public education sector • 2009 Cape Breton University graduate - Bachelor of Technology Information in Network Management • OSCP, OSWP, Security+, OCSA, MCTS, Network+, Server+, A+ • Co-Host of the East Coast InfoSec Podcast (along with co-host Darryl MacLeod – AtlSecCon Board Member)
is duped into revealing personal or confidential information which the scammer can use illicitly source: https://www.merriam-webster.com/dictionary/phishing
is duped into revealing personal or confidential information which the scammer can use illicitly source: https://www.merriam-webster.com/dictionary/phishing • A scam by which an e-mail, SMS, or phone user is duped into revealing personal or confidential information which the scammer can use illicitly
have here is a failure to communicate. Apparently, the communication between the criminal and the victim is much more effective than the communication between employees and security staff.” – 2016 Verizon DBRI Report
Antivirus 2) Use Strong Passwords 3) Change Passwords Frequently 4) Only Visit Websites They Know 5) Don’t Share Personal Information SECURITY EXPERTS 1) Install Software Updates 2) Use Unique Passwords 3) Use Two-Factor Authentication 4) Use Strong Passwords 5) Use a Password Manager https://security.googleblog.com/2015/07/new-research-comparing-how-security.html
for in emails • Do not open email attachments from unknown senders • Look for grammar and spelling errors • Check link destinations • Aggressive email content …but does it really work?
malicious code • Can prevent ransomware from encrypting files • Etc. • Ensure software is up to date • Prevents known exploits from triggering • DOUBLEPULSAR… *mic drop* • Etc. …but does it really work?
or a computing resource that exists for the purpose of alerting you when someone accesses it. HONEYTOKENS (THANKS JSAVOIE FOR THIS TIP) Source: https://zeltser.com/honeytokens-canarytokens-setup/