Cybersecurity expert: Hackers target humans, not machines - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
October 16, 2018 Newswires
Share
Share
Tweet
Email

Cybersecurity expert: Hackers target humans, not machines

Gazette (Colorado Springs, CO)

Oct. 17--Hackers don't target machines; they target humans as the easier route to gaining access to their target -- computer networks, on which they can find data and other valuable information, according to a Denver cybersecurity expert.

John Sileo, the opening speaker Monday at the National Cybersecurity Center's Cyber Symposium, spent an hour telling about 300 cybersecurity and information technology professionals how to reduce the chances of their organizations being hacked. He also showed how easy it was to get a member of the audience to give up enough information to access their iPhone and how he was able to handle more than 20 devices left unattended at breakfast before his speech.

Sileo said two-thirds of the 347 million people affected by data breaches in the past few years at Equifax, Facebook and Target took no action to protect themselves or their data, such as changing passwords to their accounts or modifying their online habits to avoid being hacked. He said some sort of personal information is available for sale on about 90 percent of all Americans as a result of data breaches.

"We are so overwhelmed with what we have to do, we don't protect what is most important. Hackers are going after the part of our brain that is on auto-response. The first defense is to be skeptical," Sileo said. "Criminals tend to hack humans first, and businesses tend to fund the training of humans last. The Target breach was due to failing to train the humans" on the basics of cybersecurity.

Sileo learned about cybersecurity the hard way. He was facing arrest and prosecution and his software company, which he had built from his parents' electronic repair business, was destroyed by cybercrime committed by his best friend and business partner. He had to spend more than two years fighting the false charges.

He compared technology to the character in the movie "The Princess Bride" that has a good and evil side -- Westley being good and the Dread Pirate Roberts being evil. He noted that Ross William Ulbricht, operator of the dark web marketplace Silk Road that Sileo described as the "Amazon of the dark web," used the alias Dread Pirate Roberts.

"We have been highly incentivized to want new technology and ignore the risk of sharing our data. Can we enjoy technology without obsessing over the risk" of using it? Sileo said. "The key to cybersecurity is to respect both faces of technology and align what you do on offense with data with your defense. The issue is assuming that the problem is always someone else's."

Sileo said he has learned that knowledge isn't enough to fight cybersecurity attacks.

"We will change our behavior when we begin to understand the threat and take it personally," he said. "It is our responsibility in business to proactively protect what we value most and protect it as your own. Otherwise, we will continue to be hacked and threatened. The problem is we are so overwhelmed by what we have to do, we don't protect what is most important."

Businesses must train employees to develop cybersecurity reflexes, so they instinctively react correctly when they are hit with a cyberattack.

Sileo also recommends that responsibility for security extend all the way to the boardroom; organizations spend 4 percent to 7 percent of an information technology budget on cybersecurity; security training reflect realistic targets; that user access be segmented to reduce exposure to attacks; risk and vulnerabilities be evaluated regularly; third-party vendors be vetted thoroughly; and organizations have a plan to respond to breaches.

The most common type of cyberattack is phishing, where the hacker sends an email asking the target to click on a website that downloads malware or a virus, Sileo said. The best defense, he said, is to hover your computer cursor over the link to show the real address to which the link is pointing and read it right to left -- the most relevant part of the address is the ending, such as ru for Russia. He said a breach of insurance giant Anthem was traced to the chief information officer clicking on a phishing email.

Whaling also is a popular cyberattack type in which a hacker targets the assistant of someone in a senior management role while the manager is traveling and cannot be reached. The hacker sends an email to the assistant asking for a wire transfer, which cost New York-based Ubiquiti Networks $39 million in such a scam.

Ransomware is a form of cyber blackmail in which a hack gains control of a company's critical data or files and holds it hostage for a ransom. Sileo said half of the victims pay the ransom.

Hotspot sniffing is a growing form of hacking in which a criminal sets up a free Wi-Fi hotspot to steal data from unsuspecting users that make a connection to the hotspot.

Strong passwords and password management software are a good defense for such scams, and blockchain technology represents a promising way to guard against cyberattacks, Sileo said.

"Resilience is our greatest security because everyone eventually will be a victim of this."

Contact Wayne Heilman: 636-0234 Facebook: www.facebook.com/ wayne.heilman Twitter: twitter.com/wayneheilman

___

(c)2018 The Gazette (Colorado Springs, Colo.)

Visit The Gazette (Colorado Springs, Colo.) at www.gazette.com

Distributed by Tribune Content Agency, LLC.

Older

EDITORIAL: TJ Cox has the needs of 21st congressional district in focus, making him best choice

Newer

Three Baltimore County police officers and woman hospitalized after house fire in Essex

Advisor News

  • 2025 Top 5 Advisor Stories: From the ‘Age Wave’ to Gen Z angst
  • Flexibility is the future of employee financial wellness benefits
  • Bill aims to boost access to work retirement plans for millions of Americans
  • A new era of advisor support for caregiving
  • Millennial Dilemma: Home ownership or retirement security?
More Advisor News

Annuity News

  • Great-West Life & Annuity Insurance Company Trademark Application for “EMPOWER BENEFIT CONSULTING SERVICES” Filed: Great-West Life & Annuity Insurance Company
  • 2025 Top 5 Annuity Stories: Lawsuits, layoffs and Brighthouse sale rumors
  • An Application for the Trademark “DYNAMIC RETIREMENT MANAGER” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Product understanding will drive the future of insurance
  • Prudential launches FlexGuard 2.0 RILA
More Annuity News

Health/Employee Benefits News

  • Get Covered Illinois extends first open enrollment deadline
  • Trump's idea for health accounts not new
  • Out-of-pocket pain means skimping on care
  • Trump's idea for health accounts was tried; debt soared
  • How to Appeal a Medicare Coverage Denial
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • 2025 Top 5 Life Insurance Stories: IUL takes center stage as lawsuits pile up
  • Private placement securities continue to be attractive to insurers
  • Inszone Insurance Services Expands Benefits Department in Michigan with Acquisition of Voyage Benefits, LLC
  • Affordability pressures are reshaping pricing, products and strategy for 2026
  • How the life insurance industry can reach the social media generations
More Life Insurance News

- Presented By -

Top Read Stories

  • How the life insurance industry can reach the social media generations
More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • Two industry finance experts join National Life Group amid accelerated growth
  • National Life Group Announces Leadership Transition at Equity Services, Inc.
  • SandStone Insurance Partners Welcomes Industry Veteran, Rhonda Waskie, as Senior Account Executive
  • Springline Advisory Announces Partnership With Software And Consulting Firm Actuarial Resources Corporation
  • Insuraviews Closes New Funding Round Led by Idea Fund to Scale Market Intelligence Platform
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet