Young and Profiting with Hala Taha - Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

Episode Date: September 9, 2026

Entrepreneurs often assume hackers only target big companies, but small businesses can be easier targets than they realize. A weak password, compromised vendor, or poorly managed access point can expo...se customer data, disrupt revenue, and damage trust. In this episode, presented by Bitdefender, cybersecurity consultant, Abed Hamdan explains why your business might be an attractive target to hackers and how entrepreneurs can protect their business from today's cyber threats without needing a full-time security team. In this episode, Hala and Abed will discuss:  (00:00) Introduction (00:00) Why Small Businesses Attract Hackers (07:55) How Hackers Target Small Businesses (14:40) How Abed Entered the Cybersecurity World (18:22) Non-Negotiable Cybersecurity Habits for Businesses (28:57) How Cyberattacks Can Destroy a Business (30:29) Cybersecurity Protection on a Small Budget (32:41) Defense in Depth for Small Businesses (40:30) AI, Deepfakes, and New Cyber Risks (54:27) Insider Threats and Employee Access Risks (57:42) Finding the Backdoor in Your Business (1:03:04) What to Do After a Cyberattack (1:05:17) From Cybersecurity Content to Entrepreneurship Abed Hamdan is a cybersecurity consultant, content creator, and founder of GRC Mastery. He has more than two decades of experience helping organizations strengthen their security, manage risk, and navigate complex cyber threats. His expertise spans cyber defense, governance, risk and compliance (GRC), and security strategy. Known online as UnixGuy, Abed has built a global cybersecurity community of more than 600,000 followers by making complex security topics practical and accessible. Sponsored By: Keep your small business safe with Bitdefender Ultimate Small Business Security. Save 30% when you go to bitdefender.com/profiting  Resources Mentioned: Bitdefender: bitdefender.com/profiting  Abed's Training Platform, GRC Mastery: grcmastery.com Abed's YouTube: youtube.com/@UnixGuy/about  Abed's LinkedIn: au.linkedin.com/in/abedhamdan  Active Deals - youngandprofiting.com/deals  Key YAP Links Reviews - ratethispodcast.com/yap YouTube - youtube.com/c/YoungandProfiting Newsletter - youngandprofiting.co/newsletter  LinkedIn - linkedin.com/in/htaha/ Instagram - instagram.com/yapwithhala/ Social + Podcast Services: yapmedia.com Transcripts - youngandprofiting.com/episodes-new  Disclaimer: This episode is a paid partnership with Bitdefender. Sponsored content helps support our podcast and continue bringing valuable insights to our audience. Entrepreneurship, Entrepreneurship Podcast, Business, Business Podcast, Self Improvement, Self-Improvement, Personal Development, Starting a Business, Strategy, Investing, Sales, Selling, Psychology, Productivity, Entrepreneurs, AI, Artificial Intelligence, Technology, Marketing, Negotiation, Money, Finance, Side Hustle, Startup, Mental Health, Career, Leadership, Mindset, Health, Growth Mindset, Passive Income, Online Business, Solopreneur, Networking

Transcript
Discussion (0)
Starting point is 00:00:00 Today's episode is sponsored in part by Shopify, Indeed, AT&T business, Northwest Registered Agent, Mindstone, and Honeylove. Shopify is the global commerce platform that helps you grow your business. Start your $1 per month trial at Shopify.com slash profiting. Indeed helps you attract, interview, and hire all in one place. Get a $75-sponsored job credit to boost your job's visibility at indeed.com slash podcast. AT&T Business delivers reliable business-grade connectivity that gives your team a competitive edge. Switch to AT&T Business at business.ATT.com. Northwest Registered Agent gives you the tools and guidance you need to build a complete business identity.
Starting point is 00:00:43 Visit Northwest Registeredagent.com slash Yap free and start using free resources to build something amazing. Mindstone is an AI transformation company that helps professionals get real value from AI. Get 10% off their four-week AI competency program at experience.mindstone.com slash yap. Honeylove makes the most advanced sports bras and shapewear on the market. Save 20% off Honeylove by going to honeylove.com slash profiting. As always, you can find all of our incredible deals in the show notes or at young and profiting.com slash deals. There's a really famous story on the news. They created a dating app.
Starting point is 00:01:23 It's for women's safety. But then turned out that app they took their passport details and all their information. Turned out this app was vimcoded with zero security. It got hacked and it put women's safety in danger. Wow. Usually women get targeted like someone leaks explicit videos of an individual. And well, that video is completely deep fake. And it has been happening.
Starting point is 00:01:43 They always target the vulnerable. They always target the young. It is a problem. And we need some kind of a strict regulation. We're joined today by Abed Hamdan, founder of GRC Master and content creator who's known as the Unix guy online. He brings more than two decades of experience in cybersecurity and risk. So we want to use AI.
Starting point is 00:02:04 We want to be on top of the new technology. But we also need to stop and think, what is it that we're using AI for? What does the AI have access to? And more importantly, where's my data going? What's one thing that entrepreneurs are doing where a hacker is going to say this is just way too easy? Something I see frequently is a founder says,
Starting point is 00:02:21 oh my God, we went live last week. You wouldn't believe it. we expected 200 clients and now we have 2,000. This tells me that this team is extremely busy. They can barely keep up. This is a really quick telltale. There are other things that... How worried do we have to be about AI agents
Starting point is 00:02:37 and their ability to hack our companies or their cybersecurity threats? There are many issues with AI agents. The first one is... This episode is brought to you by Bit Defender, a global leader in cybersecurity. Have you ever received an email that looked like came from a bank or a trusted vendor asking you to wire money immediately, small business owners
Starting point is 00:02:59 get hit by scams like this all the time, and one click can cost your business everything. Bit Defender, ultimate small business security keeps your devices, passwords, and team safe, even if you don't have an IT team. Protect your business with Bit Defender Ultimate Small Business Security. Save 30% when you go to Bit Defender.com slash profiting. That's BIT Defender.com slash profiting. Now, to help us better understand the business of cybercrime and how organizations can protect themselves, we're joined today by Abed Hamdan.
Starting point is 00:03:30 Abed, welcome to Young and Profiting Podcast. Hi, Hala, thanks for having me. I am really looking forward to having this conversation about cybersecurity. I feel like all business owners need to protect their businesses. And with AI, cybersecurity is becoming more important than ever. But let's start at the very basics. for the entrepreneurs tuning in. What is something that you think
Starting point is 00:03:53 they fundamentally don't understand about cybersecurity? Entrepreneurs usually make, I think, a couple of assumptions about cybersecurity. I think the first assumption they make is about the attacker. So they think the hacker is this person in a hoodie in some basement
Starting point is 00:04:11 or they go the other extreme and they think the attacker is some really sophisticated sort of spy agency or foreign government. And as a result of these two assumptions, they usually think, well, I'm an entrepreneur, I run a small agency or run a small business. Why would anyone attack me? And unfortunately, of the businesses that I help, it's usually after the fact. So they get attacked and they really sometimes underestimate the consequences of some cyber attacks. Some of them, unfortunately, can be business ending or it can have such a large cost that it may even be cheaper to just shut the business down.
Starting point is 00:04:50 And this is huge everywhere across from like small business to even medium sized and in some instances, even large businesses. Yeah, I always think of like really big companies like meta getting hacked or Big of America or something like this. But small businesses actually can be attractive targets. Why is that? 100%. In fact, think about it. If you were a hacker, how life, let's say you've just learned how to hack and you want to start, you know, legally hack, hack, you naturally wouldn't. go after meta because that's such a difficult target. They invest so much in cybersecurity. They are at the forefront of everything technology. However, when it comes to small businesses and entrepreneurs,
Starting point is 00:05:33 usually they're just focused on getting their product out. They are overworked. And in most instances, also underfunded. So they can be, quote-unquote, easier targets, but they also hold something really valuable. They hold what we refer to as privately identified. information. So that's something that we classify as a critical asset. For example, a lot of entrepreneurs will have something like a customer database where they have the names and last
Starting point is 00:06:00 names and phone numbers and sometimes the addresses. This is extremely valuable because what attackers can do, they can get that information and sell it on the dark web. It's actually extremely valuable. So that's a really key critical asset that lots of small businesses have. And unfortunately, sometimes they don't have the knowledge or the resources. to protect that. The other thing and probably the more important thing that small businesses have is that, well, like I said earlier, it may be a lot harder to hack something like a big bank or something like meta, as you alluded to. However, the way to get into those companies is usually you hack their suppliers. So if that small business is a supplier for a bigger business,
Starting point is 00:06:42 usually it's a lot easier to attack that small business and use it to pivot or use it to trust. So if you can compromise the email account of a small business, well, you can start sending malicious stuff using their email address. In fact, that's how most big businesses get compromised through their suppliers and they're usually on the smaller side. So interesting. I never thought about that. So we not only have to worry about our own security, we have to worry about the security that our vendors are doing for their own companies, which is just so crazy to think about. What are the main ways that small businesses are compromised? So we just talked about vendors for bigger enterprise businesses. How about small businesses? What are the main
Starting point is 00:07:23 ways that they're compromised? So look, the way sort of hacking or compromise happened, there are actually so, so many ways. Most of them aren't even known to the public. They tend to be complicated. But the most common ways for, let's say, an attacker to gain foothold and tend to be the easiest way. It's what we refer to as social engineering. This is where the attacker pretends to be someone that the business owner knows or pretends to give them something that they trust. So we really use the old age sort of trust relationship that we humans rely on. For example, as a small business, I could pretend to be one of their employees and send an email urgently say, hey, floss my account, urgent. Please click on that link and help me out. So we apply time pressure.
Starting point is 00:08:09 So we call that social engineering or fishing, which falls under social engineering. There are other sinister ways as well. but it all comes back to really pretending to be someone else. So fellow entrepreneurs and YouTubers, a really common recent one is actually pretending to be a brand and offering a brand deal. Yes, I get so many of those. I've even helped like cybersecurity professionals who got hacked this way.
Starting point is 00:08:37 And that's no shade on them. This is just a testament on how good some of those attacks are. They can really pretend to be a legitimate brand and the website look exactly the same. There might be just a slight variation on the URL, and sometimes it's something that your eye cannot see. So some of the alphabets, we can replace it with special characters, and it's really hard to detect.
Starting point is 00:08:58 So that's a really common way. There are more and more ways. For example, if you have physical access to the business, there are things you can install, but that's a whole other story. But when it comes to sort of the most common ones, it tends to be 100% social engineering. So let's really unpack this with a real example.
Starting point is 00:09:18 If you could really just walk us through. Let's say there's a company that has like 20, 30 employees. They're using the typical things, Slack, cloud storage, Zoom. They might have vendors, different SaaS tools. Walk us through how they could get attacked and some of the things that could happen and how it could escalate. Yeah, I mean, just before I say anything, just disclaimer. Hacking is illegal. Well, what I'm about to say is for educational purposes, so please don't do it.
Starting point is 00:09:47 But hypothetically, if I was to attack this imaginary business, the first step I would do is always reconnaissance. So I'll try to collect as many information as I can about that business. This includes their LinkedIn posts, how many people work there. I'll even draw like an org chart, see who's who, who's the employee, go on Instagram. They usually share everything. So I'll get a list of the individuals who work there. More importantly, I'll get a list of the technologies that they use and also the product that they have.
Starting point is 00:10:19 So once I get a list of that, the next step would be I'll start to craft things that they trust. I'm going to a social engineer my way there because it's a lot easier for me, like I said, to get an employee to do something for me as opposed to me trying to hack Microsoft and get inside their email. So what I will do is I'll try to mimic what their email looks like. And now that's really easy. I can literally vibe code that in like five minutes. It used to take a lot more time. The second thing is I'll see what vendors they use. So if they use so many SaaS applications, well, I could hypothetically go to the dark web
Starting point is 00:10:55 and see if there is any information about those services. If there is a new vulnerability, it may not be patched. So I could directly go and hack one of their SaaS services and get into their network. But let's say everything they use is secure. well, I'll try to then attack, sort of target the employees individually. I'll usually target who may appear to be more vulnerable. Usually it's very busy individuals, very busy founders. They are more likely to click on something really fast.
Starting point is 00:11:26 Sometimes I'll even, not I, but the hypothetical attack I may look at some elderly parents and try to tell them they've won something. Because what happened, Hala, is if the illicitical. elderly parent gets their email compromised, well, I can use their email to send stuff to sort of their kids and they're more likely to click on them than if it comes from an unknown individual. Now, the final one that is very, very effective with entrepreneurs and all the startups that I don't recommend anyone to do, but I could simply purchase the product that they have and be a legitimate customer and just give their customer support help. I'm like, it's not working.
Starting point is 00:12:08 help me, hop on a Zoom call, do this. So the customer support individuals are very likely to say, well, I tell them my Zoom is not working, please click on this, so I can get them to click on something. And unfortunately, support individuals usually have a lot of access. So as soon as they click on something, I'm in. And I can continue pretending to be a legitimate customer, which I am, close everything so they don't suspect that something is happening,
Starting point is 00:12:32 and then I'm in the network. Then I'll start to slowly and surely take over everything. but that's more or less how I guess a lot of hackers would actually approach it. That's so frightening. It's so frightening that this could be happening. And I guarantee you that so many entrepreneurs tuning in are now realizing how big of a deal this is and how little they're probably protected. So what is one thing that with our cybersecurity, when you're looking at small businesses, what's one thing that entrepreneurs are doing where a hacker is going to say this is just way too easy?
Starting point is 00:13:04 I mean, there are a number of things, and I'm going to start with the big business and then go down to the small one. A really big tail tail, even for me as a consultant, if a company is hiring me to check their security, the first thing I go on LinkedIn and I just see who works there, if that organization is sort of mid-sized to large size, and I see that they have like one person that's called quote-unquote IT person that's doing everything, this is a sure sign that this person is overworked, probably doesn't have enough time to do everything. everything security-wise. So I know there is a high chance that they may not be doing everything they need to do. So that's a quick tell-tale for me. The other one would be, I'll believe it or not, I'll go on Instagram and something I see frequently is a founder says, oh my God, we went live
Starting point is 00:13:52 last week. You wouldn't believe it. We expected 200 clients and now we have 2,000. This tells me that this team is extremely busy. They can barely keep up and it's a lot easier to do things with them that, you know, I'll put a time pressure. Hey, I'm a customer. The apps down. Help me. Log into my computer. Do something for me.
Starting point is 00:14:09 This is a really quick tale tale. Now, more than that, there are other things that I wouldn't say small business owners sort of do. Used to be more common in the past. So things like not having two-factor authentication or like old practices that they still exist, but not so much nowadays. So systems have gotten better, thankfully, but as a result, because we have, better systems, better IT setups, we can produce a lot faster. And with speed comes compromise.
Starting point is 00:14:40 And not just in cybersecurity, you probably have seen it, where organizations or entrepreneurs or small businesses, they release something, but they haven't done their due diligence from a legal point of view. They haven't gotten everything reviewed and they say, well, we'll do it after the fact. So these kind of things may have large impact and in some cases, large consequences. This episode is sponsored by Bit Defender, a global leader in cybersecurity. Many small business owners lack dedicated IT support, making them easy targets for cyber criminals
Starting point is 00:15:10 who steal data, money, or sensitive information. Bit Defender Ultimate Small Business Security is built specifically for business owners like you. It protects all of your team's devices, scans for fishing and scams, manages passwords, and even checks the dark web for leaked info. Unlimited VPN allows your team to work securely from anywhere. The dashboard is super simple. I set it up in just minutes. I add my whole team, and now everybody is covered whether they're in the office or the studio
Starting point is 00:15:38 or working remotely. Bit Defender makes cybersecurity easy so you can focus on what really matters, growing your business and serving your customers. Protect your business today with Bit Defender Ultimate Small Business Security. Save 30% when you go to BitDefender.com slash profiting. That's BITDefender.com slash profiting for 30% off. Bitdefender.com slash profiting. I want to understand how you know so much about cybersecurity and hacking.
Starting point is 00:16:06 And I learned from studying you that you got into this when you were like a teenager. And you were really exploring, you know, how does hacking work? And I'm curious to understand, like, where did this all begin? Tell us a story. Yeah. I mean, not to show my age, but I'd say I started perhaps late 90s, early 2000. And at that time, and especially where I was living, internet was new. It was a novelty.
Starting point is 00:16:34 It's the new thing. Internet, for those my age, internet cafes were a thing. So you'd go to an internet cafe, your paper hour, and you start exploring, and there wasn't much to explore. So it really started with chat rooms called the IRC chat rooms. And within that, I discovered, well, people were sharing files. You can download. There is a music file that was new to me. and then there was this thing called hacking.
Starting point is 00:16:58 It coincided with me watching a movie called Hackers. It was an early Angelina Jolie movie. It is fiction, but it really opened my eye. Like, hold on, this is a thing. Like, you can actually do that. So as a teenager, and as you do as a teenager, you start imagining things, oh my God, I could hack an airplane and fly myself everywhere.
Starting point is 00:17:19 These imaginary scenarios that are not real, but like as a 15 years old, this is everything. Then as I sort of quote-unquote do research, sort of find movies, I find another movie about someone called Kevin Mettnick. Late Kevin Mettnick, he is the most famous hacker in the world. At the time, there was a movie, not in just one, I think more than one movie. One was in German, one was in English. Of course, I'll watch with subtitles. The things he did were incredible.
Starting point is 00:17:47 He would hack phone lines, he would jam radio signals, he was on the run by the FBI. And the movies, of course, made it so glamorous. So all I could think of like, oh, my God, and that was a time when we would call people on phone line. So I'm like, oh, I could hack my friends' phone line. I could do these pranks. So I wanted to learn everything. I'd go to these chat rooms. And at the time, Hela, things were a bit different in the sense.
Starting point is 00:18:12 If you ask for help, people start swearing at you. It was not a friendly time, unlike today. So I had to learn certain things the hard way. I got myself hacked multiple times. but long story short. I sort of went into the right direction, started learning an operating system called Unix, hence where my nickname came.
Starting point is 00:18:33 And actually a fun sort of useful anecdote, my website, Unixky.com, is a few months older than Google.com. So I go way back. Wow. Yeah. So that's where it all started. Then I got my first job, studied things at university
Starting point is 00:18:51 that were completely useless, got my first job, but I continued learning. And I still do that to this day, even after consulting for so many years. I enjoy it. I like to learn. I stay curious and experience, of course. I've done this so many times, so much so that sometimes I can look at something and have an educated guest that maybe you can look here. Let's just start this way and take it from there. But yeah, it's been a continuous learning and experimenting journey and it's a lot of fun. Your entrepreneurship journey is like really interesting. So we're going to spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business. And you've done such a great job like really owning this niche and this lane and helping so many people in their IT careers, especially in Australia. So since we have this incredible consultant in front of us, a lot of the people tuning in are entrepreneurs. We're small business owners. We don't have endless budgets. We have a lot of information that might be vulnerable, but, you know, we're not this huge company.
Starting point is 00:19:55 But like you said, that makes us actually pretty attractive. So what are the few things, let's say three things that we should absolutely not compromise on when it comes to our security? What should we be investing in and where do we begin? This is challenging because it may slightly vary between businesses. But I'd say the first one, non-negotiable, is always two-factor authentication. Luckily, we live in a day and age, everyone knows what that is. So when you log into your email, sometimes you get an SMS says that you, enter a code. The preference is always to use something like a PASki or the Authenticator app.
Starting point is 00:20:34 Even a few years ago, this wasn't rolled out to everyone. We had to have difficult conversations. It tends to really, really reduce the risk of cyber attacks, not to zero, but it's really important. And within that, no exceptions. So if you have a busy executive or someone precious in the team that says, I hate that, tough luck. This is unnegotiable. This is like having a building and having a fire exit.
Starting point is 00:20:58 It's not a conversation that businesses should have. So this should be there, rolled out for everyone. That's number one. For every single platform that we're using or just email. Excellent point. It is meant to be for every single platform. However, with platforms now, as you log in, Hala, you notice. that it tells you use your Gmail to like use the same credit.
Starting point is 00:21:20 Like if you log and use it. So this is called single sign on, which is essentially you've already logged into your email. Your email is trusted. So we use that as a trusted token to get into apps. So that's perfectly fine. You still consider that as someone who used that. As long as the app is not asking you for username and password
Starting point is 00:21:38 and you're just entering and getting in, if it's asking you to use the email that you've already logged in, that is this is the same thing. So single sign on, have made that a lot easier. So instead of having an authenticator app for everything, some of them will use your email. However, even for me,
Starting point is 00:21:55 my authenticator app is really large. So it happens. I have it with everything, unless I can reuse my email, which is fine. It's just to get us out of just username and password. Because if the hacker have the username and password, it's game over.
Starting point is 00:22:11 So you just make it a lot harder. The second one, which is also related to credentials, is a password manager. So having a password manager is really, really important. No matter how complicated we make our passwords, the human tendency is for us to reuse the password everywhere. And that's extremely dangerous because your company may be secure, not hacked, but the local cinema might get hacked.
Starting point is 00:22:36 And guess what? People use their work email and work password to log into the cinema. So hack as usually when we do the reconnaissance step, when we try to collect information, we actually see if your password is out there. It doesn't matter if someone have the same name. We try to first use that and see if we can't get in. So a password manager really essential as a business,
Starting point is 00:22:55 have some sort of enterprise solution with these passwords where you have a complex password everywhere. And they're really convenient because you can have it as part of your browser. So you literally just copying a password that you want to reuse. This is the second one. The third one, if you just narrow it down to three, is our key critical assets. We need to understand.
Starting point is 00:23:18 It could be customer information. It could be intellectual property. For example, you're on a podcast. I'm sure you have, let's say, a method to make an amazing podcast. So that's intellectual property. Let's say it's in a word document. I would restrict access to that. And that even includes employees.
Starting point is 00:23:36 Make it on a need-to-know basis. If someone needs to access it, we ask why. You get a time-restricted access, but that's it. it shouldn't be free access to everyone. And that could get more complicated. Like I worked with Beverages organization here in Australia, and some of their intellectual property was recipes for their drinks. And those recipes needed to be in a secure vault with encryption
Starting point is 00:24:00 and with really secure passwords. But also once you log in and get access to that, you shouldn't have that login indefinitely. It should be time restricted. So those would be the three things. And if you allow me a bonus one, like I said, similar to... Yeah, I was going to say, what's the four and five? Because clearly I can tell it.
Starting point is 00:24:18 It's not just three things we need to worry about. The fourth one is similar to... It's just get a professional opinion. For example, small businesses, when they draft a contract, they get legal advice, right? So you get someone to review it as solicitor. Likewise, with cybersecurity, it doesn't have to be something massive. Get a small company, preferably something local, where you can reach out to them if things go bad and say,
Starting point is 00:24:40 I just like guys, a couple of hours, whatever, $2,000 or could be less, could be more, check, make sure we're doing everything, right? Give us a recommendation. And sometimes all they do is just check that you're doing everything. You may miss something. So they just give you professional advice. You know what? You're doing 99%. That's perfectly fine.
Starting point is 00:24:59 And as the business grow, that sort of consultation or that assessment can grow with you. If you have a software application, you're releasing to the market, obviously, that needs more scrutiny. but if someone is just, let's say, an Instagram content creator and they just share advice, they may not need that. I hope that gives small business owners a thing to work towards. It does. And I think because one of the most important things, like you said, is password safety. And there's some really, I know Bit Defender, I believe, has like a password feature that you can get.
Starting point is 00:25:32 And it's really cost effective. But you mentioned this thing, this concept, concept of least price. And I'd love to understand, like, what is this concept of least privilege? Help break it down for the people that aren't in cybersecurity. Yeah, the concept of least privileges or least privilege is falls under the umbrella of what we refer to as identity and access management. It really is you have a resource that could be an application. It could be intellectual property.
Starting point is 00:26:04 You want to restrict access to that and make it. so that the individual or the system or the software that have access to that, they just have access to the minimum amount of resource required for them to do their job with a time restriction. For example, we go back to, let's say, a customer database. You have a customer database, you have all your clients' details, and let's say you have a marketing officer. Marketing officer needs to run a campaign for some of those individuals.
Starting point is 00:26:35 So what I do is the marketing officer will only get access. to that database for like 30 minutes, so they get a temporary password, and they will only get access to those individuals, and then the access will get revoked. This reduces the impact of a cyber attack. For example, if two weeks later this marketing officer gets hacked, well, the hacker wouldn't have access because the access has been revoked. And you mentioned Bit Defender. They have their enterprise suite solution, so they will have that password manager where you can provide a temporary password access. So it can definitely assist with that. But that's more or less the principle of least privilege. We always assume that for cybersecurity, it needs to be this
Starting point is 00:27:17 complex, expensive piece of technology. But no, it's really people, process, and technology. So we start with the process. We just define this is how we access things from now on. And then we enforce it with technology, if it's possible, if not it can even do it manual. When it comes to customer data, like, for example, my business, we don't collect that much data. Like, we have everyone's email, but that's pretty much it. So, like, is that really sensitive customer data or does it get more sensitive when you're collecting people's, like, addresses and their social security and, like, that kind of stuff? So it's like, what customer data is the most desirable? Yeah, this is where there is a fine line between cybersecurity
Starting point is 00:27:57 and the legal profession, because here we're going into the territory of privacy, or some people say privacy, depends on how you pronounce it. But this is where we start. We're sort of even sometimes consult with a legal professional or a solicitor. Email address on its own, it's not really what we refer to as PII or privately identifiable information. It really is not why privately identifiable information is something that can uniquely identify you. This would be your full name, home address, date of birth, but also things we don't think about, such as sexual orientation, political views, these things because it can be used against you, to target you.
Starting point is 00:28:38 Okay. And within that, there comes a whole lot of laws and regulations. A simple one that many people don't know is your business is based in the United States, so you're in the U.S. However, if some of your customers are EU citizens, so they're Europeans and their country is part of the EU citizens and they sort of trade with you, you actually need to comply with a standard called the GDPR, which is the privacy standards for European citizens. So you need to do certain activities to make sure that you're not breaking their privacy laws.
Starting point is 00:29:13 Even though you're not really a European Union organization, likewise, there is that California Privacy Act and there is the China Act. So there is all of these things. And this is where, as cybersecurity professional, we provide advice, but then we consult with a solicitor. Sometimes it could be just, just please review this, make sure our policy is up to scratch. So as far as emails, I would treat it with absolute care because like I said, it may not be a huge legal liability, but it's very attractive. People on the dark web, they purchase email addresses. They use it for spam campaigns. They use it to scam people. It's a very attractive thing. And even I'm not sure if you like have an interest in, say, paid ads, email addresses are really attracted to use for paid ads. So there is commercial value for them. And as a result, We encrypt them. We make sure that our newsletter provider is doing their due diligence when it comes to security,
Starting point is 00:30:10 which the majority of the big ones are. So helpful. You are just like a wealth of information. So for the entrepreneurs tuning in who still don't feel like there is much of a risk with cybersecurity or still aren't scared enough, talk to us about what could go wrong, like reputation-wise, revenue-wise. You mentioned earlier that sometimes cyber attacks can be so bad. that the business actually has to shut down. I'd love to hear some examples of the way that
Starting point is 00:30:41 these types of attacks can actually impact businesses. Yeah, we tread a fine line here, Hala, of being an alarmist versus just encouraging individuals and entrepreneurs to really, really do their due diligence and just do what needs to be done. When it comes to security, it can definitely be a career ending in the sense. The biggest one we've just alluded to, which is breaking privacy laws, there are hefty fines. So the European Union is really strict with fines when it comes to the privacy of their citizens. So a company in the US that's providing services globally
Starting point is 00:31:16 and somehow they get hacked and European citizens get their data out there, there might be a big fine and it can be in the seven figures and that can have huge direct financial impact. The other one is, let's say you have an application and subscribers and that application gets hacked. Now what subscribers are paying, they need their money back, and you really don't know what to do, your revenue stopped. So all of these things can and do have significant financial impacts,
Starting point is 00:31:47 which is a good segue to also make sure you have the cyber insurance or talk to your insurance organization and make sure that insurance against cyber attacks is there. It's a sort of controversial topic. It may or may not help, but it's best to have it than not to have it. So those are things that are important. I've never heard of cybersecurity insurance. And then nobody talks about this stuff.
Starting point is 00:32:12 Cyber security insurance? Yes, I think it really is important. And look, the good news is you may already have it as an example. So if you have insurance for your business, depends on your provider, you can talk to them and say, is cyber attacks are included under that. And within that, there is a threshold and there is a limit. And however, I've had mixed experiences with cyber insurance.
Starting point is 00:32:37 But to summarize, it's better to have it than not to have it. And the good insurance providers, usually it's there in the fine print. So it's worthwhile just checking that it's already there. The other thing is also, like I said, if the organization or the business, like you had a consultation with a cybersecurity company that's preferably local. Also, if things go bad, you have them on speed dial, you can call them in and get them in. So having that relationship also is really helped. And they can also give you an advice when it comes to cyber insurance as well. So there's things helpful.
Starting point is 00:33:08 But when it comes to just things going wrong for small businesses, Hala, like I said, it does go a bit more sinister. And there are things that most of us don't hear about because it's sort of bad news. And really bad news, we don't want to hear about it for the most part. But there are cases of extortion. There are cases. and this is really, really common. So as a small business owner, someone could target one of your employees, and you're kind of responsible for them because your business got hacked,
Starting point is 00:33:38 and it's really complicated. And the implications are sometimes your employees could be the target or your customers could be the target. And as you mentioned earlier, it could also be your brand reputation, and we call it brand equity. Well, if people signed up to your application, it's hot stuff, but the next day, everything is hacked and everyone is complaining. can, that can be carried ending, unfortunately.
Starting point is 00:34:00 So let's go back to the entrepreneur who has no budget. Now, you mentioned the three to four things that we should pay attention to, but what if I literally had just $1,000 to invest in cybersecurity? And let's say, I don't know, maybe this isn't just not enough. I guess $1,000 for the year, or do we want to say $1,000 for the month? Like, what is the bare minimum that we can be spending on cybersecurity? Let's say we just have a thousand dollars. Let's just say the business has just started. And look, and there is good news here is that it's not always like the amount of money. I think as humans, when we see a problem, like I'm going to throw money at the problem and make it disappear. It doesn't always work that way, especially with entrepreneurship. The good news is a lot of the services that we use, Hela, are really built in a solid way. So let's say if someone is using the all their email and everything is from Google, for example, using the G Suite.
Starting point is 00:35:00 That is an inherently really secure platform if it's used properly. So if I just have $1,000, which tells me I'm early in business, let's say, content creator or I have a small agency, this also, I will guess that we're not building an email system from scratch. We're not building. We're just using popular services, whether it's from Google, Microsoft, et cetera, et cetera. This can be good news. I would honestly get that $1,000.
Starting point is 00:35:26 And like I said, reach out to a local trusted company and say, hey, this is our budget. Can you just give us advice? What can we do? And they can literally just have one hour, look at your stuff and just tell you, you know what, you're doing everything right, maybe do this one thing that's, you know, will give you 80% of the value. So I would, yeah, I would get a professional opinion. Like similar to, I think, the example of getting legal advice, you may not have the budget
Starting point is 00:35:52 to hire a lawyer that works full time. but all you need is someone to review employment contract. That $1,000 can do it. May not do it all the time, but it's better than doing what a lot of businesses do now, which is chat, GBT things, and AI is telling you, yep, you're doing a great job, you're fantastic, you're the best thing since sliced bread.
Starting point is 00:36:11 So I think just getting a human who know what they're doing is a lot better. I didn't think you were going to go that way. I didn't think you were going to say, get like a consultation and have somebody tell you what you need to be doing. How about a solution like Bit Defender, It's super affordable. I just went on their website and it's like less than 200 bucks a month to get all these different tools. It'll like scan your Slack and or like your messages for anything that looks like fishing your emails.
Starting point is 00:36:39 It will send warnings if it looks suspicious. So I feel like that's also like just a great layer to be adding on. 100%. And like I said, that could be also the outcome of that consultation. They said, hey, you're doing everything right now. you're ready for an enterprise solution, which like the one you mentioned from Bit Defender. And the good news is these things, they weren't available for us a few years ago. So we are living in a good time where a company like Bit Defender have something
Starting point is 00:37:07 targeted for the enterprise small businesses to medium-sized businesses where, yes, they do scan your emails, so you get rid of them spam headaches. They offer you some kind of password manager and monitoring. It's always better to have these things in place. It also Like from a, I hate to go that way, but from a legal perspective, if, you know, things go south, it's also proof that as a founder or as a business owner, you're doing your due diligence. They can't say, well, you've done everything, but you still got hacked. That can still happen, even massive organizations. But in this case, you will be a victim of criminals who really know what they're doing.
Starting point is 00:37:45 They're, you know, criminals do criminal things. And sometimes we're just victims of that. But that's a different story than someone who, you know, they've done. nothing. There's a really famous story on the news of those company that they created a dating app for women to protect women's safety. But then turned out that that app because it needed to verify women, they took their passport details and all their information. Turned out this app was vimcoded with zero security. It got hacked and it put women's in safety in danger. But that was an example of an organization that didn't do their due diligence. Whereas a small
Starting point is 00:38:23 organization, like we said, okay, they've got the consultation, they've got the defender enterprise security. They're doing stuff. Will you do what you can? Right? It's like having a building, you have your fire exits, you have everything. Sure, disasters can happen, but you've done what you can do with what you have. You've described cybersecurity as defense and depth. I'd love for you to walk us through what that actually looks like for a normal small business. How can we practice that? Yeah, defense in-depth is a concept that surprisingly even cyber security professionals can and frequently do get wrong. Defense in-depth is in a nutshell having more than one layer of defense stacked one on top of the other. So if one layer of defense fails, the other one can sustain. So it just makes it a lot harder,
Starting point is 00:39:13 a lot more expensive to get to what we call the crown jewel or the important asset. I'll walk you through an example. Let's say you have your customer database. That's the most important thing that we have. We want to protect that. And then we have our attacker, and the first thing they do, they send the phishing email. Okay. So the phishing email comes, but you have your anti-spam filter, so the spam filter blocked that. So that's layer one of defense. So you didn't even see the email, that attack failed. Now, let's say a more sophisticated attacker, they crafted their email in such a way that it even passed that spam filter, and it went into your inbox. So you looked at it and you said, well, you know what?
Starting point is 00:39:52 This looks like spam. Sorry, report spam. So the second layer of defense here was your awareness. So that's another strong layer of defense, right? Let's say they were, you know, the email came from a trusted supplier. So they hacked the supplier. They came to you. So like, oh, this is a legitimate email.
Starting point is 00:40:06 I need to do something. You click on that link. But when you click on that link, well, your anti-malware solution, your endpoint security systems, blocked it from being executed. So that's another layer. So it failed here. And that can, you know, go on, go on like for longer. But you get the concept, right? So we have multiple layers of security. In the, like, late 90s and even early up to the 2000, let's say, 2005, 2010, there were organizations that didn't have firewalls, so they'd have nothing. So the fact that we put one layer was a huge thing. But nowadays, you'll find these layers work.
Starting point is 00:40:45 in tandem. This, and it's controversial, I keep saying defense in depth because when it comes to marketing of the marketing of cybersecurity, people say, human is the weakest link. I can have all the defenses, but if a human makes a mistake and click on something, it's game over. Well, it's not. As we explained earlier, there are multiple layers of defense. And I say that in defense of the human, in defense of the employee that's overworked, I clicked on something, sorry, if someone clicked on something and it's game over, then your security were fundamentally. tell you wrong. So yes, the way cybersecurity is approached nowadays, how it should be, multiple layers of defenses. Let's move on to AI because I feel like AI is such a hot topic in
Starting point is 00:41:27 cybersecurity. How has AI changed the landscape? What is new now that AI is here? Yeah, everyone's topic. And I've been labeled sort of anti-AI, which is not true. AI has definitely made cybersecurity professionals a lot busier because every business now have an AI and they call us and say, hey, is this okay? Is it not okay? And then we need to go and look. Look, it definitely has changed things and it's here to stay. But also, it's not the sort of doom and gloom and the movie, Hollywood things that we read on the news of these AI escaping and hacking things. This is just marketing. Look, the truth is always a bit more nuanced. AI, I mean, the most obvious, one that we all need to be careful and be aware of is the deep fakes. So deep fakes is a huge,
Starting point is 00:42:18 huge problems. And I know we talk about entrepreneurs and small businesses, but even for children and in schools, it's been an absolute nightmare and law enforcement deals with that all the time. So deep fakes, faking voice, faking video is something we need to be really careful of. But even as I said earlier, I can really create a website really quickly that looks exactly like a replica of a real one. Now, that wasn't overly difficult before AI, but now it's even faster, if that makes sense. So in the hands of a skilled hacker,
Starting point is 00:42:51 AI can make certain aspects faster. Now, is AI this really advanced thing that's going to do, go and hack things? That's not true. And the big AI companies have actually sort of safeguards against making AI do these things. There are ways around it, but let's say, if someone is completely unskilled
Starting point is 00:43:10 and they're just trying to do something, and it's just not happening. So that's one aspect of it. The second aspect, which is what keeps us busy, is businesses are really quick to sort of want to use AI. And this is where things get a bit more complicated because when we say AI, so what are we really using? Are we just prompting chat GPT?
Starting point is 00:43:28 Or are we giving AI access to everything and making it talk to customers and do finance for us? Or are we even using AI? But we have this SaaS service or this product. And then all of a sudden this product on their website says we're AI enabled or AI powered. What does that mean? Do you feed our information to your AI? Is it going to the AI company, which is really a private company if you think about it?
Starting point is 00:43:54 So all these things are making life a bit more interesting for cyber security professionals and small business owners. So we want to use AI. We want to be on top of the new technology. But we also need to stop and think, what is it that we're using AI for? what does the AI have access to? And more importantly, where's my data going? Is it going to a private company? Why do I trust that private company? This private company could get hacked or they could do something like sell my data somewhere. Big tech companies have done that. And we love to see news. And this big tech company got sued for selling election information. Well,
Starting point is 00:44:31 they don't care. The hundreds of millions of dollars find that they pay. This is just one week's earning. So these things I think we need to keep in mind when we use something like AI, just why we use it and how we're using it is fundamental. Yeah, are we getting to a point where we literally just can't trust anybody's face or voice digitally? Unfortunately, yes, it happened to me. I thought I was this great AI detector up until someone, I'm in Melbourne, Australia. And yeah, yeah, I thought I was like this, you know, a great video guy that I know I can detect it. And one of my fellow YouTube, He visited me in Australia and he was just showing me what he does. I'm like, oh, this actually was AI.
Starting point is 00:45:12 So what he does, he record himself talking. And then for his Instagrams, it's him, but it's really an AI of him. That looks exactly, I couldn't tell. Nobody could tell up until he pointed it out. It looks like him talking. It's his voice, but the video is entirely fabricated. And it looked real. And with the short form videos, because the resolution is low, I couldn't tell.
Starting point is 00:45:33 Like a few months ago, AI would give you a few more fingers. or things will be obvious, not anymore. And to the human eye, my eye, at least, it's not always detectable. So absolutely. And stangy enough, I got an email from Microsoft saying yesterday that they want to rely on past keys, which is a more secure way of authentication.
Starting point is 00:45:53 So no longer, you know, the voice authentication and all of these things are going are no longer secure. So absolutely seeing a video and usually women get targeted, like with explicit, like someone leaks, quote-unquote leaks, explicit videos of an individual. And, well, that video is completely deep fake, and it has been happening. And, yeah, it's something I actually had to deal with, with law enforcement where they always target the vulnerable, they always target the young.
Starting point is 00:46:20 And it is a problem. And we need some kind of a strict regulation on, you know, putting someone face on a body that doesn't belong to them or do these things. It's crazy because as a creator, you actually see a lot of opportunity in this. My team is actually creating an AI avatar for me. I just did like the whole turning my head a million ways and walking towards the camera and turning my body every which way so that they can create an AI avatar for me. Is there risk in having an AI avatar that you actually create for yourself and for your content?
Starting point is 00:47:00 Look, this is a difficult thing to sort of answer and guess because, like, let's think about it. look, what could go wrong? Because you and I are content creators. So if someone wants to impersonate me, there is thousands of footage of me speaking and it's really straightforward and exactly for yourself as well. And we could say, well, it's illegal. Well, the hacker is doing something illegal. I don't think they're going to stop and say, oh, hold a second. I'm not going to do that because it's illegal. They'll still do it. So for me, I don't think there is any risk from a content. Yeah, we're already out there. We are out there. And, you know, I always say, I tell people, if someone wants to hack me, you know what, just go and hack me.
Starting point is 00:47:39 My phone is full of food pictures and sell. Like, it's completely useless. But, like, I'm aware, as I said, my stuff could be used to harm someone else. I don't think there is a risk from a content creation perspective, which is not really a cyber security thing. For me, I actually went a complete opposite of that. I do everything physical and analog now. Even a photo has to be photographer. I'm strictly not a fan of AI.
Starting point is 00:48:04 however, it's a technology, it's a new thing. There is a viral Mr. Beast dance video that people thought it was AI, but then it was real. But it is the world we live in. And as an entrepreneur, there's no reason why you shouldn't jump onto these technologies. Like we said in the conversation, as long as you know, you know, your critical assets or private information or stuff or financial information, don't feed that into AI. You should be fine. If it's avatar, if it's fun stuff, it's, why not? I think one of the new things coming up in AI and cybersecurity is for a couple of years,
Starting point is 00:48:37 AI was mostly like chatting, chatting to chat GPT, getting help writing emails. But now we've got AI agents that are jumping from tools to tools that are kind of like AI digital employees. How worried do we have to be about AI agents and their ability to hack our companies or their cybersecurity threats? AI, I mean, agentic AI or AI agent is exactly what you describe, where you have the AI, but instead of it just being a prompt or a chatbot, you're actually giving it access to stuff and can do things for you. For example, you can program the AI to send an email from your email or have given access to your calendar, or in some instances, it can be a chatbot on your website. AI agent is something that needs to be treated with absolute care. It shouldn't be just just because it's, you know, just because it's. Exist doesn't mean we need to use it.
Starting point is 00:49:30 There are many issues with AI agents. The first one is, the obvious one is access. Well, you're giving a piece of software access to things. So we need to assess that access. We'll go back to the principle of least privilege. Does the AI really need access to everything in my email or does it need access to a copy of certain emails? Does it need access to calendars of everyone or perhaps you can create a dummy calendar for certain
Starting point is 00:49:52 things and that can access that? So the first one is, you know, don't be too generous with access. treated like, you know, it's just another piece of software. I don't want to say it's another employee. It's an employee or it's just really a software. So we don't really give software access to everything just because we can. I think that the craze or the hysteria that we face now is, is, oh, I can do this. Therefore, I need to do, I need to use it.
Starting point is 00:50:17 No. As a business, do you really need that? And if not, then why? And that could be also costly in terms of tokens. And we've heard lots of stories of companies paying so much on AI tokens. a famous one of the fan companies, they laid off so many employees just so they can afford paying for the tokens
Starting point is 00:50:32 and it's not always a smart business decision. This is one, and the most important one as well is, well, accountability. So as I found out, just because the AI is doing something doesn't mean the AI is accountable for it. I'm still accountable. So if I get the AI to review my legal contract, great.
Starting point is 00:50:52 The review may be accurate or may not be accurate. Who's accountable? If I get into legal, trouble. I can't say, oh, well, oops, AI did it. No, it's still me. So we need to really stop and think, well, I'm still accountable. AI is just software, it's doing something. I'm still accountable. Just like a normal employee. Yes, the employee can make a mistake or so, but ultimately, the accountability falls on leadership or on the CEO or on the board of directors. So these are the things we need to really be careful about. So I do think one of the things that we need to be
Starting point is 00:51:23 worried about with our employees in AI is actually, we might be rolling out. specific company AI tools, but because AI is kind of popping up everywhere, employees are probably using all these disparate AI tools or like whatever tool they think is fun, and they're probably using their company computer and thinking it's harmless. Is there a risk in people just using like not approved AI tools? Absolutely. And this is not a new problem. We used to call, what we still call this shadow IT or unsanctioned software. which is really what AI is what you just described. We had this problem even before AI.
Starting point is 00:52:02 We'd have, let's say, the marketing team, they just found this online tool and they start using it. They didn't tell everyone and they put customer data in it without sort of the cybersecurity team doing an assessment and saying, hey, this is approved. We can monitor. We can do that. Same thing with AI. If we have an employee opening their own personal chat, GBT, putting company information in it, yeah, we didn't really approve that.
Starting point is 00:52:25 So they did something that a business didn't approve of. it is really hard and it's something that we need to, like I said, do our due diligence. We need to have clear policies that say do not put company information into AI tools. Also, the other thing I saw, even in big tech companies where they're really skilled so they have built different agents to do different tasks, they always have someone sort of verifying and validating the output of AI. So really skilled programmers, they do this cloud code. The AI is producing code. Before it goes to production, it needs to be reviewed. It needs to be tested by a vetted senior programmer.
Starting point is 00:53:07 So this way we have safeguards against what goes into AI, but what comes out of AI. That is really essential. There is the other thing, of course, like I said, in terms of privacy and stuff, there is a setting in all these AI chatposts that says something along the lines of don't use my data to train AI. We should all toggle that, and this way, allegedly, our data doesn't go in there.
Starting point is 00:53:29 So that's something that we need to do. But there has been instances, a really famous one, early days Chad GPT, the source code. Some Samsung employees really leaked the source code, not leaked, they're just posted it to ChadGBT. And it's a huge problem because ChartGPT will use it to learn. But that source code is massively, massively pricey and important intellectual property that should not have gone there. So these things happened. Yeah. So we do need safeguards against who uses AI.
Starting point is 00:54:00 What do we use it for? And exactly like any other piece of software and employee, shouldn't be just using random softwares and use it for business purposes on business laptop. If we have like a company version of ChatGBT and Cloud, is it safe to upload certain financial information or code or whatever it is, is it safe to upload those types of things or is it still not safe? So when we say a company version, There is like a rag, which is a local AI that you can have, absolutely where the data is not going elsewhere.
Starting point is 00:54:31 And also, if it depends on the solution that you use, there are against safeguards that just doesn't get your data leaving the organization. And then the word safe, we need to also really put it under the microscope, safe in the sense. Okay, so the data is not leaving, but is it safe from mistakes? It can still get hacked, yeah. Sure, but also is it safe from mistakes? I'm doing financial data and I get the AI to be my finance officer. I'm still accountable when a mistake happens. And this is the problem, the inherent problem with AI, Hala, is it makes mistakes.
Starting point is 00:55:07 You know, humans make mistakes, but they're accountable. AI is a software, it will make mistakes. And that's a problem. So if it's doing financial data, financial analysis for me, I need to validate that. So if I can validate that, no worries. It can really save time. If I have a finance officer, they use AI in some sort of. tough way, but then they review everything, that is fine. It's just us validating and verifying
Starting point is 00:55:30 that things are fine. Also, like I said, like need to know basis or least privileges, meaning I'll use AI just because AI can do certain things and I'll give it certain amount of data. It doesn't mean I need to give them access to everything. Just give it access to what needs to happen and then revoke that access. So I'd like to talk about, aside from the technology and AI, the people who actually have keys to your business, like a lot of us think that the only way that our business is vulnerable is through a stranger, a hacker, is going to come hack our company. But it turns out that our employees can actually be a really big risk, especially employees,
Starting point is 00:56:07 maybe disgruntled employees who have left the business. Is that right? Absolutely. That technical name we use for it is insider threat. Although some people don't like the word insider threats, like humans aren't threat. it could be exactly what you said. So one scenario is a disgruntled employee. They know all the business secrets, everything,
Starting point is 00:56:26 and they leave, and six months later they said, hold on a second. I'm not happy with that business. Let's do some damage. And the way we reduce the attack surface, we reduce the impact is back to basics. They shouldn't have access to everything. So when they hold the key to the business, well, they need to hold the key to certain aspect that they need for their job.
Starting point is 00:56:47 And this way, if they do damage, will that damage is restricted. That's one. Two, a common mistake that happens even with large businesses. In fact, probably more with large businesses than smaller ones is when someone leaves, we call it the off-boarding process. They don't take all of their access out, so they may still have access to certain applications or certain things that they log into. So that's a problem. So we need to have a process of just like we're on-board employees, we need to know how we off-board them, and that includes revoking access. The third one is also an hour. contract legally, we need to say that, you know, if you leave, please don't go on social media
Starting point is 00:57:24 and just spell out all our secrets. That's illegal, but having it in the contract doesn't hurt. There's been many instances of that happening, a really popular one, a big tech Australian organization that has laid off people, and they laid off one of their very senior software engineers. And the next day he creates, I think I want our YouTube video, explaining everything he's done for them, everything he's built. It's online. It got millions of views.
Starting point is 00:57:53 So, yeah, that's really valuable information that the employees build out. And you know how awkward it is for an organization to legally go after someone. So these things, we need to be careful of the insider threat. There's other aspect that we forget when it comes to insider threat is the employees are humans. They make mistakes. So I, even early in my career, as an example,
Starting point is 00:58:16 I made a mistake early early in my career. as I was working faster and faster, I ended up deleting stuff that were really important files. I did that by mistake, and I had to go find backups and restore backups. So mistakes can happen. It could be a really genuine unintended mistake, which again goes back to why did I even have access to that stuff. Why was I able to delete without someone looking over my shoulder without a chain of approvals? All of these things that sometimes we may think of as tedious or unnecessary. We want to be fast.
Starting point is 00:58:46 We want to be lean. well, there is a course that comes with that. This has been such a valuable session. Like, I feel like I've got to, like, do so much work and make this, like, a core initiative for my business. If you're a hacker, please leave me alone. But I want to play a game with you. It's called Find the Back Door.
Starting point is 00:59:07 So I want you to find the back door. I want you to break it down and then close the back door. So basically, how can somebody hack this company? I'll give you a scenario. and then how do we actually fix that? What is the solution to that? Okay, so the first one is the media company. The company works with freelancers around the world.
Starting point is 00:59:29 Some use personal laptops and personal email accounts to access company files. Where's the backdoor? There are about three backdoors in here. The first one is offshore employees. you need to vet those employees, especially if they have access, so have some kind of vetting process,
Starting point is 00:59:50 and that could be something as simple as use an agency that does the vetting for you. So make sure they're not hiring criminals just as a basic sanity check. The second one, of course, if you can't give them laptops, then restrict what they can access. Absolutely restrict what they can access.
Starting point is 01:00:10 Don't give them what we call as a right. So read access. maybe less damaging, but right access, which gives you the ability to delete stuff that should absolutely be restricted on a need-to-no basis with strict approval processes. The fourth one is a personal email address. This is a huge no-no because when they leave the company, they own the data. It's on their email. So if there's anything sensitive, they'll take it with them.
Starting point is 01:00:39 And that's precisely why organizations have emails on the company domain, because the company owns that. As soon as they're using personal emails, well, they own their data. So you're really handing over their data and you're as vulnerable as any one of them. One of them could be criminal, one of them could be hacked,
Starting point is 01:00:56 or you just really don't know. So you're overly exposed. If you want to use offshore employees or contractors, really restrict them to a very specific task and have in mind that if that person gets compromised, what's the impact? And do I accept the impact and consequences. If no, then find alternatives.
Starting point is 01:01:16 The fast finance team, this is the next scenario. The founder and the finance team approve urgent payment requests through Slack because it's faster and more convenient. Yep. So anything that we do fast, it just means we're going to make more mistakes. So with speed, the compromises more mistakes. Yeah, a big really red flag here is approving things over Slack. It shouldn't happen this way. We need to have a chain of approval, that's really clear because the strong use case is if one of your employees get hacked and their account gets hacked. So the hacker is using your employee's account and, well,
Starting point is 01:01:54 everyone has access to Slack. They're going to ask you to approve something. And fast means you're just going to approve it. So that's a call for disaster. You will lose money. So that's what you're compromising. So you need to have the fix for that is have a proper approval process. And that approval process may just mean it will take an extra. five minutes. It's not really, it's not really war on pace. It's literally just a proper approval process that will save you a lot of headache and will save you time in the long run. Yeah, potentially a lot of money. Exactly. Okay. The last scenario, the SaaS heavy e-commerce brand, the company uses
Starting point is 01:02:31 dozens of third-party applications connected to customer and payment information. That is, everything is wrong with this. This is a dangerous one. Surprisingly very common, Hala. Okay, the first one is when they use so many SaaS applications, but you need to know who owns that SaaS service because there has been cases where it's foreign government
Starting point is 01:02:56 operating from a different country, having this amazing SaaS application that does amazing things and it's surprisingly cheap. Well, the purpose of the application was to collect information. So you need to really vet and know who you're dealing with. So the first thing is we call it supply chain management. supply chain, meaning your suppliers, in this case is your SaaS providers. Just make sure you know who you're doing business with instead of just randomly signing up for things
Starting point is 01:03:18 because they are quote-unquote cheap and fast and they do the job. So because it's a legal liability if you're leaking customer information to somewhere that shouldn't go. It's a huge problem. This is one. Two, again, know who you're dealing with. A small SaaS app. What if one of your providers get hacked and they have access to all your customers? And therefore, once you know who you're dealing with,
Starting point is 01:03:41 second one is manage access. Why do all of them have access to everything? Really common in the real world, sadly, but manage your access. Again, need to no basis, least privilege, all these really timeless principles, meaning you restrict access. I'm pretty sure that business, whatever it is, doesn't require everyone to have access to everything. The only reason why businesses usually do that where they give everyone access to everything is just lazy. It's easier. It's just take everything on. And that's a call for disaster. So these are the two fixes. Manage your supplier is number one.
Starting point is 01:04:15 Number two, manage your access. I love those principles. I'm sure everybody tuning in is learning so much and getting so many ideas of like where they need to start first. Let's say, unfortunately, our company gets hacked. What is something that we shouldn't do? We get hacked. Somebody just stole a bunch of money from our bank accounts.
Starting point is 01:04:35 What shouldn't we do in that moment? really difficult because the first reaction that happened to all of us, and myself includes we panic. And to tell someone not to panic, it's unreasonable. So I'd say panic, but don't act. It's just like, you know, when I'm sure as a business owner and even as someone on the internet, sometimes you get angry and the advice is to don't reply to an email when you're angry or don't take action.
Starting point is 01:05:02 Just like, just sit back. It happened. It's a problem. We're going to deal with it in a systematic way. So I'd say the first thing is don't interact with the hackers, don't reply to emails, leave everything as it is. And in some instances, I'd say, don't actually close the laptop or don't just leave everything as it is, reach out to an expert right away.
Starting point is 01:05:24 And there is levels to that. So reach out to law enforcement. It's a sort of contested thing to do because usually enforcement are sort of overworked, underfunded, and may not be always be able to help. But you'd be surprised, law enforcement can help. Having that consulting company, you have them on speed dial, you have their number, get an expert right away to do it. That's the most important thing. But the biggest one is what we said earlier.
Starting point is 01:05:50 Do not interact with the hackers because the first thing they will do is try to get more access. So they'll say, oh, sorry, mistake, just do this one more thing because they're trying to get as much foothold as possible. So don't interact with them. They're really skilled at getting you to do what they want you to do. and they're going to use the fact that you're panicking to their advantage. So yeah, disconnect, completely disconnect, get an expert to deal with it right away. Like, don't take actions. And the worst thing that businesses do is they'll have like an IT support person who's really,
Starting point is 01:06:22 they don't have the expertise. I'm like, okay, go deal with it. And that person ends up making things a lot worse. So I think this is a big, no, no. Get an expert to deal with it right away. Such great advice. Abed, this has been such an awesome interview. Before we go, I do want to talk to you about your entrepreneurship journey, your business.
Starting point is 01:06:41 So you actually started creating content and you've created a business out of educating people. And it all started because people would just ask you questions, your colleagues would ask you questions, and you just wanted a way to not have to answer the same thing over and over again. So just talk to us about your story, how you ended up growing this content business, how you make money today. and hopefully you can inspire somebody else who's a thought leader in their space to become a content creator and start their own business too. Yeah, absolutely. I mean, it's funny. I still don't think of myself as a business or even a content creator. But the story started. It was during the lockdowns. And I was working at PWC, which is a consulting firm. And as a senior manager, part of our job is to coach consultants and senior consultants.
Starting point is 01:07:30 So I'd have these one-on-one calls with them. And I really don't like Zoom or online meetings, so I'd prefer it to be in person. And I remember one day I had like three or four back-to-back calls with junior consultants, and they were asking exactly the same question over and over. So I get this idea where I'm looking, no what, I'm just going to film myself answering those questions, and I'm just going to send it to them so they watch it. And I just put it on YouTube as somewhere to upload the video on, like not as a sort of discoverability, So I thought no one would find it.
Starting point is 01:08:02 I watched YouTube, but it didn't occur to me that the video that I'll put, strangers will watch it. So I said them, I told them before you do the meeting, just watch this video, and then you can ask your questions. And I left it, and then I think months later or so I saw, oh, there was comments and likes and the strangers watching it. We're like, oh, well, let's just answer more questions, I guess. And I started answering them, and it wasn't, like, it wasn't sort of a business,
Starting point is 01:08:29 or I had no idea that YouTube pays me your money. And while it's a small amount, but I didn't know that was a thing. And when I got the first paycheck from YouTube, it was like $50, I'm like, that's a mistake or like, how? I didn't put two and two together. It's not the universe that I'm a part of. I had no idea. So that was YouTube.
Starting point is 01:08:48 But then I started getting messages from people and individuals, like from all over the world. And the first one was, like, I could see in the picture. It was a dad and kids. And it's like commenting on my video. He was somewhere in an African country, and then it's like, actually, I got a job. And for him, a job is they changed their life. So got a full-time job, completely new field, highly paid so it improved their life. And then it started to spiral.
Starting point is 01:09:12 I started getting these success stories, either in a comment, sometimes on an email thing, I actually followed your advice. I got a job. It changed my life. Thank you so much. And the more I posted, the more I get nowadays, every time I look in my inbox, there's at least one message a day from someone, somewhere in the world, has actually followed your advice, which my advice is really just do these practical things,
Starting point is 01:09:34 learn and apply yourself, and you'll get a job. It will take time. It's challenging, but it's possible. So this really gave me the drive to continue. I felt that I was making a difference, and I felt that I just felt responsible. I felt responsible that people watch my stuff. Now, I need to give really the most accurate advice. I need to do what I can. Time management became really difficult. My job is really, really demanding as a consultant, but I enjoy it. And because I do it, I've been doing it for so long, it doesn't require a lot of thinking from my end. So I was able to manage, but then I've always wanted to do consulting on my own. So I started a cybersecurity consulting company, and I have long-term clients. So I'm active in the field. I do that, but at the same
Starting point is 01:10:21 time, I create YouTube videos. I'm not very good at like creating a lot of content. So I'll create one video a month, really. That's my average. So in 12 months, I'll have like 13, maybe 15 videos of YouTube. That's all I can do. Within my advice, because cybersecurity is a range of jobs. It's not just one job. There was one nation cybersecurity called governance risk and compliance. At the time, I didn't feel comfortable recommending what was in the market. So I thought, I'm going to take three months and just tried to create something. It took me a year and a half and I created my certification, got it accredited, and I just put it out there and thank God it's been really successful in the sense. People started to recommend. And that's the GRC mastery, right? Yeah, yeah. And people started
Starting point is 01:11:07 recommending it to each other through word of mouth. So every time I go to a conference and someone says, hey, someone did it in the team, then all of us did it in the team. So it became bad. So really my time now is between consulting. I help usually large organizations. I've got long-term relationships with them. I do have some consultants that work under me. And yeah, the occasional YouTube video
Starting point is 01:11:31 where I talk about what's happening in cybersecurity and how to land a job. You got a full plate of clients. You have a team. And then you're able to create content and give back. I mean, that's an incredible career that you have. So, okay, let's bring you back to cybersecurity and wrap this up.
Starting point is 01:11:47 So if you're a young improfitor listening right now, what are the three things that we should do tomorrow morning to protect our company? Number one, two-factor authentication. Use your authenticator app or a pass key. This is a non-negotiable, no exception. This includes all of your employees. Number two, a password manager. I know it will take you some time to get used to using a password manager.
Starting point is 01:12:11 I can promise you it's a lot more convenient for you and your team to use a trusted password manager, it will save you time in the long run. It will save you so much headache. And number three is, we talked about it a lot, is manage your access. Just because someone works for you
Starting point is 01:12:28 doesn't mean they need to have access to everything in your company. Provide this access, give them access only to the things they need and know more and have fun as an entrepreneur. Amazing. Beautiful recap.
Starting point is 01:12:42 Thank you so much, Abed, for spending time with us on Young and Profiting Podcast. Thanks for having me and thank you so much for your time. This has been an absolute pleasure. Big thanks to Bit Defender for sponsoring this episode and for keeping small businesses safe. Protect your team, your data, and your business from scams, ransomware and fishing. Get 30% off Bitdefender.com slash profiting. That's Bitdefender.com slash profiting. And if you enjoy this episode and learn something valuable, we'd greatly appreciate a five-star review on Apple Podcast or Spotify.
Starting point is 01:13:09 Reviews help us reach more listeners and continue bringing you these conversations that educate, inspire, and empower. You can also connect with me on Instagram, TikTok, or X at Yap with Hala, or find me on LinkedIn by searching Hala Taha. This is your host, Hala Taha, aka the podcast Princess, signing off.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.