Ranking Locally: Your Guide to GMB & SEO (Unknown Secrets Revealed!) Ep. 580
Are you struggling to rank for local search terms? Have you ever wondered if creating separate local landing pages for various locations could be the…
Small businesses and marketers can reduce cyber risk by keeping plugins updated, avoiding SMS link clicks, minimizing stored data, and using configuration-based platforms like Shopify instead of heavily customized WordPress setups.
updates alone will get you 80% of the way there because most people aren't
Of Best SEO Podcast, join us for an enlightening conversation with cybersecurity expert Clayton Riness of 16 years as we navigate the complex landscape of cyber threats in digital marketing. Clayton sheds light on common risks like email and text phishing attacks, ransomware, card swipers, QR codes, and social engineering targeting individuals, marketers, and businesses offering practical preventive measures. We…
Outdated plugins are the top issue. WordPress is a frequent target because it is so prevalent, and unpatched plugins create easy crimes of opportunity. Beyond plugins, third-party libraries tied into those plugins can also be compromised, as seen with the Magecart incident where downstream dependencies were hacked.
According to Clayton Riness, yes. Shopify operates like a walled garden where merchants configure rather than customize with custom code, which reduces complexity and uncertainty. Less complexity means fewer unknown security gaps compared to assembling multiple WordPress plugins that may not play well together.
Riness recommends outsourcing HR data to a dedicated HRIS platform and keeping that data off internal SharePoint or email entirely. Businesses should also set a data retention policy and avoid keeping information longer than legally required, since excess retained data can create additional legal and security liability.
Riness advises never clicking links in text messages and instead going directly to the known website. For emails, hover over links to inspect the actual URL before clicking. Use spam filters in Gmail or Office 365 as a first layer, and always log into a site directly if an alert seems suspicious rather than clicking the email link.
These are basically blasted out. You can get phishing attacks really from all sides, and it's pretty easy to build a profile on someone, right? If I'm really targeting you, I can probably find out where you went to school, where you went to high school, which high school mascot is, who you have relationships with.
Clayton Riness
if you can reduce your complexity, kind of de facto improving your security
Clayton Riness
the juiciest part of any penetration test or attack that we would do if we get into someone's iCloud, it's iCloud notes, right? Because what do they put in notes? They put passwords in things
Clayton Riness
Howdy. Welcome back to another fun-filled episode of the Unknown Secrets of Internet Marketing. My name is Matt Bertram. Today, I have a special guest for you, Clayton Rines, 15-year cybersecurity expert. Clayton, how are you doing today? I'm doing well, Matt. Thank you for having me on. Well, you and I met, I think, mutual friends over the Christmas break, right? That's correct. Yeah. It's great to get to know you. So it's funny, you know, this year, really, I don't know if it's an election year or what, but cybersecurity, like, attacks and DLS attacks, and we have a hosting company, and there's just a lot of activity there. We've seen some, I think it's called zero-day, zero-day, like, things with e-commerce that we've had to turn over to the cybersecurity community. And, you know, I just thought it'd be good to have you on. We have a lot of web developers that listen to this. We usually touch on marketing, but I thought, you know, to bring you in would be valuable for people that listen to this podcast. Yeah, sounds good. Yeah, definitely. I would say tensions are certainly high going into election year, so there's a lot of activity out there happening. Yeah. Well, everybody that is listening, I am going to do a solo podcast next. I've been getting a lot of questions, technical questions related to SEO, and really, the format with guests hasn't been conducive to that. So thank you all for your questions. Keep sending them in. We'll get to it and answer them. Just know that the next podcast I do, I will focus on that. There's been a lot going on with some of these algorithm updates, but I thought it would be really important, Clayton, to have you on because of all the cybersecurity stuff that we're seeing. So tell us a little bit about yourself just to kind of set the table. Yeah. Currently, I'm principal consultant at a consulting firm called Tavora, and we do all cybersecurity consulting. I've been there for about 13 years, but
before that really cut my teeth in doing IT and cybersecurity work for private companies. But today, I really oversee our technical delivery practice areas that we have. That's all of the penetration testing, incident response, cloud security and security solution integration and advisory work that we do. So really see what's happening at our clients, our customers, emerging threats, and then actually testing and validating controls on a regular basis. That's something we do every day across really hundreds of clients every year. So get to see a good swath of what's working, what's not working, and help people really across all kinds of industries. Yeah. Well, I definitely want to get into WordPress. That's used by just a lot of businesses as well as marketers. But before that, phishing attacks, ransomware, social engineering, I'm seeing a lot of social engineering attacks through text message, click on this link, emails. You know, they're not just targeted at, you know, maybe like the elderly generation. I mean, they're very advanced. They're targeting me. They have, you know, different, I guess, our data is out there. Like, right, there's been so many cybersecurity attacks. All our data is out there. So they know stuff about you. I know one of the things that I do a lot is ask them for their email callback, like the main number, try not to never click on links, but maybe you could just speak to, in general, some of the common cybersecurity threats, like those phishing attacks, ransomware, social engineering, that sort of thing, and maybe some preventative measures. Yeah, sounds good. Those are really, you know, crimes of opportunity, right? So people think, well, I'm not a target. I don't have anything important, but your stuff's important to you. Your data is important to you. And you may be willing to pay money to retain interest in that information that you have, right? So these are basically blasted out. You can get phishing attacks really from all sides. And it's pretty easy to build a profile on someone, right? If I'm really targeting
you, I can probably find out where you went to school, where you went to high school, which high school mascot is, who you have relationships with. I mean, let's not forget there's data breach databases out there that have tons of information, right? The LinkedIn data breach from years ago still bears a lot of fruit because I can see all your relationships. I can see all of your passwords that you've used, right? I can get it, really get a sense for what you're all about. And there's automated ways that people go and just create crafted emails or spear phishing attacks, right? Against specific people. So phishing is broad, spear phishing is direct at you where I can build a profile against you, right? And really get something that looks and seems legit. Like I know your internet provider is, I know you're using Google, right? All these things can help me really craft something that's really interesting and compelling for you to get that click, right? And even initially, it's about, hey, can I get you to click? And if I get you to click, can you, will you, what are you going to do when this pop-up happens? And can I get your password? And where else are you using that password? Oh, I can tell where you work. Oh, they only have single factor, right? So you sort of unwind from a very innocuous sort of emailed into something very, very critical to you personally. Yeah, definitely. I mean, that's certainly not going away because again, cost is low to execute. So the attacks happen and later, let's see what happens, right? Even if they get a 2% click rate, that's 2% that they'll run with, right? And use against you. And then Clayton, there's a lot of like, as you look at like social media, certainly you know, when you said two-factor authentication and we, and I think we should cover that briefly, but I would tell you like, you know, there's been a lot of social media handles like a Twitter of
a politician or some kind of news that's going to be released. People hack into that and release it early is what I've seen recently with, well, the Bitcoin ETF, which had huge implications for people trading in the markets. I mean, they're like social media handles and what you could say and publish something that could be damaging. It's not just, you know, Viagra ads anymore, right? Like, or whatever. There's real damage, I feel like, that people can cause by accessing someone's social media. Also, if you could talk to, I really don't understand this completely, but like, there's people on LinkedIn that say that they work for our company, but don't. There's a lot of people that create face, which maybe they're trying to get a job. I don't know, right? Or whatever, but I'm like, I don't know who this person is. And then certainly it, which that's something I think the verification process is helpful for because there was no way to defend on that. You could just say whoever you were, whatever you did, right? Like there's, there's, there's a lack of verification with that, but also even on Facebook, um, you know, I mean, really the weird questions, Hey, do you have a second? Can you send me money sort of thing? Uh, I think it's getting overdone and, and, and people are seeing that, but like, why are people still creating a fake profiles? Um, you know, someone actually, uh, just created a fake profile of one of my family members and then friended me. And I'm like, wait, I, I don't know what necessarily, um, is the end goal. You know, it's certainly, uh, sometimes the people show who they really are. Uh, there's, you know, certainly guys that are acting as cute girls online. Um, you know, I, I, I don't know, like, can you kind of speak to this world? Cause, um, from somebody that maybe is not involved in it every day, um, you know, can see what they're doing, but don't really understand like the wise, right.
It looks, it looks not, it looks innocuous, right? Like, it's like, ah, you know, why are they doing that? Um, maybe, you know, I, I would have thought first, you know, everything on social media is like a sales kind of, uh, bent that, okay, maybe they're trying to get a list to, uh, send people, uh, some kind of spam to, to buy something. I don't know, but it seems like it, it, it's more than that. Yeah. That's certainly, I mean, the genesis of the internet is full of anonymity, right. Which is gone, partially gone, right. I think there is value in having some of it, right. You want to be able to speak freely and sometimes that may jeopardize, you know, your, your employment situation or something else. Right. But there's certainly a method and a reason why those fake accounts are created. It's really about building that reputation. Right. So a lot, sometimes what we're looking at as well as how long has this profile been there? Right. So they want to cook things for a while. We had someone that created a profile where I worked to Vora and just, it's, we're like, who is this person? And, uh, it turns out it was, you know, years ago, one of our pen testers had created this profile specifically so they could burn it later. Right. So you want to get these things created. You want to have them be around for years if possible and tied to say a cell phone account that's been around for a while. Cell phone number reputation is a big thing too, because I mean, I got the same number. I've had it for two decades. Right. But if you get a new number, we can tell it's a new number, a newly issued number, and that's a red flag. So you want sort of old profiles with old numbers that have been around a while. That's great for reputation and just believability on these fake profiles. That's sort of why they're done sort of as a hedge,
right. They're sort of creating them ahead of time before they may need them, before they get burned. What, what do they do with them? Yeah. Well, just like you experienced, right. So someone tried to friend me like, well, what if you don't know, you work at a large enough firm. You're like, yeah, yeah, I worked with you in this, whatever department. You're like, oh, okay, maybe. Right. And then you sort of just friend this person and then they start sending you other stuff later. Right. Sort of the long game. Right. But they want to, they want to appear legitimate. They want to build your trust. Ultimately. So they just want to get past that initial barrier. And as time goes on, you know, it looks like a regular profile that you're connected to. Like certainly I think like on LinkedIn, they've done a good job now. You can only send a certain number of friend requests, but in the past, like, you know, like it was just very noisy. Everybody would connect with everybody because then you could see other people's connections. And, and it's certainly, I'm sure I'm, I'm certain there's a lot of people that are under the radar in a lot of people's quote unquote networks. Right. Which are just sleeping to do something nefarious at some point. There's some people on my LinkedIn that I look, I don't remember where we met. Oh, we met a, it may have been a vendor. I met one time, you know, 15 years ago, but he's, you know, we're connected. Like what, what if he did something else? You know, you can get profiles like that. They're sort of like, well, I think I know you, but maybe I don't. You're sort of in this gray area. That's certainly a risky place to be. Okay. So, you know, just what are some general tips in, in, in just the, the, the general arena of, you know, the, the, the social engineering, the phishing tax, or maybe what are some of the common types of
things that, that you're seeing that are getting people that are still working? Cause I, I know I look every time at the email, like where did that email come from? Because many times there's like, Amazon's going to shut down your account or, you know, Apple's going to do whatever or whatever. And then it's from like some crazy number. Um, uh, and, and so, you know, there's telltale signs that you're looking for, but maybe you could just share, uh, if, if someone's not up to date, because I think technology is moving quite rapidly. Right. And I think a lot of people listen to this podcast, uh, because digital marketing continues to change, uh, SEO continues to change and you need to stay up to date with it. Um, I think it can be easy to get bypassed in, in other areas. If, if you're not like, I call it like writing the technology wave, like you got to stay up to it and it's easy to stay up to it. But if, if you let that wave hit you and, and you're underneath it, it's just going to pass you by and it's very hard to, to get caught up, but what are some best practices maybe to, uh, you know, insulate yourself from some of these things as we, we, we may move into other topics. Yeah. Best thing is I basically don't trust SMS or text messages. Right. And I, I get plenty, right. You, everyone's been to Instagram and you click on a vendor and they hit you with the, Hey, sign up and get 15% off. Hey, sign up with your cell phone number and get 20% off. And then you get the text message. Right. Well, the text message can be spooked, right. It's just basically caller ID and caller ID is basically sender driven. You can just set what it is. Right. So you can impersonate someone pretty quickly and easily over SMS. So the trick is don't like click on those SMS links, just log in straight to the
site. Like, Oh, I've got to notice that there's a sale happening or whatever. Let me just, I'm not going to click on that link, but I'm going to go to the website that I know. And then you kind of come in the front door, right. Uh, that sort of short circuits that like just clicking on random links to get texted to you. Even it seems legit, or there's a whole history of them texting you previously, usually just shy away from that. I kind of avoid that entirely. When you get email marketing or anything that looks maybe spammy, a lot of it is just, Hey, mouse over that link and hover on it. What does the URL look like? Right. Is it bank of America something, you know, that's obscure that like, that doesn't look like the right domain name and domain names are, are, are, are, are secured. Right. So people will get ones that look very close to what your, like a letters off, you know, you gotta be really careful. I mean, some of them, some of them are better than others, right? Like some people spend a lot more time crafting these things than not. Yeah. We, we had, we did, we did an attack on one client and they had an M in their domain name and we replaced it at the M. There was a domain registered that had an R and N replacement of the M. So if you look like just briefly, in the URL line, it looked almost like an M was an R and N. So you can get little nuances like that that just trick people. And it doesn't need to happen to everybody. Just enough people to get them to click and what have you. So, uh, you know, the email spam filters are pretty good. If you're using Gmail or use the office 365, it's, it's not a hundred percent. I still get some, but just hover on that link and see where does this thing really go? Right. And if it isn't
like, Hey, log in here and check it out, go click the link, just log into the front end and ignore the email and see what you get. Right. If it's an alert, you'll see it when, when you log into the site. Okay. Well, quick question. You made me think of this QR codes. How do you feel about random QR codes? Scan this QR code. Right. Uh, and we'll take you to the website and everybody's putting QR codes on everything. There's no way to scroll over that link to see where it's taking you. If it could take you somewhere, redirect you somewhere else. Like you don't even know that your information, there's like a man in the middle attack essentially. Right. Yeah. Very skeptical. Some QR codes. I mean, it used to be, you just scan them. It wouldn't even give you a preview URL, but if you do it on an iPhone now, it kind of shows you a little bit and same, same logic would hold there. Like, is this a URL that makes sense? But even, even so it's like, Oh, I go to this restaurant. There's this QR code. They're not hosting the menu themselves with some third parties. It has some weird URL and you're like, I don't really know. But normally, I mean, you got to look, is there a sticker over it? Has it been covered? Partially covered, right? There's always that physical security element. I mean, it's sort of the same mentality I think is when you're looking at, you know, card skimmers that still happen on, on, on card readers. Right. So you go to that, you go to that gas pump and you're looking like, is there a skimmer here? I mean, sometimes we've, we've done a task where we create those custom skimmers and 3d print the plastic and put it in place. So this as low tech as those can be, those are still prevalent. Right. I think QR codes are the same way. Like, has this been added to as a sticker or
what, what's going on here? So on the card skimmers, I haven't seen it and I'm not sure how good they are on the actual gas pumps, but certainly like when you go into the store you know, now they have like kind of those protectors, certainly at the grocery store, they have the protectors because for, for those of you listening that don't know what a card skimmer is, it like sets on top of, uh, the, the, the actual kind of, um, you know, uh, keypad and it looks identical. Like you cannot tell the difference. There's just kind of like this little gap, uh, in the back. And I mean, once they get your card, I don't know what I've seen. A lot of it is, is that they start adding like random charges, like, you know, 10 bucks here reoccurring per month, like where you don't even know that you're just slowly, you know, getting money stolen. I mean, what, you know, what, like, how are the, what are the things to look for in physical, maybe card skimmers, but also, uh, I'm worried e-commerce. We've seen some really interesting things with plugins, which we can move into next, uh, not being updated on e-commerce sites. When a new site comes to us, nobody's been maintaining that site. No one's been updating any plugins like, you know, and then, and then they want to like, Hey, we want you to host us now. Can we transfer to you? Like there, there's a whole bunch of steps where we kind of pump the brakes here and let let's look at what's going on. Maybe you can start that, that can lead into what we can talk about on websites as far as card skimmers to e-commerce, I guess. Yeah. It makes sense. I normal, uh, standard operating procedure, I would say for looking for skimmers is, well, most prevalent is really ATMs. Uh, we have some banking clients that we do that we work for. And normally it's because they're sort of bulky and old school and
you fully insert the card, right? So that little section that, that plastic that takes the card, right? Give that a good tug, a good pull. And you can pull on a pretty hard. I always do that before I insert anything. And usually the ATM is, is more prevalent because one, one, they want, they want your debit card and pin, which is more interesting than just a card, right? Number one. Number two is you're normally kind of distracted. Like you're looking in the mirror, like, is there anybody around? Like what's going on? Like, I don't want to, you know, you're not really looking carefully at the device where you're inserting your cards. That's really just give it a good tug, right? Good pull. Uh, in cases like when you're using your credit card and if you have like the NFC, like you can use the wireless tap, that's much better, right? Anytime you've got to dip your card or insert it to use the pin, right? You're inserting it in something that's, uh, that's, you know, it's a little harder to get like, it's a smart card, basically hard to get like smart card readers or skimmers, but anytime you're swiping like gas pumps, you put it in and then you pull it all the way out, there could be a mag. So the tapping is actually, um, safer. Can people pick up, uh, that like through Bluetooth or wifi or like, you know, close enough, like within, you know, three, three to five feet, you can, depending on the reader, you can pick up that card a hundred percent. Yeah. So should you be keeping your stuff in like a little fair day bag or something like that? Some people do that. I, I, I have some stuff that I put in storage in a fair day bag is helpful. Um, it, it can, you have to get pretty close to someone to, to sort of passively read like their, the cards that they're using for their office. But even that is within a few
feet, but that's not hard to do if you're in like the food court at a business somewhere and you can brush up against somebody, you can get those cards, you can get a flipper zero. That's a, you know, a reading device and you can do that pretty, pretty readily, but credit cards, at least normally, I mean, the merchant absorbs that risk. Right. So, uh, even if it is, even if I do, you know, scan the card, I'm in the gas station, someone picked it up and someone replayed it. I wouldn't necessarily be on the hook for that. I wouldn't go crazy for card credit card security, debit card security. Absolutely. I basically don't carry it with me. Right. Me either. Yeah. Once you get the debit card and the pen, like you're sort of on the hook. So if someone goes and transacts and they pull cash out, uh, you're done. Like there's really no recourse that you have, but, um, credit cards, most of the time, I'm not too worried about credit cards getting out there because the fraud protection is pretty good. And even if they don't detect it, right. The merchant's on the hook. So if you're taking cards, I'd be more worried, but if you're using cards, it's, it's, it's sort of less of a, okay. So there's a lot of small businesses out here that are using like a WooCommerce plugin or Shopify. Um, you know, I've seen on WordPress websites, WooCommerce actually plugins that were really keystroke logging tracking. Like it was, it was basically, uh, somehow got in there. And if you're on that website and you're punching in your, your, your credit card information, it's capturing that it was pretty sophisticated. I mean, what are the things in commerce that, that you can see if you're a merchant or you're actually, uh, a developer, you're building a site or, or even a customer, maybe kind of touch from all angles. Yeah. There's, there's always the, uh, sort of where did the software come concern, especially in e-commerce.
And if you're using, using WordPress, WordPress has a lot of features, obviously in a lot of plugins. Number one issue is, you know, just updating your plugins. There's a constant, just be ready, right? There's a constant treadmill of just like, this plugin is outdated. It needs to be updated. Is it going to break something? You got to be sort of committed to, to detecting and updating those plugins on a regular basis. And beyond that, there's a lot of third parties that these plugins even use. And there, there's, there's a big cyber incident around, you know, Magecart and that Magecart. So basically what Magecart was a plugin to track certain elements of your browsing experience, like where you're hovering with your mouse, right? They want to know kind of how the ergonomics of the site are working. Right. Uh, but that some of their downstream stuff that they linked into was hacked. So there's sort of this, like almost software building materials that you need to understand, like what is actually running on this site. And it's amazing. I mean, we do pen testing, we profile some sites and sometimes there's like dozens and dozens of third-party libraries, third parties that are tying into, right. And a lot of dependencies for your feature set that you're relying on may not be fully controlled by you or even the plugin that you're using. So you got to be pretty vigilant in making sure that that's updated on a regular basis. And I think WordPress in particular is a target because it's so prevalent, but, uh, it's not unsurmountable, right? I think if you get to a point where you're doing good security testing of your site, right, hopefully through some sort of means, right. But also just updates, updates alone will get you 80% of the way there because most people aren't right. Especially on smaller sites that are hosted by third party, right. They're just, again, it's a crime of opportunity, right. If you're unpatched and there's a vulnerability, guess what? You're, it's your lucky day,
right? But if you're patched, you're, you're, you're doing better than most. Gotcha. Okay. I mean, what I, you know, get going into it a little bit deeper. Like there, there's now a lot of sites like Shopify, which has a payment processor built in. Um, we, we, we personally seen with small business sites because of all those updates, um, security being one component of it, usability, um, you know, you talked about CRO, like there's a lot you can do, but I've found that because everything's open source, uh, many times one plugin could break another component of another plugin. And you know, the more kind of balls in the air that you have, uh, there's more opportunities for stuff to break. Uh, we've ended up, uh, taking sites that were like WooCommerce. Uh, and when it was kind of time to rebuild the site every couple of years, uh, it's, it's good to, to rebuild the site, refresh the brand. Um, we'll build a Shopify store. Okay. Or the e-commerce component. And then we'll maybe put on a sub domain, like a WordPress instance or, or, or, or, or, or we'll do the SEO in Shopify. Uh, but it's just, it was the best combination of e-commerce cart usability. That's what it's meant for. And then, you know, all the flexibility. And also if you have other team members, freelancers, stuff like that, everybody's familiar with WordPress, you can even separate those rights. And then if you're bringing somebody in on a permission standpoint, uh, they don't have access to, uh, client information, uh, which is good one. Um, but, but two is, uh, you're not having to worry about all of these plugins talking to each other. Like you talked about all the third party data. You don't know who it is. It's kind of essentially a Shopify just like Apple, right? This is your, this is your, uh, app store. This is your, uh, responsibility. And then it's all in one place and they can manage it. Um, we, we found that to be an
effective solution. Just curious what your thoughts are on maybe something like, like Shopify. Is that maybe a better way to go? Or, um, how, how do you view the world in that regard? I think so. I, I, you mentioned Apple and Apple's philosophy is have the walled garden, right? It sort of works a certain way and take it or leave it right. And the Shopify is of the same ilk. And I think the benefit is you're, you're, when you're customizing, it's not really cut. You're just, it's, there's a configuration exercise that goes through for your customization versus customizing and almost coding or do some light coding. You don't want, you don't want like custom stuff because that's where you're going to introduce uncertainty and errors and problems, right? You want something that, Hey, this is built to work a certain way. I'm going to change the way the, the, the page looks and maybe the colors and the logo, but I'm using the Shopify functionality straight through. That's where you're going to be successful because you're relying on Shopify to go through and do that, right? You're not often the weeds sort of cobbling together a collection of features via plugins that may or may not all play nicely together, right? That's where, cause that's what that, that's the biggest security problem is just complexity, right? I just don't know. And how many businesses just don't know what the level of stuff that's out there because they're, it's too complicated to understand, right? So if you can reduce your complexity, kind of de facto improving your security. No, I really liked that point. And I like how you put it too is customization. And there's a lot of people that will add custom code, we'll build custom sites. You know, you, you don't have the, uh, history and longevity of like, this is tried and true. This is tested. This is off the shelf because everybody wants that kind of customization, but you're saying, Hey, you want a configuration of a standardization that, you know,
is safe, right? Versus the customization. And that, that delineation between those two are quite different, but some people, when they say they want customization, all they're really wanting is a, a custom configuration, right? And I, I really like how you, how you, you put that, um, you know, storing customer data, right? Um, uh, and like data privacy, GDRP kit speak, speak to that, speak to that. Tell me what, what your thoughts are surrounding some of those things. So data privacy, uh, obviously mandated by certain governments or GDPR is big in Western Europe, right? The idea here is you should have forgettability, right? You should be able to say, I want you to drop all of my information that you have about me to my purchase online, whatever. Right. So you have to have one, a data classification program. Then you have to have a way of basically confirming like, yes, I, here's all of your data and yes, I've disposed of it. And there's a closed loop, right? Pretty difficult to do in certain instances where you've got sort of co-mingled data, uh, in cases where, you know, there is a, I would say a compliance need. There's, there's ways where we can sort of help basically have data stores based on whatever privacy requirements you do have. Uh, I mean, generally speaking privacy is kind of dead, especially in the United States. I mean, you've got data breaches for all the major, uh, companies have probably been breached at some point or another. We can find those breach databases, right? There were some large ones for credit reporting agencies for 22 million Americans. I can probably find your full credit history. Right. So part of the rub, I think with privacy is the expectation that you still have some privacy, but you probably don't. Right. Uh, as defeatist as that is, that's sort of the reality of it, but there are ways that you can kind of protect your own information, uh, you know, from misuse and everything from, you know, credit reporting and
people use the life lock, but the really life lock does stuff like it just basically blocks people from opening credit cards until they get authorization from you. If you're a little more savvy about how you treat, uh, you know, certain critical transactions in your life, you can do a pretty good job of protecting yourself. Uh, but the privacy issue, I think from data security is, I mean, I still have my personal stuff. It's just backed up. Yes, it's in the cloud, like everyone else's stuff, but the critical stuff is cold storage, right? It's offline, right? It's available to me. You know, a cloud is just somebody else's database, right? Like when they were coming out with like, what is the cloud? Like Microsoft, I remember all their ads. I mean, it's essentially, Hey, you know, even like Apple, right? I back stuff up, people hack, can I hack Apple? And, and you might've taken a screenshot of something that, you know, was sensitive or whatever, and then they back it up and then someone hacks that. I mean, you're, you just talked about like air gap or, you know, having your own servers, which there are ways to do that. Um, but just putting something in the cloud means you're just like, you're putting something in the bank. It's somebody else's responsibility. And from what you just said, um, like every major, let's say 70%, 80%, 90% of everybody's information has been in a database that has been, uh, exploited at some point. And that's out there on the dark web. Um, you know, cloud, cloud security. Um, I mean, you're just trusting somebody else with your information, right? Um, is, is, I mean, there are, uh, uh, companies and stuff out there that will go try to scrub your information, but you know, people stored these, the, these databases offline, you know, like, I mean, it's going to be hard to, you know, once Pandora's out of the box or whatever the analogy is, like, it's hard to put it back in the box.
What you're saying is, um, any kind of sensitive information you have never put it on the cloud, uh, put it on a, uh, maybe like a, a hard drive that, that is encrypted or, uh, has a, a key code password or a punch password, to put stuff on it. I mean, or even just a little, yeah, get an external drive and put it in your safe. Right. That's, that's, that's fine too. Right. I think just having some resiliency there, not relying solely on the cloud provider is key. And you mentioned something that, that piqued my, well, piqued my interest on there is, uh, you know, you mentioned iCloud. I'll tell you the biggest, the juiciest part of any penetration test or attack that we would do if we get into someone's iCloud's iCloud notes, right? Because what do they put in notes? They put passwords and things, right? If you've got that, that's, that's, it's usually they're aggregated somewhere. Like I just jotted this note down and now it's a password for this thing, or this is the recovery key, right? That stuff, just print it out, put it somewhere, right? That's okay. It's a, it's, it's low tech. Low tech is fine. If it's offline, you're good to go. Don't keep that stuff on iCloud. You can help it. Right. So as much stuff as you can spread out, that's really what, that's really the ticket for personal security stuff. Well, what should businesses do, right? Like, um, you know, people's, uh, you know, information when they're hiring, right? Like there's a lot of information, um, like there's payroll stuff. There's all this information that companies are responsible for. Uh, and you know, things are exceedingly becoming more remote and, um, and, and virtual. And so how do you, how do you manage that? Like, is there, I know y'all go in sometimes to companies, evaluate them, do audits and suggest they do things a certain way. Can you maybe, speak to like a small business? Some of the things you're seeing, I know
even one of the hacks we haven't talked about yet, but I was sitting next to a pen tester, uh, on a plan. They were like, Hey, no one ever updates their, uh, printer. All right. They're the printer driver is. And if that's on your network, that's one of the easiest ways in. Um, but like, okay, there's a ton of small businesses out there. I've seen, uh, even, I was even seeing large businesses and we won't even talk about like license, like people operating on like the proper licenses, like these big businesses. Uh, like, we're not going to go into that. I'll not, I'll not call anybody out, but I've, I've, I've certainly seen like, and we, I want to talk about SharePoint too, before we go, uh, like intranet. Um, but like businesses of all sizes. Okay. I'm not just saying small businesses of all sizes have bad habits, like bottom line, they just have bad habits. Um, maybe talk about some basic structures or some recommendations, like actionable steps that if someone's listening to this, that runs a small business or is helping out a smart business on, uh, in a capacity beyond, um, you know, even maybe they're managing the website or beyond that. Like, what are some things to look for? There's a lot of CMOs that, that listen to this, that work with it and it professionals as well. So for small businesses, especially around, you know, HR information, there is, I think a tendency to sort of keep too much. And that may be not just HR information. There's like, well, I may need this. So I'm going to keep this. Right. And there's sort of this, uh, hoarding of almost hoarding of information. Like you may go into a business and they've got background checks from people that go back 10 years. Like, well, why is this even here? Right. Oh, well, we didn't know how we want to keep it. Like, would you even need it? Like, well, no. Right. So it starts with, uh, how long are
we legally obligated to keep this information? Right. What's the policy around data retention, data classification. So you don't have to go overboard, but a little bit of thought around, do I need to actually keep this? And we advise a lot of clients in some cases, they want to keep everything. Cause I want to go, I want to go back as far as I can. I won't have any issues, but even legally that sometimes I can hang you as much as it can hurt you. Right. So like two years, right. Or something like that on average, something like that. Two years. Yeah. Sometimes or even one year and you know, some things tax related, obviously seven years in for businesses, but don't keep it longer than you have to, because sometimes that legal ramifications can even be worse if you do have it and it can be subpoenaed and you have to recover all of that. So a lot of what we're encouraging people to do is just keep less, right. Especially if you're a small mid-sized business, right. You're working with HR information system, HRIS, just outsource that stuff and have it handled by a dispassionate third party and have the background checks go through their platform and keep it off your stuff. Right. That's a great thing to have hosted. You should not be emailing out, you know, W-2s to each other and all that stuff. That should not be in a SharePoint anywhere. Right. Put it in an HRIS. You can pay a reasonable fee monthly and it's just handled, right. It's sort of the same philosophy as a Spotify, right. Just they're, they're, they're good at that use cases, have them use that use case and then it's off, it's off limits for your team. Talk about that really quickly. Sending sensitive information, like certainly tax accountants sometimes are better about it. That's what I've seen of like zipping information in a encrypted file and sending it. But I have seen so many businesses send passwords and, you know, billing information, send
all kinds of stuff, HR information, just in an email, like just in an email, like, like constantly. Um, there's gotta be better solutions out there, uh, that can easily be implemented. I mean, what are some recommendations? Cause that's something I, I 90%, you know, uh, businesses that I see, uh, are sending sensitive information. I believe, uh, just by email. Most people, it happens because it's convenient, right. And there's not a good way for them to actually send secure email. So there are some platforms that you can basically do secure link drop. Like I want to send this person encrypted message and it just basically sends them a link. Then they got to authenticate into that link and then download that. There's, there's, you know, even large commercial pieces of software that do that. But if you make it convenient, people will tend to use it. And there's even ones that, you know, give you like an outlet plugin, right? Like, Oh, I just want to send this secure. Doesn't send the actual email, just zips it up, basically puts it on the web portal, sends the recipient a link and they can download that link or it's single use, or it's only good for 90 seconds or something. Right. But if you make it convenient, people will tend to use it, which is, you know, I think what we ultimately after, but, um, there's other ways to do like end-to-end encrypted encryption and PGP and other ways. It's sort of, it's sort of clunky, right? Uh, if you want like fully encrypted email to be sent all the time to all of your recipients, it's almost, it's almost so much to manage that you don't want to deal with. Do you think ProtonMail or something? I've seen people use that. I think that that's their, their marketing. I I've heard different stories about that. What's your. It's probably fine. I there, there's some, there's some folks that I know that, that, that rely on it, but it's not really, I mean, you don't know. I
mean, I guess I think it's hosted in Western Europe, but who has access to it? I don't really know. Right. But you can get to a point where if you're managing your own encryption keys and so-called encryption, you're not relying on the vendor or the provider in any way, that's where you're going to be in good shape, but it puts the burden of key management on you and the recipient, which, you know, most unsavvy people will not be able to handle like, Oh, I got to share keys with Matt. Oh, Matt, send me your private or your public keys so I can encrypt it. It becomes more of a burden, but that's really the only way to really secure those trends and any transmission is you've got to basically to have a key exchange, public, private key exchange and encrypt it and you handle in crypto yourself. Right. Yeah. Well, there's multi-sig there. There's multi-sig that you can, you can put different people and you know, you have two different peoples putting, putting their, their keys together to, to do some of this. I, I you know, like VPNs, it's funny, like VPNs, right? Like, so someone is still seeing your information. Okay. Like, like, like you're, it's just a different service provider that your information is going through. People think when they use a VPN, uh, all their information safe and that's not necessarily the case. It's just a different email provider, right? That's right. Or, or, uh, uh, internet browsing provider that is seeing your traffic flow, right? It's not completely anonymous. Someone is seeing it unless it's a hundred percent. Yeah. It gets encrypted on the D D encrypted on the other end. And that, that traffic is seen. It looks just it's in the clear at that point, right? They know who, what you're browsing, what you're up to, right? So if you're doing crazy file sharing and torrents and all that stuff, if there's, they're going to see all of that. Um, but what it does provide the VPN, it
provides your current ISP plausible deniability on what you're doing, right? They just go, I just see traffic. I don't have any legal obligation to act on it. I don't know what they're up to because they don't want to spend the time, money, energy, basically fighting all those fights. Right. So, uh, but getting good anonymity online is, is, is difficult and takes several layers. And even if that's impossible, right? People do VPNs and they do for browser and all kinds of other ways to sort of become anonymous. And, uh, you know, maybe it works, maybe it doesn't, maybe it's comp, maybe those systems are compromised. Maybe not. Maybe your VPN providers compromise hard to know, but just know that it will just get you basically anonymity from your ISP that you're having at your house or business. Wow. Well, I, I, hopefully people kept up with this conversation. Uh, certainly I think that this was actually a pretty much cyber security one-on-one. Um, I, I don't think we went into too much detail. Um, and if you were not keeping up, right, um, maybe, uh, Clayton share, uh, are there, are there places for people to go to educate themselves, uh, to, to dig into this further definitely should have you back on and we can dig into things a layer deeper. And then maybe talk a little bit about, uh, what, what you and your company does, how they get in touch with you, how you might be able to help people because I I'm sure there's somebody that was listening is like, okay, I feel like they're talking to me and, uh, I need to, to take some kind of action. Um, certainly, uh, a few years ago, uh, I was in the same place. And so maybe talk a little bit about just some general education, best practices, what you do and, and how to get in touch with you as we wrap up. Yeah, sounds good. Uh, I, you know, as far as where to start, cybersecurity is a very broad topic
and you can take a very academic approach and, you know, like, Hey, I want to learn how to be an electrician. Well, here's some physics lessons like, oh my gosh, right. Too much theory, right. When it comes to actually understanding what things are practical, if you're non-technical and, or small business owner and, or in the marketing space, right. There's a, the CISA, which is basically part of the, uh, department of Homeland security. It's really around, it's basically a government resource to help exactly this use case, right. Small businesses understand what attack scenarios are relevant, how to protect against them. It's very accessible. And, you know, it's part of what it's a government program. So it has plenty of resources and things you can read up on and basically increase your knowledge in this space. Uh, that's, uh, that would start there. There's also ISACA, I S A C A, which is basically, uh, it's a community of auditors, right. And it's a, it's association that does a lot of publishing of original work on topics that are relevant to cybersecurity for businesses, right. It has a compliance angle, uh, but that may be exactly what you want, especially if you have compliance needs or you've got GDPR or PCI or ISA, ISO or HIPAA or HITRUST or any one of the other acronyms out there. Uh, if there's any sort of compliance draw, then ISACA may be the best way to go to get started on some of those resources. Um, you can always, I mean, I'm, I'm, I'm ultimately a consultant, so you can always call me and contact me. I mean, I'm at, uh, again, the company I work for is Tavora. Uh, I have counterparts that handle other, other parts of our business and other practice areas as well, but you can always contact me. Uh, and, uh, yeah, I'd be happy to have a conversation and help out where I can. All right. Well, I'll, uh, give me some of these resources. We'll get your LinkedIn profile, um, and put that
in the show notes. Um, this was, this was awesome. I think for a lot of people, uh, it might not be top of mind, uh, but it, but it, it should be, uh, something that, uh, is, is, is that you're thinking about and, and you should have some of these best practices in place, uh, as you move forward. So Clayton, thank you so much, uh, for coming on. Uh, it was a pleasure. Uh, we'll have to have you on again, uh, until the next time. Bye-bye for now.
Matthew Bertram is an AI keynote speaker, creator of DIG® (Digital Information Governance), and owner and CEO of EWR Digital. He helps energy and industrial leaders win visibility in AI search (GEO and AEO), is President of ModalPoint and CMO of the Oil & Gas Global Network, hosts The Best SEO Podcast, and has authored eight books including LLM Visibility. More about Matthew Bertram.
Are you struggling to rank for local search terms? Have you ever wondered if creating separate local landing pages for various locations could be the…
In this insightful episode of the Best SEO Podcast, host Matthew Bertram engages in a captivating conversation with Larry Roberts, an AI and…
SEO is changing. From search updates and algorithm changes to advancements in AI and conversational search, check out these trends to stay ahead.
7 Ways To Use AI Writing Tools To Generate New Content Ideas Sponsored by Frase.io & SE RankingAuthor: Marcelo Beilin Source:…
The Best SEO Podcast breaks down SEO and AI search; EWR Digital, the agency behind the show, implements it for operators. Start with a free, no-pitch audit of where you stand in Google and in AI answers.
Get a free AI visibility audit