The latest episode of the AZ Big Podcast with Michael & Amy has officially dropped. Episode 112 features Ken Januszewski, Construction and General Liability lawyer & shareholder at Burch & Cracchiolo.
Listen to more of the AZ Big Podcast here.
Transcript:
Michael Gossie
Welcome to the AZ Big Podcast, sponsored by Burch & Cracchiolo. I'm Michael Gossie, Editor-in-Chief at AZ Big Media, and I'm joined by my co-host, our publisher, Amy Lindsey. Today, we're very excited to be joined in the studio by Ken Januszewski, shareholder at Burch & Cracchiolo.Ken, great to see you today.
Ken Januszewski
Good morning. Thank you for allowing me to be here.Michael Gossie
We're going to be talking about something that impacts nearly everybody, every individual in every business. So let's get right to it.Amy Lindsey
Start off, Ken, can you tell us a little bit about your background and your law practice?Ken Januszewski
Sure. I'm a litigator. I litigate in Arizona, New Mexico, and Nevada, although since COVID, it's mostly in front of my computer, whichever side I'm practicing on.Amy Lindsey
Things have changed.Ken Januszewski
Right. But I do a lot of insurance defense work, and I also tell insurance carriers what their policies mean in a particular case.Michael Gossie
But one of the interesting things about you is now you kind of have ventured into the tech world away from insurance a little bit, and you deal a lot with cybersecurity. How did you make that transition?Ken Januszewski
I was just asked to join the tech committee at the firm, and it just kind of went from there. And in the last five or six years, it's really, you know, it's always changing, but, you know, the changes have accelerated in the last four or five years. For example, multi-factor authentication, you know, like when you try to log into your bank now, you know, you get those little numbers you have to put in, that's MFA, multi-factor.That was coming on in 2019. Well, now it's almost passe. Now that's not enough anymore.
Michael Gossie
You just expect it. Well, that's the thing about technology, it's changing all the time. Just when you...Even we just went through a transition with Google Analytics. Just when you think you know it, new technology is out there and you have to learn it all again. So how do you stay up with all that?
Ken Januszewski
Well, as a lawyer, ethically, you're obligated to stay up with technology. And so we all have to do that as best we can. But you just, you know, if you don't keep up, you're going to be passed by.And that's not good.
Amy Lindsey
Yeah. It's kind of scary. And COVID has really changed with so many people working remote and, you know, it exposes the employee as well as the business.So how do you safely access the internet when you're at home?
Ken Januszewski
Well, at home, it's not too hard. I mean, you have your own network and you have your password protected. And well, you better have your password protected and a strong password too.And you know, passwords are important, but and they're, you know, they're so good now most of the time that hackers don't get in by brute force anymore, trying to just like guess what your password is. They usually, you know, ask you what your password is and you usually give it to them in a way that you don't think you're giving it to them.
Michael Gossie
So explain that.Ken Januszewski
Well, it's, you know, you've heard of phishing before. And this is a phishing spell with PH instead of F, of course. And I get these all the time and I'm sure you do too.Some of them look pretty good. Like I got this one from Chase saying, you know, you need to log in and do this or that. And it looked that email look for all the world, just like a Chase email.
But because I'm on the tech committee, I'm like, I can't be that guy. So I looked at the email address and it was from genwow.cox.net. And I'm like, that's probably a phony.
So and if I get one of those at work, Kathy Stoner is our in-house IT person. I sent it off to her and she sends it around to the firm and she says, look, if you see these things or another example is last week I got an email from Dan Cracchiolo asking me to send him $500 and probably know Dan Cracchiolo passed away in May of 2022. So I mean, I didn't fall for that one, but, you know, people try to get you to fall for it that way too.
Amy Lindsey
Yeah, we have that a lot at our office that they say that the owner wanted us to go out and run out and buy gift cards. And, you know, no matter how much you warn employees, at the end of the day, employees want to satisfy whatever their, you know, bosses are asking them to do. So it's really hard sometimes to tell them to stop and ask, confirm it.And like you say, look at the email address it came from first.
Ken Januszewski
What's called social engineering. And that's the way they're, you know, most people are hacked nowadays. Like, you know, help this puppy, click on this and the next thing you know, you've downloaded malware.For example, I had an email from a lawyer I was litigating with and it said, please download this. And I just thought, I'm not expecting anything from her right now. So I emailed her back saying, you know, tell me about this.
And I got two emails back, one saying, oh, I just wanted you to get this document, please download it. And the other one saying, hi, I'm out of the country for two weeks.
Michael Gossie
Oh my gosh.Ken Januszewski
Oh wow. Yeah. So I called her firm and of course they had been hacked, you know, so you have to be careful about that.I got another one from a firm where I was expecting documents, but I don't, and I can't tell you why, but some, it looked pretty good, but I sent it to my secretary and said, call them. And so she called and she emailed me back and she says, they've never heard of that guy.
Michael Gossie
Oh my gosh.Ken Januszewski
Yeah.Michael Gossie
Well, I just got hacked recently because I got a message through Facebook from one of my high school friends that said, hey, did you hear who, who died? And then there was a hyperlink.Amy Lindsey
I get that one all the time.Michael Gossie
Yeah. There was a hyperlink to obituary and I'm like, oh my gosh, I wonder who died. And I clicked on it and then I'm like, oh, immediately when I did.Amy Lindsey
I didn't click on it.Ken Januszewski
Yeah.Amy Lindsey
Just saying. Social engineering.Ken Januszewski
That's how they get you.Amy Lindsey
It's scary. Cause I have your whole list of your Facebook friends and yeah, I didn't open mine just because I knew it was something that never would have sent me one, but it had been, been from somebody different. I probably would have.Michael Gossie
Right.Amy Lindsey
They're pretty smart.Michael Gossie
So, so what are the biggest threats out there? What, what happens when people can, can hack into your system or hack into your network?Ken Januszewski
Well, you know, if you're working for a company, it's, you know, it's, there's ways that they mitigate it right away. Like if your IT provider, you know, your outside IT provider notices that, you know, gigabytes are suddenly going to Sweden or Russia, you know, they can, they can, they can cut that off right away.Amy Lindsey
Oh, okay. I never really thought about that.Ken Januszewski
Yeah. Or if someone is trying to hack it, like for example, if somebody, if, if you were to do that at your office where you click on something and they download a malware, they don't necessarily start sending that information right away. But if somebody then logs back in and they're logging in from somewhere like, you know, Chechnya or something, you know, then your, your IT provider can, can say, well, we're not going to allow that in.So there are ways, but again, it's, you know, one of the things I want to tell everybody today is you really have to train your people because as we've been just discussing, it's through people that they get in anymore. It's not through brute force. So you have to train your people.
We send, we have a, this is a funny story for me. We, we, you know, we have the same thing happen to us. I got an email about a year ago and I said, I don't think this is correct.
So I sent it off to Kathy and I said, you know, what do you think? And she said, well, I'm not sure if she clicked on it. And it was one of our training emails.
And so at the next meeting, everybody said, well, and Ken clicked on this. I'm like, no, Ken didn't click on it.
Amy Lindsey
Don't blame me. I, I played it safe. So what are, Ken, what are some of the biggest cybersecurity threats to businesses?Ken Januszewski
Well, you know, if you, everybody has what's called personally identifiable information and probably personal health, health information. And it's called PII, personal, personally identifiable information or PHI, personal health information. You know, you're in, in cyber, you just have to get used to acronyms and having PII on your system is where the risk is because it's a, it's a name and it's an address social or something like that.There's a statute that defines it and it's, it's changing all the time. So you have to be careful what you do with that. And when you send that sort of stuff, like in a law firm, I get health information about people.
And when I send it out, I have to have it redacted, have to have the social, redacted all their insurance information. And sometimes, you know, sometimes people challenge me on that, say, Hey, this is all redacted. I'm like, you, you get a court order that says I have to unredact it fine.
But until then, I'm, I'm sending it out redacted because I don't want it. And we also have to send that in a secure way through like a share file email instead of just sending it through an email. So you have to, you know, you have to encrypt your emails and you have to know what kind of emails have to be encrypted, those sorts of things.
And that's all through training, you know. And it just, it's a continuing process.
Michael Gossie
Ken, we have a million questions for you. But before we get to them, I have to say, you want to make a difference in your business and life in 2023 or 2024, contact an attorney at Burch & Cracchiolo to handle all your legal needs. Burch & Cracchiolo is a time-honored, full-service law firm who can partner with you no matter what your challenges, goals, or new horizons on the radar.Contact them today at bcattorneys.com. That's bcattorneys.com. So I have a question for you.
So we all work a lot of hours. Everybody's in the office a lot. Even when you're working from home, you're working on your work computer.
You're occasionally going to check your personal bank account. You're occasionally going to check your personal social media. How do companies protect themselves from being vulnerable to somebody exposing themselves through the company network?
Ken Januszewski
Well, I'm not really sure I understand your question. Like if you're at work and you're checking your bank account?Michael Gossie
Right, right. And then somebody hacks in and now they have my bank account. Who's liable?Am I liable or is the company liable?
Ken Januszewski
Well, I don't know if it's so much a case of the company being liable in that instance. I mean, again, unless the company allowed that malware to be there in some way. But it's a reasonableness standard.It's not like if it happened, you're at fault. You have to take reasonable precautions and that sort of thing. But that's all you can do is just keep trying.
Amy Lindsey
Yeah, we have the rule that employees aren't supposed to use their work computer for personal things, but I do. It's really hard for me. I can say it, but then I look at them and go, well, I've been known to check my banking account or Amazon might be on my work computer.Ken Januszewski
Yeah, well, we have 40 shareholders and telling them you can and can't do that is not always the easiest thing.Amy Lindsey
Good luck with that.Ken Januszewski
So how do most hacks occur today? Well, again, I think it's through social engineering. I have a lot of robust passwords and I have an app where I keep all of my passwords and I recommend something like that, Mindskeeper, but there's a lot of other kinds of apps out there so that you can have really strong passwords.But again, you just have to be alert for how is this email or another way is we do not allow people to, well, if you go on Google and you do a search, the first three or four searches are going to be called sponsored searches. And if you click on those anymore and you're in our system, it won't allow you to do that because that's where generally if there's going to be some malware, it's in one of those sponsored ones.
Michael Gossie
Is that right?Ken Januszewski
Yeah. I didn't realize that. Yeah.So if you, so like if the first one comes up is, you know, a company X and it's sponsored for, you know, entries down, you're going to see the same thing. Click on that one instead. You know.
Is that right? Yeah.
Michael Gossie
It's. So you're really good at SEO. Yeah.Amy Lindsey
Yeah. Wow. Well, I do notice that a lot too, that, you know, Facebook is one that pops up, you know, Oh, get this Yeti cooler for $10.Sometimes if the deal was too good to be true.
Ken Januszewski
Yeah.Amy Lindsey
It's too good to be true.Ken Januszewski
Just like Mama said.Amy Lindsey
Yeah. You know, one of our office people about a year ago was at Christmas time. Look at this.I'm going to buy all these Yeti coolers. And I just looked at her and said, I wouldn't think about it. And sure enough, she came to me an hour later and said it was a scam.
And it's like, yeah.
Ken Januszewski
Yeah. Unfortunately, it's, it's, it's true that if there's one man who has a piece of property, there's somebody else out there trying to get it away from them.Michael Gossie
Right. So, so what should people be looking for to be able to identify a phishing email as opposed to like, you know, a legitimate email?Ken Januszewski
Well, you know, fortunately, most of these phishing emails, if you, if you actually look at them, they make grammatical mistakes and like, you know, Chase or, you know, these other companies, they're not going to make those kinds of mistakes. So that's one good way. And a lot of times, I mean, they're just like really simplistic.It'll say, you know, in the, in the subject line, one thing, and it'll be blank in the body. Well, yeah, just delete, you know, put that, send that to your drunk mail. But again, you know, if it really looks really good, but you weren't expecting something from somebody, take a look at the email address.
And sometimes it looks good, but if you, if you put your cursor over it, it'll reveal that it's from Aunt Sally, you know, dot com.
Amy Lindsey
Oh, I didn't realize that.Ken Januszewski
Yeah, yeah. Oh, okay. Yeah.I mean, you know, again, you just, it's. And that takes two seconds to throw your cursor over and it's not a big process. Yeah.
What they're hoping for is that you're so busy that you're just clicking through things and that's how they get you. I mean, and it's going to happen to everybody at some point, because there's going to be, no matter how careful you are, there's going to be that one day when you're busy and you just click on it. Like, uh oh.
Michael Gossie
Okay. You mentioned earlier the importance of training when it comes to business leaders and businesses training their employees. Can you talk a little bit about what kind of training they should be doing?Ken Januszewski
Well, you know, we've implemented some training where we have people, you know, I put on a seminar for the firm, you know, about all this. For example, you know, we don't, our policy is you can't use the internet at Starbucks. You know, you have to use your, you know, all the lawyers and apparel legals have phones provided by the company, the firm, so they should use their hotspots.And you know, you tell them, you know, you can't, like if you're at the airport and you want to charge your phone, don't put that, your USB charger into that USB charger because sometimes those things can get hacked as well. So things like that, that you wouldn't necessarily think about that just as a matter of course, stay away from those things.
Michael Gossie
And you mentioned earlier before we started recording the importance of like turning off Bluetooth.Ken Januszewski
Yeah. Because, and this is really hard because most people aren't going to do this. But you know, when you're not near something where you need to be connected to your Bluetooth, you should turn your Bluetooth off because, you know, that's, that's a portal through which someone can hack your phone.Now, they also, you know, to do that, you have to click allow pairing, right? And most of the times, if you're at a, you know, if you are at a Starbucks and you get that request, you're probably going to say, no, I'm not going to do that. But if you're busy, again, you might click on that.
So it's just reducing your chances.
Amy Lindsey
Yeah, that makes sense. So what is the best advice that you can give a business leader to help protect themselves and their business from cybersecurity?Ken Januszewski
Well, you need to keep all of your applications up to date and you have to train your employees. I mean, I really can't emphasize that enough. It's, it's, you know, for all of the cyber tools at my firm employees, I mean, you know, it's going to be through somebody clicking on something that they shouldn't have clicked on at the end of the day.And so, you know, we do a lot of that, you know, again, if we get a, if we get somebody gets an email that's kind of fishy, well, we'll send it around the firm and say, hey, if you get one of these, you know, so, you know, it's just training your people. It comes down honestly to that, no matter how much tech you have.
Michael Gossie
With the advent of more people working from home and working remotely, has it created even more problems or has that helped ease the concerns?Ken Januszewski
Well, you know, again, technology is changing so quickly. I mean, from the time we were kids to, you know, to now, and I tell my, my children that, you know, from, you know, they're just all graduated from college now and by the time you're my age, you know, there's going to be so much more innovation than there is today. But so again, we had the VPN, you know, which was a state of the art a couple of years ago.Now we're going to migrate probably towards the terminal server concept, which is similar but different and, you know, it's always, and it costs money, but it's still cheaper to getting hacked. Right.
Michael Gossie
Wow. Ken Januszewski from Burch & Cracchiolo, it's been great having you here. Really fascinating information.Thanks for listening to the AZ Big Podcast with Michael and Amy for the latest, greatest business, real estate and lifestyle news. Check out the all new azbigmedia.com and once again, thank you to Ken and thank you to everybody at Burch & Cracchiolo for sponsoring.
Amy Lindsey
Thank you, Ken.Michael Gossie
Thank you.