Broker Check

Salt Lake City Office

2150 South 1300 East,

Suite 500
Salt Lake City, UT 84106

DIGITAL SECURITY TIPS

You’ve probably heard about digital security before but now is not the time to drop your defenses or get complacent. Cybercrimes have a big impact, the FTC reported that $12.5 Billion was lost to fraud in 2024. 

While new technologies have made our lives more connected than ever, it also creates new vulnerabilities.  As Artificial Intelligence continues to rapidly advance, bad actors have even more tools that can identify and exploit vulnerabilities and weaknesses faster than ever. 

Along with AI, continuing conflicts around the world are also bringing cyber threat levels up.  State-sponsored cyber actors gather intelligence and attack critical infrastructure as part of their tactics.

Passwords and MFA

Creating a strong password along with Multi-Factor Authentication(MFA) is one of the strongest actions you can take to protect your online accounts.   Bad actors use password-stealing practices to gain access to your digital life.  If you don’t update your passwords, any past database hacks could continue to expose your personal information.

The strongest password:

  • Is unique for every site
  • Gets changed regularly (90 Days)
  • Has a combination of upper and lowercase letters, numbers, and symbols
  • Is at least 13 characters long


When you enable Multi-Factor Authentication (sometimes called Two-Factor Authentication) you verify your identity on another device, usually a code sent to your phone.  With this extra layer of verification, even if hackers get your password, they wouldn’t get into your account or device.  Biometrics (fingerprint or facial recognition) is another layer of enhanced security available on certain devices.  Some companies are using Knowledge-Based Authentication as an extra layer of security, requiring users to answer personal questions before getting into accounts.

 

Remembering your passwords can be difficult, that’s why you may consider using a password manager.  Password managers are apps that generate and store your usernames and passwords, requiring a “master password” to access your list.  The login information is stored in an encrypted database.

 

Action Steps:

1. Update your Passwords to meet the criteria in the chart

2. Use Multi-Factor Authentication whenever possible

3. Consider Using a Password Manager

4. If you have a device that allows biometrics, enable it

 

 

Hive Systems, Password Table www.hivesystems.com/password

NYT, Best Password Managers https://www.nytimes.com/wirecutter/reviews/best-password-managers/

Phishing

Phishing is a common cyber threat where criminals create seemingly trustworthy messages to trick you.  These messages can bait you into giving your username, password, account numbers, or even your Social Security number or install Malware that can compromise your device.  There are many different forms of phishing attacks but are usually seen in emails and texts, sometimes called smishing.

 

Some Examples of Common Phishing Attacks to Look Out For:

Spear Phishing: sending communications appearing to come from reputable businesses, such as your bank, or digital accounts asking you to verify your account.  They trick you into clicking a link to a fraudulent website and entering your login information, giving them access to your account.

Clone Phishing: creating a replica of a legitimate previous email and sending malicious links or attachments.

Fake Invoice or Delivery Scams: sending a text or email asking you to pay an invoice or fix a delivery problem.

Action Steps:

1. Verify the sender’s email address, not just display name.  Logos and graphics can be spoofed.

2. Don’t click the links in the message to login!  Use your browser to type the website address to login to your account.

3. If it looks suspicious or you didn’t expect the email, call to verify.  Don’t open attachments you were not expecting.

4.  Use Multi-Factor Authentication whenever possible.

Updates


Software updates can seem unimportant, and it is tempting to click “Update Later” but these updates are an important part of digital security. Out-of-date software leaves you exposed to risks. As soon as software is released, hackers start to look for vulnerabilities.  Installing updates can close these dangerous weakness.  According to the US Government Cybersecurity and Infrastructure Security Agency (CISA), “The best defense against attackers exploiting patched vulnerabilities is simple: keep your software up to date. This is the most effective measure you can take to protect your computer, phone, and other digital devices.”


Action Steps:

1. Update software as soon as possible.  Some programs have automatic update options. This link from CISA has guides to update common operating systems and apps.

2. ONLY update from the known official sources.  Prompts to update through an email, text, or browser pop-up could be phishing scams.

3.  If your software is older, updates may no longer be offered (known as end-of-life software).  If your operating system or app is no longer providing security updates, it is time to find a replacement.


CISA, Understanding Patches and Software Updates

Travel

Digital vigilance doesn’t end when you leave your house, most of us go everywhere with our phones.  When your phone does “everything” it becomes a target for hackers.  Wi-Fi networks, Bluetooth, and charging ports can create exposures.

 

Action Steps:

1. Don’t post on social media about your vacation while you are gone, wait until you get home.  Don’t advertise when your house is empty.

2. Don’t use public Wi-Fi.  Hackers can use it as a connection to access your device.  Instead, use a hotspot (through your phone provider) or VPN (Virtual Private Network, a service that creates a secure connection over the internet).

3. Adjust your phone settings to not automatically connect to nearby Wi-Fi.

4. If you need to charge your phone, tablet, computer, or any other USB device, use a cable and charger brick to plug into a standard wall outlet, don’t plug into a public or unknown USB port.

5.Turn off Bluetooth when not in use and unpair your phone from any unused devices (such as a rental car).



TMI

Online there are lots of ways to share Too Much Information (TMI).  Here are some ways you may be sharing more personal information than is safe with potential unintended consequences.

 

Social Media

Frequent posts with detailed personal information can give bad actors enough information to guess the answers to your security questions or passwords, manipulate you through social engineering, or imitate you to scam your social media friends.  Birth or anniversary dates, maiden names, and pet names are common passwords that are easy to guess from social media posts.


Artificial intelligence (AI) Platforms

Information you share with AI platforms (ChatGPT, Claude, etc.) is usually processed in cloud-based systems, meaning it can be stored, shared publicly, or vulnerable to breaches.  Paid or proprietary AI services are more likely to keep your information private.


Action Steps:

1.  Think before you post on Social Media platforms.  Less personal information in your profile is better and consider limiting who can see your profile to “friends only”.

2. Don’t assume anything you share with AI is private.