<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybersecurity - Jazz Solutions, Inc. (JSL)</title>
	<atom:link href="https://www.jazzsolutions.com/category/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.jazzsolutions.com</link>
	<description>Cybersecurity, ICAM, Government IT</description>
	<lastBuildDate>Wed, 22 Oct 2025 17:50:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.jazzsolutions.com/wp-content/uploads/2023/04/cropped-JSL-updated-favicon-1-150x150.webp</url>
	<title>Cybersecurity - Jazz Solutions, Inc. (JSL)</title>
	<link>https://www.jazzsolutions.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Your first pet&#8217;s name is not a secret to hackers</title>
		<link>https://www.jazzsolutions.com/your-first-pets-name-is-not-a-secret-to-hackers/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=your-first-pets-name-is-not-a-secret-to-hackers</link>
		
		<dc:creator><![CDATA[Avery Moore]]></dc:creator>
		<pubDate>Wed, 22 Oct 2025 17:42:52 +0000</pubDate>
				<category><![CDATA[Cyber in 60]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.jazzsolutions.com/?p=14889</guid>

					<description><![CDATA[<p>I have&#160;written&#160;articles about password management. I have told an uncountable number of people about password management.&#160;The advice that you should&#160;create&#160;unique and strong passwords for every single&#160;service you&#160;use is still relevant and sound.&#160;In fact, you&#160;don’t&#160;need to search the internet&#160;very hard&#160;to find [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/your-first-pets-name-is-not-a-secret-to-hackers/">Your first pet’s name is not a secret to hackers</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="14889" class="elementor elementor-14889" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-77ea5da elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="77ea5da" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-932fbe5" data-id="932fbe5" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-3f1e51a elementor-widget elementor-widget-text-editor" data-id="3f1e51a" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>I have&nbsp;written&nbsp;articles about password management. I have told an uncountable number of people about password management.&nbsp;The advice that you should&nbsp;create&nbsp;unique and strong passwords for every single&nbsp;service you&nbsp;use is still relevant and sound.&nbsp;In fact, you&nbsp;don’t&nbsp;need to search the internet&nbsp;very hard&nbsp;to find instances of accounts being taken over because someone used their “old reliable” password on most of their accounts. This is&nbsp;a&nbsp;fundamental&nbsp;personal cybersecurity&nbsp;practice.&nbsp;I’ll&nbsp;say it louder for the people in the back. Use strong and unique passwords for every single online service you use.&nbsp; Zero exceptions.<span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">But&nbsp;there’s&nbsp;one&nbsp;aspect of account security that&nbsp;isn’t&nbsp;discussed often or as widely: your security questions.&nbsp;We’re&nbsp;told that we should “limit sharing” on social media. Isn’t&nbsp;the point of social&nbsp;media&nbsp;to share?&nbsp;We’d&nbsp;better not reveal our favorite food or our first car or the city where we were married because, you know, security. And this is one of the fundamental weaknesses&nbsp;of security questions.&nbsp;</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">Security questions rely on the fact that 1)&nbsp;you’re&nbsp;going to forget your password; and 2) there are fundamental things about yourself or your past that are immutable. But what&nbsp;they are&nbsp;really intended to do is cut down on calls to the support desk. You forgot your password? No problem!&nbsp;</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto"> Question:What’s&nbsp;the name of your first pet?</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto"> Answer:Fuzzy Britches</span><span data-ccp-props="{}">&nbsp;</span></li>
</ul>
<p><span data-contrast="auto">Welcome&nbsp;back!!&nbsp;No&nbsp;need to call the support desk now.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">There are at least two&nbsp;points of ponderance I have&nbsp;about these so-called security questions:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ol>
<li><span data-contrast="auto"> Where and how do online&nbsp;services store and protect the answers to your&nbsp;security&nbsp;questions?</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto"> When (not if) a data breach happens to one of those services, are the answers to your security questions included in the breached data (along with your personal data and password)?</span></li>
</ol>
<p><span data-contrast="auto">The answer to the first question is: I&nbsp;don’t&nbsp;know,&nbsp;and it&nbsp;probably varies&nbsp;widely&nbsp;across&nbsp;sites&nbsp;and services.&nbsp;The name of your first girl/boyfriend is&nbsp;probably stored&nbsp;in plain text.&nbsp;</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">The answer to the second question is: It is&nbsp;probably part&nbsp;of the criminal data haul.&nbsp;As a result,&nbsp;the bad guys&nbsp;now&nbsp;know that your&nbsp;childhood nickname was “Poochy”.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">There’s&nbsp;really nothing&nbsp;you can do&nbsp;about how online services manage your security questions. But there is something you can do&nbsp;on&nbsp;your end.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">If you can, avoid answering security questions in the first place. That information is yours to share or not&nbsp;in accordance with&nbsp;your own tolerance for privacy about&nbsp;the name of your&nbsp;first-grade&nbsp;teacher or your favorite food. However, in most cases, sites and services that use security questions do not let you&nbsp;proceed&nbsp;without answering them.&nbsp;The best counsel I can give is to treat the answers to your security questions as you would any other authenticator. In other words, treat it just like a password.&nbsp;Both passwords&nbsp;and security question answers&nbsp;should only be known to you.&nbsp;Both passwords&nbsp;and&nbsp;security question answers&nbsp;should be long and&nbsp;strong&nbsp;and—you guessed it—unique for every single&nbsp;site or&nbsp;service.&nbsp;Here’s&nbsp;an example.&nbsp;I’m&nbsp;going to go ahead and let you know what my favorite flavor of ice cream is. Here it is:&nbsp;7vri;1&amp;Nu_&amp;% 0Dvx%Y4ETV$&nbsp;There’s&nbsp;just nothing more delicious than a big bowl of 7vri;1&amp;Nu_&amp;% 0Dvx%Y4ETV$ ice cream!!</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">Don’t&nbsp;worry,&nbsp;that’s&nbsp;not the answer I really use, but you get the idea. You should be treating this authentication information just like a password.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">Now you may be thinking to yourself that you&nbsp;can’t&nbsp;possibly memorize&nbsp;that and then be able to reproduce it if you “forget your password”.&nbsp;That’s&nbsp;where password managers come in. Use&nbsp;a password manager to create&nbsp;a&nbsp;strong and&nbsp;unique password for&nbsp;each and every&nbsp;site. And, when the security questions appear, use the notes feature&nbsp;in&nbsp;that same&nbsp;password&nbsp;entry&nbsp;in your password manager&nbsp;to record the security questions that you used&nbsp;along with the strong and&nbsp;unique answers to the security questions.&nbsp;Here’s&nbsp;an example of&nbsp;what I do.</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto"> Username: UsernameExample</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto"> Password: I2OB1FP(U}`WN4WX!H)!K+lW=O9omns&lt;</span></li>
<li><span data-contrast="auto"> Security Questions:</span></li>
<li><span data-contrast="auto"> Q1: What was&nbsp;the name of your fifth grade PE teacher?</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto"> A1:!.Z^La&amp;Me3Mc5nx2s-o3$&#8217;Z7a</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto"> Q2: What was the first concert you attended?</span><span data-ccp-props="{}">&nbsp;</span></li>
<li><span data-contrast="auto"> A2:rbGm&#8217;rYrgFpV&amp;ga-nYz$=L~i</span><span data-ccp-props="{}">&nbsp;</span></li>
</ul>
<p><span data-contrast="auto">When you set yours up, be sure to use something different than what I used above&nbsp;and use a different answer every single time, even for the exact same question. Many password managers provide password creation&nbsp;tools,&nbsp;and there are websites that will generate random strings of characters that you can&nbsp;use for&nbsp;both your passwords and the answers to your security questions.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">If you use a password manager for all of your accounts, the chances are good that you’ll never need to invoke the use of the security questions at all, because you’ll be able to&nbsp;easily&nbsp;access the password.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">Of course, this is not a “silver bullet” solution, but it does prevent bad guys from easily getting into your account by simply knowing that your first car was a 1979 Ford Fairmont.&nbsp;Becoming a harder target is not difficult, but it does require a little bit of diligence.</span><span data-ccp-props="{}">&nbsp;</span></p>
<p><span data-contrast="auto">&nbsp;</span></p>
<p></p>								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/your-first-pets-name-is-not-a-secret-to-hackers/">Your first pet’s name is not a secret to hackers</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Scarier than Halloween: My Brush with Identity Theft</title>
		<link>https://www.jazzsolutions.com/scarier-than-halloween-my-brush-with-identity-theft/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scarier-than-halloween-my-brush-with-identity-theft</link>
		
		<dc:creator><![CDATA[Avery Moore]]></dc:creator>
		<pubDate>Wed, 08 Oct 2025 18:15:50 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.jazzsolutions.com/?p=14858</guid>

					<description><![CDATA[<p>There is at least one more thing scarier than Halloween: identity theft. That’s the fear that swept through me last month when I received a text message purportedly coming from “SimpleVerify” regarding my “application”. Saying that it was fear is [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/scarier-than-halloween-my-brush-with-identity-theft/">Scarier than Halloween: My Brush with Identity Theft</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="14858" class="elementor elementor-14858" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-5d8ef96 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="5d8ef96" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-194f6af" data-id="194f6af" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-416aa84 elementor-widget elementor-widget-text-editor" data-id="416aa84" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>There is at least one more thing scarier than Halloween: identity theft. That’s the fear that swept through me last month when I received a text message purportedly coming from “SimpleVerify” regarding my “application”. Saying that it was fear is somewhat of an understatement. I was almost in a panic. Thus far, I’ve been able to avoid having my identity stolen. So, seeing a text message that indicated there was an account in my name with an indication of “previous actions” caused my stomach to drop. My credit is pretty good. I thought to myself, “I didn’t open this account! Wait! Who did???” I texted my wife to let her know what was going on. She provided assurances that she didn’t open a loan account either.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6c54375 elementor-widget elementor-widget-image" data-id="6c54375" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img fetchpriority="high" decoding="async" width="476" height="338" src="https://www.jazzsolutions.com/wp-content/uploads/2025/10/screen-shot.jpg?x29045" class="attachment-large size-large wp-image-14861" alt="" srcset="https://www.jazzsolutions.com/wp-content/uploads/2025/10/screen-shot.jpg 476w, https://www.jazzsolutions.com/wp-content/uploads/2025/10/screen-shot-440x312.jpg 440w" sizes="(max-width: 476px) 100vw, 476px" />															</div>
				</div>
				<div class="elementor-element elementor-element-fbf26cd elementor-widget elementor-widget-text-editor" data-id="fbf26cd" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<h6><em>Screenshot of text images I received</em></h6>								</div>
				</div>
				<div class="elementor-element elementor-element-906f8f7 elementor-widget elementor-widget-text-editor" data-id="906f8f7" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>What was going on?</p><p>Knowing that there was a strong possibility this was an SMS phishing attempt (also known as “smishing”), I proceeded cautiously and used a sandbox tool to explore the link. In many cases, these types of social engineering attacks seek to steal information rather than propagate malicious code, but one can’t be too safe.</p><p>After navigating to the link, I saw what appeared to be some sort of login page with a field that was already filled in with my actual phone number. In the URL (redacted in the screenshot), it showed my phone number and my wife’s email address.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-3e30935 elementor-widget elementor-widget-image" data-id="3e30935" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img decoding="async" width="652" height="304" src="https://www.jazzsolutions.com/wp-content/uploads/2025/10/screenshot-2.jpg?x29045" class="attachment-large size-large wp-image-14862" alt="" srcset="https://www.jazzsolutions.com/wp-content/uploads/2025/10/screenshot-2.jpg 652w, https://www.jazzsolutions.com/wp-content/uploads/2025/10/screenshot-2-440x205.jpg 440w" sizes="(max-width: 652px) 100vw, 652px" />															</div>
				</div>
				<div class="elementor-element elementor-element-19c0669 elementor-widget elementor-widget-text-editor" data-id="19c0669" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<h6><em>Screenshot of malicious &#8220;SimpleVerify&#8221; page</em></h6>								</div>
				</div>
				<div class="elementor-element elementor-element-17bd504 elementor-widget elementor-widget-text-editor" data-id="17bd504" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Seeing our actual information on this page increased my feeling of panic. Even though I was 95% sure this was social engineering, I still felt the need to take proactive action. I immediately logged into the major credit bureau sites using known good links. I checked all my credit reports. To my relief, I did not see any activity that looked suspicious and didn’t see any accounts I didn’t open myself. While I was there, I put fraud alerts on my credit report, which, admittedly, I should have had those in place before my panic.</p><p>With my credit intact and assurance that I dodged identity theft for another day, I was feeling a little bit better about things. The malicious page requested the last 4 digits of my SSN, which I did not provide. The attack appeared to be a relatively sophisticated smishing attempt designed to trick me into voluntarily disclosing highly sensitive personal information through a deceptive verification service impersonation. Not having taken the bait, I felt somewhat relieved.</p><p>But what continued to nag at me was the fact that my phone number and wife’s email address were contained on the landing page. This caused an emotional reaction that I simply did not expect. Though I’ve had years of analyzing phishing emails and sneaky SMS messages, it hits a little differently when you see your own personal information in one. More about that in a moment.</p><p>This attack gave me the opportunity to follow my own advice to: 1) Stop; 2) Think; 3) Verify. That first step to “Stop” may be the most important. Taking actions quickly without thinking is precisely what the attacker wants you to do. The less you think, the more likely you are to ignore sound advice, not follow procedures, or completely violate policies. Stopping and thinking about what’s happening gives you a moment to digest what’s going on, bounce it against what you know to be right, seek counsel, and ultimately avoid making a terrible decision. The verification step ensures that you reach out to the person or organization you think is communicating with you, if possible. For things like bank account phishing or smishing, this simply means navigating to your bank’s website using a known good URL you have previously bookmarked or have saved in your password manager. You can also use known good phone numbers to call the person or organization to verify what is happening. I use the phrase “known good” because one thing you should never do is use contact information that was provided by the suspicious email or sender. Attackers often provide “help” numbers or links that lead to their own malicious call centers or web sites.</p><p>Following these three steps can prevent a lot of problems.</p><p>As for that personal data that appeared in the malicious web site, it’s very likely that it was part of one of the many data breaches we read about in the news just about every week. As more data breaches occur, it becomes more likely that your data will be involved and you’ll be targeted, if you haven’t been already. So, check your credit reports often. Put a fraud alert or a freeze on your credit reports. And do your best to keep a cool head.</p><p>No one is immune from falling for a phishing, smishing, or other social engineering attack, not even a CISO. Everyone has a “button” that can be pushed to generate fear and panic and cause them to make panicked decisions. But remembering to stop, think, and verify can help to keep you from having a very bad day.</p>								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/scarier-than-halloween-my-brush-with-identity-theft/">Scarier than Halloween: My Brush with Identity Theft</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Five ways to keep staff awake during cybersecurity training</title>
		<link>https://www.jazzsolutions.com/five-ways-to-keep-staff-awake-during-cybersecurity-training/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=five-ways-to-keep-staff-awake-during-cybersecurity-training</link>
		
		<dc:creator><![CDATA[JSL Staff]]></dc:creator>
		<pubDate>Mon, 29 Sep 2025 15:05:04 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.jazzsolutions.com/?p=14805</guid>

					<description><![CDATA[<p>Cybersecurity training is critical, but unfortunately a lot of it is forgettable. Slide decks about encryption or an annual compliance video won’t prepare employees for phishing emails or social engineering. If you want people to stay awake and remember what they’ve learned, [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/five-ways-to-keep-staff-awake-during-cybersecurity-training/">Five ways to keep staff awake during cybersecurity training</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="14805" class="elementor elementor-14805" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-917d068 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="917d068" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-22690dc" data-id="22690dc" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-0ea77bc elementor-widget elementor-widget-text-editor" data-id="0ea77bc" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Cybersecurity training is critical, but unfortunately a lot of it is forgettable. Slide decks about encryption or an annual compliance video won’t prepare employees for phishing emails or social engineering. If you want people to stay awake <em>and</em> remember what they’ve learned, here are five practical approaches that work.</p><ol><li><strong> Tell Stories, Not Just Rules</strong><br />People don’t remember checklists, they remember stories. Share real examples of phishing scams, invoice fraud, or deepfake calls that targeted organizations like theirs. Put it in context: “Here’s how a federal contractor lost millions, and here’s how we avoid that.”</li><li><strong> Keep It Short and Frequent</strong><br />Long annual trainings feel like a big burden. Bite-sized lessons — five minutes in a team meeting, a quick video on Teams, a short phishing drill — fit better into busy schedules and are easier to remember.</li><li><strong> Make It Personal</strong><br />Don’t treat cybersecurity as abstract. Show how good habits protect not only organizations but also employees’ own paychecks, benefits, and personal information. When people see what’s at stake for them, they are more invested.</li><li><strong> Use Interaction and Gamification</strong><br />Quizzes, role-playing, or even a little competition can help keep people engaged. Reward teams that report phishing emails quickly. Recognize employees who demonstrate strong cyber habits. Positive reinforcement works better than complicated trainings.</li><li><strong> Put a Human Face on Security</strong><br />Generic training feels distant. Have a trusted leader — your CISO, a security lead, or even a peer — deliver messages directly. A recognizable face turns training from “another compliance box” into part of the company culture.</li></ol><p>Training doesn’t have to be dull. With stories, interaction, and some relevance, employees can actually remember the lessons, and apply them. That’s the difference between a rote checkbox exercise and building a culture of security that protects contracts and missions.</p>								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/five-ways-to-keep-staff-awake-during-cybersecurity-training/">Five ways to keep staff awake during cybersecurity training</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>White Paper: JSL&#8217;s CISO reveals how you can protect your agency from social engineering attacks</title>
		<link>https://www.jazzsolutions.com/white-paper-jsls-ciso-reveals-the-hidden-tactics-threat-actors-use-to-bypass-your-security/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=white-paper-jsls-ciso-reveals-the-hidden-tactics-threat-actors-use-to-bypass-your-security</link>
		
		<dc:creator><![CDATA[JSL Staff]]></dc:creator>
		<pubDate>Thu, 22 May 2025 13:50:02 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[JSL News]]></category>
		<guid isPermaLink="false">https://www.jazzsolutions.com/?p=14210</guid>

					<description><![CDATA[<p>90% of cyber attacks start with a phishing email. That statistic alone should be a wake-up call for government agencies and cybersecurity professionals. While agencies invest heavily in firewalls, authentication systems, and encryption, attackers often sidestep these technical controls—not by hacking, [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/white-paper-jsls-ciso-reveals-the-hidden-tactics-threat-actors-use-to-bypass-your-security/">White Paper: JSL’s CISO reveals how you can protect your agency from social engineering attacks</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="14210" class="elementor elementor-14210" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-b6b33ac elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="b6b33ac" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7a00032" data-id="7a00032" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-378f2c2 elementor-widget elementor-widget-text-editor" data-id="378f2c2" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>90% of cyber attacks start with a phishing email.</strong> That statistic alone should be a wake-up call for government agencies and cybersecurity professionals. While agencies invest heavily in firewalls, authentication systems, and encryption, attackers often sidestep these technical controls—not by hacking, but by manipulating people.</p><p>This is the essence of social engineering, a form of cyber attack that preys on human psychology rather than software vulnerabilities. Phishing, vishing, pretexting, and tailgating are just a few of the tactics bad actors use to trick employees into handing over sensitive information, clicking malicious links, or granting unauthorized access. And these attacks are growing more sophisticated every day.</p><p>That’s why JSL’s Chief Information Security Officer, Avery Moore, has authored &#8220;The Fundamentals of Social Engineering&#8221;, a free white paper designed to help government agencies understand, recognize, and defend against these threats.</p><p>What You’ll Learn:</p><ul><li>The top social engineering tactics cybercriminals use to infiltrate government systems</li><li>How attackers exploit human tendencies like authority, reciprocity, and obligation</li><li>Case studies, including insights from infamous hacker Kevin Mitnick</li><li>Actionable steps to strengthen your agency’s defenses</li></ul><p><strong>Government systems are prime targets. The question isn’t if attackers will attempt a social engineering attack—but when. Are your employees prepared?</strong></p>								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-59795e0 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="59795e0" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c1c1a1a" data-id="c1c1a1a" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-f268472 elementor-align-center elementor-widget elementor-widget-button" data-id="f268472" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="https://www.jazzsolutions.com/defend-your-agency-from-social-engineering-expert-insights-from-jsls-ciso/" target="_blank">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Click here</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/white-paper-jsls-ciso-reveals-the-hidden-tactics-threat-actors-use-to-bypass-your-security/">White Paper: JSL’s CISO reveals how you can protect your agency from social engineering attacks</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Unlock the Secrets to Social Engineering Defense</title>
		<link>https://www.jazzsolutions.com/unlock-the-secrets-to-social-engineering-defense/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=unlock-the-secrets-to-social-engineering-defense</link>
		
		<dc:creator><![CDATA[Avery Moore]]></dc:creator>
		<pubDate>Wed, 16 Oct 2024 15:17:13 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www.jazzsolutions.com/?p=13417</guid>

					<description><![CDATA[<p>Curious how even the best tech can fall short against clever social engineering? Download the presentation slides from our Chief Information Security Officer, Avery Moore, from his recent talk at DOL Cybersecurity Day: &#8220;The Best Tech Can&#8217;t Stop It! The Fundamentals of [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/unlock-the-secrets-to-social-engineering-defense/">Unlock the Secrets to Social Engineering Defense</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="13417" class="elementor elementor-13417" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-1ac5db71 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="1ac5db71" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-32361faf" data-id="32361faf" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-4e77d5d5 elementor-widget elementor-widget-text-editor" data-id="4e77d5d5" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									
<p>Curious how even the best tech can fall short against clever social engineering? <a href="https://www.jazzsolutions.com/wp-content/uploads/2024/10/20241010_Jazz_Solutions_Social_Engineering_Fundamentals_DOL_Cybersecurity.pdf?x29045">Download the presentation slides from our Chief Information Security Officer, Avery Moore, from his recent talk at <strong>DOL Cybersecurity Day</strong>: <em>&#8220;The Best Tech Can&#8217;t Stop It! The Fundamentals of Social Engineering.&#8221;</em></a> In this insightful session, Avery breaks down the human element behind cyber threats and shares actionable strategies to safeguard your organization. Whether you&#8217;re a cybersecurity pro or just looking to strengthen your defenses, these slides are packed with practical tips you won’t want to miss!</p>
								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-d1a6835 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="d1a6835" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e7c8473" data-id="e7c8473" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-3ff67fb elementor-align-center elementor-widget elementor-widget-button" data-id="3ff67fb" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="https://www.jazzsolutions.com/wp-content/uploads/2024/10/20241010_Jazz_Solutions_Social_Engineering_Fundamentals_DOL_Cybersecurity.pdf?x29045">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Download Presentation Slides</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/unlock-the-secrets-to-social-engineering-defense/">Unlock the Secrets to Social Engineering Defense</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>I use Last Pass. What now?</title>
		<link>https://www.jazzsolutions.com/i-use-last-pass-what-now/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=i-use-last-pass-what-now</link>
		
		<dc:creator><![CDATA[Avery Moore]]></dc:creator>
		<pubDate>Wed, 26 Apr 2023 03:43:53 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www2.jazzsolutions.com/index.php/2023/04/26/i-use-last-pass-what-now/</guid>

					<description><![CDATA[<p>Have you heard about the LastPass breach? The company’s last press release was in late December but had few details. If you&#8217;ve paid attention in security awareness class, you know that since we still heavily rely on passwords for authentication, [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/i-use-last-pass-what-now/">I use Last Pass. What now?</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="20" class="elementor elementor-20" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-5135c6eb elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="5135c6eb" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-16c01952" data-id="16c01952" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-14915f4e elementor-widget elementor-widget-text-editor" data-id="14915f4e" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Have you heard about the <a href="https://www.wired.com/story/lastpass-breach-vaults-password-managers/">LastPass breach</a>? The company’s <a href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/">last press release</a> was in late December but had few details. If you&#8217;ve paid attention in security awareness class, you know that since we still heavily rely on passwords for authentication, you need to use some kind of password manager.  </p><p>Ideally, we wouldn&#8217;t need passwords, but that&#8217;s not feasible right now. A notch down from that is having all our passwords in hard copy—yes, printed in a notebook and kept in a safe. Actual paper is not reachable via any network and, therefore, is about as &#8220;unhackable&#8221; as you can get. But that’s not practical when you have tens or hundreds of passwords. Plus, you could lose it!  </p><p>Enter the password manager. As a smart user, you have probably already chosen a password manager and are using it for all your passwords. But let&#8217;s say you happen to have chosen LastPass as your password manager, and now you are confused and don&#8217;t know what to do.  </p><p>Here&#8217;s what we know: </p><p> </p><ul><li><strong>The attackers stole backup copies of password vaults.</strong> You should assume that a copy of some version of your password vault is in an attacker&#8217;s hands. In and of itself, this isn&#8217;t bad. That&#8217;s why we encrypt things. If you followed the <a href="https://support.lastpass.com/help/what-is-the-lastpass-master-password-lp070014">LastPass recommendation</a> of setting your master password at 12 characters, using all available characters (upper and lower case, numbers, special characters), it would take an attacker about 174 years to exhaustively search the password space. That&#8217;s using brute force to try all possible passwords and assumes all possible combinations are tried. But if your master password was short or used only letters, you have much less time. If your master password is the same as any of your other accounts, you should consider your password vault compromised. <strong>Not everything in the password vault was encrypted.</strong>Usernames, passwords, and notes are encrypted. But everything else does not appear to be, including URLs. Attackers may have what they need to send carefully crafted phishing emails so be on the lookout for those. </li><li><strong>Multi-factor authentication won&#8217;t help with this.</strong> The MFA you have set up for LastPass is there only to access your vault in the cloud. The bad guys already have your vault and all they need is that master password (the key) to unlock it. </li></ul><p>So, what should you do now? </p><p> </p><ol><li><strong>Start changing passwords on high-priority accounts first.</strong> I recommend starting with your financial accounts. <strong>If you haven&#8217;t already, enable and enforce multi-factor authentication where available.</strong> This way, even if the bad guys do discover the password to one or more of your accounts, there&#8217;s another factor to make it harder for them and to buy you some time. </li><li><strong>Watch out for convincing phishing emails.</strong> An attacker doesn&#8217;t need to guess your password if they can just trick you into giving it to them.  </li><li><strong>Evaluate other password managers.</strong> Jazz Solutions does not endorse one password manager over another, so do your homework, and make the best choice for your particular needs. <em>Pro tip: Add the name of the password manager to your Google news alerts, so if this happens again, you’ll find out faster.</em></li></ol>								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-7f0f3f78 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="7f0f3f78" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1988419b" data-id="1988419b" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-5f14978c elementor-widget elementor-widget-image" data-id="5f14978c" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img decoding="async" width="1024" height="697" src="https://www.jazzsolutions.com/wp-content/uploads/2023/04/passwords-1024x697.webp?x29045" class="attachment-large size-large wp-image-21" alt="" srcset="https://www.jazzsolutions.com/wp-content/uploads/2023/04/passwords-1024x697.webp 1024w, https://www.jazzsolutions.com/wp-content/uploads/2023/04/passwords-300x204.webp 300w, https://www.jazzsolutions.com/wp-content/uploads/2023/04/passwords-768x523.webp 768w, https://www.jazzsolutions.com/wp-content/uploads/2023/04/passwords.webp 1232w" sizes="(max-width: 1024px) 100vw, 1024px" />															</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-63b9436 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="63b9436" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-32923b6" data-id="32923b6" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-8a4d42b elementor-widget elementor-widget-text-editor" data-id="8a4d42b" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Share Post</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-b705973 elementor-share-buttons--view-icon elementor-share-buttons--skin-flat elementor-share-buttons--shape-circle elementor-grid-0 elementor-share-buttons--color-official elementor-widget elementor-widget-share-buttons" data-id="b705973" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="share-buttons.default">
				<div class="elementor-widget-container">
							<div class="elementor-grid" role="list">
								<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_linkedin" role="button" tabindex="0" aria-label="Share on linkedin">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-linkedin" aria-hidden="true"></i>							</span>
																				</div>
					</div>
									<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_facebook" role="button" tabindex="0" aria-label="Share on facebook">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-facebook" aria-hidden="true"></i>							</span>
																				</div>
					</div>
									<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_twitter" role="button" tabindex="0" aria-label="Share on twitter">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-twitter" aria-hidden="true"></i>							</span>
																				</div>
					</div>
						</div>
						</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/i-use-last-pass-what-now/">I use Last Pass. What now?</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>&#8216;The Triple C&#8217;​ Approach to Security Incident Response</title>
		<link>https://www.jazzsolutions.com/the-triple-c-approach-to-security-incident-response/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-triple-c-approach-to-security-incident-response</link>
		
		<dc:creator><![CDATA[Avery Moore]]></dc:creator>
		<pubDate>Wed, 26 Apr 2023 03:43:52 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://www2.jazzsolutions.com/index.php/2023/04/26/the-triple-c-approach-to-security-incident-response/</guid>

					<description><![CDATA[<p>Creating an incident response (IR) capability can be a daunting task. The National Institute of Standards and Technology (NIST) alone has a dozen or so security controls related to just that topic. The prevention of all security incidents is the [&#8230;]</p>
<p>The post <a href="https://www.jazzsolutions.com/the-triple-c-approach-to-security-incident-response/">‘The Triple C’​ Approach to Security Incident Response</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></description>
										<content:encoded><![CDATA[<div data-elementor-type="wp-post" data-elementor-id="16" class="elementor elementor-16" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-3e81f1cc elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="3e81f1cc" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-130ecc50" data-id="130ecc50" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-7a6d5ddf elementor-widget elementor-widget-text-editor" data-id="7a6d5ddf" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p class="reader-text-block__paragraph">Creating an incident response (IR) capability can be a daunting task. The National Institute of Standards and Technology (NIST) alone has a dozen or so security controls related to just that topic.</p><p class="reader-text-block__paragraph">The prevention of all security incidents is the ideal scenario; but the fact is that security incidents do occur and being able to respond to them should be a priority in your organization. But how can this be done? </p><p class="reader-text-block__paragraph">Auditors and assessors examine an organization’s compliance against specific controls, and issue findings typically without regard for how that organization is maturing in that area. IR can and should be viewed as a miniature maturity model with the most critical concepts addressed first, while simultaneously planning for implementation of more advanced capabilities. Viewing this as a maturity model shifts your focus from where you are now to where you’re going. NIST’s <em>Computer Security Incident Handling Guide </em>breaks down the IR life cycle as follows:</p><ul><li>Preparation </li><li>Detection &amp; Analysis </li><li>Containment, Eradication &amp; Recovery </li><li>Post-Incident Activity </li></ul><p class="reader-text-block__paragraph">Volumes have been written about the above phases, but I will focus on one small but critical piece: <strong>Containment</strong>. </p><p class="reader-text-block__paragraph">Once you understand that a security incident is occurring, it’s important to quickly get to a state of containment to avoid further damage or data loss. Being in a contained state allows the organization a moment to breathe so that the next step can be taken.  </p><p class="reader-text-block__paragraph">Using a first-aid analogy, containment means <em>stop the bleeding</em>. When a person is hurt, you don’t start asking about their life choices and circumstances that led to the problem. The most important thing is to stop the bleeding and get to containment. After that is achieved, other important measures can be taken. </p><p class="reader-text-block__paragraph">Security incident containment, however, doesn’t just occur on its own. Some critical functions must be established to implement that capability while the organization is building out the other aspects and capabilities of IR. Those minimal functions are <strong>Communication</strong> and <strong>Coordination</strong>. </p><p class="reader-text-block__paragraph">If an organization can communicate and coordinate during security incidents, they will be much more successful in achieving containment. I call this the “Triple C”: <strong>Communication and Coordination leads to Containment.</strong> </p><p class="reader-text-block__paragraph">Proper communication enables responders to: </p><ul><li>Talk an issue out quickly and effectively; </li><li>Know who to talk to about what; and </li><li>Speak the language of IR. </li></ul><p class="reader-text-block__paragraph">None of the above works well without coordination. Proper coordination enables responders to: </p><ul><li>Know what team members and support members do what; </li><li>Keep communications short and focused; and </li><li>Know their own role and job. </li></ul><p class="reader-text-block__paragraph">If your communication and coordination are executed well, that will lead you to containment, where: </p><ul><li>The root issue is identified and stopped or isolated quickly; </li><li>Further issues are prevented; </li><li>Damage is minimized; and </li><li>The “bleeding” is stopped. </li></ul><p class="reader-text-block__paragraph">Using this “Triple C” concept as a step in your IR maturity model means that you can’t simply stop once you’ve determined you can contain an incident.  </p><p class="reader-text-block__paragraph">A static security incident containment program is not adequate in the long term. While implementing these minimal measures, organizations should simultaneously be working on implementing or shoring up measures for detection &amp; analysis, eradication, and recovery.  </p><p class="reader-text-block__paragraph">After all, you can’t contain a security incident if you haven’t found it first.  </p>								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				<section class="elementor-section elementor-top-section elementor-element elementor-element-7d25b087 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="7d25b087" data-element_type="section" data-settings="{&quot;avante_ext_is_background_backdrop&quot;:&quot;false&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-334206a4" data-id="334206a4" data-element_type="column" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-5c987a44 elementor-widget elementor-widget-text-editor" data-id="5c987a44" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Share Post</strong></p>								</div>
				</div>
				<div class="elementor-element elementor-element-fc7f1af elementor-share-buttons--view-icon elementor-share-buttons--skin-flat elementor-share-buttons--shape-circle elementor-grid-0 elementor-share-buttons--color-official elementor-widget elementor-widget-share-buttons" data-id="fc7f1af" data-element_type="widget" data-settings="{&quot;avante_ext_is_scrollme&quot;:&quot;false&quot;,&quot;avante_ext_is_smoove&quot;:&quot;false&quot;,&quot;avante_ext_is_parallax_mouse&quot;:&quot;false&quot;,&quot;avante_ext_is_infinite&quot;:&quot;false&quot;,&quot;avante_ext_mobile_static&quot;:&quot;false&quot;,&quot;avante_ext_link_sidemenu&quot;:&quot;false&quot;,&quot;avante_ext_link_fullmenu&quot;:&quot;false&quot;,&quot;avante_ext_link_closed_fullmenu&quot;:&quot;false&quot;}" data-widget_type="share-buttons.default">
				<div class="elementor-widget-container">
							<div class="elementor-grid" role="list">
								<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_linkedin" role="button" tabindex="0" aria-label="Share on linkedin">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-linkedin" aria-hidden="true"></i>							</span>
																				</div>
					</div>
									<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_facebook" role="button" tabindex="0" aria-label="Share on facebook">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-facebook" aria-hidden="true"></i>							</span>
																				</div>
					</div>
									<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_twitter" role="button" tabindex="0" aria-label="Share on twitter">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-twitter" aria-hidden="true"></i>							</span>
																				</div>
					</div>
						</div>
						</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div><p>The post <a href="https://www.jazzsolutions.com/the-triple-c-approach-to-security-incident-response/">‘The Triple C’​ Approach to Security Incident Response</a> first appeared on <a href="https://www.jazzsolutions.com">Jazz Solutions, Inc. (JSL)</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudfront

Served from: www.jazzsolutions.com @ 2026-04-22 09:30:24 by W3 Total Cache
-->