Category: Article

  • Online Safety for Students: A Guide for Parents and Teachers

    By J. Mesa

    As students head back to school, parents and educators worry about the risks that come with more time online. Cyberbullying, scams, and strangers with bad intentions make the internet a dangerous place for young people.

    Students stay safe when adults teach them the risks and give them the tools to protect themselves. This guide covers both.

    What are the biggest online risks for students?

    • Cyberbullying. Harassment through messages, posts, and group chats
    • Online predators. Adults who pose as peers to build trust
    • Scams and phishing. Fake prizes, game currency offers, and messages that steal accounts
    • Oversharing. Personal details and photos that can’t be taken back
    • Inappropriate content. Material that is not suited to their age
    • Sextortion. Criminals who trick or pressure a young person into sending an image, then demand money or more images

    How do I set rules for internet use?

    Before students use the internet for school, set clear boundaries.

    • Agree on screen time limits and device-free times, such as meals and bedtime
    • Decide which websites, apps, and games are allowed
    • Keep devices in shared rooms for younger children
    • Explain that you will check on their activity, and why

    Write the rules down as a family agreement. Children follow rules they helped create.

    How do I teach students to protect personal information?

    One of the largest risks for young people is that others misuse their personal information. Teach them to keep these private:

    • Full name, home address, and phone number
    • School name and schedule
    • Passwords, even from friends
    • Photos that show their location or school uniform

    A simple test helps: “Would I be comfortable if a stranger, my teacher, or my grandmother saw this?”

    What is cyberbullying, and what should I do about it?

    Cyberbullying is repeated, hurtful behavior carried out through technology. Signs that a child is a target include avoiding their device, a sudden change in mood after being online, and reluctance to go to school.

    If it happens:

    1. Listen, and stay calm. Don’t take the device away as a first response, because children then hide problems.
    2. Save the evidence with screenshots.
    3. Block the person and report them to the platform.
    4. Tell the school if other students are involved.
    5. Contact the police if there are threats of violence.

    How do I talk to children about online predators?

    Use plain language that fits their age.

    • People online are not always who they say they are.
    • Never agree to meet someone you know only from the internet.
    • An adult who asks you to keep a secret from your parents is a warning sign.
    • If anyone asks for a private photo, stop, and tell a trusted adult.

    Make sure they know they will not be in trouble for telling you. Predators and extortionists rely on a child’s fear of punishment.

    If a child is threatened or pressured for images, do not pay and do not delete the messages. Report it to the platform and to the National Center for Missing and Exploited Children at CyberTipline.org, or contact the FBI.

    How do I encourage open communication?

    A student who sees something that makes them uncomfortable needs to feel safe talking about it.

    • Ask about their online life the way you ask about their day
    • Learn the apps and games they use
    • Thank them when they bring you a problem
    • React calmly

    Remind them that they can report any concern to a trusted adult: a parent, a teacher, or a school counselor.

    What parental controls should I use?

    Parental control tools and filters help you monitor activity and block inappropriate content.

    • Device settings. Screen Time on Apple devices and Family Link on Android set limits and content filters.
    • App and game settings. Most platforms offer restricted modes and privacy controls.
    • Home network. Many routers include filtering and schedules.
    • App store approvals. Require permission before a download or purchase.

    Tools support your conversations. They do not replace them.

    What is the right age for a phone or social media?

    There is no single answer. Most social media platforms set a minimum age of 13 in their terms. Consider your child’s maturity, their need to reach you, and your ability to supervise. A basic phone or a device with strong limits is a reasonable first step.

    How do I teach students about scams?

    Young people see fake giveaways, offers of free game currency, and messages from “friends” whose accounts were stolen. Teach three rules:

    1. Nobody gives away valuable things for free online.
    2. Never enter a password on a page you reached from a link in a message.
    3. Check with an adult before you buy, download, or sign up.

    What is a digital footprint, and why does it matter to students?

    Everything a student posts builds a record that can last for years. Colleges, scholarship committees, and employers look. Encourage students to post what they would be proud of later, and to ask before they post photos of friends.

    How do I secure a student’s accounts and devices?

    • Use a strong, unique password for each account, with a password manager for older students
    • Turn on two-factor authentication
    • Set profiles to private
    • Turn on automatic updates
    • Turn off location sharing in apps that don’t need it
    • Cover or disable webcams when not in use

    What should schools do?

    • Teach digital citizenship at every grade level
    • Publish clear rules for school devices and accounts
    • Give students and parents a simple way to report problems
    • Protect student data, and check the privacy practices of educational apps
    • Train teachers and staff on current online threats

    Are AI chatbots and image tools a risk for students?

    They can be. Remind students not to share personal details with a chatbot, and that anything a tool produces may be wrong. Explain that fake images and videos of real people are easy to create, that making them of classmates causes real harm, and that it carries serious consequences.

    Your next step

    Have one conversation with your child this week about what they do online, and set up the family agreement together. With the right knowledge and tools, students enjoy the benefits of the internet and stay safe from its risks. If your school or organization wants a session on online safety, contact Cerberus Cybersecurity about our cybersecurity training.

  • Cyber Hygiene Checklist: 12 Habits for Remote and Hybrid Work

    By J. Mesa

    When the COVID-19 pandemic sent people home, hackers and scammers followed. They sent fake health alerts, targeted home networks, and took advantage of people doing their banking and their jobs from the kitchen table.

    Remote and hybrid work stayed. So did the threats. This checklist gives you the habits that keep you and your information safe.

    What is cyber hygiene?

    Cyber hygiene is the set of routine habits that keep your devices, accounts, and data healthy. Like washing your hands, each step is small and works because you repeat it.

    Why does remote work raise the risk?

    • Home networks are less protected than office networks.
    • Personal and work devices mix. Family members share computers and Wi-Fi.
    • Coworkers are not nearby. You can’t lean over and ask, “Did you send this?”
    • Attackers adapt to the news. Any crisis produces scams within days.

    1. How do I spot crisis-related scams?

    Scammers use emergencies to trick people into giving up information or money. During the pandemic they posed as government agencies and healthcare organizations. They do the same after storms, during tax season, and around benefit programs.

    • Be cautious with emails, texts, and calls that claim to come from a government agency or a health organization
    • Never click links or give personal information unless you have confirmed the source
    • Go to the agency’s official website by typing its address yourself

    2. Use strong, unique passwords

    Using one password for many accounts lets an attacker open all of them at once. Use a different, long password for each account. A password manager stores them, so you don’t have to remember them all.

    3. Turn on multi-factor authentication

    Add a second step at login for email, banking, and work accounts. A stolen password alone then fails.

    4. How do I secure my home Wi-Fi?

    • Change the router’s default administrator password
    • Use WPA2 or WPA3 encryption with a strong Wi-Fi password
    • Update the router’s software, or replace a router that no longer gets updates
    • Set up a guest network for visitors and smart devices
    • Turn off remote management if you don’t use it

    5. Keep every device updated

    Turn on automatic updates for computers, phones, tablets, and browsers. Restart when asked. Update smart home devices too.

    6. Separate work and personal use

    • Use your work device for work only
    • Don’t let family members use it
    • Keep work files in the systems your employer approves, not in personal email or cloud accounts

    7. Use a VPN when your employer provides one

    A virtual private network encrypts your connection to company systems. Use it on public Wi-Fi and wherever your employer requires it.

    8. Be careful with personal information

    Scammers look for ways to collect your name, address, Social Security number, and card details. Before you give personal information online, confirm who is asking and why.

    9. Watch for shopping and financial scams

    More shopping moved online, and scammers stepped up their efforts to steal payment data.

    • Buy from retailers you can verify
    • Pay with a credit card
    • Be wary of fake investment offers and requests for payment up front

    10. Secure your video calls

    • Use a meeting password or a waiting room
    • Don’t post meeting links in public
    • Check who is in the call before you discuss anything sensitive
    • Look at what is visible behind you and on your shared screen

    11. Lock your screen and protect your devices

    • Set a screen lock that starts after a few minutes
    • Encrypt laptops and phones
    • Don’t leave devices in a car or unattended in public
    • Report a lost or stolen work device right away

    12. Back up your work

    Save work files in the company’s approved storage, where backups run. For personal files, keep a copy on an external drive or in a cloud service.

    How do I verify a request from a coworker or boss?

    Attackers pose as managers and ask for gift cards, wire transfers, or login details. When a message asks for money, credentials, or a change in payment details, confirm it by phone or video with a number you already have. A two-minute call stops the most costly fraud a business faces.

    What should an employer do for remote staff?

    • Provide company devices with security software and encryption
    • Require multi-factor authentication and a VPN
    • Write a short remote work policy
    • Train staff on home network security and scams
    • Give people a way to report problems outside office hours
    • Remove access as soon as someone leaves

    Is it safe to work from a café or an airport?

    It can be, with care. Use a VPN or your phone’s hotspot. Sit where nobody can read your screen, or use a privacy filter. Don’t take sensitive calls where others can hear. Never leave your device unattended.

    How do I dispose of work documents at home?

    Shred printed papers that carry customer, employee, or financial details. Don’t put them in household recycling. Return old company devices to your employer for secure wiping, and never sell or donate a personal device before you erase it.

    How often should I run through this checklist?

    Review it every three months. Check that updates ran, that your router is current, and that you still recognize every device on your home network.

    What should I do if something goes wrong?

    1. Disconnect the device from the network.
    2. Tell your employer’s IT contact right away.
    3. Change your passwords from a different device.
    4. Call your bank if money or card details are involved.
    5. Report scams at reportfraud.ftc.gov.

    Do smart home devices put my work at risk?

    They can. Cameras, speakers, and TVs often run old software and share the network with your work laptop. Put them on a guest network, change their default passwords, and update them. That way a weak device can’t reach your work computer.

    Your next step

    Pick three items from this checklist and do them today. Start with your router password, multi-factor authentication, and automatic updates. No security measure is foolproof, and these habits go a long way toward keeping your personal and financial information safe. If your business has remote staff, Cerberus Cybersecurity can help with policies and training for a distributed team. Contact us to learn more.

  • Travel Cybersecurity: 12 Tips to Protect Your Data on the Go

    By J. Mesa

    More people travel for work and leisure each year, and each trip puts your devices and data in unfamiliar places. Airports, hotels, and cafés are where attackers look for easy targets.

    Here are twelve tips to protect your privacy and personal data while you travel, organized by what to do before, during, and after the trip.

    What are the biggest cybersecurity risks when traveling?

    • Public Wi-Fi in airports, hotels, and cafés
    • Lost or stolen devices
    • Shoulder surfing, where someone reads your screen or watches you type
    • Public charging stations and shared computers
    • Travel scams, such as fake booking sites and phishing emails about your reservation
    • Card fraud at unfamiliar ATMs and shops

    What should I do before I leave?

    1. Update your software. Install updates for your operating system, apps, and security software. Updates fix known flaws that attackers exploit.
    2. Back up your devices. If a phone or laptop is lost, you keep your data.
    3. Turn on device encryption and a strong screen lock.
    4. Turn on “Find My” tracking and remote wipe for phones and laptops.
    5. Tell your bank and card issuer about your travel dates if they ask for notice, and turn on transaction alerts.
    6. Travel light. Leave devices and data you don’t need at home.

    1. Use a VPN

    A virtual private network encrypts your internet connection. That makes it harder for others on the same network to see what you do. Use one on any network you don’t control.

    2. Use a password manager

    A password manager creates and stores a strong, unique password for each account. If one account is exposed during your trip, the rest stay safe.

    3. Avoid public Wi-Fi

    Public networks are often unsecured, and attackers set up fake hotspots with names like the real one. Use your phone’s mobile data or hotspot when you can. If you must use public Wi-Fi, confirm the network name with staff and connect through your VPN.

    4. Be cautious with email

    Be wary of unexpected messages with links or attachments. Travelers get phishing emails that pose as airlines, hotels, and booking sites. Check your reservation in the company’s own app.

    5. Turn on two-factor authentication

    Two-factor authentication requires a second proof, such as a code from an app, along with your password. It blocks access even when a password is stolen. Use an authenticator app. Text-message codes can fail when you are abroad without service.

    6. Use a firewall

    A firewall blocks incoming connections from unknown sources. Make sure the one built into your computer is on, and set the network type to “public” when you join a network away from home.

    7. Keep your software updated

    Install updates before you leave. Don’t accept an update offered through a hotel or airport network pop-up. Attackers have used fake update prompts to install malware.

    8. Pay with a credit card

    Credit cards offer stronger protection than debit cards. Under US law your liability for unauthorized credit card charges is capped at $50, and a debit card puts your bank balance at risk. Use ATMs inside banks, and cover the keypad.

    9. Guard your personal information

    Be careful about sharing your full name, date of birth, or Social Security number while you travel. Don’t post your location or travel dates in real time.

    10. Use a privacy screen

    A privacy screen narrows the viewing angle of your laptop or phone, so the person in the next seat can’t read it. It prevents shoulder surfing on planes and in lounges.

    11. Keep your devices with you

    • Never leave a device unattended in a café, a conference room, or a car
    • Carry laptops in your hand luggage
    • Use the hotel safe for devices you leave in the room
    • Lock your screen every time you step away

    12. Avoid public charging ports and shared computers

    A USB port can carry data as well as power. Use your own charger and a wall outlet, or carry a power bank. Don’t log in to personal or work accounts on a hotel business center computer.

    Is hotel Wi-Fi safe?

    Treat it as public. Many guests share it, and you can’t see how it is managed. Use a VPN or your phone’s hotspot for anything sensitive, such as banking and work.

    What should I do if my device is lost or stolen?

    1. Use “Find My” to locate it, lock it, or erase it.
    2. Change the passwords for accounts you used on it, starting with email.
    3. Report it to your employer if it holds work data.
    4. Report it to local police and get a report number for insurance.
    5. Tell your mobile carrier, so they can suspend the SIM.

    What should business travelers do?

    • Follow your company’s travel policy
    • Use the company VPN for all work
    • Carry only the data the trip requires
    • Don’t discuss confidential matters where others can hear
    • Be careful with devices and USB drives handed out at conferences
    • Report any lost device or suspicious activity to IT right away

    Do I need to worry about Bluetooth and file sharing?

    Turn off Bluetooth, AirDrop, and similar sharing features when you are not using them. In a crowded place, an open setting lets strangers send you files or try to connect to your device.

    What should I do when I get home?

    • Change the passwords you used on public networks
    • Review bank and card statements for unfamiliar charges
    • Run a security scan on your devices
    • Remove travel apps you no longer need
    • Post your trip photos now

    How do I avoid travel booking scams?

    Fake travel sites and listings take your payment and disappear. Book through companies you can verify, and type their web address yourself. Be wary of a price far below every other listing, a host who asks you to pay outside the booking platform, and any request for payment by wire or gift card.

    Your next step

    Before your next trip, run through the “before I leave” list and install a VPN. Protecting your privacy on the road takes attention and good habits. If your team travels for work, Cerberus Cybersecurity can add travel security to your cybersecurity training and your written policies. Contact us to learn more.

  • The Top 5 Cyber Threats to Small Businesses, by the Numbers

    By J. Mesa

    Small businesses face growing risk from cyberattacks and organized digital crime. Hacking tools are easy to obtain, and attackers use them to steal sensitive information, disrupt operations, or extort payment.

    Numbers make the risk concrete. This post walks through five common threats, what studies say each one costs, and how to defend against it.

    A note on the numbers

    The cost figures below come from industry reports published around 2020, and several of them measure organizations larger than a small business. Use them to compare the threats and to see the scale. Your own costs will depend on your size, your data, and how prepared you are.

    1. What is ransomware, and what does it cost?

    Ransomware encrypts a company’s data and demands payment for the key to unlock it. A victim faces financial loss and damage to its reputation.

    Datto’s Global Ransomware Report 2020 found an average ransom of $5,600 among small businesses, and an average downtime cost of $274,200. The downtime cost nearly fifty times the ransom.

    How to defend:

    • Keep offline, tested backups
    • Patch systems, and put internet-facing ones first
    • Require multi-factor authentication on remote access
    • Train staff to spot phishing

    2. What is phishing, and what does it cost?

    Phishing tricks people into giving up login credentials or financial information through fake emails and messages that appear to come from legitimate sources. Attackers use what they collect to enter company systems or steal data.

    PhishMe’s 2017 Enterprise Phishing Resiliency and Defense Report put the average cost of a successful phishing attack on a mid-sized company at $1.6 million.

    How to defend:

    • Train employees with real examples
    • Turn on multi-factor authentication
    • Use email filtering
    • Confirm payment requests by phone

    3. What is malware, and what does it cost?

    Malware is software built to damage or disrupt a computer system or to steal from it. The category includes viruses, spyware, trojans, and ransomware.

    Accenture’s research in 2020 put the average cost of a malware attack at $2.6 million.

    How to defend:

    • Run security software on every device
    • Keep software updated
    • Limit administrator rights
    • Block downloads from untrusted sources

    4. What is a denial of service attack, and what does it cost?

    A denial of service (DoS) attack floods a website or network with traffic until legitimate users can’t reach it. When the traffic comes from many sources at once, it is a distributed denial of service, or DDoS, attack.

    Estimates from 2020 put the cost at $20,000 to $40,000 per hour of outage.

    How to defend:

    • Use a hosting or DNS provider that includes DDoS protection
    • Put a content delivery network in front of your website
    • Know who to call at your provider when an attack starts

    5. What is an insider threat, and what does it cost?

    An insider threat comes from inside the organization. It can be an employee who steals data on purpose, or one who exposes it by accident.

    The Ponemon Institute’s Cost of Insider Threats study found an average annual cost of $8.76 million in 2018, rising to $11.45 million in 2020.

    How to defend:

    • Give each person access to only what the job requires
    • Remove access on an employee’s last day
    • Log and review access to sensitive data
    • Train staff on safe data handling

    Which threat is most common for small businesses?

    Phishing. It is cheap to send, it reaches every employee, and it opens the door to most other attacks, including ransomware and payment fraud. If you can fund only one defense, make it phishing training with multi-factor authentication.

    Why do attacks cost so much?

    The ransom or the stolen money is a small part of the bill. The larger costs come from:

    • Downtime. Sales and work stop.
    • Recovery. Investigators, IT labor, and replacement equipment.
    • Legal and notification costs.
    • Lost customers and damaged reputation.

    The Datto figures show the pattern. Being down costs more than the ransom.

    What is organized digital crime?

    Many attacks come from organized groups that run like businesses. They have developers, support staff, and affiliates. Some sell ransomware as a service: one group builds the tool, and others rent it and share the profits.

    That model means an attacker needs little skill to hit a small business. It also means the attacks are well tested.

    Who is behind attacks on small businesses?

    • Criminal groups seeking money
    • Individual opportunists using rented tools
    • Insiders, through intent or error
    • Automated scanners that look for weak systems across the whole internet

    Most of them are not targeting you by name. They are looking for any business with an open door.

    How does a small business protect itself?

    Technology:

    • A firewall and security software
    • Multi-factor authentication
    • Automatic updates
    • Tested backups
    • Monitoring for suspicious activity

    People:

    • Regular cybersecurity training
    • A simple way to report suspicious messages

    Process:

    • Strict rules for who can access company information and systems
    • A written incident response plan
    • A review of access and controls every quarter

    How do I estimate my own exposure?

    1. Work out what one day of downtime costs you in lost sales and wages.
    2. Count the customer and employee records you hold.
    3. Ask how long a full restore from backup would take.
    4. Multiply the daily cost by the restore time.

    That figure is a floor. It leaves out legal costs and lost customers.

    Are these numbers still accurate?

    The reports cited here date from 2017 to 2020, and costs have risen since. Newer editions of the same studies show higher figures each year. The ranking and the lesson hold: downtime and recovery cost far more than the attack itself, and prevention costs far less than either.

    Should I work with a cybersecurity consultant?

    A consulting service gives a small business a direct route to protection. A consultant identifies the threats that apply to your operations, ranks them, and helps you fix the most serious ones first. That saves you from buying tools you don’t need.

    Your next step

    Small businesses face a rising threat from hackers and organized digital crime. Investing in effective security and educating your employees protects you. Cerberus Cybersecurity offers risk and compliance assessments that show which of these five threats put your business at the most risk. Contact us to schedule one.

  • IRS Scams: How to Spot Fake IRS Calls, Emails, and Texts

    By J. Mesa

    Every tax season, criminals pretend to be the Internal Revenue Service. They use email, phone calls, texts, and social media to trick taxpayers into handing over a Social Security number, bank details, or money. A victim faces identity theft or financial loss.

    Here is how to recognize an IRS scam, what to do about it, and how to keep your tax information safe all year.

    What is an IRS scam?

    An IRS scam is any attempt to steal money or personal information by posing as the IRS or a tax professional. The most common forms are:

    • Phishing emails that link to fake IRS pages
    • Text messages about a refund or a problem with your return
    • Phone calls that threaten arrest or demand immediate payment
    • Fake letters that copy IRS notices
    • Social media messages offering help with refunds or credits
    • Fraudulent tax preparers who steal refunds or client data

    How does the IRS contact taxpayers?

    The IRS contacts most taxpayers first by a letter sent through the US Postal Service. The agency does not initiate contact by email, text message, or social media to ask for personal or financial information.

    The IRS does make phone calls and visits in some situations, such as an overdue bill or an audit. Those follow letters you have already received.

    What will the IRS never do?

    • Demand immediate payment by gift card, wire transfer, payment app, or cryptocurrency
    • Threaten to have you arrested or deported by local police
    • Ask for your card or bank details over the phone, by email, or by text
    • Demand payment without giving you the chance to question or appeal the amount
    • Send an email or text asking you to “verify” your identity through a link

    Any message that does one of these is a scam.

    How do I spot a fake IRS email or text?

    • It arrives without warning and mentions a refund, a penalty, or a locked account
    • It contains a link or an attachment
    • The sender’s address does not end in irs.gov
    • It pushes you to act within hours
    • It asks for your Social Security number, bank details, or login

    Don’t reply, and don’t click anything.

    How do I spot a fake IRS phone call?

    Scam callers sound official. They give a badge number, know part of your Social Security number, and show “IRS” on the caller ID, which criminals can fake. They then threaten arrest or a lawsuit unless you pay right now.

    Hang up. If you think you owe taxes, call the IRS yourself at 1-800-829-1040, or check your account at IRS.gov.

    How do I report an IRS scam?

    • Email: forward it to [email protected], then delete it.
    • Text: forward the message to [email protected] with the number it came from.
    • Phone call: report it to the Treasury Inspector General for Tax Administration at tigta.gov and to the Federal Trade Commission at reportfraud.ftc.gov.

    Reporting helps the IRS shut down fake sites and warn other taxpayers.

    What is an Identity Protection PIN, and should I get one?

    An Identity Protection PIN (IP PIN) is a six-digit number the IRS issues to you each year. Nobody can file a tax return with your Social Security number without it.

    Any taxpayer who can verify their identity can request one at IRS.gov. It is free, and it is the strongest protection against someone filing a fraudulent return in your name.

    How do I verify a request for information?

    Be careful any time someone asks for personal details. The IRS does not ask for your Social Security number or bank details by email. If you are unsure whether a request is real, contact the IRS directly at 1-800-829-1040, or log in to your account at IRS.gov. Don’t use the phone number or link in the message.

    How do I protect my tax information?

    • Use strong, unique passwords for your tax software, your IRS online account, and your email
    • Turn on multi-factor authentication wherever it is offered
    • File early. A criminal can’t file a fraudulent return after yours is accepted.
    • Use a secure network. Don’t file taxes on public Wi-Fi.
    • Keep your devices updated

    How do I choose a tax preparer I can trust?

    Give your tax information only to trusted sources, such as a qualified tax preparer or financial advisor.

    • Check that the preparer has a Preparer Tax Identification Number (PTIN). Paid preparers must have one and must sign your return.
    • Ask how they store and send your documents
    • Avoid preparers who base their fee on the size of your refund
    • Never sign a blank return
    • Make sure your refund goes to your account, not theirs

    How do I dispose of tax documents?

    Shred any paper that carries sensitive information, including old tax returns, W-2s, and 1099s, once you no longer need to keep it. The IRS suggests keeping returns and supporting records for at least three years in most cases. Erase old computers and drives before you recycle them.

    Is tax software safe?

    Reputable tax preparation software files your return electronically over an encrypted connection, and e-filing is safer than mailing paper. Download the software from the company’s own website, use a strong password, and turn on multi-factor authentication.

    What should I do if I gave information to a scammer?

    1. If you sent money, call your bank or card issuer right away.
    2. Change the passwords on your email and financial accounts.
    3. Place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion.
    4. Report identity theft at IdentityTheft.gov for a recovery plan.
    5. Request an IP PIN from the IRS.
    6. If someone filed a return in your name, the IRS will ask you to complete Form 14039, the Identity Theft Affidavit.

    How do tax scams target small businesses?

    Criminals target payroll and human resources staff.

    • W-2 scams. An email that appears to come from the owner asks for copies of all employee W-2 forms.
    • Fake payroll changes. A message asks to change an employee’s direct deposit account.
    • Fake IRS notices about business tax accounts or new “registration” fees.

    Protect your business with one rule: confirm any request for employee tax data or a payment change by phone, using a number you already have. If you prepare taxes for others, federal law requires you to have a written information security plan.

    When do tax scams peak?

    Scams rise from January through April and again around extension deadlines in the fall. They also follow the news. New credits, relief payments, and disaster declarations each bring a wave of fake messages. Stay alert all year.

    Your next step

    Request an IP PIN at IRS.gov before you file this year. Protecting yourself from IRS impersonators takes attention and a commitment to guarding your personal information. If your business handles employee tax or payroll data, Cerberus Cybersecurity can train your team to spot these scams. Contact us about our cybersecurity training.

  • IT Security for Small Businesses: 8 Layers of Protection

    By J. Mesa

    As a small business owner, protecting your company against hackers and ransomware is essential to its security and success. Attacks keep getting more capable, and no single product stops them all.

    Good IT security works in layers. If one fails, the next one catches the problem. This guide explains each layer in plain language and tells you where to begin.

    What is IT security?

    IT security is the set of tools, rules, and habits that protect your computers, networks, and data from unauthorized access, damage, and theft. For a small business it covers your devices, your accounts, your network, your data, and the people who use them.

    Why do small businesses need layers?

    Security professionals call the approach defense in depth. An attacker who gets past your email filter still has to fool a trained employee. If the employee clicks, security software can still block the malware. If the malware runs, limited access keeps it from reaching everything, and a backup lets you recover.

    Each layer is imperfect. Together they are hard to beat.

    Layer 1: What does a firewall do?

    A firewall controls the traffic that enters and leaves your network. It blocks connections you did not ask for.

    • Use the firewall in your router or a dedicated business firewall
    • Keep its software updated
    • Change the default administrator password
    • Turn on the firewall built into each computer

    Layer 2: Do I need antivirus and anti-malware software?

    Yes. Security software on each device detects and blocks known malware. Newer products, called endpoint detection and response, also watch for suspicious behavior. Install protection on every computer, keep it updated, and make sure someone reviews its alerts.

    Layer 3: Why do updates and patches matter?

    Attackers use known flaws in outdated software. Updates close them.

    • Turn on automatic updates for operating systems and applications
    • Update routers, firewalls, printers, and other network devices
    • Replace hardware and software the vendor no longer supports
    • Subscribe to security alerts from your key vendors and from CISA to hear about urgent fixes

    Layer 4: What are intrusion detection and prevention systems?

    An intrusion detection system watches network traffic for signs of an attack and raises an alert. An intrusion prevention system also blocks the traffic. Many business firewalls include both. They help you spot an attacker who is already inside.

    Layer 5: How do I control access?

    Set strict rules for how people reach company information and systems.

    • Give each employee a unique account
    • Require long, unique passwords and a password manager
    • Turn on multi-factor authentication for email, remote access, and financial systems
    • Give each person access to only what the job needs
    • Remove access on an employee’s last day

    Current guidance from NIST recommends changing a password when there is evidence it was exposed, in place of forced changes on a fixed schedule.

    Layer 6: Why train employees?

    Your staff see phishing emails before any tool does. Training teaches them to recognize and avoid the tactics hackers use to get into your systems.

    • Train at hire and at least once a year
    • Use real examples
    • Make it easy and safe to report a suspicious message

    Layer 7: How should I back up my data?

    Backups mean that if your systems are compromised, you still have your information and files.

    • Back up on a schedule
    • Follow the 3-2-1 rule: three copies, two types of storage, one offsite or offline
    • Store a copy in a secure offsite location, so a disaster can’t destroy every copy
    • Test a restore every few months

    Layer 8: Do I need a security plan and outside help?

    A written plan ties the layers together. It names who is responsible, what you protect, and what you do in an incident.

    A trusted cybersecurity provider or consultant can help you build the plan and put it in place. They bring advice on the right solutions for your needs and help you stay ahead of new threats.

    What security does a small business need at minimum?

    1. Multi-factor authentication on email and banking
    2. Automatic updates on every device
    3. Tested backups with one copy offline or offsite
    4. Security software on every computer
    5. Phishing training for all staff

    These five block the attacks that hit small businesses most often.

    What is the difference between IT support and cybersecurity?

    IT support keeps your systems working. Cybersecurity keeps them safe. Many IT contracts cover setup and repair and leave out security monitoring, risk assessment, and incident response. Ask your provider which security tasks are included, and get the answer in writing.

    How do I secure Wi-Fi in the office?

    • Use WPA2 or WPA3 encryption and a strong password
    • Set up a separate guest network for visitors
    • Keep smart devices and printers off the network that holds business data
    • Change the router’s default administrator password

    What about cloud services and email?

    Most small businesses now run on cloud email and file storage. The provider secures the service. You secure the accounts.

    • Turn on multi-factor authentication for every user
    • Review sharing settings and remove public links
    • Turn on the security features your plan includes, such as phishing protection
    • Remove accounts for former staff

    How much should I budget?

    Start with the minimum list above, which costs little. Then match further spending to your risk: the data you hold, the rules that apply to you, and what a day of downtime costs. A risk assessment tells you where each dollar does the most good.

    How do I know if my security is working?

    • Updates and backups show as current when you check
    • Staff report suspicious emails
    • You can restore a file from backup
    • You know who has access to what
    • An outside assessment finds fewer problems each year

    What are the signs my business has been hacked?

    • Computers run slowly or behave oddly
    • Passwords stop working
    • Customers receive strange emails from your address
    • Files are missing, renamed, or locked
    • Your bank reports unusual transactions

    If you see any of these, disconnect the affected device and call your IT or security provider.

    Your next step

    Protecting your small business takes effective security tools, educated employees, and steady upkeep. Check the minimum list above against your business today. Cerberus Cybersecurity can assess your current layers and help you close the gaps with a risk and compliance assessment. Contact us to get started.

  • How Do Hackers Get In? Social Engineering Explained for Small Businesses

    By J. Mesa

    Thanks to Hollywood, most people picture a hacker as a hooded figure in a dark room, with a wall of monitors and streaming green text. The real ones look like anyone you pass during the day. They use practical, boring methods, and those methods work.

    The most common method is social engineering. This post explains what it is, why small businesses are targets, and how to defend against it.

    What is social engineering?

    Social engineering is the use of deception to get a person to do something that helps an attacker: click a link, open a file, share a password, or send money. The attacker goes after the person in place of the technology.

    It is the first step in most multi-phase attacks. A tricked employee downloads malware or gives up a login, and the attacker builds from there.

    Are small businesses too small to be a target?

    No. That belief is one of the most damaging misconceptions in small and medium-sized business (SMB).

    In 2021 the United States had about 32.5 million small businesses, close to 99.9 percent of all US businesses. The pandemic pushed more of them online, which multiplied their exposure. That is an enormous pool of potential victims.

    Why do attackers prefer SMBs?

    • There are so many of them. Volume makes up for smaller payouts.
    • Attacks are automated. Software sends the emails and scans for weak systems.
    • Hacking tools are for sale. Criminals rent tools and services. Think of an online marketplace for hackers.
    • The risk to the attacker is low. Small businesses seldom have the means to investigate or pursue them.
    • Defenses are thinner than at a large company.

    The cost to a victim goes beyond money. A breach damages a reputation for years. Remember Equifax.

    What are the most common social engineering techniques?

    • Phishing. Mass emails that imitate a trusted company.
    • Spear phishing. A message written for one person, using details about them.
    • Business email compromise. An attacker poses as an owner, executive, or vendor and asks for a payment or a change in bank details.
    • Pretexting. The attacker invents a story, such as “I’m from IT and need your password to fix your account.”
    • Vishing. The same tricks by phone call.
    • Smishing. The same tricks by text message.
    • Baiting. A free download or a USB drive left where someone will find it.
    • Tailgating. Following an employee through a locked door.

    Why is phishing the biggest threat?

    Phishing is the most damaging and widespread threat facing small businesses. Industry analyses attribute the large majority of breaches to it, with business losses in the billions of dollars.

    Malware attacks follow, a category that includes ransomware. Malware can disable devices or leak confidential data. That is expensive to fix, and it harms the company in ways that go beyond equipment and cleanup costs.

    Why does social engineering work?

    It works because it uses normal human reactions.

    • Authority. We follow requests from a boss or an official.
    • Urgency. A deadline stops us from thinking.
    • Fear. A threat to an account or a job pushes us to act.
    • Helpfulness. Most people want to assist a coworker or a customer.
    • Curiosity. An unexpected file or link is tempting.
    • Familiarity. A message that mentions real names and details feels safe.

    None of this requires expensive or complex tools. An attacker needs a convincing story and an email address.

    What does a real attack look like?

    1. The attacker reads your website and social media to learn names and roles.
    2. They send an email that appears to come from a vendor, with an “updated invoice” attached.
    3. An employee opens it. Malware installs, or a fake login page captures a password.
    4. The attacker reads email quietly and learns how you handle payments.
    5. They send a payment request at the right moment, or they lock your files with ransomware.

    Depending on the malware, security software may or may not catch the file. The person who received the email was the first and best chance to stop it.

    How long before a business notices?

    Often a long time. Reports indicate that outside parties, such as a bank, a customer, or law enforcement, discover most social engineering and phishing incidents. The business itself does not realize it is a victim.

    How do I spot a social engineering attempt?

    • The request is unexpected
    • It pushes you to act fast or in secret
    • It asks for a password, a code, or a payment
    • It asks you to skip a normal process
    • The sender’s address or phone number is slightly wrong
    • Something about the tone feels off

    When you notice any of these, stop, and verify through another channel.

    What is the best defense?

    Training. Technology keeps advancing, and new tools reach the market fast. Those tools are only as effective as the people who use them.

    Raising security awareness through training pays back sooner than most investments, because staff come to understand both their tools and the threats.

    • Train everyone, including owners and executives
    • Use real examples from your own industry
    • Run simulated phishing tests and teach from the results
    • Repeat through the year

    What technical controls help?

    • Multi-factor authentication, so a stolen password is not enough
    • Email filtering and warnings on messages from outside the company
    • Limited access, so one compromised account can’t reach everything
    • Security software and automatic updates
    • Tested backups

    What rule stops the most fraud?

    Verify by phone. Any request to send money, change bank details, buy gift cards, or share employee records gets a call to a number you already have. This one habit blocks most business email compromise.

    How do I build a security culture?

    Cybersecurity is a community effort and a cultural approach. A hacker needs to succeed once. Your team needs to stay alert together.

    • Thank people who report suspicious messages
    • Treat mistakes as lessons
    • Talk about security in regular meetings
    • Lead by example

    What should I do if an employee falls for it?

    1. Disconnect the device from the network.
    2. Change the affected passwords from another device.
    3. Call your bank if money is involved.
    4. Bring in your IT or security provider to check for further access.
    5. Report it to the FBI at ic3.gov.
    6. Share what happened with the team, without blame.

    Your next step

    Ask yourself how your team would respond to a fake invoice email tomorrow. If you aren’t sure, start with training. Get in touch with our team to learn how Cerberus Cybersecurity can help you defend against cybercriminals with cybersecurity training built for your staff. Contact us today. At Cerberus Cybersecurity, we are people first.