Navigating Cyber Threats in the Digital Landscape with Clayton Riness Ep. 609

Ep. 60944 min2024-05-27Guest: Clayton Riness1,216 plays

Small businesses and marketers can reduce cyber risk by keeping plugins updated, avoiding SMS link clicks, minimizing stored data, and using configuration-based platforms like Shopify instead of heavily customized WordPress setups.

Cover art for Navigating Cyber Threats in the Digital Landscape with Clayton Riness Ep. 609
Key takeaways
updates alone will get you 80% of the way there because most people aren't

About this episode

Of Best SEO Podcast, join us for an enlightening conversation with cybersecurity expert Clayton Riness of 16 years as we navigate the complex landscape of cyber threats in digital marketing. Clayton sheds light on common risks like email and text phishing attacks, ransomware, card swipers, QR codes, and social engineering targeting individuals, marketers, and businesses offering practical preventive measures. We…

Questions this episode answers

What are the biggest cybersecurity risks for WordPress sites?

Outdated plugins are the top issue. WordPress is a frequent target because it is so prevalent, and unpatched plugins create easy crimes of opportunity. Beyond plugins, third-party libraries tied into those plugins can also be compromised, as seen with the Magecart incident where downstream dependencies were hacked.

Is Shopify safer than WooCommerce for small business e-commerce?

According to Clayton Riness, yes. Shopify operates like a walled garden where merchants configure rather than customize with custom code, which reduces complexity and uncertainty. Less complexity means fewer unknown security gaps compared to assembling multiple WordPress plugins that may not play well together.

How can small businesses protect sensitive HR and payroll data?

Riness recommends outsourcing HR data to a dedicated HRIS platform and keeping that data off internal SharePoint or email entirely. Businesses should also set a data retention policy and avoid keeping information longer than legally required, since excess retained data can create additional legal and security liability.

What should someone do to protect themselves from phishing and SMS scams?

Riness advises never clicking links in text messages and instead going directly to the known website. For emails, hover over links to inspect the actual URL before clicking. Use spam filters in Gmail or Office 365 as a first layer, and always log into a site directly if an alert seems suspicious rather than clicking the email link.

In their words

These are basically blasted out. You can get phishing attacks really from all sides, and it's pretty easy to build a profile on someone, right? If I'm really targeting you, I can probably find out where you went to school, where you went to high school, which high school mascot is, who you have relationships with.

Clayton Riness

if you can reduce your complexity, kind of de facto improving your security

Clayton Riness

the juiciest part of any penetration test or attack that we would do if we get into someone's iCloud, it's iCloud notes, right? Because what do they put in notes? They put passwords in things

Clayton Riness
Terms defined in this episode
Spear phishing
A targeted phishing attack where an attacker builds a detailed profile on a specific individual using public data, breach databases, and social media to craft a highly convincing and personalized malicious message.
Magecart
A cyber incident where a plugin used to track browsing behavior had its downstream third-party dependencies hacked, injecting malicious code into e-commerce sites without the site owners knowing.
Card skimmer
A physical device placed over ATM or payment card readers, sometimes 3D-printed, that captures card data when a card is swiped or inserted.
CISA
Part of the Department of Homeland Security, CISA is a government resource offering practical cybersecurity guidance for small businesses and non-technical users on relevant attack scenarios and protections.

Full transcript is being added.

Matthew Bertram, host of The Best SEO Podcast
Matthew Bertram
AI keynote speaker · Owner & CEO, EWR Digital · President, ModalPoint

Matthew Bertram is an AI keynote speaker, creator of DIG™ (Digital Information Governance), and owner and CEO of EWR Digital. He helps energy and industrial leaders win visibility in AI search (GEO and AEO), is President of ModalPoint and CMO of the Oil & Gas Global Network, hosts The Best SEO Podcast, and has authored eight books including LLM Visibility. More about Matthew Bertram.

Related episodes

The show explains it. EWR Digital does it.

The Best SEO Podcast breaks down SEO and AI search; EWR Digital, the agency behind the show, implements it for operators. Start with a free, no-pitch audit of where you stand in Google and in AI answers.

Get a free AI visibility audit