My New Book Is Out!

Hi All, I'm very excited to announce my new book: CYBERHEIST.

Why I wrote it? To increase executive level awareness that the bad guys

have moved from simple identity theft to full fledged robbery of corporate

bank accounts (non-profits are targets too), using phishing and scam

tactics that are called 'social engineering'.

Most business owners, C-level executives and people in HR functions simply

do not know this yet, but cyberheists are happening right now as we speak.

Organized cyber crime has developed into a very well funded, sophisticated and technically skilled operation, and their results are very damaging.

Unfortunately, management still has a false sense of security. With the

rapid proliferation of social media and mobile computing, -people- are

now the new security perimeter!

The threat is there, and getting worse. Just have a look at this Google

map overlaid with cases, and that is only the tip of the iceberg, there

are many hundreds more unreported cyberheist cases. You can zoom in and see

the cyberheists in your state and how much money was stolen:

So, do you need some ammo to get more budget for your IT security? You

need state-of-the-art endpoint protection, and I strongly recommend VIPRE

Antivirus for that, but you need to combine it with end-user Internet

Security Awareness Training (ISAT) to be as safe as possible.

Please either forward this link to management and tell them to buy a copy

of the Cyberheist book, or better yet, if you really want to make sure

they get the message, get a copy yourself and give it to them. It's

enlightening, and written for both IT and non-IT people. Everything is

explained in normal terms to make sure we don't put anyone to sleep.

Do me a big favor and tell all your friends? Thanks so much in advance!

Cyberheist is available in paperback and also in a Kindle version. Oh, and

check out the reviews at!

PS: It might say 'Out of Print', and that is when they run out of stock,

but another 500 have been sent to Amazon, so you can order and they will

ship it the moment they have this new stock.

Quotes of the Week

"A fool thinks himself to be wise, but a wise man knows himself to be a

-- William Shakespeare.

"Although a soldier by profession, I have never felt any sort of fondness for war, and I have never advocated it, except as a means of peace." -- Ulysses S. Grant.

Cybercrime Statistics Expose Five Industries Most Susceptible to

Phishing Attacks

Reuters News Agency reported this week: "Internet Security Awareness Training

(ISAT) firm KnowBe4 has released new cybercrime statistics that identify

the nation's most Phish-prone™ industry sectors, which are those most

susceptible to cybercrime ploys. The top five industries vulnerable to

cybercrime include travel, education, financial services, government

services and IT services. These findings are based on a recent phishing

experiment KnowBe4 conducted among small and medium enterprises (SMEs)

featured in the latest Inc. 500 and Inc. 5000 listings.

"Any business that provides access to email or access to its networks via

the Internet is only as safe from cybercrime to the degree that its

employees are trained to avoid phishing emails and other cyberheist schemes.

The more employees within an organization that use email or go online,

the greater the risk of exposure to cybercrime," said KnowBe4 founder

and CEO Stu Sjouwerman (pronounced "shower-man").

"KnowBe4 conducted a comprehensive data analysis of its FAIL500 study results,

which included categorizing the companies into 25 industry sectors. The

findings revealed that some industries are particularly vulnerable to

cybercrime." Industries with the highest Phish-prone percentages are:

Travel - 25%

Education - 22.92%

Financial Services - 22.69%

Government Services - 21.23%

IT Services - 20.44%

More at:


How To Stop Your Executives From Being Harpooned

Last year, a senior executive in charge of customer satisfaction at his

company opened an email with the subject "customer complaint" that appeared

to be sent from the Better Business Bureau. He followed a link to see details

of the complaint. "If he had stopped to examine the URL carefully, he would

have seen that it was a trap" -- known as a whaling attack and based on

spear-phishing techniques -- intended to gather information about the

company, says Jonathan Gossels, president of SystemExperts, a security

consulting firm. "But during a busy work day, that hardly happens." The

story is at NetworkWorld:


Phishing Your Own Employees is a Must

Following is an excerpt from SC Magazine: For IT Security Professionals. It

highlights the importance of educating organizational employees against the

tactics Cybercriminals will use to hack your company network to access

valuable company information and your bank accounts.

“If you are going to effectively fight this prevalent form of cybercrime

(phishing), you are going to have to have an educated workforce. Since

most colleges don't teach social engineering defense skills, it falls on

the savvy employer to provide education for their employees. I have long

advocated phishing your own employees… “

While it is not that easy to set up an in-house simulated phishing attack

on your employees as the author of the article suggests, you can use an

existing resource set up exactly for that purpose. KnowBe4 provides a

free and safe online way to simulate a phishing attack on as many of

your employees as you want. Go to this link to check it out:


Average Cost Of Cyberattack: $188,242

In 2010, 74% of small and medium businesses reported they were targeted

for cybercrimes, according to Symantec's 2010 Global SMB Information

survey. The average cost of such attacks was $188,242. Of the more than

2,000 small businesses surveyed around the country, 42% lost confidential

or private data and 40% experienced direct financial costs as a result.

Read more:


