Category: Recommendations

  • Gift Card Scams: Why Scammers Ask for Gift Cards and How to Stop Them

    By J. Mesa

    Your boss emails you. She is stuck in a meeting and needs five $100 gift cards for client gifts. Buy them now, scratch off the backs, and send photos of the codes. You will be reimbursed today. The email came from a stranger, and the money is gone the moment you hit send. December brings a surge of these requests, because buying gift cards looks normal this month.

    What is a gift card scam?

    A gift card scam is a fraud in which a criminal persuades you to buy gift cards and hand over the numbers and PINs. With those numbers, the criminal spends or resells the balance within minutes.

    One rule covers every version: gift cards are for gifts. Anyone who demands payment by gift card is a scammer. No government agency, utility, court, bank, or tech company accepts them.

    Why do scammers want gift cards?

    • Speed. The value moves the instant you read out the numbers.
    • Anonymity. Nobody needs an ID or a bank account to redeem a card.
    • No reversal. A gift card lacks the dispute rights of a credit card.
    • Availability. Every grocery store and pharmacy sells them.

    Criminals turn the balances into cash by buying electronics to resell or by selling the codes at a discount on online marketplaces.

    What are the common gift card scams?

    • The fake boss. An email or text that appears to come from an owner, a manager, a pastor, or a principal asks an employee to buy cards for clients or staff and keep it quiet.
    • Government impersonators. A caller claims to be from the IRS, Social Security, or a court and threatens arrest unless you pay a fine with gift cards.
    • Tech support. A pop-up or a caller says your computer is infected and takes payment for the “repair” in gift cards.
    • Utility shutoff. A caller says your power goes off in an hour unless you pay now.
    • Family emergency. A caller posing as a grandchild or a lawyer needs bail money.
    • Romance. An online sweetheart you have never met needs help with an emergency.
    • Prizes and sweepstakes. You won, and you owe “taxes” or “fees” first.
    • Overpayment. A buyer sends a check for too much and asks for the difference back in gift cards. The check bounces later.

    How does the fake boss gift card scam work?

    This version targets businesses, schools, churches, and nonprofits.

    1. The scammer finds the name of the owner or director on your website, and a list of staff.
    2. The scammer creates a free email account with the boss’s name as the display name, or sends a text from an unknown number that opens with “Hi, this is [boss’s name].”
    3. The first message is short: “Are you at your desk? I need a quick favor.”
    4. Once the employee answers, the request arrives: buy gift cards, keep it confidential, send the codes.
    5. The scammer asks for more cards until the employee stops.

    It works because employees want to help the boss and because the boss is “in a meeting” and can’t take a call. New employees get targeted most, since scammers watch LinkedIn for job announcements.

    What are the warning signs?

    • Any request to pay with a gift card
    • Urgency, with a deadline measured in minutes or hours
    • A request for secrecy, or an instruction to lie to the cashier about why you are buying
    • An order to stay on the phone while you shop
    • A request to buy cards at several different stores
    • A request to photograph or read out the numbers on the back
    • An email from the boss that comes from a personal address, or a text from an unknown number

    How do I protect my business?

    • Write the rule down. The company never buys gift cards on the strength of an email or a text. Purchases follow the normal approval process.
    • Verify by voice. Any unusual request for money or cards gets a phone call to a known number, or a walk down the hall.
    • Tell every new hire in the first week. Scammers reach new staff within days of a public announcement.
    • Tag external email. A banner that marks outside messages exposes a fake boss.
    • Have the owner say it out loud: “I will never ask you to buy gift cards. If you get that message, it is not me.”
    • Limit what the website gives away. Review whether you need a full staff directory with titles and direct email addresses.
    • Cover it in training. See our post on how to spot a phishing email and our cybersecurity training.

    How do I protect my family?

    Talk about it at the holiday table. Older relatives lose the most, and many have never heard that gift card payment is the mark of a scam. Agree on a simple plan: if a caller demands money, hang up and call a family member before doing anything. Tell the grandparents that a real grandchild in trouble will still be in trouble ten minutes from now, after a callback.

    What should I do if I gave a scammer gift card numbers?

    Move fast. Minutes matter.

    1. Call the gift card company right away and say the card was used in a scam. Ask whether any balance remains and whether they can freeze it. The phone number is on the back of the card or on the company’s website. Apple, Google Play, Amazon, Target, Walmart, and the major prepaid card brands all run fraud lines.
    2. Keep the card and the receipt. You need both for the report.
    3. Tell the store where you bought the cards.
    4. Report it to the FTC at ReportFraud.ftc.gov and to the FBI at ic3.gov.
    5. Tell your employer if the request posed as your boss. Others in the company may be getting the same message.
    6. Stop responding to the scammer. Expect follow-up contacts that promise to recover your money for a fee. Those are scams too.

    Can I get my money back?

    Sometimes, if the scammer has not yet spent the balance when you call. Once the funds are used, recovery is unlikely. That is the reason criminals prefer gift cards, and the reason to call the card company before you do anything else.

    What is gift card tampering?

    A different crime hits honest shoppers. Thieves take cards from store racks, record the numbers and PINs, reseal the packaging, and return the cards to the shelf. When a shopper loads money onto the card, the thief drains it.

    Protect yourself when you buy gift cards as gifts:

    • Inspect the packaging. Skip any card with a torn, wrinkled, or resealed wrapper, or a scratched PIN cover.
    • Pick cards from behind the counter or from the middle of the rack.
    • Buy from the retailer’s own website when you can.
    • Keep the receipt and give it with the card.
    • Tell the recipient to use the card soon.

    What should retail staff watch for?

    If your business sells gift cards, your cashiers are the last line of defense. Train them to notice a customer who is on the phone while buying, seems frightened or rushed, buys large amounts, or is elderly and buying cards for a brand they would not normally use. A calm question can stop the loss: “Did someone ask you to buy these to make a payment?” Post a warning sign at the rack. Many retailers now do.

    Are other payment methods a warning sign too?

    Yes. Scammers also demand wire transfers, cryptocurrency, payment apps such as Zelle and Cash App, and cash sent by mail or handed to a courier. Each shares the traits that make gift cards attractive: fast, hard to trace, and hard to reverse. Treat a demand for any of them, from someone you did not contact first, as a scam.

    Your next step

    Send a two-line message to your staff today: “I will never ask you to buy gift cards by email or text. If you receive that request, call me.” Then make the same promise to your family. For help writing payment verification rules and training your team, see our services or contact Cerberus Cybersecurity.

  • What Is a VPN, and Do You Need One?

    By J. Mesa

    VPN advertisements promise to make you anonymous, block hackers, and protect your identity. A VPN does none of those things on its own. It does one useful job well, and knowing what that job is tells you whether you need to pay for one.

    What is a VPN?

    A VPN, or virtual private network, is a service that creates an encrypted connection between your device and a server run by the VPN provider. Your internet traffic travels through that encrypted tunnel to the provider’s server and goes out to the internet from there.

    How does a VPN work?

    Without a VPN, your traffic passes through the local network and your internet provider on its way to a website. Each of them can see which sites you connect to. The website sees your IP address, which reveals your provider and your rough location.

    With a VPN turned on:

    1. Your device encrypts the traffic before it leaves.
    2. The local network and your internet provider see only scrambled data going to the VPN server.
    3. The VPN server decrypts the traffic and sends it to the website.
    4. The website sees the VPN server’s IP address in place of yours.

    You have moved your trust. Your internet provider can no longer see your browsing, and the VPN company now can.

    What does a VPN protect you from?

    • Snooping on untrusted networks. On hotel, airport, and coffee shop Wi-Fi, a VPN stops the network operator and other users from watching where your traffic goes.
    • Tracking by your internet provider. Your provider can’t log the sites you visit.
    • Exposure of your IP address. Websites and services see the VPN’s address.
    • Location limits. A VPN can make you appear to be in another region.

    What does a VPN not protect you from?

    This list matters more than the first one.

    • Phishing. A VPN delivers a fake sign-in page to you through an encrypted tunnel. You can still type your password into it. See our guide to spotting a phishing email.
    • Malware. A VPN does not scan what you download.
    • Weak or reused passwords. An attacker with your password signs in from anywhere.
    • Tracking by the sites you use. Google, Facebook, and advertisers identify you by your login, your cookies, and your browser, with or without a VPN.
    • Data breaches. A VPN has no effect on how a company stores your information.
    • Anonymity. The VPN provider knows who you are and can see your traffic. Websites you sign in to know who you are.

    Do I need a VPN at home?

    For security, most people do not. Nearly every website and app now encrypts its own traffic with HTTPS, the padlock in your browser. Your home network is one you control. A VPN at home adds privacy from your internet provider and little else.

    Spend the effort where it counts first: a strong, unique password for each account, multi-factor authentication, and software updates.

    Do I need a VPN on public Wi-Fi?

    It helps, and the risk is smaller than the ads suggest. Because of HTTPS, a snoop on the coffee shop network can’t read your banking session or your email. The snoop can see which sites you visit, and a fake hotspot can steer you toward a fraudulent page.

    A VPN closes those gaps. So does using your phone’s hotspot or cellular data. If you travel often and work from shared networks, a VPN is a reasonable purchase. Our post on staying safe on the go covers the rest.

    What is a business VPN?

    A business VPN serves a different purpose from the consumer products in the ads. It connects a remote employee’s computer to the company’s private network, so the employee can reach file servers, accounting systems, and other internal resources from home or the road. Your firewall or a dedicated service provides it, and your IT team controls who may connect.

    A consumer VPN hides your browsing from the local network. A business VPN extends your office network to an authorized person. Buying consumer subscriptions for your staff does not give them secure access to the office.

    How do I secure a business VPN?

    A VPN is a door into your network, and attackers know it. VPN devices sit among the most common entry points for ransomware.

    • Require multi-factor authentication for every VPN login. A VPN protected by a password alone is one stolen password away from a break-in.
    • Patch the VPN device quickly. Vendors release fixes for serious flaws several times a year, and criminals scan the internet for unpatched devices within days.
    • Give each person an account. No shared logins. Disable the account the day someone leaves.
    • Limit what the VPN reaches. A remote bookkeeper needs the accounting system and nothing else.
    • Allow company-managed devices only, where you can. A family computer full of malware should not join the office network.
    • Review the logs for logins at odd hours and from unexpected countries.
    • Replace hardware the vendor no longer supports.

    Do small businesses still need a VPN?

    It depends on where your systems live. If your email, files, and accounting all run in cloud services such as Microsoft 365, Google Workspace, and QuickBooks Online, your staff reach them directly over HTTPS, and a VPN adds little. Protect those logins with multi-factor authentication.

    If you keep a server, a records system, or network storage in the office, remote staff need a secure way in. A VPN is the traditional answer. Never expose Remote Desktop straight to the internet as a shortcut.

    Newer “zero trust” access tools take a different approach. They verify the person and the device, then grant access to one application at a time and not to the whole network. Ask your IT provider whether one fits your size and budget.

    How do I choose a consumer VPN?

    If you decide to buy one, check these points.

    • Independent audits. Look for a published audit of the provider’s no-logs claim by a named outside firm.
    • Clear ownership. You should be able to learn who runs the company and where it operates.
    • Modern protocols, such as WireGuard or OpenVPN.
    • A kill switch that blocks traffic if the VPN connection drops.
    • A paid plan from a known provider. Running servers costs money. A free VPN often pays its bills by collecting and selling your browsing data, which defeats the purpose.
    • No outsized promises. Be wary of any product that claims to make you anonymous or “unhackable.”

    Are free VPNs safe?

    Many are not. Studies of free VPN apps have found data collection, advertising trackers, and in some cases malware. A few reputable providers offer limited free tiers supported by their paid customers. Outside of those, avoid free VPN apps, above all on a device that holds work email.

    Does a VPN slow down my internet?

    Somewhat. Your traffic takes a longer route and gets encrypted along the way. With a good provider and a nearby server, most people notice little difference for browsing and video calls.

    Is using a VPN legal?

    In the United States, yes. A handful of countries restrict or ban them, so check before you travel. A VPN does not make an illegal act legal, and it may violate the terms of a streaming service.

    Your next step

    List the systems your staff reach from outside the office and how they connect to each one. For every remote connection that relies on a password alone, add multi-factor authentication this month. Cerberus Cybersecurity reviews remote access as part of our risk and compliance assessments and writes remote work policies your team can follow. Contact us to get started.

  • How to Spot a Phishing Email: 9 Warning Signs

    By J. Mesa

    An email lands in your inbox at 4:45 on a Friday. Your mailbox is full, it says, and you will stop receiving messages unless you sign in now. You click, type your password, and go home. By Monday, a stranger has read three months of your email and sent an invoice to your largest customer. Most break-ins at small businesses begin this way, with one message and one tired person.

    What is phishing?

    Phishing is a fraudulent message that poses as a trusted sender to trick you into giving up a password, sending money, or opening a malicious file. Email carries most of it. Text messages, phone calls, and social media carry the rest.

    How does a phishing attack work?

    The attacker wants one of three results.

    • Your credentials. The message links to a fake sign-in page for Microsoft 365, Google, your bank, or a shipping company. Whatever you type goes to the attacker.
    • Your money. The message poses as a vendor, a boss, or a customer and asks for a payment, a gift card, or a change of bank details.
    • Your computer. The message carries an attachment or a link that installs malware, including the kind that leads to ransomware.

    What are the warning signs of a phishing email?

    1. The sender address does not match the name. The display name says “Microsoft Support,” and the address behind it ends in a domain you have never seen. Click or tap the name to reveal the full address.
    2. The domain is close but wrong. Look for swapped or added characters: “rn” in place of “m,” a zero in place of the letter o, or an extra word such as “-secure” or “-billing.”
    3. The message creates urgency. Your account closes today. The invoice is overdue. The boss needs it in ten minutes. Pressure exists to stop you from thinking.
    4. The request is unusual. A vendor changes its bank account by email. The owner asks for gift cards. Payroll gets a request to move a direct deposit.
    5. The link goes somewhere else. Hover over the link on a computer, or press and hold on a phone, and read the real address. A Microsoft sign-in page does not live on a random website.
    6. The attachment was not expected. Treat surprise invoices, voicemails, scans, and shipping documents as suspect, above all files that ask you to “enable content” or sign in to view them.
    7. The greeting is generic. “Dear customer” from a bank that knows your name.
    8. The tone is off. A colleague who writes in short bursts sends three formal paragraphs. Trust that instinct.
    9. The message asks for secrets. No legitimate company asks for your password, your verification code, or your full card number by email.

    Spelling mistakes used to be a reliable sign. They are less reliable now, because attackers use better tools and copy real company emails word for word. A clean, well-written message can still be a fake.

    What are the common types of phishing?

    • Bulk phishing. One message to millions of people, posing as a bank, a streaming service, or a delivery company.
    • Spear phishing. A message written for one person, using details from LinkedIn, your website, or an earlier breach.
    • Whaling. Spear phishing aimed at owners and executives.
    • Business email compromise. A message that poses as a boss or a vendor to redirect a payment. It often contains no link and no attachment, which lets it pass through filters.
    • Smishing and vishing. The same tricks by text message and by phone.
    • Clone phishing. A copy of a real email you received before, with the link or attachment swapped.

    Our post on how hackers get in covers the psychology behind these attacks.

    How do I check a link safely?

    • Hover first, and read the address from right to left. The part just before “.com” or “.org” is the real owner. In “microsoft.com.account-verify.net,” the owner is account-verify.net.
    • Do not trust the padlock. Fake sites have them too.
    • When in doubt, skip the link. Open your browser and type the company’s address yourself, or use the bookmark you already have.
    • Be careful with shortened links and QR codes, which hide the destination.

    What should I do when I get a suspicious email?

    1. Do not click, reply, or open the attachment.
    2. Report it. Use the “Report phishing” button in Outlook or Gmail, and forward it to whoever handles your IT.
    3. Verify through another channel. Call the sender at a number you already have. Do not use the phone number in the message.
    4. Delete it.

    If the message poses as a coworker or a vendor you know, tell that person. Their account may have been hacked, and they may not know yet.

    What should I do if I clicked a phishing link?

    Speed matters more than embarrassment. Tell your IT contact right away.

    • You clicked but entered nothing. Close the page. Run a scan with your security software. Watch the account for a few days.
    • You entered a password. Change it at once from a different device. Change it on every other account where you used the same one. Turn on multi-factor authentication. Ask IT to sign out all active sessions and check the mailbox for forwarding rules the attacker may have added.
    • You opened an attachment or enabled content. Disconnect the computer from the network and call IT. Do not keep working on it.
    • You sent money or bank details. Call your bank immediately and ask for a recall, then report the fraud to the FBI at ic3.gov.

    How do I protect my business from phishing?

    • Turn on multi-factor authentication for email first, then for banking, payroll, and remote access. A stolen password alone then gets the attacker nowhere.
    • Use the email filtering you already pay for. Microsoft 365 and Google Workspace include phishing and attachment protections that many businesses never switch on.
    • Tag outside email. A banner that marks messages from outside the company exposes a fake “boss” at a glance.
    • Set a payment verification rule. No change to bank details and no new payee without a phone call to a known number and a second approver.
    • Use a password manager. It fills passwords only on the real site, so a look-alike page gets nothing.
    • Limit what staff post. Job titles, vendor names, and travel plans on public pages help an attacker write a convincing message.
    • Make reporting easy and safe. One button or one address. Thank the people who report, including the ones who clicked first.

    Does phishing training work?

    Yes, when you repeat it. A one-hour lecture once a year fades within weeks. Short sessions through the year, paired with simulated phishing emails, build the habit of pausing before a click. Track two numbers: how many people click, and how many people report. The second number matters more, because one fast report lets you warn everyone else.

    Treat a failed test as a coaching moment. Staff who fear punishment hide their mistakes, and a hidden click does the most damage. Our cybersecurity training covers phishing for every role, from the front desk to the owner.

    Can email filters stop all phishing?

    No. Filters catch most bulk phishing. Targeted messages, messages sent from a real hacked account, and messages with no link or attachment still arrive. Your people are the last check, so give them the knowledge and the permission to slow down.

    Your next step

    Forward this list of nine signs to your staff, and ask each person to find the “Report phishing” button in their mail program today. To build a training program and a payment verification policy that fit your business, see our services or contact Cerberus Cybersecurity.

  • What Is a Digital Footprint? How to Check and Shrink Yours

    What Is a Digital Footprint? How to Check and Shrink Yours

    By J. Mesa

    Every post, purchase, search, and sign-up leaves a mark. Put together, those marks form your digital footprint, and criminals read it like a file on you.

    This post explains what a digital footprint is, how criminals use it, how to check your own, and how to shrink it.

    What is a digital footprint?

    Your digital footprint is the record of what you do and share online. It includes your social media profiles, the accounts you created, the sites you visited, what you bought, and the information other people and companies published about you.

    What is the difference between an active and a passive footprint?

    • Active footprint. Data you share on purpose: posts, photos, comments, reviews, and forms you fill out.
    • Passive footprint. Data collected without your direct action: your IP address, location, browsing history, and the tracking that follows you between websites.

    You control the active part with your choices. You limit the passive part with settings and tools.

    Who collects this data?

    Businesses collect it to improve services and target ads. Data brokers gather it from public records and other companies, then sell profiles. Criminals collect it from social media, breached databases, and the same broker sites that anyone can search.

    How do criminals use my digital footprint?

    • Targeted phishing. A message that names your employer, your bank, or your recent trip is far more convincing than a generic one.
    • Identity theft. A full name, birth date, and address are enough to open accounts or file fraudulent claims.
    • Account takeover. Security questions ask for your first pet, your school, or your mother’s maiden name. Your profile often answers all three.
    • Physical risk. A post announcing your vacation also announces your empty house.
    • Impersonation. Criminals copy your photos and name to scam your friends and family.

    One birthday post, one tagged location, and one old forum account add up. Attackers combine small details that look harmless on their own.

    How do I check my digital footprint?

    1. Search your full name in quotation marks, with your city, on more than one search engine. Check the image results too.
    2. Search your email addresses and phone number.
    3. Enter your email at haveibeenpwned.com to see which breaches included it.
    4. View your social media profiles while logged out, or use the “view as public” feature.
    5. List the old accounts you no longer use.

    Write down what you find. The surprises tell you where to start.

    How do I reduce my digital footprint?

    1. Think before you post. Leave out your home address, phone number, birth date, and financial details.
    2. Tighten privacy settings. Limit your profiles to friends, and hide your friend list and contact details.
    3. Use strong, unique passwords. A password manager makes this practical.
    4. Turn on two-factor authentication. It protects an account when its password leaks.
    5. Watch for phishing. Treat unexpected links and attachments with suspicion.
    6. Monitor your accounts. Review bank and card statements, and report charges you don’t recognize.
    7. Limit app permissions. Deny access to contacts, location, and photos unless the app needs it.
    8. Delete old accounts. Close the ones you no longer use.
    9. Post about trips after you return.
    10. Use a VPN on public Wi-Fi. It encrypts your traffic on networks you don’t control. It does not make you anonymous, and it does not hide what you post.

    Can I delete my digital footprint?

    Not all of it. You can remove a great deal.

    • Delete old posts and close unused accounts.
    • Ask search engines to remove results that show sensitive personal information. Google offers a request form for this.
    • Opt out of data broker sites. Each one has its own process, and some services handle the requests for a fee.
    • Ask companies to delete your data. Privacy laws in several US states give residents that right.

    Information that others have copied or archived can persist. Reducing what is out there still lowers your risk.

    Should I freeze my credit?

    A credit freeze stops anyone from opening new credit in your name. It is free in the United States, and you place it with each of the three credit bureaus: Equifax, Experian, and TransUnion. You lift it when you apply for credit yourself. If your personal information has appeared in a breach, a freeze is one of the strongest protections you have.

    How do I protect my family’s footprint?

    • Ask before you post photos of children, and leave out school names and locations.
    • Help older relatives set their profiles to private.
    • Agree on a family rule about what stays offline, such as travel plans and home addresses.

    Does my business have a digital footprint too?

    Yes. Your website, staff listings, social media, and job posts tell an attacker who works for you, who handles money, and which software you use. Criminals use that to write emails that pose as your owner or your vendors.

    • Don’t publish direct emails for staff who handle payments.
    • Train employees on what they share about work online.
    • Set a rule that any payment change gets a phone call to confirm.

    How often should I check?

    Review your footprint twice a year, and again after any breach notice. Managing your footprint is an ongoing habit, because you add to it every day.

    What do data brokers know about me?

    Data brokers are companies that collect personal details from public records, apps, loyalty programs, and other businesses, then sell the combined profile. A typical profile holds your current and past addresses, phone numbers, relatives, age, and property records. People-search websites are the public face of this trade, and anyone can look you up on them for a few dollars.

    To push back, search your name on the larger people-search sites and use each site’s opt-out page. The process takes time, and listings can return, so repeat it once or twice a year.

    Your next step

    Run the five-step check above this week and fix the two biggest surprises. If you want your team to learn how attackers use public information against a business, Cerberus Cybersecurity covers it in our cybersecurity training. Contact us to learn more.

  • Log4Shell Explained: What It Is, Who Is at Risk, and How to Check

    Log4Shell Explained: What It Is, Who Is at Risk, and How to Check

    By J. Mesa

    In December 2021, security teams around the world spent their holidays hunting for one small piece of software. A flaw in a logging tool called Log4j let an attacker take over a server by sending it a single line of text. The flaw got the name Log4Shell, and attackers still use it today.

    You may never have heard of Log4j. Your business may still run it. This post explains what happened, who is at risk, and what to check.

    What is Log4Shell?

    Log4j is a free, open-source logging library for the Java programming language. Developers use it to record what an application does: who logged in, what a user searched for, which errors occurred. Thousands of commercial products include it, from web applications to network appliances.

    Log4Shell is the name for a vulnerability in Log4j tracked as CVE-2021-44228. Researchers disclosed it on December 9, 2021. It received a severity score of 10 out of 10, the highest rating possible.

    How does the Log4Shell attack work?

    Log4j had a feature that looked up information whenever it found a special instruction inside a log message. An attacker could place that instruction anywhere the application would log it: a username field, a search box, a web request header.

    1. The attacker sends text containing a lookup instruction that points to a server the attacker controls.
    2. The application writes that text to its log.
    3. Log4j reads the instruction, connects to the attacker’s server, and downloads code.
    4. The application runs that code. The attacker now controls the system.

    The attacker needs no password and no account. The industry calls this remote code execution, and it is the reason the score reached 10.

    Why was Log4Shell so serious?

    • It was everywhere. Log4j sat inside products from hundreds of vendors. Many companies did not know they used it.
    • It was easy. Working attack code spread within hours of disclosure.
    • It was hidden. Log4j often sits several layers deep inside other software, so finding it took weeks.

    The director of the US Cybersecurity and Infrastructure Security Agency (CISA) at the time called it one of the most serious vulnerabilities she had seen in her career. Criminal groups and nation-state actors both used it. Botnets such as Mirai and Kinsing scanned the internet for vulnerable servers and installed malware, cryptocurrency miners, and ransomware.

    Is Log4Shell still a threat?

    Yes. Many organizations patched in 2021 and 2022. Many forgotten or unmanaged applications still run vulnerable versions, and attackers keep scanning for them. In 2022 the US Cyber Safety Review Board called Log4Shell an “endemic vulnerability” and warned that vulnerable copies would stay in systems for a decade or longer.

    Old software does not fix itself. The server someone set up in 2019 and forgot is the one an attacker finds.

    Am I affected if my business doesn’t write software?

    You can be. You don’t need a developer on staff to run Java software. Log4j shipped inside products that small businesses buy and install, including:

    • Network and security appliances
    • Remote access and virtual desktop products
    • Backup, monitoring, and help desk tools
    • Line-of-business applications from smaller vendors

    Cloud services you subscribe to were the vendor’s job to patch. Software and devices in your own office or server room are your job.

    How do I check if I am vulnerable to Log4Shell?

    1. List what you run. Write down every server, appliance, and business application you own, with its version. You can’t patch what you don’t know about.
    2. Check vendor advisories. Search each vendor’s site for “Log4j” or “CVE-2021-44228.” Most published a statement and a fixed version.
    3. Scan. A vulnerability scan finds known-vulnerable versions of Log4j on your network. This is a standard part of a vulnerability assessment.
    4. Look for old systems. Pay attention to anything installed before 2022 that no one has updated since.

    Vulnerable versions of Log4j run from 2.0-beta9 through 2.14.1.

    How do I fix Log4Shell?

    • Update the affected product to the vendor’s fixed release. For Log4j itself, that means version 2.17.1 or later on Java 8.
    • If a vendor no longer supports the product, replace it or take it off the network.
    • Limit which servers can make outbound connections to the internet. The attack depends on your server reaching out to the attacker.
    • Watch your logs for the text ${jndi:, the marker of an attempted attack.

    What did Log4Shell teach us?

    • Know your software supply chain. You depend on code you never chose. Keep an inventory of the products you run and the components inside them.
    • Patch fast. Attackers began exploiting Log4Shell within hours. A patch process that takes months leaves the door open.
    • Detect and respond. You need a way to see an attack in progress and a tested plan for what to do next.
    • Train your people. Staff who know how to report something odd shorten the time an attacker spends inside your network.

    What should a small business do now?

    1. Build or update your inventory of systems and software.
    2. Turn on automatic updates wherever a product offers them.
    3. Schedule a vulnerability assessment at least once a year.
    4. Write a one-page incident response plan and walk through it with your team.

    What is a software bill of materials, and do I need one?

    A software bill of materials (SBOM) is an ingredient list for a piece of software. It names every component inside the product, including libraries such as Log4j. When the next Log4Shell arrives, a company with SBOMs can search them and know within minutes which products to patch.

    You don’t need to build one yourself. Ask your software vendors whether they provide an SBOM, and ask how they notify customers about security fixes. A vendor with clear answers to both questions handled Log4Shell faster than one without. Add those two questions to your checklist when you buy new software.

    Your next step

    If you don’t know whether a vulnerable system sits on your network, find out before an attacker does. Cerberus Cybersecurity runs risk and compliance assessments that include vulnerability scanning and a plain-language report. Contact us to schedule one.

  • What Is Tech Debt? How Small Businesses Can Manage It Before It Bites

    What Is Tech Debt? How Small Businesses Can Manage It Before It Bites

    By J. Mesa

    Technology is the lifeblood of most small and medium-sized businesses. Like any powerful tool, it carries hidden costs. One of the largest is technology debt.

    This post explains what tech debt is, how to spot it, what it costs, and how to pay it down without replacing everything at once.

    What is tech debt?

    Technology debt, or tech debt, is the buildup of outdated systems, postponed upgrades, and quick fixes that make your technology harder and riskier to run. The term comes from software development, where a shortcut taken today creates extra work later, the way a loan creates interest.

    Think of website maintenance you keep putting off. Over time the site gets slow, buggy, and open to attack. Tech debt does the same thing across your whole business.

    What are examples of tech debt in a small business?

    • A server or PC running an operating system that no longer receives security updates
    • Accounting or point-of-sale software several versions behind
    • A spreadsheet that runs a critical process and that only one person understands
    • A firewall or router nobody has updated in years
    • Shared passwords and accounts for staff who left long ago
    • Custom software written by a contractor you can no longer reach

    What are the signs my business has tech debt?

    • Outdated systems. You rely on aging hardware or old software. That brings compatibility problems, security holes, and trouble adopting newer tools such as cloud services.
    • Workarounds. “Duct tape” fixes hold your systems together. Each one adds another piece that can break.
    • Frequent outages and errors. Crashes, lost data, and slow performance show an infrastructure under strain.
    • Trouble scaling. Your systems can’t handle more clients or more staff.
    • Security concerns. Your software has known vulnerabilities that the vendor has stopped fixing.

    Two or more of these means the debt is already costing you.

    Why is tech debt a security risk?

    Attackers scan the internet for systems with known flaws. Software that no longer receives updates keeps every flaw found after its end date, forever. Each month adds to the list.

    Outdated systems also tend to lack modern protections such as multi-factor authentication and encryption. They fail compliance checks for standards such as PCI-DSS and HIPAA. And they often sit forgotten, which means nobody notices when someone breaks in.

    What does it cost to ignore tech debt?

    Ignoring tech debt is like ignoring a leaky roof. It looks manageable at first, and the repair bill grows the longer you wait.

    • Lost productivity. Slow, unreliable systems waste staff time every day.
    • Higher costs. Old systems need special skills and hard-to-find parts. For our island community the problem is sharper, because everything is imported and shipping adds cost and delay.
    • Security breaches. One breach can bring financial loss and lasting damage to your reputation.
    • Lost opportunity. You can’t adopt tools that would help you compete, such as automation and data analytics.

    How do I measure my tech debt?

    Run a simple technology audit. A spreadsheet works.

    1. List every device, application, and online service you use.
    2. For each, record its age, its version, and whether the vendor still supports it.
    3. Note what business process depends on it.
    4. Mark what would happen if it failed tomorrow.

    The items that are unsupported and critical go to the top of your list.

    How do I manage tech debt on a small budget?

    You don’t have to replace everything overnight. Follow five steps.

    1. Prioritize and plan. Use your audit to rank the issues by severity and business impact. Start with security risks and the systems that block growth. Set a realistic roadmap with milestones.
    2. Decide between modernizing and replacing. Compare the cost of updating a system against the cost of a new one. Cloud-based services can lower maintenance and include ongoing support.
    3. Invest in employee training. New tools only help when your team knows how to use them.
    4. Put security first. Update software, maintain your firewall, and encourage safe online habits.
    5. Seek expert help. An IT consultant can build a plan that fits your business and your budget.

    Should I repair or replace an old system?

    Ask four questions:

    • Does the vendor still provide security updates?
    • Can it support multi-factor authentication and encryption?
    • Does keeping it cost more per year than replacing it, once you count downtime?
    • Does it hold up a process the business depends on?

    If the vendor has ended support, plan a replacement. If you can’t replace it yet, isolate it from the rest of the network and limit who can reach it.

    How do I avoid new tech debt?

    • Budget for replacement when you buy. Plan on three to five years for computers.
    • Turn on automatic updates wherever you can.
    • Document how your systems work, so the knowledge does not sit with one person.
    • Review your technology list once a year.
    • Before you add a tool, check how long the vendor will support it.

    How long does it take to pay down tech debt?

    It depends on how much has built up. Most small businesses can fix their highest risks within a few months and spread the rest across one to two budget years. Tackling tech debt is an ongoing process. You maintain technology the way you maintain a building.

    What is end of life software, and why does it matter?

    End of life means the vendor has stopped releasing updates, including security fixes. From that date the product gets less safe every month. Vendors publish these dates years ahead. Add them to your technology list so a deadline never surprises you.

    Can cyber insurance cover problems caused by outdated systems?

    Do not count on it. Insurers ask about your systems when you apply, and many policies exclude or limit claims tied to unsupported software. An honest application that lists old systems can raise your premium. Replacing them can lower it.

    Your next step

    Start your audit this week with the ten systems your business depends on most. By facing tech debt and taking steady steps, a small business gains efficiency, stronger security, and room to grow. Contact Cerberus Cybersecurity to learn how we can support your organization with a risk assessment that shows where outdated technology puts you at risk.

  • Social Media Safety: 10 Ways to Spot Scams and Fake Friends

    By J. Mesa

    Social media is great for catching up with friends, watching funny pet videos, and picking up a kådu recipe or two. Like any busy place, it has a few shady characters. They want your personal information, your money, or your account.

    You can outsmart them. Here are ten habits that keep you safe, plus what to do if something goes wrong.

    What are the most common social media scams?

    • Fake friend or follow requests from copied or invented profiles
    • Phishing messages that link to fake login pages
    • Marketplace and shopping scams with deals that never ship
    • Giveaway and prize scams that ask for a fee or your details
    • Romance and investment scams that build trust over weeks, then ask for money
    • Impersonation of someone you know, asking for urgent help

    Every one of them works by getting you to trust the wrong person.

    1. How do I spot a fake friend request?

    Don’t accept requests from people you don’t know. Check the profile first.

    • Few photos, or photos that look like stock images
    • An account created in the last few weeks
    • No friends in common
    • A second request from someone who is already your friend

    That last one means a scammer copied your friend’s profile. Decline it, and tell your friend through another channel.

    2. What do phishing messages look like?

    Scammers send private messages that look real. Be careful with any message that:

    • Pressures you. “Act now” and “limited time offer” are meant to stop you from thinking.
    • Has odd spelling or grammar. Real companies proofread.
    • Contains a link. Hover over it on a computer, or press and hold on a phone, to see the real address before you open it.
    • Asks for your password or a code. Real platforms never ask for these in a message.

    3. Should I trust a deal that looks too good?

    No. A price far below normal, a seller who wants payment by gift card or wire, or a buyer who “overpays” and asks for a refund are all scams. Pay through the platform’s own checkout, which offers buyer protection.

    4. How do I check before I share?

    False stories travel fast. Before you share a post that makes you angry or afraid, look for the same story on a news source you trust. If you can’t find it, don’t pass it on.

    5. Why should I avoid clickbait?

    Headlines built to shock often lead to sites that install malware or collect your data. If a headline looks too wild to be true, it is. Skip the link.

    6. How do I lock down my profile?

    • Privacy settings. Control who sees your posts, your friend list, and your contact details. Set them to friends only.
    • Passwords. Use a strong, different password for each account. A password manager helps.
    • Two-factor authentication. Turn it on. It works like a second lock on your door.
    • Personal details. Keep your birthday, address, and phone number off your public profile.

    7. How much sharing is too much?

    Posting where you are in real time tells strangers when your house is empty. Details such as your pet’s name, your school, and your hometown answer common security questions. Share trip photos after you get home, and keep the answers to security questions to yourself.

    8. Are quizzes and giveaways safe?

    Be careful. “Which character are you?” quizzes often ask for the same facts banks use to verify you. Giveaways with huge prizes collect personal details or ask for a “shipping fee.” Research any contest before you enter, and never pay to claim a prize.

    9. What is like-farming?

    Scammers post content designed to collect likes and shares, such as “Share if you love your mom.” Once the page has a large audience, they change it to promote scams or sell it. Don’t like or share suspicious posts to help someone gain followers.

    10. How do I report a scam or a fake account?

    Every major platform has a report button on profiles, posts, and messages. Use it. Reporting gets fake accounts removed and protects the next person. You can also report fraud to the Federal Trade Commission at reportfraud.ftc.gov.

    What should I do if my account gets hacked?

    1. Change your password right away. If you can’t log in, use the platform’s account recovery page.
    2. Log out of all other devices in the security settings.
    3. Turn on two-factor authentication.
    4. Check for changes: a new email address or phone number on the account, new posts, new messages.
    5. Tell your friends, so they ignore messages the attacker sent as you.
    6. Change the password on any other account that used the same one.

    What should I do if I sent money to a scammer?

    Act fast. Call your bank or card company and ask to stop or reverse the payment. Report the scam to the platform, to reportfraud.ftc.gov, and to the FBI at ic3.gov. Keep screenshots of the profile and the messages. The sooner you report, the better your chance of getting money back.

    How do I help kids and older relatives stay safe?

    Teach your friends and family, and pay special attention to our Manåmko’. Scammers target older adults with fake family emergencies and prize notices.

    • Agree that any request for money gets a phone call to confirm, on a number you already have.
    • Set up privacy settings and two-factor authentication on their accounts with them.
    • Remind them that a real friend will not mind waiting while they check.

    For kids, keep accounts private, know who they talk to, and make it easy for them to tell you when something feels wrong.

    Is it safe to log in to other sites with my social media account?

    It is convenient, and it ties those sites to one account. If someone takes over that account, they reach everything connected to it. Protect it with a strong password and two-factor authentication, and review the list of connected apps in your settings once or twice a year. Remove the ones you no longer use.

    What habits keep me safe over time?

    • Trust your gut. If something feels off, ignore the message or block the person.
    • Stay updated. Platforms change their security settings often. Check yours a few times a year.
    • Spread the word. The more people who know these tricks, the fewer victims scammers find.

    Your next step

    Spend ten minutes today on your privacy settings and turn on two-factor authentication. If your business uses social media, your team needs these skills too. Cerberus Cybersecurity teaches them in our cybersecurity training. Contact us to set up a session.

  • 7 Bad Cybersecurity Habits That Put You at Risk (and How to Fix Them)

    By J. Mesa

    Most security incidents don’t start with a brilliant hacker. They start with a habit: a reused password, a skipped update, a quick click. The same seven habits show up again and again, in homes and in businesses.

    Here is each one, why it puts you at risk, and how to fix it.

    1. Why are weak passwords dangerous?

    Passwords such as “password” and “123456” sit at the top of every attacker’s list. Software tries them in seconds.

    The fix: Use a long passphrase made of several unrelated words. Words from another language make it harder to guess. Something built around a phrase like “Biba Mes CHamoru” means a lot to me and nothing to a cracking tool. Don’t copy an example from a blog post, mine included. Make your own, and use a different one for every account. A password manager keeps track of them.

    2. Is it safe to share passwords?

    No. Sharing a streaming login to catch the latest episode of a show feels harmless. Once you share a password, you no longer control where it goes. The other person may reuse it, save it somewhere unsafe, or fall for a phishing email.

    The fix: Give each person their own account. For family services, use the plan’s built-in sharing feature. At work, never share a login. If several people need the same system, give each one a separate account, so you can see who did what and remove access when someone leaves.

    3. Is public Wi-Fi safe?

    Public Wi-Fi in an airport, hotel, or café is a shared network. An attacker on it can set up a fake hotspot with a similar name or try to intercept traffic that is not encrypted.

    The fix:

    • Confirm the network name with staff before you join
    • Use your phone’s hotspot for banking and work
    • Use a virtual private network (VPN) when you handle sensitive or business data while traveling
    • Turn off automatic connection to open networks

    4. What happens if I click a suspicious link?

    Phishing is a common way for attackers to get into accounts. A link can lead to a fake login page that captures your password, or it can install malware on your device.

    The fix: Check the address before you click. Don’t open attachments you did not expect. If you doubt an email, call the business or person using a phone number from their official website. Do not use the contact details in the email.

    If you already clicked, change the password for that account from a different device and tell your IT contact.

    5. Why do software updates matter?

    Updates carry security patches that fix known flaws. Skip them, and attackers can use those flaws against you. Updates take time and interrupt your day. They also close the holes that criminals are using right now.

    The fix: Turn on automatic updates for your operating system, browser, apps, and phone. Restart when asked. Replace devices that no longer receive updates.

    6. Why should I change default settings?

    Many routers, cameras, and other devices ship with a standard username and password such as “admin” and “admin.” Lists of those defaults are published online. Attackers scan the internet for devices that still use them.

    The fix: Change the default username and password on every device as soon as you set it up. Start with your home or office router. Turn off features you don’t use, such as remote management.

    7. What if I don’t back up my data?

    Without a backup, a ransomware attack, a failed drive, or a stolen laptop means the data is gone.

    The fix: Back up to an external drive or cloud storage. Follow the 3-2-1 rule: three copies, two types of storage, one offsite. Test that you can restore a file. It is better to have a backup and not need it than the alternative.

    What other bad habits should I watch for?

    • No multi-factor authentication. A second step at login blocks most attacks that use stolen passwords. Turn it on for email and banking first.
    • Oversharing online. Birthdays, pet names, and travel plans help attackers guess security answers and write convincing scams.
    • Using an administrator account for daily work. Malware runs with the rights of the account that opens it. Use a standard account for everyday tasks.
    • Ignoring old accounts. Close accounts you no longer use. Each one is a breach waiting to happen.

    Which habit should I fix first?

    Start with passwords and multi-factor authentication. Stolen and weak passwords open more accounts than any other cause. Then turn on automatic updates, which takes a few minutes and keeps working without you. Backups come third.

    How do I change habits across a whole team?

    • Make the safe way the easy way. Provide a password manager and turn on automatic updates for everyone.
    • Explain the reason behind each rule. People follow rules they understand.
    • Train in short sessions through the year.
    • Praise people who report a suspicious email or admit a mistake.
    • Write the rules into a short policy that new hires read on day one.

    How do I know if a bad habit already caused harm?

    • Search your email address at haveibeenpwned.com to see if it appears in a breach
    • Review the login history on your email and bank accounts
    • Look for email forwarding rules you did not create
    • Check that your backups ran

    If you find a problem, change the password, turn on multi-factor authentication, and tell anyone who may be affected.

    Are these habits a problem for businesses too?

    Yes, and the stakes are higher. One employee’s reused password can expose a customer database. One unpatched server can stop operations for a week. The same seven fixes apply, and a business should add written policies and regular training.

    Your next step

    Pick the habit from this list that describes you and fix it today. Cybersecurity is a priority for everyone, at home and at work. If you want your whole team to build better habits, Cerberus Cybersecurity offers cybersecurity training for every audience. Contact us to learn more.

  • How to Spot a Phishing Email: 9 Red Flags and What to Do Next

    By J. Mesa

    Each new year brings new technology and the same old threat. Phishing sounds like a tired topic. It keeps coming up because it still works, and criminals reach for it first.

    This guide shows you how to recognize a phishing message, the forms it takes, and what to do when one lands in your inbox.

    What is phishing?

    Phishing is a scam where a criminal sends a message that appears to come from a source you trust, such as a bank, a delivery service, a coworker, or a vendor. The goal is to get you to click a link, open a file, share a password, or send money.

    Why does phishing still work?

    • It targets people. Software can be patched. A busy person in a hurry can be rushed.
    • It is cheap. A criminal can send thousands of messages for almost nothing.
    • It looks better every year. Attackers copy real logos and layouts, and writing tools remove the spelling mistakes that used to give them away.
    • One click is enough. A single response out of thousands pays for the campaign.

    What are the types of phishing?

    • Email phishing. Mass messages that imitate well-known companies.
    • Spear phishing. A message written for one person, using details about their job or life.
    • Business email compromise. A message that poses as an owner, executive, or vendor and asks staff to send money or change bank details.
    • Smishing. Phishing by text message.
    • Vishing. Phishing by phone call, often with a fake caller ID.
    • QR code phishing. A code that leads to a fake login page.

    What are the red flags of a phishing email?

    1. You didn’t expect it. Be wary of any unsolicited message that asks for information or payment.
    2. It creates urgency. “Your account closes in 24 hours” is meant to stop you from thinking.
    3. It asks for personal information. Legitimate companies don’t ask for passwords or card numbers by email.
    4. The sender address is off. Look at the full address, not the display name. Watch for swapped letters and odd domains.
    5. The link doesn’t match. Hover over it to see where it goes.
    6. It has an unexpected attachment. Invoices, shipping notices, and “scanned documents” you didn’t ask for are common lures.
    7. The greeting is generic. “Dear customer” from a company that knows your name is a warning.
    8. The request is unusual. Gift cards, wire transfers, and secrecy are scam hallmarks.
    9. Something feels wrong. Odd tone, odd timing, or an odd request from someone you know deserves a second look.

    Spelling and grammar errors are still a sign. Their absence proves nothing.

    How do I verify a sender?

    Before you respond, confirm who sent the message. Contact the company or person through a phone number or address you already know to be real. Don’t use the contact details in the message, and don’t reply to it.

    For any request that involves money or a change to payment details, make a phone call. This one habit stops most business email compromise.

    What should I do if I receive a phishing email?

    1. Don’t click, reply, or open attachments.
    2. Report it with your email program’s “Report phishing” button.
    3. At work, tell your IT contact so they can warn others.
    4. Delete it.

    What should I do if I clicked a phishing link?

    Act right away. Speed matters more than embarrassment.

    1. Disconnect the device from the network if you opened a file or installed something.
    2. Change the password for the affected account from a different device, and for any account that shares it.
    3. Turn on multi-factor authentication.
    4. Tell your IT contact or manager at work.
    5. Call your bank if you entered payment details or sent money.
    6. Run a security scan on the device.
    7. Report it to the FBI at ic3.gov and to the Federal Trade Commission at reportfraud.ftc.gov.

    How do I protect my business from phishing?

    • Train your team. Use real examples. Repeat through the year.
    • Run simulated phishing tests and use the results to teach, never to punish.
    • Turn on multi-factor authentication for email. It limits the damage when a password is stolen.
    • Use email filtering and turn on the security features your email provider offers.
    • Set a payment verification rule. Any change to bank details gets a phone call to a known number.
    • Make reporting easy. One button, no blame.

    How does my online information help phishers?

    Attackers research their targets. Your social media tells them your employer, your job title, your coworkers, and where you spent the weekend. They use those details to write messages that sound real.

    • Keep your home address and phone number off public profiles
    • Limit what you share about your role and your workplace
    • Use strong, unique passwords for every account

    You would be surprised how much a criminal can learn from a public profile.

    Does multi-factor authentication stop phishing?

    It stops most of it. If you give away a password, the attacker still needs the second step. Some attacks trick people into approving a login prompt or typing a code into a fake page, so never approve a prompt you did not start. Security keys and passkeys resist phishing best, because they only work on the real website.

    Can phishing happen by phone or text?

    Yes. A text about a missed delivery or a call from “your bank’s fraud team” follows the same pattern as a phishing email. Hang up, and call the number on your card or the company’s official website.

    How do I teach my family?

    Share three rules: don’t click links in unexpected messages, never give a code or password to anyone who contacts you, and confirm any request for money with a phone call.

    What does a real example look like?

    Picture an email from “Microsoft 365 Support” that says your mailbox is full and will stop receiving mail today. A button reads “Increase storage.” The sender’s address ends in an unfamiliar domain, and the button leads to a login page that looks right and sits at the wrong web address. That one message shows urgency, a mismatched sender, and a mismatched link.

    Your next step

    Stay informed about the latest phishing methods, and teach yourself and your team how to spot them. Cerberus Cybersecurity offers training and awareness programs that use real examples and hands-on practice. Contact us to see how we can help your organization. Stay alert, stay safe, and keep your digital life secure.

  • The 5 Most Hacked Passwords (and What to Use Instead)

    The 5 Most Hacked Passwords (and What to Use Instead)

    By J. Mesa

    Attackers don’t break into most accounts. They log in. They take a list of the passwords people use most, try each one against your email or your bank, and move on to the next person. If your password sits on that list, the attack takes seconds and needs no skill.

    This post covers the passwords attackers try first, why they work, and the stronger habit I recommend to every client: the passphrase.

    What are the most common passwords?

    NordPass publishes a yearly study built from millions of passwords exposed in data breaches. In its 2025 report, these five led the United States list:

    1. admin
    2. password
    3. 123456
    4. 12345678
    5. 123456789

    The global list looks much the same, with 123456 in first place. Older favorites such as qwerty, 111111, and abc123 still rank high every year. The names change order. The pattern holds: short, predictable, and typed by millions of people.

    Why do hackers try these passwords first?

    Attackers don’t type guesses by hand. They run software that tests thousands of passwords per second, and that software starts with wordlists built from past breaches. Three common attacks rely on those lists:

    • Dictionary attack. The tool tries every word and common password on a list against one account.
    • Password spraying. The attacker tries one common password, such as Password1, against every employee in a company. One match gives them a way in.
    • Credential stuffing. The attacker takes email and password pairs leaked from one site and tries them on other sites. This works because people reuse passwords.

    A password from the top five fails all three attacks on the first try.

    Is adding a number or symbol enough?

    No. Attackers know the tricks. Their tools swap a for @, add 1 or ! to the end, and capitalize the first letter. Password1! sits at number 16 on the 2025 list.

    A short password full of symbols, such as x7g9@k2!, is also weak. Eight characters is short enough that cracking hardware can work through every combination when a site stores passwords poorly. It is also hard for you to remember, so you write it down or reuse it.

    Length beats complexity. Each character you add multiplies the work an attacker has to do.

    How long should a password be?

    The National Institute of Standards and Technology (NIST) writes the password guidance that most US security standards follow. Its current guidance, SP 800-63B, calls for at least 15 characters on an account protected by a password alone. It also tells organizations to stop requiring mixed character types and to accept long passwords of at least 64 characters.

    Fifteen random characters are hard to remember. Fifteen characters of words are easy. That is the case for a passphrase.

    What is a passphrase, and is it safer than a password?

    A passphrase is a string of several unrelated words. It runs longer than a traditional password, so it resists guessing and brute-force attacks, and you can remember it because you know the words.

    Compare the two. The password x7g9@k2! has 8 characters. The passphrase kadu tasi ayuyu babui has 21.

    That example uses words from Chamorro, my own language. Words from a language other than English make a passphrase stronger, because many attacker wordlists focus on English and on passwords leaked from English-language sites. The phrase means something to me and reads as gibberish to a cracking tool.

    How do I create a strong passphrase?

    1. Pick four or more words that have no connection to each other.
    2. Avoid quotes, song lyrics, and famous examples. If a phrase appears in a book or a movie, it appears in a wordlist.
    3. Mix in a word from another language, a place only you know, or an invented word.
    4. Aim for 15 characters or more.
    5. Use a different passphrase for every important account.

    A personal touch helps you remember it. Keep personal facts out of it. Your pet’s name, your birth year, and your street all show up on your social media, and attackers check there first.

    Do I need to change my password every 90 days?

    No. NIST now tells organizations to stop forcing password changes on a schedule. Forced changes push people toward weak patterns, such as Summer2025 turning into Fall2025. Change a password when you have a reason: a breach notice, a phishing link you clicked, or a shared login after someone leaves the company.

    How do I know if my password was exposed?

    Search your email address at haveibeenpwned.com, a free service that tracks breached accounts. Many password managers and browsers run the same check and warn you about exposed logins. If a password shows up in a breach, change it on that site and on every site where you reused it.

    How do I remember a different passphrase for every account?

    You don’t. Use a password manager. You remember one strong passphrase, and the manager creates and stores a unique password for each account.

    Then turn on multi-factor authentication (MFA) wherever a site offers it. With MFA, a stolen password alone does not open the account.

    What should a small business do about passwords?

    • Set a minimum length of 15 characters and drop the forced 90-day change.
    • Block the common passwords listed above. Most identity systems, including Microsoft 365, can do this.
    • Give every employee a password manager.
    • Require MFA on email, banking, and remote access.
    • Train your team to spot phishing. A passphrase does not help once someone types it into a fake login page.

    What makes a password weak?

    A password is weak when an attacker can predict it. Short length, common words, keyboard patterns such as qwerty, repeated characters, and personal details all make a password easy to predict. Reuse makes a strong password weak too, because one breached site exposes every account that shares it.

    Your next step

    Check your own accounts against the list in this post today. If you run a business and want help writing a password policy or training your team, contact Cerberus Cybersecurity. We put people first, and passwords are a people problem.

    A strong passphrase is your first line of defense. Treat it that way.