Security CPR (Cloud Burst Ep. 01.03)
Sept. 16, 2024
Sept. 16, 2024
As small and midsize businesses (SMBs), we face tough decisions around cybersecurity and cyber insurance. We need to balance the cost and impact of cybersecurity measures and our cyber insurance coverage and premiums with our needs, priorities, and budgets.
You can take simple, affordable steps to improve your cybersecurity and lower cyber insurance premiums.
In this Coffee & Clouds online event, Cumulus Global CEO Allen Falcon shares 5 questions to ask your IT service provider. Leveraging analysis from our cyber insurance partner Datastream, Allen shares a set of basic, affordable actions you can take to improve your cyber insurance coverage and lower premiums.
Invest 15 minutes to understand how to improve cybersecurity and cyber insurance. Join us live or view the recording on-demand, and the Dunkin’ or Starbucks is on us.
[av_vide
o src=’https://youtu.be/ANcn7MmMRZ0′ mobile_image=” attachment=” attachment_size=” html5_fullscreen=’aviaTBhtml5_fullscreen’ format=’16-9′ width=’16’ height=’9′ conditional_play=” id=” custom_class=” template_class=” av_uid=’av-kt41j3′ sc_version=’1.0′]
Sept. 9, 2024
![]()
In the last 72 hours, our clients have reported an alarming increase in threatening emails. These emails contain enough personal information to legitimately trigger worry, fear, and in some cases, panic.
This post covers three types of threatening messages and how to respond.
This type of attack is known as a “Exposure Threat” or “Fear of Exposure” attack. Attackers threaten to release embarrassing or sensitive information about you or your business. They may share bits of information or make claims that imply or confirm that they really do have some information.
Here are three common forms of the threat:
The email arrives in your inbox from what looks like a “legitimate” Gmail, Yahoo!, or other email service. The subject line contains your name or that of a family member. The message includes your full address and a valid phone number. In some cases, this threat may also include a picture of your home or office.
Most often, this type of email does not include any explicit threat or demand.
The implication “we know where you live” is intended to instill fear. The goal is to make you more likely to respond and cooperate with future threats.
This form of attack claims to have documents, images, or video of you doing something embarrassing or illegal. The attacker will claim to have access to your email account, or all of your contacts, and will threaten to share the information if you fail to pay a ransom.
This is an explicit form of extortion.
The attackers are betting that the fear of exposure will cause you to pay the demand and prevent you from reporting the attack.
This form of attack threatens to disclose sensitive information about you, your business, or your customers. The threat is the damage a data breach causes. This can include serious and costly legal, regulatory, or contractual issues. The attackers may share a sample that “proves” they have the information on hand.
This attack typically includes a specific threat and an extortion demand.
The preview information shared by the attackers may be from sensitive files, but it may also be available from other sources. This form of attack warrants some investigation.
First and foremost, do NOT panic. The success of these attacks is dependent upon your fear and your reaction. If you receive an email that is like one of these cases or similar, how you respond can make a difference.
You can protect yourself and your business from these attacks, and other cyber attacks before they happen. Our Security CPR® managed security model and services provide a guide.
For help assessing your current cybersecurity protections, please send an email or schedule time with one of our Cloud Advisors to discuss our cybersecurity assessments and solutions.
Christopher Caldwell is the COO and a co-founder of Cumulus Global. Chris is a successful Information Services executive with 40 years experience in information services operations, application development, management, and leadership. His expertise includes corporate information technology and service management; program and project management; strategic and project-specific business requirements analysis; system requirements analysis and specification; system, application, and database design; software engineering and development, data center management, network and systems administration, network and system security, and end-user technical support.
As small and midsize business leaders, we understand the need to comply with regulatory and industry requirements. We also want and need our IT services to support our business priorities and fit within our budget. So how much cybersecurity is enough? Our cyber insurance partner, Datastream, analyzed policies and coverages for nearly 8 million businesses across dozens of industries globally. The most common cyber attacks exploit weak credentials, human behavior, and out-of-date software to gain access to your systems and data. From there, they can not only launch ransomware attacks, they can initiate business email compromise and other costly and damaging attacks. The result: Datastream identified a bare minimum set of 5 cybersecurity standards
To address the most common and costly forms of cyber attacks, implement these 5 cybersecurity standards.
MFA requires a secondary physical authentication when logging in. Whether by text, authenticator app, one-time passwords, or magic links, MFA can prevent attackers from using compromised credentials. According to studies by Microsoft, more than 90% of cyber attacks can be blocked if MFA is in place.
While the minimum standard is coverage for email access and remote network connections, we recommend using MFA for access to any and all critical systems, applications, and data.
Do you encrypt all sensitive information at rest, including backups?
Most of our systems and applications encrypt data in transit (in motion). Encrypting data at rest, regardless of where it resides, prevents your data from being easily accessed and used in a cyber attack. Encryption should be in place on workstations and personal computers, not just on servers and in cloud-based services.
Just as important, backups should be encrypted. Unencrypted backups provide cyber attackers with easy access to data. Backups should also be stored off-site or in the cloud using immutable storage. This strategy prevents corruption of backup sets in the event of a ransomware attack.
In the last 6 months, has your company tested its ability to recover all business-critical data and systems within 10 days or less, from offline or cloud backups that are no more than a week old?
Backing up data and systems is easy. Recovery is hard. Knowing that you can reliably restore your data and systems demonstrates your level of protection and how well you have reduced risks. Documenting this will impact your cyber insurance premiums.
While the 10-day recovery window is a minimum expectation, it may not be sufficient for your business. We recommend analyzing your business needs and setting goals to return to operations in a way that minimizes the impact of any disruption.
Do you implement automated hardening policies?
Hardening systems is the process of limiting the attack surface of your systems, applications, and data. Hardening tactics include:
The process of configuring and managing hardened systems is easiest to manage with a remote monitoring and management (RMM) system in place.
Do you apply critical patches and updates to key IT systems and applications within two months?
Updates and patches to operating systems are familiar and comfortable. We regularly receive and apply updates to our smartphones, laptops, and desktops, most often as part of a default, automated process. We may not, however, be as diligent with our business systems and applications.
Updates and patches to databases, applications, and other software often require validation and may require changes to settings and integrations. Regularly reviewing updates and patches, and having a process in place to verify and apply updates, ensures that your systems have current security fixes and features.
Having these five cybersecurity standards in place represents a no-nonsense minimum that protects your business and can improve your cybersecurity coverage and premiums.
Our eBook, Cyber Security Requirements for Cyber Insurance, dives deeper to define basic, preferred, and best practices. You can, and should, scale your cybersecurity to meet your business’s specific risks, priorities, and budget.
We offer multiple assessments to help you understand and benchmark your current cybersecurity.
These assessments are free with a Referral Code. Contact us or schedule time with one of our Cloud Advisors to learn more and obtain your code.
Help us keep the ideas flowing. If you have any blog posts that are leadership thoughts you want to share, please let us know.
Allen Falcon is the co-founder and CEO of Cumulus Global. Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America. Starting his first business at age 12, Allen is a serial entrepreneur. He has launched strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.
eBook | Source: Cumulus Global — This eBook presents the minimally required, recommended, and best practice cyber security components for small and midsize businesses seeking appropriate and affordable cyber insurance.
July 16, 2024
(6/18/24) – For many of us, ensuring we have the right security and compliance program in place remains a challenge. A basic understanding of security and compliance will inform and guide your security priorities, plans, investment, and results.

As small business owners and leaders, you carry the responsibility for the direction and success of your business. And while Cumulus Global provide managed cloud services that help you thrive and grow, we understand your responsibilities are broader than just IT. As a way to share some leadership thoughts, here is a curated list of blog posts from trusted experts that we hope will inform and inspire.
A few of our past IT leadership thoughts that remain true and relevant today.
Help us keep the ideas flowing. If you have any blog posts that are leadership thoughts you want to share, please let us know.

A recent online post pointed out that the whitespace in the FedEx logo, between the “E” and “x”, creates an arrow.

Once you see the arrow, you cannot miss it. You will see it every time you look at the logo.
The subtle, almost subliminal, arrow symbolizes a sense of forward motion and subconsciously reinforces the FedEx brand message of on-time delivery.
The power of the logo is not just the name, it is in the symbolism. The same is true for your cybersecurity.
The power of your cybersecurity is not just in the overt actions, success is in the whitespace.
Our cybersecurity efforts often focus on the concrete measures we can take to protect ourselves and prevent attacks. We deploy hardware, install software, and configure settings to both passively and actively protect our systems, data, and people. These actions are tangible and visible.
Equally important, if not more so, are the less visible cybersecurity efforts– your cybersecurity whitespace. Ask yourself these questions:
Successful cybersecurity includes the visible and the whitespace. Our Security CPR® model and managed security services include all three best-practice pillars:
If you have not done so recently, now is a great time to step back and assess your IT services and solutions. Our Cloud Advisors are ready to help and assist with any questions or concerns. Start with a complimentary Rapid Security Assessment, contact us, or schedule time with one of our Cloud Advisors.
Allen Falcon is the co-founder and CEO of Cumulus Global. Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America. Starting his first business at age 12, Allen is a serial entrepreneur. He has launched strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.

4 Bellows Rd / 2nd Floor
Westborough, MA 01581
PO Box 1129
Westborough, MA 01581-6129
120 W Trinity Pl
Decatur, GA 30030
