption and a strong password
    • Set up a separate guest network for visitors
    • Keep smart devices and printers off the network that holds business data
    • Change the router’s default administrator password

    What about cloud services and email?

    Most small businesses now run on cloud email and file storage. The provider secures the service. You secure the accounts.

    • Turn on multi-factor authentication for every user
    • Review sharing settings and remove public links
    • Turn on the security features your plan includes, such as phishing protection
    • Remove accounts for former staff

    How much should I budget?

    Start with the minimum list above, which costs little. Then match further spending to your risk: the data you hold, the rules that apply to you, and what a day of downtime costs. A risk assessment tells you where each dollar does the most good.

    How do I know if my security is working?

    • Updates and backups show as current when you check
    • Staff report suspicious emails
    • You can restore a file from backup
    • You know who has access to what
    • An outside assessment finds fewer problems each year

    What are the signs my business has been hacked?

    • Computers run slowly or behave oddly
    • Passwords stop working
    • Customers receive strange emails from your address
    • Files are missing, renamed, or locked
    • Your bank reports unusual transactions

    If you see any of these, disconnect the affected device and call your IT or security provider.

    Your next step

    Protecting your small business takes effective security tools, educated employees, and steady upkeep. Check the minimum list above against your business today. Cerberus Cybersecurity can assess your current layers and help you close the gaps with a risk and compliance assessment. Contact us to get started.

  • What Is a CVE? How to Prioritize Software Vulnerabilities

    What Is a CVE? How to Prioritize Software Vulnerabilities

    By J. Mesa

    In 2021, researchers recorded more software vulnerabilities than in any year before it. The record has been broken several times since. For a business, the lesson is practical: you can’t fix everything, so you need to know what to fix first.

    This post explains what a vulnerability is, how the industry tracks them, and how to set priorities.

    What is a software vulnerability?

    A vulnerability is a flaw in software or hardware that an attacker can use to do something the designer never intended, such as running their own code, reading private data, or crashing a system. Vendors fix vulnerabilities with updates, also called patches.

    What is a CVE?

    CVE stands for Common Vulnerabilities and Exposures. It is a public catalog that gives each known vulnerability a unique ID, such as CVE-2021-44228. The nonprofit MITRE runs the program with funding from the US government.

    A CVE ID gives everyone the same name for the same flaw. Vendors, researchers, and security tools all use it.

    What is the National Vulnerability Database?

    The National Vulnerability Database (NVD) is run by the National Institute of Standards and Technology. It takes each CVE and adds detail: a severity score, the affected products, and links to fixes.

    How many vulnerabilities were disclosed in 2021?

    A report by Risk Based Security and Flashpoint counted 28,695 vulnerabilities disclosed in 2021, the highest number on record at the time. Three findings stood out:

    • 28,695 vulnerabilities were disclosed during the year.
    • 29 percent had no CVE ID. Another 4 percent had an ID in “reserved” status, which meant the NVD held no usable information about them yet.
    • 4,108 were remotely exploitable and had both a documented public exploit and an available fix.

    That last group matters most. The report found that an organization could cut its risk and its immediate workload by nearly 86 percent by putting those vulnerabilities first.

    Why does the number keep rising?

    • More software exists, and more of it connects to the internet
    • More researchers look for flaws, and more vendors run reward programs
    • Software is built from shared components, so one flaw affects many products
    • Reporting has improved

    A rising count partly reflects better discovery. It still means more work for whoever maintains your systems.

    What does a severity score mean?

    Most vulnerabilities receive a score from the Common Vulnerability Scoring System (CVSS), on a scale of 0 to 10.

    • 9.0 to 10.0: critical
    • 7.0 to 8.9: high
    • 4.0 to 6.9: medium
    • 0.1 to 3.9: low

    The score measures how bad a flaw could be. It does not tell you whether attackers are using it, or whether your business is exposed.

    Do I need to patch every vulnerability?

    Over time, yes. Right away, no. Nobody can install every fix at once. What matters is the order.

    Which vulnerabilities should I patch first?

    1. Flaws attackers are using right now. CISA publishes the Known Exploited Vulnerabilities catalog, a list of flaws with confirmed attacks. Start there.
    2. Flaws in systems that face the internet. Firewalls, VPNs, email servers, and websites are reachable by anyone.
    3. Flaws that can be exploited remotely and have public exploit code.
    4. Critical and high scores on systems that hold sensitive data.
    5. Everything else, on a regular schedule.

    This is the same lesson the 2021 report drew. A small share of vulnerabilities carries most of the real risk.

    What is a zero-day?

    A zero-day is a vulnerability that attackers use before the vendor has released a fix. You can’t patch it, so other layers have to protect you: limited access, network controls, monitoring, and backups. When the fix arrives, install it at once.

    What is patch management?

    Patch management is the routine of finding, testing, and installing updates. A simple version for a small business:

    1. Keep a list of your devices and software.
    2. Turn on automatic updates wherever you can.
    3. Check once a month for updates that need manual installation, such as firewalls and business applications.
    4. Install urgent fixes for internet-facing systems within days.
    5. Replace products the vendor no longer supports.
    6. Record what you did.

    How fast should I patch?

    Many organizations aim to fix critical flaws on internet-facing systems within days and everything else within 30 days. Attackers often begin using a new flaw within days of its disclosure, so speed on the most exposed systems matters more than perfect coverage.

    How do I find out which vulnerabilities affect my business?

    • Turn on update notifications from your vendors
    • Subscribe to CISA alerts
    • Run a vulnerability scan, which checks your systems against the list of known flaws
    • Ask your IT provider for a report on what is out of date

    A scan gives you a list. A risk assessment tells you which items on the list matter.

    What if a system can’t be patched?

    Some older systems have no fix available. Reduce the risk another way:

    • Take the system off the internet
    • Put it on a separate network segment
    • Limit who and what can connect to it
    • Plan and budget for its replacement

    Why do so many vulnerabilities lack a CVE ID?

    The CVE program depends on vendors and researchers to request IDs, and the process takes time. Some flaws are published on a vendor’s site or a researcher’s blog and never enter the catalog. Tools that rely only on CVE data miss those. It is one more reason to follow your vendors’ own security notices.

    Does this apply to a small business?

    Yes. You use the same operating systems, browsers, routers, and business applications as large companies, and attackers scan for the same flaws. The good news is that you have fewer systems to keep track of.

    What should I do this month?

    1. List your devices and software.
    2. Turn on automatic updates.
    3. Check your firewall and router for updates.
    4. Look up CISA’s Known Exploited Vulnerabilities catalog and compare it with the products you use.
    5. Schedule a vulnerability scan.

    Your next step

    As the world changes, so does the threat landscape. Diligence and awareness build resistance, and a community that shares what it learns protects everyone in it. Get in touch with our team to learn how Cerberus Cybersecurity can find and rank your vulnerabilities with a risk and compliance assessment. Contact us today. At Cerberus Cybersecurity, our stance on cybersecurity is and will remain people first.

  • How Do Hackers Get In? Social Engineering Explained for Small Businesses

    By J. Mesa

    Thanks to Hollywood, most people picture a hacker as a hooded figure in a dark room, with a wall of monitors and streaming green text. The real ones look like anyone you pass during the day. They use practical, boring methods, and those methods work.

    The most common method is social engineering. This post explains what it is, why small businesses are targets, and how to defend against it.

    What is social engineering?

    Social engineering is the use of deception to get a person to do something that helps an attacker: click a link, open a file, share a password, or send money. The attacker goes after the person in place of the technology.

    It is the first step in most multi-phase attacks. A tricked employee downloads malware or gives up a login, and the attacker builds from there.

    Are small businesses too small to be a target?

    No. That belief is one of the most damaging misconceptions in small and medium-sized business (SMB).

    In 2021 the United States had about 32.5 million small businesses, close to 99.9 percent of all US businesses. The pandemic pushed more of them online, which multiplied their exposure. That is an enormous pool of potential victims.

    Why do attackers prefer SMBs?

    • There are so many of them. Volume makes up for smaller payouts.
    • Attacks are automated. Software sends the emails and scans for weak systems.
    • Hacking tools are for sale. Criminals rent tools and services. Think of an online marketplace for hackers.
    • The risk to the attacker is low. Small businesses seldom have the means to investigate or pursue them.
    • Defenses are thinner than at a large company.

    The cost to a victim goes beyond money. A breach damages a reputation for years. Remember Equifax.

    What are the most common social engineering techniques?

    • Phishing. Mass emails that imitate a trusted company.
    • Spear phishing. A message written for one person, using details about them.
    • Business email compromise. An attacker poses as an owner, executive, or vendor and asks for a payment or a change in bank details.
    • Pretexting. The attacker invents a story, such as “I’m from IT and need your password to fix your account.”
    • Vishing. The same tricks by phone call.
    • Smishing. The same tricks by text message.
    • Baiting. A free download or a USB drive left where someone will find it.
    • Tailgating. Following an employee through a locked door.

    Why is phishing the biggest threat?

    Phishing is the most damaging and widespread threat facing small businesses. Industry analyses attribute the large majority of breaches to it, with business losses in the billions of dollars.

    Malware attacks follow, a category that includes ransomware. Malware can disable devices or leak confidential data. That is expensive to fix, and it harms the company in ways that go beyond equipment and cleanup costs.

    Why does social engineering work?

    It works because it uses normal human reactions.

    • Authority. We follow requests from a boss or an official.
    • Urgency. A deadline stops us from thinking.
    • Fear. A threat to an account or a job pushes us to act.
    • Helpfulness. Most people want to assist a coworker or a customer.
    • Curiosity. An unexpected file or link is tempting.
    • Familiarity. A message that mentions real names and details feels safe.

    None of this requires expensive or complex tools. An attacker needs a convincing story and an email address.

    What does a real attack look like?

    1. The attacker reads your website and social media to learn names and roles.
    2. They send an email that appears to come from a vendor, with an “updated invoice” attached.
    3. An employee opens it. Malware installs, or a fake login page captures a password.
    4. The attacker reads email quietly and learns how you handle payments.
    5. They send a payment request at the right moment, or they lock your files with ransomware.

    Depending on the malware, security software may or may not catch the file. The person who received the email was the first and best chance to stop it.

    How long before a business notices?

    Often a long time. Reports indicate that outside parties, such as a bank, a customer, or law enforcement, discover most social engineering and phishing incidents. The business itself does not realize it is a victim.

    How do I spot a social engineering attempt?

    • The request is unexpected
    • It pushes you to act fast or in secret
    • It asks for a password, a code, or a payment
    • It asks you to skip a normal process
    • The sender’s address or phone number is slightly wrong
    • Something about the tone feels off

    When you notice any of these, stop, and verify through another channel.

    What is the best defense?

    Training. Technology keeps advancing, and new tools reach the market fast. Those tools are only as effective as the people who use them.

    Raising security awareness through training pays back sooner than most investments, because staff come to understand both their tools and the threats.

    • Train everyone, including owners and executives
    • Use real examples from your own industry
    • Run simulated phishing tests and teach from the results
    • Repeat through the year

    What technical controls help?

    • Multi-factor authentication, so a stolen password is not enough
    • Email filtering and warnings on messages from outside the company
    • Limited access, so one compromised account can’t reach everything
    • Security software and automatic updates
    • Tested backups

    What rule stops the most fraud?

    Verify by phone. Any request to send money, change bank details, buy gift cards, or share employee records gets a call to a number you already have. This one habit blocks most business email compromise.

    How do I build a security culture?

    Cybersecurity is a community effort and a cultural approach. A hacker needs to succeed once. Your team needs to stay alert together.

    • Thank people who report suspicious messages
    • Treat mistakes as lessons
    • Talk about security in regular meetings
    • Lead by example

    What should I do if an employee falls for it?

    1. Disconnect the device from the network.
    2. Change the affected passwords from another device.
    3. Call your bank if money is involved.
    4. Bring in your IT or security provider to check for further access.
    5. Report it to the FBI at ic3.gov.
    6. Share what happened with the team, without blame.

    Your next step

    Ask yourself how your team would respond to a fake invoice email tomorrow. If you aren’t sure, start with training. Get in touch with our team to learn how Cerberus Cybersecurity can help you defend against cybercriminals with cybersecurity training built for your staff. Contact us today. At Cerberus Cybersecurity, we are people first.