What is cyber security, really?
Ask ten IT companies what cyber security means and you'll get ten answers, most of them designed to sell you something. Here's the version we give people at the kitchen table.
// overview
It's not what the movies told you.
Cyber security is just the practice of making it hard for someone to get at your accounts, your files and your money. That's it. It isn't a product you buy once, and it isn't a hooded figure in a dark room typing very fast.
In twenty-odd years of callouts across Toowoomba and the Darling Downs, we can count on one hand the number of genuine "hacks" we've seen, the kind where someone actually broke through a technical defence. What we see instead, week in and week out, is far more ordinary. Someone reused a password. Someone clicked a link in an email that looked exactly like their bank. Someone got a phone call from "Microsoft" and let a stranger onto their computer.
That's good news, oddly enough. Ordinary problems have ordinary fixes, and most of them cost nothing but an afternoon.
// what actually happens
The four ways people actually come unstuck.
- 01
The reused password
One password used across email, banking and a shopping site. That shopping site gets breached (and it will, eventually) and now someone has the key to everything else. This is far and away the most common way we see accounts taken over.
- 02
The convincing email
Not the obvious Nigerian prince. A real-looking invoice from a supplier you actually use, with the bank details quietly changed. We've seen Darling Downs businesses pay five figures to the wrong account this way.
- 03
The phone call
Someone rings claiming to be from Telstra, Microsoft or the ATO. They're friendly, they're patient, and they talk you through installing remote access software yourself. No technical skill required on their part at all.
- 04
The missing backup
Ransomware locks your files and demands payment. If you have a working backup, it's an annoying afternoon. If you don't, it can be the end of a business. The difference is entirely down to preparation.
// the fixes
Five things that stop most of it.
You'll notice none of these are exciting. That's rather the point: the unglamorous things are what actually work, and the expensive things are usually solving a problem you don't have.
- Turn on multi-factor authentication for your email first. Your inbox resets every other password you own. Protect it and you've closed the door most attacks walk through.
- Use a password manager. One strong password to remember, unique passwords everywhere else. Free ones are perfectly good for most people.
- Have a backup you've actually tested. A backup nobody has ever restored from is a hope, not a plan. Test it once a year.
- Keep things updated. Most updates are security patches. Turning on automatic updates is a one-time decision that pays off forever.
- Agree a rule about money. If bank details change, someone rings the supplier on a number they already had. Not the number in the email. This single habit stops invoice fraud dead.
// for small business
"Am I really a target?"
This is the question we get most often, usually from someone running a trade business or a small practice with a handful of staff. The honest answer is yes, but not in the way people imagine. Nobody has singled you out. Attacks are automated and scattered wide, the equivalent of walking down a street trying every car door.
Small businesses get caught disproportionately because the defences are assumed to be weak, and because there's rarely anyone whose job it is to think about this. You don't need an enterprise budget. You need someone to spend a day turning on the things that are already included in what you're paying for.
If you've got staff, the other half of the job is making sure they can spot a dodgy email without feeling stupid for asking. A short, practical session beats a policy document nobody reads.
// questions
Good questions, straight answers.
What's the single most useful thing I can do today?
Turn on multi-factor authentication for your email account. It takes about five minutes and it's the closest thing to a silver bullet in this whole field. Everything else on your list can wait until after that.
Do I need antivirus software?
Windows Defender, which is built into Windows and free, is genuinely good these days. For most homes and small businesses it's enough. If someone is trying to sell you an expensive security suite, ask them what it does that Defender doesn't.
I've already been caught, what now?
Change the password on your email first, then anything that shares that password. Turn on MFA while you're there. If money has moved, ring your bank immediately, speed matters enormously. Then give us a call and we'll go through what was exposed.
Is a Mac safer than a Windows PC?
Slightly, mostly because there are fewer of them about. But the attacks that actually catch people (reused passwords, convincing emails, scam phone calls) work exactly the same on a Mac. The fixes are the same too.
$ inspyred --book-a-callout
Got a question about this?
Ask a human.
Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.