BCX Connects

The Everyday Risks in Cybersecurity

BCX

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 17:40

In this episode of BCX Connects, hosts Garith Peck and Chris Bester dive deeper into the everyday digital habits that shape our cyber-resilience. From passwords and public Wi-Fi use to bring-your-own-device policies, they unpack how small, consistent actions form the foundation of stronger cybersecurity, proving that the battle is often won (or lost) in the basics.



For more information visit:  https://www.bcx.co.za/

Garith Peck

Welcome back to BCX Connects. My name is Garith Peck. I'm the Managing Executive for Cybersecurity. In our last episode, we explored how people themselves can be the weakest link in cybersecurity defense. Today we're gonna be delving a little bit deeper into the everyday digital habits and the habits that quietly shape our resilience. So things like weak passwords, public Wi-Fi, home networks, bring your own device policies may sound basic, but they're very often where the real battles are lost. The future of cybersecurity won't just be decided by new technologies or AI or things like zero trust. It will depend on how consistently we get the basics right. Now, digital hygiene

Digital Hygiene

Garith Peck

is about the small repetitive actions that create resilience over time. Now, joining me again today is my colleague and subject matter expert Chris Bester. Welcome, Chris. Good morning, thank you. So together we're gonna be exploring how the simple risks still matter and how future trends are shaping the way we defend against them. Now, firstly, Chris, I'm gonna maybe touch on public Wi-Fi because I I find the public Wi-Fi thing quite interesting. You know, uh I myself have uh a bit of a habit where I just don't use public Wi-Fi and I also don't use those airport charging uh stations, you know, where you plug in your USB. I've I've heard a few horror stories and I'm just so um untrusting of anything. Now public Wi-Fi um is has always been risky. You know, I mean the risk profile is changing, um, but it's not just about sniffing the uh unencrypted uh traffic um anymore. Uh attackers are now using automation and AI to mimic uh legitimate networks. Um so tailored fishing uh sites in real time to capture credentials, even public charging points are becoming weaponized, uh you know, where they call it uh juice jacking.

Chris Bester

Juice jacking, yeah, that's the word.

Garith Peck

So I mean like uh so Chris, uh when you look at this evolution, um how do you see individuals and businesses balancing the convenience of public connectivity and the growing sophistication of attacks?

Chris Bester

It's I mean, you the attacks really are getting sophisticated. And and and unfortunately, I mean as humans, we are our own worst enemy. You know, we um convenience most often trumps uh vigilance, you know. Yes. And it comes back to what we discussed in our previous episode, it's the education. Um it we need to from from a corporate perspective, it is just to repeat repeat that message, repeat that it becomes part of our fiber, becomes part of our culture to to be vigilant. Yeah, um, like I said, you know, it's so easy to be just for convenience sake, let's just plug it in quickly. And not thinking, um, I my phone is dead, my phone, I need to plug it in. You know, and and oh, this is free. Yes. It's so easy to and and and most often those are um weaponized, and um yeah, exactly.

Garith Peck

I think so uh you know the the lack of people's awareness on utilizing VPNs as an example, yeah. You know, uh just that awareness you know boils down to what we were speaking about yesterday. But I think that's that's the tension we face, right? I mean it's like you said, it's uh convenience versus resilience. Um you know that the future will likely bring more embedded encryption and seamless VPN-like protection, but until then the choice to connect like uh you know it it it lies securely, um it rests with the individual. So at the end of the day, it it sits with them.

Chris Bester

And and ignorance sometimes, it's it's uh especially the man up in the street out there, you know. They you talk about VPN, and the moment I had a conversation with someone the other day, and at the moment I said use a VPN, I don't have money for that, you know. But I just you know, just look around. There's some free options that's basic protection, but it's already uh better than nothing.

Garith Peck

I mean, look, so so for me, the the model is like the the next time you see free airport Wi-Fi 123, uh don't click it unless you want uh willing to donate your your banking details to exactly Lager in the basement or maybe some guy sitting in in Russia or Finland.

Chris Bester

Yeah, and and like you said, there's some horror stories if you just let your fingers walk through the internet forest for a while, you'll find those stories and then and and and I think like this like the the second part that I wanted to segue into is I think um more horror stories, I suppose, is when we start talking about IoT devices

Secure IoT Devices and Home networks

Chris Bester

and and home networks, you know.

Garith Peck

I mean, like we move into the home. I think if you look at the pandemic, right, the pandemic really blurred the boundary between personal and professional networks, like default router passwords and insecure IoT devices are now enterprise risks. Um, and it always this example always comes to me is the the very famous uh casino hack in 2017, right? Where via the fish tank sensor, the thermostat uh um you know that uh that was used um and that they gained access to the network because the fish tank had um access to the um the Wi-Fi and to the network and they moved around laterally for months. Yeah, um, so much to the point that they downloaded over 10 gigabytes of sensitive data. Um, and that is just uh a prime example of overlooked devices. Now, if you look specifically at IoT, think about the thousands of IoT devices because now we're talking about so many different connected devices. You have a fridge that's your IoT device, you know what I mean? Your fridge can betray you. Your fridge can betray you, yes. Exactly. So, I mean, so looking ahead, I think as homes fill with AI-driven or voice-activated devices, you know, I've got Alexa all over the place for my house, um, you know, the attack surface um multiplies, right? So IoT won't just be about DDoS botnets anymore, it's it's gonna pivot into something more, right?

Chris Bester

Exactly. And and you know, your um the perpetrators out there, they they know what's happening in in our world as well. And and once again, coming over its convenience, you know, convenience over vigilance over security. Um, I mean, I myself I have uh quite a few uh home automation things in my house. You know, and and and when you talk about uh talk about your network setup and whatever with people, I say, oh I'll just slap it on, you know. They don't think about uh maybe segregating that kind of network, especially people working from home. They have their corporate devices and plug it in in the home network, yeah. Um and and and that it's uh open a whole kind of worms there.

Garith Peck

Yeah, I mean, and and and for me, um the the critical insight is uh IoT isn't um consumer tech, right? It's part of enterprise perimeter as well. I mean, we see on the day-to-day how big the IoT space is. Um you know, the way we secure our homes will increasingly define the security posture of our organizations, essentially. So, I mean, um uh I always think also of that very famous water filtration plant that was breached in the States, you know, and and the actors came in via the Econ system, the HVAC system.

Chris Bester

So it's and and and that is very scary. I mean, they're now now we're talking about attacks on uh a cyber attack that can have a physical effect on human lives.

Garith Peck

Exactly, because I mean think about it a water filtration plant doesn't hold any sensitive uh you know uh personal credentials or anything like that. But what those threat actors are doing, they're trying to change the formula for palatable water. Exactly. Ultimately you can poison an entire populace. Yeah, right. So putting uh you know upping the potassium and upping the sodium and all of those kind of things, small differences brings it home, yeah. Exactly. I mean it sounds like a movie, but uh there are really scary stories about that. Exactly. Yeah, but I mean, let's be honest, I mean, no no one updates their smart fridge, right? So it's true. Um I mean, I I'm I'm I'm sitting in there in the kitchen, you know, uh like you know, while my my my my fridge is plotting against me, uh and uh, you know, probably sending out uh the grocery list straight to the hacker uh in Moscow, you know what I mean?

Chris Bester

So uh it's uh it's just a crazy idea. Even your your vacuum cleaner. Your vacuum cleaner has a camera on it to navigate.

Garith Peck

That's correct.

Chris Bester

And and that's there's some some horror stories of vacuum cleaners, uh, the automated vacuum cleaners have been hacked. It's fascinating. And and people spying on it. And some celebrities actually uh was that people spied on them.

Garith Peck

Um people exactly. But I think uh the other thing I wanted to touch on is passwords. I mean passwords uh you know remain the soft underbelly of cyber. So I mean, credential stuffing attacks, you know, cheap scaling, it's devastating, you know, and the human behavior hasn't changed, you know. Uh reuse it till it's rampant. Um, but uh I I see the landscape shifting. I mean, there's more things moving towards uh passwordless authentication, you know, those 502 standards, biometrics, behavioral recognition, etc. You know, so we see a lot of the big players like Microsoft's and Google's, you know, look moving towards the that direction.

Chris Bester

I think spending big bucks on the on their computers on that, yeah. Yeah, exactly.

Garith Peck

I think I mean privilege access management is really key. I mean, um that is really growing in in most of the sequence as well. But I think over time uh identity will will move from something we know to something we are or do, yeah, ultimately. So I I think uh so Chris, uh what's your view on this passwordless future?

Chris Bester

You know, this there's actually quite a debate if you go out on and and look at the subject on the internet. There's this there's the the the people that's for it and people that's against it, and so you know, you still have to have your password because that's something you know and things like that. But the big players are moving, as you as you said, moving towards the password list, and and and really having the the the biometric factor coming in and and and you know um they want us, you know, if you climb into your car, which is all internet connected, you know, that you don't need to to log on to something or log in here and there, and your car will just recognize you, yeah, as you, yeah, who you are, um, and and that's it's a profound shift, right? It is a profound shift.

Garith Peck

So passwordless won't arrive uh overnight, um honestly speaking. I think uh but uh forward-looking businesses and enterprises are already preparing.

Chris Bester

They are preparing for it, and

Future proof your identity

Chris Bester

and it's been implemented in quite a few places.

Garith Peck

Yeah, I mean for me, for me, it's about future-proofing your identity, yes, ultimately.

Chris Bester

Uh, because I like that term, yeah. Future pretty much.

Garith Peck

So so because the the cost of of clinging to passwords, you know, is gonna grow.

Chris Bester

Yeah, I mean, how long can it be? You know, you you keep on making it longer and longer and longer to make it stronger and stronger. And and the human mind is not made to remember all these things because uh then ultimately you write it down, and uh that's another surface scratch.

Garith Peck

Yeah, so in the future, I think uh in instead of remembering fluffy 2010 as your password or something like that, you know. You know, I'll just log in with my thumbprint or or maybe from the behavioral uh analytics, maybe how angrily I bash my keyboard on a Monday morning, you know, that behavioral pattern will be picked up.

Chris Bester

They were talking, especially the Germans were uh doing research on that kind of thing, you know.

Garith Peck

So um, yeah, it's uh it's interesting. Yeah, no, it's I think, and then uh I mean, then obviously it's a natural position to talk about uh bringing your own device. I mean the BYOD is uh has been there, right? Uh so to unlock productivity and flexibility, but uh what we've seen is it has also unlocked massive exposure. Yeah, um personal devices uh often lack the enterprise grade defenses. Um, you know, it creates that blind spot uh that that organizations don't pick up, you know, for specifically around data protection. Um I think for me the the the future lies in a unified endpoint management around zero trust architectures. Yeah, I think definitely around that. I mean, this for me means separating you know personal professional environments while maintaining that visibility and control.

Chris Bester

Yeah, lay it layer, yeah, differently. Yeah, because now you you're bringing in your own device, which obviously doesn't have all that protection and all the things that you have in your corporate machine. Um so you're not gonna have that particular uh endpoint protection on there. Uh that you that's that's okay for your organization. Yeah. So yeah, then you have to step just that layer back and say, okay, let's let's protect it from here. Or you know, it's it's it's complicated. You have to you have to strike a balance.

Garith Peck

Uh it's a complicated BYOD. I think uh it's it's it's always funny. I think the the new slogan for for for BYOD should be uh you know, bring your own devices, but don't bring your own malware. True. So so yeah, I think uh you know we see it, right? Uh lost devices, unpatched apps, you know, even worse, the shadow IT. I mean it's uh we've been speaking about shadow IT for the last eight to ten years. It's it's it's still there.

Chris Bester

And you know, with today's technology, with AI now, also in the in the play, everybody thinks he's an IT specialist because he can just ask AI, you know, um, and and that's another yeah, the shadow AI is a different story.

Garith Peck

We'll we'll pick up that in our next episode.

Chris Bester

Exactly, that's a good one. Yeah, yeah.

Garith Peck

I think, yeah, so I think uh on on the BYRD side, I think um the balance we might we have to strike that balance, you know, trust and empowerment on the one side, but accountability and resilience on the other. I think that's that's the best way. I think look uh I want to um um touch on um everyday hygiene habits. And ultimately I found you know the foundation that uh cyber resilience comes from digital hygiene. So updating firmware, enabling uh MFA, um reviewing app permissions, um, these are not glamorous, but they're essential. So I mean the next wave is obviously automation, self-patching devices, AI monitoring, etc. But the real question is whether people will trust systems to act on their behalf. That's the question. You know, the the cultural acceptance of an automated defense is all be crucial as technology itself, you know.

Chris Bester

So and I I just had a conversation with someone um in this week uh asking me, what about all this AI? I'm scared of this, you know. So it there's there's still that mentality. Some people don't know where to place it. Yeah, um, they still don't know whether they to they need to be scared of it or if they need to adopt it, you know, or uh embrace it.

Garith Peck

Yeah, no, I think you know the hygiene is really the fundamentals in having successful right secure environments. I think ultimately for me, uh MFA is like eating vegetables, right? You don't love it, but it'll it will keep you alive.

Chris Bester

It will keep you alive. You very, very that's a good that's a good analogy. I like that.

Garith Peck

Yeah. So I think uh um just some closing thoughts. I think uh the the reflection I I'd like to leave everyone is that you know cybersecurity isn't just defined by the sophistication of the attacker or the strength of the technology, it's definitely defined by the consistency of our habits. Um public Wi-Fi, IoT devices, passwords, BYOP, they may seem mundane, but these are true front lines. Uh the future will bring passwordless authentication, like we mentioned, AI-driven endpoint security, autonomous patching, etc. But until those are fully realized, um it's our digital hygiene today that that sets the tone. So with that, Chris, um thank you for your insights and uh to our listeners stay disciplined, stay aware, and remember resilience is built in the everyday. Thank you very much. Thank you.