Category: Recommendations

  • Is Online Shopping Safe? 9 Tips for Secure Shopping

    By J. Mesa

    Shopping from home is convenient, and most of the time it is safe. The trouble comes from a small number of fake stores, stolen accounts, and scam messages. A few habits protect you from nearly all of them.

    Here are nine tips to help you shop online with confidence, in the holiday season and all year.

    Is online shopping safe?

    Yes, when you buy from retailers you can verify and pay with a method that protects you. The risk rises when you follow a link from an ad or a message, buy from a store you have never heard of, or pay in a way you can’t reverse.

    1. How do I check that a website is secure?

    Look for “HTTPS” at the start of the web address and a lock icon in the address bar. They show that the site encrypts the information you send.

    Encryption is the minimum. Scam sites use HTTPS too, so treat the lock as one check among several.

    2. How do I know an online store is legitimate?

    • Read the web address carefully for misspellings
    • Look for a physical address, a phone number, and a return policy
    • Search the store’s name with “reviews” and “scam”
    • Check how long the site has existed. A store created last month with huge discounts is a warning.
    • Be wary of sites that accept only wire transfers, payment apps, or cryptocurrency

    When in doubt, buy the item from a retailer you already know.

    3. Why should I use strong, unique passwords?

    A store account holds your address, your order history, and often a saved card. If you reuse a password and one site is breached, attackers try that password everywhere.

    Avoid passwords such as “123456” or “password.” Use a password manager to create and store a different password for each account.

    4. Should I turn on two-factor authentication for shopping accounts?

    Yes. Turn it on for your email first, since password resets go there, and then for the retailers and payment services you use most. With two-factor authentication, a stolen password alone does not open the account.

    5. How do I avoid phishing while shopping?

    Scammers send fake order confirmations, shipping notices, and “problem with your payment” alerts.

    • Don’t click links in messages about orders you don’t remember
    • Open the retailer’s app or type its address yourself to check an order
    • Never enter your password or card number on a page you reached from a link

    6. Why does the privacy policy matter?

    A privacy policy tells you what a store collects and who it shares it with. Before you buy from an unfamiliar site, skim it. Avoid stores with no policy or one that is vague about selling your data.

    7. Is a credit card safer than a debit card?

    Yes. In the United States, federal law limits your liability for fraudulent credit card charges, and most issuers set it at zero. You dispute the charge while the bank’s money is at stake.

    A debit card pulls money directly from your bank account. Your protection depends on how fast you report the fraud, and you wait for the money to come back.

    8. Should I save my card on shopping sites?

    Saving a card is convenient, and it means a breach of that store or your account exposes it. Save cards only with retailers you use often and trust. For one-time purchases, check out as a guest. Digital wallets such as Apple Pay and Google Pay add protection, because they give the store a one-time code in place of your card number.

    9. Is it safe to shop on public Wi-Fi?

    Avoid it for purchases. Public networks are shared, and an attacker can set up a fake hotspot. Use your phone’s mobile data or a VPN when you buy something away from home.

    How do I shop safely on social media and marketplaces?

    • Pay through the platform’s checkout, which carries buyer protection
    • Don’t move the conversation or the payment off the platform
    • Be wary of sellers with new accounts and stock photos
    • Meet in a public place for local pickups

    What are the signs of a scam deal?

    • A price far below every other seller
    • A countdown timer pushing you to buy now
    • A request for payment by gift card, wire, or payment app
    • A seller who avoids questions

    If a deal looks too good to be true, it is.

    How do I monitor my accounts after I shop?

    • Turn on transaction alerts from your card issuer
    • Review statements each week during heavy shopping periods
    • Check your credit reports, which are free at annualcreditreport.com
    • Keep order confirmations until the items arrive

    What should I do if I am scammed?

    1. Contact your card issuer and dispute the charge.
    2. Change the password on the affected account.
    3. Report the seller to the platform.
    4. Report the scam at reportfraud.ftc.gov and to the FBI at ic3.gov.
    5. Watch your accounts for more charges.

    Act fast. Disputes have deadlines.

    What if an order never arrives?

    Contact the seller first and keep a record of the conversation. If the seller does not respond or refuses a refund, file a dispute with your card issuer. Card networks allow a dispute for goods that were not delivered, and the issuer will ask for your order confirmation and the messages you exchanged.

    Does my business need to think about this?

    If you sell online, your customers are asking the same questions about you.

    • Use a reputable payment processor and never store card numbers yourself
    • Keep your website and plugins updated
    • Publish a clear privacy policy, return policy, and contact details
    • Follow PCI-DSS, the security standard for businesses that accept cards

    If employees buy for the company, give them a company card with alerts and a simple approval rule.

    Your next step

    Before your next purchase, turn on two-factor authentication for your email and set up transaction alerts on your card. Those two steps catch most problems early. If you run an online store and want to know how well you protect your customers, contact Cerberus Cybersecurity about a risk and compliance assessment.

  • Black Friday and Cyber Monday Scams: How to Shop Safely

    By J. Mesa

    It’s that time again! Black Friday and Cyber Monday bring some of the best prices of the year. They also bring scammers, who know that shoppers in a hurry check fewer details.

    Here is how to get the deals and keep your money.

    Why do scammers love Black Friday?

    • Shoppers expect big discounts. A fake 80 percent discount looks plausible for one week of the year.
    • Deals have deadlines. Real time limits make fake urgency harder to spot.
    • Inboxes overflow. A scam email hides among hundreds of real promotions.
    • People try new stores. A shopper chasing a deal will buy from a site they have never used.

    What are the most common Black Friday scams?

    • Fake online stores that take payment and send nothing, or send a counterfeit
    • Phishing emails and texts that imitate real retailers
    • Fake order and delivery notices that link to malicious sites
    • Social media ads for products that don’t exist
    • Bogus coupon and gift card offers that collect personal details
    • Counterfeit apps that imitate a retailer’s shopping app

    How do I know a website is secure?

    Before you enter a card number, check that the address starts with “HTTPS” and shows a lock icon. That means the site encrypts what you send.

    The lock does not prove the store is real. Fake stores use encryption too. Use the next section to check the seller.

    How do I spot a fake store?

    • Check the address. Look for misspellings, extra words, or an unusual ending.
    • Look for contact details and a return policy.
    • Search for reviews on independent sites, not only on the store itself.
    • Compare prices. A price far below every competitor is a warning.
    • Check the payment options. A store that takes only wire transfers, payment apps, or cryptocurrency is unsafe.
    • Look at the writing and images. Copied photos and awkward text suggest a quick copy of another site.

    How do I tell a real deal from a fake one?

    If a deal seems too good to be true, it is. Be careful with offers that:

    • Last only minutes and show a countdown timer
    • Ask for personal or financial details before you can “claim” them
    • Arrive by text or direct message from an unknown sender
    • Come through an ad for a store you can’t find elsewhere

    Go to the retailer’s own website by typing its address. If the deal is real, you will find it there.

    How do I protect my accounts?

    Create a strong, unique password for each online account and use a password manager to keep track. Turn on two-factor authentication for your email and your main shopping accounts. Those steps keep a breach at one store from spreading to the rest.

    Should I click links in sale emails and texts?

    Be careful. Scammers copy the design of real promotions. Even when a message comes from a company you shop with, confirm it before you click.

    • Check the sender’s full address
    • Hover over a link to see where it leads
    • Type the store’s address yourself when you are unsure

    What is the safest way to pay?

    • Use a credit card. It gives you the strongest fraud protection and a dispute process.
    • Use a digital wallet such as Apple Pay or Google Pay where a store offers it. The store never receives your card number.
    • Avoid debit cards for online purchases. Fraud takes money straight from your account.
    • Never pay a seller by wire transfer, gift card, or cryptocurrency.

    What should I avoid posting on social media?

    Be careful about what you share during the season.

    • Don’t announce that you are out of town
    • Don’t post photos of expensive new purchases
    • Don’t share order confirmations or tracking numbers

    That information tells burglars and package thieves when and where to look.

    How do I keep my packages safe?

    • Track deliveries and bring packages in the same day
    • Use a pickup locker or ship to your workplace if nobody is home
    • Require a signature for expensive items
    • Ask a neighbor to collect packages when you travel

    How do I shop safely on my phone?

    • Download shopping apps only from the official app store
    • Check the developer’s name and the number of reviews
    • Keep your phone’s software up to date
    • Avoid making purchases on public Wi-Fi. Use mobile data.

    How do I prepare before Black Friday?

    1. Update your computer, phone, and browser.
    2. Turn on two-factor authentication for your email.
    3. Set up transaction alerts with your card issuer.
    4. Make a list of what you want and where you will buy it.
    5. Bookmark those stores, so you don’t need to follow links.

    A plan keeps you from making rushed decisions when the sales start.

    What should I do if I fall for a scam?

    1. Call your card issuer and dispute the charge.
    2. Change the password on any account you used.
    3. Report the scam at reportfraud.ftc.gov and to the FBI at ic3.gov.
    4. Report the fake store or ad to the platform where you found it.
    5. Watch your statements for further charges.

    How should a small business prepare?

    If you sell during the holiday rush, criminals target you too.

    • Update your website, shopping cart, and plugins before the season
    • Watch for unusual orders, such as many small test charges
    • Warn staff about fake supplier invoices and gift card requests
    • Tell customers how you will contact them, so they can spot impostors

    Are buy now, pay later plans safe?

    They are legitimate services, and they carry weaker dispute rights than a credit card in some cases. Read the terms before you use one, and sign up through the retailer’s checkout or the provider’s own app. Scammers send fake “payment overdue” messages in the names of these services, so check your balance in the app, not through a link.

    Your next step

    Bookmark your favorite stores and set up card alerts before the sales begin. With those two steps and the checks above, you protect yourself and your loved ones from scammers this season. Happy shopping! If your business wants its team ready for the holiday rush, contact Cerberus Cybersecurity about our cybersecurity training.

  • How to Secure Your Small Business Online: 10 Expert Tips

    By J. Mesa

    Your online presence is your storefront. Your website, email, domain name, social media, and business listings are how customers find and trust you. An attacker who takes over any one of them can steal from you, pose as you, or shut you down.

    Cyberattacks can bring financial loss, damage to your reputation, and legal penalties. These ten tips protect the accounts and systems your business shows to the world.

    What is an online presence, and why protect it?

    Your online presence includes every account and service that represents your business:

    • Your domain name and website
    • Business email
    • Social media profiles
    • Business listings, such as your Google Business Profile
    • Online banking and payment accounts
    • Cloud storage and business applications

    Each one is a way in. Losing your domain or email account can take the others with it, because password resets flow through them.

    1. How do I create strong passwords for business accounts?

    Weak or easy-to-guess passwords are among the most common ways criminals get into accounts.

    • Use a long, unique password for every account
    • Never reuse a password
    • Use a password manager to create and store them
    • Give each employee their own login. Don’t share accounts.

    2. What is two-factor authentication, and should I use it?

    Two-factor authentication (2FA) adds a second proof of identity at login, such as a code from an app on your phone. With it on, a stolen password is not enough.

    Turn it on for every account that offers it. Start with email, your domain registrar, banking, and social media. An authenticator app or a security key is stronger than a text-message code.

    3. Why do updates matter?

    Criminals exploit flaws in outdated software and devices. Updates fix those flaws.

    • Turn on automatic updates for computers and phones
    • Update your website platform, themes, and plugins
    • Update routers, firewalls, and other network devices
    • Replace equipment that no longer receives security updates

    4. How do I handle emails and attachments safely?

    Phishing emails imitate people and companies you trust.

    • Check the sender’s full email address
    • Don’t click links or download attachments from unknown or unexpected senders
    • Confirm any request for money or a change in payment details by phone
    • Report suspicious messages to your IT contact

    5. How do I know a connection is secure?

    When you open financial accounts or enter personal information, check that the web address begins with “HTTPS” and shows a padlock icon. That means the site encrypts the data you send and receive.

    Your own website needs HTTPS as well. Browsers warn visitors away from sites without it, and search engines favor sites that have it.

    6. How do I monitor my accounts?

    • Review bank and card statements for transactions you don’t recognize
    • Check your business credit reports
    • Turn on login and transaction alerts
    • Look at the login history on your email and social accounts

    If you see something suspicious, contact your bank or card company right away and change the affected passwords.

    7. How do I protect my website?

    • Keep the platform and plugins updated, and remove the ones you don’t use
    • Use strong passwords and 2FA for every administrator
    • Limit the number of administrator accounts
    • Back up the site and store the backup somewhere else
    • Use a web application firewall, which many hosting and DNS providers include

    8. How do I protect my domain name?

    Your domain is the root of your online identity. If someone takes it, they control your website and your email.

    • Turn on 2FA at your domain registrar
    • Turn on the registrar lock, which blocks unauthorized transfers
    • Keep the contact email on the account current
    • Set the domain to renew automatically, so it never lapses

    9. How do I stop criminals from spoofing my email?

    Attackers send email that appears to come from your domain to trick your customers and staff. Three DNS records help prevent it:

    • SPF lists the servers allowed to send mail for your domain
    • DKIM adds a signature that proves a message was not altered
    • DMARC tells receiving mail servers what to do with messages that fail those checks

    Your email provider or IT contact can set these up. A DMARC policy of “quarantine” or “reject” gives the strongest protection.

    10. How do I secure my social media and business listings?

    • Use a unique password and 2FA on every profile
    • Assign roles to staff through the platform’s business tools. Don’t share one login.
    • Remove access when an employee or agency leaves
    • Claim your business listings, so nobody else does
    • Watch for fake profiles that copy your name and logo, and report them

    What should I do if an account is hacked?

    1. Change the password from a clean device.
    2. Sign out of all other sessions.
    3. Turn on 2FA.
    4. Check for changes: forwarding rules, new administrators, new payment details.
    5. Tell customers and partners if the attacker sent messages as you.
    6. Use the platform’s recovery process if you are locked out.
    7. Report fraud to your bank and at ic3.gov.

    How often should I review my online security?

    Review it every quarter. Check who has access, confirm that updates and backups ran, and test that you can recover an account. Review again whenever an employee or vendor leaves.

    Are these steps enough?

    No security measure is foolproof. These practices cut your risk sharply and help keep your business and your customers’ information safe. Businesses that hold regulated data or serve larger clients should add written policies, employee training, and a regular risk assessment.

    What is the most common way a small business loses an account?

    A reused password and no second step at login. An employee uses the same password for a business account and a personal one. The personal site is breached, criminals try the leaked password on the business account, and it works. A password manager and two-factor authentication close that route, which is why they come first on this list.

    Your next step

    Turn on two-factor authentication for your email and your domain registrar today. Those two accounts protect all the others. To see how we can help with your cybersecurity goals, contact us or write to [email protected]. At Cerberus Cybersecurity, we believe in people first.

  • Cybersecurity Training for Employees: Why It Matters and What to Teach

    By J. Mesa

    One of the most important steps a small business owner can take against cyber threats is to educate employees. Staff who can recognize phishing and other common tactics reduce the chance that your systems get compromised.

    This guide explains why training matters, what to teach, and how to make it stick.

    Why is employee cybersecurity training important?

    Attackers target people because people are easier to fool than software. An employee who clicks a malicious link or shares a password can undo the best security tools.

    Training turns that weakness into a defense. An employee who spots a suspicious email and reports it protects the whole company.

    What are the benefits of training?

    • A stronger defense. Even with the best security systems and software, attackers get in through employees. Trained staff catch attacks that technology misses.
    • Fewer costly mistakes. A small business faces real risk from an employee who clicks a phishing link or gives a password to the wrong person. Training on best practices prevents those mistakes.
    • Better morale and productivity. Training shows your employees that you value their safety. That supports a positive workplace, and people use the same skills to protect their families.
    • Protection for your customers and your reputation. A breach brings financial loss and lost trust. Staff who know how to protect your systems prevent incidents.

    What topics should training cover?

    1. Phishing and social engineering. How to spot fake emails, texts, and calls, with real examples.
    2. Passwords and multi-factor authentication. How to use a password manager and why the second step matters.
    3. Safe handling of data. What counts as sensitive, where to store it, and how to share it.
    4. Device security. Updates, screen locks, and what to do with a lost phone or laptop.
    5. Safe browsing and downloads. Which sites and files to avoid.
    6. Remote work and travel. Public Wi-Fi, home networks, and working in public places.
    7. Payment and invoice fraud. How to verify a request for money or a change in bank details.
    8. Reporting. Who to tell, how, and how fast.

    Match the topics to each role. Staff who handle money need more on payment fraud. Managers need more on impersonation.

    How often should employees be trained?

    • At hire, before they get access to systems
    • At least once a year for everyone
    • In short refreshers through the year, such as a monthly five-minute tip
    • After any incident or near miss

    One long annual session fades within weeks. Short, frequent lessons keep the habits alive.

    What makes training effective?

    • Keep it short. Ten to twenty minutes per session.
    • Make it relevant. Use examples from your own industry and your own inbox.
    • Make it practical. Show people what to do, not only what to fear.
    • Practice. Simulated phishing emails give staff a safe place to make mistakes.
    • Explain the reason. People follow rules they understand.
    • Include everyone. Owners and executives are frequent targets and need the training most.

    What is a phishing simulation?

    A phishing simulation is a harmless test email that imitates a real attack. It shows who clicks and who reports. Run one every month or quarter, and use the results to guide your next training.

    Never use a simulation to embarrass or punish. Staff who fear blame stop reporting, and silence is what attackers count on.

    How do I build a security culture?

    • Thank people who report suspicious messages, including false alarms
    • Treat an honest mistake as a chance to learn
    • Talk about security in staff meetings
    • Make the safe way the easy way, with tools such as a password manager
    • Lead by example. If the owner skips the rules, so will everyone else.

    Culture decides what people do when nobody is watching.

    How do I measure whether training works?

    • The click rate on simulated phishing emails over time
    • The number of suspicious emails staff report
    • How fast people report after a test or a real attempt
    • Training completion rates
    • The number of incidents caused by human error

    A falling click rate and a rising report rate tell you the training is working.

    Is training required by law or by insurers?

    Often, yes. Standards such as PCI-DSS and HIPAA call for security awareness training. The FTC Safeguards Rule requires it for covered financial businesses. Cyber insurers ask about it on applications, and some clients write it into contracts. Keep records of who completed training and when.

    How much does training cost?

    Costs range from free resources published by CISA and the FTC to paid online platforms and live sessions with a consultant. Compare the price with the cost of one wire fraud or one ransomware incident. Training is among the cheapest protections you can buy.

    What mistakes should I avoid?

    • Running training once and never again
    • Using generic material that has nothing to do with your business
    • Relying on fear
    • Skipping contractors and part-time staff
    • Leaving out the reporting process
    • Treating a completed quiz as proof of changed behavior

    How do I train a remote team?

    • Deliver sessions by video and record them
    • Use short online modules people can complete on their own schedule
    • Cover home network basics, such as router passwords and updates
    • Give remote staff a clear way to report problems outside office hours

    How do I get started?

    1. Pick the three topics that matter most to your business. Phishing belongs on every list.
    2. Schedule a 20-minute session this month.
    3. Set up a simple way to report suspicious messages.
    4. Plan short refreshers for the rest of the year.
    5. Record attendance.

    Who should run the training?

    A trusted manager can deliver the basics with free material from CISA. An outside trainer adds current examples, answers hard questions, and gets attention that an internal memo does not. Many small businesses combine the two: a consultant leads one live session a year, and a manager sends short reminders in between.

    Your next step

    Employee education on cybersecurity is essential to the security and success of your small business. Training and support give your team the means to protect your systems against cybercriminals. Contact us or write to [email protected] to see how our cybersecurity training can meet your goals. At Cerberus Cybersecurity, we believe in people first.

  • How to Write a Small Business Cybersecurity Plan in 7 Steps

    By J. Mesa

    As a small business owner, you protect your company from many threats. You lock the doors, buy insurance, and keep the books in order. Many small businesses skip the same care for cybersecurity.

    Every small business needs a cybersecurity plan to protect its data, its customers, and its bottom line. Without one, you are open to criminals who look for weaknesses to exploit. This guide shows you how to write a plan that works and that you can put in place.

    What is a cybersecurity plan?

    A cybersecurity plan is a written document that states what your business needs to protect, how you protect it, who is responsible, and what you do when an incident occurs. For a small business, a few pages is enough.

    Why does every small business need one?

    • It sets priorities. You spend time and money on your biggest risks first.
    • It prevents panic. In an incident, people follow the plan and don’t improvise.
    • Clients and insurers ask for it. Contracts and policy applications now request proof.
    • Rules require it. The FTC Safeguards Rule, HIPAA, and PCI-DSS all call for a written security program.

    What should the plan include?

    • An inventory of your assets and data
    • Your main risks
    • Policies and procedures
    • The security measures you use
    • A training schedule
    • An incident response section
    • A schedule for review

    The seven steps below build each part.

    Step 1: Identify your assets

    List what you need to protect:

    • Computers, phones, servers, and network equipment
    • Software and online services
    • Customer data, employee records, and financial information
    • Accounts: email, banking, domain, social media

    Note where each item lives and who can access it. You can’t protect what you haven’t listed.

    Step 2: Identify your vulnerabilities and risks

    For each asset, ask three questions:

    1. What could go wrong? Think of theft, ransomware, loss, or an honest mistake.
    2. How likely is it?
    3. How badly would it hurt?

    Rank the results. The items that are both likely and damaging go to the top. A simple high, medium, low scale works.

    Step 3: Develop policies and procedures

    Write short, clear rules for how your business protects its assets. Start with these:

    • Password policy. Unique passwords, a password manager, and multi-factor authentication.
    • Acceptable use. What staff may do on company devices and networks.
    • Access control. Who gets access to what, and how you remove it when someone leaves.
    • Data handling. How you store, share, and dispose of sensitive information.
    • Remote work. Rules for home networks, personal devices, and public Wi-Fi.
    • Vendor management. How you check the companies that hold your data.

    Keep each policy to a page. People follow rules they can read in five minutes.

    Step 4: Implement security measures

    Put the tools in place that carry out your policies:

    • Multi-factor authentication on email, banking, and remote access
    • Automatic updates on all devices
    • A firewall and security software
    • Encryption on laptops and phones
    • Backups that follow the 3-2-1 rule: three copies, two types of storage, one offsite
    • Email filtering

    Start with the measures that address your top-ranked risks.

    Step 5: Train your employees

    Your plan depends on the people who follow it.

    • Train every employee when they join and at least once a year
    • Teach them to recognize phishing and other common scams
    • Explain each policy and the reason for it
    • Make reporting simple and free of blame

    Step 6: Plan your incident response

    Decide now what you will do when something goes wrong. Write down:

    • Who leads the response
    • Who to call: IT provider, cyber insurer, attorney, bank
    • How to isolate affected systems
    • How to reach staff if email is down
    • How and when you notify customers and regulators
    • Where the backups are and how to restore them

    Print this section. You can’t open a file on a locked computer.

    Step 7: Monitor and update the plan

    A cybersecurity plan is a living document. Review it:

    • Once a year
    • After any incident or near miss
    • When you add a new system, vendor, or location
    • When laws or contract requirements change

    Check each quarter that the measures in the plan are still running: updates, backups, and access reviews.

    How long should the plan be?

    For a business with fewer than 50 people, five to ten pages covers it. A short plan that people use beats a long one that sits in a drawer.

    Who should write it?

    The owner or a senior manager should own it, with input from whoever handles IT. A cybersecurity consultant can speed the work and bring experience from other businesses. The plan must reflect how your company operates, so someone inside has to be involved.

    What frameworks can I use as a guide?

    You don’t need to start from a blank page.

    • NIST Cybersecurity Framework. A widely used structure built around identifying, protecting, detecting, responding, and recovering.
    • CIS Critical Security Controls. A prioritized list of safeguards, with a starter group suited to small organizations.
    • FTC guidance for small business. Plain-language guides at ftc.gov.

    Pick one and adapt it to your size.

    What mistakes should I avoid?

    • Copying a template without changing it to fit your business
    • Writing the plan and never testing it
    • Leaving out the incident response section
    • Forgetting vendors and cloud services
    • Assigning no owner

    How do I test the plan?

    Run a tabletop exercise once a year. Gather the people named in the plan, describe a realistic incident, and walk through each step. You will find missing phone numbers and unclear roles. Fix them while the stakes are low.

    Is a cybersecurity plan the same as an incident response plan?

    No. The incident response plan is one section of the larger document. The cybersecurity plan covers prevention, training, and review as well as response. A business needs both, and writing the full plan produces the response section along the way.

    Your next step

    Start with Step 1 this week. List your assets and data on a single page. Following these seven steps gives you a plan that protects your small business from the growing threat of cyberattacks. Don’t wait until it’s too late. Cerberus Cybersecurity offers policy and documentation development to help you write a plan that fits. Contact us or write to [email protected].

  • Online Safety for Students: A Guide for Parents and Teachers

    By J. Mesa

    As students head back to school, parents and educators worry about the risks that come with more time online. Cyberbullying, scams, and strangers with bad intentions make the internet a dangerous place for young people.

    Students stay safe when adults teach them the risks and give them the tools to protect themselves. This guide covers both.

    What are the biggest online risks for students?

    • Cyberbullying. Harassment through messages, posts, and group chats
    • Online predators. Adults who pose as peers to build trust
    • Scams and phishing. Fake prizes, game currency offers, and messages that steal accounts
    • Oversharing. Personal details and photos that can’t be taken back
    • Inappropriate content. Material that is not suited to their age
    • Sextortion. Criminals who trick or pressure a young person into sending an image, then demand money or more images

    How do I set rules for internet use?

    Before students use the internet for school, set clear boundaries.

    • Agree on screen time limits and device-free times, such as meals and bedtime
    • Decide which websites, apps, and games are allowed
    • Keep devices in shared rooms for younger children
    • Explain that you will check on their activity, and why

    Write the rules down as a family agreement. Children follow rules they helped create.

    How do I teach students to protect personal information?

    One of the largest risks for young people is that others misuse their personal information. Teach them to keep these private:

    • Full name, home address, and phone number
    • School name and schedule
    • Passwords, even from friends
    • Photos that show their location or school uniform

    A simple test helps: “Would I be comfortable if a stranger, my teacher, or my grandmother saw this?”

    What is cyberbullying, and what should I do about it?

    Cyberbullying is repeated, hurtful behavior carried out through technology. Signs that a child is a target include avoiding their device, a sudden change in mood after being online, and reluctance to go to school.

    If it happens:

    1. Listen, and stay calm. Don’t take the device away as a first response, because children then hide problems.
    2. Save the evidence with screenshots.
    3. Block the person and report them to the platform.
    4. Tell the school if other students are involved.
    5. Contact the police if there are threats of violence.

    How do I talk to children about online predators?

    Use plain language that fits their age.

    • People online are not always who they say they are.
    • Never agree to meet someone you know only from the internet.
    • An adult who asks you to keep a secret from your parents is a warning sign.
    • If anyone asks for a private photo, stop, and tell a trusted adult.

    Make sure they know they will not be in trouble for telling you. Predators and extortionists rely on a child’s fear of punishment.

    If a child is threatened or pressured for images, do not pay and do not delete the messages. Report it to the platform and to the National Center for Missing and Exploited Children at CyberTipline.org, or contact the FBI.

    How do I encourage open communication?

    A student who sees something that makes them uncomfortable needs to feel safe talking about it.

    • Ask about their online life the way you ask about their day
    • Learn the apps and games they use
    • Thank them when they bring you a problem
    • React calmly

    Remind them that they can report any concern to a trusted adult: a parent, a teacher, or a school counselor.

    What parental controls should I use?

    Parental control tools and filters help you monitor activity and block inappropriate content.

    • Device settings. Screen Time on Apple devices and Family Link on Android set limits and content filters.
    • App and game settings. Most platforms offer restricted modes and privacy controls.
    • Home network. Many routers include filtering and schedules.
    • App store approvals. Require permission before a download or purchase.

    Tools support your conversations. They do not replace them.

    What is the right age for a phone or social media?

    There is no single answer. Most social media platforms set a minimum age of 13 in their terms. Consider your child’s maturity, their need to reach you, and your ability to supervise. A basic phone or a device with strong limits is a reasonable first step.

    How do I teach students about scams?

    Young people see fake giveaways, offers of free game currency, and messages from “friends” whose accounts were stolen. Teach three rules:

    1. Nobody gives away valuable things for free online.
    2. Never enter a password on a page you reached from a link in a message.
    3. Check with an adult before you buy, download, or sign up.

    What is a digital footprint, and why does it matter to students?

    Everything a student posts builds a record that can last for years. Colleges, scholarship committees, and employers look. Encourage students to post what they would be proud of later, and to ask before they post photos of friends.

    How do I secure a student’s accounts and devices?

    • Use a strong, unique password for each account, with a password manager for older students
    • Turn on two-factor authentication
    • Set profiles to private
    • Turn on automatic updates
    • Turn off location sharing in apps that don’t need it
    • Cover or disable webcams when not in use

    What should schools do?

    • Teach digital citizenship at every grade level
    • Publish clear rules for school devices and accounts
    • Give students and parents a simple way to report problems
    • Protect student data, and check the privacy practices of educational apps
    • Train teachers and staff on current online threats

    Are AI chatbots and image tools a risk for students?

    They can be. Remind students not to share personal details with a chatbot, and that anything a tool produces may be wrong. Explain that fake images and videos of real people are easy to create, that making them of classmates causes real harm, and that it carries serious consequences.

    Your next step

    Have one conversation with your child this week about what they do online, and set up the family agreement together. With the right knowledge and tools, students enjoy the benefits of the internet and stay safe from its risks. If your school or organization wants a session on online safety, contact Cerberus Cybersecurity about our cybersecurity training.

  • Cyber Hygiene Checklist: 12 Habits for Remote and Hybrid Work

    By J. Mesa

    When the COVID-19 pandemic sent people home, hackers and scammers followed. They sent fake health alerts, targeted home networks, and took advantage of people doing their banking and their jobs from the kitchen table.

    Remote and hybrid work stayed. So did the threats. This checklist gives you the habits that keep you and your information safe.

    What is cyber hygiene?

    Cyber hygiene is the set of routine habits that keep your devices, accounts, and data healthy. Like washing your hands, each step is small and works because you repeat it.

    Why does remote work raise the risk?

    • Home networks are less protected than office networks.
    • Personal and work devices mix. Family members share computers and Wi-Fi.
    • Coworkers are not nearby. You can’t lean over and ask, “Did you send this?”
    • Attackers adapt to the news. Any crisis produces scams within days.

    1. How do I spot crisis-related scams?

    Scammers use emergencies to trick people into giving up information or money. During the pandemic they posed as government agencies and healthcare organizations. They do the same after storms, during tax season, and around benefit programs.

    • Be cautious with emails, texts, and calls that claim to come from a government agency or a health organization
    • Never click links or give personal information unless you have confirmed the source
    • Go to the agency’s official website by typing its address yourself

    2. Use strong, unique passwords

    Using one password for many accounts lets an attacker open all of them at once. Use a different, long password for each account. A password manager stores them, so you don’t have to remember them all.

    3. Turn on multi-factor authentication

    Add a second step at login for email, banking, and work accounts. A stolen password alone then fails.

    4. How do I secure my home Wi-Fi?

    • Change the router’s default administrator password
    • Use WPA2 or WPA3 encryption with a strong Wi-Fi password
    • Update the router’s software, or replace a router that no longer gets updates
    • Set up a guest network for visitors and smart devices
    • Turn off remote management if you don’t use it

    5. Keep every device updated

    Turn on automatic updates for computers, phones, tablets, and browsers. Restart when asked. Update smart home devices too.

    6. Separate work and personal use

    • Use your work device for work only
    • Don’t let family members use it
    • Keep work files in the systems your employer approves, not in personal email or cloud accounts

    7. Use a VPN when your employer provides one

    A virtual private network encrypts your connection to company systems. Use it on public Wi-Fi and wherever your employer requires it.

    8. Be careful with personal information

    Scammers look for ways to collect your name, address, Social Security number, and card details. Before you give personal information online, confirm who is asking and why.

    9. Watch for shopping and financial scams

    More shopping moved online, and scammers stepped up their efforts to steal payment data.

    • Buy from retailers you can verify
    • Pay with a credit card
    • Be wary of fake investment offers and requests for payment up front

    10. Secure your video calls

    • Use a meeting password or a waiting room
    • Don’t post meeting links in public
    • Check who is in the call before you discuss anything sensitive
    • Look at what is visible behind you and on your shared screen

    11. Lock your screen and protect your devices

    • Set a screen lock that starts after a few minutes
    • Encrypt laptops and phones
    • Don’t leave devices in a car or unattended in public
    • Report a lost or stolen work device right away

    12. Back up your work

    Save work files in the company’s approved storage, where backups run. For personal files, keep a copy on an external drive or in a cloud service.

    How do I verify a request from a coworker or boss?

    Attackers pose as managers and ask for gift cards, wire transfers, or login details. When a message asks for money, credentials, or a change in payment details, confirm it by phone or video with a number you already have. A two-minute call stops the most costly fraud a business faces.

    What should an employer do for remote staff?

    • Provide company devices with security software and encryption
    • Require multi-factor authentication and a VPN
    • Write a short remote work policy
    • Train staff on home network security and scams
    • Give people a way to report problems outside office hours
    • Remove access as soon as someone leaves

    Is it safe to work from a café or an airport?

    It can be, with care. Use a VPN or your phone’s hotspot. Sit where nobody can read your screen, or use a privacy filter. Don’t take sensitive calls where others can hear. Never leave your device unattended.

    How do I dispose of work documents at home?

    Shred printed papers that carry customer, employee, or financial details. Don’t put them in household recycling. Return old company devices to your employer for secure wiping, and never sell or donate a personal device before you erase it.

    How often should I run through this checklist?

    Review it every three months. Check that updates ran, that your router is current, and that you still recognize every device on your home network.

    What should I do if something goes wrong?

    1. Disconnect the device from the network.
    2. Tell your employer’s IT contact right away.
    3. Change your passwords from a different device.
    4. Call your bank if money or card details are involved.
    5. Report scams at reportfraud.ftc.gov.

    Do smart home devices put my work at risk?

    They can. Cameras, speakers, and TVs often run old software and share the network with your work laptop. Put them on a guest network, change their default passwords, and update them. That way a weak device can’t reach your work computer.

    Your next step

    Pick three items from this checklist and do them today. Start with your router password, multi-factor authentication, and automatic updates. No security measure is foolproof, and these habits go a long way toward keeping your personal and financial information safe. If your business has remote staff, Cerberus Cybersecurity can help with policies and training for a distributed team. Contact us to learn more.

  • How to Protect Your Financial Information Online: 10 Steps

    By J. Mesa

    You bank, pay bills, invest, and shop online. That convenience puts your financial information within reach of hackers and scammers, who keep finding new ways to get at your data and your money.

    Here are ten steps that keep your eye on the money, followed by what to do if something goes wrong.

    How do criminals steal financial information?

    • Phishing. Fake messages from “your bank” lead to fake login pages.
    • Data breaches. A company you do business with loses your details.
    • Reused passwords. Attackers try leaked passwords on banking and payment sites.
    • Malware. Malicious software records what you type.
    • Phone scams. A caller poses as your bank’s fraud team.
    • Card skimmers. Devices on gas pumps and ATMs copy your card.
    • Account takeover. A criminal resets your password through your email.

    1. Use strong, unique passwords

    Using the same password for several accounts lets an attacker open all of them with one leak. Use a different, long password for every financial account. A password manager creates and stores them.

    2. Turn on multi-factor authentication

    Add a second step at login for your bank, card, investment, and payment accounts. Add it to your email too, because password resets go there. An authenticator app is stronger than a code sent by text.

    3. Set up account alerts

    Turn on alerts for every transaction, login from a new device, and change to your contact details. An alert lets you catch fraud in minutes.

    4. Be careful with personal information

    Scammers try to collect your name, address, Social Security number, and card details. Before you give personal information online, confirm the person or company that is asking. Your bank will not ask for your password or a one-time code by phone, text, or email.

    5. Keep software and devices up to date

    Hackers exploit flaws in outdated software. Use the latest versions of your operating system, browser, and banking apps, and turn on automatic updates.

    6. Use security software and a firewall

    Security software and firewalls help block malware and unwanted connections. Run them on all your devices and keep them updated.

    7. Shop with care

    • Buy from retailers you can verify
    • Check that the site uses HTTPS before you enter card details
    • Pay with a credit card or a digital wallet
    • Avoid saving your card on sites you seldom use

    8. Use secure networks for banking

    Don’t log in to financial accounts on public Wi-Fi. Use your home network, your phone’s mobile data, or a VPN.

    9. Freeze your credit

    A credit freeze blocks anyone from opening new credit in your name. It is free. Place one with each of the three bureaus: Equifax, Experian, and TransUnion. Lift it for a short time when you apply for credit.

    10. Review your accounts and credit reports

    • Check bank and card statements every week
    • Get your free credit reports at annualcreditreport.com
    • Look for accounts and inquiries you don’t recognize

    How do I know if my financial information was stolen?

    • Charges or withdrawals you did not make
    • Bills or collection notices for accounts you never opened
    • A drop in your credit score with no cause
    • Missing mail, or statements that stop arriving
    • A notice that your information was part of a data breach
    • A rejected tax return because someone already filed with your number

    What should I do if my card or account is compromised?

    1. Call your bank or card issuer using the number on the back of your card. Ask them to block the card and dispute the charges.
    2. Change your passwords for the affected account and your email.
    3. Place a fraud alert or a credit freeze with the credit bureaus.
    4. Report identity theft at IdentityTheft.gov, the Federal Trade Commission’s recovery site. It gives you a step-by-step plan.
    5. Report the fraud to the FBI at ic3.gov.
    6. Keep records of every call and letter.

    Report fast. Your legal protections depend on how soon you notify the bank.

    Is online banking safe?

    Yes, when you take the steps above. Banks invest in security, encrypt your connection, and monitor for fraud. Most losses happen when a customer is tricked into giving away credentials or approving a transfer. Your habits are the layer the bank can’t supply.

    Are payment apps safe?

    Apps such as Zelle, Venmo, and Cash App are safe for paying people you know. They move money fast, and a payment you authorized is hard to reverse. Scammers know this.

    • Send money only to people you know and trust
    • Confirm the recipient’s phone number or username before you send
    • Turn on a PIN or biometric lock in the app
    • Never send a payment to “verify” your account or to receive a refund

    Is a credit card safer than a debit card?

    For online purchases, yes. US federal law caps your liability for unauthorized credit card charges at $50, and most issuers waive even that. With a debit card the money leaves your bank account, and your protection shrinks the longer you wait to report.

    How do I protect my business finances?

    • Use a dedicated computer or browser for online banking
    • Require two people to approve wire transfers and new payees
    • Confirm any change in a vendor’s bank details by phone, using a number you already have
    • Turn on multi-factor authentication and alerts for every business account
    • Review account activity every day
    • Train staff who handle money to spot invoice and payroll fraud

    Business email compromise, where a criminal poses as an owner or vendor to redirect a payment, costs businesses more than any other online fraud. The phone call to confirm is your best defense.

    How do I spot a fake call or text from my bank?

    • It asks for your password, PIN, or a one-time code
    • It tells you to move money to a “safe account”
    • It pressures you to act right now
    • The caller ID shows the bank’s name, which criminals can fake

    Hang up, and call the number on your card.

    Should I pay for identity theft protection?

    A paid service watches for your data and helps with recovery. It can’t prevent theft. You can do the most effective steps yourself for free: freeze your credit, turn on alerts, and review your reports. Consider a paid service if you want the monitoring handled for you.

    Your next step

    Turn on transaction alerts and multi-factor authentication for your main bank account today. Following these steps protects your financial information and lowers your risk of becoming a victim. If your business wants to protect its accounts and train the staff who handle payments, contact Cerberus Cybersecurity about our cybersecurity training.

  • Travel Cybersecurity: 12 Tips to Protect Your Data on the Go

    By J. Mesa

    More people travel for work and leisure each year, and each trip puts your devices and data in unfamiliar places. Airports, hotels, and cafés are where attackers look for easy targets.

    Here are twelve tips to protect your privacy and personal data while you travel, organized by what to do before, during, and after the trip.

    What are the biggest cybersecurity risks when traveling?

    • Public Wi-Fi in airports, hotels, and cafés
    • Lost or stolen devices
    • Shoulder surfing, where someone reads your screen or watches you type
    • Public charging stations and shared computers
    • Travel scams, such as fake booking sites and phishing emails about your reservation
    • Card fraud at unfamiliar ATMs and shops

    What should I do before I leave?

    1. Update your software. Install updates for your operating system, apps, and security software. Updates fix known flaws that attackers exploit.
    2. Back up your devices. If a phone or laptop is lost, you keep your data.
    3. Turn on device encryption and a strong screen lock.
    4. Turn on “Find My” tracking and remote wipe for phones and laptops.
    5. Tell your bank and card issuer about your travel dates if they ask for notice, and turn on transaction alerts.
    6. Travel light. Leave devices and data you don’t need at home.

    1. Use a VPN

    A virtual private network encrypts your internet connection. That makes it harder for others on the same network to see what you do. Use one on any network you don’t control.

    2. Use a password manager

    A password manager creates and stores a strong, unique password for each account. If one account is exposed during your trip, the rest stay safe.

    3. Avoid public Wi-Fi

    Public networks are often unsecured, and attackers set up fake hotspots with names like the real one. Use your phone’s mobile data or hotspot when you can. If you must use public Wi-Fi, confirm the network name with staff and connect through your VPN.

    4. Be cautious with email

    Be wary of unexpected messages with links or attachments. Travelers get phishing emails that pose as airlines, hotels, and booking sites. Check your reservation in the company’s own app.

    5. Turn on two-factor authentication

    Two-factor authentication requires a second proof, such as a code from an app, along with your password. It blocks access even when a password is stolen. Use an authenticator app. Text-message codes can fail when you are abroad without service.

    6. Use a firewall

    A firewall blocks incoming connections from unknown sources. Make sure the one built into your computer is on, and set the network type to “public” when you join a network away from home.

    7. Keep your software updated

    Install updates before you leave. Don’t accept an update offered through a hotel or airport network pop-up. Attackers have used fake update prompts to install malware.

    8. Pay with a credit card

    Credit cards offer stronger protection than debit cards. Under US law your liability for unauthorized credit card charges is capped at $50, and a debit card puts your bank balance at risk. Use ATMs inside banks, and cover the keypad.

    9. Guard your personal information

    Be careful about sharing your full name, date of birth, or Social Security number while you travel. Don’t post your location or travel dates in real time.

    10. Use a privacy screen

    A privacy screen narrows the viewing angle of your laptop or phone, so the person in the next seat can’t read it. It prevents shoulder surfing on planes and in lounges.

    11. Keep your devices with you

    • Never leave a device unattended in a café, a conference room, or a car
    • Carry laptops in your hand luggage
    • Use the hotel safe for devices you leave in the room
    • Lock your screen every time you step away

    12. Avoid public charging ports and shared computers

    A USB port can carry data as well as power. Use your own charger and a wall outlet, or carry a power bank. Don’t log in to personal or work accounts on a hotel business center computer.

    Is hotel Wi-Fi safe?

    Treat it as public. Many guests share it, and you can’t see how it is managed. Use a VPN or your phone’s hotspot for anything sensitive, such as banking and work.

    What should I do if my device is lost or stolen?

    1. Use “Find My” to locate it, lock it, or erase it.
    2. Change the passwords for accounts you used on it, starting with email.
    3. Report it to your employer if it holds work data.
    4. Report it to local police and get a report number for insurance.
    5. Tell your mobile carrier, so they can suspend the SIM.

    What should business travelers do?

    • Follow your company’s travel policy
    • Use the company VPN for all work
    • Carry only the data the trip requires
    • Don’t discuss confidential matters where others can hear
    • Be careful with devices and USB drives handed out at conferences
    • Report any lost device or suspicious activity to IT right away

    Do I need to worry about Bluetooth and file sharing?

    Turn off Bluetooth, AirDrop, and similar sharing features when you are not using them. In a crowded place, an open setting lets strangers send you files or try to connect to your device.

    What should I do when I get home?

    • Change the passwords you used on public networks
    • Review bank and card statements for unfamiliar charges
    • Run a security scan on your devices
    • Remove travel apps you no longer need
    • Post your trip photos now

    How do I avoid travel booking scams?

    Fake travel sites and listings take your payment and disappear. Book through companies you can verify, and type their web address yourself. Be wary of a price far below every other listing, a host who asks you to pay outside the booking platform, and any request for payment by wire or gift card.

    Your next step

    Before your next trip, run through the “before I leave” list and install a VPN. Protecting your privacy on the road takes attention and good habits. If your team travels for work, Cerberus Cybersecurity can add travel security to your cybersecurity training and your written policies. Contact us to learn more.

  • IRS Scams: How to Spot Fake IRS Calls, Emails, and Texts

    By J. Mesa

    Every tax season, criminals pretend to be the Internal Revenue Service. They use email, phone calls, texts, and social media to trick taxpayers into handing over a Social Security number, bank details, or money. A victim faces identity theft or financial loss.

    Here is how to recognize an IRS scam, what to do about it, and how to keep your tax information safe all year.

    What is an IRS scam?

    An IRS scam is any attempt to steal money or personal information by posing as the IRS or a tax professional. The most common forms are:

    • Phishing emails that link to fake IRS pages
    • Text messages about a refund or a problem with your return
    • Phone calls that threaten arrest or demand immediate payment
    • Fake letters that copy IRS notices
    • Social media messages offering help with refunds or credits
    • Fraudulent tax preparers who steal refunds or client data

    How does the IRS contact taxpayers?

    The IRS contacts most taxpayers first by a letter sent through the US Postal Service. The agency does not initiate contact by email, text message, or social media to ask for personal or financial information.

    The IRS does make phone calls and visits in some situations, such as an overdue bill or an audit. Those follow letters you have already received.

    What will the IRS never do?

    • Demand immediate payment by gift card, wire transfer, payment app, or cryptocurrency
    • Threaten to have you arrested or deported by local police
    • Ask for your card or bank details over the phone, by email, or by text
    • Demand payment without giving you the chance to question or appeal the amount
    • Send an email or text asking you to “verify” your identity through a link

    Any message that does one of these is a scam.

    How do I spot a fake IRS email or text?

    • It arrives without warning and mentions a refund, a penalty, or a locked account
    • It contains a link or an attachment
    • The sender’s address does not end in irs.gov
    • It pushes you to act within hours
    • It asks for your Social Security number, bank details, or login

    Don’t reply, and don’t click anything.

    How do I spot a fake IRS phone call?

    Scam callers sound official. They give a badge number, know part of your Social Security number, and show “IRS” on the caller ID, which criminals can fake. They then threaten arrest or a lawsuit unless you pay right now.

    Hang up. If you think you owe taxes, call the IRS yourself at 1-800-829-1040, or check your account at IRS.gov.

    How do I report an IRS scam?

    • Email: forward it to [email protected], then delete it.
    • Text: forward the message to [email protected] with the number it came from.
    • Phone call: report it to the Treasury Inspector General for Tax Administration at tigta.gov and to the Federal Trade Commission at reportfraud.ftc.gov.

    Reporting helps the IRS shut down fake sites and warn other taxpayers.

    What is an Identity Protection PIN, and should I get one?

    An Identity Protection PIN (IP PIN) is a six-digit number the IRS issues to you each year. Nobody can file a tax return with your Social Security number without it.

    Any taxpayer who can verify their identity can request one at IRS.gov. It is free, and it is the strongest protection against someone filing a fraudulent return in your name.

    How do I verify a request for information?

    Be careful any time someone asks for personal details. The IRS does not ask for your Social Security number or bank details by email. If you are unsure whether a request is real, contact the IRS directly at 1-800-829-1040, or log in to your account at IRS.gov. Don’t use the phone number or link in the message.

    How do I protect my tax information?

    • Use strong, unique passwords for your tax software, your IRS online account, and your email
    • Turn on multi-factor authentication wherever it is offered
    • File early. A criminal can’t file a fraudulent return after yours is accepted.
    • Use a secure network. Don’t file taxes on public Wi-Fi.
    • Keep your devices updated

    How do I choose a tax preparer I can trust?

    Give your tax information only to trusted sources, such as a qualified tax preparer or financial advisor.

    • Check that the preparer has a Preparer Tax Identification Number (PTIN). Paid preparers must have one and must sign your return.
    • Ask how they store and send your documents
    • Avoid preparers who base their fee on the size of your refund
    • Never sign a blank return
    • Make sure your refund goes to your account, not theirs

    How do I dispose of tax documents?

    Shred any paper that carries sensitive information, including old tax returns, W-2s, and 1099s, once you no longer need to keep it. The IRS suggests keeping returns and supporting records for at least three years in most cases. Erase old computers and drives before you recycle them.

    Is tax software safe?

    Reputable tax preparation software files your return electronically over an encrypted connection, and e-filing is safer than mailing paper. Download the software from the company’s own website, use a strong password, and turn on multi-factor authentication.

    What should I do if I gave information to a scammer?

    1. If you sent money, call your bank or card issuer right away.
    2. Change the passwords on your email and financial accounts.
    3. Place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion.
    4. Report identity theft at IdentityTheft.gov for a recovery plan.
    5. Request an IP PIN from the IRS.
    6. If someone filed a return in your name, the IRS will ask you to complete Form 14039, the Identity Theft Affidavit.

    How do tax scams target small businesses?

    Criminals target payroll and human resources staff.

    • W-2 scams. An email that appears to come from the owner asks for copies of all employee W-2 forms.
    • Fake payroll changes. A message asks to change an employee’s direct deposit account.
    • Fake IRS notices about business tax accounts or new “registration” fees.

    Protect your business with one rule: confirm any request for employee tax data or a payment change by phone, using a number you already have. If you prepare taxes for others, federal law requires you to have a written information security plan.

    When do tax scams peak?

    Scams rise from January through April and again around extension deadlines in the fall. They also follow the news. New credits, relief payments, and disaster declarations each bring a wave of fake messages. Stay alert all year.

    Your next step

    Request an IP PIN at IRS.gov before you file this year. Protecting yourself from IRS impersonators takes attention and a commitment to guarding your personal information. If your business handles employee tax or payroll data, Cerberus Cybersecurity can train your team to spot these scams. Contact us about our cybersecurity training.