Gain Client's Trust by ensuring Cybersecurity

26 Sep 2024 · 25 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Podcast Summary: Gain Client's Trust by Ensuring Cybersecurity

Podcast Details

  • Title: The Duct Tape Marketing Podcast
  • Episode Title: Gain Client's Trust by Ensuring Cybersecurity
  • Host: John Jantsch
  • Guest: Zach Kromkowski, Co-founder of Sention
  • Description: This episode discusses the importance of cybersecurity for small businesses and marketing firms, sharing insights on best practices for system hardening, security management in a distributed workforce, password management, compliance standards, and addressing AI-related risks.

Key Topics Discussed Importance of Cybersecurity

  • Cybersecurity is critical for both marketing firms and small businesses due to the sensitive information they handle.
  • Bad actors can exploit vulnerabilities to create targeted phishing attacks using the data shared by businesses.

Best Practices for Cybersecurity

  • System Hardening:
  • Understand where assets (computers, servers) are located and how they are configured.
  • Regularly update software to enhance security.
  • Password Management:
  • Use dedicated password managers (e.g., Bitwarden, LastPass) instead of storing passwords in browsers.
  • Enforce policies to disable browser password saving features.
  • Policies for Distributed Workforce:
  • Implement clear security policies for employees using their personal devices (BYOD).
  • Use different browser profiles for work and personal use to create a layer of separation.
  • Compliance Standards:
  • SOC 2 compliance is recommended for small businesses as it indicates a commitment to security measures.

Managing Security in a Distributed Workforce

  • Communicate risks to build trust with clients.
  • Implement browser hardening and ensure clear security policies are established.
  • Regularly review linked accounts in services like Google Workspace to minimize security risks.

Addressing AI Risks in Cybersecurity

  • AI can be used by bad actors to impersonate businesses and exploit personal data.
  • Businesses must educate employees to recognize potential threats and verify unusual requests through pre-established security questions.

Additional Security Measures

  • Two-Factor Authentication (2FA):
  • Recommended for all software to add an additional layer of security.
  • Virtual Private Networks (VPNs):
  • Essential for remote work environments to secure data access.

Key Takeaways

  • Cybersecurity does not require a large budget; practical steps can significantly enhance security posture.
  • Employee education about security risks fosters a culture of vigilance and trust.
  • Regular reviews of security practices and compliance standards are necessary to keep up with evolving threats.

Guest Information

  • Zach Kromkowski LinkedIn: [LinkedIn Profile](https://www.linkedin.com/in/securityzachkromkowski/)
  • Sention Website: [Sention](http://senteon.co)
  • YouTube Channel: [Sention CIS Benchmarks](https://www.youtube.com/@senteonCISBenchmarks)

Sponsor Information

  • This episode is sponsored by ActiveCampaign:
  • Offers marketing automation solutions for small businesses.

Conclusion The episode emphasizes that cybersecurity is an integral part of business operations, especially for marketing firms that handle sensitive client data. By implementing best practices, leveraging available tools, and fostering a culture of security awareness, businesses can protect themselves against potential threats and build client trust.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00I was like, this, I found it, I found it, this is what I've been looking for. I can honestly say it has genuinely changed the way I run my business. It's changed the results that I'm seeing. It's changed my engagement with clients. It's changed my engagement with the team. I couldn't be happier. Honestly, it's the best investment I ever made. What you just heard was a testimonial from a recent graduate of the Duct Tape Marketing Certification Intensive Program for fractional CMOs, marketing agencies, and consultants. Just like them, you could use our system to move from vendor to trusted advisor, attract only ideal clients, and confidently present your strategies to build monthly recurring revenue.

0:39Visit dtm.world.scale to book your free advisory call and learn more. It's time to transform your approach. Book your call today. dtm.world.scale

1:04Hello and welcome to another episode of the Duct Tape Marketing Podcast. This is John Chance. My guest today is Zach Kromkowski. I was so worried about the last name that I messed it up. You overthought the last name and you got the first name. No worries. Kromkowski. Here we go. He is a force in cybersecurity driven to make system hardening both effective and accessible. Co-founder of Cention, he and his team developed an innovative platform that automates hardening for workstation servers and browsers to CIS standards, streamlining compliance and security. So we're going to talk about security, cybersecurity, I suppose, more specifically.

1:44So this is a topic that is not necessarily marketing, very related to what we do as marketers, very related to what we do as business owners. So, Zach, welcome to the show. Yeah, thank you for having me on. And I mean, you kicked off right there, John. Why is this relatable to marketing firms and owners? I mean, our little pre-session banter, it's like us marketing firms. And when we work with clients, they're telling us a lot of their IP. They're telling us their brand, their image. All of these details is how bad actors might be able to create a more targeted phishing email or more targeted, more persuasive email that isn't real.

2:23So even though we're talking about security on a marketing podcast, it's all related. So I really appreciate the pre-show banter we had, John. Yeah. Well, and not to mention, I mean, we have clients that, you know, their cousin's ex-boyfriend set up all of their passwords on things and they just have them on a spreadsheet and they give them to us. And, you know, as a marketing agency, in some ways that makes life easier because I've got all the keys, right? But it's also very, should be very scary to anybody that is taking that data. So let's kind of back up and can you give us some best practices on, you know, the typical small business?

3:01We can get into the agency, maybe it's a little different, but the typical small business, you know, what are some of the things they need to be doing as just routine practices? Not because the sky is falling, just because, you know, lots of things happen, right? You've got bad actors, but you've also got disgruntled employees. Maybe you've got, you know, lots of things that can happen in the world because stuff happens. So let's kind of start there. What are the basics? Yeah, I mean, there's risk to anything. Again, in that pre-show, we talked about as duct tape marketing, you have your own third party vendors.

3:33What can I do to protect myself? And you shared a little bit about that. So talking to those basics, there's a misconception with security that you have to invest hundreds, thousands of dollars just to have security. And I'll be the first vendor to admit, you don't need to spend a ton of money on security. There are things you can do specifically called system hardening. So this is one of the first things, in my opinion, any business owner, any SMB can really focus on. This is a concept of understanding where are your assets? Where are your computers? Where is your server? Maybe you have one, maybe you don't.

4:09Where are your computers? And the next step of saying, how are they configured? What software is installed on this computer? How can I configure that new software? to be more secure. So talking about some of these easy examples, something every small business owner I talk to always, and my parents, right? My family, for example, they want to save their passwords to the browser. Okay. This is universally just accepted. This is what everyone does, but what, but the browser, the Google, the Microsoft edge, these are not security first browser password storage methods, right? There are literally companies that dedicate their entire business model just to saving the password.

4:55So that's like Bitwarden, LatsPass. And when I talk about hardening, you know, you can't write a policy and say, hey, employees, I don't want any of you to save your password to the browser and expect them to do that. When I talk about hardening, we literally remove the ability to save a password to the browser. That way that policy is enforced and happens by nature. There's no way around it. So that's one aspect of hardening, John. Yeah. Awesome. So what about, I guess I'll stand on that same topic. What about the fact that like in my particular case, there is no server, there is no central office.

5:32In a lot of cases, people are using their own devices to, you know, to connect to many of the assets. So how does somebody who has a distributed workforce, is that going to be different or are we really just going to run a much higher risk? Yeah. So this is another good follow-up. It's this concept of risk and being able to communicate this as a marketing department or that owner is really important because if you can educate and talk towards your risk, it's going to build more trust. And this trust, you know, if I'm outsourcing my marketing as Centian, I have to trust the person that I want to work with, right?

6:12So let's say there is a distributed network, BYOD devices, you know, it's my personal computer and my work computer. What can we do? One of the things, and I'll stay on the topic of browsers, right? Browser security, browser hardening is very important. You can write a policy to say, hey, for work, you have to use the Google Chrome browser. For personal, use the other one, right? The Edge, the Firefox. Or if you want to set up a Google workspace, if you have a little bit of budget to invest, you can create a Google Chrome profile and you configure the profile to have company standards and then the personal one they manage on their own.

6:51There is a level of risk to that decision because they still have access to the other profile. Worst case scenario, that profile is compromised and they find a way to get to the other one, but you at least have that segmentation to add an additional barrier to that bad actor. Right. So when I talk about hardening, again, the key thing is here not to have default settings. If your settings are in defaults, a bad actor will know what the settings are before they get there. So if we can change some of those settings and create even the smallest barrier for that bad actors who have to invest 10 minutes instead of 30 seconds, they might just bypass you and go to the next target.

7:38They may not even try to hack you anymore. Yeah. Great example of that. It's not necessarily on a server, but many of our clients are on WordPress and just a simple thing like changing the page name of the admin login does that same thing because they're out there knowing that 90 % of the sites out there, it's admin, WPA-admin. And so if they're not going to find that in the one second bot search, they're probably going to move on. That is a really good example. And we talk about WordPress, but we can also talk about Microsoft in the same respect. So there's also an administrator account on the workstation, on the laptop itself.

8:17And that admin account, or I mean, we could talk about Fortinet firewalls, the password and usernames. If we just take that five minutes to change these default choices, it adds an extra layer of effort. And this is by most intensive purposes, the most important takeaway from the show is by adding layers of difficulty, even just one layer makes you a target that they probably won't want to hit. Yeah. Cause you see a lot of these, you know, things are obviously being done by bots in a lot of cases. So they're, you know, the bots just told ping this and so it'll move on. That's exactly right, John.

8:52That is a perfect way to say it. So what about many people? I don't know what the percentages are these days, but a lot of especially virtual companies have turned to Google Workspace as really a lot of their internal storage, their email, their calendars. What are some best practices for that? I know super admins have some security things they can set up. So what are some best practices to make sure that even if it's not the most secure thing, you can make it more secure? Absolutely. So this is going to go into more, I guess you're a Google house. You want to use, you know, single sign-on. You just want to click sign on with Google.

9:33That's great, right? But we do that so often. We're just signing up for this free trial of that, free trial of that. It builds up so much. So my recommendation here would be one, look at Google had a recent update. My CISO was extremely excited, but you can actually see now all of the accounts that are linked to your single sign-on. And you can easily remove that from having access. Because again, this is looking at the layers of security. If you're single sign-on, if your Google account is unfortunately compromised, now they have access to everything. And even things you don't use or don't need anymore.

10:10So doing that asset inventory review allows you to reduce your tax surface and reduce the things that have access. And let's talk about the flip side of that. if that third party company, the one you did use single sign on to sign on with, and you don't even need it anymore, they get compromised. Now they can leverage that to attack you, right? Because you still are authenticated. You still have the permissions because you never removed it. So that first most important best practice would be to review what you currently have available via that single sign on. It's my pleasure to welcome a new sponsor to the podcast, our friends at ActiveCampaign.

10:49ActiveCampaign helps small teams power big businesses with a must-have platform for intelligent marketing automation. We've been using ActiveCampaign for years here at Duct Tape Marketing to power our subscription forms, email newsletters, and sales funnel drip campaigns. ActiveCampaign is that rare platform that's affordable, easy to use, and capable of handling even the most complex marketing automation needs. and they make it easy to switch. They provide every new customer with one-on-one personal training and free migrations from your current marketing automation or email marketing provider.

11:24You can try ActiveCampaign for free for 14 days, and there's no credit card required. Just visit ActiveCampaign.com slash duct tape. That's right, duct tape marketing podcast listeners who sign up via that link will also receive 15 % off an annual plan if purchased by March 31st, 2024. That's activecampaign.com slash duct tape. Now this offer is limited to new ActiveCampaign customers only. So what are you waiting for? Fuel your growth, boost revenue, and save precious time by upgrading to ActiveCampaign today. What about users? Are there policies that you should have all of your users adhering to?

12:04This is a good one. So this goes towards, you know, disabled browser password manager. So that one example is the most relatable to everyone because everyone knows what a password is. Everyone knows how to save a password. I'll go high level on this, but there's an organization. It's a free nonprofit. It's called Center for Internet Security, CIS. And they have free downloadable PDFs on how to configure your Google Chrome, how to configure your Microsoft Edge. And that setting I gave the example of with passwords, that's about one setting out of 100 some different settings. So another example is, you know, when executing a download, you have to explicitly say, download it to this folder, right?

12:49It makes you do one extra click because for that fish, without that in place, that fish you click, automatically done. With the extra layer, now the user says, okay, I'm going to click this. oh, now it wants to trigger a download. That's not behavior I expected. And it allows your employee, it allows your clients, it allows you to take an extra second to say, is this what I thought would happen? And maybe that extra second prevents the worst from happening. A little bit about password management as it relates to certainly to Google, but then you also mentioned some of the password managers out there.

13:27Are there best practices for password management in general? Yeah. So this one's good. So 2FA, I'll say this on every single episode I go on for any field. Password managers are critical. Save your passwords there, but let's talk about getting into the password manager. This has to be the most unique password because you can't put it in their password manager. You can't because if you don't know this password, you can't sign into it to figure out what it is, right? So you need to know that password and that is something you should treat like your social security number, whether you have it written down and put into a safe or you just have it memorized, which memorizes, of course, the best practice.

14:06But making sure this has at least 20 different characters. And when I say characters, I'm referring to letters, numbers, and symbols, right? Those are the things that make a strong password. And because this is a password you use nowhere else, it's a single password. This is actually not something I would recommend to rotate or change. This is just your forever password until your safe gets broken into, until you get an alert saying possible password compromise, you never have to rotate this password. This is your single source of truth to get into your password manager. And yeah, on top of that, I'll say one more time, the 2FA, you know, if you, every piece of software, every, everything that you have access to always go through and just see, hey, in the setting section or the security and option section, do they have a 2FA option available?

14:59Do you want me to go a little bit deeper into why that's important, John? No, but I do want to explain, not everybody knows the acronym 2FA. So, you know, two-factor authentication. So we've all got some, you know, all the financial folks have gone to almost forcing that. So, right. So you log in and then says, all right, we're not sure this is you, we're going to text you a code or you need to use an authenticator or something. So it's basically it's just a second hoop, if you will, to, you know, somebody could have your phone, you know, they could have your password so they could authenticate it, but it just adds a, an extra hoop of, you know, for somebody that's out there and some, you know, some far away Island that's trying to hack into your stuff.

15:38And I think that's a great point. And I'm glad you called me out for that. I do my best to speak all of my acronyms. It's, it's alphabet soup in the security world. But this is a cool thing. And relating it again, back to the marketing departments and marketing teams and doing sales, right? If you were trying to sell Cention or a security company, hey, I want to do your marketing. I need all of this brand information. I need all of your value props. I need whatever to build the perfect messaging. If one question I would probably ask you, hey, how are you storing this? So marketing departments may want to take half a step into enabling their sales team to say, Hey, you know, if it ever makes sense, feel free to let the prospect know, Hey, we secure our data this way.

16:23We have managed browsers, right? We do use 2FA. Like if a marketing firm said that to me and leaned into my space as a security vendor, I'd be impressed. I'd be like, Hey, you know, maybe they're not experts, but they took that half a step to at least try to appeal to what I care about. And that would mean a lot to me. So here's my other topic. I'm going to throw this one in here. This might just mix up the soup a little bit, but where do you stand on VPNs? So again, since we're all over the world and all doing, you know, we're all logging into like Google to do X, should we all be using virtual private networks that kind of mask our IPs?

17:01Yeah, I mean, this again goes towards that BYOD. If you are an enterprise who can only access certain things via the on-premise domain, you have to be connected, you have to be on-site in order to obtain certain information, you're going to be inherently required to have a VPN. Now, the debate kind of comes in, okay, we can only access the data on site, we have no one remote, do we really need a VPN? In that case, you probably don't. I mean, more is always better. But in that case, it's probably overkill. If everyone is already working on site, the computers never leave the business, right? Everything has to be done there.

17:44There's not a lot of value because the data is never leaving that secure built in environment. Now, to your point, a lot of people are BYOD. We're all remote nowadays. So yeah, they really do become that backbone to say, if I don't lock out some of that business data and require a VPN in order to reach it, anyone can reach it. Right. So it's going to depend on your business model, your business setup. But yeah, VPNs are critical for those remote environments. But if you are on site, probably not necessary. So you talked about if somebody was wanting to do your marketing, if I went to a company and they were asking, in fact, we've had this happen before where people have an IT company that they work with and they're like, hey, here's our checklist of security standards.

18:34do you meet them? So is there, is there kind of a, I wouldn't call it the gold standard, but maybe even a minimum standard that, that if I went to them and just said, Oh yeah, we are BXYC compliant, you know, is there one, one sort of compliance level that, that say a small business should strive towards? So there's an easy answer that comes to mind here, and that's going to be SOC two compliance, which is maybe what you're leaning towards. And it's definitely one of the most common and most understood compliances to me. And it would mean something to me. It would definitely say, well, they at least did that.

19:10That means they care about it to some extent. The follow-up question, and if you do take the approach of getting a SOC 2, which, yes, that's a good approach. Centian has one, right? We're doing all this. But be able to say, you know, not only do we have one, this is what we got it for. So that's the very unique thing with SOC 2. I can get a SOC 2 on the Centian website, but the Centian solution itself has no security certification, right? So if you intend to take the approach of leading or injecting at some point during the sales conversation as a marketing firm, hey, we have our SOC 2, be sure to be ready for that follow-up question and say, what's your SOC 2 for?

19:52Because that is something that we would ask if anyone ever said that to us. And I believe that's SOC 2, right? It is. And I think it's the Roman numerals too is usually how it's. Okay. All right. If people want to look that up. Let's say we're 18 minutes and 38 seconds into this recording. Let's talk about AI. Oh boy. So does AI, where are the risks, I suppose, posed by AI that we need to at least be thinking about? So risk, especially in the relation to marketing and the business field that you cater to, John, You are a goldmine to a bad actor. Why? We talked about this a little bit at the start, but you have multiple companies' brand, multiple companies' points of context, multiple companies' just image.

20:39If an AI, if you were to be compromised, and I already heard you have your layers of security, so kudos to you on being able to talk towards that. Very good conversation pre-show. But let's talk about if, worst case scenario, you were compromised. That AI can now ingest hundreds of companies' unique branding colors, branding verbiage, branding everything, and it takes that data and then can target the next business, your customer. You have a similar risk profile to a managed service provider. So a managed service provider will typically manage the IT and security and has more access. So they can be a direct point of breach, right?

21:23They can take advantage of things. But you're the next layer. You're the layer still hugely valuable to an AI because that AI now is tailoring its messaging, becoming you, talking to that end client. And it's going to be hard to tell the difference, John. I mean, that's the end of the day. Our AIs are becoming so trained and so tailored. If we inject it with the appropriate information, which marketing firms already have, how are your clients going to know the difference? I actually saw somebody post. And again, you know, there are definitely a lot of people out there trying to kind of lead with the fear factor, but some of it's real.

22:00and they were suggesting that if you got a phone call from somebody and, you know, your boss, your spouse, and they were asking you for something that you thought was a little odd, but it sure sounded like them that, you know, that level of fake is going to be out there. And that people were actually talking about having your own sort of password with each other. I love the stories. And I've, so, you know, when we call partners and sometimes, you know, know, they don't always have our numbers saved. And a lot of, I mean, just you guys, we're all in marketing here, right? We've done the cold calls, we've done the customer calls, and they may not recognize the number.

22:37Some security companies will take an edgier take to this and have a little AI recording or AI interface to almost annoy the person on the other line. They simply pretend to be a real person, but you're actually talking to a computer the whole time. And that's just one piece of AI, right? Now you take that kind of a comedy scenario, that satire, like, oh, it was just used for Goofy, but you actually allow it to now make outgoing calls, make those outgoing fakes. Having that key password phrase makes a difference. I think my biggest point here is, hey, can you remind me what so-and-so's story was, right?

23:17doing something personal that an AI probably doesn't know. And I'm going to be honest, like I've had to do that. And like, Hey, like this conversation has been going for 45 seconds. I haven't felt anything real out of it. I'm going to put a very personal question here to see how it responds. And sure enough, it couldn't, it just went back to the replay loop. Yeah. Wow. So Zach, I appreciate you taking a few moments to stop by the duct tape marketing podcast, we obviously had a wide range of topics that probably just stirred up more questions than answers. Happy to come back. But you want to invite people where they might want to connect with you and maybe find out more about some of the things we talked about if they have some concerns.

23:58Yeah. So my name, again, Zach Kromkowski. I'm very active on LinkedIn. You can find that at securityzach as the profile name. But the big thing I want to shout out here is you don't need a security budget to do security activities. The things I talked about today is knowing what software you have, knowing what hardware you have, and then changing settings. If you're overwhelmed and don't know what these settings do, we have free documentation across YouTube and our resource hub to say this setting does that, this setting does that, and you can take advantage of this 100 % free offering to do some of these steps without paying anything.

24:36Now if you do want to do this at a mass scale. Centian automates all of this. That's the plug. But there's a lot of free steps you can do without even investing a dollar. Awesome. Again, I appreciate you stopping by and hopefully we run into you one of these days out there on the road.

From the publisher

In this episode of the Duct Tape Marketing Podcast, I interviewed Zach Kromkowski, co-founder of Sention, about the importance of cybersecurity for small businesses and marketing firms.

Zach's cybersecurity journey began with a passion for problem-solving and a talent for turning ideas into reality. Blending intelligence, tenacity, and a love for community education, he simplifies cybersecurity through webinars, workshops, and consultations, helping MSPs and enterprises easily enhance their security.

We discuss best practices for system hardening, managing security in a distributed workforce, and the significance of password management and compliance standards. The conversation also touches on the risks AI poses in cybersecurity and the necessity of implementing two-factor authentication and VPNs. Zach also emphasizes that adequate security doesn't require a large budget and offers practical steps businesses can take to enhance their security posture.

 

Key Takeaways

  • Cybersecurity is crucial for marketing firms and small businesses.
  • System hardening can be done without a large budget.
  • Managing security in a distributed workforce requires clear policies.
  • Google Workspace users should regularly review linked accounts.
  • Password managers are essential for secure password storage.
  • Two-factor authentication (2FA) is a must for all software.
  • SOC 2 compliance is a common standard for businesses.
  • AI poses unique risks in cybersecurity that need to be addressed.
  • Adding layers of security can deter potential attacks.
  • Educating employees about security risks builds trust.


 

More About Zach Kromkowski:

  • Add Zach Kromkowski on LinkedIn - https://www.linkedin.com/in/securityzachkromkowski/
  • Check out his Website - http://senteon.co/
  • Subscribe to his YouTube channel - https://www.youtube.com/@senteonCISBenchmarks

 

This episode of The Duct Tape Marketing Podcast is brought to you by: Active Campaign. Try ActiveCampaign free for 14 days with our special offer. Exclusive to new customers—upgrade and grow your business with ActiveCampaign today


Rate, Review, & Follow on Apple Podcasts

If you liked this episode, please rate and review the show. Click here - https://podcasts.apple.com/us/podcast/the-duct-tape-marketing-podcast/id78797836 scroll to the bottom, tap to rate with five stars, and select “Write a Review.” Then, let us know what you loved most about the episode.

Connect with John Jantsch on LinkedIn - linkedin.com/in/ducttapemarketing/

Are you stuck trying to figure out your marketing strategy? Get Your Free AI Prompts To Build A Marketing Strategy HERE - dtm.world/freeprompts


More from The Duct Tape Marketing Podcast

All 360 episodes
Gain Client's Trust by ensuring CybersecurityThe Duct Tape Marketing Podcast · 25 min
Listen in VO