Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

Close the Cybersecurity Backdoors Hackers Use to Target Your Business | Entrepreneurship | Abed Hamdan | Presented by Bitdefender

Entrepreneurs often assume hackers only target big companies, but small businesses can be easier targets than they realize. A weak password, compromised vendor, or poorly managed access point can expose customer data, disrupt revenue, and damage trust. In this episode, presented by Bitdefender, cybersecurity consultant, Abed Hamdan explains why your business might be an attractive target to hackers and how entrepreneurs can protect their business from today’s cyber threats without needing a full-time security team.

In this episode, Hala and Abed will discuss:

(00:00) Introduction

(00:00) Why Small Businesses Attract Hackers

(07:55) How Hackers Target Small Businesses

(14:40) How Abed Entered the Cybersecurity World

(18:22) Non-Negotiable Cybersecurity Habits for Businesses

(28:57) How Cyberattacks Can Destroy a Business

(30:29) Cybersecurity Protection on a Small Budget

(32:41) Defense in Depth for Small Businesses

(40:30) AI, Deepfakes, and New Cyber Risks

(54:27) Insider Threats and Employee Access Risks

(57:42) Finding the Backdoor in Your Business

(1:03:04) What to Do After a Cyberattack

(1:05:17) From Cybersecurity Content to Entrepreneurship

Abed Hamdan is a cybersecurity consultant, content creator, and founder of GRC Mastery. He has more than two decades of experience helping organizations strengthen their security, manage risk, and navigate complex cyber threats. His expertise spans cyber defense, governance, risk and compliance (GRC), and security strategy. Known online as UnixGuy, Abed has built a global cybersecurity community of more than 600,000 followers by making complex security topics practical and accessible.

Sponsored By:

Keep your small business safe with Bitdefender Ultimate Small Business Security. Save 30% when you go to bitdefender.com/profiting

Resources Mentioned:

Bitdefender: bitdefender.com/profiting

Abed’s Training Platform, GRC Mastery: grcmastery.com

Abed’s YouTube: youtube.com/@UnixGuy/about

Abed’s LinkedIn: au.linkedin.com/in/abedhamdan

Active Deals – youngandprofiting.com/deals

Key YAP Links

Reviews – ratethispodcast.com/yap

YouTube – youtube.com/c/YoungandProfiting

Newsletter – youngandprofiting.co/newsletter

LinkedIn – linkedin.com/in/htaha/

Instagram – instagram.com/yapwithhala/

Social + Podcast Services: yapmedia.com

Transcripts – youngandprofiting.com/episodes-new

Disclaimer: This episode is a paid partnership with Bitdefender. Sponsored content helps support our podcast and continue bringing valuable insights to our audience.

Entrepreneurship, Entrepreneurship Podcast, Business, Business Podcast, Self Improvement, Self-Improvement, Personal Development, Starting a Business, Strategy, Investing, Sales, Selling, Psychology, Productivity, Entrepreneurs, AI, Artificial Intelligence, Technology, Marketing, Negotiation, Money, Finance, Side Hustle, Startup, Mental Health, Career, Leadership, Mindset, Health, Growth Mindset, Passive Income, Online Business, Solopreneur, Networking

Hala Taha: [00:00:00] Abed, welcome to Young and Profiting podcast. Hi,

Abed Hamdan: Hala. Thanks for having me.

Hala Taha: Of course. I am really looking forward to having this conversation about cybersecurity. I feel like all business owners need to protect their businesses, and with AI, cybersecurity is becoming more important than ever. But let's start at the very basics.

For the entrepreneurs tuning in, what is something that you think they fundament- fundamentally don't understand about cybersecurity?

Abed Hamdan: Entrepreneurs usually make, I think, a couple assumptions about cybersecurity. I think first, the, the first assumption they make is about the attacker. So they think the hacker is this person in a hoodie in some basement, or they- Mm-hmm

go the other extreme and they think the attacker is some really sophisticated, um, sort of spy agency or foreign government. And as a result of these two assumptions, they usually think, "Well, I'm an [00:01:00] entrepreneur. I run a small agency or run a small business. Why would anyone attack me?" And unfortunately, of the businesses that I helped, um, it's usually after the fact.

So they get attacked, and they really sometimes underestimate the consequences of some cyber attacks. Some of them, unfortunately, can be business-ending, or it can have- Mm ... such a large cost that it may even be cheaper to just s- um, shut the business down. Um, and this is huge everywhere across, from, like, small business to even medium-sized, and in some instances, even large businesses.

Hala Taha: Yeah. I always think of, like, really big companies like Meta getting hacked or Bank of America or something like this. But- Mm ... small businesses actually can be attractive targets. Why is that?

Abed Hamdan: 100%. In fact, uh, think about it. If, if you were a hacker, Halaf, let's say you've just learned how to hack and you wanna start, you know, legally hack, you naturally wouldn't- Mm-hmm

go after Meta because that's such a difficult [00:02:00] target. Um, they invest so much in cybersecurity. They're at the forefront of, of, of everything technology. However, when it comes to small businesses and entrepreneurs, usually, um, they're just focused on getting their product out. They're overworked and mos- in most instances, also underfunded.

So they can be, quote-unquote, "easier targets," but they also hold- Mm ... something really valuable. They hold what we refer to as, um, privately identifiable information, so that's- Mm ... something that we classify as a critical asset. For example, a lot of entrepreneurs will have something like a customer database where they have the names and last names and phone numbers- Yeah

and sometimes the addresses. This is extremely valuable because what attackers can do, they can get that information and sell it on the dark web. It's actually extremely valuable. So that's a really key critical asset that lots of small businesses have, and um, unfortunately, sometimes they don't have the knowledge or the resources to protect that.

The other thing, and [00:03:00] probably the more important- Mm-hmm ... thing that small businesses have is that, well, like I said earlier, it may be a lot harder to hack something like a big bank or something like Meta- Mm ... as you, um, alluded to. However, the way to get into those companies is usually you hack their suppliers.

So if that small business- Mm ... is a supplier for a bigger business, usually it's a lot easier to attack that small business and use it to pivot or use it to trust. So- If you can compromise the email account of a small business, well, you can start sending malicious stuff using their email address. In fact, that's how most big businesses get compromised, through their suppliers, and they're usually on the smaller side.

Hala Taha: So interesting. I never thought about that. So we not only have to worry about our own security, we have to worry about the security that our vendors are doing for their own companies, which is just so crazy to think about. What are the, what are the main ways that small businesses are compromised? So we just talked about vendors, uh, for bigger [00:04:00] enterprise businesses.

How about small businesses? What are the main ways that they're compromised?

Abed Hamdan: Hmm. So look, the way sort of hacking or compromise happen, uh, there are actually so, so many ways. Uh, most of them aren't even known, uh, to the public. They tend to be complicated. But the most common ways for, let's say, an attacker to gain foothold and tend to be the easiest way, um, it's what we refer to as social engineering.

This is where the attacker pretends to be someone that the business owner knows or pretends to, to give them something that they trust. So we really use the, the old age sort of trust relationship that we humans rely on. Mm-hmm. For example, as a small business, um, I could pretend to be one of their employees and send an email urgently say, "Hey, lost my account, urgent.

Please click on that link, and, um, help me out." So we apply time pressure. So we call that, um, social engineering or phishing, which falls under social engineering. Um, there are other- Hmm ... sinister ways as well, but it all goes, it all comes back to really [00:05:00] pretending to be someone else. Um, so fellow entrepreneurs and, and, and YouTubers, um, a really common recent one is actually pretending to be a brand and offering a brand deal.

Um- Yes.

Hala Taha: I get so many of those.

Abed Hamdan: I've even helped, like, cybersecurity, uh, professionals, uh, who got hacked this way, and that's not, no shade on them. This is, this is just a testament on how good some of those attacks are. They can really pretend to be a legitimate brand, and the website look exactly the same.

There might be just a slight variation on the URL, and sometimes it's something that your eye cannot see. So some of the alphabets, we can replace it with special characters, and it's really hard to detect. So that's a really common way. There are more and more ways, uh, for example, if you have physical access to the business, there are things you can install, but that's a whole other story.

But when it comes- Hmm ... to sort of the most common ones, um, it tends to be 100% social engineering.

Hala Taha: So let's really unpack this with [00:06:00] a real scenario, uh, or, like, a real example if you could really just walk us through. Let's say there's a company that has, like, 20, 30 employees. They're using the, the typical things: Slack, cloud storage, Zoom.

Uh, they might have vendors, s- different SaaS tools. Walk us through how they could get attacked and some of the things that could happen and how it could escalate.

Abed Hamdan: Yeah. I mean, just before I, I say anything, just disclaimer, hacking is illegal. What I'm about to say is for educational purposes, so please don't do it.

Uh, but hypothetically, if I was to attack, um, this imaginary business, the first step I would do is always reconnaissance. So I'll try to collect as many information as I can about that business. This includes their LinkedIn posts, how many people work there. I'll even draw like an org chart, see who's who, who's the employee, go on Instagram.

They usually share everything. So I'll get a list of the individuals who work there, but more [00:07:00] importantly, I'll get a list of the technologies that they use and also the product that they have. So once I get a list of that, um, the next step would be I'll start to craft things that they trust. I'm gonna social engineer my way there because it's a lot easier for me, like I said, to get an employee to do something for me as opposed to me trying to hack Microsoft and get inside their email.

So what I will do is I'll try to, um, mimic what their email looks like, and now that's really easy. I can literally vibe code that in, in like five minutes. It used to take a lot more time. Um, the second thing is I'll see what vendors they use. So if they use so many SaaS applications, well, I could hypothetically go to the dark web and see if there is any information about those services.

If there is a new vulnerability, it may not be patched. So I can-- I could directly go and hack one of their SaaS services and get into their network. But let's say everything they use is secure. Well, um, I'll try to then attack, sort of target the employees [00:08:00] individually. I'll usually target, um, wha-- who may appear to be more vulnerable.

Um, usually, it's very busy individuals, very busy founders. They are more likely to click- Mm-hmm ... on something, um, really fast. Um, sometimes I'll even, um, not I, but the hypothetical attacker may look at- ... sort of elderly parents and, um, try to tell them they've won something. Because what happen, Hala, is if the elderly parent gets their email compromised, well, I can use their email to send stuff to sort of their kids, and they're more likely to click on them than if it comes from an unknown individual.

Now, the final one that, um, is very, very effective with, um, with entrepreneurs and all the startups that I don't recommend anyone to u- to do, but, um, I could simply purchase the product that they have and be a legitimate customer and just give their customer support hell. I'm like, "It's not working. Help me."

Mm. "Hop on a Zoom call. Do this, do..." So the, the customer support [00:09:00] individuals are very likely to say, well, I tell them, "My Zoom's not working. Please click on this," so I can get them to click on something. And unfortunately, um, support, uh, individuals usually have a lot of access. So as soon as they click on something, I'm in, and I can continue pretending to be a legitimate customer, which I am.

Close everything so they don't suspect that something's happening, and then I'm in the network. Then I'll start to- Mm ... slowly and surely take over everything But that's more or less how, um, I guess a lot of hackers would actually approach it.

Hala Taha: Yeah. That's so frightening. It's so frightening that this could be happening.

And I guarantee you that so many entrepreneurs tuning in are now realizing how big of a deal this is and how little they're probably protected. So what is one thing that, uh, with our cybersecurity, when you're looking at small businesses, where a hacker will say, "Man, this is just way too easy"? Like, what's one thing that entrepreneurs are doing where a hacker's gonna say, "This is just way too easy"?

Abed Hamdan: Hmm. I [00:10:00] mean, there are a number of things, and I'm gonna start with the big business and then go down to the small one. Okay. A really big telltale, even for me as a consultant, if, if a company's hiring me to check their security, the first thing, I go on LinkedIn and I just see who works there. If that organization is sort of mid-size to large size, and I see that they have, like, one person that's called, quote-unquote, "IT person" that's doing everything, this is a sure sign that this person is overworked, probably doesn't have enough time- Mm

to do everything security-wise. So I know there is a high chance that they may not be doing everything they need to do. Um, so that's a quick telltale for me. The other one would be, I'll... believe it or not, I'll go on Instagram, and, um, something I see frequently is a founder says, "Oh my God, we went live last week.

You wouldn't believe it. We expected 200 clients, and now we have 2,000." This tells me that this team is extremely busy. They can barely keep up. Mm. And it's a lot easier to do things with them that, you know, I'll put the time pressure. [00:11:00] "Hey, I'm a customer, and the app's down. Help me. Log into my computer. Do something for me."

This is a really quick telltale. Um, now more than that, there are other things that I wouldn't say small business owners sort of do. Um, used to be more common in the past. So things like not having two-factor authentication or, um, like, old practices that they still exist, but not so much nowadays. So systems- Mm-hmm

have gotten better, thankfully, but as a result, because we have, um, better systems, better IT setups, we can, um, produce a lot faster, and with speed comes compromise. And not just in cybersecurity. You probably have seen it, Hala, where, um, organizations or entrepreneurs or small businesses, they release something, but they haven't done their due diligence from a legal point of view.

They haven't gotten everything reviewed, and they say, "Well, we'll do it after the fact." So these kind of things may have large impact and, in some cases, uh, large consequences.

Hala Taha: Okay. So let's make this a little bit personal. [00:12:00] I wanna understand how you know so much about cybersecurity and hacking, and I learned from studying you that you got into this when you were like a teenager.

And, uh, you were really exploring, you know, how does hacking work, and I'm curious to understand, like where did this all begin? Tell us a story.

Abed Hamdan: Yeah. Uh, I mean, not to show my age, but I'd say I started perhaps late '90s, early 2000s. Uh, and, and at that time, and especially where I was living, internet was new.

It was a novelty. It's the new thing. Um- Mm-hmm ... internet for, for, for those my age, internet cafes were a thing. So you'd go to an internet cafe, you pay per hour, and you start exploring, and there wasn't much to explore. So it really started with, um, chat rooms called the IRC chat rooms, and within that I discovered, well, people were sharing files you can download.

There is music file. That was new to me. Um, and then there was this thing called hacking. It [00:13:00] coincided with me, uh, watching a movie called Hackers. Um, it was- ... early Angelina Jolie movie. Um, it is fiction, but it, it really opened my eye, like, hold on, this is a thing. Like, you can actually do that. So as a teenager, and as you do as a teenager, you start imagining things.

Oh my God, I could, uh, hack an airplane and fly myself everywhere. These imaginary scenarios that are not real, but, uh, like as a 15 years old, this is everything. Um, then, uh, as I sort of, quote-unquote, "do research," start to find movies, I find another movie about someone called Kevin Mitnick, late Kevin Mitnick.

He is the fam-most famous hacker in the world. At the time, there was movie, not just one, I think more than one movie. One was in German, one was in English. Um, of course I watch with subtitles. Um, he, the things he did were incredible. He would hack phone lines. He would jam radio signals. He was on the run by the FBI, and the movies, of course, made it so glamorous.

So all I could think of like, "Oh my God," um, and that was a [00:14:00] time when, um, we would call people on phone line. So I'm like, "Oh, I could hack my friend's phone line. I could do these pranks." So I wanted to learn everything. I'd go to these chat rooms and, uh, at, at the time, Hella, things were a bit different in the sense if you ask for help, uh, people start swearing at you.

You would n-they, it was not a friendly time, unlike today. So I had to learn certain things the hard way. I got myself hacked multiple times, but Long story short, um, I sort of went into the right direction, started learning an operating system called Unix, hence where my nickname came. And, um, actually a fun, um, sort of useful anecdote, my website unixguy.com is few months older than google.com.

So, um, I go way back.

Hala Taha: Wow. So,

Abed Hamdan: yeah. Um, so that's where it all started. Um, then I got my first job, started, uh, studied things at university that were completely useless. Got my first job, but I continued learning, and I still do that to this day. Even after- Mm ... consulting for so many [00:15:00] years, um, I enjoy it. I like to learn.

I stay curious. And, um, experience of course. Uh, I've done this so many times, um, so much so that sometimes I can look at something and, like, have an educated guess that, oh, maybe we can look here. Let's just start this way and take it from there. But yeah, it's been a continuous learning and experimenting journey, and, uh, i- it's, it's a lot of fun.

Hala Taha: Yeah. Your entrepreneurship journey is, like, really interesting, so we're gonna spend time at the end of the conversation and really just unpack how you turned educational content into this entire career and business. And you've done such a great job, like, really owning this niche and this lane and helping so many people in their IT careers, especially in Australia.

So since we have this incredible consultant in front of us, a lot of the people tuning in are entrepreneurs.

We're small business owners. We don't have endless budgets. We probably don't, we have a lot of information that might be vulnerable, but you know, we're not this huge [00:16:00] company. But like you said, that makes us actually pretty attractive. So what are the few things, let's say three things, that we should absolutely not compromise on when it comes to our security?

What should we be investing in and where do we begin?

Abed Hamdan: Yeah, this is challenging, um, because it may slightly vary between businesses, but I'd say the first one, non-negotiable, is always two-factor authentication. Luckily, we live in a day and age everyone knows what that is. So when you log into your email, um, sometimes you get an SMS, says, "Is that you?"

Enter a code. Um, the preference is always to use something like a passkey or the authenticator app. Um, even few years ago, um, this w-wasn't rolled out to everyone. We had to have difficult conversations. But this tends to reduce, uh, the-- it tends to really, really reduce the risk of cyber attacks. Not to zero, but it, it, it's really important.

And within that, no exceptions. So if you have- Yep ... a busy executive or [00:17:00] someone precious in the team that says, "I hate that," um, tough luck. This is a non-negotiable. This is like, this is like having a building and having a fire exit. It, it, it, it's, it's not a conversation that businesses should have, so this should be there, rolled out for everyone.

That's, um, number one. For

Hala Taha: every single platform that we're using or just email?

Abed Hamdan: Um, I would say, okay, but really excellent point. Um, it, it is meant to be for every single platform. However, um, with platforms now, as you log in, Halah, you notice that it tells you, "Use your Gmail to," like, use the same creden- Yeah

like if you log in, you use it. So that, this is called single sign-on, which is essentially you've already logged into your email, your email is trusted, so we use that as a trusted token to get into apps. So that is, that's perfectly fine. You, you're still considered as someone who used that. As long as the app is not asking you for username and password, then you're just entering it and getting in.

If it's asking you to use the email that you've already logged in, that is, this is the same thing. Um, so single sign-on, um, [00:18:00] have made that a lot easier. So instead of having an authenticator app for everything, um, some of them will use your email. However, like even for me, um, my authenticator app is really large, so i-it happens, um, I have it with everything, um, unless I can reuse my email, which is fine.

Um, it's just to get it out, to get us out of just username and password because if the hacker have the username and password, it's game over. So we just make it a lot harder. Okay. The second one, which is also related to credentials, um, is a password manager. So having a password manager, um, is really, really important.

No matter how complicated we make our passwords, um, the human tendency is for us to reuse the password everywhere, and that's extremely dangerous, uh, because- Your company may be secure, not hacked, but the local cinema might get hacked. And guess what? People use their work email and work password to log into the cinema.

So hackers usually when, when we do the reconnaissance, uh, reconnaissance step, when we try to collect information, we actually see if your password is out [00:19:00] there. Doesn't matter if someone have the same name, we try to first use that and see if we can get in. So a password manager, really essential. As a business, have some sort of enterprise solution with these passwords where you have a complex password everywhere.

And they're really convenient because you can have it as part of your browser, so you're just literally just copying the password that, um, that you want to use. This is the second one. Um, the third one, if we just narrow it down to three, um, is our key critical assets we need to understand. This could be customer information, it could be intellectual property.

For example, you're on a podcast, I'm sure you have, let's say, a method to make an amazing podcast. So that's intellectual property. Um, let's say it's in a Word document. I would restrict access to that, and that even includes employees. Um, make it on a need-to-know basis. If someone needs to access it, we ask why.

You get a time-restricted access, but that's it. It shouldn't be free access to everyone. Um- Mm. A- and [00:20:00] that could get more complicated. Like I worked with, um, beverages organization here in Australia, and some of their, uh, intellectual property was recipes for their drinks, and those recipes needed to be in a secure vault with encryption and with really secure passwords.

But also, once you log in and get access to that, you shouldn't have that login indef- um, indefinitely. It should be time-restricted. Mm. So those would be the three things, and if you allow me a bonus one, like I said, similar

Hala Taha: to- Yeah. Give me... I was gonna say, what's the four and five? Because clearly I can tell it's not just three things we need to worry about.

The,

Abed Hamdan: the fourth one is similar to, i- it's just get a professional opinion. For example, small businesses, when they draft a contract, they get legal advice. Mm-hmm. Right? So you get someone to review it, a solicitor. Likewise, with, with cybersecurity, it doesn't have to be something massive. Um, get a small company, preferably something local where you can reach out to them if things go bad and say, "I just...

Look, guys, couple of hours, whatever, $2,000 or could be less, could be more. Check, [00:21:00] make sure we're doing everything right. Give us a recommendation." And sometimes all they do is just check that you're doing everything. You may miss something, so they just give you professional advice that, "You know what?

You're doing 99%. That's perfectly fine." And as the business grow, that sort of consultation or that assessment can grow with you. If you have a software application- Mm ... you're releasing to the market, obviously that needs more scrutiny. But if someone is just, let's say, an Instagram content creator and they just share advice, they may not need that.

I hope that gives small business owners- Yeah ... a, a thing to talk towards.

Hala Taha: It does. And I think, uh, because one of the most important things, like you said, is password safety, and there's some really ... I know Bitdefender, I believe, has- Mm ... uh, like a password feature that you can get, and it's really cost-effective.

Um, but, but you mentioned this thing, this concept, I don't know if you said it verbatim, but it's this concept of least privilege, and I'd love to understand, like, what is this concept of [00:22:00] least privilege? Help, help break it down for the people that not, that aren't in cybersecurity.

Abed Hamdan: Yeah. The concept of, of least priv- least privileges or least privilege is, um, falls under the umbrella of what we refer to as identity and access management.

It really is, um, you have a resource, that could be an application, it could be intellectual property. You want to, you want to restrict access to that, um, and make it so that, um, the individual or the system or the software that have access to that, they just have access to the minimum amount of resource, uh, required for them to do their job with a time restriction.

For example, we go back to, let's say, a customer database. You have a customer database, you have all your clients' details, um, and let's say you have a marketing officer. Marketing officer need to run a campaign, um, for some of those individuals. So what I do is, the marketing officer will only get access to that database, um, for, like, 30 [00:23:00] minutes.

So they get a temporary password, and they will only get access to those individuals, and then the access will get re- um, revoked. This reduces the impact of, um, a cyber attack. For example, if two weeks later this marketing officer gets hacked, well, the hacker wouldn't have access because the access has been revoked.

And you, um, you mentioned Bitdefender. I- they have this, their enterprise, um, suite solution, so they will have that password manager where you can provide a temporary password access to. It can definitely assist with that. Um, but that's- Hmm ... more or less the principle of least privilege. We always, um, assume that for cybersecurity it needs to be this complex, expensive piece of technology, but no, it's really people, process, and technology.

So we start with the process. We just define this is how we access things from now on, and then we enforce it with technology if it's possible. If not, you can even do it manually. Hmm.

Hala Taha: When it comes to customer data, like for example, my business, we don't collect that much data. Like, we have everyone's email, but that's pretty much [00:24:00] it.

So, like, is that really sensitive customer data, or does it get more sensitive when you're collecting people's, like, addresses and their Social Security and, like, that kind of stuff? So it's like, what customer data is the most desirable?

Abed Hamdan: Yeah. This is where, um, there is a fine line between cybersecurity and the legal profession because here we're going into the territory of privacy, or some people say privacy.

Mm-hmm. Depends on how you pronounce it. But this is where we sort of even sometimes consult with a legal professional or a solicitor. Um, email address on its own, it's not really what we refer to as PII or privately identifiable information. Hmm. It, it really is not. Why? Privately identifiable information is something that can uniquely identify you.

This would be your full name, home address, um, date of birth, but also things we don't think about such as, um, sexual orientation, political views. These things c- they can be used against you to target you, okay? Hmm. And within that, there comes a whole [00:25:00] lot of, um, laws and regulations. A simple one that, uh, many people don't know is- y- your business is based in the United States, so you're in the US.

Um, however, if some of your customers are EU citizens, so they're Europeans and their country is part of the EU citizens, and they sort of trade with you, you actually need to comply with a standard called the GDPR, which is the privacy standards for European citizens. So you need to, um, do certain activities to make sure that you're not breaking their privacy, uh, laws, even though you're not really a European Union, um, organization.

Likewise, there is the California Privacy Act, and there is the- Yeah ... China Act. So there is all of these things, and this is where, as cybersecurity professional, we provide advice, but then we, um, we consult with a solicitor. Sometimes could be just, just please review this, make sure our policy is, is up to scratch.

So as far as emails, I would treat it with absolute care because, like I said, it may not [00:26:00] be a, a huge legal liability, but it's very attractive. Um, you know- Mm-hmm ... people on the dark web, they purchase email addresses. They use it for spam campaigns. They use it to scam people. Um, it's a very attractive thing, and even, uh, I'm, I'm not sure if, if you, um, like, have an interest in, say, paid ads, um, email addresses are really attractive to use for paid ads.

So there is commercial value- Mm ... for them, and as a result, uh, we encrypt them. We make sure that our newsletter provider is doing their due diligence when it comes to security, which the majority of the big ones are.

Hala Taha: Mm. So helpful. You're just, like, a wealth of information. So for the entrepreneurs tuning in who still don't feel like there is much of a risk with cybersecurity or still aren't scared enough, talk to us about what could go wrong, like reputation-wise, revenue-wise.

You mentioned earlier that sometimes cyber attacks can be so bad that the business actually has to shut down. I'd love to hear [00:27:00] some examples of the way that these types of attacks can actually impact businesses.

Abed Hamdan: Yeah. And, and, and yeah, we tread a fine line here, Hala, of being an alarmist versus just encouraging individuals and, and entrepreneurs to really, um, really do their due diligence and just-

Hala Taha: Yeah

Abed Hamdan: do what needs to be done when it comes to security. It can definitely be career-ending in the sense, um, the biggest one we've just alluded to, which is breaking privacy laws. Um, there are hefty fines. So the European Union is really strict with fines when it comes to, um, um, the privacy of their citizens.

So a company in the US that's providing services globally and, um, somehow they get hacked and European citizens get their, um, data out there, there might be a big fine, and it can be in the seven figures, and that can have- Mm-hmm ... huge finan- like, direct financial impact. Um, the other one is, um, let's say you have an application and subscribers, and that application gets hacked.

Now what? [00:28:00] Subscribers are paying. They need their money back, and, um, you, you really don't know what to do. Your revenue stopped. So all of these things can and do have, um, significant, uh, financial impacts, um- Mm ... which is a, a good segue to also make sure you have the cyber insurance or talk to your insurance organization and make sure that insurance against cyberattacks is there.

It, it's a sort of controversial topic. Mm. It may or may not help, but it's best to have it than not to have it. Um, so those are things that, um, are important. Uh, there

Hala Taha: are, and if you want- I've never heard of cybersecurity insurance. And then nobody talks about this stuff. So- Cybersecurity insurance?

Abed Hamdan: Yes, I think, uh, it, it really is important.

And look, the, the good news is it-- you may already have it as an example. So y-if you have insurance for your business, depends on, on your provider, you can talk to them and say, is cyberattacks are included under that? And, and within that, that there is a threshold, and there is a limit. And, uh, however, I've had mixed experiences with [00:29:00] cyber insurance.

Um, but to summarize, it's better to have it than not to have it. And- Mm-hmm ... the good insurance providers, usually it's there in the fine print, so it's worthwhile just checking that, that it's already there. Um, the other thing is also, like I said, if, if, if the organization or the business, um, like you had a consultation with a cybersecurity company that's preferably local also, if things go bad, you have them on speed dial, you can call them in and get them in.

So having that relationship also is really help. And they can also give you an advice when it comes to cyber insurance as well. So these things helpful. But w-when it comes to just things going wrong for small businesses, Hala, uh, like I said, it, it, it does go a bit more sinister. And there are things that, um, most of us don't hear about because it's sort of bad news, and the really bad news, we don't wanna hear about it for the most part.

But, um, there, there are cases of extortion. Uh, there are cases, and this is really, really common. So, uh- Mm-hmm ... a-as a small business owner, someone could target one of your employees, and you're kind of [00:30:00] responsible for them, um, because your business got hacked, and it, it's really complicated. And, um, yeah, it, it, it-- the implications are sometimes your employees could be the target, or your customers could be the target.

And as you mentioned earlier, it could also be your brand, um, reputation, and we call it brand equity. Well, if people signed up to your application, it's hot stuff, but the next day everything's hacked, and everyone's complaining, and that, that can, that can be career-ending, unfortunately.

Hala Taha: Mm-hmm. So interesting.

So let's go back to the entrepreneur who has no budget. Now, you mentioned the three to four things that we should pay attention to, but what if I literally had just $1,000 to invest- Hmm ... in cybersecurity? And let's say, I don't know, maybe this isn't just not enough, I guess $1,000 for the year or do we wanna say $1,000 for the month?

Like, what is the bare minimum that we can be spending on cybersecurity?

Abed Hamdan: Yeah. Look, let, let's say we just have $1,000. Let's just [00:31:00] say the business- Okay ... has just started. And look, and th- there is good news here, uh, is that, uh, it, it's not always, like, the amount of money. I think, um, as humans, when we see a problem, like I'm gonna throw money at the problem and make it disappear, uh, it doesn't always work that way, especially with entrepreneurship.

Um, the good news is, um, a lot of the services that we use, Hala, are really, um, built in a solid way. So let's say- Mm-hmm ... if someone is using the G- like, all their email and everything is from Google, for example. They're using the G Suite. Yep. That is an inherently really secure platform if it's used properly.

So if I just have $1,000 and, um, which tells me I'm early in business, I'm an, let's say, content creator, or I have a small agency, this also, I will guess that we're not building an email system from scratch. We're not building ... We're just using popular services, whether it's from Google- Mm-hmm, mm-hmm

Microsoft, et cetera, et cetera. This can be good news. I would honestly get that $1,000 and, like I said, reach out to a local trusted company and say, [00:32:00] "Hey, this is our budget. Can you just give us advice? What can we do?" And they can literally just have one hour, look at your stuff, and just tell you, "You know what?

You're doing everything right. Maybe do this one thing that's, you know, will give you 80% of, of the value." So I would, yeah, I would get a professional, uh, opinion. Like, similar to, I, I think the example of getting legal advice. You may not have the budget to hire a lawyer that works full-time, but all you need is someone to review employment contract.

That $1,000 can do it. Hmm. May not do it, uh, all the time, but, uh, it's better than, um, doing what a lot of businesses do now, which is ChatGPT things and, uh, AI is telling you, "Yep, you're doing a great job. You're fantastic. You're the best thing since sliced bread." So I think just getting a human who know what they're doing is, is a lot better.

Hala Taha: Hmm. I love that. I, I didn't think you were gonna go that way. I didn't think you were gonna say get, like, a consultation and have somebody tell you what you need to be doing. How about a solution like Bitdefender? It's super affordable. I just went [00:33:00] on their website, and it's, like, less than 200 bucks a month to get all these different tools.

It'll, like, scan your Slack and, or, like, your messages for anything that looks like phishing, your emails. It will send warnings if it looks suspicious. So I feel like that's also, like, just a great layer to be adding on.

Abed Hamdan: 100%. And, and like I said, that could be also the outcome of that consultation. They said, "Hey, you're doing everything right.

Now you're ready for an enterprise solution," which, like the one you've mentioned from Bitdefender. And the good news is, uh, the- these things, Heather, they weren't available for us a few years ago. So we are living in a good time where, um, like a company like Bitdefender have something targeted for the enterprise small businesses to medium-sized businesses where, yes, they do scan your emails, so you get rid of them spam headaches.

They, um, they offer you some kind of password manager and monitoring. It's always better to have these things in place. Um, it also, like from a... I, I hate to go that way, but from a legal [00:34:00] perspective, if, you know, things go south, it's also proof that as a founder or as a business owner, you, you're doing your due diligence.

They can't say, "Well, you've done everything, but you still got hacked." That can still happen, even massive organizations. But in this case, you, you will be a victim of criminals who really know what they're doing. They're, you know... Criminals do criminal things, and sometimes we're just victims of that. But that's a different story than someone who, you know, they've done nothing.

There's a really famous story on the news of those, uh, company that created a chat service or something for... Sorry, um, I can't... It's just they created a dating app for women to protect women's- Hmm. Um, it's for women's safety. Bumble. It, it wasn't Bumble. It was, like, an- another app that was created- Ah ... um, with women's safety in mind, but then turned out that that app, b- because it needed to verify women, they took their passport, uh, details and all their information.

Turned out this app was coded with zero security. It got hacked, and it put women's [00:35:00] in, um, safety in, in danger. Oh my

Hala Taha: gosh.

Abed Hamdan: But that's, but that was an example of an organization that didn't do their due diligence. Whereas a small organization, like we said, okay, they've got the consultation. They've got the Bitdefender enterprise security.

They're doing stuff. Well, you do what you can, right? It's like- Hmm ... having a building. You have your fire exits. You have everything. Sure, disasters can happen, but you've done what you can do with what you have.

Hala Taha: Hmm. So you've described cybersecurity as defense in depth. I'd love for you to walk us through what that actually looks like for a normal small business.

How can we practice that?

Abed Hamdan: Yeah. Defense in depth is a concept that surprisingly even, um, cybersecurity professionals can and frequently do get wrong. Defense is, in depth is in a nutshell, having more than one layer of defense stacked one on top of the other. So if one layer of defense [00:36:00] fails, the other one, um, can sustain.

So it just makes it a lot harder- Mm ... a lot more expensive to get to what we call the crown jewel or the important asset. I'll walk you through an example. Let's say, let's say you have your cl- customer database. That's the most important thing that we have. We wanna protect that, and then we have our attacker, and the first thing they do, they send a phishing email.

Okay? So the phishing email comes, but you have your anti-spam filter, so the spam filter block that. So that's layer one of defense. So you didn't even see the email. Their attack failed. Now, let's say a more sophisticated attacker, they crafted their email in such a way that it's even passed that spam, um, filter, and it went into your inbox.

So you looked at it and you said, "Well, you know what? This looks like spam. Sorry, report spam." So the second layer of defense here was your awareness, so that's another strong layer of defense, right? Mm-hmm. Let's say they were, you know, the email came from a trusted supplier. So they hacked the supplier.

They came to you. So you're like, "Oh, this is a legitimate email. I need to do something." You click on that [00:37:00] link and, but when you click on that link, well, your anti-malware solution, your endpoint security system blocked it from being executed. So that's another layer. So it failed here, and that can, you know, go on, go on like for, for longer and, um, but you get the concept, right?

So we have- Yep ... multiple layers of security. Um, in the, in the like late, late '90s and in even early, uh, up to the 2000 and, let's say, 2005, 2010, there were organizations that didn't have firewalls, so they'd have nothing. So the fact that we put one layer was a huge thing. But nowadays, you, you'll find these layers, uh, work in tandem.

This, and it's controversial, uh, I keep saying defense in depth because, um, when it comes to marketing of, the marketing of cybersecurity, people say human is the weakest link. I can have all the defenses, but if s- a human makes a mistake- Mm ... and click on something, it's game over. Well, it's not. As we explained earlier, there are multiple layers of defense, and I say that in defense of the human, in defense of the employee that's overwrote, that [00:38:00] clicked on something.

Sorry. If, if someone clicked on something and it's game over, then your security were fundamentally wrong. Um, so yes-

Hala Taha: Mm ...

Abed Hamdan: the way cybersecurity is approached nowadays, how it should be, multiple layers of defenses.

Hala Taha: Hmm. Okay, let's move on to AI, because I feel like AI is such a hot topic in cybersecurity. How has AI changed the landscape? What is new now that AI is here?

Abed Hamdan: Yeah. Everyone's topic, and I've been labeled sort of anti-AI, which, which is not true.

Uh, AI has definitely made cybersecurity professionals a lot busier because, um, every business now have an AI, and they call us and say, "Hey, is this okay? Is this not okay?" And then we need to go and look. Um, look, it definitely has changed things, and it's here to stay. But also, it's not the sort of doom and gloom and the movie Hollywood things that we read on the news of these AIs escaping and hacking things that this is just, uh-

[00:39:00] marketing. Uh, look, the truth is always a bit more nuanced. Um, AI, I mean, the most obvious one that we all need to be careful, uh, a- and be aware of is the deepfakes. So deepfakes- Yeah ... are huge, huge problems. And I, I know we talk about entrepreneurs and small businesses, but even for children in schools, it's, it's been a absolute nightmare, and law enforcement, uh, deals with that all the time.

So deepfakes, um, faking voice, faking, um, video is something we need to be really careful of. But even as I said earlier, um, you can-- I can really create a website really quickly that looks exactly like a replica of a real one. Now, that wasn't overly difficult before AI, but now it's even faster, if that makes sense.

So, um, in the hands of a skilled hacker, AI can make certain aspects faster. Now, is AI this really advanced thing that's gonna do, go and hack things? That's not true. And, um, the big AI companies have actually, um, sort of safeguards against making AI do these things. There [00:40:00] are ways around it, but let's say if someone is completely unskilled and they're just trying to do something, it's, it's, it's just not happening.

So that's one aspect of it. The second aspect, which is what keeps us busy, is businesses, um, are really quick to sort of wanna use AI. And this is where things get a bit more complicated because when we say AI, so what are we really using? Are we just prompting ChatGPT, or are we giving AI access to everything and making it talk to customers and do finance for us?

Or, or are we even not even using AI, but we have this SaaS service or this product, and then all of a sudden this product on their website says, "We're AI enabled or AI powered"? Mm-hmm. Well, what does that mean? Do you feed our information to your AI? Mm-hmm. Is it going to, um, you know, the AI company, which is really a private company if you think about it.

So all these things, um- Are making life a bit more interesting for cybersecurity professionals and small business owners. So we wanna use AI, we wanna be on top of the new technology, but we [00:41:00] also need to stop and think, what is it that we're using AI for? What does the AI have access to? And more importantly, where's my data going?

Is it going to a private company? Why do I trust that private company? This private company could get hacked, or they could do something like sell my data somewhere. Um, big tech companies- Mm-hmm ... have done that, and, uh, we love to see news, and this big tech company got sued for selling election information.

Well, they don't care. Yeah. The hundreds of millions of dollars fine that they pay, this is just, um, you know, one week's earnings. So these things I think we need to keep in mind when we, uh, when we use something like AI. Just why we use it and how we're using it is, is fundamental.

Hala Taha: Yeah. Well, I think one of the, the new things coming up in AI and cybersecurity is, is for a couple of years, AI was mostly, like, chatting, chatting to ChatGPT, getting help writing emails. But now we've got AI agents that are jumping from tools to tools that are kind of like AI digital employees.

How worried do [00:42:00] we have to be about AI agents and their ability to hack our companies or their cybersecurity threats?

Abed Hamdan: Um, AI, I mean agentic AI or AI agent is exactly what you described, where you have the AI bot, instead of it just being a prompt or a chatbot, you're actually giving it, um, access to stuff, and it can do things for you.

For example, you can program the AI to send an email from your email or have give it access to your calendar, or in some instances it can be, you know, a chatbot on your website. AI agent is something that needs to be treated with absolute, uh, care. Uh, it shouldn't be just, just because it exists doesn't mean we need to use it.

There are many issues with AI agents. The first one is, the obvious one is, is access, where you're giving a piece of software access to things. So we need to assess that access. We go back to the principle of least privilege. Does the AI really need access to everything in my email or does it need access- Mm.

[00:43:00] -to a copy of certain emails? Does it need access to calendars of everyone or perhaps we can create a dummy calendar for certain things and that can access that. So this is the, the first one is, you know, don't, don't be too generous with access. Treat it like, you know, it's just another piece of software.

I don't wanna say- Yeah ... it's another employee. It's an employee or it, it's just really a software. So we don't really give software access to everything just because we can. I think that the, the craze or, or, or the hysteria that we, we face now is, is, "Oh, AI can do this, therefore I need to do-- I need to use it."

No. As a business, do you really need that? And if not, then why? And that could be also costly in terms of tokens and, and we've heard lots of stories of companies paying so much, um, on AI tokens. Um, a famous one of the FAANG companies, they laid off so many employees just so they can afford paying for the tokens and it, it's not always a smart business decision.

Um, this is one. And the, the, the most important one as well is, well, accountability. So as a founder, just because the AI is doing something doesn't mean the AI [00:44:00] is accountable for it. I'm still accountable. So if I get the AI to review my legal contract, great.

Hala Taha: Mm.

Abed Hamdan: The review may be accurate or may not be accurate.

Um, who's accountable? I- if I get into legal trouble, I can't say, "Oh, well, oops, AI did it." No. It, it's still me. So w- we need to really stop and, and think, "Well, I'm still accountable." AI is just software. It's doing something. I'm still accountable. Just like a normal employee. Yes, the employee can make a mistake or so, but ultimately the accountability falls on leadership or on the CEO, or on the board of directors.

So these are the things we need to really be careful about.

Hala Taha: So I do think one of the things that we need to be worried about with our employees and AI is actually we might be rolling out specific company AI tools, but because AI is kind of popping up everywhere, employees are probably using all these, like, disparate AI tools or, like, whatever tool they think is fun, and they're probably using their company computer and thinking it's [00:45:00] harmless.

Is there a risk in people just using, like, not approved AI tools?

Abed Hamdan: Absolutely. And this is not a new problem. We used to call... We, we still call this shadow IT or- Hmm ... unsanctioned software, which is really what AI is, what you just described. We had this problem even before AI. We'd have, let's say, the marketing team, they just found this online tool and they start using it.

They didn't tell everyone, and they put customer data in it w-without sort of the cybersecurity team doing an assessment and saying, "Hey, this is approved. We can monitor, we can do that." Same thing with AI. If we have an employee opening their own personal ChatGPT, putting company information in it, um, yeah, w-we haven't really, we didn't really approve that.

So they did something that the business didn't approve of. Um, it is really hard, and it's, um, it's something that we need to, um, like I said, do our due diligence. We need to have clear policies that say, "Do not put company information into AI tools." Also, the other thing I saw even [00:46:00] in big tech companies where they're really skilled, so they have built a s- different agents to do different tasks, they always have someone sort of verifying and validating the output of AI.

So really skilled programmers, they do this- Mm-hmm ... um, Claude code. They, the AI is review, producing code. Before it goes to production, it needs to be reviewed. It needs to be tested by a vetted senior programmer. Um, a-and s-s-so this way we have safeguards against what goes into AI, but what comes out of AI.

That is really essential. Hmm. Um, there is the other thing, of course, like I said, in terms of privacy and stuff. There is a setting in, in all these AI chatbots that says, um, something along the lines of, "Don't use my data to train AI." I think we should all toggle that, and this way-

Hala Taha: Hmm ...

Abed Hamdan: allegedly our data doesn't go in there.

So that's something that we need to do. But there has been instances, um, a really famous one early days ChatGPT, um, the source code, um, some Samsung employees really leaked the source code. Not leaked, they just posted it to [00:47:00] ChatGPT, and it's a huge problem because ChatGPT will use it to learn, but that source code is massively, massively pricey and important intellectual property that should not have gone there.

Hmm. So these things happened. Um, yeah, so we do need safeguards against who uses AI, what do we use it for, and exactly like any other piece of software, an employee shouldn't be just using random softwares and use it for business purposes on business laptops.

Hala Taha: Hmm. Uh, so I'd like to talk about aside from the technology and AI, the people who actually have keys to your business. Like, a lot of us think that the only way that our business is vulnerable is through a stranger. A hacker is gonna come hack our company. But it turns out that our employees can actually be a really big risk, especially employees, maybe disgruntled employees who have left the business.

Is that right?

Abed Hamdan: Absolutely. Um, the, the technical name we use for it is insider threat. Um, although some people don't like [00:48:00] the word insider threats, like, well, humans aren't threat. Uh, it's, it, it could be, uh, exactly what you said. So one scenario is a disgruntled employee. They know all the business secrets, everything, and they leave, and six months later they decide, "Hold on a second.

I'm not happy with that business. Let's do some damage." Um, and the way we reduce, um, the attack surface, we reduce the impact is back to basics. Um, they shouldn't have access to everything. So wouldn't they hold the key to the business? Well, they need to hold the key to certain aspect that they need for their job, and this way if they do damage, well, that damage is restricted.

That's, that's one. Two, a common mistake, um, that happens even with large businesses, in fact probably more with large businesses than smaller ones, is when someone leaves, we call it the off-boarding process, they don't take all of their access out, so they may still have access to certain applications or certain things that they log into.

So that's a problem. So we need to have a process of just like we onboard employees, we need to know how we off-board them, and that includes revoking access. [00:49:00] Um, the third one is also in our contract legally. Uh, we need to say that, you know, if you leave, um, please don't go on social media and just spill out all our secrets.

That's illegal, but having it in the contract- Mm-hmm ... doesn't hurt. Um, there's been many instances o- of that happening. A really popular one, a big tech, um, Australian organization that has, um, laid off people, and they laid off one of their very senior software engineers, and the next day he creates, I think, a one-hour YouTube video explaining everything he's done, um, for them, everything he's built.

It's online. It got millions of views. So yeah, that, that's really valuable information that the employees spilled out and you, you know how awkward it is for an organization to legally go after someone. So these things we need to be careful of. Um- The insider threat, there is other aspect that we forget when it comes to insider threat is, um, the employees are humans, they make mistakes.

So I-

Hala Taha: Mm-hmm ...

Abed Hamdan: even early in my career, as an example, I made a mistake early, [00:50:00] early in my career. Um, as I was going, working faster and faster, I ended up deleting stuff that were really important files, and I did that by mistake, and I had to go find backups and restore backups. So- Mm ... mistakes can happen. It could be a really genuine, um, unintended mistake, which again, goes back to why did I even have access to that stuff?

Why was I able to delete without someone looking over my shoulder, without, um, a chain of approvals? All of these things that sometimes we may think of as tedious or unnecessary. We wanna be fast, we wanna be lean. Well, there is a cost that comes with that.

Hala Taha: Hmm. This has been such a valuable session. Like, I feel like I've gotta, like, do so much work and make this, like, a core initiative for my business.

If you're a hacker, please leave me alone. But, um, I wanna talk-- I wanna play a game with you. It's called Find the Backdoor.

So I want you to find the back door, I want you to break it down, and then close the back door. So basically, how can [00:51:00] somebody hack this company? I'll give you a scenario. And then how do we actually fix that? What is a solution to that?

Okay, so the first one is the media company. The company works with freelancers around the world. Some use personal laptops and personal email accounts to access company files Where's the backdoor?

Abed Hamdan: There are about three backdoors in here. Um, the first one is offshore employees. Um, you need to vet those employees, especially if they have access, so have some kind of vetting process, and that could be something as simple as use an agency that does the vetting for you.

So make sure they're, you're not hiring criminals, just as a, a, a, as a basic sanity check. Um- Mm ... the second one, of course, um, if you can't give them laptops, uh, then restrict what they can access. Absolutely restrict what they can access. [00:52:00] Don't give them what we call as a write... So read access may be, um, less damaging, but write access, which gives you the ability to delete stuff, that, that should absolutely be restricted on a need-to-know basis- Excuse me, with strict approval processes.

The fourth one is a personal email address. This is a huge no-no because when they leave the company, um, they own the data. That's, it's on their email. So if there's anything sensitive, they'll take it with them, and that's precisely why organizations have emails on the company domain, because the company owns that.

As soon as they're using personal emails, well, they own the data, so you're really handing over their data, and you're as vulnerable as any one of them. One of them could be criminal, one of them could be hacked, or y- you just really don't know, so you're overly exposed. If you want to use f- offshore employees or contractors, really restrict them to a very specific task, and have in mind that [00:53:00] if that person gets compromised, what's the impact, and do I accept the impact and consequences?

If no, then find alternatives.

Hala Taha: Um- Yeah ... okay. The fast finance team, this is the next scenario.

Mm-hmm. The founder and the finance team approve urgent payment requests through Slack because it's faster and more convenient.

Abed Hamdan: Yep. So w- any- anything that we do fast, it's-- it just means we're gonna make more mistakes. So with speed- Mm. -that compromises more mistakes. Um, yeah, a big, a big really, um, red flag here is approving things over Slack.

Shouldn't happen this way. We need to have a chain of approval that's really clear because, um, the strong use case is if one of your employees gets hacked and they have, um, their account gets hacked, so the hacker is using their, your employee's account, and well, everyone have access to Slack, they're gonna ask you to approve something, and fast means you're just gonna approve it.

Um, so that's a call for disaster. You, you will, you will lose money, so that's what you're compromising. So you need to have... The fix for that is have a [00:54:00] proper approval process. Um, and that approval process may just mean you-- it will take an extra five minutes. It's not really- Mm. Uh, uh, it's not really war and peace.

It's, it's, it's literally just a proper approval process that will save you a lot of headache and will save you time in the long run.

Hala Taha: Yeah. And potentially a lot of money. Um- Exactly. Okay. The last one, the last scenario: the SaaS-heavy e-commerce brand. The company uses dozens of third-party applications connected to customer and payment information

Abed Hamdan: That is, uh, e-e-e-that everything is wrong with this.

Uh- Th-th-this, this, this is a dangerous one. Uh, surprisingly very common, Heather. Okay. The first one is, uh, w-when they use, uh, so many SaaS applications, um, what, what people don't know is that there is, there, there is like r- I wanna say the correct term here, but you need to know who owns that SaaS service [00:55:00] because there have been cases where it's foreign government operating from a different country, having g-this amazing- Mm-hmm

SaaS application that does amazing things, and it's surprisingly cheap. Well, the purpose of the application was to collect information. So you need to really vet and know who you're dealing with. So the first thing is, we call it supply chain management. Supply chain meaning your suppliers, in this case is your SaaS providers.

Just make sure you know who you're doing business with n-instead of just- Mm-hmm ... randomly signing up for things because they are, quote-unquote, "cheap and fast," and they, they do their job. So, a-a-and because it's a legal liability, if you're leaking customer information to somewhere that shouldn't go, that's a huge problem.

This is one. Um, two, again, know who you're dealing with. A small SaaS app, what if one of your providers get hacked, and they have access- Yeah ... to all your customers? So, and therefore, once you know who you're dealing with, the second one is manage access. Why do all of them have access to everything? Really common in the real world, sadly.

But manage your access. Again, need to know- Mm ... basis, least privilege, all these really timeless principles, [00:56:00] meaning you restrict access. I'm pretty sure that business, whatever it is, doesn't require everyone to have access to everything. The only reason why businesses usually do that, where they give everyone access to everything, is l-just lazy.

They just, it's easier. Yeah, convenience. They just tick everything on and, and that's a call for disaster. So that, these are the two fixes. Manage your supplier is number one. Number two, manage your access.

Hala Taha: Yeah. I love those principles. I'm sure everybody tuning in is learning so much and getting so many ideas of, like, where they need to start first.

Let's say, unfortunately, our company gets hacked. What is something that we shouldn't do? We get hacked- Mm ... somebody just stole a bunch of money from our bank accounts. What shouldn't we do in that moment?

Abed Hamdan: Uh, really difficult, because the first reaction that happened to all of us, myself included, we panic.

And to tell someone not to panic, it's unreasonable. So I'd say panic, but don't act. It's just [00:57:00] like y- you know when, I'm, I'm sure as an, as a business owner and even as someone on the internet, um, sometimes we get angry, and, um, the advice is just don't reply to an email when you're angry, or d- don't take action.

Mm-hmm,

Hala Taha: mm-hmm.

Abed Hamdan: Just, it's like, just sit back. It happened. It's a problem. We're gonna deal with it in a, in a systematic way. So I'd say the first thing is, um, don't interact with the hackers, don't reply to emails. Just leave everything as it is. And in some instances, I'd say don't actually close the laptop or don't disc- Leave everything as it is.

Reach out to an expert right away. And there is levels- Mm ... to that, so reach out to law enforcement. Um, that, that, it's a sort of contested thing to do because usually law enforcement are, um, sort of overworked, underfunded, and may not be always be able to help, but you'd be surprised. Law enforcement can help.

Um, having that, uh, consulting company, sort of you have them on speed dial, you have their number. Get an expert right away to do it. Um, that's the, the, that's the most important thing. But the biggest one is what we said earlier, do not interact with the [00:58:00] hackers, because the first thing they will do is try to get more access.

So they'll say- Mm ... "Ah, sorry, a mistake. I'll just do this one more thing," because they're trying to get as much, uh, foothold as possible. So don't interact with them. They're really skilled at getting you to do what they want you to do, and they're gonna use the fact that you're panicking, um, to their advantage.

So yeah. Mm. Disconnect, completely disconnect. Get an expert to deal with it right away. Like, don't take actions. And the worst thing that businesses do is they'll have, like, an IT support person who's really, they don't have the expertise, and they're like, "Okay, go deal with it." And that person end up being, um, ends up making things a lot worse.

So I think this is the big- Mm ... no-no. Get some, get an expert to deal with it right away.

Hala Taha: Mm. Such great advice. Abed, this has been such an awesome interview. Before we go, I do wanna talk to you about your entrepreneurship journey, your business. So you actually started creating content, and you've created a business out of educating people, and it all started because people would just ask you [00:59:00] questions, your colleagues would ask you questions, and you just wanted a way to not have to answer the same thing over and over again.

So just talk to us about your story, how you ended up growing this content business, uh, how you make money today, and hopefully you can inspire somebody else who's a thought leader in their space to become a content creator and start their own business too.

Abed Hamdan: Yeah, absolutely. I mean, it's, uh, it's funny, I still don't think of myself as a business or even a content creator.

But, uh, the story started, it was during the lockdowns and, um, I was working at PwC, which is a consulting firm, and as a senior manager, part of our job is to coach, um, consultants and senior consultants. So I'd have these, um, um, one-on-one calls with them, and I'm... I really don't like, um, Zoom or online meetings, so I prefer it to be in person.

And I remember one day I had, like, three or four back-to-back calls with junior consultants, and they were asking exactly the same question over and over. So I got this idea where I'm like, "You know what? I'm [01:00:00] just gonna film myself answering those questions, and I'm just gonna send it to them so they watch it."

And I just put it on YouTube as somewhere to upload the video on, like, not as a sort of discoverability platform. So I thought, I thought no one would find it. I thought it's, um... Like, I, I watch YouTube, but it didn't occur to me that the video that I will put, strangers will, uh, will watch it. So I send them, uh, I told them, "Before you do the meeting, just watch this video, and then you can ask your questions."

And I left it, and then I think months later, or so, I saw, oh, there was comments and likes, and there's strangers watching it. I'm like, "Oh, well, let's just answer more questions, I guess." And I started answering them, and it wasn't, like, it wasn't a sort of a business or I had no idea that YouTube pays you money.

And while it's- Hmm ... it's a small amount, but I didn't, I didn't know that was a thing. And when I got the first paycheck from YouTube, it was, like, 50 bucks. I'm like, "Oh, is that a mistake or, like, how?" What happened? I didn't put two and two together. It's not the universe that I'm a part of. I had no idea. So that was YouTube.

But then [01:01:00] I started getting messages from people and individuals, like, from all over the world. Uh, and the first one was, like, I could see in the picture it was a dad and kids, and it's like- commenting on my videos. He was somewhere, um, in an African country, and then he's like, "Actually, I got a job." And for him, a job is-- they changed their life.

So got a full-time job, completely new field, highly paid, so it improved their life. And then it started to spiral. I started getting these success stories, either in a comment, sometimes in an email, saying, "I actually followed your advice. I got a job. It changed my life. Thank you so much." And the more I posted, the more, um, I get nowadays, every time I look in my inbox, there's at least one message a day from someone somewhere in the world says, "Actually followed your advice."

Um, which my advice is really just do these practical things, learn and apply yourself, and you'll get a job. It will take time. It's challenging, but it's possible. Um, so this really gave me the drive to continue. I felt that, um, I was making a difference, and I felt that, um, I just felt responsible. I felt [01:02:00] responsible that people watch my stuff now.

I need to give really the most accurate advice. I need to do, um, do what I can. Um, time management became really difficult. My job, um, is really, really demanding as a consultant, um, but I enjoy it. And because I do it, been doing it for so long, um, uh, it- Mm-hmm ... like, it doesn't require a lot of thinking from my end.

So I was able to manage, but then I've always wanted to do consulting on my own. So I started a cybersecurity consulting company, and I have, um, long-term clients. So I'm active in the field. I do that, but at the same time, I create YouTube videos. Um, I'm not very good at, like, creating a lot of content, so I, I'll create one video a month.

Really, that's my average. So in, in- Mm ... twelve months I'll have, like, thirteen, maybe fifteen videos of YouTube. That's all I can, I can do. Um, within my advice, 'cause cybersecurity is a range of jobs, it's not just one job. There was one niche in cybersecurity called governance, risk, and compliance. At the time, I didn't feel comfortable recommending what was in the market, so I thought, "I'm gonna [01:03:00] take three months and just try to create something."

It took me a year and a half, and I created my- ... uh, certification, got it accredited, and I just put it out there and, um, and thank God it's been, uh, it's been really successful in the sense, uh, people started doing- And

Hala Taha: that's the GRC Mastery, right?

Abed Hamdan: Yeah, yeah. And people started recommending it to each other through word of mouth.

So every time I go to a conference and someone says, "Hey, someone did it in the team," then all of us did it in the team. So i-i-it's, it became that. So really, my time now is split between consulting. I help, um, usually large organizations. I've got long-term relationships with them. Um, I do have some consultants that work under me.

Um, and yeah, the occasional YouTube video where I talk about what's happening in cybersecurity and how to land a job.

Hala Taha: It's great. You get, you g- you got a full plate of clients, you have a team, and then you're able to create content and give back.

I mean, that's an incredible career that you have. So, um, okay, let's bring it back to cybersecurity [01:04:00] and wrap this up. So if you're a young entrepreneur listening right now, what are the three things that we should do tomorrow morning to protect our company?

Abed Hamdan: Um, number one, two-factor authentication. Use your authenticator app or a passkey.

This is a non-negotiable, no exception. This includes all of your employees. Uh, number two, a password manager. I know it will take you some time to get used to using a password manager. I can promise you it, it's a lot more convenient for you and your team to use a trusted password manager. It will save you time in the long run.

It will save you so much headache. And- Mm ... number three is, we talked about it a lot, is manage your access. Just because someone works for you doesn't mean they need to have access to everything in your company. Provide this access, give them access only to the things they need and no more, and have fun as an entrepreneur.

Hala Taha: Amazing. Beautiful recap. Thank you so much, Abed, for spending time with us on [01:05:00] Young and Profiting podcast.

Abed Hamdan: Thanks for having me, and thank you so much for your time. This has been an absolute pleasure

Subscribe to the Young and Profiting Newsletter!
Get access to YAP's Deal of the Week and latest insights on upcoming episodes, tips, insights, and more!
✔Thank you for Signing Up
We respect your privacy. Your information is safe and will never be shared.
Don't miss out. Subscribe today.
×
×