Category: Recommendations

  • Small Business Cybersecurity Checklist: 20 Things to Review Every Year

    By J. Mesa

    The start of a new year is a good time to check your locks. Staff changed, you added software, a vendor came and went. Each change can leave a gap.

    This checklist covers twenty items in five groups. Set aside an afternoon, work through it, and write down what you find.

    Why review your security every year?

    • People join and leave, and their access lingers
    • Software reaches the end of its support
    • New services get added without a security review
    • Backups fail without anyone noticing
    • Insurers and clients ask for proof

    A yearly review catches what daily work misses.

    Accounts and access

    1. List every account and who can use it. Include email, banking, cloud storage, your website, your domain, and social media.

    2. Remove access for former employees and vendors. Check shared mailboxes and shared passwords too.

    3. Confirm multi-factor authentication is on for every account that offers it. Start with email, banking, and administrator accounts.

    4. Check for shared or reused passwords. Give each person their own login and a password manager.

    5. Review administrator rights. Few people should have them, and nobody should use an administrator account for daily work.

    Devices and software

    6. Inventory your devices. List every computer, phone, tablet, server, router, and printer.

    7. Confirm automatic updates are on for operating systems, browsers, and applications.

    8. Identify anything that no longer receives security updates and plan its replacement.

    9. Check that security software is installed and current on every computer.

    10. Confirm laptops and phones are encrypted and lock after a few minutes.

    Network

    11. Update your router and firewall, and change any default password.

    12. Check your Wi-Fi. Use WPA2 or WPA3 with a strong password, and keep guests and smart devices on a separate network.

    13. Review remote access. Close anything exposed to the internet that you don’t need, and require multi-factor authentication for the rest.

    Data and backups

    14. Know where your sensitive data lives. Customer records, employee files, and financial information.

    15. Test a restore from backup. Time it. Confirm one copy sits offline or offsite.

    16. Delete data you no longer need, and dispose of old devices and paper securely.

    17. Review cloud sharing settings and remove public links.

    People and plans

    18. Train every employee on phishing and safe data handling, and record who attended.

    19. Review your incident response plan. Update the names and phone numbers, and print a copy.

    20. Review your vendors, your insurance, and your compliance duties. Confirm who holds your data, what your cyber policy requires, and which rules apply to you.

    How long does the checklist take?

    For a business with fewer than 25 people, plan on three to four hours for the first pass. It goes faster each year, because you keep the lists you made.

    Who should do it?

    Name one person to lead, often the owner or the office manager, and involve whoever handles IT. Ask your IT provider for the device and update reports. The person who leads does not need to be technical. They need to ask each question and write down the answer.

    What should I do with the results?

    Sort what you find into three groups:

    1. Fix now. Missing multi-factor authentication, active accounts for former staff, failed backups.
    2. Fix this quarter. Unsupported devices, missing training, an outdated plan.
    3. Plan and budget. Larger replacements and projects.

    Assign each item an owner and a date.

    What are the most common problems this review finds?

    • An email account without multi-factor authentication
    • A former employee who can still log in
    • A backup that stopped running months ago
    • A router that has never been updated
    • A shared password that everyone knows
    • An incident plan with phone numbers for people who left

    Any one of these is an open door.

    How do I prove I did the review?

    Keep a dated copy of the completed checklist, with notes on what you found and fixed. Insurers, clients, and auditors accept this kind of record as evidence of a security program.

    Should I review more than once a year?

    Some items deserve a shorter cycle.

    • Monthly: confirm that updates and backups ran
    • Quarterly: review who has access to what
    • Yearly: the full checklist, training, and the plan
    • After any change: a new system, a new vendor, or a departing employee

    Is a checklist the same as a risk assessment?

    No. A checklist confirms that basic controls are in place. A risk assessment looks at your specific business: what data you hold, what could go wrong, how likely it is, and what it would cost. The checklist is the starting point. An assessment tells you where to invest next.

    What if I find something I can’t fix?

    Write it down with the reason, and reduce the risk another way. An old system you can’t replace yet can be taken off the internet and restricted to the people who need it. A documented risk with a plan is far better than an unknown one.

    Does this checklist cover compliance?

    It covers the basics that most standards share. If you accept payment cards, handle health information, or provide financial services, you have added duties under PCI-DSS, HIPAA, or the FTC Safeguards Rule. Use this list as a foundation and check the specific requirements that apply to you.

    Where do I start if I am short on time?

    Do these five first. They take under an hour.

    1. Turn on multi-factor authentication for email.
    2. Disable accounts for former staff.
    3. Check that your last backup succeeded.
    4. Confirm automatic updates are on.
    5. Print your emergency contact list.

    How long does this checklist take?

    Plan for one working day. Most owners finish the account review and the backup test before lunch, then spend the afternoon on updates and the phone call to the bank. Put the date on your calendar now and invite the person who handles your IT. A checklist you schedule gets done. A checklist you save for a slow week waits until after the breach.

    Your next step

    Put the review on your calendar this month and work through all twenty items. If you want an outside view, Cerberus Cybersecurity performs risk and compliance assessments that cover this checklist and go deeper into the risks specific to your business. Contact us to schedule yours.

  • What Is Business Email Compromise? How to Stop Invoice and Wire Fraud

    By J. Mesa

    A bookkeeper gets an email from a longtime vendor. The vendor has changed banks, the message says, and future payments should go to a new account. The email looks right. The bookkeeper updates the record and pays the next invoice. Weeks later the real vendor calls to ask about the overdue payment.

    That is business email compromise. It needs no malware, and it costs businesses more than any other online crime reported to the FBI.

    What is business email compromise?

    Business email compromise (BEC) is a scam in which a criminal uses email to pose as someone you trust, such as an owner, an executive, a vendor, or an attorney, and asks an employee to send money or sensitive information.

    The message may come from a look-alike address or from a real account the criminal has taken over.

    How does a BEC scam work?

    1. Research. The criminal studies your website and social media to learn who handles payments and who your vendors are.
    2. Access or imitation. They break into an email account through phishing, or they register a domain one letter off from the real one.
    3. Watching. Inside a mailbox, they read invoices and learn how people write.
    4. The request. They send a payment request or a change in bank details at a believable moment.
    5. The transfer. The money goes to an account they control and moves again within hours.

    What are the common types of BEC?

    • Vendor or invoice fraud. A fake notice that a supplier’s bank details have changed.
    • CEO fraud. A message from “the owner” asking for an urgent wire.
    • Payroll diversion. A request to change an employee’s direct deposit account.
    • Gift card requests. “The boss” needs gift cards for clients right away.
    • Attorney impersonation. A message about a confidential deal that requires a fast payment.
    • Real estate fraud. Fake closing instructions sent to a buyer.
    • Data theft. A request for employee W-2 forms or customer lists.

    Why does BEC work?

    • It uses trust in people you know
    • It arrives during real transactions
    • It contains no malicious link or attachment for a filter to catch
    • It creates urgency and asks for secrecy
    • Employees want to be helpful and fast

    What are the warning signs?

    • A change in bank account or payment details
    • Pressure to act today
    • A request to keep the matter confidential
    • A sender address that differs by a letter or uses a different domain
    • A reply-to address that differs from the sender
    • A request outside the normal process
    • Writing that sounds unlike the person
    • A message that says the sender can’t take calls

    How much does BEC cost?

    The FBI’s Internet Crime Complaint Center reports losses from BEC in the billions of dollars each year, more than ransomware by a wide margin. A single incident at a small business can run from a few thousand dollars to several hundred thousand.

    How do I prevent BEC?

    Technology helps, and process stops it.

    • Verify by phone. Confirm any new or changed payment details by calling a number you already have on file. Never use the number in the email.
    • Require two people to approve wire transfers and new payees.
    • Set a waiting period for payments to a new account.
    • Turn on multi-factor authentication for all email accounts.
    • Train your staff to recognize these requests, with real examples.
    • Limit what you publish about who handles finance.
    • Review mailbox rules. Attackers create forwarding rules to hide their activity.

    What technical controls help?

    • SPF, DKIM, and DMARC records on your domain, which make it harder to send email that appears to come from you
    • External sender warnings that flag messages from outside your company
    • Email filtering with impersonation protection
    • Alerts for new forwarding rules and logins from unusual locations
    • Registration of look-alike domains, so criminals can’t use them

    What is the single most effective control?

    The phone call. A two-minute call to a known number defeats almost every version of this scam. Write it into your payment procedure, and make it mandatory for every bank detail change, no matter who asks or how urgent it sounds.

    What should I do if I sent money to a scammer?

    Move fast. Recovery depends on hours.

    1. Call your bank at once and ask for a recall of the wire or a reversal of the transfer.
    2. File a complaint with the FBI at ic3.gov. Include the bank and account details of the recipient. The FBI can sometimes freeze funds when a report arrives soon after the transfer.
    3. Change the passwords on the affected email accounts, and check for forwarding rules.
    4. Notify your cyber insurer and your attorney.
    5. Tell the vendor or person who was impersonated.
    6. Keep the emails. Don’t delete evidence.

    Can I get the money back?

    Sometimes. The chance is best when you report within a day or two, before the money moves overseas. After that, recovery becomes unlikely. Speed is the reason every employee should know who to call.

    Does cyber insurance cover BEC?

    Some policies do, often under a “social engineering” or “funds transfer fraud” section with its own lower limit. Many require proof that you followed a verification procedure. Read your policy and ask your broker before you need it.

    How do I protect my customers from criminals posing as me?

    • Set up DMARC on your domain
    • Tell customers that you will never change bank details by email alone
    • Put that statement on your invoices
    • Give customers a phone number to verify any request

    How is BEC different from phishing?

    Phishing casts a wide net and aims to steal credentials or install malware. BEC targets one person in one business with a request for money. Phishing often comes first: a stolen email password gives the criminal the mailbox they use for the BEC attempt.

    How often should I train staff on BEC?

    Train everyone who touches money at hire and at least once a year, and send a reminder before busy periods such as year end and tax season. Include the owner. Criminals impersonate the owner because staff hesitate to question the boss.

    Your next step

    Write one rule into your payment process today: every change in bank details gets a phone call to a known number. Cerberus Cybersecurity can train your finance staff and document your payment controls through our cybersecurity training and policy development. Contact us to protect your business from invoice fraud.

  • What Is Multi-Factor Authentication? A Small Business Guide to MFA

    By J. Mesa

    If I could convince every business owner to do one thing this week, it would be to turn on multi-factor authentication. It costs little or nothing, it takes minutes, and it stops the attack I see most often: someone logging in with a stolen password.

    This guide explains what multi-factor authentication is, how the different types compare, and how to put it in place across a small business.

    What is multi-factor authentication?

    Multi-factor authentication (MFA) is a login method that asks for two or more proofs of identity. After you enter your password, you confirm it is you with a second step, such as a code from an app or a tap on your phone.

    The proofs come from different categories:

    • Something you know: a password or PIN
    • Something you have: a phone, an authenticator app, or a security key
    • Something you are: a fingerprint or your face

    A login counts as multi-factor when it uses at least two categories.

    What is the difference between MFA and 2FA?

    Two-factor authentication (2FA) is MFA with exactly two factors. Most people use the terms to mean the same thing. Two-step verification is a close cousin that some services use for the same idea.

    Why do I need MFA?

    Passwords leak. They leak through data breaches, phishing emails, and malware, and people reuse them across sites. An attacker who buys a list of leaked passwords can try them against your email in seconds.

    With MFA on, the password alone is not enough. The attacker also needs your phone or your security key. Microsoft has reported that MFA blocks the vast majority of automated account attacks.

    How does MFA work?

    1. You enter your username and password.
    2. The service asks for a second proof.
    3. You approve a prompt, enter a code, or touch a key.
    4. The service lets you in.

    Many services remember a trusted device, so you see the second step only on a new device or after a set period.

    What are the types of MFA?

    • Text message codes. The service sends a code to your phone number.
    • Authenticator apps. An app such as Microsoft Authenticator or Google Authenticator generates a code that changes every 30 seconds.
    • Push notifications. You approve a prompt on your phone, sometimes by matching a number shown on the login screen.
    • Hardware security keys. A small device, such as a YubiKey, that you plug in or tap.
    • Passkeys. A login stored on your device and unlocked with your fingerprint, your face, or a PIN.
    • Biometrics. A fingerprint or face scan, often used to unlock one of the methods above.

    Which type of MFA is the most secure?

    From strongest to weakest:

    1. Hardware security keys and passkeys. They check that you are on the real website, so a fake login page can’t capture them.
    2. Authenticator apps and push prompts with number matching.
    3. Text message and phone call codes. A criminal can intercept these by taking over your phone number, a fraud called SIM swapping.

    Any MFA is far better than a password alone. Use the strongest option each service offers, and don’t wait for the perfect one.

    Which accounts should I protect first?

    1. Email. Password resets for every other account go there.
    2. Banking and payroll.
    3. Remote access, such as a VPN or remote desktop.
    4. Administrator accounts for your computers, network, and cloud services.
    5. Cloud file storage.
    6. Your domain registrar and website.
    7. Social media.

    How do I set up MFA?

    1. Open the security or account settings of the service.
    2. Look for “two-step verification,” “two-factor authentication,” or “multi-factor authentication.”
    3. Choose an authenticator app or a security key when available.
    4. Scan the QR code with your app, or register your key.
    5. Save the backup codes somewhere safe, away from your computer.
    6. Add a second method, so one lost device does not lock you out.

    What if I lose my phone?

    Plan for it before it happens.

    • Keep the backup codes each service gives you
    • Register two methods, such as an app and a security key
    • Use an authenticator app that backs up its accounts
    • At work, name an administrator who can reset MFA for staff after confirming their identity

    Can MFA be bypassed?

    Yes, and it still stops most attacks. Know the tricks:

    • MFA fatigue. An attacker who has your password sends prompt after prompt, hoping you approve one to make it stop. Deny any prompt you did not start, and change that password.
    • Real-time phishing. A fake login page passes your password and code to the real site as you type them.
    • SIM swapping. A criminal moves your phone number to their SIM and receives your text codes.
    • Stolen session cookies. Malware copies the token that keeps you logged in.

    Number matching, security keys, and passkeys defeat the first three.

    How do I roll out MFA across my business?

    1. Start with email and administrator accounts.
    2. Tell staff what is coming and why.
    3. Give them a short guide with screenshots.
    4. Set a deadline, and help anyone who gets stuck.
    5. Turn on enforcement, so MFA is required and not optional.
    6. Check each month that new accounts have it.

    Microsoft 365 and Google Workspace both let an administrator require MFA for every user.

    How do I handle employees who resist?

    Explain the reason in plain terms: one stolen password could expose every customer. Show how little time it takes. Let people choose between an app and a security key. Offer a key to anyone who does not want to use a personal phone.

    Do insurers and regulations require MFA?

    More and more, yes. Cyber insurers ask about MFA on applications and may decline coverage without it. PCI-DSS requires it for access to card data environments. The FTC Safeguards Rule requires it for covered financial businesses. Clients often ask for it in security questionnaires.

    Does MFA cost money?

    The MFA features in Microsoft 365, Google Workspace, and most online services are included. Authenticator apps are free. Hardware keys cost a modest one-time amount per person. The time to set it up is the main cost.

    Your next step

    Turn on MFA for your own email account today, then set a date to require it for everyone in your business. Cerberus Cybersecurity helps small businesses roll out MFA and write the policy that goes with it, as part of our policy and documentation development. Contact us to get started.

  • Secure Our World: CISA’s 4 Steps to Stay Safe Online

    Secure Our World: CISA’s 4 Steps to Stay Safe Online

    By J. Mesa

    The Cybersecurity and Infrastructure Security Agency (CISA) is the US government’s lead agency for cyber defense. Its public campaign, Secure Our World, became the theme of Cybersecurity Awareness Month in 2023 and has carried through each October since.

    The campaign asks everyone to adopt four habits. They are simple and free, and together they block the most common attacks. This post explains each one and how to put it in place at home and at work.

    What is Secure Our World?

    Secure Our World is CISA’s cybersecurity awareness program for the public, small businesses, and families. It replaces a long list of advice with four actions:

    1. Use strong passwords and a password manager.
    2. Turn on multi-factor authentication.
    3. Recognize and report phishing.
    4. Update your software.

    CISA chose these four because most successful attacks exploit one of them. A weak password, a missing second step at login, a convincing email, or an old piece of software gives an attacker the way in.

    Step 1: How do I use strong passwords?

    A strong password is long, random, and unique to one account. CISA’s guidance sets the bar at 16 characters or more.

    Nobody can remember dozens of passwords like that, so use a password manager. It creates a strong password for each account, stores them, and fills them in for you. You remember one long passphrase that unlocks the manager.

    • Make the master passphrase four or more unrelated words.
    • Never reuse a password across accounts.
    • Change a password when a site reports a breach.

    Step 2: What is multi-factor authentication, and why turn it on?

    Multi-factor authentication (MFA) asks for a second proof that you are you. After your password, you approve a prompt in an app, enter a code, or touch a security key.

    MFA matters because passwords leak. With MFA on, a stolen password alone does not open the account.

    The options rank like this, from strongest to weakest:

    1. A physical security key or a passkey
    2. An authenticator app
    3. A code sent by text message

    Any of them beats a password alone. Turn MFA on first for email, banking, and social media, then for every account that offers it.

    Step 3: How do I recognize and report phishing?

    Phishing is a message built to trick you into clicking a link, opening a file, or giving up information. It arrives by email, text, phone call, or direct message.

    Look for these signs:

    • Pressure to act right now
    • A request for a password, a code, or a payment
    • A sender address that is close to a real one and slightly off
    • A link that goes somewhere other than what the text says
    • An attachment you did not expect

    When you spot one, don’t click and don’t reply. Report it with the “Report phishing” button in your email program, tell your IT contact at work, and then delete it. Reporting helps your email provider block the same message for other people.

    If a message claims to come from your bank or a vendor, contact them through a phone number or website you already trust.

    Step 4: Why do software updates matter?

    Software has flaws. Vendors fix them with updates. Attackers read those update notes too, and they build tools to attack anyone who has not installed the fix.

    • Turn on automatic updates for your computer, phone, and browser.
    • Update apps, routers, and smart devices as well.
    • Replace devices that no longer receive security updates.
    • Restart when an update asks you to. Many fixes don’t take effect until you do.

    How does this apply to a small business?

    The same four steps work for a company. They need a little structure.

    • Passwords. Give every employee a password manager and set a minimum length.
    • MFA. Require it for email, payroll, banking, and remote access.
    • Phishing. Train your team at least once a year and make reporting easy and blame-free.
    • Updates. Assign one person to check that devices and software are current each month.

    CISA also offers small businesses free resources, including guides and a vulnerability scanning service for internet-facing systems.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month takes place every October. The President and Congress first declared it in 2004, and CISA leads it with the National Cybersecurity Alliance. Schools, businesses, and agencies use the month to teach safe online habits.

    You don’t have to wait for October. The four steps work on any day of the year.

    Do these four steps stop every attack?

    No. They stop the common ones. A determined attacker has other methods, and businesses with sensitive data need more: backups, access controls, monitoring, and an incident response plan. The four steps are the floor. Build on them.

    Where can I learn more?

    CISA publishes tip sheets, videos, and a toolkit at cisa.gov/secure-our-world. The materials are free to share with your staff, your family, and your community.

    What mistakes do people make with these four steps?

    • Using a strong password twice. One breach then exposes both accounts.
    • Approving an MFA prompt they did not start. Attackers send repeated prompts and hope you tap “Approve” to make them stop. Deny any prompt you did not trigger, then change that password.
    • Trusting a message because it looks polished. Criminals copy logos and signatures. Judge the request, not the design.
    • Postponing the restart. An update that waits for a restart protects nothing.

    How long does it take to set up all four?

    Plan on an hour for one person. Install a password manager and move your most important accounts into it, which takes about 30 minutes. Turn on MFA for email and banking in 10 minutes. Switch on automatic updates in 5. Spend the rest learning where your email’s “Report phishing” button lives.

    Your next step

    Pick one of the four steps and do it today. Turning on MFA for your email takes five minutes and blocks the attack I see most often.

    If you want training for your team built around these habits, Cerberus Cybersecurity offers cybersecurity training for every audience, from the sales floor to the executive team. Contact us to set up a session.

  • Cybersecurity Awareness Month: What It Is and How to Take Part

    Cybersecurity Awareness Month: What It Is and How to Take Part

    By J. Mesa

    Every October, governments, schools, and businesses set aside time to talk about staying safe online. Cybersecurity Awareness Month is the reminder most of us need, because the habits that protect us are simple and easy to put off.

    This post explains what the month is, which threats deserve your attention, and how to use four weeks to make your home or business harder to attack.

    What is Cybersecurity Awareness Month?

    Cybersecurity Awareness Month is an annual campaign held each October in the United States. The President and Congress first declared it in 2004. The Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance lead it together.

    The goal is to give everyone practical steps to protect their accounts, devices, and data. Many other countries run similar campaigns in the same month.

    Why does it matter?

    Technology sits in the middle of daily life. You bank, shop, work, and talk to family through it. Criminals follow the money and the data, and they count on people being too busy to take precautions.

    An awareness month works because security depends on habits. One person who pauses before clicking a link can stop an attack that software missed.

    What are the biggest cyber threats right now?

    • Phishing. Fake emails, texts, and calls trick people into clicking malicious links, opening files, or sharing passwords.
    • Ransomware. Malware encrypts your files and holds them until you pay.
    • Data breaches. Attackers steal personal and financial records, which leads to identity theft and fraud.
    • Supply chain attacks. Attackers break into a supplier to reach that supplier’s customers.
    • Internet of Things weaknesses. Cameras, smart appliances, and industrial controls often ship with weak security and rarely receive updates.

    What can a cyberattack cost?

    • Money. Stolen funds, ransom payments, recovery fees, and lost sales add up fast.
    • Reputation. Customers leave a business that loses their data.
    • Essential services. Attacks on hospitals, utilities, and local government put public safety at risk.

    Island communities feel this more than most. When a single hospital, utility, or bank serves everyone, an outage reaches every household.

    What are the best practices to follow?

    1. Use strong, unique passwords. A password manager creates and stores them for you.
    2. Turn on multi-factor authentication. A second step at login blocks most attacks that use stolen passwords.
    3. Update your software. Install updates for your operating system, apps, and devices as soon as they arrive.
    4. Watch for phishing. Treat unexpected messages with suspicion, and verify requests through a channel you trust.
    5. Use security software. Keep antivirus and anti-malware protection running and current.
    6. Back up your data. Keep a copy offline or in a separate cloud account.
    7. Teach someone else. Share what you know with family, coworkers, and neighbors.

    How can I take part? A four-week plan

    Week 1: Passwords. Install a password manager. Replace your email and banking passwords with long, unique ones.

    Week 2: Multi-factor authentication. Turn it on for email, banking, social media, and any account that holds payment details.

    Week 3: Phishing. Learn the warning signs. Find the “Report phishing” button in your email and use it. Talk with older relatives about scam calls and texts.

    Week 4: Updates and backups. Turn on automatic updates on every device. Run a backup and test that you can restore a file.

    By the end of the month you have closed the four doors attackers use most.

    How can a business take part?

    • Send a short weekly tip to all staff.
    • Run a 30-minute lunch session on phishing with real examples.
    • Send a simulated phishing email and use the results to teach, never to punish.
    • Review who has access to what, and remove accounts for people who have left.
    • Check that your backups work.
    • Recognize employees who report suspicious messages.

    Keep it positive. People report problems when they feel safe doing so.

    How can I teach kids and older relatives?

    • Keep the rules short: don’t share passwords, don’t click links from strangers, ask before you download.
    • Set up their devices with automatic updates and a password manager.
    • Agree on a family rule: any request for money or gift cards gets a phone call to confirm.
    • For our Manåmko’, practice hanging up on a caller who creates pressure, and calling back on a known number.

    Is cybersecurity only an IT problem?

    No. Cybersecurity is a shared responsibility. IT staff install the tools. Every person who uses a computer decides whether to click, whether to reuse a password, and whether to report something strange. Attackers aim at people because people are easier to fool than software.

    What happens after October?

    The risk does not stop on November 1. Pick two habits from the month and make them permanent:

    • A monthly ten-minute check that updates and backups ran
    • A yearly training session for everyone in the business

    What should I do if I think I have been scammed?

    Act fast. Speed limits the damage.

    1. Change the password on the affected account, and on any account that shares it.
    2. Call your bank or card company if you sent money or shared payment details.
    3. Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and to the Federal Trade Commission at reportfraud.ftc.gov.
    4. At work, tell your manager or IT contact right away. A fast report gives them time to contain the problem.

    Do not feel embarrassed. Scammers fool careful people every day, and a quick report protects the next person.

    Is cybersecurity training worth the time?

    Yes. Most attacks need a person to click, reply, or pay. Training teaches people to pause at that moment. Short sessions repeated through the year work better than one long session, because the reminders arrive before the habit fades.

    Your next step

    Use this October to build your skills. Cerberus Cybersecurity runs cybersecurity training and workshops that cover current threats and the habits that stop them. Contact us to schedule a session for your team. When you understand the risks and practice the basics, you help build a safer digital world for your whole community.

  • SPF, DKIM, and DMARC Explained: How to Stop Email Spoofing of Your Domain

    By J. Mesa

    Anyone can send an email that claims to come from your business address. The original design of email never checked. Criminals use that gap to send fake invoices to your customers in your name. Three DNS records close it: SPF, DKIM, and DMARC. Since February 2024, Google and Yahoo have required them from bulk senders, and mail from domains without them lands in spam more often each month.

    What is email spoofing?

    Email spoofing is forging the “From” address of a message so that it appears to come from someone else. A spoofed message from your domain needs no access to your mailbox. The sender simply types your address into the From line.

    What is SPF?

    SPF, or Sender Policy Framework, is a DNS record that lists the servers allowed to send email for your domain. When a message arrives, the receiving server checks whether it came from a server on your list.

    An SPF record for a business that sends through Microsoft 365 looks like this:

    v=spf1 include:spf.protection.outlook.com -all

    The ending matters. “-all” tells receivers to reject senders that are not listed. “~all” tells them to treat such mail as suspicious. A domain can have only one SPF record, and that record may trigger no more than ten DNS lookups, so adding every service you have ever tried will break it.

    What is DKIM?

    DKIM, or DomainKeys Identified Mail, adds a digital signature to each message you send. Your mail system signs the message with a private key. You publish the matching public key in DNS. The receiving server uses it to confirm that the message came from your domain and that nobody altered it on the way.

    DKIM survives forwarding better than SPF does, which is one reason you need both.

    What is DMARC?

    DMARC, or Domain-based Message Authentication, Reporting, and Conformance, ties the other two together. It does three jobs.

    • Alignment. It checks that the domain in the visible From address matches the domain that passed SPF or DKIM. Without this check, a criminal could pass SPF with their own domain while showing yours to the reader.
    • Policy. It tells receiving servers what to do with mail that fails: nothing, quarantine it, or reject it.
    • Reporting. It asks receivers to send you reports of who is sending mail in your domain’s name.

    A starting DMARC record looks like this:

    v=DMARC1; p=none; rua=mailto:[email protected]

    What do the DMARC policies mean?

    • p=none. Monitor only. Receivers deliver failing mail as usual and send you reports. This protects nobody, and it is the right place to begin.
    • p=quarantine. Receivers send failing mail to the spam folder.
    • p=reject. Receivers refuse failing mail outright. This is the goal.

    What do Google and Yahoo require?

    Since February 2024:

    • All senders to Gmail and Yahoo addresses need SPF or DKIM.
    • Bulk senders, which Google defines as those sending about 5,000 or more messages a day to Gmail accounts, need SPF, DKIM, and a DMARC record with a policy of at least p=none. Marketing messages need a one-click unsubscribe, and spam complaint rates must stay low.

    A small business sending a few hundred messages a day is not a bulk sender. The direction is still clear. Unauthenticated mail is getting filtered, and your invoices and appointment reminders are not exempt.

    How do I set up SPF, DKIM, and DMARC?

    1. List every system that sends email as your domain. Your mail provider, your website’s contact form, your invoicing or accounting software, your newsletter service, your scheduling tool, your CRM, the office copier that scans to email.
    2. Publish one SPF record that includes each legitimate sender.
    3. Turn on DKIM in each sending service. Each one gives you DNS records to add. In Microsoft 365 and Google Workspace, DKIM for your own domain is off until you enable it.
    4. Publish a DMARC record at p=none with a reporting address.
    5. Read the reports for two to four weeks. They arrive as data files that are hard to read by hand. A DMARC reporting service, several of which offer free tiers, turns them into a chart of who is sending as you.
    6. Fix what you find. Add the legitimate senders you forgot. Note the ones you do not recognize.
    7. Move to p=quarantine, then watch for a few more weeks.
    8. Move to p=reject.

    You make these changes wherever your DNS is hosted: your domain registrar, your web host, or a DNS provider.

    How do I check my domain?

    Free lookup tools from MXToolbox, dmarcian, and others show your current records. You can also send a message to a Gmail account, open it, and choose “Show original.” Gmail displays a pass or fail result for SPF, DKIM, and DMARC.

    What are the common mistakes?

    • Staying at p=none forever. Monitoring mode stops no spoofed mail. Many businesses publish the record to satisfy a checklist and never move on.
    • Two SPF records. That counts as an error, and SPF fails.
    • Too many lookups in the SPF record.
    • Ending SPF with “+all,” which authorizes the entire internet.
    • Forgetting a sender. The invoicing system gets left out, and customer invoices go to spam once enforcement begins.
    • Skipping DKIM on third-party services.
    • Jumping to p=reject without reading the reports first.
    • Ignoring domains you own and do not use for email. Criminals spoof those too. Publish “v=spf1 -all” and a DMARC record of p=reject on each parked domain.

    Does DMARC stop all phishing?

    No. DMARC stops exact spoofing of your domain. It does not stop:

    • Look-alike domains, such as a version of your name with one letter changed
    • Display name tricks, where the name shows your boss and the address belongs to a free mail account
    • A hacked mailbox, which sends real, authenticated mail. See how to tell if your email has been hacked.

    You still need mail filtering, multi-factor authentication, a payment verification procedure, and trained staff who can spot a phishing email.

    Why should a small business bother?

    • Protection for your customers and vendors. A fake invoice from your address damages your name even though you did nothing.
    • Deliverability. Authenticated mail reaches the inbox more reliably.
    • Compliance and insurance. PCI DSS version 4 calls for anti-phishing controls, and insurance applications ask about email authentication.
    • Visibility. The reports show you every service sending mail as your company, including ones nobody remembers setting up.

    How long does it take?

    The DNS changes take an hour. Reaching p=reject safely takes four to eight weeks for most small businesses, because you need time to see all your legitimate senders in the reports.

    What comes after DMARC?

    Two optional additions. MTA-STS tells other servers to deliver mail to you only over an encrypted connection. BIMI displays your logo next to authenticated messages in some inboxes and requires a DMARC policy of quarantine or reject first. Both help. Neither matters until the first three records are in place and enforced.

    Your next step

    Look up your domain’s DMARC record today. If you find none, or you find p=none with no plan to move forward, start with step 1 above. Cerberus Cybersecurity checks email authentication as part of our risk and compliance assessments and guides small businesses to an enforced policy without losing legitimate mail. Contact us to get started.

  • How to Tell If Your Email Has Been Hacked, and What to Do About It

    By J. Mesa

    A customer calls to ask why you sent a strange link. A password reset arrives for an account you did not touch. Messages you never read show up as opened. Any one of these can mean a stranger is inside your email. Act the same day, because your mailbox is the master key: nearly every other account you own sends its password reset there.

    How do I know if my email has been hacked?

    Watch for these signs.

    • Contacts report messages from you that you did not send.
    • Your Sent folder holds messages you did not write, or the folder has been emptied.
    • You stop receiving mail you expect, such as replies from a customer or bank notices.
    • Password reset emails arrive for other accounts.
    • Your password no longer works.
    • You receive sign-in alerts from places you have never been.
    • You get multi-factor prompts you did not start.
    • Your recovery phone number or backup email address has changed.
    • You find rules or forwarding settings you did not create.
    • Unread messages appear as read, or mail turns up in odd folders.

    How do email accounts get hacked?

    • Phishing. You typed your password into a fake sign-in page. See our guide to spotting a phishing email.
    • Reused passwords. A breach at another website exposed a password you also use for email. Attackers test those in bulk, an attack called credential stuffing.
    • Malware. An information-stealing program on your computer copied saved passwords and browser sessions.
    • Session theft. A phishing page relayed your sign-in to the real site and captured the session token, which works even on accounts with basic multi-factor authentication.
    • Malicious app permission. You approved an app that asked to read your mail.
    • Weak or guessable passwords.
    • A sign-in on a shared or infected computer.

    What do hackers do with a hacked email account?

    • Reset your other passwords. Banking, shopping, payroll, and social media all send reset links to email.
    • Read your history. Old messages hold tax documents, ID scans, contracts, and invoices.
    • Watch quietly. In a business account, an attacker may read mail for weeks to learn who pays whom and when.
    • Redirect payments. The attacker replies inside a real email thread and tells your customer that your bank details have changed.
    • Phish your contacts. A message from your real address gets opened and trusted.
    • Hide the evidence. Inbox rules move replies and security alerts out of sight.

    What should I do first?

    Work from a device you trust. If you suspect malware on your computer, use a different one or your phone.

    1. Change the password to a long one you have never used anywhere.
    2. Sign out of all sessions. In Gmail, open your Google Account, then Security, then “Your devices.” In a Microsoft account, use “Sign out everywhere.” This ejects anyone already inside.
    3. Turn on multi-factor authentication, or reset it if it was already on. Remove any phone number, authenticator, or security key you do not recognize.
    4. Check your recovery options. Confirm that the backup email address and phone number are yours.
    5. Remove forwarding and rules. See the next section.
    6. Review connected apps and remove any you do not recognize or no longer use.
    7. Scan your computer for malware before you sign in from it again.

    How do I find hidden forwarding rules?

    Attackers count on you skipping this step. A rule they created keeps working after you change the password.

    • Gmail. Open Settings, then “See all settings.” Check “Forwarding and POP/IMAP” for a forwarding address, “Filters and Blocked Addresses” for filters you did not make, and “Accounts and Import” for unknown “Send mail as” addresses or delegates.
    • Outlook and Microsoft 365. Open Settings, then Mail. Check “Rules” and “Forwarding.” Look for rules that move messages to RSS Feeds, Conversation History, or Deleted Items, or that mark mail as read. Rules that match words such as “invoice,” “payment,” or “wire” are a strong sign of payment fraud in progress.
    • Yahoo and others. Look under mail settings for filters, forwarding, and connected accounts.

    Check your signature and your automatic reply as well. Attackers sometimes plant a link or a phone number there.

    What should I do after I regain control?

    1. Change the passwords on your important accounts, starting with banking, payroll, and anything that uses the same password. Check each for changes to contact details.
    2. Warn your contacts. Tell them to ignore recent messages and not to act on any payment instructions.
    3. Read your Sent and Deleted folders to see what the attacker sent and to whom.
    4. Check what your mailbox held. If it contained Social Security numbers, tax forms, or financial statements, freeze your credit.
    5. Watch your accounts closely for the next few months.

    What if I am locked out?

    Use the provider’s official recovery process: Google’s account recovery page, Microsoft’s recovery form, or the equivalent for your provider. Answer from a device and a location you have used with that account before, which improves your odds. Recovery can take days.

    Never pay a “recovery service” you found through a search or a social media comment. Those are scams that target people who are already locked out. The provider does not charge for recovery.

    What if it is a business email account?

    A hacked work mailbox is a security incident for the whole company. Bring in your IT provider at once, and add these steps.

    1. Reset the password and revoke all sessions from the admin console.
    2. Review sign-in logs for the account and for other accounts from the same addresses.
    3. Search the audit log to learn which messages the attacker opened and sent.
    4. Check every other mailbox for the same malicious rules.
    5. Call your bank if invoices, wires, or payroll were discussed in the mailbox. Call customers and vendors by phone to confirm that no payment instructions have changed.
    6. Call your cyber insurance carrier and your attorney. A mailbox that held customer, patient, or employee data can trigger breach notification laws.
    7. Preserve the evidence. Do not delete the account or its logs.

    Our guide to securing Microsoft 365 lists the settings that prevent most of these takeovers.

    How do I prevent the next one?

    • Use a unique, long password for email, stored in a password manager.
    • Use strong multi-factor authentication. An authenticator app or a security key beats text message codes.
    • Never approve a sign-in prompt you did not start.
    • Keep your devices updated and avoid pirated software, a common source of password-stealing malware.
    • Review your account security page twice a year: devices, recovery options, connected apps, and rules.
    • Avoid signing in on shared computers.
    • Reach your mail by typing the address or using a bookmark, not through a link in a message.

    Should I just create a new email address?

    Rarely. Once you remove the attacker and secure the account, the old address is safe to keep. Abandoning it creates new risks: other accounts still send resets there, and some providers recycle unused addresses. Clean it and lock it down.

    Your next step

    Open your email settings now and check two things: the forwarding address and the list of rules. It takes two minutes, and it is the check most people have never made. For help securing business email and training your team, see our cybersecurity training and services, or contact Cerberus Cybersecurity.

  • How to Secure Microsoft 365 for a Small Business: 12 Settings to Change

    By J. Mesa

    Most small businesses run on Microsoft 365. Email, calendars, files, and Teams all sit behind one sign-in. Criminals know that, so a Microsoft 365 account is the most common target in business email compromise. Microsoft supplies strong protections with most plans, and many of them stay switched off until someone turns them on. Work through this list with whoever manages your tenant.

    Is Microsoft 365 secure by default?

    Partly. Microsoft secures its data centers and the service. You are responsible for how your accounts are set up: who can sign in, how they prove who they are, and what they can share. Microsoft calls this the shared responsibility model. A tenant left on its original settings from years ago has gaps that attackers use every day.

    What are the most important Microsoft 365 security settings?

    1. Require multi-factor authentication for everyone. This single setting blocks the large majority of account takeovers. No exceptions for the owner. If your tenant has no custom policies, turn on Security Defaults in the Microsoft Entra admin center. It requires all users to register for multi-factor authentication and costs nothing.
    1. Protect administrator accounts. Give each administrator a separate account used only for admin work, with no mailbox and no daily use. Keep the number of Global Administrators between two and four. Require the strongest sign-in method you have on those accounts.
    1. Block legacy authentication. Old protocols such as POP, IMAP, and basic SMTP authentication can’t perform multi-factor authentication, so attackers use them to get around it. Security Defaults blocks them. Confirm that no old copier, scanner, or app still depends on them, and replace what does.
    1. Use the authenticator app with number matching. Text message codes are better than nothing, and they can be intercepted. The Microsoft Authenticator app with number matching resists the “approve this prompt” trick.
    1. Turn on the email protections. In the Microsoft Defender portal, apply the Standard preset security policy. It sets anti-phishing, anti-spam, and anti-malware protection to Microsoft’s recommended levels. With Business Premium or Defender for Office 365, it also enables Safe Links and Safe Attachments, which check links and files when a user opens them.
    1. Turn on impersonation protection. List your owners, executives, and finance staff as protected users, and your own domain as a protected domain. The filter then flags mail that poses as them.
    1. Tag external email. Enable the external sender tag in Outlook, so staff can see when a message “from the boss” came from outside the company.
    1. Block automatic forwarding to outside addresses. After taking over a mailbox, an attacker often creates a rule that forwards a copy of every message to an outside account. Disable external auto-forwarding in the outbound spam policy.
    1. Confirm that auditing is on. The unified audit log records sign-ins, mailbox access, rule changes, and file activity. You need it to investigate an incident. Verify it is enabled in the Microsoft Purview portal, and know how long your plan retains it.
    1. Tighten sharing. In the SharePoint admin center, change the default sharing link from “Anyone with the link” to “Specific people.” Set guest links to expire. Review which sites allow outside sharing at all.
    1. Stop users from approving apps. Attackers trick users into granting a malicious app permission to read their mail, which survives a password change. In Entra, restrict user consent so that an administrator must approve new apps.
    1. Publish SPF, DKIM, and DMARC for your domain. These DNS records stop others from sending mail that claims to come from your address. Google and Yahoo began requiring them from bulk senders in February of this year.

    Which Microsoft 365 plan should a small business buy?

    For most businesses under 300 users, Business Premium gives the best security value. Compared with Business Standard, it adds:

    • Conditional Access, which lets you set sign-in rules by user, location, and device
    • Defender for Office 365, with Safe Links and Safe Attachments
    • Defender for Business, an endpoint detection and response tool for your computers
    • Intune, to manage and wipe laptops and phones
    • Information protection, to label and encrypt sensitive files

    Bought separately, those tools cost far more than the price difference between the plans.

    What is Conditional Access?

    Conditional Access is a rules engine for sign-ins. Each rule says: when this kind of user signs in to this app under these conditions, require this. Useful starting rules:

    • Require multi-factor authentication for all users
    • Require stronger authentication for administrators
    • Block legacy authentication
    • Block sign-ins from countries where you have no staff
    • Require a managed, compliant device to reach company data

    Before you enforce any rule, create one emergency “break glass” administrator account with a long random password stored in a safe, and exclude it from the policies. It keeps you from locking yourself out.

    How do I check my Microsoft 365 security?

    Open Microsoft Secure Score in the Defender portal. It grades your tenant against Microsoft’s recommendations and lists each improvement with instructions. Treat the score as a to-do list. Work from the top, and check it each quarter.

    How do I know whether a mailbox has been hacked?

    Look for these signs:

    • Inbox rules the user did not create, often ones that move mail to the RSS Feeds or Conversation History folder or mark it as read
    • Forwarding to an unknown outside address
    • Sign-ins from unfamiliar cities or countries in the sign-in log
    • Sent messages the user did not write
    • Contacts reporting strange emails from the user
    • Multi-factor prompts the user did not start
    • A new authentication method or device registered on the account

    What should I do if an account is compromised?

    1. Reset the password.
    2. Revoke all active sessions, so stolen tokens stop working.
    3. Review and remove unknown multi-factor methods and devices.
    4. Delete suspicious inbox rules and forwarding.
    5. Review app consents and remove any the user does not recognize.
    6. Search the audit log to learn what the attacker read and sent.
    7. Warn the contacts who received messages, and your bank if invoices or payments were discussed.
    8. Ask your attorney whether the mailbox held data that triggers a notification duty.

    Do I need to back up Microsoft 365?

    Yes. Microsoft keeps the service running. Retention settings and the recycle bin cover short-term mistakes. They do not protect against a deletion nobody notices for months, a malicious insider, or ransomware that syncs encrypted files. A third-party backup for Exchange, OneDrive, and SharePoint costs a few dollars per user each month.

    What mistakes do small businesses make?

    • Exempting the owner from multi-factor authentication
    • Using a Global Administrator account for daily email
    • Leaving former employees’ accounts active and licensed
    • Sharing one mailbox password among several people in place of a shared mailbox
    • Leaving “Anyone” sharing links as the default
    • Ignoring Secure Score
    • Assuming the IT provider configured everything, with nothing in writing

    How does this apply to Google Workspace?

    The same principles hold: enforce two-step verification for all users, protect administrator accounts, turn on the advanced phishing and malware settings, restrict third-party app access, limit external sharing, and publish SPF, DKIM, and DMARC.

    Your next step

    Sign in to the admin center today and answer one question: does every account, including the owner’s, require multi-factor authentication? Then open Secure Score. Cerberus Cybersecurity reviews Microsoft 365 configurations as part of our risk and compliance assessments and writes the access policies behind them. Contact us for a review, or see our training to prepare your staff.

  • Antivirus vs. EDR: What Is the Difference, and Which Does Your Business Need?

    By J. Mesa

    Your cyber insurance renewal form asks whether you run EDR on all endpoints. You run antivirus. Are those the same thing? They are not, and the gap between them explains why businesses with up-to-date antivirus still get hit by ransomware.

    What is antivirus?

    Antivirus is software that scans files and programs for known malicious code and blocks or removes what it finds. Traditional antivirus works from signatures. A signature is a fingerprint of a known piece of malware. The vendor updates the list, and the software compares each file against it.

    Modern products, often sold as next-generation antivirus, add machine learning and behavior checks that catch some malware nobody has seen before.

    What is EDR?

    EDR stands for endpoint detection and response. An endpoint is any device that connects to your network: a laptop, a desktop, a server. EDR software records what happens on each endpoint, looks for suspicious behavior, alerts you, and gives you tools to investigate and contain an attack.

    Think of antivirus as a lock that keeps known burglars out. EDR is a camera system with a guard: it watches what happens inside, notices someone acting wrong, and lets you lock the room they are in.

    What is the difference between antivirus and EDR?

    • What it looks for. Antivirus looks for bad files. EDR looks for bad behavior.
    • When it acts. Antivirus acts at the moment a file arrives or runs. EDR keeps watching after that moment.
    • What it records. Antivirus logs a detection. EDR records processes, network connections, logins, and changes, so you can trace how an attack unfolded.
    • How you respond. Antivirus quarantines a file. EDR lets you isolate a computer from the network, stop a process, and in some products roll back changes.
    • Who it needs. Antivirus runs with little attention. EDR produces alerts that a trained person must review.

    Why is antivirus no longer enough?

    Attackers changed their methods.

    • Stolen logins. Many break-ins use a real username and password. No malicious file exists for antivirus to catch.
    • Living off the land. Attackers use tools already built into Windows, such as PowerShell and remote administration utilities. To antivirus, those look like normal programs.
    • Fileless attacks. Malicious code runs in memory and never touches the disk.
    • Custom malware. Criminals alter their code for each victim, so no signature matches.
    • Hands-on attacks. In a modern ransomware case, a person works inside the network for days: stealing data, finding backups, and disabling security tools before the encryption starts. Each step is a chance to catch them, and antivirus sees few of those steps.

    EDR is built to notice that chain. A word processor that launches a command prompt, which downloads a tool, which starts copying password data, tells a story no single file reveals.

    What is MDR?

    MDR stands for managed detection and response. It is EDR software plus a team of security analysts who watch the alerts for you around the clock, investigate, and act.

    For a small business this matters more than the software. EDR raises an alert at 2 a.m. on a Saturday. Someone has to see it, decide whether it is real, and isolate the machine before the attack spreads. Few small businesses have that person. An MDR provider does.

    What is XDR?

    XDR, or extended detection and response, widens the view beyond endpoints to include email, identity systems, cloud services, and the network. It connects events across those sources. An XDR tool might link a suspicious sign-in to your email with odd activity on a laptop an hour later. Many EDR vendors now sell XDR as the next tier up.

    Does my small business need EDR?

    In most cases, yes. Choose EDR or MDR if any of these apply:

    • You hold sensitive data: patient records, financial records, card data, or client files
    • A regulation such as HIPAA, PCI DSS, or the FTC Safeguards Rule covers you
    • You are applying for or renewing cyber insurance
    • You run servers or have staff working remotely
    • Downtime of a few days would threaten the business

    A very small office with a few computers, everything in the cloud, and no regulated data can start with the protection built into Windows, turned on and kept current, alongside multi-factor authentication and backups. Revisit that choice each year.

    Do cyber insurers require EDR?

    Many now do. Applications ask whether EDR runs on all workstations and servers, and some carriers decline or surcharge businesses without it. Answer accurately. If the form says EDR covers every endpoint and a claim investigation finds half your machines unprotected, the insurer has grounds to contest the claim.

    How much does EDR cost?

    Prices vary by vendor and volume. Rough ranges for a small business:

    • Business antivirus: $3 to $6 per device per month
    • EDR software: $5 to $15 per device per month
    • MDR, with monitoring included: $10 to $30 per device per month

    Many managed IT providers bundle EDR or MDR into their monthly fee. Ask yours what you have today.

    Is Microsoft Defender good enough?

    Be precise about which Defender. The name covers several products.

    • Microsoft Defender Antivirus comes free with Windows 10 and 11. It is a solid antivirus. It is not EDR.
    • Microsoft Defender for Business adds EDR features for companies with up to 300 users. It is included in Microsoft 365 Business Premium and sold on its own.
    • Microsoft Defender for Endpoint is the enterprise product.

    If you already pay for Business Premium, you own an EDR tool. Someone still has to deploy it to every device and watch its alerts.

    How do I choose an EDR or MDR product?

    Ask these questions.

    1. Who watches the alerts, and during what hours?
    2. What actions will the provider take without calling me first, and which ones need my approval?
    3. How fast do they respond to a serious alert?
    4. Does the product cover Windows, Mac, and servers?
    5. Can it isolate a device and roll back ransomware changes?
    6. How does it perform in independent tests, such as the MITRE ATT&CK evaluations?
    7. Can someone with administrator rights on a computer turn it off? Good products resist tampering.
    8. What reports will I receive, and can I show them to my insurer or an auditor?
    9. Does it work with my IT provider’s tools?

    Can I run antivirus and EDR together?

    Most EDR products include their own antivirus component and replace the old one. Running two antivirus engines side by side causes slowdowns and conflicts. Follow the vendor’s guidance, and remove the old product fully before installing the new one.

    Does EDR replace my other protections?

    No. EDR detects and limits an attack in progress. You still need the controls that prevent one and the ones that let you recover:

    • Multi-factor authentication
    • Prompt software updates
    • Tested, offline backups
    • Email filtering
    • Limited administrator rights
    • Staff training, since many attacks start with a phishing email

    What are the common mistakes?

    • Installing EDR on workstations and skipping the servers, where the valuable data lives
    • Leaving a few “problem” computers unprotected
    • Sending alerts to an inbox nobody reads
    • Running the product in alert-only mode, so it reports attacks and blocks nothing
    • Assuming the IT provider monitors alerts without confirming it in writing
    • Buying the tool and never testing whether anyone responds

    Your next step

    Ask your IT provider three questions this week: which endpoint protection do we run, is it on every computer and server, and who responds to an alert at night? Cerberus Cybersecurity reviews endpoint protection as part of our risk and compliance assessments and helps you answer insurance applications with evidence. Contact us to schedule a review.

  • How to Freeze Your Credit: A Step-by-Step Guide

    By J. Mesa

    Data Privacy Week arrives at the end of January. Mark it with one action that takes fifteen minutes and costs nothing: freeze your credit. After years of large breaches, assume your Social Security number and date of birth are already for sale. A freeze makes that stolen information far less useful to a thief.

    What is a credit freeze?

    A credit freeze, also called a security freeze, blocks lenders from viewing your credit report. Lenders check that report before they approve a new account. With the report locked, a criminal who applies for a loan or a credit card in your name gets declined.

    Is a credit freeze free?

    Yes. Federal law has required the three national credit bureaus to place and lift freezes for free since September 2018. Do not pay anyone for one.

    Does a credit freeze hurt my credit score?

    No. A freeze has no effect on your score. You can keep using your existing cards and loans as usual. Your current lenders can still see your report, and you can still pull your own.

    How do I freeze my credit?

    You must contact each of the three bureaus separately. A freeze at one does not carry over to the others.

    1. Equifax. Go to equifax.com and look for “Security Freeze,” or call 1-800-685-1111.
    2. Experian. Go to experian.com/freeze, or call 1-888-397-3742.
    3. TransUnion. Go to transunion.com/credit-freeze, or call 1-888-909-8872.

    At each one:

    • Create an account with your name, address, date of birth, and Social Security number.
    • Answer the identity questions.
    • Choose the free freeze. The sites promote paid “lock” and monitoring products along the way. You can skip them.
    • Save the login or the PIN in your password manager. You will need it to lift the freeze.

    By law, a freeze requested online or by phone takes effect within one business day.

    Type the bureau addresses into your browser yourself. Search results and emails sometimes lead to look-alike sites built to steal the same details you are trying to protect.

    Should I freeze my credit at other agencies?

    For fuller coverage, add these:

    • Innovis, a fourth credit bureau, at innovis.com.
    • ChexSystems, which banks check before opening a checking or savings account, at chexsystems.com.
    • NCTUE, which phone, cable, and utility companies use, at nctue.com.

    How do I lift a credit freeze?

    When you apply for a mortgage, a car loan, a new credit card, or an apartment, lift the freeze first. Sign in to the bureau’s site and choose a temporary lift, sometimes called a thaw, for a set number of days. Online and phone requests take effect within one hour.

    Ask the lender or landlord which bureau they use, and lift only that one. The freeze returns on its own when the period ends.

    What is the difference between a freeze, a lock, and a fraud alert?

    • Credit freeze. Free, set by federal law, and blocks new creditors until you lift it.
    • Credit lock. A product the bureaus sell or bundle with their apps. It works much like a freeze with a quicker on-and-off switch, but it is governed by the company’s terms and not by the freeze law, and it may carry a monthly fee.
    • Fraud alert. A note on your report that tells lenders to verify your identity before opening an account. It is free, lasts one year, and you only need to request it from one bureau, which notifies the other two. Victims of identity theft can get an extended alert that lasts seven years.

    A freeze gives the strongest protection. A fraud alert asks lenders to be careful. A freeze stops them from seeing the report at all.

    Who should freeze their credit?

    Nearly every adult. If you do not plan to apply for credit in the next few weeks, a freeze costs you nothing and removes a major risk. It matters most if:

    • You received a breach notification letter
    • You lost your wallet or your Social Security card
    • You saw accounts or inquiries you do not recognize
    • You are older and rarely apply for new credit

    Should I freeze my child’s credit?

    Yes. Children make attractive targets, because nobody checks a child’s credit for years. A thief can use a child’s Social Security number until the child turns 18 and applies for a student loan. Parents and guardians can freeze the credit of a child under 16 for free. The process requires mailing copies of documents, such as a birth certificate and your own ID, to each bureau. You can do the same for an adult you hold a power of attorney for.

    What does a credit freeze not protect against?

    A freeze stops new credit accounts. It does not stop:

    • Fraud on the cards and bank accounts you already have
    • Tax refund fraud
    • Medical identity theft
    • Fraudulent unemployment or benefits claims
    • Phishing and account takeover

    So add these steps:

    • Check your credit reports. You can get free reports from all three bureaus at annualcreditreport.com, the only site authorized by federal law.
    • Get an IRS Identity Protection PIN. This six-digit number stops someone else from filing a tax return with your Social Security number. Since 2021, any taxpayer who can verify their identity may request one at IRS.gov. See our post on tax scam season.
    • Turn on transaction alerts for your bank and card accounts.
    • Use unique passwords and multi-factor authentication on financial accounts and email.
    • Create your own accounts first. Set up your online accounts at ssa.gov, IRS.gov, and the Postal Service’s Informed Delivery before a criminal claims them in your name.

    Do I need to pay for credit monitoring or identity theft protection?

    Monitoring tells you after something happens. A freeze prevents the most damaging kind of fraud before it happens, for free. If a breached company offers you free monitoring, accept it. Paying for a service is a personal choice. Some people value the insurance and the recovery help. No service prevents identity theft, whatever the advertisement says.

    What should I do if someone already opened an account in my name?

    1. Go to IdentityTheft.gov, the FTC’s recovery site. It builds a step-by-step plan and generates an identity theft report.
    2. Call the fraud department of the company where the account was opened. Ask them to close it and send written confirmation.
    3. Freeze your credit at all three bureaus and place a fraud alert.
    4. Dispute the fraudulent entries with each bureau, using the FTC report.
    5. File a police report if a creditor asks for one.
    6. Keep notes of every call: date, name, and what was said.

    Why should a business owner care?

    Your personal credit often backs your business. Many owners personally guarantee loans, leases, and business credit cards, so identity theft against you can damage the company’s ability to borrow. Criminals also commit business identity theft, filing false paperwork with a state agency or opening credit lines in a company’s name.

    • Freeze your personal credit.
    • Check your business credit reports with Dun and Bradstreet, Experian, and Equifax.
    • Sign up for email alerts from your Secretary of State, where the state offers them, so you learn when someone changes your business filing.
    • Share this guide with employees. Staff who suffer identity theft lose work time and focus, and a company that holds their Social Security numbers has a duty to protect them.

    Your next step

    Set aside fifteen minutes tonight and freeze your credit at Equifax, Experian, and TransUnion. Save the three logins in your password manager. If your business holds Social Security numbers for employees or customers, Cerberus Cybersecurity can assess how you protect them. See our services or contact us.