Debunking the Top 5 Cybersecurity Myths | Eastern NC Now

October is National Cybersecurity Awareness Month.

ENCNow
News Release:

    October is National Cybersecurity Awareness Month. As a cybersecurity practitioner straddling both academia and industry, I frequently encounter disparities between common perceptions and the reality of cybersecurity. Here are five persistent myths that I consistently find myself debunking:

    1. Password requirements are ridiculous. Why must I change them so often? This couldn't be further from the truth. Login credentials serve as your primary means of authentication, making them a critical vulnerability if compromised. Let's break this down:

  • Length matters exponentially: A four-digit numeric password offers 10,000 possible combinations, whereas an eight-digit password presents 100 million possibilities. Longer passwords significantly increase the difficulty of brute-force attacks.
  • Time is your enemy: Given sufficient time, attackers can eventually crack even strong passwords. Regularly changing passwords mitigates this risk.
  • Avoid predictable patterns: Modern password-cracking tools leverage algorithmic analysis and generative AI to detect and exploit patterns, inadvertently aiding attackers.
  • Two-factor authentication (2FA) is essential: Even robust passwords benefit from an additional layer of security through 2FA or multi-factor authentication (MFA).

    Remember, security is fundamentally about deterrence. While stopping a determined attacker is exceedingly challenging, you can slow them down enough to make yourself a less appealing target.

    2. My information isn't valuable. Why would anyone target me? This myth is particularly dangerous, as it underestimates the value of personal and business data on the dark web. Here's a breakdown of what your information could be worth to cybercriminals:

  • Credit cards:
  • $100 each
  • Driver's licenses: $150
  • Bank account information: $40-$4,000
  • Hacked social media or email accounts: $20-$50
  • Netflix logins: $10-$20

    For business owners, possessing a Dun & Bradstreet (DUNS) number makes your company a potential target for identity theft, where attackers could leverage credit in your business's name. In the eyes of a hacker, all data holds potential value.

    3. Compliance equals security. This myth is particularly pervasive in the United States, where adherence to industry standards such as PCI DSS (for credit card processing), HIPAA (for healthcare), and Sarbanes-Oxley (for publicly traded companies) is often conflated with robust security. While compliance frameworks provide a baseline for security practices, they do not guarantee protection.

    For instance, I've heard from others in my field of systems where a VPN, firewall or other security appliances were installed but never configured with appropriate rulesets, rendering them nearly useless. The mere presence of these devices lulled executives into a false sense of security, illustrating how compliance can create a dangerous illusion of safety.

    4. Expensive tools alone ensure security. Many organizations, particularly those transitioning to e-commerce, fall prey to the belief that purchasing high-end security tools is sufficient. However, expenditure does not equate to security. Without proper implementation and configuration, even the most advanced tools can fail to deliver their promised benefits. It's akin to buying a state-of-the-art alarm system but never setting it up - you might as well put jingle bells on the front doors.

    5. Cybersecurity is prohibitively expensive. While it's true that comprehensive cybersecurity measures can be costly, the long-term benefits far outweigh the initial investment. Many organizations outsource their cybersecurity needs due to the high costs of analysis, testing, implementation and maintenance, which can range from $500 to over $20,000 per month, depending on the organization's size.

    However, integrating security into your business plan from the outset is far more cost-effective than bolting it on later. Proper planning and investment in cybersecurity can prevent costly breaches and data losses, ultimately saving your organization significant financial and reputational damage.

    I'm sure I'll find some more fun fallacies to crack for next time. Until then, keep watching the skies, folks.

    John Armke is a lead instructor, ethical hacking at Wake Technical Community College and a North Carolina Advisory Board member for Western Governors University
Go Back


Leave a Guest Comment

Your Name or Alias
Your Email Address ( your email address will not be published )
Enter Your Comment ( text only please )




Update (10/9) - Developing Coastal Low - This Weekend News and Information, The Region Top NC court tackles suit over Raleigh impact fees


HbAD0

Latest The Region

The great misnomer for non Christians that the day Jesus Christ was executed by occupying Romans, celebrated by Christians as "Good" Friday, must be a paradox of ominous proportions.
A North Carolina State Senate race is heading for a recount after the two pro-Trump Republicans come down to a two vote margin.
This is simply a failure of will, and we are here to help impose that will today, so that to me is the simple punchline," said State Treasurer Brad Briner. "I appreciate the leaders of Rocky Mount being here, but we need to get to a place where there is the will to fix a very, very serious problem.”
Our office is monitoring the likelihood of severe weather across Eastern NC for tomorrow. Forecast details for Beaufort County include:
This morning’s update included minor adjustments to snow accumulations, with Beaufort County forecasted to receive between 8 and 12 inches.
This afternoon’s update continues to indicate “Major Impacts” (Dangerous driving conditions, closures, disruptions with normal daily activities, etc.) from this weekend’s winter weather with Beaufort County currently forecasted to receive 10 and 14 inches of snow.

HbAD1

While this afternoon’s update once again included increased probabilities of moderate to major impacts, it will likely be tomorrow before we receive specific accumulation details.
Our probability for experiencing “Moderate Impacts” (hazardous driving conditions, closures, disruptions with normal daily activities, etc.) increased to between 60 and 80% with this morning’s update
Our office continues to monitor the forecasted potential of another round of winter weather for this Saturday and Sunday.
This afternoon’s update continues to shift winter weather impacts further west and north, with Beaufort County now forecasted to receive less than 1/8 of an inch of accumulating ice from freezing rain, and little to no measurable snow.
Today's weather updates have suggested slightly warmer temperatures for our area than was previously forecasted, which is shifting significant snow and freezing rain accumulations further west and north.
Like many of you, our office has been monitoring the potential for impactful winter weather this weekend. Current forecast details for Beaufort County include:

HbAD2

A federal judge will not issue an injunction blocking local Watauga County election districts created by the Republican-led North Carolina General Assembly.

HbAD3

 
 
Back to Top