She's On The Money - Keeping Your Small Business Cybersafe
Episode Date: July 12, 2024Another day, another high profile data breach, Medibank, Canva, Optus, Latitude – but it’s not just big corporations that are targeted. Every day, individuals and small businesses are under attack..., and these stories don’t make the news. As a small business owner, a cyber security attack could end your business and really hurt your customers. But it is so easy to ensure that your business and customers are safe. Join Victoria for this bonus episode giving you some simple steps to take to keep your small business cybersafe! Acknowledgement of Country By Natarsha Bamblett aka Queen Acknowledgements. The advice shared on She's On The Money is general in nature and does not consider your individual circumstances. She's On The Money exists purely for educational purposes and should not be relied upon to make an investment or financial decision. If you do choose to buy a financial product, read the PDS, TMD and obtain appropriate financial advice tailored towards your needs. Victoria Devine and She's On The Money are authorised representatives of Money Sherpa PTY LTD ABN - 321649 27708, AFSL - 451289. See omnystudio.com/listener for privacy information.
Transcript
Discussion (0)
Hello, my name is Natasha Nabanunga-Bamblett. I'm a proud Yorta Yorta, Kernai, Wolperi and
Awadjeri woman. And before we get started on She's on the Money podcast, I would like
to acknowledge the traditional custodians of the land of which this podcast is recorded
on Awadjeri country, acknowledging the elders, the ancestors and the next generation coming
through. As this podcast is about connecting, empowering, knowledge sharing and the storytelling
of you to make a difference for today and lasting impact for tomorrow. Let's get into it.
She's on the money. She's on the money.
hello and welcome to she's on the money the podcast for millennials who want financial
freedom. Guys, as you probably already know, my name is Victoria Devine, and I don't have someone
here with me today. I have a little solo episode for you today, all about keeping your small
business cyber safe. I feel like at the moment, it's another day, another high-profile data breach,
Medibank, Canva, Optus, Latitude, but it's not just big corporations that are being targeted.
Literally every day, individuals and small businesses are under attack, and these stories
just don't make the news because they're not that newsworthy according to the media.
As a small business owner myself, this kind of terrifies me and a cyber security attack could
literally end my business but also ruin my reputation and hurt my community. But it is
so easy to ensure that your business and your community and your customers are safe and it's
something that we all gloss over, right? As a small business owner, it is something that we
are so good at overlooking because it's always on the back burner. There's always something
so much more important to do, but today I really want to chat to you about how to get cyber safe.
But first, I'm stats girl, so I have come prepared with a number of stats for you.
So, research shows that women are not as confident as men when it comes to preparing,
managing, and responding to cyber attacks, even though we are less likely to be scammed
compared to our male counterparts. I feel like that's the only good thing to come out of that.
A survey of more than 2,000 small business owners and employees showed that while female
business owners are less likely to be scammed compared to their male counterparts, they're
not as confident as men when it comes to their general cyber security knowledge.
And this survey, it was part of the Council of Small Business Organizations Cyber Wardens
Program, a mouthful, but it was developed in partnership with the CBA, so the Commonwealth
Bank and Telstra.
All right, let's start with arguably the most vital step, and that is passwords. I feel like
I'm talking to myself here, one, because this is a solo episode, but two, because I'm really bad
at passwords. They all used to just be one word, and everyone in my entire team used to know that
word. If you knew my family, you probably knew that word. It wasn't good, but passwords really
are your first line of defense against cyber break-ins, and it's essentially the keys to
your business. So strong, long and unique passwords make your accounts more secure and are more
likely to keep out hackers. But now with the rise of supercomputers and AI, having a short and
simple password, it means that these are really easy for cyber criminals to crack. Reusing passwords
across different businesses or even personal accounts can make you a target for what they
call credential stuffing scams. One compromised account is like giving cyber criminals the master
key to your entire business, which is really scary. In really busy small businesses, the
temptation to use short, simple passwords and repeat them is a really easy trap to fall into
and one I used to fall into until I learned about this and had to get myself together.
If you're doing your best to create secure passwords and then struggling to remember them
all, you're not alone. So, passphrases are actually your best line of defense. Now,
if you're wondering what a passphrase was, when I first heard passphrase, I was a little confused,
So let me talk you through it. A passphrase are a type of password that are harder for
cyber criminals to crack and they're easy to remember, which makes them an easy cyber safety
win. Passphrases are longer and they actually contain a sequence of really random words,
usually four or five of them. And the trick is making sure it isn't a proper sentence,
but an easy combination for you to remember. So if you're wondering the, how do I create a
strong passphrase, a good passphrase generally contains at least four words that are completely
unrelated and completely unpredictable. And the best way to generate a passphrase is to choose
completely random words. Be extra careful and make sure that they don't contain any personal
information. So if you were me, you wouldn't go, all right, well, I'll use my cat's and my dog's
name and my husband's name, because that is really easy to guess because it's all over the internet.
It is not hard to find that information. Many websites now require you to have a capitalized
character, number, and symbol. So you could still add this to a passphrase. So you could capitalize
random letters, or you could add hashes, or you could add the at sign. You could also spell out
numbers instead of just using the number and mix it all up. So that's what I've ultimately done.
And the important thing here is that they're not words that are relatable to you. So I haven't
used my name. I haven't used my cat's name. I've literally used random words. I've written down
four key points that are kind of like pro tips when using passphrases. So let me whip through
these really quickly so that we're all on the same page. Number one, don't duplicate your
passphrases. So what we want to do is ensure that each passphrase for each account is unique and we
never double up ever. This means that if one does become compromised, you haven't breached all of
your accounts. Number two, we're going to keep our passphrases to ourselves. So we're not going to
share our login details with team members. It might save some time and some money, but it honestly
increases your cyber risks and it is not worth doing it. Number three is use a password manager
to safely store passwords. This has been a game changer for me. Apps can be used to securely
manage passwords for all of your accounts and using one is going to keep all of your accounts
more secure. Number four is add a virtual alarm by pairing passphrases with multi-factor
authentication. So if your passphrase is ever compromised, multi-factor authentication is going
to add another layer of security to keep your account protected. And this for me, I thought it
was going to be really complicated, but it's not. I have an app on my phone and it guards all of my
accounts. It's a simple code. I pop it in and it just makes so much sense. In all honesty, I don't
know why I didn't do it earlier. Another massive threat to your small business is what's called a
bin attack. No, someone doesn't come at you with a wheelie bin. Unfortunately, bin attacks are
happening in Australia and they're increasing year on year. At the end of 2023, there was an ABC
report who talked about a Melbourne-based business who had more than 15,000 attempted transactions
through their online shop in just a space of two months. You're probably wondering,
V, what's a bin? So a bin is a bank identification number and it refers to the initial sequence of
four to six numbers that appears on your credit card. So it's the number used to identify a cards
issuing bank or another financial institution. And a bin attack is when cyber criminals steal
bin numbers and then attempt to generate working cards by guessing the remaining card numbers.
To check if these card numbers are linked to real cards, fraudsters, they test them on the payment
page of your online shop. And then if it's a successful transaction, it means they've guessed
a winning combination of numbers and then they can start making a heap more fraudulent transactions
which is really scary. So although every bank card has 16 numbers, it can be relatively
straightforward and pretty fast for cybercriminals to cycle through a whole list of numbers that
follow the bin in order to make enough correct guesses and find a live card number with accounts
attached. So generating thousands of guesses and testing them is actually fairly easy for
a cybercriminal thanks to the help of AI and computer bots. The cybercriminal might then use
these working card numbers to make transactions themselves, or they might actually on-sell those
numbers to other criminals to use them for bigger and scarier things. Thin attacks pose two major
risks to small businesses. So firstly, they can be really expensive. Depending on the contract
with your payment gateway, you might actually be charged for each attempted transaction.
So this expense can multiply really quickly if bots and AI are involved and you're hit with a
really large attack. Secondly, they can be a serious reputation risk when victims start seeing
your store charged on their credit card, which is terrifying because you know that wasn't you,
it was actually somebody else. So there are multiple signs of a bin attack and here are
some things that you need to look out for. So are you experiencing lots of low value transactions
that might be pretty unusual for your business? You might have gotten a heap of notifications
that your customers' cards have been declined multiple times? Have you seen the use of
international cards, so banking cards consistently from countries that are outside of Australia?
Maybe you've experienced a spike in transactions, whether they're attempted and processed in a short
period of time, and the same card number being used for multiple transactions. You might also
have noticed strange transactions outside your normal customer behavior. So you might see things
at 3am in the morning, for example, when all your normal transactions generally take place between
12pm and 11pm. Or you might have seen an unusually significant increase in transaction fees from your
bank. The final thing I want you to watch out for is a really unusual spike in customers disputing
payments. If a group of customers all notice that their cards have successfully been used on your
website, they might contact you or they might just go direct to their bank and dispute the payment
because they go, well, this is fraudulent and process a refund or a chargeback. So these are
things that I need you to be looking out for. And any small business with an online presence
that accepts payments over the internet is ultimately at risk. And this includes me and
I don't even have physical products. So the best thing that you can do is actually set yourself up
with a payment processor that can identify these types of attacks. So when you're searching for
this type of service for your online shop, I really need to make sure that you're reading
through what they offer in regards to fraud prevention. Some processes may offer multiple
additional layers of protection, requiring customers to type in a capture, 3D secure,
and the rate limit that you can easily implement on your website. And I've got a few points that
I've written down here, so bear with me, my friends. So what these processes are going to do
is check transactions are real and not a robot. This means that you're making sure that genuine
customers can make their purchases, but a scammer using software to test various credit card numbers
might not be able to get through. Adding a capture is one way that you can do this. So then we're
going to want to limit transactions and set alarms for large transaction volumes. A rate limit
actually prevents the number of new customers who can be created from a single internet address in
one day, which is really important. If you're a small business where a customer only places maybe
like one or two orders, a rate limit is a really sensible option and isn't going to impact your
genuine customers. Because what type of customer is creating lots and lots of different accounts
from the same internet address, right? What it's going to do for you is ensure that a scammer can't
process hundreds or even thousands of purchases through your website, which protects you and your
consumer. And then the next thing you want to do is turn on a virtual alarm for online payments.
Are you familiar with multi-factor authentication for your online accounts?
When you try to log in, you might have to enter like a code or a one-time password to
double check it's you.
I mentioned before that I've got an app on my phone that lets me get into everything.
And when I say everything, I mean everything.
If I can multi-factor authenticate something, I have my Facebook, my Instagram, obviously
my bank.
But also more recently, I was able to multi-factor my pet food ordering company.
So we are going hard on this because it's so important.
and to be honest, my credit card details are where my pet food is ordered. So I don't particularly
want anyone jumping into that. And businesses, you can do the same for all online payments.
Its official name is 3D Secure or 3DS, but it works really simply. When a customer's card is
attempted to be charged, they'll have to verify that you're the one trying to make a payment.
Think of it like turning on a virtual alarm to online payments, which I think is really smart.
Now, let's go to a really quick break because I feel like I have been talking underwater with a mouthful of marbles.
So I'm going to grab a coffee.
And when we get back, I'm going to give you my top four security tips for small businesses.
And we're going to be talking about how to pimp your password.
So don't go anywhere.
All right, guys, we are back.
And I did promise that I would give you my top four security tips.
And in a minute, I'll get to how to pimp your password.
But calm down.
we actually need to get through these top four security tips first. So number one, I need you
to make sure that you don't ignore software upgrades. I am always clicking the button that
says remind me later. And it's really easy to do that when pesky software updates pop up on your
phone or computer screen. Literally, I have only just updated my iPhone and it has been months
since the last update came out. And that is honestly not good enough. I also feel like
whenever my computer needs an update, it always pops up at the most inopportune time. I'm jumping
into a Teams meeting and my computer's like, oh, hey V, good time to update your computer.
And I always hit remind me later. But what you're going to do if that happens is just set a little
reminder on your phone so that you can come back to it. Software updates often contain really
important patches or fixes for security flaws in your operating system or software. So what we need
to do is make sure that they're always up to date. Cyber criminals know about these weaknesses and
they know how to exploit them. It's why your software company wants to update them because
they've identified them as well. And usually it's through a breach. So updating your software can
close the gaps to make it harder for cybercriminals to break into your business, which is a win for
everyone. And cybercriminals, let's be honest, they're quite intelligent. I mean, I wish that
they would use their intelligence for better, but they don't. But they know this and they attempt
to impersonate these trusted organizations to scam small businesses. So always check who is
sending you this notification. Is it an email? Is that a trusted email? If it's a text message,
make sure you're trusting where this is coming from before you action anything. In fact, across
my entire life, I have decided to never click a link in a text message ever again. And I think
that most businesses are on board with this nowadays. I know the banks are jumping up and down
about how do not click links. We would never send you a link. We would never do that to you. So I
feel like if you want my business, you will not send me a link. You'll say, go to my website. I
know your website. I'll key it in myself. Thank you. The second thing we're going to do is use
multi-factor authentication on your devices. So as I said before, I'm obsessed with this. I have
it now. It does make me feel a lot safer. Multi-factor authentication is an added layer
of security for your accounts that makes it so much harder for hackers to break in. Using
multi-factor authentication means that anyone who wants to log into your account is going to need
to supply additional information in addition to your username and password. And some accounts use
a unique text message, while others will suggest to use an authenticator app. So I use both, but I
think it's really important that you're implementing these things. I told you that I'd tell you how to
pimp out your password. So new financial year, new me, but also new password, babe. The new financial
year is a great time to wipe the slate clean with old passwords and usher in some new, stronger
ones. Weak passwords, especially those used across multiple accounts, are one of the biggest risks to
cybersecurity for small businesses. As I mentioned before, a password manager can help you create
strong passwords and then save them in a really secure place, meaning you don't need to remember
them all for your accounts. They're in your password manager, which is completely protected.
And then four, what we're going to do is back up our business. You back yourself in business. You
need to back your actual business when it comes to protecting it from a cyber attack? What would
you do if your small business was the victim of a cyber attack and your critical business
information couldn't be recovered? There's a few things here, right? Let's pretend that someone
attacks your business, you lose a heap of money and the bank refunds all of your money. Fantastic,
money win. However, what about your reputation? I know that companies who have experienced these
types of breaches lose a lot of customers and they don't just lose customers because it happened to
them. They lose customers because the reputation that they weren't safe makes people really,
really worried. So it is so much more important than just worrying about the financial loss.
A loss as important as business and customer data could be completely devastating for any
small business. And a really good way to help protect yourself from that loss is to make a
plan to regularly back up your critical business information, either through an external storage
drive or in the cloud, or if you're me, you do both because you have anxiety. While you make up
a backup plan, it's a really good time to consider making an emergency plan in the event of a cyber
attack. A sound emergency plan will outline how staff should report a suspected cyber incident,
who would you contact for help, and how would you communicate any incident to customers or staff,
and how would you manage if critical systems are then offline for any period of time.
An emergency plan sounds a bit silly, but it can actually help you feel in control and recover
quickly in the event of a cyber threat or incident. The other thing I would say here is how do you
educate your consumer in advance? So I know because I own a mortgage broking company and we deal with
money every single day that at the bottom of our emails, we are always letting customers know,
it's literally in our email signature, that we will never ask you via email to transfer funds.
if we ever send you bank codes, BSB and account numbers to deposit money, it is not us because
we would never do that. And I think that educating your consumer upfront is going to mean that you're
protecting yourself as well as you can. Now, I feel like that was a lot because it is a lot.
Cybercrime is sadly on the rise. And I think it's so important to keep your small business
cyber safe. It is something that has slipped to the wayside for a long time for me and now
is not, thank God. But I think it's really important that you take it seriously as well.
To me, one of the things that stopped me was it felt like an overwhelming admin task. So if you're
going to do it, set some time aside and get it done because it's one of the most important things
that you do for your business. But friends, I know I have talked a lot about this. I'm happy to
continue the conversation. But unfortunately, when it comes to podcast time, that is all we have time
for today. So if you'd like to chat more about this, we can jump into the Business Bible Facebook
community. You can join us on Instagram. Obviously, we're a community that shares our business and
money tips and tricks every single day, free of judgment. So, search She's On The Money or
The Business Bible on Facebook and join us. If Facebook's not your thing though, we're at
She's On The Money AUS. So, don't forget to join the conversation and I will see you next time,
hopefully, for another solo episode.
the advice shared on she's on the money is general in nature and does not consider your
individual circumstances she's on the money exists purely for educational purposes and
should not be relied upon to make an investment or financial decision if you do choose to buy a
financial product read the pds tmd and obtain appropriate financial advice tailored towards
your needs. Victoria Devine and She's On The Money are authorised representatives of Money
Sherpa PTY LTD ABN 321 649 27708 AFSL 451 289.
