Skip to content
TrackPodcasts
businessSep 9, 20261:12:09

Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

About this episode

Young and Profiting with Hala Taha (Entrepreneurship, Sales, Marketing) is made possible by:


Entrepreneurs often assume hackers only target big companies, but small businesses can be easier targets than they realize. A weak password, compromised vendor, or poorly managed access point can expose customer data, disrupt revenue, and damage trust. In this episode, presented by Bitdefender, cybersecurity consultant, Abed Hamdan explains why your business might be an attractive target to hackers and how entrepreneurs can protect their business from today's cyber threats without needing a full-time security team. In this episode, Hala and Abed will discuss:  (00:00) Introduction (00:00) Why Small Businesses Attract Hackers (07:55) How Hackers Target Small Businesses (14:40) How Abed Entered the Cybersecurity World (18:22) Non-Negotiable Cybersecurity Habits for Businesses (28:57) How Cyberattacks Can Destroy a Business (30:29) Cybersecurity Protection on a Small Budget (32:41) Defense in Depth for Small Businesses (40:30) AI, Deepfakes, and New Cyber Risks (54:27) Insider Threats and Employee Access Risks (57:42) Finding the Backdoor in Your Business (1:03:04) What to Do After a Cyberattack (1:05:17) From Cybersecurity Content to Entrepreneurship Abed Hamdan is a cybersecurity consultant, content creator, and founder of GRC Mastery. He has more than two decades of experience helping organizations strengthen their security, manage risk, and navigate complex cyber threats. His expertise spans cyber defense, governance, risk and compliance (GRC), and security strategy. Known online as UnixGuy, Abed has built a global cybersecurity community of more than 600,000 followers by making complex security topics practical and accessible. Sponsored By: Keep your small business safe with Bitdefender Ultimate Small Business Security. Save 30% when you go to bitdefender.com/profiting  Resources Mentioned: Bitdefender: bitdefender.com/profiting  Abed's Training Platform, GRC Mastery: grcmastery.com Abed's YouTube: youtube.com/@UnixGuy/about  Abed's LinkedIn: au.linkedin.com/in/abedhamdan  Active Deals - youngandprofiting.com/deals  Key YAP Links Reviews - ratethispodcast.com/yap YouTube - youtube.com/c/YoungandProfiting Newsletter - youngandprofiting.co/newsletter  LinkedIn - linkedin.com/in/htaha/ Instagram - instagram.com/yapwithhala/ Social + Podcast Services: yapmedia.com Transcripts - youngandprofiting.com/episodes-new  Disclaimer: This episode is a paid partnership with Bitdefender. Sponsored content helps support our podcast and continue bringing valuable insights to our audience. Entrepreneurship, Entrepreneurship Podcast, Business, Business Podcast, Self Improvement, Self-Improvement, Personal Development, Starting a Business, Strategy, Investing, Sales, Selling, Psychology, Productivity, Entrepreneurs, AI, Artificial Intelligence, Technology, Marketing, Negotiation, Money, Finance, Side Hustle, Startup, Mental Health, Career, Leadership, Mindset, Health, Growth Mindset, Passive Income, Online Business, Solopreneur, Networking

Get every episode summarized

Each time Young and Profiting with Hala Taha (Entrepreneurship, Sales, Marketing) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

763 searchable segments. Every word is indexed and playable.

Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

Young and Profiting with Hala Taha (Entrepreneurship, Sales, Marketing)

0:00
1:12:09

Full transcript

Young and Profiting with Hala Taha (Entrepreneurship, Sales, Marketing)Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender. Machine-transcribed; use the interactive transcript above to jump the player to any line.

There's a really famous story on the news. They created a dating app. It's for women safety. But then turned out that app, they took their passport details and all their information. Turned out this app was vibing coded with zero security. It got hacked and it put women's safety in danger. Wow. Usually women get targeted like someone leaks, explicit videos of an individual. And well, that video is completely deep fake and it has been happening. They're always target, the vulnerable, they're always target, the young. It is a problem. And we need some kind of domestic regulation. We're joined today by Abed Hamdan, founder of GRC Mastery and content creator who's known as the UNIX guy online. He brings more than two decades of experience in cybersecurity and risk. So we want to use AI. We want to be on top of the new technology. But we also need to stop and think, what is it that we're using AI for? What does the AI have access to? And more importantly, where is my data going? What's one thing that entrepreneurs are doing where a hacker is going to say this is just way too easy? Something I see frequently is a

founder says, oh my god, we went live last week. You wouldn't believe it. We expected 200 clients and now we have 2000. This tells me that this team is extremely busy. They can barely keep up. This is a really quick tail tail. There are other things that... How worried do we have to be about AI agents and their ability to hack our companies or their cybersecurity threats? There are many issues with AI agents. The first one is... This episode is brought to you by Bitdefender, a global leader in cybersecurity. Have you ever received an email that looked like it came from a bank or a trusted vendor asking you to wire money immediately? Small business owners get hit by scams like this all the time and one click can cost your business everything. Bitdefender, ultimate small business security, keeps your devices, passwords and team safe. Even if you don't have an IT team, protect your business with Bitdefender ultimate small business security. Save 30% when you go to bitdefender.com slash profiting. That's bitdefender.com slash profiting. Now to help us better understand the business of

cybercrime and how organizations can protect themselves, we're joined today by a bed hamden, a bed welcome to Young & Profiting podcast. I have a last thanks for having me. I am really looking forward to having this conversation about cybersecurity. I feel like all business owners need to protect their businesses and with AI, cybersecurity is becoming more important than ever. But let's start at the very basics for the entrepreneurs tuning in. What is something that you think they fundamentally don't understand about cybersecurity? Entrepreneurs usually make I think a couple of assumptions about cybersecurity. I think first the first assumption they make is about the attacker. They think the hacker is this person in a hoodie in some basement or they go the other extreme and they think the attacker is some really sophisticated sort of spy agency or foreign government. As a result of these two assumptions, they usually think, well, I'm an entrepreneur, I run a small agency or I run a small business. Why would anyone

attack me and unfortunately of the businesses that I helped, um, usually after the fact? So they get attacked and they really sometimes underestimate the consequences of some cyber attacks. Some of them unfortunately can be business ending or it can have such a large cause that it may even be just shut the business down. And this is huge everywhere across from like small business to even medium sized and in some instances, even large businesses. Yeah, I always think of like really big companies like meta getting hacked or big of America or something like this, but small businesses actually can be attractive targets. Why is that? 100%. In fact, think about it if you were a hacker, Halif. Let's say you've just learned how to hack and you want to start, you know, legally hack. You naturally wouldn't go after meta because that's such a difficult target. They invest so much in cyber security. They are at the forefront of of everything technology. However, when it comes to small businesses and entrepreneurs,

usually they're just focused on getting their product out. They are overworked and most instances also underfunded. So they can be quote unquote easier targets, but they also hold something really valuable. They hold what we refer to as privately identifiable information. So that's something that we classify as a critical asset. For example, a lot of entrepreneurs will have something like a customer database where they have the names and last names and phone numbers and sometimes the addresses. This is extremely valuable because what attackers can do, they can get that information and sell it on the dark web. It's actually extremely valuable. So that's a really key critical asset that lots of small businesses have. And unfortunately, sometimes they then have the knowledge or the resources to protect that. The other thing and probably the more important thing that small businesses have is that, well, like I said earlier, it's maybe a lot harder to hack something like a big bank or something like meta as you alluded to. However, the way to get into those companies is

usually you hack their suppliers. So if that small business is a supplier for a bigger business, usually it's a lot easier to attack that small business and use it to pivot or use it to trust. So if you can compromise the email account of a small business, well, you can start sending malicious stuff using their email address. In fact, that's how most big businesses get compromised through their suppliers and they're usually on the smaller side. So interesting. I never thought about that. So he not only have to worry about our own security, we have to worry about the security that our vendors are doing for their own companies, which is just so crazy to think about. What are the main ways that small businesses are compromised? So we just talked about vendors for bigger enterprise businesses. How about small businesses? What are the main ways that they're compromised? So look the way sort of hacking or compromise happened that are actually so many ways. Most of them aren't even known to the public. They tend to be complicated, but the most common ways for let's say an attack at 2GN

foothold and tend to be the easiest way. It's what we refer to as social engineering. This is where the attack up pretends to be someone that the business owner knows or pretends to give them something that they trust. So we really use the old age sort of trust relationship that we humans rely on. For example, as a small business, I could pretend to be one of their employees and send an email urgently, say, hey, floss my account urgently, please click on that link and help me out. So we apply time pressure. So we call that social engineering or phishing, which falls on the social engineering. There are other sinister ways as well, but it all goes to all comes back to really pretending to be someone else. So fellow entrepreneurs and YouTubers, a really common reason to one is actually pretending to be a brand and offering a brand deal. Yes, I get so many of those. I've even helped cyber security professionals who got hacked this way. And that's not a no shade on

them. This is just a testament on how good some of those attacks are. They can really pretend to be a legitimate brand and the website look exactly the same. They might be just a slight variation on the URL. And sometimes it's something that your eye cannot see. So some of the alphabets we can replace it with special characters. And it's really hard to detect. So that's a really common way. There are more and more ways, for example, if you have physical access to the business, there are things you can install, but that's a whole other story. But when it comes to sort of the most common ones, it tends to be 100% social engineering. So let's really unpack this with a real example. If you could really just walk us through. Let's say there's a company that has like 20, 30 employees. They're using the typical things, Slack, Cloud storage, Zoom. They might have vendors, different SaaS tools. Walk us through how they could get attacked and some of the things that could happen and how could escalate. Yeah, I mean, just before I say anything, just this

claim, hacking is illegal. What I'm about to say is for educational purposes. So please don't do it. But hypothetically, if I was to attack this imaginary business, the first step I would do is always reconnaissance. So I'll try to collect as many information as I can about that business. This includes their linked impulse to how many people work there. I'll even draw like an org chart, see who's who, who's the employee go on Instagram, they usually share everything. So I'll get a list of the individuals who work there, but more importantly, I'll get a list of the technologies that they use and also the product that they have. So once I get a list of that, the next step would be I'll start to craft things that they trust. I'm doing a social engineer my way there because it's a lot easier for me. Like I said, to get an employee to do something for me as opposed to me trying to hack Microsoft and get inside their email. So what I will do is I'll try to mimic what their email looks like. And now that's really

easy. I can literally vibe code that in like five minutes used to take a lot more time. The second thing is I'll see what vendors they use. So if they use so many SaaS applications, I could hypothetically go to the dark web and see if there is any information about those services. If there is a new vulnerability, it may not be patched. So I could directly go and hack one of the SaaS services and get into their network. But let's say everything they use is secure. Well, I'll try to then attack sort of target the employees individually. I'll usually target what may appear to be more vulnerable. Usually it's very busy individuals, very busy founders. They are more likely to click on something really fast. Sometimes they'll even not eye, but the hypothetical attack I may look at. So elderly parents and try to tell them they've won something because what happened, Hela, is if the elderly parent gets their email compromised, well, I can use their email to send stuff to sort of their kids. And they're more likely to click

on them than if it comes from an unknown individual. Now, the final one that is very, very effective with entrepreneurs and all the startups that I don't recommend anyone to do. But I could simply purchase the product that they have and be a legitimate customer and just give their customer support help. I'm like, it's not working. Help me up on a Zoom call. Do this. So the customer support individuals are very likely to say, well, I tell them my Zoom is not working. Please click on this. So I can get them to click on something. And unfortunately, support individuals usually have a lot of access. So as soon as they click on something, I mean, and I can continue pretending to be a legitimate customer, which I am, close everything so they don't suspect that something's happening. And then I mean, then it's like, then I'll start to slowly and surely take over everything. But that's more or less how, I guess a lot of hackers would actually approach it. That's so frightening. It's so frightening that this could be happening. And I guarantee you

that so many entrepreneurs tuning in are now realizing how big of a deal this is and how little they're probably protected. So what is one thing that with our cybersecurity, when you're looking at small businesses, what's one thing that entrepreneurs are doing where a hacker is going to say, this is just way too easy. I mean, there are a number of things. And I'm going to start with the big business and then go down to the small one. A really big telltale, even for me, as a consultant, if a company is hiring me to check their security, the first thing I go on LinkedIn and I just see who works there. If that organization is sort of midsize, too large size, and I see that they have one person that's called, quote unquote, IT person that's doing everything. This is a sure sign that this person is overworked probably doesn't have enough time to do everything security wise. So I know there is a high chance that they may not be doing everything they need to do. So that's a quick telltale for me. The other one would be, I'll leave it or not, I'll go on Instagram and

something I see frequently is a founder says, oh my god, we went live last week. You wouldn't believe it. We expected 200 clients. And now we have 2000. This tells me that this team is extremely busy. They can barely keep up. And it's a lot easier to do things with them that you know, but at the time, pressure, hey, I'm a customer that apps down, help me log into my computer. Do something for me. This is a really quick telltale. Now more than that, there are other things that I wouldn't say small business owners sort of do used to be more common in the past or things like not having to factor authentication or like old practices that they still exist, but not so much nowadays. So systems have gotten better thankfully, but as a result, because we have better systems, better IT setups, we can produce a lot faster. And with speed comes compromise. And not just in cybersecurity, you probably have seen it, how aware organizations or entrepreneurs or small businesses, they release something, but they haven't done their due diligence from a legal point of

you. They haven't gotten everything reviewed and they say, well, we'll do it after the fact. So these kind of things may have a large impact on in some cases, large consequences. This episode is sponsored by Bitdefender, a global leader in cybersecurity. Many small business owners lack dedicated IT support, making them easy targets for cyber criminals who steal data, money, or sensitive information. Bitdefender ultimate small business security is built specifically for business owners like you. It protects all of your team's devices, scans for fishing and scams, manages passwords, and even checks the dark web for leaked info. Unlimited VPN allows your team to work securely from anywhere. The dashboard is super simple. I set it up in just minutes, I add my whole team, and now everybody is covered whether they're in the office or the studio, or working remotely. Bitdefender makes cyber security easy so you can focus on what really matters, growing your business, and serving your customers. Protect your business today with Bitdefender ultimate small business security. Save 30% when you go to bitdefender.com slash profiting. That's

b-i-t-defender.com slash profiting for 30% off. Bitdefender.com slash profiting. I want to understand how you know so much about cyber security and hacking, and I learned from studying you that you got into this when you were like a teenager. You were really exploring how does hacking work. I'm curious to understand where did this all begin. Tell us the story. I mean not to show my age, but I'd say I started perhaps late 90s, early 2000, and at that time, and especially what I was living, the internet was new. It was a novelty. It's the new thing. Internet for those my age. Internet cafes were a thing. So you'd go to an internet cafe, a paper hour, and you start exploring, and there wasn't much to explore. So it really started with chat rooms called the IRC chat rooms, and within that I discovered well people were sharing files. You can download. There is music file that was new to me, and then there was this thing called

hacking. It coincided with me watching a movie called Hackas. It was early Angelina Jolie movie. It is fiction, but it really opened my heart. This is a thing. You can actually do that. So as a teenager, as you do as a teenager, you start imagining things. Oh my God, I could hack an airplane and fly myself everywhere. These imaginary scenarios that are not real, but as a 15 years old, this is everything. Then as I sort of court and court do research, find movies. I find another movie about someone called Kevin Mithnik. Late Kevin Mithnik, he is the most famous hacker in the world. At that time, there was a movie, not just one. I think more than one movie. One was in German, one was in English. Of course, a lotch with subtitles. The things he did were incredible. He would hack phone lines. He would jam radio signals. He was on the run by the FBI, and the movies, of course, made it so glamorous. So all I could think of, oh my God, and that was a

time when we would call people on phone line. So I'm like, oh, I could hack my friends phone line. I could do these pranks. So I wanted to learn everything. I'd go to these chat rooms. And at the time, hella, things were a bit different in the sense. If you ask for help, people start swearing at you. It was not a friendly time, unlike today. So I had to learn certain things. The hard way. I got myself hacked a multiple times, but long story short, my sort of went into the right direction, started learning an operating system called Unix, hence where my nickname came, actually a fun sort of useful anecdote. My website, Unix, Sky.com is a few months older than Google.com. So I go way back. Yeah. So that's where it all started. Then I got my first job, started studying things at university that were completely useless. Bet my first job, but I continued learning. And I still do that to this day, even after consulting for so many years.

I enjoyed, I like to learn, I stay curious and experience, of course. I've done this so many times, so much so that sometimes I can look at something and like have an educated guess that, maybe you can look here, let's just start this way and take it from there. But yeah, it's been a continuous learning and experimenting journey. And it's a lot of fun. Your entrepreneurship journey is like really interesting. So we're going to spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business. And you've done such a great job like really owning this niche and this slain and helping so many people in their IT careers, especially in Australia. So since we have this incredible consultant in front of us, a lot of the people tuning in are entrepreneurs for small business owners. We don't have endless budgets. We have a lot of information that might be vulnerable, but you know, we're not this huge company. But like you said, that makes us actually pretty attractive. So what are the few things? Let's say three things that we should absolutely not compromise on

when it comes to our security. What should we be investing in and where do we begin? This is challenging because it may slightly vary between businesses, but I'd say the first one, non-negotiable is always two factor authentication. Luckily, we live in a day and age. Everyone knows what that is. So when you log into your email, sometimes you get an SMS, says that you enter a code, the preferences always do you something like a pasque or the authenticator app. Even a few years ago, this wasn't rolled out to everyone. We had to have difficult conversations, tends to really, really reduce the risk of cyber attacks, not to zero, but it's really important. And within that, no exceptions. So if you have a busy executive or someone precious in the team that says, I hate that, tough luck. This is unnegotiable. This is like having a building and having a fire exit. It's not a conversation that businesses should have. So this should be there. Rolled out for everyone. That's number one. For every single platform that we're using or just

excellent point. It is meant to be for every single platform. However, with platforms now, as you log in, how you notice that it tells you use your Gmail to use the same client, like if you log in, use it. So this is called single sign on, which is essentially you've already logged into your email. Your email is trusted. So we use that as a trusted token to get into apps. So that is that's perfectly fine. You still consider that as someone who used that. As long as the app is not asking you for using an unpassword, and you're just entering and getting in, if it's asking you to use the email that you've already logged in, that is this is the same thing. So single sign on have made that a lot easier. So instead of having an authenticator app for everything, some of them will use your email. However, like even for me, my authenticator app is really large. So it happens. I have it with everything. Unless I can reuse my email, which is fine. It's just to get us out of just using an unpassword. Because if the

hack I have this name unpassword, it's game over. So we just make it a lot harder. The second one, which is also related to credentials, is a password manager. So having a password manager is really, really important. No matter how complicated we make our passwords, the human tendency is for us to reuse the password everywhere. And that's extremely dangerous, because your company may be secure, not hacked, but the local cinema might get hacked. And guess what? People use their work email and work password to log into the cinema. So hack, as usually, when we do the reconnaissance step, when we try to collect information, we actually see if your password is out there. It doesn't matter if someone have the same name. We try to first use that and see if we can get in. So a password manager, really essential as a business, have some sort of enterprise solution with these passwords where you have a complex password everywhere. And they're really convenient because you can have it out of your browser, so you literally just copying a password that you want to reuse. This is the second one. The third one, if we just

narrow it down to three, is our key critical assets. We need to understand that it could be customer information. It could be intellectual property. For example, you're on a podcast. I'm sure you have the same method to make an amazing podcast. So that's intellectual property. Let's say it's an award document. I would restrict access to that. And that even includes employees. Make it on a need to know basis. If someone needs to access it, we ask why you get a time restricted access, but that's it. It shouldn't be free access to everyone. And that could get more complicated. Like I worked with the beverages organization here in Australia. And some of their intellectual property was recipes for their drinks. And those recipes needed to be in a secure vault with encryption and with really secure passwords, but also once you log in and get access to that, you shouldn't have that login indefinitely. It should be time restricted. So those would be the three things. And if you allow me a bonus one, like I said, yeah, give me, I was going to say,

what's the four and five? Because clearly I can tell it's not just three things we need to worry about. The fourth one is similar to it's just get a professional opinion. For example, small businesses, when they draft a contract, they get legal advice, right? So you get someone to review it as solicitor. Likewise, with with cyber security, it doesn't have to be something massive. And get a small company, preferably something local where you can reach out to them if things go bad and say, I just like guys, couple hours, whatever, $2,000 or could be less, could be more, check, make sure we're doing everything right, give us a recommendation. And sometimes all they do is just check that you're doing everything you may miss something. So they just give you professional advice. They're, you know what, you're doing 99%. That's perfectly fine. And as the business grow, that sort of consultation or that assessment can grow with you. If you have a software application, you're releasing to the market, obviously, then it's more scrutiny. But if someone is just, let's say, an Instagram content creator and they just share advice, they may not need that. I hope that gives

a small business owner the thing to talk towards. It does. And I think because one of the most important things, like you said, is password safety. And there's some really, I know Bitdefender, I believe, has like a password feature that you can get. And it's really cost effective. But you mentioned this concept concept of least privilege. And I'd love to understand, like, what is this concept of least privilege? Help, help break it down for the people that aren't in cybersecurity. Yeah, the concept of least privilege, least privileges or least privilege is falls under the umbrella of what we refer to as identity and access management. It really is, you have a resource that could be an application. It could be intellectual property. You want to restrict access to that and make it so that the individual or the system or the software that have access to that, they just have access to the minimum amount of resource required for them to do their job

with a time restriction. For example, we go back to, let's say, customer database. You have a customer database. You have all your clients details. And let's say you have a marketing officer, marketing officer need to run a campaign for some of those individuals. So what I do is the marketing officer will only get access to that database for like 30 minutes. So they get a temporary password and they will only get access to those individuals and then the access will get revoked. This reduces the impact of cyber attack. For example, if two weeks later, the marketing officer gets hacked, well, the hacker wouldn't have access because the access has been revoked. And you mentioned bit defender. They have this their enterprise suite solution. So they will have that password manage aware. You can provide a temporary password access so it can definitely assist with that. But that's more or less the principle of least privilege. We always assume that for cybersecurity, it needs to be this complex, expensive piece of technology. But no, it's really people process

and technology. So we start with the process, we just define this is how we access things from that one. And then we enforce it with technology if possible, if not, he can even do it manual. When it comes to customer data, like for example, my business, we don't collect that much data. Like we have everyone's email, but that's pretty much it. So like, is that really sensitive customer data or does it get more sensitive when you're collecting people's like addresses and their social security and like that kind of stuff? So it's like, what customer data is the most desirable? Yeah, this is where there is a fine line between cybersecurity and the legal profession because here we're going into the territory of privacy or some people say privacy. Depends on how you pronounce it. But this is where we sort of even sometimes consult with a legal professional or a solicitor. Email address on its own, it's not really what we refer to as PI or privately identifiable information. It really is not why privately identifiable information

is something that can uniquely identify you. This would be your full name, home address, date of birth, but also things we don't think about such as sexual orientation, political views. These things, can be used against you to target you. And within that, there comes a whole lot of laws and regulations. A simple one that many people don't know is your business is based in the United States, so you're in the US. However, if some of your customers are EU citizens, so they're Europeans and their country is part of the EU citizens and they sort of trade with you, you actually need to comply with a standard called the GDPR, which is the privacy standards for European citizens. So you need to do certain activities to make sure that you're not breaking their privacy laws. Even though you're not really a European union organization, likewise, there is that California Privacy Act and there is the China Act. So there is all of these things and this is where as

cyber security professionals we provide advice, but then we we consult with a solicitor. Sometimes could be just just please review this, make sure our policy is up to scratch. So as far as emails, I would treat it with absolute care, because like I said, it may not be a huge legal liability, but it's very attractive. People on the dark web, they purchase email addresses, they use it for spam campaigns, they use it to scam people. It's a very attractive thing and even I'm not sure if you have an interest and say paid ads, email addresses are really attractive to use for paid ads. So there is commercial value for them and as a result, we encrypt them, we make sure that our newsletter provider is doing their due diligence when it comes to security, which the majority of the big ones are. So helpful, you are just like a wealth of information. So for the entrepreneurs tuning in who still don't feel like there is much of a risk with

cyber security or still aren't scared enough, talk to us about what could go wrong, like reputation wise, revenue wise. You mentioned earlier that sometimes cyber attacks can be so bad that the business actually has to shut down. I'd love to hear some examples of the way that these types of attacks can actually impact businesses. Yeah, we try the fine line here, Hela, of being an alarmist versus just encouraging individuals and entrepreneurs to really do their due diligence and just do what needs to be done when it comes to security. It can definitely be career ending in the sense. The biggest one we've just alluded to, which is breaking privacy laws, there are hefty fines. So the European Union is really strict with fines when it comes to the privacy of their citizens. So a company in the US that's providing services globally and somehow they get hacked and European citizens get their data out there, there might be a big fine and it can be in the seven figures and that can have huge financial direct financial impact.

The other one is, let's say you have an application and subscribers and that application gets hacked. Now what subscribers are paying, they need their money back and you really don't know to do your revenue stopped. So all of these things can and do have significant financial impacts, which is a good segue to also make sure you have the cyber insurance or talk to your insurance organization and make sure that insurance against cyber attacks is there. It's a sort of controversial topic. It may or may not help, but it's best to have it than not to have it. So those are things that are important. There are, I've never heard of cyber security insurance and then nobody talks about this stuff. Cyber security insurance. Yes, I think it really is important and look that the good news is you may already have it as an example. So if you have insurance for your business, depends on your provider, you can talk to them and say is cyber attacks are included under that

and within that there is threshold and there is a limit. However, I've had mixed experiences with cyber insurance, but to summarize, it's better to have it than not to have it and the good insurance providers usually it's there in the fine print. So it's worthwhile just checking that it's already there. The other thing is also like I said, if the organization or the business, like you had the consultation with a cyber security company that's preferably local also, if things go bad, you have them on speed dial, you can call them in and get them in. So having that relationship also is really helpful and they can also give you an advice when it comes to cyber insurance as well. So these things helpful, but when it comes to just things going wrong for small businesses, like I said, it does go a bit more sinister and there are things that most of us don't hear about because it's sort of bad news and with the really bad news, we don't want to hear about it for the most part, but there are cases of extortion. There are cases and this is really, really common.

So as a small business owner, someone could target one of your employees and you're kind of responsible for them because your business got hacked and it's really complicated and the implications are sometimes your employees could be the target or your customers could be the target. And as you mentioned earlier, it could also be your brand reputation and we call it brand equity. Well, if people signed up to your application, it's hot stuff, but the next day, everything is hacked and everyone is complaining and that can be carried ending unfortunately. So let's go back to the entrepreneur who has no budget. Now, you mentioned the three to four things that we should pay attention to, but what if I literally had just $1,000 to invest in cyber security? And let's say, I don't know, maybe this isn't just not enough. I guess $1,000 for the year, do we want to say $1,000 for the month? What is the bare minimum that we can be spending on cyber security? Let's say we just have $1,000. Let's just say the business has just started and look,

and there is good news here is that it's not always like that amount of money. I think as humans, when we see a problem, like I'm on a throw money at the problem and make it disappear, it doesn't always work that way, especially with entrepreneurship. The good news is a lot of the services that we use, Hela, are really build in a solid way. So let's say if someone is using the G, let's all their email and everything is from Google, for example, using the G Suite. That is an inherently really secure platform if it's used properly. So if I just have $1,000 and which tells me I'm early in business, I'm an, let's say, content creator or I have a small agency. This also, I will guess that we're not building an email system from scratch. We're not building. We're just using popular services, whether it's from Google, Microsoft, etc. This can be good news. I would honestly get that $1,000 and like I said, reach out to a local trusted company and say, hey, this is our budget. Can you just give us advice? What can we do?

And they can literally just have one hour look at your stuff and just tell you, you know what, you're doing everything right. Maybe do this one thing that will give you 80% of the value. So I would get a professional opinion. Like similar to, I think the example of getting legal advice, you may not have the budget to hire a lawyer that works full-time, but all you need is someone to review employment contracts. That $1,000 can do it. It may not do it all the time, but it's better than doing what a lot of businesses do now, which is chat GBT things and AI selling you, yep, you're doing a great job. You're fantastic. You're the best thing since last thread. So I think just getting a human who know what they're doing is a lot better. I didn't think you were going to go that way. I didn't think you were going to say, get like a consultation and have somebody tell you what you need to be doing. How about a solution like Bitdefender? It's super affordable. I just went on their website and it's like less than 200 bucks a month to get all these different tools. It'll like scan your Slack and or like your messages

for anything that looks like fishing or emails. It will send warnings if it looks suspicious. I feel like that's also just a great layer to be adding on. 100%. Like I said, that could be also the outcome of that consultation. They said, hey, you're doing everything right now. You're ready for an enterprise solution, which the one you mentioned from Bitdefender. The good news is these things, however, they weren't available for us a few years ago. So we are living in a good time where a company like Bitdefender have something targeted for the enterprise small businesses to medium-sized businesses where yes, they do scan your emails. So you get rid of them. spam headaches. They offer you some kind of password manager and monitoring. It's always better to have these things in place. It also like from a, I hate to go that way, but from a legal perspective, if things go south, it's also proof that as a founder or as a business owner, you're doing your due diligence. They can't say, well, you've done everything, but you still got hacked. That can still happen, even massive organizations. But in

this case, you will be a victim of criminals who really know what they're doing. They're, you know, criminals do criminal things and sometimes we're just victims of that. But that's a different story than someone who, you know, they've done nothing. There's a really famous story on the news of those companies that they created a dating app for women to protect women's, it's for women's safety. But then turned out that that's app because it needed to verify women. They took their passport details and all their information. Turned out this app was vibing coded with zero security. It got hacked and it put women's in safety in danger. But that was an example of an organization that didn't do their due diligence. Whereas a small organization like we said, okay, they've got the consultation. They've got that with defender enterprise security. They're doing stuff. Well, you do what you can, right? It's like having a building, you have your fire exits, you have everything. Sure, disasters can happen, but you've done what you can do with what you have. You've described

cyber security as defense and depth. I'd love for you to walk us through what that actually looks like for a normal small business. How can we practice that? Yeah, defense and depth is a concept that surprisingly even cyber security professionals can and frequently do get wrong defense isn't in depth is in a nutshell, having more than one layer of defense stacked one on top of the other. If one layer of defense fails, the other one can sustain. It just makes it a lot harder, a lot more expensive to get to what we call the crown jewel or the important asset. I'll walk you through an example. Let's say you have your customer database. That's the most important thing that we have. We want to protect that. Then we have our attacker and the first thing they do, they send the phishing email. The phishing email comes, but you have your anti spam filters or the spam filter block that. That's layer one of defense. You didn't even see the email that attack failed. Now let's say a more sophisticated attacker. They crafted their email in such a way that it's

even past that spam filter and it went into your inbox. You looked at it and you said, well, you know what this looks like spam, sorry, reports spam. The second layer of defense here was your awareness. That's another strong layer of defense. Let's say the email came from a trusted supplier. They hacked the supplier. They can't use it. They're like, oh, this is a legitimate email. I need to do something. You click on that link. When you click on that link, your anti malware solution, endpoint security system blocked it from being executed. That's another layer. It failed here. That can go on for longer. You get the concept. We have multiple layers of security. In the late 90s and even early up to 2005, 2010, there were organizations that didn't have firewalls. They didn't have nothing. The fact that we put one layer was a huge thing. Nowadays, you'll find these layers work in tandem. This and its controversial, I keep saying defense in depth because

when it comes to marketing, the marketing of cybersecurity, people say, human is the weakest link. I can have all the defenses, but if a human makes a mistake and click on something, it's game over. Well, it's not as we explained earlier. There are multiple layers of defense. I say that in defense of the human, in defense of the employee that's overridden, clicked on something. Sorry. If someone clicked on something and it's game over, then your security were fundamentally wrong. Yes, away cyber security is approached. Nowadays, how it should be, multiple layers of defenses. Let's move on to AI because I feel like AI is such a hot topic in cybersecurity. How has AI changed the landscape? What is new? Now that AI is here. Yeah, everyone's topic and I've been labeled anti-AI, which is not true. AI has definitely made cybersecurity professionals a lot busier because every business now have an AI and they call us and say, hey, is this okay? Is this not okay? Then we need to go and look. Look, it definitely has changed

things and it's here to stay, but also it's not the doom and gloom and the movie Hollywood things that we read on the news of these AI is escaping and hacking things that this is just marketing. Look, the truth is always a bit more nuanced. AI, the most obvious one that we only to be careful and be aware of is the deep fakes. Deep fakes is huge, huge problems and I know we talk about entrepreneurs and small businesses, but even for children and in schools, it's been an absolute nightmare and law enforcement deals with that all the time. So deep fakes, faking voice, faking video is something we need to be really careful of, but even as I said earlier, you can, I can really create a website really quickly that looks exactly like a replica of a real one. Now that wasn't overly difficult before AI, but now it's even faster, if that makes sense. So in the hands of a skilled hacker, AI can make certain aspects faster. Now,

is AI this really advanced thing that's going to do go on hack things? That's not true. And the big AI companies have actually sort of safeguards against making AI do these things, raised around it, but let's say if someone is completely unscaled and they're trying to do something, it's just not happening. So that's one aspect of it. The second aspect, which is what keeps us busy, is businesses are really quick to sort of want to use AI. And this is where things get a bit more complicated, because when we say AI, so what are we really using? Are we just prompting chat GPT, or are we giving AI access to everything and making it talk to customers and do finance for us, or are we even not even using AI, but we have the SaaS service or this product, and then all of us are doing this product on the websites as we're AI enabled or AI powered. What does that mean? Do you feed our information to your AI? Is it going to the AI company, which is really a private company if you think about it? So all these things are making life a bit more interesting for

cybersecurity professionals and small business owners. So we want to use AI, we want to be on top of the new technology, but we also need to stop and think, what is it that we're using AI for? What does the AI have access to? And more importantly, where is my data going? Is it going to a private company? Why do I trust that private company? This private company could get hacked or they could do something like sell my data somewhere. Big tech companies have done that. And we love to see news and this big tech company got sued for selling election information. Well, they don't care. The hundreds of millions of dollars find that they pay. This is just one week's earnings. So these things, I think we need to keep in mind when we use something like AI, just why we use it and how we're using it is fundamental. Yeah, are we getting to a point where we literally just can't trust anybody's face or voice digitally? Unfortunately, yes. It happened to me. I thought I was this great AI detector up until someone in Melbourne, Australia. And yeah, I thought I was like this,

you know, a great video guy that I know I can detect it. And one of my fellow YouTubers, he visited me in Australia and he was just showing me what he doesn't like. Oh, this actually was AI. So why does he record himself talking? And then for his Instagrams, it's him, but it's really an AI of him that looks exactly like I couldn't tell. Nobody could tell up until he pointed it at it. Looks like him talking. It's his voice, but the videos in childy fabricated and it looked real. And with the like the short form videos, because the resolution is low, I couldn't tell like few months ago, I would give you a few more fingers or things will be obvious. Not anymore. And to the human eye, my eye at least, it's not always detectable. So absolutely. And staying in, I got an email from Microsoft saying yesterday that they want to rely on past keys, which is a more secure way for authentication. So no longer, you know, the voice authentication and all of these things are going unknown, no longer secure. So absolutely seeing a video and usually women get targeted like with

explicit luck. Someone leaks, quote, unquote leaks, explicit videos of an individual. And well, that video is completely deep fake and it has been happening. And yeah, it's something I actually had to deal with with law enforcement where they target the always target the vulnerable, they always target the young and it is a it is a problem. And we need some kind of a strict regulation on, you know, putting someone face on a body that doesn't belong to them or do these things. It's crazy because as a creator, you actually see a lot of opportunity in this. Like my team is actually creating an AI avatar for me. I just did like the whole turning my head a million ways and walking towards the camera and turning my body every which way so that they can create an AI avatar for me. Is there risk in having an AI avatar that you actually create for yourself and for your content? Look, this is a difficult thing to sort of answer and guess because like, let's

think about it. Look, what could go wrong? Because you and I are content creators. So if someone wants to impersonate me, there is thousands of footage of me speaking and well, it's it's really straightforward and exactly for yourself as well. And we could say, well, it's illegal. Well, I'm doing something illegal. I don't think they're going to stop and say, oh, hold a second. I'm not going to do that because it's illegal. They'll still do it. So for me, I don't think there is any risk from a point of time. Yeah, we're already out there. We are out there. And you know, like, I always say, I tell people, if someone wants to hack me, you know, I'll just go and hack me. My phone is full of food pictures and so like it's completely useless. But like I'm aware, as I said, my stuff could be used to harm someone else. I don't think there is a risk from a content here, in perspective, which is not really a cyber security thing for me. I actually went to a complete opposite of that. I do everything physical and analog now. Even a photo has to be photographed. I'm a strictly not a fan of AI. However, it's a technology. It's a new thing. There

is a viral Mr. Beast dance video that people thought it was AI, but then it was real. But it is the world we live in. And as an entrepreneur, there's no reason why you shouldn't jump onto these technologies. Like we said in the conversation, as long as you know, you're critical assets or private information or stuff or financial information, don't feed that into AI. You should be fine. If it's avatar, if it's fun stuff, it's why not? I think one of the new things coming up in AI and cyber security is for a couple of years, AI was mostly like chatting, chatting to chat, you be tea, getting help writing emails. But now we've got AI agents that are jumping from tools to tools that are kind of like AI digital employees. How worried do we have to be about AI agents and their ability to hack our companies or their cyber security threats? AI, I mean, agent AI agent is exactly what you describe where you have the AI, but instead of it just being a prompt or a chatbot, you're actually giving it access to stuff and can do things for

you. For example, you can program the AI to send an email from your email or have given access to your calendar or in some instances, it can be chatbot on your website. AI agent is something that needs to be treated with absolute care. It shouldn't be just because it exists doesn't mean we need to use it. There are many issues with AI agents. The first one is obvious one is access. When you're giving a piece of software access to things, so we need to assess that access, we'll go back to the principle of least privilege. Does the AI really need access to everything in my email or does need access to a copy of certain emails? Does it need access to calendars of everyone or perhaps you can create a dummy calendar for certain things and that can access that? So the first one is don't be too generous with access. Treat it like it's just another piece of software. I don't want to say it's another employee. It's an employee or it's just really a software. So we don't really give software access to everything just because we can. I think that the craze or the hysteria that we face now is, oh, AI can do this. Therefore, I need to do, I need to do

it. No. As a business, do you really need that? And if not, then why? And that could be also costly in terms of tokens and we've heard lots of stories of companies paying so much on AI tokens. A famous one of the fan companies, they laid off so many employees just so like a fort paying for the tokens and it's not always a smart business decision. This is one and the most important one as well is well accountability. So as a founder, just because the AI is doing something, doesn't mean the AI is accountable for it. I'm still accountable. So if I get the AI to review my legal contract, great. The review may be accurate or may not be accurate. Who's accountable? If I get into legal trouble, I can't say, oh, well, oops, AI did it. No, it's still me. So we need to really stop and think, well, I'm still accountable. AI is just a software. It's doing something I'm still accountable. Just like a normal employee. Yes, the employee can make a mistake or so, but ultimately that accountability falls on leadership or on the CEO or on the board of directors.

So these are the things we need to really be careful about. So I do think one of the things that we need to be worried about with our employees in AI is actually we might be rolling out specific company AI tools, but because AI is kind of popping up everywhere, employees are probably using all these like disparate AI tools or like whatever tool they think is fine and they're probably using their company computer and thinking it's harmless. Is there a risk in people just using like not approved AI tools? Absolutely. And this is not a new problem. We used to call what we still call this shadow IT or un-sanctioned software, which is really what AI is what you just described. We had this problem even before AI would have let's say the marketing team, they just found this online tool and they start using it. They didn't tell everyone and they put customer data in it without sort of the cybersecurity team doing an assessment and saying, hey, this is approved. We can monitor. We can do that. Same thing with AI. If we have an employee opening their

own personal chat GPT, putting company information in it, yeah, we haven't we didn't really approve that. So they did something that the business didn't approve of. It is really hard and it's something that we need to like I said, do our due diligence. We need to have clear policies that say do not put company information into AI tools. Also the other thing I saw even in big tech companies where they really skilled so they have built different agents to do different tasks. They always have someone sort of verifying and validating the output of AI. So really skilled programmers, they do this cloud code, the AI is producing code. Before it goes to production, it needs to be reviewed. It needs to be tested by a vetted senior programmer. So this way we have safeguards against what goes into AI but what comes out of AI. That is really essential. There is the other thing, of course, like I said, in terms of privacy and stuff. There is a setting in all these AI chat puts that says something along the lines of don't use my data to train AI.

I think we should all toggle that and this way allegedly our data doesn't go in there. So that's something that we need to do. But there has been instances, a really famous one, early days chat GPT, the source code, some Samsung employees really leaked the source code, not leaked, they're just posted to chat GPT. It's a huge problem because chat GPT will use it to learn but that source code is massively, massively, pricey and important intellectual property that should not have gone there. These things happen. We do need safeguards against who uses AI. What do we use it for? Exactly like any other piece of software. An employee shouldn't be just using random software and use it for business purposes on business laptop. If we have a company version of chat GPT and cloud, is it safe to upload certain financial information or code or whatever it is, is it safe to upload those types of things? Or is it still not safe? When we say a company version, there is a logo which is a local AI that you can have

absolutely where the data is not going elsewhere. Also, if depends on the solution that you use, there are against safeguards that just doesn't get your data leaving the organization. Then the word safe, we need to also really put it under the microscope, safe in the sense that it's not leaving but is it safe from mistakes? It still gets hacked. Sure, but is it safe from mistakes? If I'm doing financial data and I get the AI to be my finance officer, I'm still accountable. When a mistake happens and this is the problem, the inherent problem with AI, is it makes mistakes. Humans make mistakes but they're accountable. AI is a software. It will make mistakes. That's a problem. If it's doing financial data, financial analysis for me, I need to validate that. If I can validate that, no worries. It can really save time if I have a finance officer, they use AI in some sort of way, but then they review everything that is fine. It's just us

validating and verifying that things are fine. Also, I said need to know basis or least privileges. I'll use AI just because AI can do certain things and I'll give it certain amount of data. That doesn't mean I need to give them access to everything. Just give it access to what needs to happen and then revoke that access. I'd like to talk about aside from the technology and AI, the people who actually have keys to your business. A lot of us think that the only way that our business is vulnerable is through a stranger. A hacker is going to come hack our company. But it turns out that our employees can actually be a really big risk, especially employees, maybe disgruntled employees who have left the business. Is that right? Absolutely. The technical name we use for it is insider threat. Although some people don't like the word insider threats like humans aren't threat. It could be exactly what you said. One scenario is that disgruntled employees. They know all the business secrets, everything, they leave, and six months later they start holding a second. I'm not happy with that business.

Let's do some damage. The way we reduce the attack surface, we reduce the impact. Back to basics. They shouldn't have access to everything. When they hold the key to the business, well, they need to hold the key to certain aspect that they need for their job. This way, if they do damage, well, that damage is restricted. That's one, to a common mistake that happens even with large businesses. In fact, probably more with large businesses than smaller ones is when someone leads, we call it the off-boarding process, they don't take all of their access out. They still have access to certain applications or certain things that they log into. That's a problem. We need to have a process of just like we onboard employees, we need to know how we off-board them, and that includes revoking access. The third one is also in our contract legally. We need to say that if you leave, please don't go on social media and just spell out all our secrets. That's illegal, but having it in the contract doesn't hurt. There's been many instances of that happening,

really popular one, a big tech, Australian organization that has laid off people, and they laid off one of their very senior software engineers. The next day he creates, I think, one hour YouTube video, explaining everything he's done for them, everything he's built. It's online, it got millions of views. That's really valuable information that the employees built that. You know how awkward it is for an organization to legally go after someone. These things we need to be careful of the inside of that. There is other aspect that we forget when it comes to inside of that. The employees are humans. They make mistakes. So, I, even early in my career, as an example, I made a mistake early in my career. As I was going, working faster and faster, I ended up deleting stuff that were really important files. I did that by mistake, and I had to go find backups and restore backups. Mistakes can happen. It could be a really genuine unintended mistake, which again,

goes back to why they even have access to that stuff. Why was I able to delete without someone looking over my shoulder without a chain of approvals, all of these things that sometimes we may think of as tedious or unnecessary. We want to be fast. We want to be lean. Well, there is a course that comes with that. This has been such a valuable session. I feel like I've got to do so much work and make this like a core initiative for my business. If you're a hacker, please leave me alone. But I want to play a game with you. It's called Find the Backdoor. I want you to find the Backdoor. I want you to break it down and then close Backdoor. Basically, how can somebody hack this company? I'll give you a scenario. Then, how do we actually fix that? What is the solution to that? The first one is the media company. The company works with freelancers around the world, some use personal laptops and personal email accounts to access company files. Where's the Backdoor?

There are about three Backdoors in here. The first one is offshore employees. We need to visit those employees, especially if they have access. Have some kind of betting process. That could be something as simple as using an agency that does the betting for you. Make sure they're higher in criminals. That's as a basic sanity check. The second one, of course, if you can't give them laptops, then restrict what they can access. Absolutely restrict what they can access. Don't give them what we call as a right. Read access, maybe less damaging, but right access would give you the ability to delete stuff that should absolutely be restricted on a need to know basis with strict approval processes. The fourth one is a personal email address. This is a huge no-no because when they leave the company, they own the data. That's on their email. If there's anything sensitive,

they'll take it with them. That's precisely why organizations have emails on the company domain because the company owns that as soon as they're using personal emails, they own the data. You really hand over their data and you're as vulnerable as any one of them. One of them could be criminal. One of them could be hacked or you just really don't know. You're overly exposed. If you want to use offshore employees or contractors, really restrict them to a very specific task and have in mind that if that person gets compromised, what's the impact? And do I accept the impact and consequences? If no, then find alternatives. The fast finance team, this is the next scenario. The founder and the finance team approve urgent payment requests through Slack because it's faster and more convenient. Anything that we do fast, it just means we're going to make more mistakes. So with speed, the compromise is more mistakes. A big, really red flag here is approving things

over Slack. It should not happen this way. We need to have a chain of approval that's really clear because the strongest case is if one of your employees gets hacked and they have, that account gets hacked. So the hacker is using their your employees account and, well, everyone have access to Slack, they're going to ask you to approve something and fast means you're just going to approve it. So that's a call for disaster. You will lose money. So that's what you're compromising. So you need to have the fix for that is have a proper approval process. And that approval process may just mean you it will take an extra five minutes. It's not really it's not really war on pace. It's it's just a proper approval process that will save you a lot of headache and will save you time in the long run. Yeah, potentially a lot of money. Exactly. Okay. The last scenario, the SaaS heavy e-commerce brand. The company uses dozens of third-party applications connected to customer and payment information. That is that everything is wrong with this. This is the dangerous one. Surprisingly very common,

okay. The first one is when they use so many SaaS applications, what you need to know who owns that SaaS service because there has been cases where it's foreign government operating from a different country having this amazing SaaS application that does amazing things and it's surprisingly cheap. Well, the purpose of that application was to collect information. So you need to really vet and know who you're dealing with. So the first thing is we call it supply chain management, supply chain meaning your suppliers in this case is your SaaS providers. Just make sure you know who you're doing business with instead of just randomly signing up for things because they are caught and caught cheap and fast and they they do their job. So because it's a legal liability if you're leaking customer information to somewhere that shouldn't go. It's a huge problem. This is one. Two again, know who you're dealing with. A small SaaS app, what if you want to feel providers get hacked and they have access to all your customers. So and therefore once you know who you're dealing with, the second one is manage access. Why do all of them have access to everything really common in the real world? Sadly, but manage your access. Again, need to know basis,

least privilege, all these really timeless principles, meaning your strict access, pretty sure that business, whatever it is, doesn't require everyone to have access to everything. The only reason why businesses usually do that where they give everyone access to everything is just lazy. It's easier to take everything on and that's a call for disaster. So these are the two fixes and manage your supplier is number one, number two, manage your access. I love those principles. I'm sure everybody tuning in is learning so much and getting so many ideas of where they need to start first. Let's say unfortunately our company gets hacked. What is something that we shouldn't do? We get hacked. Somebody just stole a bunch of money from our bank accounts. What shouldn't we do in that moment? Really difficult because the first reaction that happened to all of us and myself included we panic and to tell someone not to panic, it's unreasonable. So I'd say panic but don't act. It's just like you know when I'm sure as

a business owner and even as someone on the internet, sometimes we get angry and the advice is don't reply to an email when you're angry or don't take action just like just sit back. It happened. It's a problem. We're going to deal with it in a systematic way. So I'd say the first thing is don't interact with the hackers. Don't reply to emails which leave everything as it is and in some instances I'd say don't actually close the laptop or don't just leave everything as it is reach out to an expert right away and there is levels to that. So reach out to law enforcement. Contested things to do because usually enforcement are overworked underfunded. They may not be always able to help but you'd be surprised. Law enforcement can help. Having that consulting company sort of you have them on speed dial, you have their number, get an expert right away to do it. That's the most important thing but the biggest one is what we said earlier. Do not interact with the hackers because the first thing they will do is try to get more access. So they'll say

sorry mistake. Just do this one more thing because they're trying to get as much a photo as possible. So don't interact with them. They're really skilled at getting you to do what they want you to do and they're going to use the fact that you're panicking to their advantage. So yeah, completely disconnect. Get an expert to deal with it right away. Don't take actions and the worst thing that businesses do is they'll have like an IT support person who's pretty, they don't have the expertise and like okay, go deal with it and that person end up mean, ends up making things a lot worse. So I think this is the big no no. Get an expert to deal with it right away. Such great advice. This has been such an awesome interview. Before we go, I do want to talk to you about your entrepreneurship journey, your business. So you actually started creating content and you've created a business out of educating people and it all started because people would just ask you questions or colleagues would ask you questions and you just wanted a way to not have to answer the same thing over and over again. So just talk to us about your story. How

you ended up growing this content business, how you make money today and hopefully you can inspire somebody else who's a thought leader in their space to become a content creator and start their own business too. Yeah, absolutely. I mean, it's funny. I still don't think of myself as a business or even a content creator, but the story started. It was during the lockdowns and I was working at PWC, which is a consulting firm. And as a senior manager, part of our job is to coach consultants and senior consultants. So I'd have these one-on-one calls with them and I'm I really don't like Zoom or online meetings. So I prefer it to be in person. And I remember one day, I had like three or four back-to-back calls with junior consultants and they were asking exactly the same question over and over. So I got this idea where I'm going to know what, I'm just going to film myself answering those questions and I'm just going to send it to them so they watch it. And I just put it on YouTube as somewhere to upload the video on, like not as a sort of discoverability platform. So I thought I thought no one would find it. I thought it's like,

I watch YouTube, but it didn't occur to me that the video that I'll put strangers will watch it. So I send them, I told them before you do the meeting, just watch this video and then you can ask your questions. And I left it and then I think months later or so I saw there was comments and likes and there's strangers watching it and they're like, oh well, let's just answer more questions, I guess. And I started answering them and it wasn't like it wasn't sort of a business or I had no idea that YouTube pays me your money. And while it's a small amount, but I didn't, I didn't know that was a thing. And when I got the first paycheck from YouTube, it was like 50 bucks on that, that mistake or like how I didn't put too much together. It's not that universe that I'm a part of, I had no idea. So that was YouTube. But then I started getting messages from people and individuals like from all over the world. And the first one was like, I could see in the picture, I was a dad and kids and it's like commenting on my videos, he was somewhere in an African country and then it's like, actually, I got a job and for him, a job is they changed their life. So I got a full-time

job completely new field, highly paid, so it improved their life. And then it started to spiral. I started getting these success stories either in a comment, sometimes in an email saying, I actually followed your advice, I got a job, it changed my life. Thank you so much. And the more I posted the more I get nowadays, every time I look at my inbox, there's at least one message a day from someone somewhere in the world that says, actually, followed your advice, which my advice is really just do these practical things, learn and apply yourself and you'll get a job, it will take time, it's challenging, but it's possible. So this really gave me the drive to continue. I felt that I was making a difference and I felt that I just felt responsible. I felt responsible that people watch my stuff now. I need to give really the most accurate advice. I need to do what I can. Time management became really difficult. My job is really, really demanding as a consultant, but I enjoy it. And because I do it, I've been doing it for so long. Like it doesn't require a lot of thinking from my end, so I was able to manage, but then I've

always wanted to do consulting on my own. So I started a cyber security consulting company, and I have one term clients. So I'm active in the field, I do that, but at the same time, I create YouTube videos. I'm not very good at creating a lot of content, so I create one video month. Really, that's my average. So in 12 months, I'll have like 13, maybe 15 videos of YouTube, that's all I can do. Within my advice, because cyber security is a range of jobs. It's not just one job. There was one nation cyber security called government service compliance. At the time, I didn't feel comfortable recommending what was in the market. So I thought, I'm going to take three months and just try to create something. It took me a year and a half, and I created my certification, got it accredited, and I just put it out there, and thank God it's been really successful in the sense that people started to recommend. And that's the GRC mastery, right? Yeah. Yeah. And people started recommending it to each other through world of math. So every time I go to a conference, and someone says, Hey, someone did it in the team, then all of us did it in the team. So it became

bad. So really, my time now is like between consulting. I help usually large organizations. I've got long-term relationships with them. I do have some consultants that work under me. And yeah, the occasional YouTube video where I talk about what's happening in cyber security and how to land the job. You got a full play to clients. You have a team, and then you're able to create content and give back. I mean, that's an incredible career that you have. So okay, let's bring you back to cyber security and wrap this up. So if you're a young and profitor listening right now, what are the three things that we should do tomorrow morning to protect our company? Number one, two factor authentication. Use your Authenticator app or a pass key. This is an unnegotiable, no exception. This includes all of your employees. Number two, a password manager. I know it will take you some time to get used to using a password manager. I can promise you it's a lot more convenient for you and your team to use a trusted password manager. It will save you time in the long run. It will save

so much headache. And number three is we talked about it a lot is manage your access. Just because someone works for you doesn't mean they need to have access to everything in your company. Provide this access, give them access only to the things they need and know more and have fun as an entrepreneur. Amazing. Beautiful recap. Thank you so much, Abed, for spending time with us on Young and Profiting podcasts. Thanks for having me and thank you so much for your time. This has been an absolute pleasure. Big thanks to Bitdefender for sponsoring this episode and for keeping small businesses safe. Protect your team, your data and your business from scams. Ransomware and Fishing get 30% off Bitdefender.com slash profiting. That's Bitdefender.com slash profiting. And if you enjoy this episode and learn something valuable, we'd greatly appreciate a five star review on Apple Podcasts or Spotify. Reviews help us reach more listeners and continue bringing you these conversations that educate, inspire and empower. You can also connect with me on Instagram, TikTok or X at Yap with Hala or find me on LinkedIn by searching Hala Taha. This is your host, Hala Taha,

aka the podcast princess signing off.

More episodes

More from Young and Profiting with Hala Taha (Entrepreneurship, Sales, Marketing)

View all episodes →