Lice Aunties: “You Don’t Get Selected … You Get Found”

Share this post

Tales from the Click

Well, it’s that time of year again. 

The time when the Black family pays its annual visit to the unnervingly-named, “Lice Aunties,” a local clinic with a specialization in lice and lice egg removal.

How do they do it? 

With an hour of specially heated air, a technique that is head and shoulders (pun intended!) above the old fashioned approach of pesticide shampoo, a fine-toothed comb, and three hours of your daughter crying.

The fact is, Mrs. Black had our two kids prescheduled for the day they came home from camp last week for a preventative lice check. After the disastrous summer of ’23 (don’t ask), she takes no chances; we visit the Aunties before the kids even set foot in the house.

But Rob, are your kids prone to getting lice in the first place? 

No. Which is part of the problem. 

Unlike other common camp activities in which poor choices can often be corrected before they occur – eating too many s’mores, walking barefoot in fungus infected showers, forgetting the sunblock – lice doesn’t work that way. 

The lice aren’t “hunting” my kids in particular and it has nothing to do with their behavior. Rather, as the Lice Aunties say, “You don’t get selected, you get found!”

In this way, lice and many cyber attacks are similar. Because while it’s unlikely your company is being targeted specifically, you still represent an opportunity for “feeding.”

No Company Is Too Small to Monetize

Targeted attacks against small companies are rare. No adversary is building a dossier on you, studying your org chart, or waiting for the right Thursday to strike.

But it doesn’t matter – attacks against small companies are opportunistic and mostly automated.

Your company converts to cash in at least five different ways, none of which require you to be either large or important … but any one of which can force you out of business, permanently:

  • Your invoices. “Business Email Compromise (BEC)” refers to an attacker getting into an email account and redirecting a payment. One changed wire instruction on a real invoice from a real vendor moves real money, making it the single highest-return attack against a small company.
  • Your operations. Kidnapping in the physical world is labor-intensive; the bad guys understandably go after people with a lot of money. But ransomware attacks are automated, making everyone a target. The only difference between an attack on a 40-person company and a 4,000-person company is the size of the ransom demanded. Provided it’s a number you can plausibly pay, attackers get what they can get from whomever has left themselves unprotected.
  • Your customer list. If you sell to Big Co., you hold credentials, a network connection, or an integration into an environment worth far more than yours. Your smallness is the feature – you’re the door nobody is watching.
  • Your infrastructure. Some attackers want nothing you own. Rather, they want your cloud hosting account to mine cryptocurrency on your credit card, your mail server to send spam that inherits your good sending reputation, or your website to host the phishing page that catches someone else.
  • Your employees’ identities. Payroll records, W-2s, and HR files support identity theft and tax fraud, whether you employ 20 people or 20,000.

What’s the Solution?

Cyber attacks are a business. Your goal is to raise the cost of going after yours, so that attacking you requires more sophistication and more human intervention, until it’s no longer worth it. 

So look for things you can do to make yourself a more expensive target…

  1. Turn on Multi-Factor Authentication (MFA), a second proof of identity beyond a password for email, remote access, and every administrator account (with no exceptions for executives). This thwarts a “password spraying” attack.
  2. Verify changes to bank information. Create a company rule that any changes to a vendor’s bank details must be verified by phone, using a number you already had on file (never from an email).
  3. Test your backup process. Ransomware only works if you don’t have a recent, up-to-date backup of your critical files. Restore a file – today – to make sure your backups are working as they should.

These are just three things. There are probably 25 more you could put in place, none of which require a budget conversation. 

But like the old joke about two guys running from a bear, you don’t need to outrun the bear … you need to outrun the other guy. The further you can move from the “cheap and easy” pile, the less attractive you become relative to the company next door.

Get Somebody to Take a Look

Last week, the Aunties handed the Black family a clean bill of health. That lets us rest easy, knowing an expert has looked and made any corrections necessary.

If you want someone to review your environment with the same care and concern, give us a call and we will be happy to take a look. (Crying optional.)


Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click!

Rob Black
Rob founded Fractional CISO in 2017 and has helped dozens of mid-size SaaS and technology companies improve their security posture as a vCISO. He consults, speaks, and writes on IoT and security. Rob has held product security and corporate security leadership positions at PTC ThingWorx, Axeda and RSA Security. He received his MBA from the Kellogg School of Management and holds two Bachelor of Science degrees from Washington University in St. Louis in Computer Science and System Science and Engineering. He is also a Certified Information Systems Security Professional (CISSP).

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales