Russell Mickler Russell Mickler

Defending Against Social Engineering Attacks

Is your small business safe from social engineering? Cybercriminals frequently bypass complex firewalls by targeting your employees instead. To protect your business from costly manipulation tactics, implement this practical, four-step playbook designed to help your team recognize the signs, protect critical data, verify unusual requests, and report threats immediately.

Small business owners and managers are highly sought-after targets. You’ve got access to your company’s most valuable assets: financial accounts, proprietary data, and employee information. Cybercriminals know this, and instead of hacking your firewall — which is technically difficult — they often try to "hack" your people through social engineering.

Protecting your business requires a practical, structured approach to spot and stop these manipulative tactics. Use this four-step playbook to train your team and secure your operations.

Step 1: Recognize the Signs

Social engineering relies on deception, but attackers almost always leave clues. Train your team to look out for:

  • Urgency: Demands for immediate action or threats of severe consequences (e.g., "Pay this invoice now or your service will be terminated").

  • High-Value Requests: Sudden solicitations for sensitive credentials, employee tax forms, or wire transfers.

  • Odd Anomalies: Unexpected or out-of-character emails from known vendors, clients, or even executive leadership.

Step 2: Protect Personal & Business Information

Attackers research your company online to make their scams look authentic. Implement a strict "need-to-know" culture. Employees should never share financial data or passwords over email or phone. Additionally, caution your staff about oversharing operational details on social media, as bad actors use these details to craft highly targeted phishing lures.

Step 3: Verify Before Trusting

Never take a high-stakes digital communication at face value. If an email looks suspicious — or requests an unusual financial transaction — verify the sender’s identity using an alternative, trusted channel. Call the client or vendor using a phone number you already have on file, not the number listed in the suspicious email. Check carefully for misspellings, slightly altered domain names, or incorrect logos.

Step 4: Report and Alert

If an employee spots a threat, train them to act immediately. Establish a clear internal protocol: gather all information about the incident, report it to your IT support team right away, and alert colleagues so they don't fall for the same scam.

Don’t have an IT support team? I’m just a click away.

R

Read More
Russell Mickler Russell Mickler

Email Security for Small Businesses

Phishing attacks are getting past traditional antivirus. Learn why your small business needs an advanced layer of Email Security—before it hits the inbox—and how a new AI-powered solution can protect your data and prevent financial loss.

Another Layer of Security

I’ve recently added Email Security to my Endpoint Management (EPM) menu of services.

I’ve come to believe that the email vector requires more advanced filtration.

Traditionally, antivirus products (including my own) detect suspicious files “after the fact.” By the time the AV solution can examine the file using its heuristics, the file’s already been downloaded and put on the user’s hard drive. By then, the suspicious file had already defeated a number of safeguards:

  • The safeguards on the mail server to detect and classify the email as a threat or spam were defeated.

  • The behavioral safeguard failed (the end user didn’t consider the file suspicious and downloaded it anyway, or, they processed a malicious request to transfer funds or give up a piece of confidential information).

  • The safeguards on the mail client (Gmail web interface or, say, a thick client like Microsoft Outlook) were defeated.

  • The antivirus product didn’t have time to scan the file locally before removing it from their downloads folder (since scans run periodically and the user typically accesses downloaded files immediately).

So, on a Windows PC, the last line of defense is heuristic scanning by Windows Defender and a 3rd-party antivirus product, which provides no protection against zero-day attacks. But that’s if the email contained a MIME attachment (a file) at all.

Even with aggressive spam filters and threat detection enabled at a high level on the mail server, I’m increasingly seeing more dangerous content slip through, threatening my user community, primarily from phishing attacks (emails sent to users that look legitimate, convincing the user to transmit money, or, execute a payload by downloading an infected PDF).

Phishing Attacks

Phishing is an evolving, critical challenge that exploits human behavior. The attacker uses social engineering to deceive users, making detection difficult. I’ve always felt that combating phishing is more behavioral (I’ve convinced users to forward suspicious emails to me if they’ve questioned their validity), and that process helps train people to spot suspicious attributes. I’m still here for that — any client that wants a second opinion on an email can always ask for my advice at any time.

Increasingly, though, I’m seeing my clients hit by phishing scams. Most small businesses have limited resources and time. What they need is a practical, cost-effective solution that renders that opinion at the mail-server level, that screens the email before it hits the user’s mailbox.

My Solution

Complementing my EPM programs, I’m now offering Email Security for Google Workspace and Microsoft 365. It stops phishing attacks with an adaptive AI that combines machine learning, behavioral analysis, and human intelligence, and is managed alongside my existing consoles (giving me instant insight into potential threats). Benefits:

  • Adaptive Email Threat Protection: My solution prevents email attacks with anomaly detection and crowdsourced threat intelligence from 16,000 security teams. It continuously adjusts to new threats with intelligent, self-learning protection.

  • Set up in Seconds: I can deploy and configure easily with just a few clicks for native API integration with cloud-based email providers — no MX record changes, no agents, no separate console. Easy-peasy.

  • Unified Endpoint and Email Security Management: It combines endpoint and email security in a single console for easy monitoring, detection, and response.

  • Rapid Auto-remediation: It accelerates response time with machine learning-based detection, classification, and remediation.

Who Is This For?

I’m thinking anyone with a compliance obligation (HIPAA, GLBA) offers the greatest incentive to implement this form of control. The price of civil penalties certainly outweighs the cost.

Companies that manage classified information (Accountants, Medical Practitioners, Attorneys) would want this kind of control to reduce the risk of inadvertent sharing with others.

Anyone who’s been bitten by a phishing attack — they accidentally transferred money to someone they shouldn’t have; they gave up their credit card to a 3rd party; they downloaded a file that granted another party access to their computer; they inadvertently fell victim to a support scam. They’re likely to be attacked again. Further, they’ve been there —they know what that felt like —and the price of the safeguard seems super cheap compared to the risk.

But it’s also for anyone who wants to proactively prevent this kind of thing from happening to them. Phishing attacks are becoming increasingly sophisticated, and I’ve come to believe that relying on human behavior isn’t practical. Another layer of technical safeguards just makes sense.

How Can We Get Started?

If you’re an existing client, just email me. Otherwise, I’m just a hop-skip-and-a-jump away.

R

Read More
Management, Info System Security Russell Mickler Management, Info System Security Russell Mickler

Protecting Your Systems in 2022

Here’s what we’ll be doing in 2022 to help our small business clients with IT security.

2021 offered an unprecedented number of challenges to small business information systems.

I wanted to take a few minutes to talk about the overall strategies that I’ll be using to protect my clients in the coming year.


Defense in Depth

There’s no such thing as a magic pill. Not one product, not one solution, not one strategy that can safeguard IT assets 100% of the time; anyone who tries to convince you otherwise is trying to sell one. And if you believe that sales pitch, you’re already falling into a trap of the mind; you’re already making too many assumptions and assumptions won’t keep you safe.

Instead, it is more rational to perceive risk in terms of layers of control.

Here are some examples:

  • one layer controls the physical access to a network;

  • another controls the wireless access to a network;

  • another controls the remote access to a network;

  • another layer authenticates who you are to that network;

  • another defines what software you do or do not have access to.

Five layers, five controls.

Over time, we can measure and test our controls to prove that they work, and we can say - with some degree of certainty - that our systems are secure.

Security, after all, is just a feeling: it is the confidence that we have in our safeguards. If you’re not already managing your IT in layers, how can you have any confidence that your systems are secure? Well, you can’t - you’re just making assumptions - and assumptions do not equal confidence.


Cloud Computing

Most small businesses do not have computer and network expertise on-staff. And aside from the talent problem, managing IT assets and information systems is extraordinarily risky and costly. So unless computer expertise is a core-competency, why do it?

It is far better for small businesses to outsource that risk and push it onto the backs of vendors who can operate at a better economy of scale and can manage IT better than them.

Somebody like Google can manage your email more cost-effectively than you can, and they have an army of professionals safeguarding your data. So why not let Google handle your email instead of running your own email server? The same could be said for applications, files, phone calls, databases, and device management.

In doing so, small businesses transform IT into an always-on utility - a system like electricity and water - allowing for the most reliable, cost-effective access, using any device, anywhere.

You don’t keep an electrician on-hand to deal with electrical problems, right? And you don’t keep a plumber on your payroll to handle the plumbing problems and run more water into your building. The same should be for your IT. Outsource the risk; transform IT into a utility.

In 2022, I’ll continue to push my small business clients to abandon running their own on-prem servers and devices, and to leverage cloud computing to the greatest extent possible.


Identity and Access Control

One of the biggest challenges we have in IT today is this concept around stealing somebody’s identity to gain access to a confidential system. This is primarily done with phishing attacks. A bad actor sends your team an email that looks legitimate. They click on a link and are brought to a website that looks and feels legitimate, but is really set up by the bad guys to capture their username and password to a secure system.

It’s a huge problem and employee training isn’t enough. The bad guys get more sophisticated every day. We need technical controls that adapt - using machine learning (ML) and artificial intelligence (AI) - to spot the phishing attack and prevent the user from evening seeing it. Google’s Gmail uses these tools to constantly screen attacks from aggressors intending to steal ident information from your employees.

Combined with good password management policies, multi-factor authentication, and admin alerts controlling end-user access, adaptive ML/AI promises to reduce these effects significantly. In 2022, in my role as a Google Partner, I’ll be continuing to help my clients get the greatest benefit from their cloud platform investment by securing their identity.


Endpoint and Mobile Device Management

Another vector of attack against your systems is through exploiting the human propensity to procrastinate and ignore risk.

A good example are computer security updates. Many users will deliberately tell their computers to not apply updates, or, won’t restart their machines after receiving updates. This prevents the system from receiving necessary software updates to help protect them, and over time, the lack of patches creates huge holes that aggressors can drive a truck through.

Endpoint Management (EPM) uses software to regulate the compliance of managed computers so that they’re always receiving their security patches. EPM also takes care of things like viruses, malware, and intrusion detection. It provides a set of tools to remotely manage assets to bring them back into compliance and safe to use.

Mobile Device Management (MDM) uses similar controls to verify that the devices approved to remotely (like mobile phones, tablets, and laptops) access company information are controlled.

Used in conjunction with each other, MDM and EPM alert administrators to take action if a machine continuously falls outside of the range of acceptable patching, suffers from malware or an attack, prevents unauthorized, lost, or stolen devices from accessing secure information, and provides dashboard-level pictures of the overall security posture of a company. It’s the best, most cost-effective way to prevent loss … rather than reacting to loss.

In 2022, I’ll be attempting to convince most of my clients to join my endpoint management program and implement MDM to best control their systems.


Managed Browsers

Increasingly, phishing attacks come not just from email but from what are referred to as browser hijacks. Websites and software will redirect the user’s browsing activities to websites that attempt to steal ident credentials or Personal Private Information (PPI). Hijacks threaten not only the user but any confidential information that may exist on their computers.

These risks demand that an IT control be extended to Internet browsers. Managed browsers are browsers that exist on any device anywhere but they receive a central set of policies. These policies dictate how the browser can be used, when it can be used, what sites and software are okay to use - and which ones aren’t - and prevents the user from accessing known-bad websites that could harm them.

In my role as a Google Partner, in 2022, I’m going to help a majority of my clients by deploying managed browsing policies governed by their Google Workspace investment to help keep their teams safe while using the Internet.


Perimeter Control

There are logical software components to every network. These components control the logical flow of information. You’re probably familiar with these devices by their names of routers, switches, bridges, and gateways. Most are simple computing appliances without a high degree of security built-in to them.

These devices do their work day in and day out and most of the time, you don’t have to even think about them. However, over time, their firmware needs to be updated; for the same reason we patch computers, we must also patch these devices. Aggressors realize that this equipment often goes unnoticed and unsecured because it’s not something most people are thinking about.

Well, I’m thinking about it. In 2022, I’ll be helping my clients identify their network’s perimeter infrastructure, either patching or replacing suspect equipment, and implementing tighter security controls over them.


Training

All the ML/AI in the world can’t beat human instinct or well-trained human behaviors. Technical controls to help secure the workplace are great but real security - real confidence - begins and ends with training people.

Your team must be brought up to speed about the most recent threats and concerns, and given tools to help them navigate the risk.

Sometimes, the best training simply interrupts an emotional response to a problem … to get somebody to just question clicking on a link so they can ask for more advice is an interrupt that a hacker can never thwart. The most skilled hacker can rarely beat an attentive, trained human! They’re counting on the human to not be paying attention, to not be trained.


Therefore, technical controls aren’t enough. This next year, I’ll be pushing training to help teach and inspire others to take these threats seriously. Further, responding to these problems by dealing with them in-depth, through implementing layers of controls, through shifting more and more risk to cloud providers, by implementing strong controls over identity and Internet browsing, and through inspecting the perimeters of our networks, will help instill a stronger sense of security for my clients next year.

R

Read More