Episode Transcript
[00:00:00] Speaker A: Foreign.
Welcome to the Clear Impact Podcast, brought to you by Mitre Brands University. Thanks for joining us today. My name is Sheri Conner and I am your host.
[00:00:19] Speaker B: And they'll tell you that if you'd like the encryption key to unlock all this encryption, it'll cost you x amount of money and it's usually in this 5, 6, 7 digit range based on the size of your organization to have this done.
[00:00:36] Speaker A: So. Good afternoon. We are here on the Clear Impact podcast and I have in studio Matt Meyer, who is our director of cybersecurity. Welcome.
[00:00:46] Speaker B: Hey, how you doing, Sheri?
[00:00:47] Speaker A: I'm doing well. Thanks for making time this afternoon. So before we start talking about some best practices around staying safe online, tell us a little bit about you, about your background, maybe how long you've been here and your roles and responsibilities.
[00:01:01] Speaker B: Yeah, absolutely, Sherry. I've been in cybersecurity from an industry perspective for a total of over 20 years. My tenure here at Mitre Brands is a little over three and a half years.
My roles and responsibilities really as director of cybersecurity, as you mentioned, and just in that it's making sure we have a mature cybersecurity program throughout the organization and in that program includes not only the safety and protection of Mitre Brands and all the brands that we represent, but also I think for today, what it also represents to our customers in dealer, community and suppliers for that matter.
[00:01:40] Speaker A: Yeah, no, I think the information we're gonna cover today will hopefully benefit everybody that's connected to us. And none of us are exempt.
Right. We can all be a target. So for like a small, like say a mom and pop operation, for those business owners who think that they maybe are not a target, why is cybersecurity something that they should still take seriously?
[00:02:04] Speaker B: Yeah, I think the more we can get companies in, however large or small, to take cybersecurity more seriously, the better it impacts them indirectly or directly, oftentimes without knowing it.
You have, of course, your standard risk that exists today when it comes to ransomware, full encryption of all your systems, pulling down all of your operations that can really impact your well being as an organization. And oftentimes can result in businesses taking such a financial hit that it could result in financial damages for them for quite some time. So that's one of the major reasons and drivers. The other areas too is the way in which it can manifest itself today. Right. Cybersecurity has changed so rapidly, especially at the inception of AI. What is now happening with threat groups and the bad guys today are they're taking AI and weaponizing it. Right. So the email from some South African prince is no longer that easily seen.
[00:03:07] Speaker A: Yeah, but that was my uncle. What do you mean?
[00:03:09] Speaker B: Right, exactly. Now, emails that look very distinctly the same as an email you might normally receive from an accounts payable or accounts receivable contact at any one of your suppliers or vendors that you do business with on a day to day basis and makes it very difficult for small businesses specifically without cybersecurity program to be able to identify with that.
[00:03:32] Speaker A: So what are some of the common fraud or phishing or scams that people are seeing today? Like what are the things that people can really look for?
You know, do we just have virus scanners on our computer now like we used to McAfee or one of those? Or does it require more than that?
[00:03:50] Speaker B: Well, it absolutely starts there having some minimum level of security protection on your PC devices as well as your primary services, which really email is one of the biggest areas. It's commonly referred to as a business email compromise. And what happens in those scenarios is a variety of different things.
What threat actors typically do as bad guys, they'll try to social engineer a small company or supplier or whatever else it might be organizationally, and they want to get in the middle of those common communications.
So what they'll do is they'll stand up email domains. So it looks like it's Mitre brands, but it's mitrebrands.inc instead of.com in the email. Right. And you have an email that is very much something that looks like what you might normally receive from a particular company. And when you do, you're not paying attention to it. It actually looks like it's the legitimate person you might normally communicate with. It's based off of an order or billing or shipping or anything like that. And it establishes some level of trust. And then additionally they back that up with a level of urgency. Hey, we are waiting on this particular order to get paid. From a payment perspective, we don't see it. Are you sure you sent it? Right. And get some level of urgency and priority around it, not knowing you're not replying to the right email domain or other source. You have someone reply, they create that relationship and then afterwards continue with the business email compromise by saying, well, if you make this particular payment now, we might provide some discounts or we might be able to help out with some future payments to help keep that urgency flowing through the communication. And then that is when usually it's followed up with things like payment instruction changes like your ACH payments or wire type transfers and things that way that then oftentimes individuals believe is what's going on after they've been usually contacted already, not knowingly and have fallen victim to this business email compromise process.
[00:06:02] Speaker A: Wow.
[00:06:02] Speaker B: Yeah.
[00:06:03] Speaker A: So is there like a real world example, either from personal or industry experience, where a phishing attempt was caught before it caused damage?
[00:06:12] Speaker B: Yeah, no. That's a fantastic question. And oftentimes there are definitely successful areas where that's caught. The best thing to do is really training and a focus on cybersecurity training, getting people used to some routine email checks. Right. Know your sources of who you do business with, who your suppliers are, who your vendors are that you work with all the time and that that way you can understand what to expect when you see it. Have people start learning how to inspect email when they come in. Look for the example like I gave a second ago, instead of.com, it's.org for org or.inc or-us or something to that effect. That's just different than what you would normally receive and those are really the best ways to do it proactively is increase the training and awareness for you as a smaller organization with that as a core focus or a conversation today and then you build from that. When people do have them stopped, they do it on the proactive side like I just described, because the education awareness is really high. When it's not, it's also your other processes that you have. So it's how effective are your own business processes you have in your organization and how you make a payment to a supplier or vendor. Right. Do you have other controls? Do you do secondary calls to confirm receiving a payment change? Is this right? Have those kind of actual processes and procedures built into your day to day operations. Really helps in those processes to help stop those things proactively.
[00:07:49] Speaker A: That's excellent. I know. We recently added a training module on Miter Brands University. I think it's called Spot the Fish, which is kind of a play. So it's P H I S H, but it has actual like little pictures of fish on the module and so that really walks people through. It's a very short thing. I think it's like a five minute course and so there's actually like an example and then you can click on the different ways that you can identify that it is not a legitimate email, that it's a fraudulent email.
[00:08:19] Speaker B: Yeah, I think having those courses available are fantastic because if especially a small organization doesn't have some of the funding for that it's real basic. It's like you said, it's five minutes. Give somebody a quick window or an opportunity to kind of learn from that like we just been talking through, and they can leverage it for their own benefit that way. I think it's great. It's either whale and that's the bad guy or the smart, small little fish. You're not expecting is always education and awareness.
[00:08:47] Speaker A: Right? So I know everybody hates getting that little pop up that says it's time to update your system and you have to reboot now and blah, blah, blah. How important is it to keep your systems updated and to have appropriate security or malware protection in place?
[00:09:04] Speaker B: It's critically important, especially in today's world and evolving technology like we touched on earlier with how AI is now being weaponized more and more. In addition to that is how do you take, take that from the normal day to day operations of what you're working on. It might be a PC that you got at Best Buy or some other source. That way, when you don't have a big program or you don't have a team dedicated to it, going back and getting that particular computer updated on a regular basis is always great. Or if you have a small computer software group that you lean on organizationally for, that would be just as effective. Having them work with you on a regular basis, every month, every quarter, whatever the case is, so that your computer and electronic processes can be updated with the latest protections.
[00:09:57] Speaker A: We are sharing our expertise around all topics relating to the window and door industry. Whether you are a customer selling our products or a homeowner doing research, the Clear Impact podcast provides helpful content that makes an impact. Subscribe today wherever you listen to podcasts.
And so it's just like everything else in business, right? You sometimes have to rely on people that know more than you do. And not everybody is an expert in everything. And so there are firms out there that you can hire to come in and help protect all of your online activities.
[00:10:30] Speaker B: Yeah, it's really important and I think the more focus and energy that can be placed on it organizationally, the better.
[00:10:37] Speaker A: Yeah, agreed. So if somebody suspects a suspicious email or a payment request, or if a login attempt doesn't seem right, what should they do immediately?
[00:10:47] Speaker B: Well, as soon as you identify it, stop, right? Take the time to understand and think about what you're doing. So stop, think and then report. That's largely what we do here at Mitre Brands as well, and we work in our cybersecurity program to help train our team members as well, on the importance of that. Right. So stop, think and report are some pretty easy fundamental things. And it's report it to whoever you might want to be able to get some help. Right. So if it's the same small IT support group that you might work at as a small business, or not to inform them that you have it, especially if it's on your PC, have a phone number call. Right. So you can explain to them what you are experiencing. Like all of a sudden my logons or my session has been diverted over when I clicked something to what looks like for me to put in my ID and password that I use on a day to day basis.
Right. That should prompt you right away to think about reporting something like that.
[00:11:44] Speaker A: Right.
[00:11:45] Speaker B: So stop thinking. Reports are really key fundamental there on how you can act when you have something that's suspicious.
[00:11:52] Speaker A: Yeah. Well, and to take advantage of the two factor authentication wherever possible too.
[00:11:57] Speaker B: Yeah, fantastic, Sherry, great point. Every time you can mature your security posture, the better. Right.
So it's another drawbridge. So if you have a moat around the castle, you have a drawbridge. Great. Oftentimes if someone can get through that, have another drawbridge available. Right. And that's what multi factor authentication is, it's that secondary code. Right. So it's not just the password and id, the authentication and authorization aspect of it, it's having multiple layers of that available. So anytime you can afford to have those levels of protections added, the more you're going to benefit from that because the bad guys and threat groups are going to go out and try to in fact emulate those same sessions and hijack those same sessions too even. That's how sophisticated they've gotten. So it's not just a matter of having a good password or not putting your password on a sticky note on your terminal anymore.
Right.
[00:12:54] Speaker A: That shouldn't go there.
[00:12:56] Speaker B: Exactly.
[00:12:57] Speaker A: That's not where my password should go.
[00:12:58] Speaker B: Right.
[00:12:59] Speaker A: And should it be the same password for all of the things I go to?
[00:13:02] Speaker B: Absolutely not. Right. At any level. But yeah, it's exactly the same kind of fundamentals that you want to work through that way.
[00:13:10] Speaker A: Yeah, agreed. And it can be annoying.
Like how many times a day do I have to authenticate myself? Like as many times as I have to.
[00:13:17] Speaker B: Really great point. Yeah, exactly.
[00:13:19] Speaker A: Yeah. Even though it's a little bit annoying, I know it's for the greater good.
So when you're talking about running a small business, and I think we're largely speaking to our dealership audience today, the people that are our customers, what roles should their IT team, if they have one, or their advisors or even their banks and insurance providers play in helping prevent fraud and cybersecurity.
[00:13:44] Speaker B: This is excellent question that I really hope we have folks focus in on, not just from a cyber perspective of cybersecurity and working with an IT professional to help assist you with your company's needs there. Reaching out to your bank. They often offer anti fraud programs. So if you have key people that are actually processing your day to day transactions, always good to see if they can provide some free education and materials. Very much like what we're trying to do with the five minute phishing program that we talked about earlier.
[00:14:17] Speaker A: Right.
[00:14:18] Speaker B: Same thing applies to your insurance providers. A lot of times smaller companies aren't aware of the fact that there's new cybersecurity insurance that you can in fact apply for and obtain.
So that it does provide some level of protection for your organization. So it's just beyond any kind of property or normal type insurance. It's very specific to the fact that you had a ransomware encryption event take place. It brought your business down and you had a real financial impact organizationally. So definitely reaching out to your banks and your insurance providers are very key and critical part of this whole protection program.
[00:14:59] Speaker A: Okay, so this is not on the script, but I have a question. So can you play out what a ransomware attack would look like?
[00:15:07] Speaker B: I can do that. So from a ransomware perspective, oftentimes they source from a phishing attempt or a phishing either email, sometimes they come in as text, which is a different term for phishing called vishing and smishing and things like that. Anything with ing at the end.
[00:15:23] Speaker A: Right.
[00:15:24] Speaker B: Okay, so you know all these different avenues that can come in to establish trust. Someone clicks a link, takes that link after they click it, and unbeknownst to them in the background, launches a malware program that installs a ransomware as well into their system. And what that does is then propagate throughout their entire computing set of systems and environment. And when it does, is designed specifically to then start encrypting everything on that computer. Right.
And then it goes across the whole environment and basically gives a warning signal back to you on the screen. Oftentimes you'll get other email communications from the threat actors that have actually targeted your company. And they'll tell you that if you'd like the encryption key to unlock all this encryption, it'll cost you X amount of money. And it's usually in this 5, 6, 7 digit range based on the size of your organization to have this done. And that's when you want to also contact, if you can, your local law enforcement to let them know what's going on if that ever does happen. And this is also why, right before when we were talking about this, the importance of having something like a cyber insurance coverage that'll help you get through this to offset costs in the event something like this could impact your business operations.
[00:16:50] Speaker A: Yeah, I mean, what do you do? Like, do you just pay it? Do you negotiate? Do you unplug everything? Like, how do you maneuver that?
[00:16:57] Speaker B: Yeah, the best thing you can do is really try to isolate all the computers that have been affected, unplug them if you will, like you just mentioned, just isolate those particular devices. You want to contact law enforcement, let them know what's going on if that's the case. And then you want to also work on how to recover. Right. So it's really, really good to have IT support that also can back up all of your systems and back up your critical data.
So that way, in the event something like this could happen, you can restore back to a certain day as close as you can operationally to really make you whole again and get you working right on new computers oftentimes and other things that come with that. And reinforces the importance of something like cyber insurance. Because that's all of an expensive proposition I just represented to you.
And for any small company or dealer out there, that way could really add some value for them in those events.
[00:17:57] Speaker A: Yeah, I know. That's so scary. Very. So here's our final question. What's the one message you would want every small business owner listening today to remember about cybersecurity?
[00:18:07] Speaker B: Yeah, excellent final question. I think it goes back to what we've touched on already, the importance of where cybersecurity is today and the evolving nature of what it represents from a risk perspective. If you don't hear about something in the news on an almost daily basis now around how very large corporations are being impacted by cyber incidents like a ransomware or payment diversion campaigns and things through email. If you're hearing it in the news and it's hitting larger organizations, it's going to hit smaller companies just as much, in fact, take advantage of those companies a lot more where they might not even know they're making some payments for weeks or months.
So getting a program pulled together is important. Looking at some of the fundamentals like we talked about with working with your banks, your insurance providers, getting a somewhat footing around the importance of cyber security organization is critically important.
And then reinforce that with what we talked about on the phishing standpoint, bring it back to the little program here we were offering all our dealer community here.
And that's with the fishing kind of training and awareness and that. Stop, think and report. Right? Just take the time.
Stop think about what you're working on and touching. If it doesn't look like it's good, if it has a sense of urgency that is just out of the ordinary, then something to report and take some action to. So I think those would probably be the big high points that I would focus on from what we talked through today.
[00:19:40] Speaker A: Those are great pieces of advice. I think we maybe need to have you in here on a regular basis just to keep us updated.
[00:19:47] Speaker B: No problem.
[00:19:48] Speaker A: On what's happening out there. Because as soon as the security increases, then people are motivated. Right. This is what they do. So they're gonna figure out a way to try to get around it. And so it's always good to just stay inform and be safe out there.
[00:20:04] Speaker B: It sure is. Thanks so much, Sherry.
[00:20:06] Speaker A: Thanks, Matt. I appreciate your time. Have a great day.
[00:20:08] Speaker B: You too.
[00:20:08] Speaker A: All right.
The Clear Impact podcast is brought to you by Mitre Brands University. We are a part of Mitre Brands, a family of leading window and door brands united by our passion for quality and relentless pursuit of 100%. At Mitre Brands, our common purpose is to deliver value by manufacturing the finest products, services and customer experience every day, everywhere.
Our window and door brands deliver regionalized expertise, products and services, all backed by a national company.
Mitre Brands University is here to educate you, our listener, so that you can be a more informed consumer of window and door products.