AI generated image of a hacker in a hoodie surrounded by computer screens
Source: Vecteezy Credit: Vecteezy

MANSFIELD — Kirk Herath has bad news for TikTok fans.

“There’s a reason we won’t let it on state assets,” said Herath, the chairman of CyberOhio. “It’s basically spyware. It tracks you.”

Herath visited Ohio State University’s Mansfield campus Wednesday. He gave a fireside chat along with Mark Bell, cybersecurity outreach coordinator for the Ohio Adjutant General.

Over the course of their talk, the two men offered insights on personal cybersecurity, resources for businesses, local governments and the state government’s efforts to bolster the cybersecurity workforce.

Whether you’re a government official, business professional or simply own a device, here are some of their top tips for making your cyber safer.

Keep your hardware, software and operating systems up-to-date

Herath and Bell agreed the first and most important thing everyone should do is make sure their hardware, software and operating systems are up-to-date.

“If you’re running Windows 7, there is nothing else I can do for you,” Bell said.

Bell said you don’t have to have the latest and greatest technology, but anything you use should still be supported by the vendor.

In other words, if your product is so old it can no longer receive security updates, bug fixes or customer support, it’s especially vulnerable to security breaches.

Mark Bell, left, and Kirk Herath offered practical cybersecurity advice for business owners, government employees and the public during a fireside chat Wendesady at the Ohio State University Mansfield campus.

“If you’re running a piece of software or a piece of hardware that is no longer supported by the vendor, every time a new piece of malware comes out, every time a critical vulnerability comes out. That machine is no longer being patched,” Bell explained.

“It’s like an old car that doesn’t have a mechanic anymore. It might still run, but nobody’s working on that old car.”

Bell said many hackers target that type of technology.

“Most of those data breaches are occurring from vulnerabilities that we’ve known about for more than 10 years,” Herath said.

“They look for the Windows 7, it’s still out there and unpatched. They know there’s probably 47 different vulnerabilities they can use to exploit that server, get in, steal data, shut it down.”

Bell said it can be helpful to think of cybersecurity like physical security.

“If I come up to your house and you’ve got a steel door, an alarm system and cameras and lights, I’m just going to keep going — because your neighbor next to you has the door unlocked,” he said.

“It’s the same thing with cybersecurity. They’re going to go after the low-hanging fruit.”

Be skeptical of any thing that’s free

In a 2022 report by the National Security Alliance found Gen Z and millennials fell for cyber crimes like phishing, identity theft and romance scams at higher rates than their Gen Z and Baby Boomer counterparts.

One reason for could be that younger generations simply spend more time online. But Herath and Bell believe it could also be because they’re less skeptical.

“They’re digital natives. They grew up trusting this stuff,” Herath said. “It got trust in your hands often before you could walk.”

Herath and Ball’s fireside chat was part of Cybersecurity: Thinking Globally, Working Locally. This free speaker series is designed to broaden the region’s awareness of cybersecurity challenges and development strategies.

The series is free to attend and hosted by the Richland Area Chamber & Economic Development and The Ohio State University at Mansfield. For more information on upcoming sessions, click here and here.

Bell said he believes young people are more likely to think everything on the Internet should be free, which can put them at risk.

“One of the things that I tell people is you should always beware of free stuff,” he said. “Many times, those free downloads come with an extra surprise that you weren’t interested in called malware.”

Herath said nothing on the Internet is truly free — but that doesn’t mean you shouldn’t be online. Just be aware of the risks and possible intentions of whoever is putting out the content or service.

“If it’s free, then you’re the product,” he said. “They’re tracking the data that you’re pumping out with your usage, where you’re going, who you’re talking to, what you like. If that doesn’t creep you out, then that’s fine.”

Know where your data is — then back it up

There are multiple ways a hacker or cybercriminal could strike. Malware can be used to steal data and damage or destroy computers and computer systems.

Ransomware is a type of malware that can block a user’s access to their device and data, keeping it locked until the victim pays up.

That’s why back-ups are a practical security measure everyone should keep up with.

“Imagine if you lost every picture you have of your all of your kids’ entire lives. What would that do to you, emotionally? What would you be willing to pay to get that back?” Bell said.

“How do you solve that problem? You have good backups. Don’t plug an external hard drive in your laptop and leave it plugged in all the time, because now it’s just another hard drive on your laptop. If the other stuff gets encrypted, it’ll get encrypted.”

That being said, backups aren’t always enough to protect sensitive information. After data backups became more common, cybercriminals got more creative. Instead of simply withholding data, hackers now threaten to make it public.

This can be a problem for businesses, government entities or anyone who stores personal data on their device.

Bell said a lot of the data that’s stolen and leaked is old and users may have forgotten about it.

“What is being released is not the working data that is being backed up today, last week, the month before,” he said. “It’s data that’s been sitting in people’s networks for years that they never went back and took care of.”

Use strong, unique passwords and multi-factor authentication

Want to keep strangers out of your accounts? Using multi-factor authentication and not reusing passwords are some basic, but crucial, strategies.

“Don’t reuse passwords. This is the easiest way for the bad guys to get your stuff,” Bell said.

“If you use the same password on all your social media and one of them gets compromised, what do they have? They have your email address and the password you use for everything.”

They also said it’s important to change the username and default password that come with your WiFi router. Herath recommended choosing a password with at least 15 characters, including special characters.

Staff reporter at Richland Source since 2019. I focus on education, housing and features. Clear Fork alumna. Always looking for a chance to practice my Spanish. Got a tip? Email me at katie@richlandsource.com.