Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender
Young and Profiting (YAP) with Hala Taha: Entrepreneurship and Self-Improvement Podcast
In this episode of Young and Profiting Podcast, entrepreneur and cybersecurity expert Abed Hamdan reveals why small businesses are prime tar
Key takeaways
- Small businesses are often easier targets than large corporations due to limited resources and cybersecurity awareness.
Main topics
- Why small businesses attract cybercriminals
Notable quotes
"If you were a hacker, would you go after Meta or a small business? The answer is obvious. They're easier targets."
Conclusion
Entrepreneurs must prioritize cybersecurity by adopting basic but critical practices like
Transcript preview
Speaker 1 (0:00) There's a really famous story on the news. They created a dating app for women's safety. But then turned out that app, they took their passport details and all their information. Turned out this app was encoded with zero security. It got hacked and it put women's safety in danger. Speaker 2 (0:15) Wow. Speaker 1 (0:15) Usually women get targeted, like someone leaks explicit videos of an individual. And well, that video is completely deepfake and it has been happening. They always target the vulnerable. They always target the young. It is a problem. and we need some kind of a strict regulation. Speaker 2 (0:30) We're joined today by Abed Hamdan, founder of GRC Mastery and content creator, who's known as the Unix guy online. He brings more than two decades of experience in cybersecurity and risk. Speaker 1 (0:42) So we want to use AI. We want to be on top of the new technology, but we also need to stop and think, what is it that we're using AI for? What does the AI have access to? And more importantly, where's my data going? Speaker 2 (0:54) What's one thing that entrepreneurs are doing where a hacker is going to say, this is just way too easy? Speaker 1 (0:59) Something I see frequently is a founder says, oh my God, we went live last week. You wouldn't believe it. We expected 200 clients and now we have 2000. This tells me that this team is extremely busy. They can barely keep up. This is a really quick telltale. There are other things that... Speaker 2 (1:14) How worried do we have to be about AI agents and their ability to hack our companies or their cybersecurity threats? There Speaker 1 (1:22) are many issues with AI agents. The first one is Speaker 2 (1:26) This episode is brought to you by Bitdefender, a global leader in cybersecurity. Have you ever received an email that looked like it came from a bank or a trusted vendor asking you to wire money immediately? Small business owners get hit by scams like this all the time, and one click can cost your business everything. Bitdefender Ultimate Small Business Security keeps your devices, passwords, and team safe, even if you don't have an IT team. Protect your business with Bitdefender Ultimate Small Business Security. Save 30 % when you go to bitdefender.com slash profiting. That's Speaker 1 (1:59) bitdefender.com slash profiting. Now Speaker 2 (2:02) to help us better understand the business of cybercrime and how organizations can protect themselves, we're joined today by Abed Hamdan. Abed, welcome to Young and Profiting Podcast. Speaker 1 (2:13) Hi, Hala. Thanks for having me. Speaker 2 (2:14) I am really looking forward to having this conversation about cybersecurity. I feel like all business owners need to protect their businesses. And with AI, cybersecurity is becoming more important than ever. But let's start at the very basics. For the entrepreneurs tuning in, what is something that you think they fundamentally don't understand about cybersecurity? Speaker 1 (2:38) Entrepreneurs usually make, I think, a couple of assumptions about cybersecurity. I think first, the first assumption they make is about the attacker. So they think the hacker is this person in a hoodie in some basement, or they go the other extreme and they think the attacker is some really sophisticated sort of spy agency or foreign government. And as a result of these two assumptions, they usually think, well, I'm an entrepreneur, I run a small agency or run a small business. Why would anyone attack me? And unfortunately, of the businesses that I helped, it's usually after the fact. So they get attacked and they really sometimes underestimate the consequences of some cyber attacks. Some of them, unfortunately, can be business ending or it can have such a large cost that it may even be cheaper to just shut the business down. And this is huge everywhere across. from like small business to even medium sized and in some instances, even large businesses. Speaker 2 (3:37) Yeah, I always think of like really big companies like Meta getting hacked or Bank of America or something like this. But small businesses actually can be attractive targets. Why is that? Speaker 1 (3:50) 100%. In fact, think about it. If you were a hacker, let's say you've just learned how to hack and you want to start, you know. legally hack, you naturally wouldn't go after meta because that's such a difficult target. They invest so much in cybersecurity. They are at the forefront of everything technology. However, when it comes to small businesses and entrepreneurs, usually they're just focused on getting their product out. They are overworked and most instances also underfunded. So they can be, quote unquote, easier targets, but they also hold something really valuable. They hold what we refer to as privately identifiable information. So that's something that we classify as a critical asset. For example, a lot of entrepreneurs will have something like a customer database where they have the names and last names and phone numbers and sometimes the addresses. This is extremely valuable because... what attackers can do, they can get that information and sell it on the dark web. It's actually extremely valuable. So that's a really key critical asset that lots of small businesses have. And unfortunately, sometimes they don't have the knowledge or the resources to protect that. The other thing, and probably the more important thing that small businesses have is that, well, like I said earlier, it may be a lot harder to hack something like a big bank or something like Meta, as you alluded to. However, the way to get into those companies is usually you hack their suppliers. So if that small business is a supplier for a bigger business, usually it's a lot easier to attack that small business and use it to pivot or use it to trust. If you can compromise the email account of a small business, well, you can start sending malicious stuff using their email address. In fact, that's how most big businesses get compromised, through their suppliers. And they're usually on the smaller side. Speaker 2 (5:41) So interesting. I never thought about that. So we not only have to worry about our own security, we have to worry about the security that our vendors are... doing for their own companies, which is just so crazy to think about. What are the main ways that small businesses are compromised? So we just talked about vendors for bigger enterprise businesses. How about small businesses? What are the main ways that they're compromised? Speaker 1 (6:04) So look, the way sort of hacking or compromise happen, there are actually so, so many ways. Most of them aren't even known to the public. They tend to be complicated. But the most common ways... for, let's say, an attacker to gain foothold and tend to be the easiest way. It's what we refer to as social engineering. This is where the attacker pretends to be someone that the business owner knows or pretends to give them something that they trust. So we really use the old age sort of trust relationship that we humans rely on. For example, as a small business, I could pretend to be one of their employees and send an email urgently, say, hey, I've lost my account, urgent, please. click on that link and help me out. So we apply time pressure. So we call that social engineering or phishing, which falls under social engineering. There are other sinister ways as well, but it all comes back to really pretending to be someone else. So fellow entrepreneurs and YouTubers, a really common recent one is actually pretending to be a brand and offering a brand deal. Speaker 2 (7:10) Yes, I get so many of those. Speaker 1 (7:12) I've even helped cybersecurity professionals who got hacked this way. And that's no shade on them. This is just a testament on how good some of those attacks are. They can really pretend to be a legitimate brand and the website look exactly the same. There might be just a slight variation on the URL. And sometimes it's something that your eye cannot see. So some of the alphabets, we can replace it with special characters and it's really hard to detect. So that's really... common way. There are more and more ways. For example, if you have physical access to the business, there are things you can install, but that's a whole other story. But when it comes to sort of the most common ones, it tends to be 100 % social engineering. Speaker 2 (7:54) So let's really unpack this with a real example. If you could really just walk us through, let's say there's a company that has like 20, 30 employees. They're using the typical things, Slack, cloud storage, Zoom. They might have vendors, different SaaS tools. Walk us through how they could get attacked and some of the things that could happen and how it could escalate. Speaker 1 (8:18) Yeah, I mean, just before I say anything, just disclaimer, hacking is illegal. What I'm about to say is for educational purposes, so please don't do it. But hypothetically, if I was to attack this imaginary business, the first step I would do is always reconnaissance. So I'll try to collect as many information as I can about that business. This includes their LinkedIn posts, how many people work there. I'll even draw like an org chart, see who's who, who's the employee, go on Instagram. They usually share everything. So I'll get a list of the individuals who work there, but more importantly, I'll get a list of the technologies that they use and also the product that they have. So once I get a list of that, The next step would be I start to craft things that they trust. I'm going to social engineer my way there because it's a lot easier for me, like I said, to get an employee to do something for me as opposed to me trying to hack Microsoft and get inside their email. So what I will do is I'll try to mimic what their email looks like. And now that's really easy. I can literally vibe code that in like five minutes. It used to take a lot more time. The second thing is I'll see what vendors they use. So if they use so many SaaS applications, well, I could hypothetically go to the dark web and see if there is any information about those services. If there is a new vulnerability, it may not be patched. So I could directly go and hack one of their SaaS services and get into their network. But let's say everything they use is secure. Well, I'll try to then attack, sort of target the employees individually. I'll usually target who may appear to be more vulnerable. Usually it's very busy individuals, very busy founders. They are more likely to click on something really fast. Sometimes I'll even, not I, but the hypothetical attacker may look at elderly parents and try to tell them they've won something. Because what happens, Hala, is if the elderly parent gets their email compromised, Well, I can use their email to send stuff to sort of their kids and they're more likely to click on them than if it comes from an unknown individual. Now, the final one that is very, very effective with entrepreneurs and all the startups that I don't recommend anyone to do, but I could simply purchase the product that they have and be a legitimate customer and just give their customer support hell. I'm like, it's not working. Help me. Hop on a Zoom call. Do this. So the customer support individuals are very likely to say, well, I tell them my Zoom is not working. Please click on this so I can get them to click on something. And unfortunately, support individuals usually have a lot of access. So as soon as they click on something, I'm in. And I can continue pretending to be a legitimate customer, which I am. Close everything so they don't suspect that something's happening. And then I'm in the network. then I'll start to slowly and surely take over everything. But that's more or less how, I guess, a lot of hackers would actually approach it. Speaker 2 (11:22) That's so frightening. It's so frightening that this could be happening. And I guarantee you that so many entrepreneurs tuning in are now realizing how big of a deal this is and how little they're probably protected. So what is one thing that... With our cybersecurity, when you're looking at small businesses, what's one thing that entrepreneurs are doing where a hacker is going to say, this is just way too easy? Speaker 1 (11:45) I mean, there are a number of things. And I'm going to start with the big business and then go down to the small one. A really big telltale, even for me as a consultant, if a company is hiring me to check their security, the first thing I go on LinkedIn and I just see who works there. If that organization is sort of mid-sized to large size. And I see that they have like one person that's called quote unquote IT person that's doing everything. This is a sure sign that this person is overworked, probably doesn't have enough time to do everything security-wise. So I know there is a high chance that they may not be doing everything they need to do. So that's a quick telltale for me. The other one would be, believe it or not, I'll go on Instagram and... Something I see frequently is a founder says, oh my God, we went live last week. You wouldn't believe it. We expected 200 clients and now we have 2000. This tells me that this team is extremely busy. They can barely keep up and it's a lot easier to do things with them that, you know, I'll put a time pressure. Hey, I'm a customer. The app's down. Help me log into my computer. Do something for me. This is a really quick telltale. Now, more than that, there are other things that I wouldn't say small business owners. sort of do, used to be more common in the past. So things like not having two-factor authentication or like old practices that they still exist, but not so much nowadays. So systems have gotten better, thankfully, but as a result, because we have better systems, better IT setups, we can produce a lot faster. And with speed comes compromise. And not just in cybersecurity. You probably have seen it, Hala, where... organizations or entrepreneurs or small businesses, they release something, but they haven't done their due diligence from a legal point of view. They haven't gotten everything reviewed and they say, well, we'll do it after the fact. So these kinds of things may have large impact and in some cases, large consequences. Speaker 2 (13:40) This episode is sponsored by Bitdefender, a global leader in cybersecurity. Many small business owners lack dedicated IT support, making them easy targets for cyber criminals who steal data, money, or sensitive information. Bitdefender Ultimate Small Business Security is built specifically for business owners like you. It protects all of your team's devices, scans for phishing and scams, manages passwords, and even checks the dark web for leaked info. Unlimited VPN allows your team to work securely from anywhere. The dashboard is super simple. I set it up in just minutes. I add my whole team. And now everybody is covered, whether they're in the office or the studio or working remotely. Bitdefender makes cybersecurity easy so you can focus on what really matters, growing your business and serving your customers. Protect your business today with Bitdefender Ultimate Small Business Security. Save 30 % when you go to bitdefender.com slash profiting. That's B-I-T-defender.com slash profiting for 30 % off. Bitdefender.com slash profiting. Speaker 1 (14:40) I want to understand how Speaker 2 (14:41) you know so much about cybersecurity and hacking. And I learned from studying you that you got into this when you were like a teenager. And you were really exploring, you know, how does hacking work? And I'm curious to understand, like, where did this all begin? Tell us the story. Speaker 1 (15:00) Yeah, I mean, not to show my age, but I'd say I started. perhaps late 90s, early 2000s. And at that time, and especially where I was living, internet was new. It was a novelty. It's the new thing. Internet, for those my age, internet cafes were a thing. So you'd go to an internet cafe, your paper hour, and you start exploring and there wasn't much to explore. So it really started with chat rooms called the IRC chat rooms. Within that, I discovered, well, people were sharing files you can download. There is a music file that was new to me. And then there was this thing called hacking. It coincided with me watching a movie called Hackers. It was an early Angelina Jolie movie. It is fiction, but it really opened my eye. Like, hold on, this is a thing. Like, you can actually do that. As a teenager, and as you do as a teenager, you start imagining things. Oh my God, I could hack an airplane and fly myself everywhere. These imaginary scenarios that are not real, but like as a 15 years old, this is everything. Then as I sort of quote unquote do research, sort of find movies, I find another movie about someone called Kevin Mitnick, late Kevin Mitnick. He is the most famous hacker in the world. At the time, there was movie, not just one, I think more than one movie. One was in German, one was in English. Of course, a lot with subtitles. The things he did were incredible. He would hack phone lines. He would jam radio signals. He was on the run by the FBI. And the movies, of course, made it so glamorous. So all I could think of, like, oh, my God. And that was a time when... We would call people on phone line. So I'm like, oh, I could hack my friend's phone line. I could do these pranks. So I wanted to learn everything. I'd go to these chat rooms. And at the time, Hala, things were a bit different in the sense, if you ask for help, people start swearing at you. It was not a friendly time, unlike today. So I had to learn certain things the hard way. I got myself hacked multiple times. Long story short, I sort of went into the right direction, started learning an operating system called Unix, hence where my nickname came. And actually a fun sort of useful anecdote, my website, unixguy.com is a few months older than google.com. So I go way back. Yeah. So that's where it all started. Then I got my first job, started studying things at university that were completely useless. Got my first job, but I continued learning. And I still do that to this day, even after consulting for so many years. I enjoy it. I like to learn. I stay curious and experience, of course. I've done this so many times, so much so that sometimes I can look at something and have an educated guess that maybe we can look here. Let's just start this way and take it from there. But yeah, it's been a continuous learning and experimenting journey. And it's a lot of fun. Speaker 2 (18:01) Your entrepreneurship journey is like really interesting. So we're going to spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business. And you've done such a great job, like really owning this niche and this lane and helping so many people in their IT careers, especially in Australia. Since we have this incredible consultant in front