Business Email Compromise episode artwork

EPISODE · Sep 29, 2022 · 49 MIN

Business Email Compromise

from QPC Security - Breakfast Bytes · host QPC Security

Ken Dwight is “The Virus Doctor” – Business consultant and advisor to IT service providers and internal IT at many businesses who have come to him for his training, has his own direct clients. Ken conducts a monthly community meetings for alumni. He provides a list of curated items of current interest for discussion and resources, and has a featured topic which often includes another speaker to provide breadth of perspective. He has been doing this community service for 83 months! I asked Ken to cover with me some topics that from his perspective don’t get talked about enough. Business Email Compromise Also known as CEO fraud. Impersonating a CEO for purposes of wire fraud. We are focused on the technological solutions. There is no technological solution for eliminating BEC. CEOs must be part of the solution. Example: Subcontractor to Airbus. Used to dealing with multi-million-dollar wire transfers. BEC is a large Fortune 500 issue, it scales down to one user environments. Title companies are a big target. Retention policies and standards for WHERE to store what kinds of data to make sure that email is not a file server thereby increasing the risk of what data is compromised as part of BEC. Perfect example of the beginning of an incident response plan or a tabletop exercise. Orgs must define the cost of compromise. That plan needs to be in place long before. It makes a recovery so much more straightforward. Attackers analyze their victims in tiers. Potential victims $10 - $50mm revenue organizations. Reputational damage, but not big enough to have an adequate cybersecurity budget. ShadowIT is a problem, which is why you must address it with a CFO-enforced procurement policy. Proactive management of M365 tenant security configuration is so critical The security of your tenant is not included in the fee for biz premium or the overall licensing. How much activity there is, changes, products, services, vendors. Ideal stack, layers, point solutions within that. Revisit that in a period of time like a year. This is a nice resource for M365 security and BEC. https://www.blumira.com/office-365-security-issues Direct advice from Ken One topic I believe falls directly into this category is the issue of Business Email Compromise, as opposed to actual malware / hacking / ransomware attacks. As you know, the losses to BEC still represent a greater dollar value than ransomware, according to the FBI statistics. But BEC isn’t even a technology problem, it’s pure social engineering – and no additional layers of hardware or software “solutions” will prevent it or reduce the cost to its victims. In my opinion, that’s why you hear so little on the subject from the cybersecurity vendors. Another topic I find interesting, but haven’t really heard any vendors or industry pundits talk about, is the whole new ecosystem and infrastructure produced by modern threat actors. The whole business model of these sophisticated criminals has created occupations, titles, and job descriptions that didn’t exist a few years ago. Some of these are a result of the specialization, compartmentalization, and outsourcing by these organizations; here are a few that come to mind: Breach attorney Ransomware Negotiator Initial Access Broker Cloud Access Security Broker Multiple “As-a-Service” offerings: Ransomware as a Service Phishing as a Service C2 as a Service Another area that is mentioned fairly frequently, but typically fueled by more heat than light – and raised as a point of frustration by MSPs and IT Solution Providers in general – is the users who still believe they don’t have to worry about cybersecurity, hackers, malware, or ransomware, because they “don’t have anything the criminals would want,” or words to that effect. I believe those users need to comprehend how real and serious the threats are to their business. By defining the multiple tiers of threat actors, the threat vectors they may employ, their potential victims, the assets owned and managed by those victims, and the attacker’s strategy for monetizing those assets, I believe it becomes obvious that every organization and every individual is the intended target of some subset of those threat actors. Visit this resource for help making argumentation. Ken is working on some additional materials for end user cybersecurity awareness training. https://qpcsecurity.podbean.com/e/the-real-reason-you-cannot-afford-to-have-a-cybersecurity-incident/  

Episode metadata supplied by the publisher feed · Published Sep 29, 2022

Embed this episode

Ready to play

Business Email Compromise

0:00 49:33

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

The Wall Ronald W. Chapman II and Sean Weiss The Wall protects our republic by safeguarding our democratic processes, civil liberties, and national security through laws and institutions. Its role in protecting the republic involves balancing security concerns with humanitarian and legal considerations.With over 50 years of legal and government experience combined, Ron Chapman and Sean M. Weiss pull back the curtain on the US government, the U.S. Judicial System, and some of the most influential trials in history that continue to shape our nation today.Join every week for unfiltered conversations, in-depth analysis, and commentary from some of America’s boldest thought leaders.Be sure to follow the podcast on your favorite platform so you never miss a new episode. From Passion to Profit: Heart Centered Strategies for FitPros Nichola Page Welcome to From Passion to Profit, the ultimate resource for fitness professionals driven by their passion to inspire and empower others on their business journey. Hosted by Nichola Page, a seasoned health and fitness business specialist, this show is tailored for FitPros and Studio Owners looking to supercharge their small business.Discover game-changing strategies and actionable tactics that will not only help you attract and retain clients but also transform your health & fitness venture into a thriving small business. Dive deep into topics like marketing, sales, financials, client retention, and business scalability. Learn how to master the art of growing a health & fitness business, and unlock the secrets to financial security, freedom, and flexibility.Join Nichola each week as she and her industry guests provides invaluable insights to guide you towards a successful and sustainable fitness business. Whether you've had your business for years or just starting ou Iran's Gambit Ali Alfoneh "Iran's Gambit" is a weekly podcast produced by Ali Alfoneh, on Iranian politics, and Iran's national security strategy, intentions, capabilities and impact. Mark Kollar’s Financial Cornerstone Mark Kollar Mark Kollar is a well-known financial educator in the Chicago area and hosts the popular weekly financial radio show, Retirement and Income Radio. He is sought after throughout the state of Illinois for his expertise in retirement planning and retirement income planning. His clients include retirees from United Airlines, AT&T, McDonald’s, Chicago Transit Authority, and HFC.As a retirement and income planning specialist, Mark helps retirees and those near retirement protect their savings, reduce income taxes and taxes on social security benefits and create a retirement income guaranteed to last as long as they do. Mark graduated from Loyola University of Chicago where he received his B.B.A. degree. He is a Registered Financial Consultant and a Certified Estate Planning Professional and has pledged always to put the needs of his clients above his own.

Frequently Asked Questions

How long is this episode of QPC Security - Breakfast Bytes?

This episode is 49 minutes long.

When was this QPC Security - Breakfast Bytes episode published?

This episode was published on September 29, 2022.

Can I download this QPC Security - Breakfast Bytes episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!