Category: Recommendations

  • QR Code Scams: What Is Quishing and How Do You Avoid It?

    By J. Mesa

    QR codes sit on restaurant tables, parking meters, shipping labels, and holiday advertisements. You scan them without a second thought, and scammers have noticed. A QR code hides its destination until after you point your camera at it. That makes it a handy wrapper for a phishing link, and holiday shopping season gives criminals more chances to use one.

    What is quishing?

    Quishing is phishing delivered through a QR code. The word combines “QR” and “phishing.” The code sends your phone to a fake website that steals your password or card number, or prompts you to install a malicious app.

    How do QR code scams work?

    A QR code is a picture of a web address. Your phone reads the picture and opens the address. You can’t read the pattern with your eyes, so you can’t judge the link before you scan.

    The scammer’s part is simple. They create a code that points to a site they control, then place it where you expect a legitimate code. The fake site copies a parking payment page, a Microsoft 365 sign-in, a delivery tracker, or a bank login. You type your details, and the criminal collects them.

    Where do fake QR codes show up?

    • Parking meters and pay stations. Criminals paste stickers over or beside the real payment code. Cities across the United States have warned drivers about this. You pay the scammer, receive a parking ticket anyway, and hand over your card number.
    • Restaurant tables and counters. A sticker over the menu code leads to a fake ordering page.
    • Emails. A message claims your password expires, your multi-factor authentication needs renewal, or a document awaits your signature. The email holds a QR code in place of a link.
    • Packages you did not order. A box arrives with a card that says “scan to see who sent this gift” or “scan to claim a prize.” This pairs with the brushing scam, in which sellers ship unsolicited items.
    • Text messages about unpaid tolls or missed deliveries.
    • Paper mail and flyers, including fake notices from a city, a utility, or a court.
    • Cryptocurrency ATMs. A caller pretending to be a government office or a bank tells you to scan a code at the machine to “protect” your money. The code holds the scammer’s wallet address.
    • EV charging stations and donation jars.

    Why do scammers put QR codes in emails?

    Three reasons.

    First, many email security filters scan links and attachments, and a QR code is an image. The filter may see a picture and let the message through.

    Second, the code moves you from a work computer to a personal phone. The computer sits behind the company firewall and web filter. The phone, on cellular data, has neither.

    Third, phone screens show a shortened address bar, which makes a fake web address harder to spot.

    A legitimate company rarely needs to send you a QR code by email. You are already on a device that can click a link. Treat any emailed QR code that leads to a sign-in page as a phishing attempt and report it.

    Can scanning a QR code hack my phone?

    Scanning alone almost never harms a phone that is up to date. The code only opens an address or suggests an action. The harm comes from what you do next: entering a password, typing a card number, approving a payment, installing an app or a configuration profile, or joining an unknown Wi-Fi network.

    Keep the phone’s operating system current. Decline any download a scanned page offers.

    How do I check a QR code before I trust it?

    1. Look at the physical code. Run a finger across it. A sticker on top of a printed sign, a crooked label, or a code that covers another code is a warning.
    2. Preview the address. The iPhone and Android cameras display the web address before opening it. Read it.
    3. Check the domain. The real name sits just before the “.com” or “.gov.” An address like “parking-city-pay.com” is not your city’s website. Watch for misspellings and extra words.
    4. Be wary of shortened links such as bit.ly, which hide the destination.
    5. Ask yourself who placed the code. A code printed on a menu inside the restaurant carries less risk than one on a flyer under your windshield wiper.
    6. Go around it. Type the company’s address yourself, or use the official app. For parking, use the app named on the meter or pay at the machine.

    Do I need a QR scanner app?

    No. Use the camera built into your phone. Third-party scanner apps add risk, and some of them have carried malware or aggressive advertising. Delete the ones you have.

    How do I protect my business from quishing?

    • Train the staff. Add QR codes to your security awareness training and to your phishing tests. Teach one rule: never scan a code from an email to sign in to a work account.
    • Check your email filter. Ask your provider whether the filter reads QR codes inside images and attachments. Microsoft and other vendors added this capability.
    • Use phishing-resistant sign-in. Passkeys and security keys refuse to work on a fake site, even when an employee falls for the code.
    • Manage the phones. Staff phones that reach company email should meet minimum requirements: current software, a screen lock, and enrollment in mobile device management where practical.
    • Create an easy way to report. One email address or one button. Thank the people who use it.

    How do I protect my customers if my business uses QR codes?

    If you print QR codes on menus, signs, invoices, or packaging, criminals can cover or imitate them.

    • Print codes directly on signs and menus. Avoid stickers, which make a pasted fake look normal.
    • Display the destination address in text next to the code, so customers can compare.
    • Point codes at your own domain. Skip link shorteners and free QR generators that route through their own servers and can expire or redirect.
    • Inspect your posted codes on a schedule. Add it to the opening checklist.
    • Tell customers what you will never ask for through a QR code.

    What should I do if I scanned a bad QR code?

    Act based on what you entered.

    • Scanned but entered nothing. Close the page. Clear your browser history and site data. You are almost certainly fine.
    • Entered a password. Change it right away from a different device, change it anywhere else you used it, and turn on multi-factor authentication. For a work account, tell IT at once so they can end active sessions and check for forwarding rules.
    • Entered card details. Call the card issuer, dispute the charge, and request a new card.
    • Installed an app or a profile. Remove it, update the phone, and run a security check. If the phone holds work data, report it.
    • Sent cryptocurrency. Report it to the FBI at ic3.gov and to the machine’s operator. Recovery is unlikely, and speed gives you the only chance.

    Report the scam at ReportFraud.ftc.gov. For a fake sticker on a meter or a sign, call the city or the business so they can remove it.

    Are QR codes safe to use at all?

    Yes, with the same care you give a link. The code itself is neutral. Trust depends on where it sits and where it sends you. Slow down for any code that asks for money, a login, or a download.

    Your next step

    Before the holiday rush, show your staff one example of a QR phishing email and one photo of a tampered parking meter. It takes five minutes at a staff meeting. For training that covers quishing, phishing, and phone scams, review our cybersecurity training or contact Cerberus Cybersecurity.

  • Incident Response Plan: What to Do in the First 24 Hours After a Cyberattack

    By J. Mesa

    October is Cybersecurity Awareness Month, and most of the advice you will read this month covers prevention. This post covers the other half: the morning your screens show a ransom note, or your bank calls about a wire you never approved. The decisions you make in the first 24 hours set the cost of the whole event.

    What is an incident response plan?

    An incident response plan is a written document that tells your team who does what when a security incident occurs. It names the people in charge, lists the phone numbers, and lays out the steps to contain the damage, recover, and meet your legal duties.

    A small business plan fits on a few pages. It needs to exist on paper, because the computer that stores it may be the one under attack.

    What counts as a security incident?

    Any event that threatens your data or your systems. Common examples:

    • Ransomware or other malware
    • A hacked email account
    • A fraudulent wire or changed vendor bank details
    • A lost or stolen laptop or phone
    • An employee who clicked a phishing link and entered a password
    • Customer records sent to the wrong person
    • A hacked website
    • A vendor that tells you it suffered a breach involving your data

    A breach is a narrower legal term. It means someone accessed or took protected information without authorization, and it triggers notification laws. Do not call an event a breach in writing until your attorney says it is one.

    What should I do in the first hour?

    1. Stay calm and stop the spread. Disconnect affected computers from the network. Pull the network cable and turn off Wi-Fi.
    2. Leave the machines powered on. Shutting down erases evidence held in memory, and investigators may need it. Disconnect, do not power off, unless your responder tells you otherwise.
    3. Do not wipe, reinstall, or “clean” anything. You will destroy the evidence that shows what the attacker took.
    4. Start a log. Write down the time, what you saw, who reported it, and each action taken. Use paper or a phone that sits outside the affected network.
    5. Take photos of ransom notes and error messages with a phone.
    6. Tell your incident lead. One named person runs the response and makes the calls.
    7. Switch channels. If email may be compromised, stop using it to discuss the incident. The attacker may be reading along. Use phone calls or a messaging app on personal devices.

    Who should I call first?

    Call in this order:

    1. Your cyber insurance carrier’s breach hotline. The policy pays for forensic and legal help only when you use approved vendors and report on time. See our guide to cyber insurance.
    2. A breach attorney, often supplied by the carrier. The attorney directs the investigation so that communications stay privileged.
    3. Your IT provider or security consultant.
    4. Your bank, if money moved or banking credentials were exposed. Ask for a wire recall and a hold on the accounts.
    5. Law enforcement. File a report at ic3.gov. For a fraudulent wire, call your local FBI field office as well, because fast reports give the best chance of freezing the funds.

    No insurance? Call an attorney and an incident response firm yourself. Keep both numbers in the plan before you need them.

    What should I do in hours 1 through 4?

    Contain the attack.

    • Isolate affected systems from the rest of the network.
    • Disable or reset compromised accounts. Start with administrator accounts and email.
    • Revoke active sessions in Microsoft 365 or Google Workspace, so a stolen login stops working.
    • Check email accounts for forwarding rules and inbox rules the attacker created.
    • Block the attacker’s known addresses at the firewall.
    • Disconnect your backups from the network to protect them.
    • Preserve the logs: firewall, email, server, and cloud. Many systems overwrite logs within days.

    What should I do in hours 4 through 12?

    Work out what you are dealing with.

    • Which systems and accounts did the attacker reach?
    • When did the first sign of entry appear? The visible attack often comes weeks after the break-in.
    • What data sits on the affected systems? Customer records, patient charts, card numbers, employee files, and tax documents each carry different legal duties.
    • Are the backups intact, and what is the date of the last clean copy?
    • Is the attacker still inside?

    Let the forensic team answer these with evidence. Guesses made in the first few hours often turn out wrong.

    What should I do in hours 12 through 24?

    • Brief the staff. Tell employees what happened in plain terms, what they should do, and who speaks for the company. Instruct them to send press, customer, and vendor questions to one person.
    • Decide how to operate. Can you run on paper, on phones, or from clean laptops for a week?
    • Plan the recovery. Rebuild from clean backups in a set order: identity and email first, then the systems that bring in revenue.
    • Review notification duties with your attorney.
    • Prepare a holding statement for customers. Keep it factual and short. Do not speculate about causes or promise that no data was taken.

    Should I pay the ransom?

    The FBI advises against it. Payment funds the next attack, gives no guarantee that the decryption tool works, and gives no guarantee that the criminals delete the stolen data. Paying a group under US sanctions is illegal.

    Some businesses with no working backups face a choice between paying and closing. Make that decision with your attorney, your insurer, and a professional negotiator. Never contact the attacker on your own, and never pay before the carrier approves.

    Do I have to notify customers or regulators?

    It depends on what data the attacker accessed and where the affected people live. All 50 states have breach notification laws, and the deadlines differ. Industry rules add their own clocks:

    • HIPAA. Notify affected patients within 60 days of discovery, and notify the Department of Health and Human Services.
    • FTC Safeguards Rule. Covered financial businesses notify the FTC within 30 days when an event involves the unencrypted data of 500 or more consumers.
    • PCI DSS. Notify your acquiring bank and the card brands at once when card data may be involved.
    • Contracts. Many customer agreements require notice within 24 to 72 hours.

    Your attorney makes the call. Your job is to supply accurate facts fast.

    What mistakes make an incident worse?

    • Wiping the infected computers before anyone investigates
    • Restoring from backup while the attacker still has access
    • Discussing the incident over the compromised email system
    • Announcing “no customer data was affected” on day one
    • Letting the staff post about it on social media
    • Waiting days to call the insurer or the bank
    • Negotiating with the attacker yourself
    • Skipping the password resets because they are inconvenient

    What goes into a small business incident response plan?

    • The incident lead and a backup person
    • A printed contact list: insurer hotline and policy number, attorney, IT provider, bank fraud line, FBI field office, key vendors, and staff cell numbers
    • Definitions of what staff must report and how
    • Step-by-step checklists for the likely events: ransomware, email compromise, wire fraud, lost device
    • An inventory of systems and where sensitive data lives
    • Backup locations and restore instructions
    • Notification requirements that apply to your industry
    • Templates for staff and customer messages
    • The date of the last test

    How do I test the plan?

    Run a tabletop exercise once a year. Gather the owner, the office manager, your IT provider, and whoever handles money. Spend 90 minutes walking through a scenario: it is Friday at 4 p.m. and a ransom note appears on the front desk computer. Who do you call? Where is the phone number? How do you make payroll on Monday? Each gap you find in a conference room is one you will not find during a real attack.

    What happens after the first 24 hours?

    Recovery continues for days or weeks. Remove the attacker’s access, rebuild, restore, and watch closely for a return. When the dust settles, hold a review. Identify how the attacker got in, fix that weakness, and update the plan and your staff training with what you learned.

    Your next step

    Print a one-page contact list today and tape it inside a cabinet door. Then set a date to write the rest. Cerberus Cybersecurity writes incident response plans for small businesses and runs the tabletop exercises that test them. See our services or contact us.

  • What Is Cyber Insurance, and What Does It Cover?

    By J. Mesa

    Your general liability policy almost certainly excludes a data breach. Most business owner policies do. That gap surprises people on the worst day of their business life. Cyber insurance fills it, but the application now reads like a security audit, and a wrong answer can cost you the claim.

    What is cyber insurance?

    Cyber insurance is a policy that pays the costs of a cyberattack or data breach. It covers your own losses, the claims other people bring against you, and access to specialists who manage the response. You may see it called cyber liability insurance or cyber risk insurance.

    What does cyber insurance cover?

    Policies split into two halves.

    First-party coverage pays your own costs:

    • Incident response. Forensic investigators who work out what happened and how far it spread.
    • Legal counsel. A breach attorney who directs the response and identifies your notification duties.
    • Notification and credit monitoring. Letters to affected people and the monitoring services the law or goodwill requires.
    • Data restoration. The cost to rebuild systems and recover data.
    • Business interruption. Income you lost while systems were down, after a waiting period.
    • Cyber extortion. Ransom negotiation and, where legal, the payment.
    • Public relations. Help managing the message to customers and the press.

    Third-party coverage pays for claims against you:

    • Lawsuits from customers, patients, or business partners whose data you exposed
    • Regulatory investigations, with fines and penalties where the law allows insurance to pay them
    • Payment card industry assessments after a card data breach
    • Media liability for content on your website

    What does cyber insurance not cover?

    Read the exclusions before you need them. Common ones include:

    • Incidents that began before the policy. An intruder already inside your network on the start date may fall outside coverage.
    • Failure to maintain the security you promised. If the application says you use multi-factor authentication and you do not, the insurer can deny the claim or cancel the policy.
    • Upgrades. The policy restores you to where you were. It does not pay for a better system.
    • Lost future profit and reputational harm, beyond what the business interruption terms define.
    • Loss of intellectual property value.
    • War and state-sponsored attacks. Insurers tightened this wording in recent years.
    • Bodily injury and property damage, in most policies.
    • Outages at your utility or internet provider.

    Does cyber insurance cover ransomware payments?

    Most policies do, subject to limits. Many insurers apply a lower sublimit or a coinsurance share to ransomware, so a $1 million policy may pay $250,000 for an extortion event. The insurer must approve the payment in advance, and paying a group under US sanctions is illegal no matter what the policy says. Call the carrier’s hotline before you communicate with the attacker.

    Does it cover wire fraud and social engineering?

    Often only by endorsement, and with a low limit. A fake invoice or a spoofed email that tricks your employee into sending a wire is “voluntary” in the insurer’s eyes. Social engineering or funds transfer fraud coverage commonly caps at $100,000 to $250,000, and many policies require proof that you verified the request by phone before paying. Ask your broker to show you this clause. See our post on business email compromise for the controls insurers expect.

    How much does cyber insurance cost?

    A small business with modest revenue and good controls often pays $1,000 to $3,000 a year for $1 million in coverage. The premium depends on:

    • Industry. Healthcare, finance, and law firms pay more.
    • Revenue
    • The number and type of records you hold
    • Your security controls
    • Your claims history
    • The limit and the deductible you choose

    How much coverage do I need?

    Estimate the cost of your worst realistic week. Count the records you hold and multiply by the per-person cost of notification and monitoring. Add a forensic investigation, legal fees, two to four weeks of lost income, and the cost to rebuild your systems. Check your contracts too, because larger customers often require a minimum limit, commonly $1 million or $2 million. A broker who specializes in cyber coverage can benchmark you against similar businesses.

    What security controls do insurers require?

    The application asks about specific controls. Expect these questions:

    • Multi-factor authentication on email, remote access, and administrator accounts
    • Backups that are offline or immutable, encrypted, and tested
    • Endpoint detection and response software on computers and servers
    • Timely patching, with no end-of-life systems
    • Security awareness training and phishing tests for staff
    • A written incident response plan
    • Email filtering
    • Call-back verification before wire transfers and bank detail changes
    • Limited administrator rights

    Missing the first two items gets many applications declined outright.

    Why do claims get denied?

    • Inaccurate application answers. The application becomes part of the contract. An owner who checks “yes” for multi-factor authentication on all accounts, when two mailboxes lack it, hands the insurer a reason to rescind the policy. Answer with evidence, and involve the person who runs your IT.
    • Late notice. Policies set deadlines. Report a suspected incident right away, even before you know the scope.
    • Unapproved vendors. Hiring your own forensic firm or lawyer without the carrier’s consent can leave you paying those bills.
    • Unapproved payments. The same applies to a ransom.
    • Skipped verification. A wire sent without the required call-back may fall outside the fraud coverage.

    What should I do when I have an incident?

    Call the carrier’s 24-hour breach hotline first. Most policies supply a breach coach, an attorney who assembles the forensic team and directs the response. Using the carrier’s panel keeps the costs covered and brings in people who handle these events each week. Put the hotline number and the policy number on paper inside your incident response plan, because your email may be down when you need them.

    Does my small business need cyber insurance?

    If you hold customer records, take card payments, depend on computers to operate, or move money by wire, the answer is yes. A single ransomware event at a small business often costs six figures between downtime and recovery. Insurance transfers part of that loss.

    Insurance does not prevent anything. It pays after the damage, it excludes more than owners expect, and it gets cheaper and easier to buy when your controls are in place. Treat the application as a free checklist for your security program.

    How do I prepare for the application or renewal?

    1. Start 60 to 90 days before renewal.
    2. Gather evidence: screenshots of multi-factor settings, backup test records, training completion reports, and your written policies.
    3. Close the gaps you find before you answer.
    4. Use a broker who places cyber coverage every week.
    5. Compare sublimits and exclusions across quotes. The lowest premium often hides the lowest ransomware and fraud limits.

    Your next step

    Pull out your current policy and search it for the words “cyber,” “data breach,” and “social engineering.” If you find exclusions or nothing at all, talk to a broker this month. Cerberus Cybersecurity helps small businesses get insurance-ready with assessments, written policies, and staff training. Contact us before your next renewal.

  • AI Voice Cloning and Deepfake Scams: How to Verify Who Is Calling

    By J. Mesa

    Your phone rings. Your daughter is crying and says she caused a car accident. A man takes the phone and demands bail money. The voice was hers. The call was fake. Criminals now copy a voice from a short audio clip, and they aim the same trick at businesses: the “CEO” who calls accounting and orders an urgent wire.

    What is AI voice cloning?

    AI voice cloning uses software to copy a person’s voice from a recording. The criminal feeds a sample into a cloning tool, types a script, and the tool speaks the script in the copied voice. Some tools convert the criminal’s own speech in real time, so the fake voice can hold a conversation.

    The tools cost little or nothing, and they need no technical skill.

    How much audio does a scammer need?

    A few seconds produces a rough copy. Thirty seconds to a minute produces a convincing one. Sources include:

    • Videos on Facebook, Instagram, TikTok, and YouTube
    • Podcast and webinar appearances
    • Your voicemail greeting
    • A recorded company video or radio advertisement
    • A “wrong number” or survey call that keeps you talking

    Business owners and executives leave the largest trail, because marketing puts their voices in public.

    What is a deepfake?

    A deepfake is audio, video, or an image that AI generated or altered to show a real person saying or doing something they did not say or do. Voice clones are audio deepfakes. Video deepfakes place a person’s face and voice on a live video call.

    How do voice cloning scams work?

    The family emergency scam. A caller in a loved one’s voice claims an accident, an arrest, or a kidnapping. A second voice, playing a lawyer or an officer, takes over and demands money by wire, gift card, crypto, or cash handed to a courier. The caller insists that you stay on the line and tell nobody.

    The executive scam. An employee in finance receives a call or voicemail in the owner’s voice. The message cites a confidential deal and orders a wire today. Often an email arrives first, and the call “confirms” it. This is business email compromise with a voice added.

    The vendor or bank scam. A caller who sounds like your account representative asks you to update payment details or read back a security code.

    The help desk scam. A caller in an employee’s voice asks IT to reset a password or enroll a new phone for multi-factor authentication.

    Has this happened to real companies?

    Yes. In early 2024, a finance employee at the engineering firm Arup joined a video call with people who looked and sounded like the company’s chief financial officer and several colleagues. All of them were deepfakes. The employee sent about $25 million across multiple transfers. In 2019, criminals used a cloned voice of a parent company’s chief executive to talk a UK energy firm out of roughly $243,000.

    Criminals have since moved down-market. A scheme that needed a specialist team in 2019 now needs a laptop, so small businesses and families receive the same calls.

    How can I tell whether a voice is fake?

    You often can’t, and that is the wrong test to rely on. Audio quality over a phone line hides the flaws, and the tools improve each month. Some clues still help:

    • Flat emotion, odd pacing, or strange pauses before answers
    • Background noise that cuts in and out
    • Refusal to answer a personal question
    • On video: unnatural blinking, lips out of step with the audio, blurring around the hairline, or a face that glitches when the person turns sideways or passes a hand in front of it

    Judge the request, not the voice. Urgency, secrecy, and an unusual payment method mark a scam no matter who seems to be asking.

    What is a family safe word?

    A safe word is a word or phrase your family agrees on in person and uses to prove identity in an emergency. Pick something a stranger could not find online. Skip pet names, street names, and birthdays. Tell the children and the grandparents. When a frantic call arrives, ask for the word. A real family member knows it. A cloned voice does not.

    No safe word yet? Ask a question only the real person can answer, or hang up and call the person’s own number.

    How do I verify a caller at work?

    Build verification into the process so no employee has to judge a voice.

    1. Call back on a known number. Hang up and dial the number already in your records. Never use a number the caller or the email supplies.
    2. Require two people. No single employee sends a wire, changes vendor bank details, or adds a payee alone.
    3. Use a second channel. Confirm a phone request through a different system, such as an internal chat message the requester must answer.
    4. Set a challenge phrase. Give the finance team and the owners a code phrase for payment requests, shared in person and changed on a schedule.
    5. Allow the delay. Tell staff in writing that nobody gets disciplined for pausing a payment to verify it, even when the request came from the owner.
    6. Lock down the help desk. Require a callback or a video check with a manager before resetting passwords or multi-factor devices.

    Write these steps into a payment verification policy. A rule on paper protects the employee who has to say no to a voice that sounds like the boss.

    How do I limit my exposure?

    • Set personal social media accounts to private and trim old public videos.
    • Replace a personal voicemail greeting with the carrier’s default.
    • Let unknown calls go to voicemail. Answering and talking supplies a sample.
    • Skip the “yes” trap. Do not answer questions from unknown callers.
    • Review how much video and audio of owners and finance staff the company website needs.

    You can’t remove every recording, and a business needs a public face. Verification protects you when exposure can’t be avoided.

    What should I do if I get a suspicious call?

    Hang up. Call the person back at the number you already have. If the caller claims a relative is under arrest or in a hospital, call the relative, then another family member. Do not send money, read codes, or share account details during the first call. A real emergency survives a five-minute check.

    What if I already sent money?

    1. Call your bank at once and ask for a wire recall or a payment reversal.
    2. Report the gift card numbers to the card issuer.
    3. File a report at ic3.gov and ReportFraud.ftc.gov. For a business wire, mention the amount and the receiving bank, because the FBI can sometimes freeze funds reported within a few days.
    4. Tell your cyber insurance carrier.
    5. Tell your staff or your family what happened, so the next call fails.

    Is voice cloning illegal?

    Using a cloned voice to defraud someone is a crime under existing fraud laws. In February 2024, the Federal Communications Commission ruled that robocalls using AI-generated voices are illegal under the Telephone Consumer Protection Act. Laws slow nobody who operates from overseas, so your own verification steps matter more than the statute.

    Should I train my staff on deepfakes?

    Yes. Play examples of cloned voices during security awareness training, so staff hear how convincing they sound. Then run a drill: have someone call accounting with an urgent payment request and see whether the callback step happens. Praise the employee who refuses.

    Your next step

    Choose a family safe word tonight. Tomorrow, write a one-page rule that requires a callback and a second approver for payments and bank detail changes. Cerberus Cybersecurity writes these policies and trains teams to follow them. See our services or contact us.

  • Vulnerability Assessment vs. Penetration Test: Which One Does Your Business Need?

    By J. Mesa

    A customer contract, an insurance form, or an auditor asks whether you have had a penetration test. A vendor quotes you $900. Another quotes $14,000. Both call the service a pen test. One of them is selling you a vulnerability scan with a nicer cover page. Knowing the difference saves you money and keeps you out of trouble with the auditor.

    What is a vulnerability scan?

    A vulnerability scan is an automated check that compares your systems against a database of known weaknesses. A scanning tool such as Nessus, Qualys, or OpenVAS probes your computers, servers, firewalls, and websites. It reports missing patches, outdated software, weak settings, and default passwords, and it ranks each finding by severity.

    A scan runs in minutes or hours. It covers a lot of ground. It also produces false alarms, and it cannot tell you which findings matter most to your business.

    What is a vulnerability assessment?

    A vulnerability assessment adds a person to the scan. An analyst runs the tools, removes the false alarms, checks the findings against how your business operates, and gives you a prioritized list with steps to fix each item.

    The question it answers: what weaknesses do we have, and which ones should we fix first?

    What is a penetration test?

    A penetration test is an authorized, simulated attack. A skilled tester tries to break in the way a criminal would, with your written permission and inside agreed limits. The tester finds weaknesses, exploits them, chains small problems into large ones, and documents how far the attack reached.

    The question it answers: what can an attacker do to us, and what would it cost us?

    A scan might report a missing patch on a file server and a weak password policy as two medium findings. A penetration tester uses the weak password to log in as a receptionist, uses the missing patch to become an administrator, and shows you a screenshot of your payroll folder. Same weaknesses. Different level of proof.

    What is the difference between a vulnerability assessment and a penetration test?

    • Goal. An assessment finds as many weaknesses as possible. A penetration test proves what an attacker can achieve.
    • Method. An assessment relies on automated tools with human review. A penetration test relies on human skill supported by tools.
    • Breadth and depth. An assessment goes wide. A penetration test goes deep on a defined scope.
    • Time. An assessment takes a day or a few days. A penetration test takes one to three weeks.
    • Frequency. Run assessments each quarter or each month. Run penetration tests once a year and after major changes.
    • Output. An assessment delivers a ranked list of findings. A penetration test delivers a narrative of the attack, evidence, business impact, and fixes.
    • Cost. A penetration test costs several times more.

    Which one does my small business need?

    Start with vulnerability assessments. If you have never scanned your network, a penetration tester will spend your money finding problems a scanner would have found for a fraction of the price.

    Follow this order:

    1. Run a vulnerability assessment.
    2. Fix the critical and high findings.
    3. Scan again to confirm the fixes.
    4. Repeat each quarter.
    5. Add a penetration test once the basics hold, or when a rule or a contract requires one.

    Buy a penetration test sooner if you take card payments on your own systems, fall under the FTC Safeguards Rule, sell software or services to larger companies that demand one, or run a custom web application that holds customer data.

    How much does each one cost?

    Prices vary by size and scope. Typical ranges for a small business:

    • External vulnerability scan: $100 to $500 per scan, or a low monthly subscription
    • Vulnerability assessment with analyst review: $1,500 to $5,000
    • Penetration test of a small network or one web application: $5,000 to $20,000
    • Larger or more complex environments: $20,000 and up

    A “penetration test” quoted under $2,000 with a two-day turnaround is almost certainly an automated scan. Ask the vendor what the tester does by hand.

    What types of penetration tests exist?

    • External network. Attacks your internet-facing systems from outside.
    • Internal network. Starts from inside the office, as if an attacker already compromised one computer or one employee.
    • Web application. Targets a website, portal, or API for flaws such as broken access controls and injection.
    • Wireless. Tests the Wi-Fi networks and guest separation.
    • Social engineering. Tests the people with phishing emails, phone calls, or an attempt to walk into the building. See our post on how hackers get in.
    • Physical. Tests doors, badges, and server room access.

    Testers also describe how much they know going in. In a black box test, the tester starts with no inside information. In a gray box test, the tester gets a user account or network diagram. In a white box test, the tester gets full documentation. Gray box gives most small businesses the best value, because the tester spends your budget attacking and wastes none of it guessing.

    What do compliance rules require?

    • PCI DSS requires external vulnerability scans each quarter by an Approved Scanning Vendor, internal scans each quarter, and penetration tests each year for merchants with larger or more complex card environments.
    • The FTC Safeguards Rule requires covered financial businesses to run annual penetration tests and vulnerability assessments every six months, unless they use continuous monitoring. Businesses holding data on fewer than 5,000 consumers are exempt from this part.
    • HIPAA requires a risk analysis and periodic technical evaluation. It does not name penetration testing, but scans and tests are the standard way to meet the requirement.
    • Cyber insurers and enterprise customers ask for recent reports in applications and vendor questionnaires.

    How do I choose a penetration testing vendor?

    Ask these questions before you sign.

    • Who performs the test, and what certifications and experience do they hold? Look for OSCP, GPEN, or similar hands-on credentials.
    • What methodology do you follow? Good answers reference NIST SP 800-115, PTES, or the OWASP Testing Guide.
    • How much of the work is manual?
    • Can I see a sample report with the client details removed?
    • Do you carry professional liability insurance?
    • Is a retest of fixed findings included in the price?
    • How do you handle and delete the data you collect?

    What should a good report include?

    • An executive summary a business owner can read in five minutes
    • The scope, dates, and methods
    • Each finding with a severity rating, evidence, and the steps to reproduce it
    • The business impact in plain language
    • Specific instructions to fix each finding
    • For a penetration test, the attack path from first foothold to final objective

    How do I prepare for a test?

    1. Define the scope in writing: which systems, which addresses, which hours.
    2. Sign a rules of engagement document and an authorization letter. Testing without written permission is a crime.
    3. Notify your IT provider, your hosting company, and your cloud vendors as their policies require.
    4. Confirm your backups work before testing begins.
    5. Name one contact on each side for emergencies.
    6. Decide in advance who receives the report. It is a map of your weaknesses, so treat it as confidential.

    What happens after the test?

    The report has no value until you act on it. Assign each finding an owner and a due date. Fix the critical items first. Schedule the retest. Feed the lessons into your policies and your staff training, because many findings trace back to a habit and not to a machine.

    Your next step

    If you have never run a scan, start there. Cerberus Cybersecurity performs risk and compliance assessments for small businesses and measures the results against PCI DSS, HIPAA, and GLBA. Contact us to scope an assessment that fits your size and your budget.

  • Windows 10 End of Support: What Small Businesses Need to Do Before October 14, 2025

    By J. Mesa

    Microsoft ends support for Windows 10 on October 14, 2025. That date sits four months away. After it, Windows 10 computers stop receiving security fixes. If your office still runs Windows 10, you have one summer to decide what to do with each machine.

    What happens when Windows 10 support ends?

    Your computers keep working. They turn on, your software opens, and nothing on the screen announces a change. That quiet is the danger.

    After October 14, 2025, Microsoft stops releasing three things for Windows 10:

    • Security updates
    • Bug fixes
    • Technical support

    Attackers keep finding flaws in Windows every month. Windows 11 will receive the fixes. Windows 10 will not. Each published Windows 11 fix also tells criminals where to look for the same flaw in Windows 10.

    Is it safe to keep using Windows 10 after October 2025?

    No, unless you pay for extended updates. An unpatched computer that reads email and browses the web becomes easier to break into with each passing month. The WannaCry ransomware outbreak in 2017 showed the pattern: it tore through machines missing a patch, and unsupported Windows versions took heavy damage.

    One unsupported computer also endangers the others. An attacker who lands on the old front-desk PC uses it as a base to reach the server and the accounting system.

    What are my options?

    You have four.

    1. Upgrade the computer to Windows 11. Free, if the hardware qualifies.
    2. Replace the computer. Required when the hardware fails the Windows 11 requirements.
    3. Buy Extended Security Updates. A paid bridge that keeps security fixes coming for a limited time.
    4. Retire or isolate the computer. Take it off the network, or replace Windows with another operating system.

    Most offices will use a mix: upgrade the newer machines, replace the older ones, and buy a year of extended updates for the one PC that runs a stubborn piece of software.

    Can my computer run Windows 11?

    Windows 11 requires:

    • A supported 64-bit processor, which in practice means Intel 8th generation or newer, or AMD Ryzen 2000 series or newer
    • TPM 2.0, a security chip
    • UEFI firmware with Secure Boot
    • 4 GB of memory and 64 GB of storage at minimum

    As a rough guide, computers sold from 2018 onward qualify, and computers from 2017 and earlier often fail on the processor. To check a machine, run Microsoft’s free PC Health Check app, or open Settings, then Update and Security, then Windows Update, and read the Windows 11 message.

    Some computers fail the check only because someone turned TPM or Secure Boot off in the firmware settings. Your IT provider can turn them on in a few minutes.

    Is the Windows 11 upgrade free?

    Yes. Microsoft charges nothing to upgrade an eligible, licensed Windows 10 computer. The upgrade keeps your files and most of your applications in place. Back up the computer first, and expect the process to take one to two hours per machine.

    What are Extended Security Updates, and what do they cost?

    Extended Security Updates, or ESU, is a paid Microsoft program that continues critical and important security patches for Windows 10 after the deadline. It adds no new features and no general support.

    For businesses, Microsoft set the price at $61 per device for the first year. The price doubles each year, and the program runs for a maximum of three years. Three years on one PC costs $427, which approaches the price of a new computer. For individuals, Microsoft announced a one-year option at $30.

    Treat ESU as a bridge for the machines you can’t replace on time. It makes a poor long-term plan.

    Should I bypass the Windows 11 hardware requirements?

    No. Guides online show how to force Windows 11 onto unsupported hardware. Microsoft does not support those installations and does not promise them updates. A business that depends on an unsupported workaround has traded one unsupported system for another. Replace the hardware.

    What about my software and equipment?

    Check three categories before you upgrade anything.

    • Line-of-business software. Confirm with each vendor that your version runs on Windows 11. Dental imaging, legal practice, older accounting releases, and industry-specific tools cause the most trouble.
    • Equipment that runs on a PC. X-ray sensors, CNC machines, label printers, lab instruments, and point-of-sale terminals often depend on old drivers. Ask the manufacturer for a Windows 11 driver in writing.
    • Microsoft 365. Microsoft says the Microsoft 365 apps will keep receiving security updates on Windows 10 for three more years, but it ends support for those apps on Windows 10 at the same October deadline. Expect problems to go unfixed.

    If a machine must stay on Windows 10 to run equipment, buy ESU for it and isolate it. Put it on its own network segment, block it from email and web browsing, and limit who can log in.

    Does Windows 10 end of support affect compliance?

    Yes. Running an unsupported operating system on a computer that touches regulated data creates a finding.

    • PCI DSS requires you to protect systems from known vulnerabilities by installing security patches. An unpatched Windows 10 PC in the card environment fails that requirement.
    • HIPAA requires a risk analysis and reasonable safeguards for patient information. Regulators have cited unsupported software in enforcement actions.
    • The FTC Safeguards Rule expects financial businesses, including tax preparers and auto dealers, to keep systems current.
    • Cyber insurance applications ask about end-of-life software. A wrong answer can jeopardize a claim.

    How do I plan the migration?

    Use the four months.

    1. Inventory this week. List each computer: user, age, processor, Windows version, and the result of the PC Health Check.
    2. Sort the list. Mark each machine as upgrade, replace, ESU, or retire.
    3. Call your software vendors. Confirm Windows 11 support for each critical application.
    4. Budget and order early. Many businesses will buy computers in the same quarter. Prices and delivery times get worse near a deadline.
    5. Back up, then test. Upgrade one computer per department first. Have that person work on it for a week.
    6. Roll out in waves. Schedule the rest in groups, away from payroll week and month-end.
    7. Train the staff. Windows 11 moves the Start menu and changes some settings. Fifteen minutes of orientation prevents a week of help requests.
    8. Finish by the end of September. Leave two weeks of slack for the machine that surprises you.

    What should I do with the old computers?

    Do not put them in a closet with customer data on the drives, and do not hand them to an employee’s nephew as they are.

    Wipe each drive with a secure erase tool, or remove the drive and have a certified vendor destroy it. Get a certificate of destruction for any computer that held patient, payment, or financial records. Record the serial number and the disposal date in your asset inventory. After that, donate or recycle the hardware through a certified electronics recycler.

    What are the benefits of Windows 11 for security?

    The hardware requirements exist for a reason. TPM 2.0 and Secure Boot support protections that Windows 11 turns on by default: drive encryption on many devices, defenses against tampering during startup, stronger protection of stored credentials, and passkey sign-in through Windows Hello. You get a harder target without buying another product.

    Your next step

    Count your Windows 10 computers today. The count takes an hour and tells you the size of the project. Cerberus Cybersecurity includes operating system and patch status in our risk and compliance assessments, and we help you write the asset and patch policies that prevent the next deadline scramble. Contact us to get on the calendar before fall.

  • What Is a Passkey? How Passwordless Sign-In Works

    By J. Mesa

    The first Thursday of May used to be World Password Day. This year the FIDO Alliance promoted World Passkey Day in its place, and Microsoft announced that new Microsoft accounts go passwordless by default. Google, Apple, Amazon, and most large banks now offer passkeys. If you run a small business, you will see the prompt soon, and your staff will ask what to do with it.

    What is a passkey?

    A passkey is a sign-in credential that replaces your password with a cryptographic key stored on your phone, computer, or security key. You approve a sign-in with your fingerprint, your face, or your device PIN. You type nothing, and you have nothing to remember.

    Passkeys follow an open standard called FIDO2, built by the FIDO Alliance and the World Wide Web Consortium. Apple, Google, and Microsoft all support it, so a passkey works across phones, laptops, and browsers from different makers.

    How does a passkey work?

    When you create a passkey for a website, your device generates two linked keys.

    • The private key stays on your device, protected by its security chip. It never leaves and nobody sees it, including you.
    • The public key goes to the website. It can check a signature, and it can’t create one.

    When you sign in, the website sends your device a challenge. You unlock the device with your fingerprint, face, or PIN. The device signs the challenge with the private key and sends the signature back. The website checks it against the public key and lets you in.

    Your fingerprint or face never leaves the device. The biometric only unlocks the key locally. The website receives a signature and nothing else.

    Are passkeys safer than passwords?

    Yes, for four reasons.

    • Nothing to phish. Your device ties each passkey to the real website address. A fake login page at a look-alike address gets no response, because the passkey for the real site does not match. You can’t hand over a secret you never knew.
    • Nothing useful to steal from the website. A breach of the site’s database exposes public keys. Criminals can’t sign in with a public key.
    • No reuse. Every passkey is unique to one account on one site.
    • No guessing. There is no word to guess and no pattern to crack.

    Most break-ins at small businesses start with a stolen or phished password. Passkeys remove that entire category for the accounts that support them.

    Do passkeys replace multi-factor authentication?

    A passkey combines two factors in one step: something you have, the device holding the key, and something you are or know, the biometric or PIN that unlocks it. For that reason, most services skip the extra code prompt when you sign in with a passkey.

    Passkeys also beat the common forms of multi-factor authentication. A criminal can trick you into reading a text message code over the phone or approving a push notification. A passkey gives the criminal nothing to ask for.

    What happens if I lose my phone?

    This question stops most people, and the answer depends on where the passkey lives.

    Synced passkeys live in a password manager: Apple Passwords with iCloud Keychain, Google Password Manager, or a third-party manager such as 1Password or Bitwarden. The manager encrypts them and syncs them to your other devices. Lose the phone, sign in to the manager on a new phone, and your passkeys return.

    Device-bound passkeys live on one piece of hardware, such as a YubiKey security key. They can’t be copied. Lose the key and that passkey is gone, so you register two keys and store the spare in a safe.

    Either way, set up recovery before you need it:

    1. Create passkeys on at least two devices, or keep a spare security key.
    2. Protect the account that syncs your passkeys with a strong password and multi-factor authentication.
    3. Save the recovery codes each service offers and store them on paper in a locked place.

    A thief who steals your phone still needs your face, your fingerprint, or your PIN to use a passkey. Choose a six-digit PIN or longer, and do not share it.

    Where can I use passkeys today?

    The list grows each month. Current supporters include Google, Microsoft, Apple, Amazon, PayPal, eBay, GitHub, Shopify, Intuit, Adobe, WhatsApp, LinkedIn, and a growing number of banks and payroll providers. Look for “Passkeys” or “Sign-in options” in the security settings of each account. The directory at passkeys.directory tracks which sites support them.

    How do I set up a passkey?

    The steps look about the same everywhere.

    1. Sign in to the account the usual way.
    2. Open the security or sign-in settings.
    3. Choose “Create a passkey” or “Add a passkey.”
    4. Approve with your fingerprint, face, or device PIN.
    5. Repeat on a second device, or confirm that your password manager synced it.

    To sign in on a computer that does not hold your passkey, pick the option to use a phone. The computer shows a QR code, you scan it with your phone, and you approve on the phone. The two devices confirm over Bluetooth that they sit near each other, which blocks a remote attacker from using the same trick.

    Should a small business switch to passkeys?

    Yes, in stages. Start with the accounts whose loss would hurt most.

    • Email and identity. Turn on passkeys in Microsoft 365 or Google Workspace for owners, administrators, and anyone who handles money. Microsoft Entra ID and Google Workspace both let administrators manage passkeys for staff.
    • Banking, payroll, and accounting. Add a passkey wherever the provider offers one.
    • Administrators. Give anyone with admin rights two hardware security keys. Device-bound keys offer the strongest protection for the accounts that control everything else.
    • Everyone else. Use a business password manager that stores and syncs passkeys, so the company keeps control when an employee leaves.

    Update your access policy to name passkeys as the preferred sign-in method, and show the staff how they work during training. The first passkey prompt confuses people. A five-minute demonstration fixes that.

    What are the downsides of passkeys?

    • Uneven support. Many sites still offer passwords only, so you will run passwords and passkeys side by side for years. Keep the password manager.
    • Ecosystem lock-in. Moving passkeys between Apple, Google, and third-party managers is still clumsy. The FIDO Alliance is working on a standard for secure transfer.
    • The password often remains. Many sites add a passkey and keep the old password as a fallback. An attacker can still phish that password. Where the service allows it, remove the password or replace it with a long random one stored in your manager.
    • Shared accounts. A passkey belongs to a person’s device. For a login that three employees share, store the passkey in a shared vault in your password manager.
    • Recovery is the weak point. An account protected by a passkey and recoverable by a text message is only as strong as the text message. Review the recovery options.

    Do passkeys stop all phishing?

    No. Passkeys stop password theft. Criminals still send fake invoices, call pretending to be your bank, and talk help desks into resetting accounts. People remain the target, so keep training them to slow down and verify.

    Your next step

    Add a passkey to your email account today. It takes two minutes. Then list the five accounts your business can’t afford to lose and check each one for passkey support. Cerberus Cybersecurity helps small businesses write access policies and train staff on changes like this one. Review our services or contact us.

  • What Is a Password Manager, and Is It Safe to Use One?

    By J. Mesa

    You have more than a hundred online accounts. You can’t remember a hundred strong passwords, so you reuse five or six. Criminals know this. They take passwords stolen from one breached website and try them on your email, your bank, and your payroll system. A password manager ends that problem for a few dollars a month.

    What is a password manager?

    A password manager is an app that creates, stores, and fills in a different password for each of your accounts. It keeps them in an encrypted vault. You unlock the vault with one master password, and the app handles the rest.

    You install it on your computer and phone and add its extension to your browser. When you sign up for a new account, the manager generates a long random password and saves it. When you return to that site, the manager fills it in. You never type the password, and you never need to know it.

    Is a password manager safe?

    Yes, and it is far safer than the alternatives most people use: reused passwords, a spreadsheet, sticky notes, or the same base word with a different number on the end.

    Reputable password managers use a zero-knowledge design. The app encrypts your vault on your own device with a key derived from your master password. The company stores only the scrambled result. Its employees can’t read your passwords, and a thief who steals the company’s servers gets encrypted data.

    Putting every password in one place sounds risky. Compare the real risks. With reuse, one breach at any website you ever joined exposes the password to all your accounts. With a manager, an attacker needs your encrypted vault, your master password, and your second factor.

    What happens if the password manager gets hacked?

    It has happened. In 2022, attackers stole encrypted customer vaults from LastPass. Customers with long, unique master passwords stayed protected by the encryption. Customers with short or reused master passwords faced real exposure, because attackers could guess at those vaults offline for as long as they liked.

    Three lessons came out of that breach:

    • Your master password carries the weight. Make it long.
    • Turn on multi-factor authentication for the vault.
    • Choose a vendor that publishes independent security audits and tells customers the truth after an incident.

    How do I choose a password manager?

    Look for these features:

    • Zero-knowledge encryption, described in public documentation
    • Independent security audits, published each year
    • Multi-factor authentication for the vault, including support for security keys
    • Apps for every device you use
    • Breach monitoring that flags weak, reused, and exposed passwords
    • Secure sharing, so you stop sending passwords by text and email
    • For a business: an admin console, shared team vaults, and the ability to remove a departing employee’s access

    Well-regarded choices include 1Password, Bitwarden, Dashlane, and Keeper. Bitwarden offers a capable free tier for individuals. Business plans from these vendors run about $4 to $8 per user per month.

    Are browser password managers good enough?

    The password managers built into Chrome, Edge, Safari, and Firefox beat reuse, and they improved a lot over the last few years. For a household, they do the job.

    For a business they fall short. They tie passwords to an employee’s personal browser profile. They offer weak controls for sharing a login among three people, no central view of weak passwords across the company, and no clean way to take access back on an employee’s last day. A dedicated business password manager gives you those controls.

    How do I create a strong master password?

    Use a passphrase: four or five random words. Roll dice against a word list or let the manager generate one. Length beats complexity, so a 25-character passphrase of unrelated words beats an 8-character jumble of symbols.

    Follow three rules.

    1. Use the master password nowhere else.
    2. Do not store it in the vault it unlocks, in an email, or in a phone note.
    3. Write it on paper along with your recovery code, and keep that paper in a safe or a locked drawer. Most vendors can’t reset a forgotten master password, because they never knew it.

    What if I forget my master password?

    Plan for this before it happens. Most managers provide an emergency kit or recovery code at signup. Print it. Family and business plans let an administrator or a trusted contact recover an account. Set that up on day one. A business should keep at least two administrators, so one person’s vacation or resignation does not lock the company out of its own accounts.

    How do I roll out a password manager at work?

    Roll it out in an afternoon and finish the cleanup over a month.

    1. Pick the product and buy a business plan.
    2. Create shared vaults by team: finance, operations, social media, IT.
    3. Require multi-factor authentication for every user.
    4. Hold a 30-minute session. Show the staff how to install the app, save a login, and share one. Cover it again in your security awareness training.
    5. Import saved passwords from browsers, then turn off the browsers’ built-in password saving.
    6. Start with the accounts that matter most: email, banking, payroll, accounting, and the domain registrar. Replace each password with a generated one.
    7. Use the manager’s report to find reused and weak passwords, and fix ten a week.
    8. Add vault removal to your offboarding checklist, and change the shared passwords a departing employee knew.

    Write the expectation into your password policy: staff store work credentials in the company password manager and nowhere else.

    What should I never do with a password manager?

    • Do not leave the vault unlocked on a shared or unattended computer. Set it to lock after a few minutes of inactivity.
    • Do not approve a login prompt you did not start.
    • Do not type your master password into a page you reached from an email link. Open the app yourself.
    • Do not skip the recovery setup.
    • Do not keep the old spreadsheet “just in case.” Delete it and empty the trash.

    Does a password manager stop phishing?

    It helps more than most people expect. The manager matches each saved login to the exact web address where you created it. When a phishing email sends you to a look-alike site, the manager finds no match and offers nothing to fill. That silence is your warning. If the manager does not offer your password on a page that looks like your bank, stop and check the address bar.

    A password manager does not stop every attack. A criminal who tricks you into reading a code over the phone can still get in. Pair the manager with multi-factor authentication and trained people.

    Should I store my authenticator codes in the password manager?

    Many managers can generate the six-digit codes too. For most accounts, that convenience is fine and still far better than no second factor. For your most important accounts, such as email, banking, and the password manager itself, keep the second factor separate: an authenticator app on your phone or a hardware security key.

    Your next step

    Pick a password manager this week and move your email, banking, and payroll logins into it first. Cerberus Cybersecurity writes password and access policies and trains staff to follow them. See our services or contact us to get started.

  • How to Back Up Your Business Data: The 3-2-1 Rule Explained

    By J. Mesa

    World Backup Day falls on March 31. Use it as a deadline. Ransomware crews count on one fact about small businesses: most of them cannot restore their own data. A working backup turns a business-ending attack into a bad week. This guide covers what to back up, where to keep it, and how to prove it works.

    What is the 3-2-1 backup rule?

    The 3-2-1 rule says you keep three copies of your data, on two different types of storage, with one copy stored offsite.

    • Three copies. The original plus two backups. One backup fails more often than you expect.
    • Two types of storage. For example, an external drive or network storage device in the office, plus a cloud backup service. A single power surge or a single bad firmware update should not reach both.
    • One offsite. Fire, flood, typhoon, and theft take the office and every device in it. An offsite copy survives.

    Many security teams now extend the rule to 3-2-1-1-0. The extra 1 stands for one copy that is offline or immutable, which means nobody can change or delete it for a set period. The 0 stands for zero errors when you test a restore.

    What data should a small business back up?

    Start with a list of what you could not operate without for one week. For most small businesses that list includes:

    • Accounting and payroll files, such as your QuickBooks company file
    • Customer and patient records
    • Contracts, proposals, and signed forms
    • Email and calendars
    • Point-of-sale data and inventory
    • Shared drives and project files
    • Website files and the website database
    • Licenses, software installers, and configuration exports for your firewall and router
    • The password manager vault export, stored encrypted

    Ask each employee one question: if your laptop died right now, what would you lose? The answers often reveal a desktop folder holding the only copy of something important.

    Do I need to back up Microsoft 365 or Google Workspace?

    Yes. Microsoft and Google keep their services running, and they protect against their own hardware failures. Your data remains your job. Microsoft calls this the shared responsibility model.

    The recycle bin and retention settings help with small accidents. They do not help when an employee deletes a folder and nobody notices for four months, when a departing employee wipes a mailbox, or when ransomware syncs encrypted files over the good ones. A third-party backup service for Microsoft 365 or Google Workspace costs a few dollars per user per month and keeps an independent copy of mail, OneDrive or Drive, and shared sites.

    Is cloud sync the same as backup?

    No. Dropbox, OneDrive, and Google Drive sync changes. If you delete a file, the sync deletes it everywhere. If ransomware encrypts a file, the sync uploads the encrypted version. Version history can save you, but retention limits vary by plan, and restoring ten thousand files one at a time takes days.

    A backup keeps point-in-time copies on a schedule, holds them for a period you choose, and restores a whole folder or a whole machine in one operation. Use sync for convenience and backup for survival.

    How often should I back up?

    Answer two questions.

    How much work can you afford to redo? IT people call this the recovery point objective. If you back up nightly, you can lose up to one day of work. A busy office with constant transactions may need hourly backups for its key systems.

    How long can you stay down? This is the recovery time objective. If the answer is four hours, a cloud-only backup that needs two days to download will not meet it. You need a local copy for speed and a cloud copy for disasters.

    Daily automated backups suit most small offices. Automate them. A backup that depends on someone remembering to plug in a drive stops in the second week.

    How do I protect backups from ransomware?

    Attackers hunt for backups first. They delete them, then encrypt everything else, then send the ransom note. Make your backups hard to reach.

    • Keep one copy offline or immutable. Rotate external drives and unplug them, or choose a cloud backup with object lock or immutability turned on.
    • Use separate credentials. The backup account should have its own password, stored in a password manager, with multi-factor authentication. Do not log in to the backup console with the same admin account you use for everything else.
    • Encrypt the backups. A stolen backup drive is a data breach. Turn on encryption and store the key somewhere other than the device it protects.
    • Limit who can delete. Few people need the power to erase backup history. Require a delay or a second approval for deletions if your product offers it.
    • Patch the backup system. Network storage devices are frequent ransomware targets. Update the firmware and keep the device off the public internet.

    How do I test a backup?

    A backup you never restored is a guess. Run these tests on a schedule.

    1. Monthly file restore. Pick three random files from different folders and restore them to a different location. Open each one.
    2. Quarterly system restore. Restore a full machine or your accounting database to spare hardware or a virtual machine. Time it. Compare the time against how long you said you could stay down.
    3. Check the logs weekly. Backup software fails without telling anyone. Send the success and failure reports to a real person, and name a second person who covers when the first is out.
    4. Write down the steps. Document where the backups live, who holds the credentials, and how to restore. Print a copy. During an attack your shared drive is the thing you lost.

    What does backup cost?

    Less than one day of downtime. A typical five-person office spends roughly this:

    • Cloud backup for computers: $7 to $10 per computer per month
    • Backup for Microsoft 365 or Google Workspace: $2 to $5 per user per month
    • A network storage device with two drives: a one-time $400 to $700
    • Two external drives for rotation: about $150

    Compare that against a week with no invoices, no schedules, and no customer records.

    What are the most common backup mistakes?

    • One backup drive that stays plugged in all year. Ransomware encrypts it along with the computer.
    • Backing up the server and forgetting the laptops, or the reverse.
    • Nobody reading the failure alerts.
    • Storing the only copy of the encryption key on the machine being backed up.
    • Assuming the IT vendor handles it. Ask for a restore demonstration and a written report.
    • Keeping only seven days of history. Some attacks sit unnoticed for weeks, so keep at least 30 to 90 days of versions.
    • Forgetting the systems outside the office: the website, the cloud accounting system, the phone that holds every customer text.

    Does compliance require backups?

    Often, yes. The HIPAA Security Rule requires a data backup plan and a disaster recovery plan for health records. PCI DSS and the FTC Safeguards Rule both expect you to protect and recover the data you hold. Cyber insurance applications now ask whether you keep offline or immutable backups and whether you test them. Answer those questions with evidence, such as dated restore test records.

    Your next step

    Pick one critical file today and restore it from backup. If you can’t, you have found your project for March. Cerberus Cybersecurity reviews backup and recovery as part of our risk and compliance assessments, and we write the recovery plan your team follows under pressure. Contact us to schedule a review.

  • Romance Scams and Pig Butchering: How They Work and How to Stop Them

    By J. Mesa

    Valentine’s Day passed yesterday, and scammers treated it as their busiest week of the year. The Federal Trade Commission counted more than $1 billion in reported romance scam losses in 2023. The real number runs higher, because most victims tell nobody. If you own a business, this matters to you twice: your family is a target, and so is the bookkeeper who holds the keys to your bank account.

    What is a romance scam?

    A romance scam is a fraud in which a criminal builds a fake relationship with you online, earns your trust over weeks or months, and then asks for money. The scammer invents a person. That person has stolen photos, a believable job, and a reason they can’t meet you. Common cover stories include a military deployment, an offshore oil rig, a medical mission, or a construction contract overseas.

    The request for money comes after the trust. A customs fee. A hospital bill. A plane ticket to come see you. You pay, a new emergency appears, and the cycle repeats until you run out of money or patience.

    What is pig butchering?

    Pig butchering is a romance scam with an investment scam attached. The name comes from a Chinese phrase about fattening a pig before slaughter. The scammer fattens you with attention first.

    The sequence follows a script:

    1. A stranger contacts you. The opener is often a “wrong number” text, a dating app match, or a friendly message on LinkedIn or Facebook.
    2. The stranger moves the conversation to WhatsApp or Telegram and chats with you every day.
    3. After a few weeks, the stranger mentions an uncle or a mentor who taught them to trade cryptocurrency. They show you screenshots of their gains.
    4. They walk you through opening an account on a trading site. The site is fake. The scammer controls it.
    5. You deposit a small amount. The site shows a profit. You withdraw a little, and the withdrawal works. That test withdrawal is bait.
    6. You deposit more. Sometimes much more. The dashboard shows a fortune.
    7. You try to cash out. The site demands a “tax” or a “verification fee” first. You pay. The money is gone, and so is your new friend.

    The FBI’s Internet Crime Complaint Center reported $4.57 billion in investment fraud losses for 2023, and crypto schemes like this one drove most of that figure.

    Who do romance scammers target?

    Everyone. Older adults lose the largest sums, because they have retirement savings and home equity. Younger adults report scams more often. Recent widows and widowers, people going through divorce, and people who relocated for work are frequent targets, because loneliness makes a daily “good morning” text feel valuable.

    Education does not protect you. Engineers, nurses, and business owners have lost six figures. The scammers work in teams, follow tested scripts, and practice on thousands of people. You are facing a call center, and the person typing to you may be a trafficking victim forced to work the script.

    What are the warning signs of a romance scam?

    Watch for these signals in yourself or in someone you care about:

    • The person can never video chat, or the video is short, dark, and glitchy.
    • They say “I love you” within days.
    • They ask you to leave the dating app and move to WhatsApp, Telegram, or Signal.
    • Their job keeps them overseas or out of reach.
    • Every plan to meet falls apart at the last minute.
    • They ask for money, gift cards, crypto, or your bank login.
    • They coach you on an investment that only works through one website or app.
    • They tell you to keep the relationship or the investment secret from your family and your bank.

    That last sign matters most. A scammer needs you isolated. Anyone who tells you to lie to your bank teller is robbing you.

    How do I check whether an online match is real?

    Run three tests before you get attached.

    • Reverse image search. Save their profile photos and upload them to Google Images or TinEye. Stolen photos often show up under a different name.
    • Live video. Ask for a video call and ask them to wave or hold up three fingers. A real person can do it in ten seconds.
    • The money rule. Decide today that you send no money to anyone you have not met in person. Write the rule down. Tell a friend about it.

    For investments, search the platform name with the word “scam.” Check the firm with your state securities regulator and FINRA BrokerCheck. A legitimate broker holds a registration. A fake trading site holds a web address registered last month.

    How do romance scams hurt a business?

    Three ways.

    First, embezzlement. A person deep in a scam will borrow from anywhere to keep the “relationship” or the “investment” alive. If that person runs your payroll or pays your vendors, your operating account sits within reach. Courts have sentenced bookkeepers and even a bank CEO for stealing from employers to feed a pig butchering scheme.

    Second, money mule work. Scammers ask victims to receive and forward money “as a favor.” An employee who agrees may route stolen funds through accounts tied to your business, and the bank will freeze those accounts.

    Third, access. A scammer who spends two months chatting with your office manager learns your vendors, your schedule, and your software. That information feeds a business email compromise attack later.

    Protect the business with controls that do not depend on any one person’s judgment. Require two people to approve wire transfers and new payees. Review bank statements yourself each month. Cover romance and investment scams in your security awareness training, and say it out loud: this happens to smart people, and nobody here gets mocked for reporting it.

    What should I do if I sent money to a scammer?

    Move fast. Hours count.

    1. Stop all contact. Do not explain, and do not send one more payment to “unlock” your funds.
    2. Call your bank or card issuer and ask them to reverse or recall the transfer. For a wire, ask for a recall the same day.
    3. If you paid with gift cards, call the card company with the card numbers and receipt.
    4. Report to the FBI at ic3.gov and to the FTC at ReportFraud.ftc.gov. Include wallet addresses, transaction IDs, phone numbers, and screenshots.
    5. Change the passwords on any account you discussed with the scammer, and turn on multi-factor authentication.
    6. Tell someone you trust. Shame keeps victims silent, and silence helps the scammer.

    Can I get my money back?

    Sometimes, if you act within a day or two and the money moved through a bank. Crypto transfers are far harder to recover.

    Expect a second wave. After a loss, “recovery agents” will contact you and promise to retrieve your funds for an upfront fee. They are the same criminals, or their colleagues. The FBI, the FTC, and your bank charge nothing to take a report, and no legitimate firm guarantees recovery.

    How do I talk to a family member who is being scammed?

    Skip the lecture. A person in a scam believes they are in love, and an attack on the relationship pushes them toward the scammer. Ask questions instead. Have you seen them on video? What happened the last time you planned to meet? Would you run their photos through an image search with me? Offer to sit with them while they call the bank. Keep the door open, because most victims come back to the one person who did not shame them.

    Your next step

    Set a two-person rule for payments in your business this week, and bring this topic to your next staff meeting. If you want help building controls and training that cover fraud like this, contact Cerberus Cybersecurity or review our services.