Washtenaw Business Lens: Preparing Local Enterprises for Emerging Cyber Threats

0
2

Key Takeaways

  • Cyber threats are growing more sophisticated, with foreign state‑linked actors and organized cyber‑crime groups (“Mafia of the Internet”) increasingly targeting businesses.
  • A robust incident‑response process hinges on preparation; detection, containment, eradication, recovery, and lessons learned follow, but preparation accounts for roughly 99 % of effectiveness.
  • Oversharing operational details on platforms like LinkedIn can give attackers the information needed to craft convincing social‑engineering scams, as illustrated by a $1 million fraud case traced to South Africa.
  • Strong authentication—two‑factor apps, hardware security keys, and emerging pass‑less keys—remains essential; passwords alone will become obsolete as quantum computing advances.
  • Businesses must continuously educate staff, revoke former employees’ credentials immediately, and enforce least‑privilege access to mitigate insider threats.
  • Staying current via daily threat‑intelligence feeds and leveraging local resources (e.g., law‑enforcement experts, chamber programs) is a practical, though ongoing, commitment for any organization.

Introduction and Guest Bios
The interview features Kevin Parviz, a detective/corporal with the Washtenaw County Sheriff’s Office who holds a Ph.D. in Information Assurance and has over 27 years of law‑enforcement experience, including 22 years conducting digital‑forensics examinations and nine years as a Homeland Security Investigations Task Force Officer focusing on human‑trafficking and child‑protection cases. Andy LaBarre serves as Executive Vice President and Director of Government Relations for the Ann Arbor/Ypsilanti Regional Chamber, a former Washtenaw County Board of Commissioners member, and co‑host of the “Washtenaw Business Lens” program. Together they discuss the evolving cyber‑security landscape and its impact on local businesses.


Overview of Current Cyber Threat Landscape
Detective Parviz notes that while public awareness programs have reduced some low‑level cybercrime, the overall threat has become far more sophisticated. Attackers now employ advanced techniques, constantly evolving to bypass defenses. He emphasizes that businesses cannot afford to lower their guard; continuous vigilance and adaptation are required as criminals refine their tactics, tools, and procedures.


Emerging Threats: Foreign Actors and Cyber Mafia
Parviz identifies foreign state‑linked cyber actors—particularly from Iran, Russia, and North Korea—as a growing concern. In addition, he describes organized cyber‑crime syndicates that operate like a “Mafia of the Internet,” developing ransomware and other monetizable malware. These groups often collaborate with private‑sector actors, creating a complex ecosystem where financial gain is the primary motive and attacks are highly targeted.


Incident Response Framework: Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned
When asked how businesses should respond, Parviz distills incident response into six core steps: preparation, detection, containment, eradication, recovery, and lessons learned. He stresses that preparation constitutes roughly 99 % of a successful response, likening it to securing a loaded gun so that a child cannot access it. The remaining steps address identifying malware, isolating infected systems, removing threats, restoring normal operations, and analyzing the event to improve future defenses.


Importance of Preparation and Practical Examples (LinkedIn Oversharing Case)
Preparation includes limiting unnecessary information disclosure. Parviz recounts a real case where a company posted details of a new contract and named its CEO, CFO, and accountant on LinkedIn. Attackers harvested that data, created a spoofed email address with a subtle character substitution, and impersonated the contractor to convince the firm’s accountant to change banking credentials. The scam resulted in a loss exceeding $1 million, with the perpetrator traced to South Africa. The incident underscores how seemingly benign public sharing can enable costly fraud.


Andy LaBarre on Business Exposure and Need for Education
LaBarre observes that virtually every Chamber member experiences some level of cyber risk because modern business necessitates an online presence. He argues that success in 2026 hinges on being plugged in—sharing content, driving traffic, and conducting transactions—yet this very connectivity multiplies exposure to scams. Education is critical: business owners must understand the threat environment, know how to stay updated, and recognize the limits of their knowledge. Local resources, such as Parviz’s expertise and chamber programs, are valuable but require ongoing commitment.


Password Security: Two‑Factor Authentication, Hardware Keys, Future of Passwords
Parviz advises moving beyond reliance on passwords alone. He recommends two‑factor authentication (2FA) via authenticator apps and, preferably, hardware security keys resembling USB drives that generate time‑based codes or use near‑field communication. A hardware key thwarts phishing attempts because it will not authenticate on a fake site (e.g., a Gmail login where the “L” is replaced by a numeral 1). He also notes the importance of keeping duplicate keys, as loss of the sole device locks the user out.


Quantum Computing Threat and Passless Keys
Looking ahead, Parviz warns that quantum computers could render traditional passwords meaningless, as qubits can represent both 0 and 1 simultaneously, allowing instantaneous bypass of conventional cryptographic safeguards. The current stopgap is the development of “pass‑less” keys—cryptographic credentials stored on a device that eliminate the need for memorized passwords. Though still under development, this technology may become essential as quantum capabilities mature.


Insider Threats and Employee Credential Management
Both speakers acknowledge that threats can originate internally, whether through accidental data exposure or malicious intent. LaBarre notes that insider incidents are an organizational reality across sectors. Parviz stresses immediate revocation of credentials for terminated employees and enforcement of the principle of least privilege—granting staff only the access necessary for their roles. He recalls a case where every employee possessed administrator rights to a server; when one went rogue, the full control allowed the individual to erase traces of the breach, illustrating the danger of over‑privileged accounts.


Daily Practices for Staying Updated and Closing Thoughts
Parviz begins each day by reviewing cyber‑threat alerts from sources such as Apple News or Google News, dedicating the first five minutes to staying informed. LaBarre echoes the need for continual learning, suggesting that businesses treat cyber‑security education as a recurring operational cost rather than a one‑time expense. The interview concludes with a reminder that protecting digital assets is essential for sustaining growth, safeguarding reputation, and ensuring resilience against increasingly sophisticated cyber adversaries.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here