<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:base="https://briangreenberg.net/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>briangreenberg.net</title>
    <link>https://briangreenberg.net/</link>
    <atom:link href="https://briangreenberg.net/feed/index.xml" rel="self" type="application/rss+xml" />
    <description>Security &amp; technology leadership — essays by Brian Greenberg.</description>
    <language>en</language>
    <item>
      <title>A Claude Code Skill to help you write better code.</title>
      <link>https://briangreenberg.net/2026/06/30/a-claude-code-skill-to-help-you-write-better-code/</link><description>&lt;p&gt;Everyone&#39;s using AI to write code faster, and almost nobody&#39;s using it to write code better. So I built something to help myself do just that, and I&#39;m putting it out there.&lt;/p&gt;
&lt;p&gt;It&#39;s a Claude Code skill called &lt;a href=&quot;https://github.com/bjgreenberg/senior-engineering-partner&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;senior-engineering-partner&lt;/a&gt;. It&#39;s not autocomplete. It&#39;s the strict senior engineer who reviews your pull request, asks why you skipped the tests, and won&#39;t let you ship a hardcoded secret because you were &amp;quot;just prototyping.&amp;quot;&lt;/p&gt;
&lt;p&gt;A few things it does:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enforces a real workflow. Agree on the spec, plan in verifiable steps, write the test first, then prove the work before calling it done.&lt;/li&gt;
&lt;li&gt;Holds a security floor that never moves. Whether you&#39;re prototyping or running in production, the secrets and input-validation basics stay non-negotiable. Cheap doesn&#39;t mean insecure.&lt;/li&gt;
&lt;li&gt;Refuses to hallucinate. It verifies claims about your environment by running a real command, rather than inventing a flag or an API that sounds right.&lt;/li&gt;
&lt;li&gt;Switches modes depending on how you call it: reviewer, debugger, mentor, or pair programmer.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class=&quot;wp-block-image size-large has-lightbox&quot;&gt;&lt;img src=&quot;https://briangreenberg.net/uploads/2026/06/senior-engineering-partner-1024x683.jpg&quot; alt=&quot;&quot; class=&quot;wp-image-8400&quot;&gt;&lt;/figure&gt;
&lt;p&gt;It&#39;s open source under Apache-2.0, stack-agnostic, and built around Python, Bash, Apps Script, and JavaScript.&lt;/p&gt;
&lt;p&gt;Here&#39;s my ask. Use it. Then tell me where it&#39;s wrong. I want the good feedback and the brutal feedback, plus any capability you wish it had. The whole point is to encode what senior engineers actually do, and I&#39;d rather hear it breaks on your stack than find out later.&lt;/p&gt;
&lt;p&gt;What would you want a skill like this to enforce?&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://github.com/bjgreenberg/senior-engineering-partner&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://github.com/bjgreenberg/senior-engineering-partner&lt;/a&gt;&lt;/p&gt;
</description><pubDate>Mon, 29 Jun 2026 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2026/06/30/a-claude-code-skill-to-help-you-write-better-code/</guid>
    </item>
    <item>
      <title>Micro-Transformations: AI&#39;s Real Path to ROI</title>
      <link>https://briangreenberg.net/2026/05/07/micro-transformations-ais-real-path-to-roi/</link><description>&lt;p&gt;Reading the headlines, it seems as though AI is already reshaping every enterprise. Boards are approving eight-figure AI programs, executives are announcing “AI-first” strategies, and vendors are achieving productivity gains by seasoning their products with AI across the board.&lt;/p&gt;
&lt;p&gt;But behind the scenes, many leaders are frustrated. The return on investment from large, enterprise-wide AI initiatives has been, as Deloitte points out, &lt;a href=&quot;https://www.deloitte.com/nl/en/issues/generative-ai/ai-roi-the-paradox-of-rising-investment-and-elusive-returns.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;underwhelming, delayed, or difficult to measure&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In my experience, many organizations are trying to run before they can walk. They might find micro-transformations a more practical approach, starting with small, low-risk AI integrations that naturally fit into existing workflows to deliver early, measurable wins.&lt;/p&gt;
&lt;h2&gt;The Hype Versus The Reality&lt;/h2&gt;
&lt;p&gt;Media coverage and vendor marketing spotlight moonshot AI projects: custom models, sweeping data platform overhauls, and enterprise-wide automation programs on the bleeding edge.&lt;/p&gt;
&lt;p&gt;These initiatives require huge investments in data engineering, governance, talent, and change management. In practice, only a handful of companies—typically hyperscalers and digital-native firms—possess the depth of data maturity, talent density, and operational discipline needed for large-scale AI programs.&lt;/p&gt;
&lt;p&gt;For many other organizations, expensive AI initiatives become what some call &amp;quot;innovation theater,&amp;quot; highly visible pilots and dashboards that signal progress but produce little day-to-day impact.&lt;/p&gt;
&lt;p&gt;Recent research underscores this gap between ambition and outcome. Research from both &lt;a href=&quot;https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;McKinsey&lt;/a&gt; and &lt;a href=&quot;https://web-assets.bcg.com/c1/a7/af0e57dc4b47a31eb7409d981d3e/mitsmr-bcg-ai-report-november-2024.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;MIT Sloan&lt;/a&gt; has shown that, while AI adoption is rising, the proportion of organizations achieving material financial returns remains modest.&lt;/p&gt;
&lt;p&gt;That disconnect resonates from a January 2026 analysis of &lt;a href=&quot;https://www.theregister.com/2026/01/20/pwc_ai_ceo_survey/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;PwC’s 29th Global CEO Survey&lt;/a&gt;, which reported that “&lt;a href=&quot;https://www.theregister.com/2026/01/20/pwc_ai_ceo_survey/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;more than half of CEOs&lt;/a&gt; report seeing neither increased revenue nor decreased costs from AI, despite massive investments in the technology… Only 12% reported both lower costs and higher revenue, while 56% saw neither benefit.”&lt;/p&gt;
&lt;p&gt;The technology itself is still evolving rapidly. Betting heavily on expensive, custom solutions can lock organizations into tools and architectures that quickly become outdated.&lt;/p&gt;
&lt;h2&gt;Cultural And Behavioral Barriers&lt;/h2&gt;
&lt;p&gt;Even when the technology works, organizations don’t have to transform overnight. The Harvard Business Review has made a &lt;a href=&quot;https://hbr.org/2025/06/the-ai-revolution-wont-happen-overnight&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;similar point, perhaps more bluntly&lt;/a&gt;: The AI revolution will arrive on enterprise time—longer, slower, and with far more friction than the hype implies.&lt;/p&gt;
&lt;p&gt;History offers a useful analogy. The introduction of personal computers in the 1980s and 1990s did not instantly make companies more productive. It took years of experimentation, new workflows, and cultural adjustment before PCs delivered their full value.&lt;/p&gt;
&lt;p&gt;AI presents a similar challenge, but at a faster and more complex pace. Expecting employees to “flip a switch” and fundamentally change how they work just won&#39;t happen. &lt;a href=&quot;https://www.pewresearch.org/social-trends/2025/02/25/u-s-workers-are-more-worried-than-hopeful-about-future-ai-use-in-the-workplace/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Many workers&lt;/a&gt; are unsure how AI fits into their roles, are skeptical of its quality, or are concerned about risk, accountability, or just being replaced.&lt;/p&gt;
&lt;p&gt;Without time to build trust and practical experience, adoption stalls—no matter how cool the underlying technology.&lt;/p&gt;
&lt;h2&gt;Micro-Transformations As A Practical Alternative&lt;/h2&gt;
&lt;p&gt;Micro-transformations offer another way forward, aligning closely with findings from &lt;a href=&quot;https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;McKinsey&lt;/a&gt; and &lt;a href=&quot;https://www.cio.com/article/4106788/ai-roi-how-to-measure-the-true-value-of-ai-2.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;CIO.com&lt;/a&gt; that organizations seeing early AI ROI tend to focus on narrow, operationally embedded use cases rather than enterprise-scale reinvention.&lt;/p&gt;
&lt;p&gt;Rather than attempting to redesign the enterprise around AI, leaders can focus on small, contained use cases that solve real problems today. A micro-transformation is typically:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Low or no additional cost&lt;/li&gt;
&lt;li&gt;Embedded in existing tools and workflows&lt;/li&gt;
&lt;li&gt;Easy to measure&lt;/li&gt;
&lt;li&gt;Low risk to operations and compliance&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Examples are already hiding in plain sight. Many organizations are paying for AI capabilities built into platforms they use every day, such as Gemini in Google Workspace and Copilot in Microsoft 365.&lt;/p&gt;
&lt;p&gt;Consider a simple starting point: In Gmail, ask Gemini to analyze your email from the past week and generate a prioritized task list. There is no new system to deploy, no data pipeline to build, and no governance committee required. Yet the productivity impact for an individual knowledge worker can be immediate and tangible.&lt;/p&gt;
&lt;p&gt;Or, in Google Drive, right-click a folder and have Gemini summarize it. No more digging through piles of files.&lt;/p&gt;
&lt;p&gt;Other micro-transformations include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using Microsoft Copilot, Zoom AI Companion, or Google Meet to summarize meeting transcripts, extract action items, and email them to the participants.&lt;/li&gt;
&lt;li&gt;Having AI draft first-pass reports or client updates that humans review and refine.&lt;/li&gt;
&lt;li&gt;Analyzing support tickets or internal requests to identify patterns and recurring issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These are not flashy initiatives, but they create momentum. More importantly, they build organizational muscle memory for using AI effectively.&lt;/p&gt;
&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img src=&quot;https://briangreenberg.net/uploads/2026/05/AI-Micro-Transformations-1024x572.jpg&quot; alt=&quot;&quot; class=&quot;wp-image-8226&quot;&gt;&lt;/figure&gt;
&lt;h2&gt;How Leaders Can Implement Micro-Transformations&lt;/h2&gt;
&lt;p&gt;For leaders looking to move beyond experimentation, a few principles help:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Start where the work already happens.&lt;/strong&gt; Focus on AI features embedded in tools your teams use daily. Adoption friction is dramatically lower when people don’t need to learn a new platform.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Define ROI narrowly.&lt;/strong&gt; For small AI tasks, ROI doesn’t need to be complex. CIO.com reporting indicates that organizations that can clearly articulate time saved, error reduction, or cycle-time improvements are far more likely to scale AI responsibly. Measure time saved, error reduction, or cycle-time improvements. If a tool saves 15 minutes per employee per day, the math adds up quickly.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Create a crawl-walk-run roadmap.&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Crawl: Individual productivity gains and low-risk automations.&lt;/li&gt;
&lt;li&gt;Walk: Team-level use cases with light process changes.&lt;/li&gt;
&lt;li&gt;Run: Larger, cross-functional AI initiatives informed by real-world learning.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Normalize experimentation.&lt;/strong&gt; Encourage teams to test, share successes, and failures. Cultural acceptance grows through practical use, not top-down mandates.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The promise of AI in business is real, but the path to value is rarely a straight line. Large, enterprise-wide AI programs can succeed—but only when organizations are ready. For many, the faster and safer route is through micro-transformations that deliver early wins, build confidence, and generate measurable ROI.&lt;/p&gt;
&lt;p&gt;By shifting focus from grand transformations to practical, incremental progress, leaders can turn AI from a strategic aspiration into a daily advantage. For boards and executive teams, the right question is no longer &amp;quot;Do we have an AI strategy?&amp;quot; but &amp;quot;Where are we seeing real, measurable impact today—and what did it cost to achieve?&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;, CIO at &lt;a href=&quot;https://rhrinternational.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;RHR International&lt;/a&gt;. This article first appeared on &lt;a href=&quot;https://www.forbes.com/councils/forbestechcouncil/2026/02/24/micro-transformations-a-practical-path-to-ai-roi-in-business/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 02/24/2026.&lt;/em&gt;&lt;/p&gt;
</description><pubDate>Wed, 06 May 2026 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2026/05/07/micro-transformations-ais-real-path-to-roi/</guid>
    </item>
    <item>
      <title>How to Protect Yourself from Identity Theft</title>
      <link>https://briangreenberg.net/2026/05/07/how-to-protect-yourself-from-identity-theft/</link><description>&lt;h2&gt;The Threat Model&lt;/h2&gt;
&lt;p&gt;Let’s face it, your personal data is already out there. Not &amp;quot;may have been exposed.&amp;quot; Trust me, it has been. Assume it, and you’ll be better off. So, now, the question isn&#39;t whether someone has your information; it&#39;s whether it’s usable.&lt;/p&gt;
&lt;p&gt;How they can be used, and the attack surfaces that actually matter: new credit accounts opened in your name, employment fraud using your SSN, fraudulent tax returns filed before you file yours, bank account takeover, and physical mail interception. Most of these are preventable with free government tools that the vast majority of people have never touched.&lt;/p&gt;
&lt;p&gt;This guide walks you through all of them.&lt;/p&gt;
&lt;h2&gt;Quick-Start Checklist&lt;/h2&gt;
&lt;p&gt;Do these in order — the first five take about 90 minutes total and give you the most protection for your time. Full details on how and where to do each one follow below.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Freeze your credit at Equifax, Experian, TransUnion, and Innovis&lt;/li&gt;
&lt;li&gt;Freeze ChexSystems (the banking equivalent of a credit bureau — prevents someone from opening a fraudulent bank account in your name)&lt;/li&gt;
&lt;li&gt;Get an IRS Identity Protection PIN (prevents someone from filing a tax return in your name)&lt;/li&gt;
&lt;li&gt;Set up E-Verify Self Lock (prevents someone from using your Social Security number to get a job)&lt;/li&gt;
&lt;li&gt;Enroll in USPS Informed Delivery (so you know what mail is coming to your address)&lt;/li&gt;
&lt;li&gt;Enable multi-factor authentication (MFA) or passkeys on all financial and government accounts&lt;/li&gt;
&lt;li&gt;Enable MFA or passkeys on all healthcare patient portals (MyChart, etc.)&lt;/li&gt;
&lt;li&gt;Lock your phone number against SIM swaps with your mobile carrier&lt;/li&gt;
&lt;li&gt;Run all your email addresses through &lt;a href=&quot;http://haveibeenpwned.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;haveibeenpwned.com&lt;/a&gt; to see if they&#39;ve been exposed in a breach&lt;/li&gt;
&lt;li&gt;Pull your MIB and IntelliScript reports (your medical and prescription history reports — used by insurance companies the way lenders use credit bureaus) and check for anything you don&#39;t recognize&lt;/li&gt;
&lt;li&gt;Sign up for a data broker removal service such as DeleteMe or Kanary to get your personal information scrubbed from people-search sites&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;em&gt;If your Social Security number is already known to be compromised, also call the Social Security Administration at (800) 772-1213 to block electronic access to your SSA record.&lt;/em&gt;&lt;/p&gt;
&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img src=&quot;https://briangreenberg.net/uploads/2026/05/Personal-Data-Breach-Risk-Mitigation-A-Practical-Guide-1024x341.jpg&quot; alt=&quot;&quot; class=&quot;wp-image-8241&quot;&gt;&lt;/figure&gt;
&lt;h2&gt;Credit Freeze vs. Credit Lock: Know the Difference&lt;/h2&gt;
&lt;p&gt;Your credit score is a number between 300 and 850 that tells lenders how risky it is to lend you money. Everyone with a credit history has one — it&#39;s calculated by the three major credit bureaus (Equifax, Experian, and TransUnion) based on your borrowing and repayment history. The higher the number, the better. Freezing your credit has zero impact on your score — it just slams the door on anyone trying to open new accounts in your name.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Credit Freeze&lt;/strong&gt; (also called a security freeze) is your default choice. It is federally mandated and free to place, lift, and remove at all three major credit bureaus. It&#39;s backed by federal law, which means the rules are clear and the legal protections are strong. When frozen, lenders can&#39;t pull your credit file, so new accounts can&#39;t be opened in your name. If you request a thaw online or by phone, the freeze must be lifted within one hour.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Credit Lock&lt;/strong&gt; is a product offered by the bureaus — not a legal right. Locking your report is usually a feature of a subscription service, and canceling that subscription may unlock it. Locks are slightly faster to toggle on/off and often come bundled with monitoring alerts, but credit locks operate under private service agreements with fewer consumer protections than federal freeze legislation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bottom line:&lt;/strong&gt; Freeze &amp;gt; Lock. Freezes are free, legally protected, and permanent until you lift them. Only consider a lock if you want the real-time toggle convenience and are already paying for a monitoring service.&lt;/p&gt;
&lt;p&gt;You must freeze or lock &lt;strong&gt;each bureau separately&lt;/strong&gt;. There is no master switch.&lt;/p&gt;
&lt;h2&gt;Equifax&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.equifax.com/personal/credit-report-services/credit-freeze&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.equifax.com/personal/credit-report-services/credit-freeze&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Experian&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.experian.com/freeze/center.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.experian.com/freeze/center.html&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;TransUnion&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.transunion.com/credit-freeze&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.transunion.com/credit-freeze&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Innovis&lt;/h2&gt;
&lt;p&gt;The 4th bureau most people skip…&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.innovis.com/securityFreeze/index&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.innovis.com/securityFreeze/index&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;ChexSystems&lt;/h2&gt;
&lt;p&gt;Used by banks for checking account applications, separate from credit bureaus.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.chexsystems.com/security-freeze/place-freeze&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.chexsystems.com/security-freeze/place-freeze&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You should freeze ChexSystems if you&#39;re concerned about someone opening a fraudulent bank account in your name.&lt;/p&gt;
&lt;h2&gt;Fraud Alerts (Supplement to Freezes)&lt;/h2&gt;
&lt;p&gt;A fraud alert instructs lenders to take extra steps to verify your identity before extending credit. Unlike a freeze, it doesn&#39;t block access — it adds friction. There are two types:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Standard fraud alert&lt;/strong&gt; — free, lasts one year, renewable. You only need to file with one bureau; they&#39;re required to notify the other two. &lt;a href=&quot;https://www.equifax.com/personal/credit-report-services/credit-fraud-alerts/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Set it up here.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Extended fraud alert&lt;/strong&gt; — lasts 7 years, requires a police report or FTC Identity Theft Report. For victims who&#39;ve already experienced identity theft. &lt;a href=&quot;https://www.identitytheft.gov/Steps&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.identitytheft.gov/Steps&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Fraud alerts don&#39;t replace freezes — use both.&lt;/p&gt;
&lt;h2&gt;Lock Your Social Security Number (SSN)&lt;/h2&gt;
&lt;p&gt;&amp;quot;Locking your SSN&amp;quot; actually refers to two distinct protections in two different systems. Most people only know about one.&lt;/p&gt;
&lt;h2&gt;Block Electronic Access via the SSA&lt;/h2&gt;
&lt;p&gt;Calling the SSA at (800) 772-1213 to request a block on electronic access is the primary way to lock your Social Security number. This prevents anyone (including you) from viewing or modifying your Social Security records. If you need to make changes later, you can unlock it by calling again with proof of identity.&lt;/p&gt;
&lt;p&gt;The SSA recommends doing this if your SSN has been compromised. It&#39;s a blunt but effective tool — no one can access or update your SSA record online while this block is active. &lt;a href=&quot;https://www.ssa.gov/myaccount/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Check on your SSN status here.&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;E-Verify Self Lock (employment fraud)&lt;/h2&gt;
&lt;p&gt;Self Lock allows you to lock your SSN to prevent it from being misused in E-Verify. When you lock your SSN, nobody else can use it in E-Verify, which helps protect you from employment-related identity theft.&lt;/p&gt;
&lt;p&gt;Why this matters: if someone uses your SSN to get a job, their wages are being reported in your name to the IRS and the SSA — meaning you could owe taxes on income you never earned. Self Lock blocks fraud at employers that use E-Verify (which is most large employers).&lt;/p&gt;
&lt;p&gt;Self Lock is free and lasts for one year. Thirty days before the lock expires, you&#39;ll have the option to extend it. You can unlock at any time if you&#39;re applying for new jobs. &lt;a href=&quot;https://www.e-verify.gov/employees/mye-verify&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Set it up here.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Important:&lt;/strong&gt; Self Lock only protects E-Verify-participating employers. It doesn&#39;t block all SSN misuse — just employment authorization fraud.&lt;/p&gt;
&lt;h2&gt;Health Data Protection&lt;/h2&gt;
&lt;p&gt;Health-related identity theft is distinct from financial identity theft and often harder to catch. Someone can use your identity to receive medical care, obtain prescriptions, or file fraudulent insurance claims — leaving errors in your actual medical record that can affect your future care and coverage. Review your Explanation of Benefits statements every time one arrives. Any line item for a service, prescription, or provider you don&#39;t recognize warrants a call to your insurer.&lt;/p&gt;
&lt;h2&gt;MIB Group (Medical Information Bureau)&lt;/h2&gt;
&lt;p&gt;The MIB is the credit bureau of the health and life insurance world. Its member companies account for 99% of individual life insurance policies and 80% of health and disability policies issued in the US and Canada. It collects information on medical conditions and hazardous activities that insurance companies use to assess risk during underwriting. You&#39;re entitled to one free report annually. Pull it, check it for errors, and dispute anything inaccurate. Errors here can cost you coverage or inflate your premiums.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.mib.com/request_your_record.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.mib.com/request_your_record.html&lt;/a&gt;&lt;br&gt;
Phone: (866) 692-6901&lt;/p&gt;
&lt;h2&gt;Milliman IntelliScript&lt;/h2&gt;
&lt;p&gt;This is a separate specialty consumer reporting agency that tracks your prescription drug history. It gathers information from pharmacies, health insurance companies, and pharmacy benefit managers once you authorize the release of your records to an insurer. They will provide a free copy of your report upon request each year. Check it for medications you were never prescribed, a red flag for medical identity theft.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.rxhistories.com/for-consumers&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.rxhistories.com/for-consumers&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Your HIPAA Rights&lt;/h2&gt;
&lt;p&gt;Under HIPAA, you can request an &amp;quot;accounting of disclosures&amp;quot; from any covered healthcare provider. It’s a log of who has accessed or received your medical records, and when. This is an underused right. If you suspect someone has been using your identity to receive care, this is where you&#39;d see the evidence. Submit the request in writing to your provider&#39;s Privacy Officer.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.hhs.gov/hipaa/for-individuals/medical-records/index.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Federal HIPAA guidance&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Patient Portal Security&lt;/h2&gt;
&lt;p&gt;Every major health system (Epic/MyChart, Athena, etc.) now offers patient portals. Enable MFA and/or Passkeys on all of them. These accounts contain diagnoses, prescriptions, test results, and insurance information. Treat them the same way you treat your bank account.&lt;/p&gt;
&lt;h2&gt;Genetic Data — Delete or Opt Out&lt;/h2&gt;
&lt;p&gt;If you&#39;ve used a consumer DNA service, your genetic data is in a commercial database. 23andMe filed for bankruptcy in 2025 and was acquired, putting genetic data for millions of users at risk of sale or transfer. If you&#39;re a 23andMe customer, download your data and then delete your account and request deletion of your genetic sample from their labs. Other services (AncestryDNA, MyHeritage) have similar deletion options; exercise them.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://customercare.23andme.com/hc/en-us/articles/212170838&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;23andMe account deletion&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;One Key Limit to Know&lt;/h2&gt;
&lt;p&gt;HIPAA only covers &amp;quot;covered entities&amp;quot; — providers, insurers, and their business associates. It does not cover data brokers, wellness apps, fitness trackers, period tracking apps, or any app that isn&#39;t explicitly part of your clinical care. That health data flows freely and is largely unregulated. Audit which health-adjacent apps have access to your data, and revoke access to anything you don&#39;t actively use.&lt;/p&gt;
&lt;h2&gt;IRS Identity Protection PIN&lt;/h2&gt;
&lt;p&gt;An Identity Protection PIN (IP PIN) is a six-digit number that prevents someone else from filing a tax return using your SSN or ITIN. Tax-related identity theft is one of the most common and damaging breach outcomes — someone files a return in your name and collects your refund before you do.&lt;/p&gt;
&lt;p&gt;An IP PIN is valid for one calendar year; new PINs are generated at the beginning of each calendar year. You must include your current IP PIN whenever you file a federal return. The fastest way to get one is through your IRS online account, in the IP PIN section of your profile page.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IRS IP PIN enrollment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.irs.gov/payments/your-online-account&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;IRS online account&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can enroll proactively — you don&#39;t have to be a breach victim to get one. Do it now.&lt;/p&gt;
&lt;h2&gt;Monitor Your Credit Reports&lt;/h2&gt;
&lt;p&gt;You&#39;re entitled to free weekly credit reports from all three bureaus. Pull them, review them, and look for accounts you didn&#39;t open.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://www.annualcreditreport.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.annualcreditreport.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Set a reminder to check quarterly at a minimum. If you have a freeze active, you&#39;ll still see your own reports — the freeze only blocks external access.&lt;/p&gt;
&lt;h2&gt;Check If You&#39;ve Been Breached&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://haveibeenpwned.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://haveibeenpwned.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Enter your email addresses (all of them). This database tracks known breaches and shows which services leaked your data and what types of data were exposed. Set up alerts so you&#39;re notified of future breaches.&lt;/p&gt;
&lt;h2&gt;USPS Mail Diversion Fraud&lt;/h2&gt;
&lt;p&gt;Criminals can submit a Change of Address form in your name and redirect your mail. This is more common than people realize and can intercept financial documents, credit cards, and government correspondence.&lt;/p&gt;
&lt;p&gt;Enroll in USPS Informed Delivery — it sends you daily email previews of mail being delivered to your address, so you know what&#39;s coming and can spot unauthorized redirects: &lt;a href=&quot;https://informeddelivery.usps.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://informeddelivery.usps.com&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Password Hygiene and MFA&lt;/h2&gt;
&lt;p&gt;None of the above matters if your email or financial accounts are compromised via credential stuffing and other attacks. Foundational requirements you should employ now:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Unique passwords for &lt;strong&gt;&lt;em&gt;every&lt;/em&gt;&lt;/strong&gt; account — managed by a password manager such as &lt;a href=&quot;https://1password.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;1Password&lt;/a&gt;, &lt;a href=&quot;https://support.apple.com/en-us/120758&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Apple&lt;/a&gt;, &lt;a href=&quot;https://www.okta.com/products/okta-personal/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Okta&lt;/a&gt;, or &lt;a href=&quot;https://safety.google/intl/en_au/safety/authentication/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Google&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;TOTP-based &lt;a href=&quot;https://www.cisa.gov/MFA&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;MFA&lt;/a&gt; (authenticator app) on every account that supports it, such as &lt;a href=&quot;https://1password.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;1Password&lt;/a&gt;, &lt;a href=&quot;https://safety.google/intl/en_au/safety/authentication/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Google&lt;/a&gt;, &lt;a href=&quot;https://www.microsoft.com/en-us/security/mobile-authenticator-app&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Microsoft&lt;/a&gt;, &lt;a href=&quot;https://support.apple.com/en-us/120758&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Apple&lt;/a&gt;, or &lt;a href=&quot;https://www.okta.com/products/okta-personal/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Okta&lt;/a&gt; — not SMS, which is vulnerable to SIM swapping&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fidoalliance.org/passkeys/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Passkeys&lt;/a&gt; wherever offered — they&#39;re phishing-resistant by design&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For high-value accounts (email, bank, brokerage, IRS, SSA, E-Verify), MFA is non-negotiable.&lt;/p&gt;
&lt;h2&gt;SIM Swap Protection&lt;/h2&gt;
&lt;p&gt;Contact your carrier and add a PIN or passcode required for any account changes, port requests, or &lt;a href=&quot;https://consumer.ftc.gov/consumer-alerts/2019/10/sim-swap-scams-how-protect-yourself&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;SIM swaps&lt;/a&gt;. For AT&amp;amp;T, this is called “Wireless Account Lock”; for T-Mobile, this is called &amp;quot;Port Out Protection.&amp;quot; For Verizon, it&#39;s &amp;quot;Number Lock.&amp;quot;&lt;/p&gt;
&lt;p&gt;This prevents someone from porting your number to a new carrier and intercepting SMS-based MFA codes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://about.att.com/story/2025/wireless-account-lock.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;AT&amp;amp;T Wireless Account Lock&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.t-mobile.com/support/plans-features/help-with-t-mobile-account-fraud&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;T-Mobile Port out Protection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.verizon.com/support/account-pin-faqs/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Verizon Number Lock&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Data Broker Opt-Outs&lt;/h2&gt;
&lt;p&gt;Your name, address, phone number, relatives, and other PII are sold by data brokers and used to build profiles that enable advertising, phishing, social engineering, and physical targeting. This doesn&#39;t &amp;quot;freeze&amp;quot; anything — it&#39;s attrition — but reducing your footprint matters.&lt;/p&gt;
&lt;p&gt;Manual opt-out starting point: &lt;a href=&quot;https://privacyrights.org/data-brokers&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://privacyrights.org/data-brokers&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;For automated removal across hundreds of brokers, services like &lt;a href=&quot;https://joindeleteme.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;DeleteMe&lt;/a&gt; ($129/year) or &lt;a href=&quot;https://www.kanary.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Kanary&lt;/a&gt; handle this continuously.&lt;/p&gt;
&lt;p&gt;If you really want a deep dive, try the &lt;a href=&quot;https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Big Ass Data Broker Opt-Out List&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;What to Do If You&#39;re Already a Victim&lt;/h2&gt;
&lt;p&gt;If fraud has already occurred:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;File an FTC Identity Theft Report: &lt;a href=&quot;https://www.identitytheft.gov&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.identitytheft.gov&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;File a local police report (needed for extended fraud alerts and some dispute processes)&lt;/li&gt;
&lt;li&gt;Place an extended fraud alert (7 years) with one bureau&lt;/li&gt;
&lt;li&gt;Dispute fraudulent accounts directly with the bureau reporting them — use CFPB&#39;s dispute portal: &lt;a href=&quot;https://www.consumerfinance.gov/consumer-tools/credit-reports-and-scores/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://www.consumerfinance.gov/consumer-tools/credit-reports-and-scores/&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
</description><pubDate>Wed, 06 May 2026 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2026/05/07/how-to-protect-yourself-from-identity-theft/</guid>
    </item>
    <item>
      <title>Deepfakes And Social Engineering: A Growing Threat To Everyone</title>
      <link>https://briangreenberg.net/2025/10/05/deepfakes-and-social-engineering-a-growing-threat-to-everyone-%f0%9f%92%80/</link><description>&lt;p&gt;Deepfakes—AI‑generated video or audio—are used by attackers to impersonate executives, family members and &lt;a href=&quot;https://arstechnica.com/security/2025/05/fbi-warns-of-ongoing-scam-that-uses-deepfake-audio-to-impersonate-government-officials/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;government officials&lt;/a&gt;, convincing victims to send money or share sensitive information. We all face serious risks and need to be prepared.&lt;/p&gt;
&lt;p&gt;Think this is all just FUD? Consider these stories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;An employee joined a video call with what appeared to be the CFO and colleagues, only to learn later it was all a deepfake used to authorize over &lt;a href=&quot;https://www.theguardian.com/world/2024/feb/05/hong-kong-company-deepfake-video-conference-call-scam&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;$25 million&lt;/a&gt; in transfers.&lt;/li&gt;
&lt;li&gt;A bank manager wired &lt;a href=&quot;https://senseient.com/ride-the-lightning/cybercriminals-deepfake-company-directors-voice-in-35-million-bank-heist/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;$35 million&lt;/a&gt; after receiving a call from a director at the bank, whose voice—an AI clone backed by forged emails—he thought he recognized.&lt;/li&gt;
&lt;li&gt;A mother &lt;a href=&quot;https://www.theguardian.com/us-news/2023/jun/14/ai-kidnapping-scam-senate-hearing-jennifer-destefano&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;received a ransom call&lt;/a&gt; using her daughter’s voice; just three seconds of audio had been enough to create the fake. Although she discovered the call was an AI-generated hoax, &lt;a href=&quot;https://www.mcafee.com/blogs/privacy-identity-protection/artificial-imposters-cybercriminals-turn-to-ai-voice-cloning-for-a-new-breed-of-scam/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;a report found&lt;/a&gt; that most people can’t distinguish a real voice from an AI-generated one.&lt;/li&gt;
&lt;li&gt;Criminals have used &lt;a href=&quot;https://www.moneylaundering.com/news/criminals-using-ai-to-open-bank-accounts-digital-wallets-in-italy/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;deepfakes&lt;/a&gt; to bypass government facial recognition, file fake tax invoices and open accounts with synthetic identities. &lt;a href=&quot;https://www.scworld.com/news/deepfake-face-swap-attacks-on-id-verification-systems-up-704-in-2023&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Researchers logged&lt;/a&gt; a 704% increase in AI face-swap attacks against identity verification systems, highlighting the growing sophistication of these types of attacks.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These examples underscore the threats and what’s to come. Attackers can easily generate convincing digital impostors that fool people and biometric systems. The common thread in each case is social engineering, and this calls for layered verification.&lt;/p&gt;
&lt;h2&gt;What Multifactor Authentication Is&lt;/h2&gt;
&lt;p&gt;Relying on a single authentication factor (like a password or caller ID) isn’t enough. Multifactor authentication (MFA) requires people to present evidence from at least two of &lt;a href=&quot;https://www.keepersecurity.com/blog/2023/06/27/types-of-multi-factor-authentication-mfa/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;four categories&lt;/a&gt; to verify their identity.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Something You Know:&lt;/strong&gt; This includes passwords, PINs and answers to security questions. These are the weakest factor because they can be guessed or stolen.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Something You Have:&lt;/strong&gt; This is a physical item (like an ID badge), a hardware token or a one-time password (OTP) generated by an authenticator app. Authenticator apps produce six‑digit codes that expire every 30 to 60 seconds, making them very difficult to intercept. SMS (texting) codes are insecure because attackers can intercept them through &lt;a href=&quot;https://www.keepersecurity.com/blog/2023/04/19/what-is-sim-swapping/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;SIM‑swapping&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Something You Are:&lt;/strong&gt; These are your biometrics: fingerprints, facial recognition or iris scans. Everyone’s biometric data is unique; however, if your biometric data is compromised, it cannot be reset like a password.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Somewhere You Are:&lt;/strong&gt; A system may verify your physical location via GPS.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Steps For Organizations&lt;/h2&gt;
&lt;h2&gt;Assume &lt;em&gt;every&lt;/em&gt; channel is spoofed.&lt;/h2&gt;
&lt;p&gt;Never rely solely on caller ID, email headers or video presence. Require employees to verify any sensitive request using at least two independent channels, such as a secure messaging platform and MFA. Be sure to involve a verified second person for high‑value transactions.&lt;/p&gt;
&lt;h2&gt;Deploy MFA everywhere.&lt;/h2&gt;
&lt;p&gt;Enforce MFA for &lt;em&gt;everything&lt;/em&gt;. Use strong factors such as authenticator apps, hardware keys and biometrics. Incorporate adaptive authentication to prompt additional factors when behavior is unusual.&lt;/p&gt;
&lt;h2&gt;Educate staff about deepfake tactics.&lt;/h2&gt;
&lt;p&gt;Explain how realistic deepfake voices and videos can be created from just a few seconds of publicly available recordings. Encourage employees to verify people through official channels when asked to transfer funds or share information. Share real‑world cases like those detailed above.&lt;/p&gt;
&lt;h2&gt;Maintain a trusted contact directory.&lt;/h2&gt;
&lt;p&gt;Store colleagues’ phone numbers and secure email addresses in a password manager for easy access. When in doubt, call or message through a verified channel instead of responding directly to the initial request. Use code words or verification phrases known only to the parties involved.&lt;/p&gt;
&lt;h2&gt;Regularly review incident response plans.&lt;/h2&gt;
&lt;p&gt;Establish procedures for reporting suspected attacks and test them through tabletop exercises. Include communication plans for notifying leadership, law enforcement and potentially affected partners.&lt;/p&gt;
&lt;h2&gt;Tips For Families And Individuals&lt;/h2&gt;
&lt;p&gt;AI‑driven scams don’t just target corporations; they prey on emotions. &lt;a href=&quot;https://it.wisc.edu/news/ai-powered-scams-how-to-protect-yourself-2024/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Scammers only need a short audio clip&lt;/a&gt; to clone a voice and then claim a family member is in distress. As it&#39;s critical to protect your loved ones, here&#39;s how you can do just that:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Create a family code word.&lt;/strong&gt; Establish a &lt;a href=&quot;https://www.cbsnews.com/news/elder-scams-family-safe-word/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;unique word or phrase&lt;/a&gt; that only family members know and use it to verify urgent calls.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Slow down and verify.&lt;/strong&gt; Scammers create a sense of urgency. Take a beat to think critically and call back using a known number.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Limit what you share.&lt;/strong&gt; Be cautious about posting personal details online.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use MFA on&lt;/strong&gt; &lt;em&gt;&lt;strong&gt;all&lt;/strong&gt;&lt;/em&gt; &lt;strong&gt;personal accounts.&lt;/strong&gt; This includes email, banking, social media and more. A good password manager with a built‑in authenticator and passkeys (often already included on your devices for free) makes this easy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Trust your instincts.&lt;/strong&gt; If you get an “off” feeling, then verify. If something feels wrong, it probably is.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;A Final Thought&lt;/h2&gt;
&lt;p&gt;Deepfakes and social engineering are not science fiction. They are real, they&#39;re happening today and they are an immediate threat to organizations and families.&lt;/p&gt;
&lt;p&gt;Criminals exploit publicly available photos and recordings to create realistic digital fakes. Our defense needs to shift to verifying identities. MFA reduces the risk of compromise by &lt;a href=&quot;https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/MFA-Microsoft-Research-Paper-update.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;99.22%&lt;/a&gt; and provides a practical, scalable approach to restoring trust. By layering the four types of authentication factors and fostering a culture of verification and skepticism, you can keep your company and loved ones safe from the next AI-driven scam.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;, CIO at &lt;a href=&quot;https://rhrinternational.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;RHR International&lt;/a&gt;. This article first appeared on &lt;a href=&quot;https://www.forbes.com/councils/forbestechcouncil/2025/08/25/deepfakes-and-social-engineering-a-growing-threat-to-everyone/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 08/25/2025.&lt;/em&gt;&lt;/p&gt;
</description><pubDate>Sat, 04 Oct 2025 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2025/10/05/deepfakes-and-social-engineering-a-growing-threat-to-everyone-%f0%9f%92%80/</guid>
    </item>
    <item>
      <title>The Case For Federal Regulations In Cybersecurity: Requiring Passwords And Multifactor Authentication (MFA)</title>
      <link>https://briangreenberg.net/2024/12/08/the-case-for-federal-regulations-in-cybersecurity-requiring-passwords-and-multifactor-authentication-mfa/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://rhrinternational.com/profiles/brian-greenberg/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;, CIO at &lt;a href=&quot;https://rhrinternational.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;RHR International&lt;/a&gt;. This article first appears on &lt;a href=&quot;https://www.forbes.com/councils/forbestechcouncil/2024/11/08/the-case-for-federal-regulations-in-cybersecurity-requiring-passwords-and-multifactor-authentication-mfa/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 11/8/2024.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;As our world continues to move entirely online, the need for thoughtful cybersecurity has never been more urgent. Almost every aspect of modern life, from social activity and business to healthcare and banking, depends on the internet.&lt;/p&gt;
&lt;p&gt;With these new abilities and conveniences comes cybercrime. Cyberattacks are becoming more frequent and sophisticated, and companies and individuals are increasingly vulnerable to hacking, breaches and identity and data theft.&lt;/p&gt;
&lt;p&gt;Even though cybersecurity is a hugely complex and evolving field, one thing is absolutely clear—basic protections such as strong passwords with &lt;a href=&quot;https://www.cisa.gov/resources-tools/training/why-strong-password-isnt-enough-your-guide-multifactor-authentication&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;multifactor authentication (MFA) are essential&lt;/a&gt;. To ensure minimum security across the digital landscape, the federal government must create regulations that mandate these basic measures for all companies with a web presence.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The Growing Threat Of Cybercrime&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The rise in cybercrime is staggering. Global cybercrime costs are expected to hit &lt;a href=&quot;https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;$10.5 trillion annually&lt;/a&gt; by 2025, up from $3 trillion in 2015. This includes everything from stolen money and intellectual property to recovery after a data breach. The Federal Bureau of Investigation (FBI) &lt;a href=&quot;https://www.fbi.gov/contact-us/field-offices/springfield/news/internet-crime-complaint-center-releases-2022-statistics&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;reported&lt;/a&gt; a record number of cybercrime complaints in 2022, with losses totaling over $10 billion in the U.S. alone.&lt;/p&gt;
&lt;p&gt;Businesses, regardless of size, are prime targets for hackers. With &lt;a href=&quot;https://www.verizon.com/business/resources/articles/small-business-cyber-security-and-data-breaches/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;43% of cyberattacks&lt;/a&gt; aimed at small businesses, small and medium-sized businesses (SMBs) are the most vulnerable due to their low expertise and investment in cybersecurity.&lt;/p&gt;
&lt;p&gt;The consequences of cyberattacks are pretty dire—not only can they cripple a business financially, but they also erode trust with their customers. Repeated breaches lead to losing customers, lawsuits and reputational damage. Large corporations’ fallout from a data breach can involve multi-million-dollar fines, as seen in cases like the Equifax data breach, which resulted in an &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;over $500 million&lt;/a&gt; settlement in 2019.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Why Federal Regulations Are Necessary&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The cybersecurity landscape is fragmented. Some businesses invest heavily in protection, and others do the bare minimum. This disparity creates a situation where vulnerabilities in one company are exploited to gain access to more extensive networks and impact entire supply chains. For example, the infamous Target data breach in 2013, which exposed the credit card information of over 40 million customers, allegedly originated from &lt;a href=&quot;https://www.npr.org/sections/thetwo-way/2014/02/05/272101928/u-s-hvac-firm-reportedly-linked-to-target-s-data-security-breach&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;a small HVAC subcontractor&lt;/a&gt; with poor security practices.&lt;/p&gt;
&lt;p&gt;Despite this, many businesses still don’t enforce even the most basic security measures like strong passwords with MFA. A 2021 survey by LastPass found that &lt;a href=&quot;https://www.lastpass.com/-/media/10aa2f653c774e428aa4cc6732734828.pdf&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;only 57% of businesses&lt;/a&gt; used MFA for employees. Frankly, this is terrifying, considering how effective MFA is. According toMicrosoft, enabling MFA can block &lt;a href=&quot;https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;99.9% of attacks&lt;/a&gt; on your accounts.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The Complexity Of Cybersecurity Regulations&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Do not underestimate just how complex cybersecurity is. Cyber threats constantly change, and no one-size-fits-all solution will protect against every possible attack. There is no such thing as perfect security. Businesses operate in various industries with different levels of exposure and risk. For example, a local bakery with an online ordering system has cybersecurity needs that are different from those of a financial institution with sensitive personal data.&lt;/p&gt;
&lt;p&gt;While more advanced cybersecurity practices may vary by industry, certain foundational protections—such as strong passwords with MFA—should be required universally. Passwords, while imperfect, are the first line of defense against unauthorized access. Poor password hygiene, ubiquitous among most people, such as using weak or reused passwords, &lt;a href=&quot;https://www.verizon.com/business/resources/reports/dbir/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;is responsible for 81% of hacking-related data breaches&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Multifactor authentication enhances security by requiring users to present two or more verification factors. These factors typically encompass something the user knows (such as a password), something they possess (like a smartphone) or something inherent to them (like a fingerprint). Implementing MFA allows businesses to significantly reduce the risk of unauthorized access for themselves, their users and their customers, even if passwords are stolen.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The Benefits Of Federal Cybersecurity Regulations&lt;/strong&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;strong&gt;Protecting Consumers And Businesses&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Enabling MFA would help protect both consumers and businesses from the financial and emotional toll of hacking. Companies implementing passwords with MFA reduce the risk of hacking. This means greater peace of mind for consumers when engaging with businesses and fewer costly breaches and lawsuits.&lt;/p&gt;
&lt;p&gt;The Ponemon Institute andIBM &lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;reported&lt;/a&gt; that the average cost of a data breach in 2024 is $4.88 million per incident. Enabling MFA would dramatically reduce these incidents.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Leveling The Playing Field&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Federal regulations would ensure that all businesses adopt essential security measures. This would level the playing field by ensuring that all companies, regardless of size, protect their customers. It would also reduce the incentive for hackers to target small, unprotected businesses as an entry point to larger companies.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Encouraging Innovation&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Setting minimum security standards would also spur innovation in cybersecurity. When businesses are required to meet security benchmarks, they are more likely to invest in cybersecurity R&amp;amp;D, which could lead to better technologies that protect against emerging threats.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Global Competitiveness&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;With the rise in international cybercrime, U.S. businesses must be prepared to compete in a global economy that increasingly values data privacy and security. The European Union’s General Data Protection Regulation (GDPR) has already set a high standard for data protection. If the U.S. doesn’t implement similar federal regulations, American companies may fall behind in global markets that prioritize cybersecurity.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Enhancing Security With MFA: Your Digital Seatbelt&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Using MFA is like wearing a seatbelt—it adds an extra layer of protection. Just as a seatbelt can save you in an accident, MFA safeguards your account even if your password is stolen.&lt;/p&gt;
&lt;p&gt;Both also benefit everyone else. Seatbelts reduce the strain on families and emergency services, and MFA helps prevent hacking, protecting not only you but also co-workers, clients and families.&lt;/p&gt;
&lt;p&gt;Best of all, enabling MFA is usually free for both individuals and businesses.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Building A More Secure Digital Future&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;We can no longer afford to leave cybersecurity to chance. Specific baseline measures—like strong passwords with MFA—should be required of all companies. Federal regulations mandating these protections would create a safer online environment, protecting both consumers and businesses from the devastating effects of cyberattacks.&lt;/p&gt;
&lt;h2&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/h2&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/the-case-for-federal-regulations-in-cybersecurity-requiring-passwords-and-multifactor-authentication-mfa-by-brian-greenberg?si=7f09743c7bef44aeb72e10704bdf96ae&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Sat, 07 Dec 2024 18:00:00 -0600</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2024/12/08/the-case-for-federal-regulations-in-cybersecurity-requiring-passwords-and-multifactor-authentication-mfa/</guid>
    </item>
    <item>
      <title>How To Incorporate AI Into Your Company Without Feeding The Beast</title>
      <link>https://briangreenberg.net/2024/11/07/how-to-incorporate-ai-into-your-company-without-feeding-the-beast/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://rhrinternational.com/profiles/brian-greenberg/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;, CIO at &lt;a href=&quot;https://rhrinternational.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;RHR International&lt;/a&gt;. This article first appears on &lt;a href=&quot;https://www.forbes.com/councils/forbestechcouncil/2024/10/11/how-to-incorporate-ai-into-your-company-without-feeding-the-beast/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 10/11/2024.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;AI is everywhere, and integrating AI into your business can help boost efficiency, spark creativity and improve decision-making. With AI tools from major players like &lt;a href=&quot;https://ai.google/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Google&lt;/a&gt;, &lt;a href=&quot;https://www.microsoft.com/en-us/ai&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Microsoft&lt;/a&gt;, &lt;a href=&quot;https://www.apple.com/apple-intelligence/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Apple&lt;/a&gt;, &lt;a href=&quot;https://openai.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;OpenAI&lt;/a&gt;, &lt;a href=&quot;https://www.zoom.com/en/ai-assistant/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Zoom&lt;/a&gt; and more, you can streamline processes, collaborate better and get more done.&lt;/p&gt;
&lt;p&gt;However, as with any new technology, adopting AI comes with risks—especially regarding data security and privacy. You don’t want to accidentally &amp;quot;feed the beast&amp;quot; by giving these tools access to sensitive company data.&lt;/p&gt;
&lt;p&gt;Here’s how to safely integrate AI tools from vendors while protecting your data and preparing your team for a smooth transition.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Knowing The Benefits Of AI Tools&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;AI tools are incredibly powerful and offer a range of benefits for your business. Understanding what some of these benefits entail and determining what you need for your organizational needs is a good place to start.&lt;/p&gt;
&lt;p&gt;When it comes to repetitive tasks, for example, AI can manage data entry, scheduling and customer service responses. AI-driven analytics can help uncover patterns and insights that might have otherwise been missed.&lt;/p&gt;
&lt;p&gt;Furthermore, chatbots and personalized recommendations can make interactions smoother and more engaging, enhancing the overall customer experience. Tools like Microsoft Copilot and Zoom’s AI integrations can summarize meetings, generate reports and automate follow-up actions to help boost collaboration. These tools can make a huge difference in productivity, but they need to be used wisely.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Watching Out For Risks: Don’t Feed The Beast&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;One major concern when using AI tools is how they handle your company’s data. Many AI systems learn from the data they’re exposed to, which can become an issue if sensitive or proprietary information is unintentionally shared. Here’s how you can protect your data:&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Understand the tool’s data policy.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Different AI tools process data in different ways. Some retain it to improve their algorithms, while others keep it private. Make sure you know exactly how your vendor uses and stores data.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Be careful what you share.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Ensure your team avoids sharing sensitive information unless you’re sure it won’t be stored or used for the AI&#39;s ongoing development.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Check compliance with regulations.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;If you operate in regions with strict data privacy laws (like Europe’s GDPR), make sure the AI tools you use comply with these regulations. The vendor should offer transparency and allow you to opt out of certain data-sharing practices.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Use private and secure options.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Some vendors offer enterprise-level AI solutions that give you more control over data, including on-premise options that keep everything within your company’s network.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Verifying Vendor Security: How Secure Is Their AI?&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Before adopting any AI tool, it’s essential to ensure the vendor has strong security measures in place. Start by asking how your data will be stored and protected. Does the vendor encrypt data at all stages? Are there regular security audits and updates?&lt;/p&gt;
&lt;p&gt;Next, look for certifications. Vendors that adhere to standards like ISO 27001 or SOC 2 tend to have stronger security practices. Also, many large vendors publish transparency reports outlining how they collect, process and protect your data. Reviewing these can give you confidence in the tool’s security.&lt;/p&gt;
&lt;p&gt;If possible, be sure to run the tool in a sandbox environment to see how it interacts with your systems without risking real data.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Preparing Your Workforce&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Rolling out AI isn’t just about getting the right technology; it’s also about preparing your team. Here’s how to help them adapt:&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Offer training.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Make sure your employees know how the AI tools work, what data they use and how they can be used safely and effectively. Address common concerns such as whether AI will replace jobs or how it might impact privacy.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Set clear guidelines.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Create a companywide AI policy that outlines best practices for using AI tools, including what data can and can’t be shared. Update these guidelines regularly as AI tools evolve.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Encourage skepticism.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;AI is powerful but not perfect. Encourage your employees to double-check AI-generated outputs and use their judgment, especially for critical decisions.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Keep communication open.&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Provide a space where employees can ask questions, voice concerns or share insights about the AI tools. This can help them feel more comfortable and engaged with the technology.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Introducing AI Gradually&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;AI adoption doesn’t have to happen all at once. Start small and build from there. Identify one or two areas where AI can make an immediate impact, such as automating routine emails or helping with data analysis. At that point, you can monitor and adjust, keeping an eye on how the AI performs. Is it helping your team? Is it meeting your expectations? Use this feedback to fine-tune its usage before expanding further.&lt;/p&gt;
&lt;p&gt;AI is evolving fast, so be ready to adapt. You might need to scale back in some areas or explore new features as they become available.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Keeping An Eye On AI’s Future&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Vendors are constantly updating their AI tools with new features and capabilities. Stay proactive by regularly checking for new features or enhancements that might be useful to your business. Some vendors may even offer early access to new AI tools through beta programs, allowing you to test out cutting-edge features before they’re widely available.&lt;/p&gt;
&lt;p&gt;Another key thing to keep in mind is the importance of staying connected. Participate in AI forums, webinars or vendor-led communities to stay informed about trends and best practices.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Embracing AI Responsibly&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;AI can be a game changer for you and your company, but it’s essential to adopt it thoughtfully. By choosing the right vendors, understanding data privacy risks and educating your workforce, you can use AI to supercharge your business without putting your data at risk.&lt;/p&gt;
&lt;p&gt;The future is AI-driven. With the right tools, safeguards and strategies, you can lead your company into this new era with confidence.&lt;/p&gt;
&lt;h2&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/h2&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/how-to-incorporate-ai-into-your-company-without-feeding-the-beastbrian-greenberg?si=75ca563bbe214cb1a357f44587173aa8&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Wed, 06 Nov 2024 18:00:00 -0600</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2024/11/07/how-to-incorporate-ai-into-your-company-without-feeding-the-beast/</guid>
    </item>
    <item>
      <title>Why Every Website &amp; Newsletter Publication Should Offer an RSS Feed: A Call for Cleaner, Convenient News Reading</title>
      <link>https://briangreenberg.net/2024/09/15/why-every-website-newsletter-publication-should-offer-an-rss-feed-a-call-for-cleaner-convenient-news-consumption/</link><description>&lt;p&gt;I’ve been cleaning out my email inbox for weeks now—really years. What I’ve found is that so many messages are from the plethora of newsletters that I’ve signed up to over the many years I’ve had email. These days, it’s hard enough to stay updated with the latest news and content…it’s overwhelming. My email is flooded with newsletters, promotional materials, and updates, making it exhausting, if not impossible, to sift through the clutter to find what truly matters. Amid this information overload, one solution stands out for its simplicity and efficiency: RSS feeds. Surprisingly, many sites and pubs (publications) have moved away from offering RSS feed options, leaving us loyal readers yearning for a more streamlined way to consume content. &lt;/p&gt;
&lt;h2&gt;A Brief History of RSS Feeds&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;RSS&lt;/strong&gt;, which stands for &lt;strong&gt;Really Simple Syndication&lt;/strong&gt; or &lt;strong&gt;Rich Site Summary&lt;/strong&gt;, is a web feed format used to distribute and aggregate website content simply. Introduced in the late 1990s, RSS was developed to share updates from news sites and blogs in a standardized, machine-readable format.&lt;/p&gt;
&lt;p&gt;RSS feeds gained huge popularity during the early to mid-2000s. They empowered users to control their content consumption, aggregating updates from multiple sources into one convenient location in their favorite news reader. However, with the rise of social media platforms and algorithm-driven news feeds, RSS began to wane, leading many websites to deprioritize or remove their RSS offerings.&lt;/p&gt;
&lt;h2&gt;The Benefits of RSS Feeds&lt;/h2&gt;
&lt;h3&gt;For Consumers/Users:&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Inbox Decluttering&lt;/strong&gt;: Subscribing to content via email leads to a cluttered and schizophrenic inbox, where essential messages compete with newsletters and updates. RSS feeds eliminate this by delivering content to a separate feed reader and keeping your email strictly for personal and professional communication.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Customized Content Consumption&lt;/strong&gt;: RSS allows you to subscribe only to the feeds that interest you, creating a personalized news stream without unwanted content or advertisements.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Efficiency and Convenience&lt;/strong&gt;: With RSS, all updates are aggregated in one place, reducing the time and effort required to visit multiple sites. This centralized approach makes staying informed about the latest posts from preferred sources easier.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Offline Access&lt;/strong&gt;: Many RSS readers offer offline capabilities, enabling you to read content without an active internet connection once the feed has been synced.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;For Publishers:&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Increased Engagement&lt;/strong&gt;: By providing an RSS feed, publishers make it easier for readers to stay connected, fostering loyalty and encouraging regular engagement with their content.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Extended Reach&lt;/strong&gt;: RSS feeds can be integrated into various platforms and applications, exposing content to a broader audience who prefer using feed readers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Better Analytics&lt;/strong&gt;: Understanding how and when content is consumed through RSS can offer insights into reader behavior, aiding in refining content strategies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;User Satisfaction&lt;/strong&gt;: Catering to the preferences of all users, including those who favor RSS, enhances overall user experience and satisfaction.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Clearing Out the Inbox: The RSS Solution&lt;/h2&gt;
&lt;p&gt;Email newsletters can be a double-edged sword. While they keep us informed, they also contribute to massive inbox clutter, making it challenging to manage daily messages effectively. Important emails get lost amidst the flood of subscription content, leading to missed messages and added stress.&lt;/p&gt;
&lt;p&gt;RSS feeds fix this by segregating newsletters and such from the important emails you’ve been missing. By using a dedicated RSS reader to manage your subscriptions, you ensure your inbox focuses only on important messages. This separation enhances productivity and reduces the cognitive context switching and mental load of sorting through an overflowing inbox.&lt;/p&gt;
&lt;h2&gt;Why Websites Should Reintroduce RSS Feeds&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Meeting User Demand&lt;/strong&gt;: A dedicated user base that relies on RSS feeds for content consumption remains. Ignoring this demographic means losing out on consistent engagement from a segment of the audience.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Competitive Advantage&lt;/strong&gt;: In a digital space where user attention is fragmented, offering multiple avenues for content delivery can set a website apart from competitors who limit their distribution channels.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ease of Implementation&lt;/strong&gt;: Adding an RSS feed is straightforward and requires minimal maintenance. Most content management systems support RSS functionality natively or through simple plugins.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhancing Accessibility&lt;/strong&gt;: RSS feeds make content more accessible to users with different needs and preferences, including those who use assistive technologies.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;You no longer have to be dominated by algorithm-driven content and massively overflowing email inboxes. RSS feeds can free your inbox and put control back into your hands. For publishers, providing RSS feed options, websites, and publications can cater to a broader audience that values simplicity, efficiency, and personalization in their content reading.&lt;/p&gt;
&lt;p&gt;RSS feeds simplify and declutter inboxes and curate news intake. For publishers, embracing RSS can increase engagement, broaden reach, and enhance user satisfaction. It&#39;s time for websites and publications to finally recognize the enduring value of RSS feeds and reintegrate them into their content distribution strategies.&lt;/p&gt;
&lt;p&gt;This is why I’m unsubscribing from all my email newsletters and transferring them to RSS subscriptions. My inbox is getting so much lighter. Yours will, too. &lt;/p&gt;
&lt;p&gt;&lt;em&gt;Try the RSS news readers I enjoy&lt;/em&gt;: &lt;a href=&quot;https://netnewswire.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;NetNewsWire&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://feedly.com&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Feedly&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Empower your audience. Simplify your content delivery. Bring back the RSS feed.&lt;/strong&gt; 🗞️&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-781278093/rss-brian-greenberg?si=1967059fe1964cbf817eee60cfe6d8c3&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
&lt;p&gt;🎧 Listen to a podcast created by NotebookLM of this article.&lt;/p&gt;
</description><pubDate>Sat, 14 Sep 2024 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2024/09/15/why-every-website-newsletter-publication-should-offer-an-rss-feed-a-call-for-cleaner-convenient-news-consumption/</guid>
    </item>
    <item>
      <title>Rocking The Boat: Interim CIO/CTO Challenges</title>
      <link>https://briangreenberg.net/2024/08/13/rocking-the-boat-interim-cio-cto-challenges/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://rhrinternational.com/profiles/brian-greenberg/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;, CIO at &lt;a href=&quot;https://rhrinternational.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;RHR International&lt;/a&gt;. This article first appears on &lt;a href=&quot;https://www.forbes.com/councils/forbestechcouncil/2024/06/14/rocking-the-boat-interim-ciocto-challenges/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 6/14/2024.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;You may have heard about interim jobs like interim executive leaders (e.g., interim CEOs, CFOs or CIOs). The need for an interim leader can come from a variety of reasons. Unlike permanent leaders, interim leaders often step into roles that open unexpectedly due to resignation or termination.&lt;/p&gt;
&lt;p&gt;An interim chief information officer (CIO) plays a crucial role in temporarily managing an IT organization. Interim CIOs are typically brought in because they can quickly assess IT operations, align technology strategies with business objectives, and oversee technology projects or transitions. According to a &lt;a href=&quot;https://www.taplowgroup.com/insights/blogs/interim-executive-management-how-short-term-leaders-drive-long-term-results&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;study&lt;/a&gt; by the Interim Management Association (via Taplow Group), around 78% of companies have used interim executive services, a noticeable increase from 65% two years earlier.&lt;/p&gt;
&lt;p&gt;Here&#39;s a detailed look at when and why an organization might need an interim CIO:&lt;/p&gt;
&lt;h2&gt;When An Interim CIO Is Needed&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Leadership transition.&lt;/strong&gt; I&#39;ve been called in as an interim CIO when a previous CIO left abruptly, as the company didn&#39;t have a succession plan in place. A company might also underestimate how long it can take to find the right candidate for the role.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strategic overhauls.&lt;/strong&gt; I&#39;ve been the interim at an organization that reevaluated and changed its IT strategy. I was brought on to drive these initiatives, bringing a fresh perspective and expertise that did not exist within the organization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Crisis management.&lt;/strong&gt; There have been critical IT issues including data breaches, system failures and security vulnerabilities where an interim CIO with specific experience in crisis management and cybersecurity was invaluable in navigating and mitigating these challenges.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Digital transformation projects.&lt;/strong&gt; Companies looking to undergo digital transformations and implement major new technology systems have brought me in as an interim CIO to ensure they meet timelines and budgets while aligning with business goals.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mergers and acquisitions.&lt;/strong&gt; In mergers or acquisitions scenarios, I&#39;ve been able to help integrate systems and technologies from different companies, which requires specific skills and experiences.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The role of an interim CIO presents a unique set of challenges and opportunities. Interim leaders like myself often find themselves in an environment harboring a toxic culture, which requires a distinct approach to leadership. This unique position demands strategic thinking and quick decision-making, and it offers the opportunity to address immediate challenges and lay a strong foundation for future success.&lt;/p&gt;
&lt;h2&gt;Understanding The Terrain&lt;/h2&gt;
&lt;p&gt;When I step into a role as interim CIO, I often encounter a scenario where a lack of succession planning has left a gap in leadership. No one ever considered what they would do if the CIO left. This gap leads to disruptions in workflow, uncertainty among team members and stalled projects. The first step for an interim leader is to assess the situation quickly, understand the company&#39;s and department&#39;s immediate needs, and identify critical issues that require urgent attention.&lt;/p&gt;
&lt;h2&gt;Navigating A Possibly Toxic Environment&lt;/h2&gt;
&lt;p&gt;One of the most challenging aspects of an interim role can be navigating the existing culture, especially if the departure of the previous leader was due to toxic dynamics. Was that leader a source of toxicity, or did it come from another senior leader? What is the nature of that toxicity? An interim leader needs to be adept at understanding and maneuvering through such environments, which often involve:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Actively listening to team members.&lt;/li&gt;
&lt;li&gt;Identifying sources of conflict.&lt;/li&gt;
&lt;li&gt;Working toward creating a more positive and productive work atmosphere.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Strategic Planning And Execution&lt;/h2&gt;
&lt;p&gt;While interim leaders may not be in the role for the long haul, they will most likely need to make quick decisions with little information. Prior experience with multiple organizations is essential. Have I seen this before, and what actions must I take to prevent taking the wrong path?&lt;/p&gt;
&lt;h2&gt;Collaboration With An OD Consultant&lt;/h2&gt;
&lt;p&gt;Bringing an organizational development (OD) consultant or organizational psychologist can be a necessary strategy for an interim CIO. An OD consultant can objectively assess the organization&#39;s culture and dynamics, suggest strategies for improvement and help implement changes that can improve the company&#39;s overall health. This collaboration can create a more stable foundation for the next permanent leader.&lt;/p&gt;
&lt;h2&gt;Critical Strategies For The Success Of An Interim CIO&lt;/h2&gt;
&lt;p&gt;For an interim officer, the following strategies can help ensure success and continuity within the organization:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Rapid assessment and prioritization.&lt;/strong&gt; Quickly evaluate the current state of the business, identifying critical issues and prioritizing necessary actions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Effective communication.&lt;/strong&gt; Establish open lines of communication with team members, stakeholders and other department heads to build trust and facilitate valuable insights.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Focus on team building.&lt;/strong&gt; Work toward fostering a collaborative and positive team environment. This will include resolving conflicts, engaging in team-building exercises and addressing underlying issues contributing to a less-than-ideal culture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Maintain business continuity.&lt;/strong&gt; Ensure projects and critical operations run smoothly, which may involve implementing temporary measures or quick fixes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Develop a transition plan.&lt;/strong&gt; Create a comprehensive plan to transition to a permanent leader, aiming to minimize disruption to the department and the organization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leverage expertise.&lt;/strong&gt; Use their extensive experience and knowledge to guide and mentor team members, helping them navigate the transition effectively.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Be an agent of change.&lt;/strong&gt; A unique opportunity exists to initiate necessary changes that might be challenging for internal leaders due to existing relationships and politics. This role highlights their potential impact on the organization&#39;s future.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Balance short-term and long-term goals.&lt;/strong&gt; Monitor the department&#39;s and the organization&#39;s long-term objectives, ensuring that actions taken now will benefit the company.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Document and report.&lt;/strong&gt; Maintain detailed records of actions taken, issues encountered and progress made. This will be invaluable for the incoming permanent leader and organizational memory.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Remain objective.&lt;/strong&gt; Remain neutral and objective and make decisions in the IT department&#39;s and the organization&#39;s best interest.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The role of an interim CIO is challenging and rewarding. It requires strategic thinking, quick decision-making, effective communication and navigation of complex organizational dynamics. By focusing on these areas, an interim leader can address immediate challenges and lay a strong foundation for future success.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/rocking-the-boat-interim-cio-challengesbrian-greenberg?si=f6afdd92beca4a67916de3945048e624&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Mon, 12 Aug 2024 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2024/08/13/rocking-the-boat-interim-cio-cto-challenges/</guid>
    </item>
    <item>
      <title>Workers Of The World Unite: Embracing Technology In Every Job</title>
      <link>https://briangreenberg.net/2024/05/15/workers-of-the-world-unite-embracing-technology-in-every-job/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;. This article first appeared on &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2024/04/15/workers-of-the-world-unite-embracing-technology-in-every-job&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 4/15/2024.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Throughout my career, I’ve had the privilege of working in several industries and many roles. The one constant was that I needed to keep learning along the way. There was always a new process to understand or technology to become familiar with. There was always something new, and as time went on, there was more and more technology to learn.&lt;/p&gt;
&lt;p&gt;In the ever-evolving landscape of the modern workplace, a new reality emerged: Every worker, regardless of their field, is now a tech worker to some extent. This shift is not limited to the tech industry and IT; it encompasses every sector, ranging from healthcare, education and carpentry to food service, manufacturing and retail. As technology permeates every aspect of our lives, adapting and continually retraining has become paramount.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The New Tech Landscape In Traditional Fields&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The phenomenon isn’t simply a trend in the job market; it’s a mirror reflecting how deeply technology has rooted itself in the fabric of our work life. Integrating technology into every conceivable profession signals a departure from the past, where a clear delineation existed between a &amp;quot;tech job&amp;quot; and a &amp;quot;traditional job.&amp;quot;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Consider a nurse in a hospital, traditionally seen as a healthcare role. Today, they must use sophisticated digital systems for patient records, understand how to operate advanced medical equipment and stay updated with the latest health tech innovations.&lt;/li&gt;
&lt;li&gt;Educators are now expected to integrate digital platforms into their teaching methodologies, which increasingly blurred the once clear line between a &amp;quot;tech job&amp;quot; and a &amp;quot;traditional job.&amp;quot;&lt;/li&gt;
&lt;li&gt;Electricians, once primarily concerned with wires and circuits, are now at the forefront of installing smart home systems. This requires an understanding of electrical fundamentals, networking and digital connectivity. They are expected to be adept at navigating complex control systems and staying up to date with the latest smart technology.&lt;/li&gt;
&lt;li&gt;A carpenter, traditionally seen wielding hammers and saws, now uses design software for precision in woodwork, relies on advanced laser measurement tools for accuracy and may even employ CNC (computer numerical control) machines for intricate designs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Continuous Learning: The New Norm&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;As technology continues invading the job market, a continuous learning and adaptability attitude is essential. The demand is no longer for workers who can perform a set task. Instead, the emphasis is on those who can learn, unlearn and relearn as technology evolves.&lt;/p&gt;
&lt;p&gt;This dynamic is not restricted to mastering new software or tools; it also includes understanding the implications of technology on your industry, keeping up with cybersecurity concerns, staying ahead of digital trends, understanding how your data is managed and developing a mindset for innovation.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Technology: A Tool, Not A Threat&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;While some view this shift as intimidating, seeing it as an opportunity is more productive. Technology can be a potent tool to enhance efficiency, accuracy, creativity and productivity in any job when used effectively.&lt;/p&gt;
&lt;p&gt;For instance, automation and AI can take over mundane tasks, freeing workers to focus on more strategic, creative aspects of their roles. These technologies need to be seen as rockets that will launch a person or company forward, and they must be fueled by the knowledge of how to steer the technology.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Ubiquitous: No Job Exempt&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Wherever you look, technology is enhancing jobs. This doesn’t mean everyone needs to learn to write code in Python or become an IT expert and know everything about the cloud, but it does mean that tech literacy has become a fundamental skill, just like reading and writing. People must be familiar with essential tech tools and concepts relevant to their fields and be ready and able to explore new digital avenues as they emerge.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Reskilling: A Collaborative Effort&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Ongoing reskilling is a responsibility shared by everyone, employees and employers alike. Companies must provide learning opportunities, time and resources to help their staff keep pace with technological advancements. These could include training programs, workshops, online resources or partnerships with educational institutions.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Overcoming The Digital Divide&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;A significant challenge in this tech-driven work landscape is the digital divide. Workers in underprivileged areas or those who lack access to digital resources are at risk of being left behind. Bridging this gap requires concerted efforts from governments, educational bodies and corporations. Becoming tech literate is no longer a nice-to-have but a necessary life skill everyone needs access to.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The Future Of Work&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Looking ahead, the integration of technology into every job will only deepen. Fields like artificial intelligence, machine learning and data science will increasingly become part of various job descriptions, not just those in the tech sector.&lt;/p&gt;
&lt;p&gt;To thrive in this new era, workers must embrace their identity as tech workers, regardless of their job titles. This means being proactive in learning new skills, adapting to new tools and being open to how technology can improve their work and lives.&lt;/p&gt;
&lt;p&gt;The call to unite as tech workers transcends traditional job boundaries and industries. It’s a call to embrace the new realities of the workplace, where technology is not just an enabler but a necessary partner in every career path. We can successfully navigate this new landscape by adopting a continuous learning mindset, seeking opportunities to upskill and leveraging technology to our advantage. The future of work is here, and it&#39;s undeniably tech-centric.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/workers-of-the-world-unite-embracing-technology-in-every-job-brian-greenberg?si=9cf818dc26fc40ea8790daf655ddb110&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Tue, 14 May 2024 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2024/05/15/workers-of-the-world-unite-embracing-technology-in-every-job/</guid>
    </item>
    <item>
      <title>Understanding Smishing: How to Protect Yourself from SMS Phishing Scams</title>
      <link>https://briangreenberg.net/2024/04/05/understanding-smishing-how-to-protect-yourself-from-sms-phishing-scams/</link><description>&lt;p&gt;I&#39;ve been inundated recently with an unusual number of fake SMS text messages. It&#39;s hard to pinpoint the exact reason - perhaps it&#39;s a seasonal spike, a reflection of the political election cycle, or scammers are becoming increasingly bold in their tactics.&lt;/p&gt;
&lt;p&gt;This brings us to an important question: What is smishing? &#39;Smishing&#39; combines &#39;SMS&#39; (short message service) and &#39;phishing,&#39; which refers to a specific phishing attack through text messages. These scams cleverly manipulate victims into revealing private or financial information. Scammers craft text messages that mimic legitimate sources, such as banks or government agencies, often creating a sense of urgency or fear. For instance, you might receive a message claiming a problem with your bank account and a link to &#39;resolve&#39; the issue. Falling for these tactics can lead to severe financial loss or identity theft.&lt;/p&gt;
&lt;p&gt;However, it&#39;s crucial to handle such messages with skepticism. First and foremost, remember that legitimate organizations will never ask for sensitive information via text message. If you receive a request for personal details or financial information, it&#39;s a red flag. Also, be wary of clicking any links in these messages. Such links could lead to fraudulent websites that steal your information or infect your device with malware.&lt;/p&gt;
&lt;p&gt;Suppose you ever wonder if the authenticity of a message. In that case, avoiding directly interacting with it is the safest action. Instead, access the company&#39;s official website by typing the URL into your web browser or contact the company through official channels. This way, you can verify the information without falling prey to smishing schemes.&lt;/p&gt;
&lt;p&gt;Here are a couple of political texts I got this week. They both contain a link, which I never click on. I don&#39;t even send back STOP messages as that will only confirm to the sender that it&#39;s a good phone number, and the person will interact. Instead, I click the little link under the message that says &amp;quot;Report Junk.&amp;quot;&lt;/p&gt;
&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;a href=&quot;https://briangreenberg.net/uploads/2024/04/smishing-1-2.jpg&quot;&gt;&lt;img src=&quot;https://briangreenberg.net/uploads/2024/04/smishing-1-2-473x1024.jpg&quot; alt=&quot;&quot; class=&quot;wp-image-4535&quot;&gt;&lt;/a&gt;&lt;/figure&gt;
&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;a href=&quot;https://briangreenberg.net/uploads/2024/04/smishing-2-2.jpg&quot;&gt;&lt;img src=&quot;https://briangreenberg.net/uploads/2024/04/smishing-2-2-473x1024.jpg&quot; alt=&quot;&quot; class=&quot;wp-image-4536&quot;&gt;&lt;/a&gt;&lt;/figure&gt;
&lt;p&gt;Clicking that little link will give me the following popup, allowing me to Delete and Report the Message as Junk. Instead of just deleting the message, doing this will reduce the number of smishing texts you ultimately get.&lt;/p&gt;
&lt;figure class=&quot;wp-block-image aligncenter size-large&quot;&gt;&lt;a href=&quot;https://briangreenberg.net/uploads/2024/04/smishing-1a-1.jpg&quot;&gt;&lt;img src=&quot;https://briangreenberg.net/uploads/2024/04/smishing-1a-1-473x1024.jpg&quot; alt=&quot;&quot; class=&quot;wp-image-4548&quot;&gt;&lt;/a&gt;&lt;/figure&gt;
&lt;p&gt;In today&#39;s digital age, where personal data has immense value, staying informed and vigilant against such tactics is more important than ever. By understanding what smishing is and how to avoid it, you can protect yourself from these increasingly sophisticated and deceptive scams. Your knowledge and vigilance are your best defense.&lt;/p&gt;
</description><pubDate>Thu, 04 Apr 2024 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2024/04/05/understanding-smishing-how-to-protect-yourself-from-sms-phishing-scams/</guid>
    </item>
    <item>
      <title>Reassessing The Allure Of ‘Shiny Objects’ In Business Strategy</title>
      <link>https://briangreenberg.net/2023/07/31/reassessing-the-allure-of-shiny-objects-in-business-strategy/</link><description>&lt;p&gt;&lt;em&gt;By&lt;/em&gt; &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;em&gt;Brian Greenberg&lt;/em&gt;&lt;/a&gt;_.&lt;em&gt;This article first appeared on&lt;/em&gt; &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2023/06/21/reassessing-the-allure-of-shiny-objects-in-business-strategy&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;em&gt;Forbes&lt;/em&gt;&lt;/a&gt; &lt;em&gt;on 6/21/2023.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Under constant pressure to stay ahead of the competition, companies often adopt the latest technologies without proper foresight. When business leaders see another company making headlines for utilizing buzz-worthy tools—like blockchain, NFTs, AI, or deep learning—they often experience FOMO when they realize they&#39;re not. It&#39;s essential, however, to consider whether these new tools align with the company&#39;s overall goals and provide real value. That’s not to say that investigating the latest technologies isn’t the right thing to do. It just needs to be done thoughtfully. For those organizations that don’t engage with new technologies thoughtfully, they’ll likely experience several pitfalls associated with chasing new technologies (a.k.a. &amp;quot;shiny objects&amp;quot;), such as:&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;1. Diverting Significant Resources To Technologies That May Not Provide ROI&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Chasing new technologies can divert considerable resources and time from critical areas of the core business, especially if the business doesn’t have teams dedicated to the kinds of research it requires. Companies investing in the latest tech without considering their alignment with long-term goals waste resources and miss opportunities. Purchasing hardware and software and hiring specialized staff to integrate and maintain the new systems can be costly. Additionally, researching, implementing, and training employees on new technologies may detract from vital business areas. If the new technology fails to provide a significant return on investment, it adds no value to the business. To avoid chasing shiny objects, companies must ask if the new technologies improve the effectiveness of business processes or customer experiences. Does the technology align with the overall objectives and values? Does it have the potential to provide a substantial return on investment? By evaluating new technologies and their potential impact on their business, companies can avoid diverting resources and focus on investments that yield positive results.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;2. Losing Sight Of Core Values In Pursuit Of Short-Term Gains&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Chasing trends risks losing sight of a company&#39;s mission and values, leading to misaligned objectives and eroding customer trust. Focusing on short-term gains diverts resources from sustainable growth, hindering adaptability in a changing market. On the other hand, prioritizing long-term goals and staying true to the company’s mission can prevent trend-chasing and deliver lasting value.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;3. Failing To Establish A Comprehensive Strategy&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Chasing shiny objects prevents companies from creating a robust and comprehensive plan to withstand industry disruptions. Focusing on short-term fads detracts from long-term planning, considering core competencies, customer needs, and market shifts. This reactive approach leads to missed opportunities and hampers the ability to pivot in response to inevitable changes in the industry. To ensure long-term success and adaptability in volatile market conditions, companies must invest in developing a comprehensive strategic plan that aligns with their overall objectives and values. Adopting a proactive approach to business and anticipating industry changes enables companies to drive sustainable growth. Instead of chasing shiny objects, companies should build a solid foundation that can withstand industry disruptions and provide lasting value.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;4. Failing To Distinguish The Company From Competitors&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Chasing shiny objects can also impede companies from differentiating their products or services, resulting in imitation and a diminished competitive advantage. For example, by fixating on the latest trends or mirroring competitors, companies risk blending in and diluting their brand identity and undermining their unique selling points and identity. To establish a unique value proposition, companies must remain focused on their core competencies and develop innovative offerings that set them apart from competitors significantly and meaningfully. Organizations must build upon their strengths and capabilities to create a loyal customer base and a strong brand identity that resonates with their target audience.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;5. Excluding Customers Or Stakeholders Who May Not Be Interested&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Chasing shiny objects risks alienating customers uninterested in the latest technologies, who may perceive the company as insincere. Overemphasis on trends can harm a company&#39;s reputation and severely erode customer trust. Companies must balance adopting new technologies and addressing customer needs to maintain customer loyalty. By understanding their target audience, companies can offer tailored solutions that foster trust and loyalty, which can help ensure long-term success.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Embracing the latest trends and technologies can entice businesses, but chasing &amp;quot;shiny objects&amp;quot; without thoughtful consideration may lead to undesirable consequences. By remaining focused on core competencies and long-term objectives, companies can build a solid foundation, differentiate themselves in the marketplace and foster customer trust. It is essential to balance adopting new technologies and meeting customer needs to ensure lasting success while avoiding the pitfalls of chasing short-term gains and blending in with competitors. Thoughtful evaluation of new technologies and their alignment with overall goals will help companies drive sustainable growth and maintain a strong brand identity.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/reassessing-the-allure-of-shiny-objects-in-business-strategybrian-greenberg?si=a1e96f6b3fdf4a0aa8291db517ca5242&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Sun, 30 Jul 2023 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2023/07/31/reassessing-the-allure-of-shiny-objects-in-business-strategy/</guid>
    </item>
    <item>
      <title>Unleashing The Power Of IT Leadership: Revolutionizing The Business Landscape In The Digital Age</title>
      <link>https://briangreenberg.net/2023/06/26/unleashing-the-power-of-it-leadership-revolutionizing-the-business-landscape-in-the-digital-age/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;.&lt;br&gt;
This article first appeared on &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2023/05/22/unleashing-the-power-of-it-leadership-revolutionizing-the-business-landscape-in-the-digital-age&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 5/22/2023.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The landscape of modern business is in an ongoing state of flux, driven by rapid technological advancements and evolving customer expectations. As organizations adapt to this new reality, IT leadership has become critical to business success. The evolving role of IT leaders, including Chief Information Officers (CIOs), Chief Technology Officers (CTOs), and Chief Information Security Officers (CISOs), has transformed significantly in recent years to keep pace with these changes.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The Expanding Role Of IT Leadership&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;In the past, the role of IT leadership was primarily focused on maintaining an organization&#39;s technical infrastructure. However, as businesses increasingly rely on technology to drive growth and innovation, the responsibilities of IT leaders have evolved to encompass strategic planning and alignment with broader business objectives.&lt;/p&gt;
&lt;p&gt;Today, IT leaders must ensure that the organization&#39;s technical infrastructure is up-to-date and secure and drive innovation and digital transformation initiatives contributing to its bottom line. Additionally, growing cybersecurity threats and the need for effective data management have further expanded the responsibilities of IT leaders. Today, they are expected to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Drive digital transformation&lt;/strong&gt;: IT leaders must proactively lead initiatives that improve operational efficiency, enhance customer experiences, create competitive advantage, and create new revenue streams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Align IT with business strategy&lt;/strong&gt;: IT leaders must collaborate with other executives and communicate with the board to develop a cohesive strategy that aligns IT initiatives with broader business goals.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Foster innovation&lt;/strong&gt;: IT leaders must create an environment encouraging learning, innovation, and experimentation, helping their organizations stay ahead of the competition, evolve with endlessly changing technology, and adapt to varying market conditions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Manage IT talent&lt;/strong&gt;: IT leaders must develop strategies to attract, retain, and develop top IT talent, ensuring their organizations have the necessary skills and culture to remain competitive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Act as change agents&lt;/strong&gt;: IT leaders cannot be shy in driving change and helping their organizations adapt to new technologies, processes, and business models.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Key Drivers Of The Evolving Role Of IT Leadership&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Several factors are driving the evolution of IT leadership in today&#39;s business world.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Digital transformation&lt;/strong&gt;: As organizations adopt new technologies and add to their digital toolsets, IT leaders must guide their teams in successfully implementing and integrating these solutions, ensuring they deliver tangible business value.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cybersecurity and data privacy&lt;/strong&gt;: The exceptionally high number of cyberattacks and data breaches has underscored the importance of robust cybersecurity measures. IT leaders must prioritize data protection and confidentiality to maintain customer trust and comply with increasing regulatory requirements.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Cloud computing and infrastructure management&lt;/strong&gt;: Cloud computing has revolutionized how businesses grow and manage their IT infrastructure, from platforms and infrastructure-as-a-service like AWS and Azure to software-as-a-service offerings such as SalesForce, Google, and ZenDesk. IT leaders must navigate the complex landscape, strategically leveraging what the cloud offers and ensuring their organizations can scale and adapt to changing needs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Analytics and data-driven decision-making&lt;/strong&gt;: The growing emphasis on data-driven decision-making has made it essential for IT leaders to harness the power of data analytics and AI to drive business insights and support strategic planning.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The need for agility and speed&lt;/strong&gt;: Organizations have had to adapt to abrupt market changes in an increasingly complex world. IT leaders must ensure their teams can quickly adapt to new technologies and processes, enabling the organization to stay ahead of the competition.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;The Importance Of Soft Skills For IT Leaders&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;While technical expertise remains crucial for IT leaders, the evolving role of IT leadership demands a broader skill set. Soft skills such as communication, collaboration, and change management have become increasingly important in today&#39;s business world. IT leaders must be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Communicate effectively&lt;/strong&gt;: IT leaders must be able to communicate complex technical concepts and strategies to non-technical stakeholders, ensuring everyone is aligned and working toward common goals.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Build strong relationships&lt;/strong&gt;: IT leaders must cultivate strong relationships with other business leaders, fostering collaboration and promoting a shared understanding of strategic objectives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Lead and inspire teams&lt;/strong&gt;: IT leaders should be able to inspire and motivate their teams, driving them to perform at their best and embrace change.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Manage conflict and negotiate&lt;/strong&gt;: Conflict resolution and negotiation skills are essential for IT leaders as they navigate competing priorities, limited resources, and diverse stakeholder interests.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Embrace change and adaptability&lt;/strong&gt;: IT leaders must be adaptable, open to new ideas, and willing to embrace change as they lead their organizations through digital transformation and other strategic initiatives.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;strong&gt;Preparing For The Future Of IT Leadership&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;As the role of IT leadership continues to evolve, IT leaders must be prepared to face new challenges and seize emerging opportunities. Here are some steps they can take to prepare for the future.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Invest in professional development&lt;/strong&gt;: IT leaders should continuously invest in their professional development, staying current with the latest technologies, trends, and best practices.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Develop a strategic mindset&lt;/strong&gt;: IT leaders must think strategically, looking beyond day-to-day operations to identify opportunities for growth and improvement.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strengthen emotional intelligence&lt;/strong&gt;: Emotional intelligence is critical to effective leadership. IT leaders should develop self-awareness, empathy, and relationship management skills.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Collaborate with other business functions&lt;/strong&gt;: IT leaders must work closely with other business leaders, such as marketing, finance, and human resources, to create synergies and ensure IT initiatives align with broader organizational goals.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Be a continuous learner&lt;/strong&gt;: IT leaders should embrace a growth and learning forward mindset and be open to learning from failures and successes, using these experiences to inform their decision-making and leadership approaches.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The role of IT leadership in today&#39;s business world is undergoing a significant transformation, driven by factors such as digital transformation, cybersecurity, cloud computing, data analytics, artificial intelligence, and the need for agility. As a result, IT leaders must adapt to these changes by developing new skills, embracing a strategic mindset, and fostering a culture of innovation and collaboration. By doing so, IT leaders can ensure they remain relevant and effective, driving their organizations toward success in the digital age.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/unleashing-the-power-of-it-leadershiprevolutionizing-the-business-landscape-in-the-digital-agebrian-greenberg?si=ad00cf4697814cd38745a3c741ce5e8b&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Sun, 25 Jun 2023 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2023/06/26/unleashing-the-power-of-it-leadership-revolutionizing-the-business-landscape-in-the-digital-age/</guid>
    </item>
    <item>
      <title>The top five cybersecurity issues in 2023 and five ways to protect yourself and your business.</title>
      <link>https://briangreenberg.net/2023/04/02/the-top-five-cybersecurity-issues-in-2023-and-five-ways-to-protect-yourself-and-your-business/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt;.&lt;br&gt;
This article first appeared on &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2023/02/23/this-years-top-cybersecurity-threats-and-how-to-protect-your-business/?sh=7aa7f53d3b75&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt; on 2/23/2023.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The average &lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;cost of a data breach&lt;/a&gt; last year was $9.44MM. Of those companies that did suffer a breach, 60% &lt;a href=&quot;https://www.inc.com/joe-galvin/60-percent-of-small-businesses-fold-within-6-months-of-a-cyber-attack-heres-how-to-protect-yourself.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;were forced into bankruptcy within six months&lt;/a&gt;. No one wants to end up a statistic like that. Hence, the priority of cybersecurity has increased as a growing concern for businesses in all industries. The security risks come in many forms, from cyber-attacks, phishing, and data breaches to insider threats and vulnerabilities in Internet of Things (IoT) devices. However, most businesses don&#39;t know where to begin and have limited resources and smaller IT teams, if any at all. In this article, I&#39;ll show you what you should be on the lookout for and what high-priority solutions you can employ to address the top issues to be aware of in 2023.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;First, things first—cybersecurity threats.&lt;/strong&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Cyber Attacks&lt;/strong&gt;: an increasingly common occurrence in today&#39;s digital age. These attacks can take many forms, such as malware infections, phishing scams, ransomware, and network intrusions. One of the most common types of cyber attacks is ransomware, software designed to encrypt a computer system making it unusable and holding the company hostage for ransom paid in cryptocurrency, often bitcoin.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data Breaches&lt;/strong&gt;: A security incident in which sensitive, confidential, or protected data is accessed, disclosed, or stolen by unauthorized individuals. They can have severe consequences for organizations and individuals whose information has been compromised. There are many ways that data breaches can occur. Some standard methods include hacking, malware infections, and phishing scams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Phishing Attacks&lt;/strong&gt;: a common type of cyber attack in which the attacker uses fake emails, text messages, or websites to trick the victim into giving away sensitive information, such as login credentials or financial information. These attacks can be challenging to recognize, as the attackers often use branding and logos designed to mimic those of legitimate companies or organizations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Insider Threats&lt;/strong&gt;: Insider threats are a type of security risk that occurs when an individual with authorized access to an organization&#39;s systems, networks, or data misuses that access to cause harm. Insider threats can take many forms, including employees who intentionally or unintentionally cause damage, contractors who have access to sensitive information, and third-party vendors who have access to an organization&#39;s systems. Insider threats can be challenging to detect and prevent, as the individuals involved often have legitimate access to the systems and data they are compromising.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IoT Security&lt;/strong&gt;: The Internet of Things (IoT) refers to the growing network of connected devices that can communicate and exchange data over the internet. These devices, which include everything from smart thermostats, security cameras, and intelligent lightbulbs to medical devices and industrial equipment, have the potential to revolutionize the way we live and work. However, as the number of connected devices continues to grow, so does the risk of security breaches and other threats. One of the main challenges with IoT security is that not many devices have good protection designed within the device.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;strong&gt;The top five things you can do to protect yourself right now are.&lt;/strong&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Multi-factor Authentication (MFA)&lt;/strong&gt;: is ubiquitous today and available on most platforms for &lt;em&gt;free&lt;/em&gt;. Using MFA is the simplest way to protect your accounts. MFA has the highest rate of return and the most significant impact on protecting you, your organization, and your information. &lt;a href=&quot;https://www.zdnet.com/article/microsoft-99-9-of-compromised-accounts-did-not-use-multi-factor-authentication/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Microsoft has reported that 99.9% of all compromised accounts did &lt;em&gt;not&lt;/em&gt; use multi-factor authentication.&lt;/a&gt; MFA is available to nearly every organization. All you need to do is turn it on and &lt;em&gt;enforce&lt;/em&gt; it in your organization. Indeed, you should turn on MFA on all your accounts as well; &lt;a href=&quot;https://www.linkedin.com/help/linkedin/answer/544/turn-two-step-verification-on-and-off?lang=en&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;LinkedIn&lt;/a&gt;, &lt;a href=&quot;https://facebook.com/help/148233965247823&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Facebook&lt;/a&gt;, &lt;a href=&quot;https://help.instagram.com/566810106808145&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Instagram&lt;/a&gt;, &lt;a href=&quot;https://www.google.com/landing/2step/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Gmail&lt;/a&gt;, &lt;a href=&quot;https://support.apple.com/en-us/HT204915&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Apple&lt;/a&gt;, &lt;a href=&quot;https://support.microsoft.com/en-us/account-billing/how-to-use-two-step-verification-with-your-microsoft-account-c7910146-672f-01e9-50a0-93b4585e7eb4&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Microsoft&lt;/a&gt;, &lt;a href=&quot;https://slack.com/help/articles/204509068-Set-up-two-factor-authentication&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Slack&lt;/a&gt;, &lt;a href=&quot;https://help.twitter.com/en/managing-your-account/two-factor-authentication&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Twitter&lt;/a&gt;, &lt;a href=&quot;https://www.amazon.com/gp/help/customer/display.html?nodeId=GE6SLZ5J9GCNRW44&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Amazon&lt;/a&gt;, &lt;a href=&quot;https://help.dropbox.com/account-access/enable-two-step-verification&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Dropbox&lt;/a&gt;, etc... do it, and &lt;em&gt;do it right now&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Password Management&lt;/strong&gt;: Good password management is complex and essential, and passwords need to be everywhere. But it doesn&#39;t need to be that hard to manage. Password management solutions are not expensive, and some are free and built into your systems, such as &lt;a href=&quot;https://appleinsider.com/articles/21/12/29/how-to-use-icloud-keychain-apples-built-in-and-free-password-manager&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Apple&#39;s iCloud Keychain&lt;/a&gt; and &lt;a href=&quot;https://passwords.google.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Google&lt;/a&gt;. Some companies have robust versions that work on many platforms, such as &lt;a href=&quot;https://1password.grsm.io/u28yl9xff9c6-gbrygd&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;1Password&lt;/a&gt;, which also has versions for businesses that store your MFA token, so you don&#39;t need a separate authenticator app like Google&#39;s or Microsoft&#39;s.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit User Accounts&lt;/strong&gt;: Add this task to your calendar to review accounts quarterly. Ensure that former employees no longer have active accounts in your system, and all active account holders are limited only to what they are required to do for their jobs. This principle is called the &lt;a href=&quot;https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Principle of Least Privilege&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Update Software&lt;/strong&gt;: Ensure all your computers are up to date on the latest operating systems, patches, application updates, and anti-virus software. Outdated computers, phones, tablets, etc., pose a security risk to your entire organization. Enable automated updates, get up to date, and reduce your risk.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Backups&lt;/strong&gt;: Disaster will strike. It&#39;s not a question of &lt;em&gt;if&lt;/em&gt; but &lt;em&gt;when&lt;/em&gt;. Be prepared for this inevitability by backing up all computers and data you depend on to keep your business functioning. &#39;&lt;em&gt;Trust but verify&lt;/em&gt;&#39; that your backups work by testing the recovery process regularly. Backup is your insurance policy, it&#39;s not sexy, but you&#39;ll be thankful you have it when disaster strikes. Get started by enlisting a professional to help ensure you&#39;re safely protected instead of taking it all on yourself. The complexity of interdependent systems can make it difficult, and you don&#39;t want any data slipping through the cracks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bonus—CyberSecurity Insurance&lt;/strong&gt;: Get Cyber Insurance. You get it for your home, your car, your health, and your business. Make sure you have the right coverage for cybersecurity events that&#39;s not included in your regular business insurance. &lt;a href=&quot;https://briangreenberg.net/2022/06/16/cyber-insurance-and-reassessing-the-cyber-business/&quot;&gt;See here for more on cybersecurity insurance&lt;/a&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Businesses are increasingly at risk of cyber-attacks and other security threats. Most companies have fewer resources and less advanced security measures than giant corporations. Therefore security can become an oversight, making companies attractive targets for attackers, who may see them as an easier target. The consequences of a security breach or other cyber attack can be severe. In addition to financial losses, the business may suffer damage to its reputation, which can be challenging to recover. Customers may also lose trust in the company and may be less likely to do business with them. For these reasons, companies must prioritize security to protect their business and customers. By taking these and other steps to improve their security posture, businesses can better protect their business and customers from the risks posed by cyber-attacks and other security threats.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Prefer to listen? &lt;a href=&quot;https://soundcloud.com/brian-greenberg-net/this-years-top-cybersecurity-threats-and-how-to-protect-your-business-brian-greenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;This article is also on SoundCloud&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
</description><pubDate>Sat, 01 Apr 2023 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2023/04/02/the-top-five-cybersecurity-issues-in-2023-and-five-ways-to-protect-yourself-and-your-business/</guid>
    </item>
    <item>
      <title>Cyber Insurance And Reassessing The Cyber Business</title>
      <link>https://briangreenberg.net/2022/06/16/cyber-insurance-and-reassessing-the-cyber-business/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/cameron-l-a9899249/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Cameron Laghaeian&lt;/a&gt;.&lt;/em&gt; &lt;br&gt;
&lt;em&gt;Originally appearing &lt;em&gt;at &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2022/05/16/cyber-insurance-and-reassessing-the-cyber-business/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt;&lt;/em&gt;&lt;/em&gt; on &lt;em&gt;5/&lt;em&gt;16&lt;/em&gt;/2022.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;As incredible as it may seem, people have been getting insurance for &lt;a href=&quot;https://www.investopedia.com/articles/08/history-of-insurance.asp&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;thousands of years&lt;/a&gt;. The Code of Hammurabi, written in 1755 B.C., is the first known legal text to describe the concept of insurance. Today, people and companies alike purchase insurance to protect themselves from financial loss. It’s a way to manage the risk that we experience in everyday life, such as auto insurance for car accidents or health insurance for when we get sick. Companies purchase insurance to manage the risk of running a business, like protection in the event of a fire with commercial property insurance or a workplace accident with workers’ compensation insurance. We use insurance to hedge against the risk of significant loss. These days, companies have &lt;a href=&quot;https://www.gao.gov/blog/what-cyber-insurance%2C-and-why-it-high-demand&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;been buying&lt;/a&gt; and exercising their cyber insurance policies for more than anyone would like or would have imagined.&lt;/p&gt;
&lt;h2&gt;What Is Cyber Insurance?&lt;/h2&gt;
&lt;p&gt;Cyber insurance is a special kind of insurance that protects organizations from the costs of technology-based risks such as ransomware, hackers, data breaches, etc. These kinds of threats are usually not included with traditional insurance policies.&lt;/p&gt;
&lt;p&gt;A cyber insurance policy should include coverage for hacking, theft, the destruction of data and &lt;a href=&quot;https://en.wikipedia.org/wiki/Denial_of_service_attacks&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;denial-of-service attacks&lt;/a&gt;, as well as protection against losses caused to others, including public relations costs, security audits and investigative expenses. Cybersecurity insurance is in addition to all the other steps that a business should take to protect an organization’s digital assets. To qualify for cybersecurity insurance and control the insurance costs, organizations usually have to complete a checklist of their cyber defenses, not unlike having smoke detectors, sprinklers and fire alarms when applying for insurance in case of fire.&lt;/p&gt;
&lt;h2&gt;What Does It Cover?&lt;/h2&gt;
&lt;p&gt;Typically, insurance companies write policies based on well-defined situations, such as a flood or fire event or how a person should operate a motor vehicle. These familiar situations allow insurers to cover specific risks based on their likelihood, allowing them to write policies that have a relatively predictable exposure for payouts. Cybersecurity, on the other hand, has not been defined in any static, meaningful manner as the technology landscape and the threats are constantly evolving.&lt;/p&gt;
&lt;p&gt;With exposures such as &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2021/05/27/the-achilles-heel-of-business-technology-zero-day-vulnerabilities&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;zero-day vulnerabilities&lt;/a&gt;, organizations can’t eliminate the possibility of data loss or business disruption. Every organization should opt for cybersecurity insurance as a sound business practice similar to fire insurance. The challenge is understanding the policy’s language to understand their coverage for the types of cybercrimes they may experience. There are four broad categories of potential losses due to cybersecurity breaches: business and operational disruption costs due to recovery activities, ransom demands, legal liabilities and lawsuits.&lt;/p&gt;
&lt;p&gt;It is essential to have specific language to address the recovery expenses and the loss of income for ransomware events. An insurance policy may only cover the cost of the ransom, which could be minimal compared to business losses due to the operational disruptions and the effort to recover the systems.&lt;/p&gt;
&lt;h2&gt;Insurance Companies Refusing To Insure?&lt;/h2&gt;
&lt;p&gt;Well-crafted cyber insurance will clearly define each category that will outline the coverage and spell out the risk assessment and necessary controls and systems for policy compliance and any potential exemptions. Several possible scenarios might cause an insurance company to refuse coverage in case of a cybersecurity event:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Failure To Maintain: One potentially confusing aspect of cyber insurance is defining what is necessary for the policy to be valid. For example, traditional policies for fire have specifically outlined equipment and procedures for testing and certification of fire prevention equipment and processes. However, cybersecurity is an ever-evolving domain. Due to new, yet to be deployed attack vectors by hackers, it is difficult to define the minimum requirements necessary for prevention. Therefore, an insurer can claim any blanket “failure to maintain” exclusion to deny coverage. There is another challenge to businesses where there has not been an actual breach of any systems caused by “failure to maintain.” There have already been a few lawsuits &lt;a href=&quot;https://www.cpajournal.com/2018/04/06/cyber-related-claims-without-a-breach-theyre-coming/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;filed against some businesses&lt;/a&gt; when their clients discovered already published security vulnerabilities that they had not remedied. Unless this type of event is explicitly covered, a typical cyber insurance policy will not cover any expenses related to the lawsuits.&lt;/li&gt;
&lt;li&gt;Act Of War: Political conflicts may affect a business in several unexpected ways. An “act of war” can be interpreted in various ways, making space for another possible exemption clause resulting in a denial of coverage. This clause, and its lack of clear definition for cybersecurity, can claim a breach was an act of war if the hackers are related to state-sponsored activities. This reasoning can also be applied if the group demanding the ransom can have suspected links to terrorism, making it &lt;a href=&quot;https://www.insurancejournal.com/news/international/2021/05/09/613255.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;illegal for insurance companies to make the actual payments&lt;/a&gt;. That would put them in violation of specific laws against funding terrorist organizations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Cybersecurity insurance should be another item on every organization’s checklist next to secure backups, especially as cybercriminals employ more sophisticated methods to access organizations’ digital assets. This way, they will be able to ensure that if and when their business-critical systems and information are compromised, they have the proper safeguards to minimize the financial impact of any security breach.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/cyber-insurance-and-reassessing-the-cyber-businessbrian-greenberg?si=291a8c62bb484876be26a207549afddd&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Wed, 15 Jun 2022 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2022/06/16/cyber-insurance-and-reassessing-the-cyber-business/</guid>
    </item>
    <item>
      <title>Entity-Level Encryption: The Only Defense Against Ransomware</title>
      <link>https://briangreenberg.net/2021/07/23/entity-level-encryption-the-only-defense-against-ransomware/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/cameron-l-a9899249/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Cameron Laghaeian&lt;/a&gt;.&lt;/em&gt; &lt;br&gt;
&lt;em&gt;Originally appearing &lt;em&gt;at &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2021/06/23/entity-level-encryption-the-only-defense-against-ransomware/?sh=12d6656a3474&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt;&lt;/em&gt;&lt;/em&gt; on &lt;em&gt;6/&lt;em&gt;23&lt;/em&gt;/2021.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Ransomware is one of the &lt;a href=&quot;https://www.natlawreview.com/article/c-suites-cybercrime-damages-expected-to-reach-6-trillion-2021&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;fastest-growing&lt;/a&gt; forms of cybercrime. It begins when ransomware criminals gain access to a company’s network and, like a virus, spread their malware, infecting all the company&#39;s computers. From there, the malware encrypts all the company&#39;s data, making the information unreadable, shutting down the business until a ransom is paid, often in the &lt;a href=&quot;https://www.computerweekly.com/news/252498029/Average-ransomware-cost-triples-says-report&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;millions of dollars&lt;/a&gt;. &lt;a href=&quot;https://www.csoonline.com/article/3566886/a-history-of-ransomware-the-motives-and-methods-behind-these-evolving-attacks.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Since 1989&lt;/a&gt;, cybercriminals have been holding data ransom for financial gain. Ransomware results in system-wide downtime for the victims and financial loss from the impact on the business and the ransom payment itself. While well-architected hardened defenses against would-be hackers are necessary to reduce the likelihood of a breach, there are no guarantees of thwarting an attack. When an attack occurs, the only way to recover data encrypted by ransomware is to restore the data from backups stored offline and isolated from the threat.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;&lt;strong&gt;The Threat Of Extortion&lt;/strong&gt;&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;As if encrypting your data for ransom wasn&#39;t enough, an even more nefarious development has increased the impact of ransomware events on businesses. Cybercriminals have been copying and downloading data to their own servers before encrypting the data on the victims&#39; computers. This gives the hackers two methods for financial gain:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;They demand a ransom payment for the key to decrypt the victims&#39; data.&lt;/li&gt;
&lt;li&gt;They can extort more money by threatening to publish the company&#39;s data on the dark web, thereby exposing all manner of confidential information.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This second threat can have an even more devastating impact on businesses. Essentially, hackers could publish all the information about a business&#39;s operations and its clients on the dark web for other criminals and even competitors to use. The damage this would cause to businesses, especially for regulated organizations such as healthcare providers, can be far worse than a simple ransom paid to unlock encrypted data. Moreover, even if a company does pay extortion money, there&#39;s no guarantee that the criminals wouldn&#39;t publish the confidential data regardless.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;A Complex Problem&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;From daily news headlines, the severity and frequency of these breaches suffered by private companies and governmental agencies seem ubiquitous and unending. It’s impossible to harden any IT system enough to guarantee that no hacker would ever have access to any company’s internal systems.&lt;/p&gt;
&lt;p&gt;IT systems are just too complex. They’re a combination of personal computers, smart devices and servers, all connected via networks. The configuration of various computer and technology components involved in any given company is in a constant state of flux. They are constantly added to, updated and replaced, occasionally introducing undetected vulnerabilities resulting in &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2021/05/27/the-achilles-heel-of-business-technology-zero-day-vulnerabilities/?sh=5387f67c6d96&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;zero-day attacks&lt;/a&gt;. Effectively, cybercriminals will always find a way to break into any given system, thereby gaining access to the company&#39;s data. Therefore, the only effective remedy to even further reduce the likelihood of data loss is to encrypt the data at rest, making it unreadable to hackers.&lt;/p&gt;
&lt;p&gt;Despite the many advantages of data encryption, we don&#39;t use it everywhere. The whole encryption process presents many challenging complexities, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Encryption key management.&lt;/li&gt;
&lt;li&gt;Computational cost.&lt;/li&gt;
&lt;li&gt;Speed.&lt;/li&gt;
&lt;li&gt;Data storage.&lt;/li&gt;
&lt;li&gt;The need to share data with various internal and external systems.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Any encryption scheme requires at least one key. This key has to be complex enough to prevent the data from being decrypted using brute force methods, causing it to be hard to remember and impractical to enter on-demand as authorized users try to interact with the data.&lt;/p&gt;
&lt;p&gt;Fortunately, there are various solutions to help organizations manage the encryption keys offered by multiple solutions providers. These solutions can provide numerous encryption schemes, including application-level encryption, which means that only an authorized application can read the encrypted data in the database. The drawback to this method is that if a hacker gains access to the application, they will have access to the data.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;A Solution&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;A more robust solution would leverage entity-level encryption with unique keys for various entities based on each business&#39;s definition of what constitutes sensitive data and tie the authorization to the users. In cybersecurity, this is considered akin to the &amp;quot;&lt;a href=&quot;https://searchsecurity.techtarget.com/definition/principle-of-least-privilege-POLP&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;principle of least privilege&lt;/a&gt;,&amp;quot; where systems&#39; or users&#39; access rights are limited to only what&#39;s strictly required to complete a function or required to do their jobs.&lt;/p&gt;
&lt;p&gt;For example, a healthcare provider could have a unique encryption key for each patient and authorize each patient to access their data. This method will guarantee that patients can only see their own records since they will not have the keys for any other patient&#39;s information stored within the same database. Leveraging this level of encryption can only be done if the encryption logic can manage all the keys and patient authorizations and still allow authorized employees&#39; access to any patient&#39;s records. This method would only expose a single patient&#39;s data if the patient&#39;s device, pc or smartphone, is compromised.&lt;/p&gt;
&lt;p&gt;With a secure key management scheme, cybercriminals will not have any way to decrypt the sensitive information even if they obtain a copy of the entire database. While this level of encryption will not prevent hackers from further encrypting the data and demanding a ransom for the decryption key, it will prevent them from attempting to publish the data on the dark web.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;The Ultimate Defense&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Ransomware is a grave threat to any business. It&#39;s an incredibly complicated problem that traditional IT defenses have been unable to stop, and a single strategy cannot fix it. The ultimate defense is a multifaceted approach depriving cybercriminals of their prize. First, companies need to employ frequent and automated backups securely maintained offline to recover data encrypted by ransomware. Secondly, companies need to begin leveraging entity-level encryption making data unreadable by unauthorized actors. In combination, these two approaches can seriously cripple a cybercriminal&#39;s power to impact businesses and their clients.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/entity-level-encryption-the-only-defense-against-ransomware-brian-greenberg?si=291a8c62bb484876be26a207549afddd&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Thu, 22 Jul 2021 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2021/07/23/entity-level-encryption-the-only-defense-against-ransomware/</guid>
    </item>
    <item>
      <title>Zero-Day Vulnerabilities: The Achilles&#39; Heel Of Business Technology</title>
      <link>https://briangreenberg.net/2021/06/28/zero-day-vulnerabilities-the-achilles-heel-of-business-technology/</link><description>&lt;p&gt;&lt;em&gt;By &lt;a href=&quot;https://linkedin.com/in/bjgreenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Brian Greenberg&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/cameron-l-a9899249/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Cameron Laghaeian&lt;/a&gt;.&lt;/em&gt; &lt;br&gt;
&lt;em&gt;Originally appearing &lt;em&gt;at &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2021/05/27/the-achilles-heel-of-business-technology-zero-day-vulnerabilities/?sh=68acd0256d96&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt;&lt;/em&gt;&lt;/em&gt; on _5/&lt;em&gt;2_7/2021.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The origin story of Achilles begins with his mother, the Greek goddess Thetis, and how she attempted to protect him. Thetis went to the River Styx, the river that formed the boundary between the Earth and the Underworld. It was said that the river could imbue a person with powers of invincibility. Wanting the best for her son, Thetis dipped her infant child into the River Styx so that he may grow up to be great and powerful. As a result, Achilles grew to be a great warrior who survived many battles due to his powers. However, unknown to Thetis and Achilles, he remained vulnerable at his heel, where Thetis held him while she dipped him into the river as a child, thus protecting him entirely except at his heel.&lt;/p&gt;
&lt;p&gt;Similar to the vulnerability of Achilles&#39; heel, a zero-day vulnerability is a computer security vulnerability unknown by its creators. However, hackers who later discover the vulnerability can exploit it to attack a business, attack its computer systems, steal data or plant malicious code within the companies network.&lt;/p&gt;
&lt;p&gt;Unlike &lt;em&gt;known&lt;/em&gt; vulnerabilities that have been identified, patched and publicized, &lt;em&gt;unknown&lt;/em&gt; (or known but unpatched) vulnerabilities are called zero-day vulnerabilities. It means that the developers have &amp;quot;zero days&amp;quot; to fix the problem that has just been exposed and likely already exploited by hackers. They&#39;re vulnerabilities that a malicious hacker or government agency could have discovered yet are not reported, or the developer knows about the vulnerabilities but hasn&#39;t yet issued a patch.&lt;/p&gt;
&lt;p&gt;Malicious hacking groups that discover the vulnerabilities keep them secret so they can exploit them to steal data, infiltrate computer systems or spy on people and organizations without alerting anyone to the fact that they&#39;ve unlocked a back door to their systems. Often, zero-day exploits are secretly sold to nefarious hacker groups on the darknet.&lt;/p&gt;
&lt;p&gt;As with Achilles, the entire system can be hardened and considered invulnerable, but even the smallest unknown or unpatched vulnerability can be catastrophic.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How serious can it be?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Zero-day vulnerabilities can be disastrously serious. They&#39;ve been used to exploit any number of systems, from &lt;a href=&quot;https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;sabotaging&lt;/a&gt; Iran&#39;s uranium enrichment plants to &lt;a href=&quot;https://www.bloomberg.com/news/features/2017-09-29/the-equifax-hack-has-all-the-hallmarks-of-state-sponsored-pros&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;affecting the credit ratings&lt;/a&gt; of hundreds of millions of people.&lt;/p&gt;
&lt;p&gt;For instance, if you&#39;re like me, then you&#39;re one of the 143 million Americans who now have to regularly check your credit reports, learn how to set up a credit freeze, and keep an eagle eye out on your credit score all because of a zero-day vulnerability and Equifax&#39;s failure to patch its servers.&lt;/p&gt;
&lt;p&gt;Back in March 2017, Chinese cybersecurity researcher Nike Zheng discovered a vulnerability in the web application software Apache Struts. Zheng notified Apache about the defect and a way to fix it on March 6. However, by March 10, hackers scanning the internet for vulnerabilities &lt;a href=&quot;https://www.cnet.com/news/equifaxs-hack-one-year-later-a-look-back-at-how-it-happened-and-whats-changed/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;had already found&lt;/a&gt; the Struts vulnerability on one of Equifax&#39;s servers. Shortly after that, more hackers had gained entry into Equifax&#39;s servers and installed back doors into its computer systems.&lt;/p&gt;
&lt;p&gt;Meanwhile, hackers who had breached the system &lt;a href=&quot;https://www.wired.com/story/equifax-breach-no-excuse/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;through May&lt;/a&gt; had stolen the personal information of more than 143 million Americans — including their addresses, birth dates, Social Security numbers, and more. Equifax hadn&#39;t discovered the hackers who were already deeply embedded within its systems until the end of July. Equifax had to shut down its customer portal for nearly two weeks while security teams conducted a forensic analysis of what happened and found and sealed all the back doors. Overall, the breach cost Equifax &lt;a href=&quot;https://www.housingwire.com/articles/equifax-expects-to-pay-out-another-100-million-for-data-breach/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;more than $1.7 billion&lt;/a&gt; despite its $125 million in cybersecurity insurance coverage.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why are patches not applied as soon as they are available?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Patches are difficult and risky to apply because they must be tested for potential adverse effects on the rest of the system. As a rule, applying a patch requires full backups and an identical test computer system to be set up to test the patch to ensure its application will not adversely impact other systems and potentially cause a business disruption. The complexity is, in part, why patching systems take an &lt;a href=&quot;https://www.infosecurity-magazine.com/news/companies-average-120-days-patch&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;average of four months&lt;/a&gt; — if they get patched at all.&lt;/p&gt;
&lt;p&gt;Zero-day issues are more complicated to patch since they typically involve foundational aspects of an organization&#39;s IT systems. Additionally, IT teams are already handling various system maintenance issues, new software releases, end-user support tickets, hardware and software upgrades, cloud migrations, and several other ongoing business projects.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What can be done?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;IT organizations must establish specific processes to pay special attention to all security disclosures and announcements from &lt;em&gt;all&lt;/em&gt; their vendors and the security organizations that provide security resources, such as &lt;a href=&quot;https://cve.mitre.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;CVE&lt;/a&gt; and the &lt;a href=&quot;https://nvd.nist.gov/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;NVD&lt;/a&gt; at NIST. All zero-day patches must be applied across all systems and given the highest priority above and beyond all other activities. These activities require specific processes to fast-track the quality assurance process for applying, testing, and rolling out of these issues that bypass the typical process for new software deployment while ensuring the overall health of the entire system is not compromised.&lt;/p&gt;
&lt;p&gt;It might also be time to migrate some services to the cloud, as cloud services operated and managed by cloud service providers have dedicated staff on the front line of cybersecurity defenses. However, even with a dedicated team actively looking out for security issues, it will not prevent zero-day vulnerabilities. Still, it can help ensure the speedy application of patches as soon as they are available.&lt;/p&gt;
&lt;p&gt;The Microsoft Exchange &lt;a href=&quot;https://www.zdnet.com/article/everything-you-need-to-know-about-microsoft-exchange-server-hack/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;vulnerabilities&lt;/a&gt; of early 2021 are an excellent example of cloud-elevated security protection available with software as a service (SaaS). Organizations using Microsoft&#39;s SaaS cloud-based Exchange server as a part of Office365 did not succumb to the exploit. Meanwhile, all other organizations with Exchange servers in their data centers or private clouds were vulnerable until they became aware of and applied the patches to their servers.&lt;/p&gt;
&lt;p&gt;Whether you&#39;re managing servers in your data center or leveraging a SaaS cloud, companies and organizations can no longer regard cybersecurity as an expensive nuisance but instead, as an opportunity to be seen as the model company that looks out for its customers. This active security posture can put you miles ahead of the competition.&lt;/p&gt;
&lt;p&gt;🎧 Listen to the podcast created by NotebookLM of this article.&lt;/p&gt;
&lt;figure class=&quot;wp-block-embed is-type-rich is-provider-soundcloud wp-block-embed-soundcloud&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;https://soundcloud.com/brian-greenberg-net/the-achilles-heel-of-business-technology-zero-day-vulnerabilities-brian-greenberg?si=291a8c62bb484876be26a207549afddd&amp;amp;utm_source=clipboard&amp;amp;utm_medium=text&amp;amp;utm_campaign=social_sharing&lt;/div&gt;&lt;/figure&gt;
</description><pubDate>Sun, 27 Jun 2021 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2021/06/28/zero-day-vulnerabilities-the-achilles-heel-of-business-technology/</guid>
    </item>
    <item>
      <title>To Delete Or Not To Delete — That Is The Question</title>
      <link>https://briangreenberg.net/2018/05/11/to-delete-or-not-to-delete-that-is-the-question/</link><description>&lt;p&gt;&lt;em&gt;&lt;a href=&quot;http://bit.ly/2deleteORnot&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Originally published on 3/28/18 at Forbes&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;There seems to be confusion in corporate America about whether or not to delete data. On one hand, there are legal departments that advise keeping everything forever, and on the other are those that recommend deleting everything as a matter of policy as soon as possible — whacking away at files and folders on your file servers like a drunk landscaper whirling a weed whacker around your yard. Meanwhile, IT is stuck in the middle trying to develop and engineer systems to enforce ever-changing data retention policies.  With a rash of &lt;a href=&quot;https://www.privacyrights.org/data-breaches&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;security breaches&lt;/a&gt; and companies getting slapped with huge fines for mismanaging data during legal investigations, for some, the only reasonable thing to do is delete all data. The view taken by some is that if there’s no data, then it can’t be stolen and won’t available for evidence in a lawsuit. Unfortunately, this is rarely true and likely to cost a lot more in the long run.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Data Is A Corporate Asset&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;So what is all this data they want you to delete? It’s everything. It’s email, Word, Powerpoint and Excel documents, sales data, accounting, market data, personnel files, pictures, videos, utility bills, cloud services, phone activity, website data — everything. How you collect, manage and use that data is vital to the success of your business. It will determine your costs, liabilities, exposure, profits and ability to be competitive. Data is being generated every day, every minute, every second. You’ve been generating it for years and it’s growing fast. In fact, data growth in the “&lt;a href=&quot;https://www.emc.com/leadership/digital-universe/2014iview/executive-summary.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;digital universe&lt;/a&gt;” will be over 44 trillion gigabytes in just two years. What’s more, over 780 billion &lt;a href=&quot;http://www.statisticbrain.com/text-message-statistics/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;text messages&lt;/a&gt; are sent each month, over 210 billion &lt;a href=&quot;http://www.statisticbrain.com/internet-statistics/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;emails&lt;/a&gt; are sent every day and there are more than 883 petabytes of internet video surveillance &lt;a href=&quot;http://www.cisco.com/c/en/us/solutions/collateral/service-provider/visual-networking-index-vni/vni-hyperconnectivity-wp.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;traffic&lt;/a&gt; sent per month, and that doesn’t include YouTube, Netflix or any other kind of video traffic. All that data allows you to make better business decisions by using business analytics, creating models and discovering emergent properties within a system to enhance business growth. Data is the cheapest the first time it’s generated. The costs of data increase the further away you get from its point of origin. Also, keep in mind that the value of your organization’s data is extremely high. This is the specific data that’s unique and proprietary to your company and provides the competitive advantage that no one else has access to. Once the data is gone, it’s usually gone forever or exceedingly expensive and difficult to reclaim. If there’s one thing you can count on, it’s that data is going to keep growing. Data drives business and the data needs to be managed. With big data initiatives, machine learning and artificial intelligence driving business forward, finding better ways to store and manage your data is what you should be thinking of instead of deleting it.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Managing And Protecting Your Data Assets&lt;/strong&gt; &lt;/h2&gt;
&lt;p&gt;The truth of the matter is that data management is critical to all companies no matter how much data you have. All company data is a business asset and should be managed according to your organizations business needs and legal strategy. Reactively and haphazardly deleting data is akin to applying weed killer in your garden with a blindfold on. You’ll spread it onto some of the weeds, but odds are you’re going to get it all over your tomatoes too. You’ll probably destroy a lot of your produce and maybe poison yourself in the process. By managing your data well, you lower business and operational costs, reduce legal costs and exposure, create new business opportunities, increase revenue, learn from lessons of the past and provide the ammunition to make better business decisions. There are many aspects of data management, including policies, procedures, data classification, data retention, litigation readiness, data access, security and more. All these activities fall into one of four basic aspects of data management that enable your company to grow with data instead of being encumbered by it:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Data capture&lt;/strong&gt;, which involves generating and acquiring data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data storage,&lt;/strong&gt; which is for every day and archival use.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data utilization,&lt;/strong&gt; which focuses on analytics, synthesis, reporting, forecasting, communicating, etc.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data protection,&lt;/strong&gt; which provides you with backups and security.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;strong&gt;Assessing Risk&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;The view that you should delete data comes from the belief that keeping data is risky, expensive and difficult to do. Let’s take a look.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;It’s risky.&lt;/strong&gt; Every company should have good processes, procedures, training and technology in place for all of its data. So long as that’s in place, maintaining more data is no more or less risky than maintaining less data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;It’s expensive.&lt;/strong&gt; The costs of data storage are &lt;a href=&quot;https://www.computerworld.com/article/3182207/data-storage/cw50-data-storage-goes-from-1m-to-2-cents-per-gigabyte.html&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;going down&lt;/a&gt; every year. For hard drives, they’ve gone from $277 per gigabyte in 1995 to $0.02 in 2017. For tape, it’s even cheaper, costing just &lt;a href=&quot;https://www.forbes.com/sites/tomcoughlin/2016/07/24/the-costs-of-storage/#68c529093239&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;$0.0089 per gigabyte&lt;/a&gt; in 2016.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;It’s difficult.&lt;/strong&gt; I don’t know what to say here. If your job is too difficult, maybe it’s time to find another line of work. Just because something is difficult doesn’t mean it shouldn’t be done. In fact, that’s when the work becomes most interesting.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is great value in data and can be a tremendous advantage if managed and utilized well. If it’s not, then it will become a huge impediment for your business.&lt;/p&gt;
&lt;p&gt;…&lt;/p&gt;
&lt;p&gt;I’d love to hear from you.&lt;/p&gt;
</description><pubDate>Thu, 10 May 2018 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2018/05/11/to-delete-or-not-to-delete-that-is-the-question/</guid>
    </item>
    <item>
      <title>Three Considerations To Help You Get A Grip On Your Data.</title>
      <link>https://briangreenberg.net/2018/02/19/three-considerations-to-help-you-get-a-grip-on-your-data/</link><description>&lt;p&gt;&lt;em&gt;Originally published on 1/8/18 at &lt;a href=&quot;http://bit.ly/Forbes3Considerations&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Hacking is no longer new. It’s become a daily conversation in newsrooms and boardrooms everywhere; hacking and data breaches are the never-ending security story of the 21st century. Hackers illegally make their way into the computer systems of companies, hospitals, government institutions and our homes on a daily basis. The systems that we trust with our personal data, perhaps naïvely and at times reluctantly, are the targets. According to Privacy Rights Clearinghouse, &lt;a href=&quot;https://www.privacyrights.org/data-breaches&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;7,859 data breaches&lt;/a&gt; have been made public since 2005 (and the actual number &lt;a href=&quot;https://digitalguardian.com/blog/history-data-breaches&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;may be higher&lt;/a&gt;). Juniper Research estimates that each single data breach will cost more than &lt;a href=&quot;https://www.juniperresearch.com/press/press-releases/cybercrime-cost-businesses-over-2trillion?utm_source=gorkanapr&amp;amp;utm_medium=email&amp;amp;utm_campaign=cybercrime15pr1&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;$150 million&lt;/a&gt; on average by 2020.
Strong IT leadership is essential. Data breaches can happen at any moment, and we now need to assess the influx of increasingly massive amounts of data for risk in real time. But it’s a complex problem. Today, companies the world over collect data at unprecedented rates. Technologies such as artificial intelligence, natural language processing, predictive algorithms, data science and automation leverage data in new and innovative ways we can’t even fully imagine yet. And the Internet of Things (IoT) has garnered momentum by being embedded in everyday appliances from your coffee maker to your car — collecting data about you and your habits to send back to the manufacturer so they can automatically schedule your next oil change or order you more coffee when you’re about to run out.
All of this data has become a river of information about you and your family’s habits, and it’s growing exponentially. Connected cars, according to Hitachi, will generate &lt;a href=&quot;https://qz.com/344466/connected-cars-will-send-25-gigabytes-of-data-to-the-cloud-every-hour/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;over 25GB of data per hour&lt;/a&gt;, equivalent to dozens of HD movies. With so much data being generated, it’s imperative to get control over collecting and storing all that data — and to do so securely. What follows are are a few thoughts that will guide you through the many types of strategies, pathways and products out there for your consideration as you continuously improve the protection of your clients’ and company’s data.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Reduce Complexity&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Reducing complexity is easier said than done, since IT and data are inherently complex. However, the artistry is in being able to design for simplicity and agility. Some of the most important parts of designing and managing sustainable and adaptable systems are, by far, the least sexy parts. With that in mind, it’s important to design in, from the beginning: security, disaster recovery, business continuity, compliance, modularity, data architecture and understanding business process flow. Not coincidentally, these topics can be tedious and time-consuming, but they are absolutely necessary to compete in today’s markets.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Observe&lt;/strong&gt; &lt;/h2&gt;
&lt;p&gt;Survey the industry, analyze new approaches and create a culture of innovation and synthesis. Technology is advancing rapidly. Industries are constantly competing by leveraging and inventing new technologies to get ahead. Some organizations are overwhelmed by everything going on from IoT to blockchain and simply don’t know where to put their resources. Others are diving into everything and chasing every shiny object that comes by. The key is to take your time and be methodical about new technologies. Read good industry news and blogs by end users, not just the sponsored articles. Send yourself and your staff to good conferences where end users are the speakers, not vendors. Listen to the use cases where people shot themselves in the foot by making avoidable mistakes. These are the best and least expensive lessons you can learn. Then let your staff set up a lab to explore these technologies and, most importantly, how they can benefit the business by solving specific business problems.&lt;/p&gt;
&lt;h2&gt;&lt;strong&gt;Collaborate&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;It’s time to join forces. In the past, organizations have looked upon data and security as two separate disciplines. Database administrators, business analysts, sales teams, network engineers, server administrators, data architects and others rarely speak the same language, nor do they have the overlapping skills required to understand the benefits and implications of their approaches. This “siloed” approach to IT must end. If you work in a small- to medium-size company, the same person is most likely attending to most aspects of the company’s IT services, covering all the bases his or herself, with hardly the bandwidth to do it all well but just enough to keep the lights on due to lack of resources. If you’re in a large company, each functional area within IT is often siloed from the others to ensure their own part of the business is running without fault. They rarely collaborate with others within the department, let alone the business. Fortunately, this is changing. Albeit slowly. With the melding of various technologies in data storage and server virtualization, people are starting to speak with one another, if for no other reason than to figure out who’s responsible for the management and administration of a job that now falls into more than one bucket. Is it the responsibility of the server admin, the storage admin or the network admin? To make matters worse, software-defined everything (network, server and storage) as well as cloud technologies and platforms, continuous integration, containers, IoT, and of course, big data, are scrambling the functions of departments, roles and job titles, leaving everyone’s head spinning. Clarify roles and responsibilities as much as you possibly can, as soon as you possibly can. Then keep the dialogue open. Finally, consider this: IT is no longer separate from the business. It is an essential and intimately woven part of the business. Sales teams, business analysts, marketing, you name it: Everyone is (or should be) collaborating every day with IT on the best ways to move forward and grow together as a company.&lt;/p&gt;
&lt;p&gt;...&lt;/p&gt;
&lt;p&gt;I’d love to hear from you.&lt;/p&gt;
</description><pubDate>Sun, 18 Feb 2018 18:00:00 -0600</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2018/02/19/three-considerations-to-help-you-get-a-grip-on-your-data/</guid>
    </item>
    <item>
      <title>Three Considerations To Help You Better Secure And Control Your Data</title>
      <link>https://briangreenberg.net/2018/01/09/three-considerations-to-help-you-better-secure-and-control-your-data/</link><description>&lt;p&gt;Hacking is no longer new. It’s become a daily conversation in newsrooms and boardrooms everywhere; hacking and data breaches are the never-ending security story of the 21st century. Hackers illegally make their way into the computer systems of companies, hospitals, government institutions and our homes on a daily basis. To rise to this occasion, strong IT leadership is essential. Data breaches can happen at any moment, and we now need to assess the influx of increasingly massive amounts of data for risk in real time. As a new member of the &lt;a href=&quot;http://www.forbes.com/sites/forbestechcouncil/people/briangreenberg1&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes Technology Council&lt;/a&gt;, I’ve shared my thinking on how IT leaders can better secure and control company data, in this sometimes hostile and always overcrowded universe of data. Learn more about how you can gain greater control over collecting and storing all that data — and to do so securely—in my latest column in Forbes, &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/2018/01/08/three-considerations-to-help-you-better-secure-and-control-your-data/#594e7b011586&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;here&lt;/a&gt;.  &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://f.briangreenberg.net/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Facebook&lt;/a&gt; | &lt;a href=&quot;http://l.briangreenberg.net/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;LinkedIn&lt;/a&gt; | &lt;a href=&quot;http://t.briangreenberg.net/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Twitter&lt;/a&gt; | &lt;a href=&quot;https://briangreenberg.net/&quot;&gt;Blog&lt;/a&gt; | &lt;a href=&quot;http://p.briangreenberg.net/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Google+&lt;/a&gt; | &lt;a href=&quot;http://medium.com/@brian.greenberg&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Medium&lt;/a&gt; | &lt;a href=&quot;https://www.forbes.com/sites/forbestechcouncil/people/briangreenberg1&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Forbes&lt;/a&gt;&lt;/p&gt;
</description><pubDate>Mon, 08 Jan 2018 18:00:00 -0600</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2018/01/09/three-considerations-to-help-you-better-secure-and-control-your-data/</guid>
    </item>
    <item>
      <title>Listen. Feedback matters.</title>
      <link>https://briangreenberg.net/2017/08/06/not-your-beta-tester/</link><description>&lt;p&gt;I feel like I’m becoming the curmudgeonly old guy who just complains about stuff. And, maybe I am, but I remember when things just worked. Don’t you? Maybe it&#39;s just me showing my age. Perhaps we all have a bit of the curmudgeon within each of us. It’s not a bad thing. When I order a pizza without anchovies and I get extra anchovies, it’s right to speak up. It’s the correct thing to do. That doesn’t give me a license to be an ass, but just to bring up the subject that a mistake was made and that I’d like it corrected, please. A mistake, that anyone can make. An honest mistake.&lt;/p&gt;
&lt;h2&gt;Not your beta tester.&lt;/h2&gt;
&lt;p&gt;However, when I buy a technology of some kind, a phone, some software, an app, I expect it to work. I expect it to be secure, tested, and beta tested. Beta testers, if you’re unfamiliar with the term, are people who are prescribed by the company as sample end users that will verify that the software works as expected without errors, before the product is sold. They are not paying customers who expect a finished, working product. Just a few weeks ago, I had some thoroughly frustrating customer experiences with three companies’ technologies; Chase Bank, Jimmy John’s, and Amazon&#39;s Seller Central. In all three of these cases, the common thread was an inability to get feedback to the company about the problem I was experiencing. Each case, a different technical problem and the same common obstacle trying to get the problem resolved—giving feedback. In each of these cases, it was an inability to give feedback to the company whose app/website was failing. It wasn’t that they didn’t have a feedback system, it was that with each one of them, their feedback systems were broken too! ‘Hey! Your website or app isn’t working as expected and I’m trying to tell you about the error that you may not know about, but your system to contact you is broken too!’ So, after making several attempts to contact customer service at each company, failing completely each and every time, trying several different methods, I resorted to tweeting to them. Only after tweeting publicly to the three companies, did I ever get any kind of contact to help address the problem. And in each of the three instances, they never corrected the problem, they just apologized and said that my business was important to them and that I’m a valued customer. But none of them got the message back to the people that could actually address the problem and make a meaningful change. The problem with so many companies today is that they’re not focused on the customer experience. They say they are and they think they’re making every attempt to put out great products and services. But unless they put in the feedback mechanisms to learn if their customers are having great experiences, they’re not getting the whole picture. It’s an incomplete portrait. At one time Guy Kawasaki wrote in the &lt;a href=&quot;http://guykawasaki.com/the_art_of_inno/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Art of Innovation&lt;/a&gt;; “Don’t worry, be crappy.” I have a love/hate relationship with this expression. I think some innovators take it too far and just ship product for the sake of shipping, thinking their product is just too cool and too novel not to ship and everyone will love it anyway because it’s so disruptive. It’s time to humble up and realize that you don’t know everything and you need to listen to your customers. You have no idea how people are going to be using your product and what their experiences are going to be until they start using it. Most customers don’t complain. Maybe they think it’s impolite. They just ignore the problem, and either live with it and the poor feelings that go along with it, or move on to a different company that might have a better product. If they do complain, or just want to give feedback about their experiences, the company needs to listen and provide a workable way for their customers to contact them, to hear them, and make them feel like they’ve been heard and are valuable. If nothing else, the most important part of the product needs to be a way to get feedback from the customer; about their experiences, good and bad. In addition, companies need to empower their employees to address the problems as directly as possible. Employees need to be able to communicate with the customer and ensure them that they have been heard and are working to fix the problem directly. If they can’t fix the problem directly, then they need a mechanism to get the feedback to someone in the company who can fix it. Then follow up with the customer thanking them for their loyalty, alerting you to the issue, and what you’re doing to address it. A little bit goes a long way in gaining new customers and retaining existing ones. They all share their stories with others, good and bad. Look, I don’t want to be a beta tester, but if I must, because you’re unable to create a reliable product on your own, then you better put in a working feedback mechanism. Listen to your customers. They’re the best feedback you’ll ever have. Ever. They’re also the best marketers for your products, good or bad. They might even blog about it.&lt;/p&gt;
&lt;p&gt;...&lt;/p&gt;
&lt;p&gt;I’d love to hear from you.&lt;/p&gt;
</description><pubDate>Sat, 05 Aug 2017 19:00:00 -0500</pubDate>
      <dc:creator>Brian Greenberg</dc:creator>
      <guid>https://briangreenberg.net/2017/08/06/not-your-beta-tester/</guid>
    </item>
  </channel>
</rss>