Small-biz tip: Don't overlook this digital danger

Are you the type of business owner who forgets about ex-employees as soon as they’re gone? Failing to remove former employees’ access to your systems and data could lead to security breaches. Don’t let poor offboarding practices be the weak link in your cybersecurity chain.

How improper offboarding can hurt your business

Whenever an employee leaves the organization, you must remove their access to company systems and data. That’s especially true if you’ve laid off an employee. They may feel a sense of anger or resentment towards the company, which makes them more likely to be malicious.

It’s more common than you might think. A recent study from Beyond Identity examined how ineffective offboarding impacts a business’ cybersecurity. They found that one in three employers has been hacked due to ineffective offboarding.

Oh, and most former employees say they can still access company files. Researchers say 91% of employees can still see private files after offboarding earlier last year. Do you want former employees to know what you’re doing a year later? Probably not!

Plus, the study found only 21% of employers deactivated an employee’s account immediately after they let the worker go. It took 29% a whole week to cut the strings.

Overall, businesses estimated they lost $7,687 to ineffective offboarding. In other words, it’s a mistake you can’t afford to make. Want to build better business practices? Here are the three lessons Kim has for fellow business owners.

Offboarding dangers for small-business owners

⚠️ If you don’t completely cut off former employees, you’re taking on a ton of risks, like:

  1. Insider threats: Former employees who can still access company systems and data can steal confidential information or sabotage your systems.
  2. Social engineering: I talk a lot about how dangerous phishing scams are. They can level a company’s computer systems. Former employees are especially dangerous because they know social details about the workplace, which can help them access sensitive information or networks.
  3. Revenge: In some cases, fired employees may attempt to cause harm to their former employer out of revenge, such as launching a denial-of-service attack or spreading false information about the company.

Beyond Identity’s survey found that 86% of employees have considered taking negative actions against a former employer. People who actually went through with retaliation had diverse reasons: 37% said they didn’t get a raise, while 29% cited a bad relationship.

People had a diverse range of revenge tactics, too. Most of them — 42% — used corporate accounts to access subscriptions, while 34% viewed company financial information and left bad reviews. Others had creepier methods, like reading employees’ emails or hacking into the backend of a company website.

Continue reading

Here's how to order an FDA-approved COVID test on Amazon

Vaccines for COVID-19 are being administered across the U.S., but infections are still at an all-time high. To make matters worse, cybercriminals are taking advantage of the vaccine to rip people off. Tap or click here for four ways scammers are out to get you.

Continue reading

Shelf control

📦 Need more space? Nah, you just need smarter storage.

🤫 Your secret’s safe with me: Stash your valuables in plain sight with a wall safe (18% off) that looks like an outlet.

🔒 Small-biz security 101: The principle of least privilege could save you big headaches down the road. The idea is you only give employees access to the data and systems they absolutely need to do their jobs. The fewer people with admin rights, the better.

How to download your entire Facebook

Open/download audio

What if you suddenly lost access to your Facebook — years of photos, posts, and memories gone? I’ll tell you how to back up your account so you don’t lose it all if something goes wrong.

📞 Scammers posing as IRS agents: Just ask Brad, who got a call saying he misfiled his taxes and owed over $800 or else he could face jail time. The scammer knew his address and wife’s name, and Brad ended up giving him access to his bank account. PSA: The IRS never calls or texts. If it’s legit, it comes by mail.

$200 a month

What you’ll pay for Anthropic’s new Claude “Max” subscription tier. It’s made for people who use Claude a lot and run into rate limits. You’ll get up to 20x more usage than the Pro plan, plus early access to new features. And yeah, the timing’s no coincidence. It’s clearly a move to compete with OpenAI’s $200/month tier.

Pro Windows user? Use “God Mode” to access all your Control Panel settings in one place. Just create a new folder anywhere, like on your desktop, and rename it to this exact string: GodMode.{ED7BA470-8E54-465E-825C-99712043E01C} Hit “Enter,” and the folder icon will change to a Control Panel icon. Opening this new folder will give you a powerful, centralized view of virtually all settings and configuration options in Windows.

🎤 iPhone & Android Tip: Turn off voice access to keep someone from using voice commands without unlocking your phone. 

Need a new book? If you have Amazon Prime, grab two free e-books from their monthly First Reads selections. It’s early access to popular new books. Sweet!

📱“Can I use your iPhone?” Sure, but let’s keep it to a single app, no snooping around. Go to Settings > Accessibility > Guided Access to toggle it on. Open the app, triple-tap your right-side button and press Start. When they’re done, triple-click the side button again to enter your passcode or Face ID to unlock it.

💸 Scammers are posing as Fidelity, Morgan Stanley and other financial giants: Remember, they’ll never call or text asking for your password, one-time code, money transfers or remote access to your computer. If something feels off, stop and contact them directly. Stay sharp!

🚫 Kick moochers off your Netflix: Changing the password is one thing, but you can also log everyone out so they’ll have to sign in again. Just click your Profile icon (top right) > Account > Manage access and devices > Sign Out of All Devices. Want to be more selective? You can also remove specific devices!

Use ChatGPT Premium? Watch out for an email that says, “Action Required: Secure Continued Access to ChatGPT with a $24 Monthly Subscription.” It looks official, logos and all, but it’s not.

Lifetime subscriptions: It’s the newest marketing ploy. Pay once and get access forever, right? But “forever” means “as long as the company stays in business” (paywall link). If it shuts down or abandons the app, you’re out of luck. Ask yourself, “Will I use this five years from now?” Probably not.

🥫 Inflation hits hard: A guy is going viral on TikTok for tapping the “Reorder” button in his Walmart grocery app. What was $126.67 two years ago for groceries (45 items) is now $414.39 for the very same products. I wouldn’t be surprised if Walmart limits access to past order histories.

Spies want in on your router

Open/download audio

Is yours at risk? Hackers’ new side hustle is charging Chinese and Russian spies and scammers for access to old home routers so they can launch denial-of-service (DoS) attacks. Plus, Google blocks romance writer, worst airlines for luggage, and Microsoft gets hacked.