In short
How small businesses get hacked via social engineering, vendor compromise, and weak identity controls; how to defend with “defense in depth,” least privilege, and basics like 2FA and password managers; AI’s role in faster scams and deepfakes, plus data/privacy risks.
Guest backgrounds
Abed Hamdan, founder of GRC Mastery and content creator known as the “Unix guy online.” He has 20+ years in cybersecurity and risk, started learning in late 1990s/early 2000s via IRC and “Hackers,” and later focused on Unix; he now consults and teaches.
Key claims
- Entrepreneurs underestimate attackers and consequences; small businesses are attractive because they hold privately identifiable information and can be used to pivot through suppliers.
- Most common compromises start with social engineering/phishing and time pressure.
- Non-negotiables: enable 2FA everywhere, use a password manager, and restrict “key critical assets” with least-privilege/time-limited access.
- AI won’t automatically “hack,” but it accelerates phishing/deepfakes and increases risk when businesses give AI access to sensitive data.
Notable examples
- A women’s safety dating app that collected passport details and was “zero security,” later hacked.
- Deepfake explicit videos targeting vulnerable people.
- Attack walkthrough: recon via LinkedIn/Instagram, then spoofing emails/brands, targeting busy founders, or impersonating customers via support calls.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOCybersecurity Risks in Emerging Tech
0:26 to 0:56
Discussion on a security breach involving a dating app and the implications for women's safety.
“That's why I want to put you guys onto AT &T Business.”
Cybersecurity Risks in Emerging Tech
1:50 to 2:20
Discussion on a security breach involving a dating app and the implications for women's safety.
“Mindstone is an AI transformation company that helps professionals get real value from AI.”
Cybersecurity Risks in Emerging Tech
2:23 to 3:06
Discussion on a security breach involving a dating app and the implications for women's safety.
“There's a really famous story on the news.”
Meet Abed Hamdan
3:06 to 3:30
Introduction of guest Abed Hamdan and his expertise in cybersecurity.
“We want to be on top of the new technology, but we also need to stop and think, What is it that we're using AI for?”
Understanding Cybersecurity for Entrepreneurs
3:30 to 3:50
Exploring entrepreneurs' misconceptions about cybersecurity and the risks they face.
“This tells me that this team is extremely busy.”
Understanding Cybersecurity for Entrepreneurs
4:23 to 4:52
Exploring entrepreneurs' misconceptions about cybersecurity and the risks they face.
“Now, to help us better understand the business of cybercrime and how organizations can protect themselves, we're joined today by Abed Hamdan.”
Attractiveness of Small Businesses to Hackers
4:52 to 6:01
Discussion on why small businesses are targeted by hackers, emphasizing their vulnerabilities.
“For the entrepreneurs tuning in, what is something that you think they fundamentally don't understand about cybersecurity?”
Main Compromise Methods for Small Businesses
6:01 to 8:07
Detailing common methods hackers use to compromise small businesses, focusing on social engineering.
“like really big companies like Meta getting hacked or Bank of America or something like this.”
Hypothetical Attack on a Business
8:07 to 10:21
A step-by-step explanation of how a hacker might attack a small business.
“So we not only have to worry about our own security, we have to worry about the security that our vendors are doing for their own companies, which is just so crazy to think about.”
The Frightening Reality of Cyber Attacks
10:21 to 13:50
Highlighting the alarming ease of cyber attacks on entrepreneurs and small businesses.
“If you could really just walk us through, let's say there's a company that has like 20, 30 employees.”
Show all 31 chapters
Identifying Weaknesses in Cybersecurity
13:50 to 14:00
Discussing telltale signs of inadequate cybersecurity within organizations.
“So what is one thing that with our cybersecurity, when you're looking at small businesses, what's one thing that entrepreneurs are doing where a hacker is going to say this is just way too easy?”
Identifying Cybersecurity Weaknesses
14:00 to 16:03
Learn how to spot potential cybersecurity vulnerabilities in businesses.
“And I'm going to start with the big business and then go down to the small one.”
The Journey into Cybersecurity
17:04 to 20:25
Explore the early experiences and motivations of a cybersecurity expert.
“And I learned from studying you that you got into this when you were like a teenager.”
Essential Security Practices for Small Businesses
20:25 to 25:24
Discover critical cybersecurity practices small businesses must implement.
“So we're going to spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business.”
Understanding Least Privilege in Cybersecurity
25:24 to 28:00
Learn about the concept of least privilege and its importance in security.
“The fourth one is similar to it's just get a professional opinion.”
Understanding Cybersecurity Basics
28:00 to 31:20
Learn about essential cybersecurity practices and how to manage customer data.
“They have their enterprise suite solution.”
Consequences of Cyber Attacks on Businesses
31:20 to 35:00
Explore the potential damage and financial implications of cyber attacks.
“So for the entrepreneurs tuning in who still don't feel like there is much of a risk with cybersecurity or still aren't scared enough, talk to us about what could go wrong, like reputation-wise, revenue-wise.”
Budgeting for Cybersecurity
35:00 to 37:00
Strategies for investing in cybersecurity even with limited funds.
“And that can be career ending, unfortunately.”
Implementing Defense in Depth
37:00 to 39:40
Discover the concept of multi-layered security in protecting your business.
“That$1 ,000 can do it, may not do it all the time, but it's better than doing what a lot of businesses do now, which is chat GBT things and AI is telling you, yep, you're doing a great job.”
The Role of AI in Cybersecurity
39:40 to 42:00
Understand how AI impacts the cybersecurity landscape and challenges professionals face.
“You've described cybersecurity as defense in depth.”
Understanding Cybersecurity Human Errors
42:00 to 44:10
Learn how human mistakes can compromise cybersecurity and the need for multiple defenses.
“I can have all the defenses, but if a human makes a mistake and click on something, it's game over.”
AI and Cybersecurity: Opportunities and Risks
44:10 to 47:55
Explore how AI is reshaping cybersecurity, including the threats of deep fakes and data misuse.
“There are ways around it, but let's say if someone is completely unskilled and they're trying to do something, it's just not happening.”
The Responsibilities of AI in Business
47:55 to 52:28
Discuss the importance of accountability when using AI tools in a business context.
“is there risk in having an AI avatar that you actually create for yourself and for your content?”
Managing Access and Risks with AI Tools
52:28 to 56:00
Learn how to effectively manage access and risks associated with AI tools in the workplace.
“AI is actually, we might be rolling out specific company AI tools, but because AI is kind of popping up everywhere, employees are probably using all these like disparate AI tools or like whatever tool they think is fun.”
The Role of AI in Business Operations
56:00 to 1:00:02
Explore the impact of AI mistakes on financial data and how validation can mitigate risks.
“And this is the problem, the inherent problem with AI, Hala, is it makes mistakes.”
Understanding Insider Threats
1:00:02 to 1:02:36
Learn about the risks posed by insider threats and the importance of access management.
“I want you to break it down and then close the back door.”
Identifying Backdoors in Business
1:02:36 to 1:05:28
Discuss scenarios of potential security vulnerabilities in businesses and how to address them.
“So with speed, the compromise is more mistakes.”
Handling Cybersecurity Breaches
1:05:28 to 1:10:01
Find out what to do and what not to do when a business experiences a cyberattack.
“Somebody just stole a bunch of money from our bank accounts.”
Success Stories and Career Development
1:10:01 to 1:12:02
Learn how sharing advice has led to life-changing success stories for others.
“And then it's like, actually, I got a job.”
Building a Cybersecurity Certification
1:12:02 to 1:12:44
Understand the process of creating an accredited certification in cybersecurity.
“And thank God it's been really successful in the sense people started recommending.”
Essential Cybersecurity Practices
1:12:44 to 1:13:44
Discover the top three practices to protect your business from cyber threats.
“I mean, that's an incredible career that you have.”
Transcript
Automatic transcript. May contain errors.0:00Hala Taha:Hey, Young and Profiters. Let's talk about that moment when your business starts growing beyond your wildest dreams. You go from working solo to managing a team, serving clients, and balancing the systems that keep your lights on. I really felt that shift as Young and Profiting grew from side hustle to the media company that it is today, Yap Media. Suddenly, reliable connectivity is no longer just a nice to have. It's become essential to keeping everything moving smoothly. That's why I want to put you guys onto AT &T Business. Think of AT &T Business as your go-to for reliable business connectivity.
0:34Hala Taha:They help your team, devices, systems, and day-to-day operations stay connected so you can focus on the important stuff, serving your clients and growing your company. You work way too hard to let a shaky signal slow down your momentum. Give your business the rock-solid foundation it needs with AT &T Business so you can step into your CEO energy. Powered by AT &T Business. Built to work. Get AT &T Business at business.att.com. Today's episode is sponsored in part by Shopify, Indeed, AT &T Business, Northwest Registered Agent, Mindstone, and Honeylove. Shopify is the global commerce platform that helps you grow your business.
1:16Hala Taha:Start your$1 per month trial at shopify.com slash profiting. Indeed helps you attract, interview, and hire all in one place. Get a$75 sponsored job credit to boost your job's visibility at indeed.com slash podcast. AT &T Business delivers reliable business-grade connectivity that gives your team a competitive edge. Switch to AT &T Business at business.att.com. Northwest Registered Agent gives you the tools and guidance you need to build a complete business identity. Visit northwestregisteredagent.com slash yap free and start using free resources to build something amazing. Mindstone is an AI transformation company that helps professionals get real value from AI.
2:00Hala Taha:Get 10 % off their four week AI competency program at experience.mindstone.com slash yap. Honeylove makes the most advanced sports bras and shapewear on the market. Save 20 % off Honeylove by going to honeylove.com slash profiting. As always, you can find all of our incredible deals in the show notes or at youngandprofiting.com slash deals. There's a really famous story on the news. They created a dating app. It's for women's safety. But then turned out that app, they took their passport details and all their information. Turned out this app was vimecoded with zero security. It got hacked and it put women's safety in danger.
2:38Usually women get targeted like someone leaks explicit videos of an individual. And well, that video is completely deep fake and it has been happening. They always target the vulnerable. They always target the young. It is a problem and we need some kind of a strict regulation.
2:53Hala Taha:We're joined today by Abed Hamdan, founder of GRC Mastery and content creator, who's known as the Unix guy online. He brings more than two decades of experience in cybersecurity and risk. So we want to use AI. We want to be on top of the new technology, but we also need to stop and think, What is it that we're using AI for? What does the AI have access to? And more importantly, where's my data going? What's one thing that entrepreneurs are doing where a hacker is going to say, this is just way too easy? Something I see frequently is a founder says, oh my God, we went live last week. You wouldn't believe it.
3:27We expected 200 clients and now we have 2 ,000. This tells me that this team is extremely busy. They can barely keep up. This is a really quick telltale. There are other things that...
3:38Hala Taha:How worried do we have to be about AI agents and their ability to hack our companies or their cybersecurity threats? There are many issues with AI agents. The first one is... This episode is brought to you by Bitdefender, a global leader in cybersecurity. Have you ever received an email that looked like it came from a bank or a trusted vendor asking you to wire money immediately? Small business owners get hit by scams like this all the time. And one click can cost your business everything. Bitdefender Ultimate Small Business Security keeps your devices, passwords, and teams safe, even if you don't have an IT team.
4:15Hala Taha:Protect your business with Bitdefender Ultimate Small Business Security. Save 30 % when you go to bitdefender.com slash profiting. That's bitdefender.com slash profiting. Now, to help us better understand the business of cybercrime and how organizations can protect themselves, we're joined today by Abed Hamdan. Abed, welcome to Young and Profiting Podcast. Hi, Hala. Thanks for having me. I am really looking forward to having this conversation about cybersecurity. I feel like all business owners need to protect their businesses. And with AI, cybersecurity is becoming more important than ever. But let's start at the very basics.
4:53Hala Taha:For the entrepreneurs tuning in, what is something that you think they fundamentally don't understand about cybersecurity? Entrepreneurs usually make, I think, a couple of assumptions about cybersecurity. I think first, the first assumption they make is about the attacker. So they think the hacker is this person in a hoodie in some basement, or they go the other extreme and they think the attacker is some really sophisticated sort of spy agency or foreign government. And as a result of these two assumptions, they usually think, well, I'm an entrepreneur, I run a small agency or I run a small business.
5:31Why would anyone attack me? and unfortunately of the businesses that I helped, usually after the fact. So they get attacked and they really sometimes underestimate the consequences of some cyber attacks. Some of them unfortunately can be business ending or it can have such a large cost that it may even be cheaper to just shut the business down. And this is huge everywhere across from like small business to even medium-sized and in some instances, even large businesses.
6:01Hala Taha:Yeah, I always think of like like really big companies like Meta getting hacked or Bank of America or something like this. But small businesses actually can be attractive targets. Why is that? 100%. In fact, think about it. If you were a hacker, let's say you've just learned how to hack and you want to start, you know, legally hack, you naturally wouldn't go after Meta because that's such a difficult target. They invest so much in cybersecurity. They're at the forefront of everything technology. However, when it comes to small businesses and entrepreneurs, usually they're just focused on getting their product out.
6:40They are overworked and in most instances also underfunded. So they can be, quote unquote, easier targets, but they also hold something really valuable. They hold what we refer to as privately identifiable information. So that's something that we classify as a critical asset. For example, a lot of entrepreneurs will have something like a customer database where they have the names and last names and phone numbers and sometimes the addresses. This is extremely valuable because what attackers can do, they can get that information and sell it on the dark web. It's actually extremely valuable. So that's a really key critical asset that lots of small businesses have.
7:19And unfortunately, sometimes they don't have the knowledge or the resources to protect that. But the other thing and probably the more important thing that small businesses have is that, well, like I said earlier, it's maybe a lot harder to hack something like a big bank or something like Meta, as you alluded to. However, the way to get into those companies is usually you hack their suppliers. So if that small business is a supplier for a bigger business, usually it's a lot easier to attack that small business and use it to pivot or use it to trust. So if you can compromise the email account of a small business, well, you can start sending malicious stuff using their email address.
7:59In fact, that's how most big businesses get compromised through their suppliers and they're usually on the smaller side.
8:05Hala Taha:So interesting. I never thought about that. So we not only have to worry about our own security, we have to worry about the security that our vendors are doing for their own companies, which is just so crazy to think about. What are the main ways that small businesses are compromised? So we just talked about vendors for bigger enterprise businesses. How about small businesses? What are the main ways that they're compromised? So look, the way sort of hacking or compromise happen, there are actually so, so many ways. Most of them aren't even known to the public. They tend to be complicated. But the most common ways for, let's say, an attacker to gain foothold and tend to be the easiest way.
8:45It's what we refer to as social engineering. This is where the attacker pretends to be someone that the business owner knows or pretends to give them something that they trust. So we really use the old age sort of trust relationship that we humans rely on. For example, as a small business, I could pretend to be one of their employees and send an email urgently, say, hey, floss my account urgent, please click on that link and help me out. So we apply time pressure. So we call that social engineering or phishing, which falls under social engineering. There are other sinister ways as well, but it all comes back to really pretending to be someone else.
9:25So fellow entrepreneurs and YouTubers, a really common recent one is actually pretending to be a brand and offering a brand deal.
9:33Hala Taha:Yes, I get so many of those. I've even helped like cybersecurity professionals who got hacked this way. And that's no shade on them. This is just a testament on how good some of those attacks are. They can really pretend to be a legitimate brand and the website look exactly the same. There might be just a slight variation on the URL. And sometimes it's something that your eye cannot see. So some of the alphabets, we can replace it with special characters and it's really hard to detect. So that's a really common way. There are more and more ways. For example, if you have physical access to the business, there are things you can install.
10:09but that's a whole other story. But when it comes to sort of the most common ones, it tends to be 100 % social engineering.
10:17Hala Taha:So let's really unpack this with a real example. If you could really just walk us through, let's say there's a company that has like 20, 30 employees. They're using the typical things, Slack, cloud storage, Zoom. They might have vendors, different SaaS tools. Walk us through how they could get attacked and some of the things that could happen and how it could escalate? Yeah, I mean, just before I say anything, just disclaimer, hacking is illegal. What I'm about to say is for educational purposes, so please don't do it. But hypothetically, if I was to attack this imaginary business, the first step I would do is always reconnaissance.
10:58So I'll try to collect as many information as I can about that business. This includes their LinkedIn posts, how many people work there. I'll even draw like an org chart. see who's who, who's the employee, go on Instagram. They usually share everything. So I'll get a list of the individuals who work there. But more importantly, I'll get a list of the technologies that they use and also the product that they have. So once I get a list of that, the next step would be I'll start to craft things that they trust. I'm going to social engineer my way there because it's a lot easier for me, like I said, to get an employee to do something for me as opposed to me trying to hack Microsoft and get inside their email.
11:39So what I will do is I'll try to mimic what their email looks like. And now that's really easy. I can literally vibe code that in like five minutes. It used to take a lot more time. The second thing is I'll see what vendors they use. So if they use so many SaaS applications, well, I could hypothetically go to the dark web and see if there is any information about those services. If there is a new vulnerability, it may not be patched. So I could directly go and hack one of their SaaS services and get into their network. But let's say everything they use is secure. Well, I'll try to then attack, sort of target the employees individually.
12:17I'll usually target who may appear to be more vulnerable. Usually it's very busy individuals, very busy founders. They are more likely to click on something really fast. Sometimes I'll even, And not I, but the hypothetical attacker may look at elderly parents and try to tell them they've won something. Because what happens, Hala, is if the elderly parent gets their email compromised, well, I can use their email to send stuff to sort of their kids. And they're more likely to click on them than if it comes from an unknown individual. Now, the final one that is very, very effective with entrepreneurs and all the startups that I don't recommend anyone to do, but I could simply purchase the product that they have and be a legitimate customer and just give their customer support hell.
13:10I'm like, it's not working. Help me. Hop on a Zoom call. Do this. So the customer support individuals are very likely to say, well, I tell them my Zoom is not working. Please click on this so I can get them to click on something. And unfortunately, support individuals usually have a lot of access. So as soon as they click on something, I'm in. And I can continue pretending to be a legitimate customer, which I am, close everything so they don't suspect that something's happening, and then I'm in the network. Then I'll start to slowly and surely take over everything. But that's more or less how, I guess, a lot of hackers would actually approach it.
13:46Hala Taha:That's so frightening. It's so frightening that this could be happening. And I guarantee you that so many entrepreneurs tuning in are now realizing how big of a deal this is and how little they're probably protected. So what is one thing that with our cybersecurity, when you're looking at small businesses, what's one thing that entrepreneurs are doing where a hacker is going to say this is just way too easy? I mean, there are a number of things. And I'm going to start with the big business and then go down to the small one. a really big telltale. Even for me as a consultant, if a company is hiring me to check their security, the first thing I go on LinkedIn and I just see who works there.
14:24If that organization is sort of mid-size to large size, and I see that they have like one person that's called, quote unquote, IT person that's doing everything, this is a sure sign that this person is overworked, probably doesn't have enough time to do everything security-wise. So I know there is a high chance that they may not be doing everything they need to do. So that's a quick telltale for me. The other one would be, believe it or not, I'll go on Instagram and something I see frequently is a founder says, oh my God, we went live last week. You wouldn't believe it. We expected 200 clients and now we have 2000.
15:00This tells me that this team is extremely busy. They can barely keep up. And it's a lot easier to do things with them that, you know, I'll put a time pressure. Hey, I'm a customer. The app's down. Help me log into my computer. Do something for me. This is a really quick telltale. Now, more than that, there are other things that I wouldn't say small business owners sort of do. Used to be more common in the past. So things like not having two-factor authentication or like old practices that they still exist, but not so much nowadays. So systems have gotten better, thankfully. But as a result, because we have better systems, better IT setups, we can produce a lot faster.
15:41and with speed comes compromise. And not just in cybersecurity. You probably have seen it, where organizations or entrepreneurs or small businesses, they release something, but they haven't done their due diligence from a legal point of view. They haven't gotten everything reviewed and they say, well, we'll do it after the fact. So these kinds of things may have large impact and in some cases, large consequences.
16:03Hala Taha:This episode is sponsored by Bitdefender, a global leader in cybersecurity. Many small business owners lack dedicated IT support, making them easy targets for cyber criminals who steal data, money, or sensitive information. Bitdefender Ultimate Small Business Security is built specifically for business owners like you. It protects all of your team's devices, scans for phishing and scams, manages passwords, and even checks the dark web for leaked info. Unlimited VPN allows your team to work securely from anywhere. The dashboard is super simple. I set it up in just minutes, I add my whole team, and now everybody is covered whether they're in the office or the studio or working remotely.
16:44Hala Taha:Bitdefender makes cybersecurity easy so you can focus on what really matters, growing your business and serving your customers. Protect your business today with Bitdefender Ultimate Small Business Security. Save 30 % when you go to bitdefender.com slash profiting. That's bitdefender.com slash profiting for 30 % off. bitdefender.com slash profiting. I want to understand how you know so much about cybersecurity and hacking. And I learned from studying you that you got into this when you were like a teenager. And you were really exploring, you know, how does hacking work? And I'm curious to understand, like, where did this all begin?
17:22Hala Taha:Tell us the story. Yeah, I mean, not to show my age, but I'd say I started perhaps late 90s, early 2000. And at that time, and especially where I was living, internet was new. It was a novelty. It's the new thing. Internet, for those my age, internet cafes were a thing. So you'd go to an internet cafe, your paper hour, and you start exploring and there wasn't much to explore. So it really started with chat rooms called the IRC chat rooms. And within that, I discovered, well, people were sharing files you can download. There is a music file that was new to me. And then there was this thing called hacking.
18:02It coincided with me watching a movie called Hackers. It was an early Angelina Jolie movie. It is fiction, but it really opened my eyes. Like, hold on, this is a thing. Like, you can actually do that. So as a teenager, and as you do as a teenager, you start imagining things. Oh my God, I could hack an airplane and fly myself everywhere. These imaginary scenarios that are not real, but like as a 15 years old, this is everything. then as I sort of quote unquote do research sort of find movies I find another movie about someone called Kevin Mitnick late Kevin Mitnick he is the most famous hacker in the world at the time there was movie not just one I think more than one movie one was in German one was in English of course I'll watch with subtitles he the things he did were incredible he would hack phone lines he would jam radio signals.
18:55He was on the run by the FBI. And the movies, of course, made it so glamorous. So all I could think of like, oh, my God. And that was a time when we would call people on phone line. So I'm like, oh, I could hack my friend's phone line. I could do these pranks. So I wanted to learn everything. I'd go to these chat rooms. And at the time, Hela, things were a bit different in the sense, if you ask for help, people start swearing at you. It was not a friendly time, unlike today. So I had to learn certain things the hard way. I got myself hacked multiple times. But long story short, I sort of went into the right direction, started learning an operating system called Unix, hence where my nickname came.
19:37And actually a fun sort of useful anecdote, my website, unixguide.com is a few months older than google.com. So I go way back. Wow. Yeah. So that's where it all started. Then I got my first job, studied things at university that were completely useless. Got my first job, but I continued learning. And I still do that to this day, even after consulting for so many years. I enjoy it. I like to learn. I stay curious and experience, of course. I've done this so many times, so much so that sometimes I can look at something and like have an educated guess that maybe we can look here, let's just start this way and take it from there.
20:18But yeah, it's been a continuous learning and experimenting journey. And it's a lot of fun.
20:24Hala Taha:Your entrepreneurship journey is like really interesting. So we're going to spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business. And you've done such a great job, like really owning this niche and the slain and helping so many people in their IT careers, especially in Australia. So since we have this incredible consultant in front of us, a lot of the people tuning in are entrepreneurs. We're small business owners. We don't have endless budgets. We have a lot of information that might be vulnerable, but you know, we're not this huge company.
20:58Hala Taha:But like you said, that makes us actually pretty attractive. So what are the few things, let's say three things that we should absolutely not compromise? on when it comes to our security? What should we be investing in and where do we begin? This is challenging because it may slightly vary between businesses, but I'd say the first one, non-negotiable, is always two-factor authentication. Luckily, we live in a day and age, everyone knows what that is. So when you log into your email, sometimes you get an SMS that says, is that you? Enter a code. The preference is always to use something like a passkey or the authenticator app.
21:37Even a few years ago, this wasn't rolled out to everyone. We had to have difficult conversations. It tends to really, really reduce the risk of cyber attacks, not to zero, but it's really important. And within that, no exceptions. So if you have a busy executive or someone precious in the team that says, I hate that, tough luck. This is unnegotiable. This is like having a building and having a fire exit. It's not a conversation that businesses should have. So this should be there, rolled out for everyone. That's number one.
22:08Hala Taha:For every single platform that we're using or just email. Excellent point. It is meant to be for every single platform. However, with platforms now, as you log in, Hala, you notice that it tells you, use your Gmail to use the same credit. So this is called single sign on, which is essentially you've already logged into your email. Your email is trusted. So we use that as a trusted token to get into apps. So that's perfectly fine. You're still considered as someone who used that. As long as the app is not asking you for username and password and you're just entering and getting in. If it's asking you to use the email that you've already logged in, this is the same thing.
Read the full transcript
22:48So single sign-on have made that a lot easier. So instead of having an authenticator app for everything, some of them will use your email. However, like even for me, my authenticator app is really large. So it happens. I have it with everything unless I can reuse my email, which is fine. It's just to get us out of just username and password because if the hacker has the username and password, it's game over. So we just make it a lot harder. The second one, which is also related to credentials, is a password manager. So having a password manager is really, really important. No matter how complicated we make our passwords, the human tendency is for us to reuse the password everywhere.
23:31And that's extremely dangerous because your company may be secure, not hacked, but the local cinema might get hacked. And guess what? People use their work email and work password to log into the cinema. So hackers usually, when we do the reconnaissance step, when we try to collect information, we actually see if your password is out there. It doesn't matter if someone has the same name. We try to first use that and see if we can get in. So a password manager, really essential as a business, have some sort of enterprise solution with these passwords where you have a complex password everywhere.
24:04And they're really convenient because you can have it as part of your browser. So you're literally just copying the password that you want to use. This is the second one. The third one, if we just narrow it down to three, is our key critical assets. We need to understand that could be customer information. It could be intellectual property. For example, you're on a podcast. I'm sure you have, let's say, a method to make an amazing podcast. So that's intellectual property. Let's say it's in a Word document. I would restrict access to that. And that even includes employees. Make it on a need-to-know basis.
24:41If someone needs to access it, we ask why. You get a time-restricted access, but that's it. It shouldn't be free access to everyone. And that could get more complicated. Like I worked with a beverages organization here in Australia, and some of their intellectual property was recipes for their drinks. And those recipes needed to be in a secure vault with encryption and with really secure passwords. But also once you log in and get access to that, you shouldn't have that login indefinitely. It should be time restricted. So those would be the three things. And if you allow me a bonus one, like I said.
25:17Hala Taha:Yeah, I was going to say, what's the four and five? Because clearly I can tell it's not just three things we need to worry about. The fourth one is similar to it's just get a professional opinion. For example, small businesses, when they draft a contract, they get legal advice, right? So you get someone to review it, a solicitor. Likewise, with cybersecurity, it doesn't have to be something massive. Get a small company, preferably something local where you can reach out to them if things go bad and say, I just like guys, a couple of hours, whatever,$2 ,000 or could be less, could be more. Check, make sure we're doing everything right.
25:52Give us a recommendation. And sometimes all they do is just check that you're doing everything. You may miss something. So they just give you professional advice. You know what? You're doing 99%. That's perfectly fine. And as the business grow, that sort of consultation or that assessment can grow with you. If you have a software application, you're releasing to the market, obviously that needs more scrutiny. but if someone is just, let's say, an Instagram content creator and they just share advice, they may not need that. I hope that gives small business owners a think-to-work towards.
26:23Hala Taha:It does. And I think because one of the most important things, like you said, is password safety. And there's some really, I know Bitdefender, I believe, has like a password feature that you can get and it's really cost-effective. But you mentioned this thing, this concept of least privilege. And I'd love to understand, like, what is this concept of least privilege? Help break it down for the people that aren't in cybersecurity. Yeah, the concept of least privileges or least privilege falls under the umbrella of what we refer to as identity and access management. It really is, you have a resource that could be an application.
27:05It could be intellectual property. You want to restrict access to that and make it so that the individual or the system or the software that have access to that, they just have access to the minimum amount of resource required for them to do their job with a time restriction. For example, we go back to, let's say, a customer database. You have a customer database. You have all your clients' details. And let's say you have a marketing officer. marketing officer needs to run a campaign for some of those individuals. So what I do is the marketing officer will only get access to that database for like 30 minutes.
27:46So they get a temporary password and they will only get access to those individuals and then the access will get revoked. This reduces the impact of a cyber attack. For example, if two weeks later this marketing officer gets hacked, well, the hacker wouldn't have access because the access has been revoked. And you mentioned Bitdefender. They have their enterprise suite solution. So they will have that password manager where you can provide a temporary password access. So it can definitely assist with that. But that's more or less the principle of least privilege. We always assume that for cybersecurity, it needs to be this complex, expensive piece of technology.
28:22But no, it's really people, process and technology. So we start with the process. We just define this is how we access things from now on. and then we enforce it with technology if possible. If not, we can even do it manual.
28:34Hala Taha:When it comes to customer data, like for example, my business, we don't collect that much data. We have everyone's email, but that's pretty much it. So is that really sensitive customer data or does it get more sensitive when you're collecting people's addresses and their social security and that kind of stuff? So it's like what customer data is the most desirable? Yeah, this is where there is a fine line between cybersecurity and the legal profession. Because here we're going into the territory of privacy, or some people say privacy, depends on how you pronounce it. But this is where we sort of even sometimes consult with a legal professional or a solicitor.
29:14Email address on its own, it's not really what we refer to as PII or privately identifiable information. It really is not. why privately identifiable information is something that can uniquely identify you. This would be your full name, home address, date of birth, but also things we don't think about, such as sexual orientation, political views. These things can be used against you to target you. And within that, there comes a whole lot of laws and regulations. A simple one that many people don't know is your business is based in the United States, so you're in the US. However, if some of your customers are EU citizens, so they're Europeans and their country is part of the EU citizens and they sort of trade with you, you actually need to comply with a standard called the GDPR, which is the privacy standards for European citizens.
30:09So you need to do certain activities to make sure that you're not breaking their privacy laws. Even though you're not really a European Union organization. Likewise, there is the California Privacy Act and there is the China Act. So there is all of these things. And this is where, as cybersecurity professionals, we provide advice, but then we consult with a solicitor. Sometimes it could be just, just please review this, make sure our policy is up to scratch. So as far as emails, I would treat it with absolute care because like I said, it may not be a huge legal liability, but it's very attractive.
30:48And people on the dark web, they purchase email addresses. They use it for spam campaigns. They use it to scam people. It's a very attractive thing. And even, I'm not sure if you have an interest in, say, paid ads, email addresses are really attractive to you for paid ads. So there is commercial value for them. And as a result, we encrypt them. We make sure that our newsletter provider is doing their due diligence when it comes to security, which the majority of the big ones are.
31:16Hala Taha:So helpful. You are just like a wealth of information. So for the entrepreneurs tuning in who still don't feel like there is much of a risk with cybersecurity or still aren't scared enough, talk to us about what could go wrong, like reputation-wise, revenue-wise. You mentioned earlier that sometimes cyber attacks can be so bad that the business actually has to shut down. I'd love to hear some examples of the way that these types of attacks can actually impact businesses? Yeah, we tread the fine line here, Hala, of being an alarmist versus just encouraging individuals and entrepreneurs to really do their due diligence and just do what needs to be done.
31:59When it comes to security, it can definitely be career-ending in the sense. The biggest one we've just alluded to, which is breaking privacy laws. There are hefty fines. So the European Union is really strict with fines when it comes to the privacy of their citizens. So a company in the US that's providing services globally, and somehow they get hacked and European citizens get their data out there, there might be a big fine and it can be in the seven figures and that can have huge direct financial impact. The other one is, let's say you have an application and subscribers and that application gets hacked.
32:38Now what? Subscribers are paying, they need their money back, and you really don't know what to do. Your revenue stopped. So all of these things can and do have significant financial impacts, which is a good segue to also make sure you have the cyber insurance or talk to your insurance organization and make sure that insurance against cyber attacks is there. It's a sort of controversial topic. It may or may not help, but it's best to have it than not to have it. So those are things that are important.
33:10Hala Taha:I've never heard of cybersecurity insurance. Nobody talks about this stuff. Cybersecurity insurance? Yes, I think it really is important. And look, the good news is you may already have it as an example. So if you have insurance for your business, depends on your provider, you can talk to them and say, yes, cyber attacks are included under that. And within that, there is a threshold and there is a limit. However, I've had mixed experiences with cyber insurance. But to summarize, it's better to have it than not to have it. And the good insurance providers, usually it's there in the fine print. So it's worthwhile just checking that it's already there.
33:51The other thing is also, like I said, if the organization or the business, like you had a consultation with a cybersecurity company that's preferably local also, So if things go bad, you have them on speed dial. You can call them in and get them in. So having that relationship also is really helpful. And they can also give you an advice when it comes to cyber insurance as well. So these things are helpful. But when it comes to just things going wrong for small businesses, Hala, like I said, it does go a bit more sinister. And there are things that most of us don't hear about because it's sort of bad news.
34:25And with really bad news, we don't want to hear about it for the most part. But there are cases of extortion. There are cases, and this is really, really common. So as a small business owner, someone could target one of your employees and you're kind of responsible for them because your business got hacked and it's really complicated. And the implications are sometimes your employees could be the target or your customers could be the target. And as you mentioned earlier, it could also be your brand reputation and we call it brand equity. Well, if people signed up to your application, it's hot stuff.
34:57But the next day, everything is hacked and everyone is complaining. And that can be career ending, unfortunately.
35:04Hala Taha:So let's go back to the entrepreneur who has no budget. Now, you mentioned the three to four things that we should pay attention to. But what if I literally had just$1 ,000 to invest in cybersecurity? And let's say, I don't know, maybe this isn't just not enough. I guess$1 ,000 for the year? Or do we want to say$1 ,000 for the month? Like, what is the bare minimum that we can be spending on cybersecurity? Let's say we just have$1 ,000. Let's just say the business has just started. And look, there is good news here, is that it's not always like that amount of money. I think as humans, when we see a problem, like I'm going to throw money at the problem and make it disappear.
35:46It doesn't always work that way, especially with entrepreneurship. entrepreneurship, the good news is a lot of the services that we use Hela are really built in a solid way. So let's say if someone is using all their email and everything is from Google, for example, using the G Suite, that is an inherently really secure platform if it's used properly. So if I just have$1 ,000 and which tells me I'm early in business, I'm an, let's say, content creator, or I have a small agency. This also, I will guess that we're not building an email system from scratch. We're not building, we're just using popular services, whether it's from Google, Microsoft, et cetera, et cetera.
36:26This can be good news. I would honestly get that thousand dollars. And like I said, reach out to a local trusted company and say, hey, this is our budget. Can you just give us advice? What can we do? And they can literally just have one hour, look at your stuff and just tell you, you know what, you're doing everything right. Maybe do this one thing that's, you know, will give you 80 % of the value. So I would, yeah, I would get a professional opinion, like similar to, I think, the example of getting legal advice. You may not have the budget to hire a lawyer that works full time, but all you need is someone to review employment contracts.
37:00That$1 ,000 can do it, may not do it all the time, but it's better than doing what a lot of businesses do now, which is chat GBT things and AI is telling you, yep, you're doing a great job. You're fantastic. You're the best thing since last thread. So I think just getting a human who know what they're doing is a lot better.
37:18Hala Taha:I didn't think you were going to go that way. I didn't think you were going to say, get like a consultation and have somebody tell you what you need to be doing. How about a solution like Bitdefender? It's super affordable. I just went on their website and it's like less than 200 bucks a month to get all these different tools. it'll like scan your Slack and or like your messages for anything that looks like phishing your emails. It will send warnings if it looks suspicious. So I feel like that's also like just a great layer to be adding on. A hundred percent. And like I said, that could be also the outcome of that consultation.
37:54They said, hey, you're doing everything right now. You're ready for an enterprise solution, which like the one you mentioned from Bitdefender. And the good news is these things, They weren't available for us a few years ago. So we are living in a good time where a company like Bitdefender have something targeted for the enterprise, small businesses to medium-sized businesses where, yes, they do scan your email. So you get rid of the spam headaches. They offer you some kind of password manager and monitoring. It's always better to have these things in place. it also like from a I hate to go that way but from a legal perspective if you know things go south it's also proof that as a founder or as a business owner you're doing your due diligence they can't say well you've done everything but you still got hacked that can still happen even massive organizations but in this case you you will be a victim of criminals who really know what they're doing they're you know criminals do criminal things and sometimes we're just victims of that But that's a different story than someone who, you know, they've done nothing.
38:57There's a really famous story on the news of those company that they created a dating app for women to protect women's safety. But then turned out that that app, because it needed to verify women, they took their passport details and all their information. Turned out this app was via coded with zero security. It got hacked and it put women's safety and danger. Oh my gosh. But that was an example of an organization that didn't do their due diligence. Whereas a small organization, like we said, okay, they've got the consultation, they've got the defender enterprise security, they're doing stuff where you do what you can, right?
39:35It's like having a building, you have your fire exits, you have everything. Sure, disasters can happen, but you've done what you can do with what you have.
39:43Hala Taha:You've described cybersecurity as defense in depth. I'd love for you to walk us through what that actually looks like for a normal small business. How can we practice that? Yeah, defense in-depth is a concept that surprisingly, even cybersecurity professionals can and frequently do get wrong. Defense in-depth is, in a nutshell, having more than one layer of defense stacked one on top of the other. So if one layer of defense fails, the other one can sustain. So it just makes it a lot harder, a lot more expensive to get to what we call the crown jewel or the important asset. I'll walk you through an example.
40:23Let's say you have your customer database. That's the most important thing that we have. We want to protect that. And then we have our attacker. And the first thing they do, they send a phishing email. So the phishing email comes, but you have your anti-spam filter. So the spam filter blocked that. So that's layer one of defense. So you didn't even see the email, that attack failed. Now, let's say a more sophisticated attacker, they crafted their email in such a way that it even passed that spam filter and it went into your inbox. So you looked at it and you said, well, you know what? This looks like spam, sorry, report spam.
40:57So the second layer of defense here was your awareness. So that's another strong layer of defense, right? Let's say they were, you know, the email came from a trusted supplier. So they hacked the supplier. They came to you, so like, oh, this is a legitimate email. I need to do something. You click on that link But when you click on that link, well, your anti-malware solution, your endpoint security system blocked it from being executed. So that's another layer. So it failed here. And that can go on for longer. But you get the concept, right? So we have multiple layers of security. In the late 90s and even up to 2005, 2010, there were organizations that didn't have firewalls, so they didn't have nothing.
41:42So the fact that we put one layer was a huge thing. But nowadays, you'll find these layers work in tandem. This, and it's controversial, I keep saying defense in depth because when it comes to marketing, the marketing of cybersecurity, people say human is the weakest link. I can have all the defenses, but if a human makes a mistake and click on something, it's game over. Well, it's not. As we explained earlier, there are multiple layers of defense. And I say that in defense of the human, in defense of the employee that's overworked, that clicked on something. Sorry, if someone clicked on something and it's game over, then your security were fundamentally wrong.
42:19So, yes, the way cybersecurity is approached nowadays, how it should be, multiple layers of defenses.
42:26Hala Taha:Let's move on to AI because I feel like AI is such a hot topic in cybersecurity. How has AI changed the landscape? What is new now that AI is here? Yeah, everyone's topic. And I've been labeled sort of anti-AI, which is not true. AI has definitely made cybersecurity professionals a lot busier because every business now have an AI and they call us and say, hey, is this okay? Is this not okay? And then we need to go and look. Look, it definitely has changed things and it's here to stay. But also it's not the sort of doom and gloom and the movie Hollywood things that we read on the news of these AIs escaping and hacking things.
43:08This is just marketing. Look, the truth is always a bit more nuanced. AI, I mean, the most obvious one that we all need to be careful and be aware of is the deep fakes. So deep fakes is huge, huge problems. And I know we talk about entrepreneurs and small businesses, but even for children and in schools, it's been an absolute nightmare and law enforcement deals with that all the time. So deep fakes, faking voice, faking video is something we need to be really careful of. But even as I said earlier, I can really create a website really quickly that looks exactly like a replica of a real one. Now, that wasn't overly difficult before AI, but now it's even faster, if that makes sense.
43:51So in the hands of a skilled hacker, AI can make certain aspects faster. Now, is AI this really advanced thing that's going to go and hack things? That's not true. And the big AI companies have actually sort of safeguards against making AI do these things. There are ways around it, but let's say if someone is completely unskilled and they're trying to do something, it's just not happening. So that's one aspect of it. The second aspect, which is what keeps us busy, is businesses are really quick to sort of want to use AI. And this is where things get a bit more complicated because when we say AI, so what are we really using?
44:30Are we just prompting chat GPT or are we giving AI access to everything and making it talk to customers and do finance for us? or are we even not even using AI, but we have the SaaS service or this product and then all of a sudden this product on their website says we're AI enabled or AI powered. Well, what does that mean? Do you feed our information to your AI? Is it going to the AI company, which is really a private company if you think about it. So all these things are making life a bit more interesting for cybersecurity professionals and small business owners. So we want to use AI. We want to be on top of the new technology.
45:09But we also need to stop and think, what is it that we're using AI for? What does the AI have access to? And more importantly, where's my data going? Is it going to a private company? Why do I trust that private company? This private company could get hacked or they could do something like sell my data somewhere. Big tech companies have done that. And we love to see news. And this big tech company got sued for selling election information. Well, they don't care. the hundreds of millions of dollars find that they pay. This is just, you know, one week's earnings. So these things I think we need to keep in mind when we use something like AI, just why we use it and how we're using it is fundamental.
45:49Hala Taha:Yeah, are we getting to a point where we literally just can't trust anybody's face or voice digitally? Unfortunately, yes. It happened to me. I thought I was this great AI detector up until someone, I'm in Melbourne, Australia. and yeah, I thought I was like this, you know, a great video guy that I know I can detect it. And one of my fellow YouTubers, he visited me in Australia and he was just showing me what he does. I'm like, oh, this actually was AI. So what he does, he record himself talking. And then for his Instagrams, it's him, but it's really an AI of him that looks exactly, I couldn't tell.
46:25Nobody could tell up until he pointed it out. It looks like him talking. It's his voice, but the video is entirely fabricated and it looked real. And with the short-form videos, because the resolution is low, I couldn't tell. Like a few months ago, AI would give you a few more fingers or things will be obvious. Not anymore. And to the human eye, my eye at least, it's not always detectable. So absolutely. And strangely enough, I got an email from Microsoft saying yesterday that they want to rely on pass keys, which is a more secure way of authentication. So no longer, you know, the voice authentication and all of these things are no longer secure.
47:01So absolutely seeing a video and usually women get targeted like with explicit, like someone leaks, quote unquote, leaks explicit videos of an individual. And well, that video is completely deep fake and it has been happening. And yeah, it's something I actually had to deal with, with law enforcement, where they always target the vulnerable. They always target the young. And it is a problem. and we need some kind of a strict regulation on, you know, putting someone's face on a body that doesn't belong to them or do these things.
47:34Hala Taha:It's crazy because as a creator, you actually see a lot of opportunity in this. Like my team is actually creating an AI avatar for me. I just did like the whole turning my head a million ways and walking towards the camera and turning my body every which way so that they can create an AI avatar for me. is there risk in having an AI avatar that you actually create for yourself and for your content? Look, this is a difficult thing to sort of answer and guess because, like, let's think about it. Like, what could go wrong? Because you and I are content creators. So if someone wants to impersonate me, there is thousands of footage of me speaking.
48:18It's really straightforward and and exactly for yourself as well. And we could say, well, it's illegal. Well, the hacker is doing something illegal. I don't think they're going to stop and say, oh, hold a second. I'm not going to do that because it's illegal. They'll still do it. So for me, I don't think there's any risk from a contact tree. We're already out there. We are out there. And you know, I always say, I tell people, if someone wants to hack me, you know what, just go and hack me. My phone is full of food pictures. And so like, it's completely useless. But like I'm aware, as I said, my stuff could be used to harm someone else.
48:52I don't think there is a risk from a content creation perspective, which is not really a cybersecurity thing for me. I actually went the complete opposite of that. I do everything physical and analog now. Even a photo has to be a photographer. I'm strictly not a fan of AI. However, it's a technology. It's a new thing. There is a viral Mr. Beast dance video that people thought it was AI, but then it was real. But it is the world we live in. And as an entrepreneur, there's no reason why you shouldn't jump onto these technologies. Like we said in the conversation, as long as you know your critical assets or private information or stuff or financial information, don't feed that into AI.
49:30You should be fine. If it's avatar, if it's fun stuff, why not?
49:34Hala Taha:I think one of the new things coming up in AI and cybersecurity is for a couple of years, AI was mostly like chatting, chatting to ChatGPT, getting help writing emails. But now we've got AI agents that are jumping from tools to tools that are kind of like AI digital employees. How worried do we have to be about AI agents and their ability to hack our companies or their cybersecurity threats? AI, I mean, agentic AI or AI agent is exactly what you described, where you have the AI, but instead of it just being a prompt or a chatbot, you're actually giving it access to stuff and it can do things for you.
50:16For example, you can program the AI to send an email from your email or give it access to your calendar. Or in some instances, it can be a chatbot on your website. AI agent is something that needs to be treated with absolute care. It shouldn't be just because it exists doesn't mean we need to use it. There are many issues with AI agents. The first one is, the obvious one is access. Well, you're giving a piece of software access to things. So we need to assess that access. We'll go back to the principle of least privilege. Does the AI really need access to everything in my email? Or does it need access to a copy of certain emails?
50:51Does it need access to calendars of everyone? Or perhaps you can create a dummy calendar for certain things and that can access that. So the first one is, you know, don't be too generous with access. Treat it like, you know, it's just another piece of software. I don't want to say it's another employee. It's an employee or it's just really a software. So we don't really give software access to everything just because we can. I think that the craze or the hysteria that we face now is, oh, AI can do this. Therefore, I need to use it. No. As a business, do you really need that? And if not, then why?
51:24And that could be also costly in terms of tokens. And we've heard lots of stories of companies paying so much on AI tokens. A famous one of the fan companies, they laid off so many employees just so they can afford paying for the tokens. And it's not always a smart business decision. This is one. And the most important one as well is, well, accountability. So as a founder, just because the AI is doing something doesn't mean the AI is accountable for it. I'm still accountable. So if I get the AI to review my legal contract, great. The review may be accurate or may not be accurate. Who's accountable?
52:00If I get into legal trouble, I can't say, oh, well, oops, AI did it. No, it's still me. So we need to really stop and think, well, I'm still accountable. AI is just software. It's doing something. I'm still accountable. Just like a normal employee. Yes, the employee can make a mistake or so, but ultimately the accountability falls on leadership or on the CEO or on the board of directors. So these are the things we need to really be careful about.
52:25Hala Taha:So I do think one of the things that we need to be worried about with our employees and AI is actually, we might be rolling out specific company AI tools, but because AI is kind of popping up everywhere, employees are probably using all these like disparate AI tools or like whatever tool they think is fun. And they're probably using their company computer and thinking it's harmless. Is there a risk in people just using like not approved AI tools? Absolutely. And this is not a new problem. We used to call, we still call this shadow IT or unsanctioned software, which is really what AI is, what you just described.
53:04We had this problem even before AI would have, let's say, the marketing team. They just found this online tool and they start using it. They didn't tell everyone and they put customer data in it without sort of the cybersecurity team doing an assessment and saying, hey, this is approved. We can monitor. We can do that. Same thing with AI. But if we have an employee opening their own personal chat GPT, putting company information in it, yeah, we didn't really approve that. So they did something that the business didn't approve of. It is really hard. And it's something that we need to, like I said, do our due diligence.
53:39We need to have clear policies that say, do not put company information into AI tools. Also, the other thing I saw, even in big tech companies where they're really skilled, so they have built different agents to do different tasks, they always have someone sort of verifying and validating the output of AI. So really skilled programmers, they do this cloud code, the AI is producing code. Before it goes to production, it needs to be reviewed. It needs to be tested by a vetted senior programmer. So this way we have safeguards against what goes into AI, but what comes out of AI. That is really essential.
54:17There is the other thing, of course, like I said, in terms of privacy and stuff, there is a setting in all these AI chatbots that says something along the lines of don't use my data to train AI. I think we should all toggle that. And this way, allegedly our data doesn't go in there. So that's something that we need to do. But there has been instances, a really famous one, early days, ChatGPT. the source code. Some Samsung employees really leaked the source code, not leaked, they just posted it to ChatGPT. And it's a huge problem because ChatGPT will use it to learn, but that source code is massively, massively pricey and important intellectual property that should not have gone there.
54:57So these things happened. Yeah. So we do need safeguards against who uses AI, what do we use it for? And exactly like any other piece of software, an employee shouldn't be just using random softwares and use it for business purposes on business laptop.
55:12Hala Taha:If we have like a company version of ChatGPT and Claude, is it safe to upload certain financial information or code or whatever it is? Is it safe to upload those types of things or is it still not safe? So when we say a company version, there is like a RAG, which is a local AI that you can have absolutely where the data is not going elsewhere. And also So it depends on the solution that you use. There are, again, safeguards that just doesn't get your data leaving the organization. And then the word safe, we need to also really put it under the microscope. Safe in the sense, okay, so the data is not leaving, but is it safe from mistakes?
55:53Hala Taha:It can still get hacked. Yeah. Sure. But also, is it safe from mistakes? If I'm doing financial data and I get the AI to be my finance officer, I'm still accountable. when a mistake happens. And this is the problem, the inherent problem with AI, Hala, is it makes mistakes. Humans make mistakes, but they're accountable. AI, the software, it will make mistakes. And that's a problem. So if it's doing financial data, financial analysis for me, I need to validate that. So if I can validate that, no worries. It can really save time. If I have a finance officer that uses AI in some sort of way, but then they review everything, that is fine.
56:29It's just us validating and verifying that things are fine. Also, like I said, need to know basis or least privileges, meaning I'll use AI just because AI can do certain things and I'll give it a certain amount of data. It doesn't mean I need to give them access to everything. Just give it access to what needs to happen and then revoke that access.
56:50Hala Taha:So I'd like to talk about, aside from the technology and AI, the people who actually have keys to your business. Like a lot of us think that the only way that our business is vulnerable is through a stranger. A hacker is going to come hack our company. But it turns out that our employees can actually be a really big risk, especially employees, maybe disgruntled employees who have left the business. Is that right? Absolutely. The technical name we use for it is insider threat. Although some people don't like the word insider threats, like humans aren't threat. It could be exactly what you said.
57:25So one scenario is a disgruntled employee. They know all the business secrets, everything, and they leave. And six months later, they decide, hold on a second. I'm not happy with that business. Let's do some damage. And the way we reduce the attack surface, we reduce the impact is back to basics. They shouldn't have access to everything. So when they hold the key to the business, well, they need to hold the key to certain aspect that they need for their job. And this way, if they do damage, well, that damage is restricted. That's one. to a common mistake that happens even with large businesses.
57:58In fact, probably more with large businesses than smaller ones is when someone leaves, we call it the offboarding process, they don't take all of their access out. So they may still have access to certain applications or certain things that they log into. So that's a problem. So we need to have a process of just like we onboard employees, we need to know how we offboard them. And that includes revoking access. The third one is also in our contract legally. We need to say that, you know, if you leave, please don't go on social media and just spell out all our secrets. That's illegal, but having it in the contract doesn't hurt.
58:32There's been many instances of that happening. A really popular one, a big tech Australian organization that has laid off people and they laid off one of their very senior software engineers. And the next day he creates, I think, one hour YouTube video explaining everything he's done for them. Everything he's built. It's online. It got millions of views. So yeah, that's really valuable information that the employees build that. And you know how awkward it is for an organization to legally go after someone. So these things we need to be careful of. The insider threat, there's other aspect that we forget when it comes to insider threat is the employees are humans.
59:15They make mistakes. So I, even early in my career, as an example, I made a mistake early, early in my career. As I was working faster and faster, I ended up deleting stuff that were really important files. And I did that by mistake. And I had to go find backups and restore backups. So mistakes can happen. It could be a really genuine unintended mistake, which again goes back to why did I even have access to that stuff? Why was I able to delete without someone looking over my shoulder, without a chain of approvals? All of these things that sometimes we may think of as tedious or unnecessary. We want to be fast.
59:49We want to be lean. Well, there is a cost that comes with that.
59:52Hala Taha:This has been such a valuable session. Like, I feel like I've got to like do so much work and make this like a core initiative for my business. If you're a hacker, please leave me alone. But I want to play a game with you. It's called find the back door. So I want you to find the back door. I want you to break it down and then close the back door. So basically, how can somebody hack this company? I'll give you a scenario. And then how do we actually fix that? What is the solution to that? Okay, so the first one is the media company. The company works with freelancers around the world. Some use personal laptops and personal email accounts to access company files.
1:00:39Hala Taha:Where's the backdoor? There are about three backdoors in here. The first one is offshore employees. you need to vet those employees, especially if they have access. So have some kind of vetting process. And that could be something as simple as use an agency that does the vetting for you. So make sure that you're not hiring criminals. That's as a basic sanity check. The second one, of course, if you can't give them laptops, then restrict what they can access. Absolutely restrict what they can access. Don't give them what we call as a right. So read access may be less damaging, but write access, which gives you the ability to delete stuff that should absolutely be restricted on a need to know basis with strict approval processes.
1:01:30The fourth one is a personal email address. This is a huge no-no because when they leave the company, they own the data that's on their email. So if there's anything sensitive, they'll take it with them. And that's precisely why organizations have emails on the company domain, because the company owns that. As soon as they're using personal emails, well, they own the data. So you're really handing over their data and you're as vulnerable as any one of them. One of them could be criminal, one of them could be hacked, or you just really don't know. So you're overly exposed. If you want to use offshore or employees or contractors, really restrict them to a very specific task and have in mind that if that person gets compromised, what's the impact?
1:02:15And do I accept the impact and consequences? If no, then find alternatives.
1:02:19Hala Taha:The fast finance team, this is the next scenario. The founder and the finance team approve urgent payment requests through Slack because it's faster and more convenient? Yep. So anything that we do fast, it just means we're going to make more mistakes. So with speed, the compromise is more mistakes. Yeah, a big really red flag here is approving things over Slack. It shouldn't happen this way. We need to have a chain of approval that's really clear because the strong use case is if one of your employees gets hacked and their account gets hacked. So the hacker is using your employee's account and, well, everyone has access to Slack.
1:02:58They're going to ask you to approve something. And fast means you're just going to approve it. So that's a call for disaster. You will lose money. So that's what you're compromising. So you need to have the fix for that is have a proper approval process. And that approval process may just mean it will take an extra five minutes. It's not really war on peace. It's literally just a proper approval process that will save you a lot of headache and will save you time in the long run.
1:03:26Hala Taha:Yeah, potentially a lot of money. Exactly. Okay. The last scenario. The SaaS heavy e-commerce brand. The company uses dozens of third-party applications connected to customer and payment information. That is, everything is wrong with this. This is a dangerous one. Surprisingly very common, Hala. Okay. The first one is when they use so many SaaS applications, but you need to know who owns that SaaS service because there has been cases where it's foreign government operating from a different country, having this amazing SaaS application that does amazing things and it's surprisingly cheap. Well, the purpose of the application was to collect information.
1:04:09So you need to really vet and know who you're dealing with. So the first thing is we call it supply chain management. Supply chain meaning your suppliers, in this case, your SaaS providers. Just make sure you know who you're doing business with instead of just randomly signing up for things because they are quote-unquote cheap and fast and they do their job. So because it's a legal liability, if you're leaking customer information to somewhere that shouldn't go, it's a huge problem. This is one. Two, again, know who you're dealing with. A small SaaS app, what if one of your providers get hacked and they have access to all your customers?
1:04:41So, and therefore, once you know who you're dealing with, the second one is manage access. Why do all of them have access to everything? Really common in the real world, sadly, but manage your access. Again, need to know basis, least privilege, all these really timeless principles, meaning you restrict access. I'm pretty sure that business, whatever it is, doesn't require everyone to have access to everything. The only reason why businesses usually do that, where they give everyone access to everything is just lazy. It's easier to take everything on. And that's a call for disaster. So these are the two fixes.
1:05:16Manage your supplier is number one. Number two, manage your access.
1:05:20Hala Taha:I love those principles. I'm sure everybody tuning in is learning so much and getting so many ideas of like where they need to start first. Let's say, unfortunately, our company gets hacked. What is something that we shouldn't do? We get hacked. Somebody just stole a bunch of money from our bank accounts. What shouldn't we do in that moment? Really difficult because the first reaction that happened to all of us, myself included, we panic. and to tell someone not to panic, it's unreasonable. So I'd say panic, but don't act. It's just like, you know, when I'm sure as a business owner and even as someone on the internet, sometimes you get angry and the advice is don't reply to an email when you're angry or don't take action.
1:06:05Just sit back. It happened. It's a problem. We're going to deal with it in a systematic way. So I'd say the first thing is don't interact with the hackers, don't reply to emails, leave everything as it is. And in some instances, I'd say, don't actually close the laptop or don't leave everything as it is, reach out to an expert right away. And there is levels to that. So reach out to law enforcement. It's a sort of contested thing to do because usually law enforcement are sort of overworked, underfunded. They may not always be able to help, but you'd be surprised. Law enforcement can help. Having that consulting company, sort of you have them on speed dial, you have their number, Get an expert right away to do it.
1:06:49That's the most important thing. But the biggest one is what we said earlier. Do not interact with the hackers because the first thing they will do is try to get more access. So they'll say, oh, sorry, mistake. I'll just do this one more thing because they're trying to get as much foothold as possible. So don't interact with them. They're really skilled at getting you to do what they want you to do. And they're going to use the fact that you're panicking to their advantage. So yeah, disconnect, completely disconnect. Get an expert to deal with it right away. Like don't take actions. And the worst thing that businesses do is they'll have like an IT support person who's really, they don't have the expertise.
1:07:27I'm like, okay, go deal with it. And that person ends up making things a lot worse. So I think this is the big no-no. Get an expert to deal with it right away.
1:07:37Hala Taha:Such great advice. Abed, this has been such an awesome interview. Before we go, I do want to talk to you about your entrepreneurship journey, your business. So you actually started creating content and you've created a business out of educating people. And it all started because people would just ask you questions, your colleagues would ask you questions, and you just wanted a way to not have to answer the same thing over and over again. So just talk to us about your story, how you ended up growing this content business, how you make money today, and hopefully you can inspire somebody else who's a thought leader in their space to become a content creator and start their own business too.
1:08:14Yeah, absolutely. I mean, it's funny, I still don't think of myself as a business or even a content creator. But the story started, it was during the lockdowns. And I was working at PwC, which is a consulting firm. And as a senior manager, part of our job is to coach consultants and senior consultants. So I'd have these one-on-one calls with them. And I really don't like Zoom or online meetings. So I prefer it to be in person. And I remember one day I had like three or four back-to-back calls with junior consultants and they were asking exactly the same question over and over. So I got this idea where I'm like, you know what, I'm just going to film myself answering those questions and I'm just going to send it to them so they watch it.
1:08:58And I just put it on YouTube as somewhere to upload the video on, like not as a sort of discoverability platform. So I thought no one would find it. And I thought it's like, I watch YouTube, but it didn't occur to me that the video that I'll put, strangers will watch it. So I send them, I told them before you do the meeting, just watch this video and then you can ask your questions. And I left it. And then I think months later or so, I saw there was comments and likes and there's strangers watching it. They're like, oh, well, let's just answer more questions, I guess. And I started answering them.
1:09:30And it wasn't like it wasn't sort of a business or I had no idea that YouTube pays me your money. And while it's a small amount, but I didn't know that was a thing. And when I got the first paycheck from YouTube, it was like 50 bucks. I'm like, is that a mistake? Or like, how? I just didn't put two and two together. It's not the universe that I'm a part of. I had no idea. So that was YouTube. But then I started getting messages from people and individuals like from all over the world. And the first one was like I could see in the picture was a dad and kids. And it's like commenting on my videos.
1:10:03He was somewhere in an African country. And then it's like, actually, I got a job. And for him, a job is they changed their life. So I got a full-time job, completely new field, highly paid so it improved their life. And then it started to spiral. I started getting these success stories, either in a comment, sometimes in an email saying, I actually followed your advice. I got a job, it changed my life. Thank you so much. And the more I posted, the more I get nowadays, every time I look in my inbox, there's at least one message a day from someone somewhere in the world says, I actually followed your advice.
1:10:34which my advice is really just do these practical things, learn and apply yourself and you'll get a job. It will take time. It's challenging, but it's possible. So this really gave me the drive to continue. I felt that I was making a difference and I felt that I just felt responsible. I felt responsible that people watch my stuff. Now I need to give really the most accurate advice. I need to do what I can. Time management became really difficult. My job is really, really demanding as a consultant. but I enjoy it. And because I do it, I've been doing it for so long, like it doesn't require a lot of thinking from my end.
1:11:13So I was able to manage, but then I've always wanted to do consulting on my own. So I started a cybersecurity consulting company and I have long-term clients. So I'm active in the field. I do that. But at the same time, I create YouTube videos. I'm not very good at like creating a lot of content. So I'll create one video a month. Really, that's my average. So in 12 months, I'll have like 13, maybe 15 videos of YouTube. That's all I can do. Within my advice, because cybersecurity is a range of jobs. It's not just one job. There was one niche in cybersecurity called governance risk and compliance.
1:11:48At the time, I didn't feel comfortable recommending what was in the market. So I thought, I'm going to take three months and just try to create something. It took me a year and a half. And I created my certification, got it accredited. And I just put it out there. And thank God it's been really successful in the sense people started recommending.
1:12:07Hala Taha:And that's the GRC mastery, right? Yeah, yeah. And people started recommending it to each other through word of mouth. So every time I go to a conference and someone says, hey, someone did it in the team, then all of us did it in the team. So it became bad. So really my time now is between consulting. I help usually large organizations. I've got long-term relationships with them. I do have some consultants that work under me. And yeah, the occasional YouTube video where I talk about what's happening in cybersecurity and how to land a job. You got a full plate of clients, you have a team, and then you're able to create content and give back.
1:12:44Hala Taha:I mean, that's an incredible career that you have. So, okay, let's bring it back to cybersecurity and wrap this up. So if you're a young and profiter listening right now, what are the three things that we should do tomorrow morning to protect our company? Number one, two-factor authentication. Use your authenticator app or a passkey. This is a non-negotiable, no exception. This includes all of your employees. Number two, a password manager. I know it will take you some time to get used to using a password manager. I can promise you it's a lot more convenient for you and your team to use a trusted password manager.
1:13:21It will save you time in the long run. It will save you so much headache. And number three is, we talked about it a lot, is manage your access. Just because someone works for you doesn't mean they need to have access to everything in your company. Provide this access, give them access only to the things they need and know more and have fun as an entrepreneur.
1:13:43Hala Taha:Amazing. Beautiful recap. Thank you so much, Aved, for spending time with us on Young and Profiting Podcast. Thanks for having me and thank you so much for your time. This has been an absolute pleasure. Big thanks to Bitdefender for sponsoring this episode and for keeping small businesses safe. Protect your team, your data, and your business from scams, ransomware, and phishing. Get 30 % off bitdefender.com slash profiting. That's bitdefender.com slash profiting. And if you enjoyed this episode and learned something valuable, we'd greatly appreciate a five-star review on Apple Podcasts or Spotify.
1:14:13Reviews help us reach more listeners and continue bringing you these conversations that educate,
1:14:18Hala Taha:inspire, and empower. You can also connect with me on Instagram, TikTok, or X at Yap with Hala, or find me on LinkedIn by searching Hala Taha. This is your host, Hala Taha, a.k.a. the Podcast Princess, signing off.
From the publisher
Entrepreneurs often assume hackers only target big companies, but small businesses can be easier targets than they realize. A weak password, compromised vendor, or poorly managed access point can expose customer data, disrupt revenue, and damage trust. In this episode, presented by Bitdefender, cybersecurity consultant, Abed Hamdan explains why your business might be an attractive target to hackers and how entrepreneurs can protect their business from today's cyber threats without needing a full-time security team.
In this episode, Hala and Abed will discuss:
(00:00) Introduction
(00:00) Why Small Businesses Attract Hackers
(07:55) How Hackers Target Small Businesses
(14:40) How Abed Entered the Cybersecurity World
(18:22) Non-Negotiable Cybersecurity Habits for Businesses
(28:57) How Cyberattacks Can Destroy a Business
(30:29) Cybersecurity Protection on a Small Budget
(32:41) Defense in Depth for Small Businesses
(40:30) AI, Deepfakes, and New Cyber Risks
(54:27) Insider Threats and Employee Access Risks
(57:42) Finding the Backdoor in Your Business
(1:03:04) What to Do After a Cyberattack
(1:05:17) From Cybersecurity Content to Entrepreneurship
Abed Hamdan is a cybersecurity consultant, content creator, and founder of GRC Mastery. He has more than two decades of experience helping organizations strengthen their security, manage risk, and navigate complex cyber threats. His expertise spans cyber defense, governance, risk and compliance (GRC), and security strategy. Known online as UnixGuy, Abed has built a global cybersecurity community of more than 600,000 followers by making complex security topics practical and accessible.
Sponsored By:
Keep your small business safe with Bitdefender Ultimate Small Business Security. Save 30% when you go to bitdefender.com/profiting
Resources Mentioned:
Bitdefender: bitdefender.com/profiting
Abed's Training Platform, GRC Mastery: grcmastery.com
Abed's YouTube: youtube.com/@UnixGuy/about
Abed's LinkedIn: au.linkedin.com/in/abedhamdan
Active Deals - youngandprofiting.com/deals
Key YAP Links
Reviews - ratethispodcast.com/yap
YouTube - youtube.com/c/YoungandProfiting
Newsletter - youngandprofiting.co/newsletter
LinkedIn - linkedin.com/in/htaha/
Instagram - instagram.com/yapwithhala/
Social + Podcast Services: yapmedia.com
Transcripts - youngandprofiting.com/episodes-new
Disclaimer: This episode is a paid partnership with Bitdefender. Sponsored content helps support our podcast and continue bringing valuable insights to our audience.
Entrepreneurship, Entrepreneurship Podcast, Business, Business Podcast, Self Improvement, Self-Improvement, Personal Development, Starting a Business, Strategy, Investing, Sales, Selling, Psychology, Productivity, Entrepreneurs, AI, Artificial Intelligence, Technology, Marketing, Negotiation, Money, Finance, Side Hustle, Startup, Mental Health, Career, Leadership, Mindset, Health, Growth Mindset, Passive Income, Online Business, Solopreneur, Networking




