Video: ISM Group CEO on How To Protect Against Dark Web Actors

ISM Group CEO Simon David Williams returns for part 2 of this discussion on security and the dark web.

Written By
Katie Bavoso
Katie Bavoso
Apr 8, 2024
1 minute read

Transcription

hey Channel insiders welcome back for part two of our special bonus episode on the dark web I'm your host Katie boso and if you haven't watched or listen to part one head on over to channel insider.com to do that right now today I continue my conversation with CEO of ism group Simon David Williams about what you can do to keep your information and your business is private information off the dark web let's talk about some some examples that you've been involved in where you've helped mitigate after an attack like this after somebody has been exploited on the dark web and when I say somebody a business that you work with has been exploited can you walk me through some of those examples and talk to me about how at what point are you contacted to say hey Simon David ISM group the worst has happened and then walk me through what you did to help them and what can be done to help them so usual scenario ransomware usually uh MSP or clients clients that have an MSP or don't have an MSP an internal it Department it happens in Quebec uh sometimes we have months that we have nothing so I'm okay but sometimes we have months like this month I get a whole lot of calls so why do they call me first I would say you know Jedi against Pirates is a conference that you know was made TR all Quebec that's the first reason the second reason I'm cool and I'm fun so I think they like having me on the phone and getting more information so and then they called me they said okay Simon I want to be sure something happened here but in Quebec we have laws so if a company has private information on their employees their clients their Partners whatever and they lose control of that data they have to publish it they have to advise those users of what happened there's a claim that they have to do to a specific website that's are you know the authorities of that law in Quebec they have to declare that to them too so they want to be sure about what they have to do as an IT business or an IT department or as a business owner depending on from who the Call Comes in so when they call me they're probably pretty nervous on the phone they usually don't believe that what's going on and their only insult prior is to restore operations that's the first five minutes I explained to them what is the dark web because usually people don't really care about what's the dark web so I show them cases of other businesses that have exposed data on the dark web and then they understand oh okay so now I understand so you're telling me that every pii of all of my clients or employees is going to be eventually published if I don't mitigate that incident I said yes so you should make them aware of what's going on you have to make people aware to be able to prepare themsel of that second wave of attack that might be not on corporate business but on the personal side the first priority is to do an investigation determine what information got out of the business and who is touched by this pii that's going to be exposed what kind of information was exposed because you have to protect your clients your employees and your partners first before restoring it operations and to do that you have to consider everything in your business phones tablets computers servers has a crime scene because if you want to do an investigation you have to consider everything as proof of what's going on so when they understand that they they're going to you know employ probably an investigation firm we're going to isolate everything on site out of the network create a new network to help them map specific computers are going to be freshly installed with brand new software brand new patch management brand new Security Services on them isolated from that crime scene I'm going to put that red Network that we call him and put it aside for the investigation to be done restart it operations on another size uh maybe mailbox email whatever you need but a bare minimum and we call that the yellow Network and the reason why it's the yellow one because it's going to be destroyed eventually because in the investigation we're going to learn a whole lot how the IQ came in what did they use everything is going to be exposed so we're going to create a green Network that's going to be a new network from scratch with every security measure that we learn in the investigation from the attack and I heard that you've been involved in some arrests of Bad actors too can you tell me about one I mean it's an effort that cames from a whole lot of people of course I was working on a case with an MSP they're friends of mine and a big case national case we're working on the case and the group is a very known a big group one of the most common ones out there on the dark web they were doing I think it was like a raid in Ontario they were you know analyzing data they wanted to do a visit of the probably somebody that's you know was dark I would say a dark a dark well dark Sith Lord a Sith Lord yeah and uh they went on site they found data onside about a specific client the client I'm working on so the ENT police patrol con Ed us and I said hey are you a victim of this guy I said yes we're victim of this guy because we can relate the pii that he had directly in his house to a direct case of victims and with that information they were able to do proceed of the uh the arrest and he's now in prison so one of the rarest case in Canada oh my goodness the first case that somebody actually went to prison for their crimes on the dark web yeah yeah he was a member of a but he's probably probably still a member of One a bigger organization that's called lock bit oh yeah and I'm sure that anybody who has ever turned on a computer has heard of lock bit for sure it's not if it's when you get exposed as a business even as an individual so for businesses out there who are listening what's the first thing that they should do if they find out that their information has been exploited and exposed on the dark web first thing would be to find out if that information is on the dark web so usually people don't believe in the dark web so the first thing would be believe it's real because I have to show them every time I no everybody can go to the dark R so believe in the dark web that would be the first thing just because you don't go there doesn't mean it won't find you exactly exactly the second would be uh people usually don't think it's a risk what's the worst case any it's only passwords they'll change it in our numbers we should be okay no there's a bigger risk uh than changing passwords it's money of course so private individuals uh as of now you know when when the cyber crime arrives there's been impact on individuals employees clients and partners that had pii exposed for a business and that happens a lot I mean we can talk about many many major business that had private information that was leaked out but they made aware of the people that what's was going on protect yourselves the problem with specific individuals when you have Pi on the dark web it's easy as of today right now to create a fake loan I mean I mean just in Quebec I think we have like six or seven websites that you can go directly on you type in your name no social security number and address and if they're okay where do I deposit that $55,000 where do I deposit that ,000 where do I you know quick loans easily online you can also get a credit card easily online everything is so easy as of now if you have the right information you enter it at the right time you can transfer that money to a basically everywhere and that has an impact on their personal score credit score and also I mean it's a fraud so it's going to be an investigation and things like that so believe in the impact also that having Pi on the dark web has consequences on your business because it's going to be your clients your employees that going to have consequences of your decisions so you have to concern that that information like is important the third one would be do the investigation I still have people that format the servers and the computers bring that to back up we have saved the business it operations is restored but I mean man you're so missing something big right now that's going to have a great consequences maybe on you as an IT Tech so having that information expose could cause great consequences on you just because you didn't do that investigation to turn out who's being touched by this information what is exposed on the dark web what will be the consequences of those individuals that's a failure when that happens and after that operations we can talk about we can restore them quickly outside of the crime scene from two different standpoints so obviously believing in the dark web and knowing that it is something that everyone is at risk of being exploited on I think that's the number one thing that people can do to start being more aware and keeping themselves safe but is there any other thing that both a starting from an individual standpoint so me as Katie boso how can I keep myself safe from being exposed or exploited on the dark web and then as a business what is the first thing that they can do to keep themselves and their employees and their customers safe from that as well for individuals MFA multiactor authentication Factor unification yes it's not 100% but it does help a lot when hackers get it those specific passwords they're going to try it everywhere let's say it was in a hot mail account they're going to try it on everything they can that same passwords so as soon as you get a password hit if you have multiactor notification you're going to receive the text file and usually that's going to stop script kitties and a whole lot of you know smaller hackers or individual hacker group that are outside of a group so MFA does help a lot and you have to understand what's MFA in a personal case everything you have access should have MFA should it's hard to implement that because I mean it's a it's a hassle let's let's talk about it it's a hassle you receiving a notification in your informance say yes or entering a code but it's very important it's very important because that's going to maybe eliminate 90% of every hacker group out there or individual that's out there wow second of all having a strong password there's diser on the dark web password diser on the available on the dark web every iteration up to I think it's 13 14 characters of 26 letters so 26 time 26 the probably of every you know outcoming word that could come up even though it's a nonsense word those dictionaries are available on the dark web so use long passwords that basically have multiple capital letters maybe dollar signs specific signs that can help you out with that that's going to help not triggering that MFA having long passwords and have individual passwords that are different for every platform as a private individual the last thing I would say to protect yourself uh something goes wrong on the D we first of off I would say don't click on those links and don't open that those attachments another thing about multiat notification would be the credit file for us in Canada we have TransUnion we have Equifax that manages our credit reports and credit history to different companies so let's say I go for a loan they go go to see that report send it back you can activate that MFA not only on the online account but on the information that's going to be pulled through ax and Transunion you have two ways of doing it you say first of all my wallet was stolen so as soon as that happens they have to call you to uh deliver that credit file to a bank or corporate funding company so they activate MFA as soon as you lost your wallet so if you say to them oh I lost my wallet MFA is activated and that's free by the way the other option is paying for credit surveillance so basically you pay for a monthly fee of x a month as soon as you have a credit question on your file you're going to see it you're going to send out an email you're going to see oh what's going on there do I have Pi that came out somewhere you're going to see who's asking for that that fake loan or that fake credit and you're going to be able to investigate on what's going on for the businesses pretty simple all of the mees the message the measures that I've been mentioning for personal individuals are the same but you have to question yourself about something do you have MFA everywhere you say yes okay on 100% of every login that you have inside your business you have MFA oh maybe not so that score has to be the highest possible not only emails everything every login everything you have access to inside a business it is a whole lot should have MFA second of all as of now for us in our small qu Canada certain insurers are now now are requiring an xdr or an EDR it's a software next next next to install I know there charges behind it it's going to monitor what you do regularly on your computer so if you connect to the dark web and open 10,000 connections to dark web from day one to day two that's not normal right so that they're going to cut out that uh workstation or phone from the network to enable you to investigate as a it uh Department as an administrator you're going to be aware that's if something goes wrong on the computer it's real but you just save the business of all the consequences of that single endpoint I clicked on the link entered a password or something like that implementation of a third gen firewall we do have businesses that don't have a third generation fireal as of now can you imagine that no security service at all a nus router with nothing on it and worst of all there's rules inside a router for Access L to one there's a word that's called any between them so basically everything is open from the land from our local network to the internet we can do everything we want and that's not normal usually internet uses like two or three ports but why do we have access to all of the rest we shouldn't because if a hacker comes in to get a computer he's going to and send out information using those specific Sports is like 65,535 ports open out to from your computer why do you need so so many of course uh password management tool that can you know going to have like hundreds of passwords so that's those password don't store them in the Excel file on your desktop or worst case on a USB stick I mean store them in a password tool that's going to be encrypted that has MFA it's going to be simple to use but secure uh training of course is very important let letting people know what's going on on the dark web and on the different measures that we're implementing why we're implementing them so they understand what we're doing right now is for your own security it's always for the users it's never for the business we always want to save the people first so we're doing that for you you mentioned cyber security insurance at one point and I think it's important to point out that many insurers if not all of them require specific tools inside of a security stack would you mind just going over what do you have to have in place to be able to be eligible for cyber insurance or not only that but to be able to get the claim should anything happen nice difference there because usually people do have cyber insurance and sometime the claims don't go through because they don't have a minimum of Standards or are applied even though they asked a question a year ago those minimum standards are changing every day so the the first one is MFA the second one will be xdr MDR EDR third one third gen firewall because first of all you have security Serv Services is going to inspect your traffic on the internet so that's a must a minimum so a third gen firewall with Security Services on it that's the bare minimum but there's just a whole lot of other other solution but when we get to I want my money back those are the three biggest ones are there any solutions Technologies or Frameworks that you're seeing right now that just work that you would suggest that people put into their security Stacks AV is important antivirus okay it's like a no-brainer because it's been there for 10 years but we sometimes forget it I just want to mention having an antivirus is still good okay going back uh what's the other solutions that you can Implement first of all having a business continuity plan prepare for the worst and test that worse is very good so let's say you shut down operations as of now test it out what would it look like and try it and it's weird because all the time it and the uh administrator says we have a backup we're okay we're back up in 24 hours fine very cool love it and you leave it like that and you go forward oh no no no no no no no create a new environment as this one would not exist in a parallel place and try flip the switch on and see if the data is okay and after 72 or 96 hours that was predicted to be 24 hours you'll know the reality of your backup solution for real the other thing that you could uh Implement testing your security having experts coming in your systems test out you know the different ports that are open the any rules that I hate for me in 2024 there shouldn't be any open ports from the the land to the land unless it's filtered and geolocated basically the rule I'm saying there shouldn't be any any inside of your rules you should always open up only specific ports to specific IP groups that you need to have access so having a tester come in and you're going to know what might be a big security risk in your business when do you see most of these exploits attacks related ransomware and malware attacks when do you see them happen during the week during the month is there a pattern there at all yes there is all always on Fridays or Saturdays or some days and always starting at 3:00 a.m. in the morning it's as you would know yeah I I know hackers usually connect to systems in the night so they're sure that you know nobody's connected nobody's going to see the mouse move or things like that and then they uh they act on the system they're going to encrypt the system I'm going to receive a whole lot of alerts or call coming in if somebody wants to learn more about being a Jedi rather than a Sith or being a Jedi against Pirates and they want to speak to you how can they reach out to you the best way would be LinkedIn uh um I always answer to my message so you can add me on LinkedIn if you have questions you on a specific case that you want guidance or maybe help or just hands or just maybe just listen our goal is not to get new clients our goal is to just support the it Community as a team because all of us together can change what's going on right now in it and in cyberspace so it's working as a team and one big family that we can assemble to those dark sit Lords and the ren thanks so much to Simon David for being on the show and thank you for watching or listening if you want more episodes of Channel Insider partner POV check us out on channel insider.com on YouTube at Channel inssider newws and Trends or on your favorite podcast platform if you've got a question or you want to be on the show email me at partner poov Chanel insider.com I'm Katie boso and I'll see you next time n

This transcript was generated automatically from the video's captions and may contain errors.

Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

ISM Group CEO Simon David Williams returns for part 2 of this discussion on security and the dark web.

In part 2 of this two part bonus episode of Channel Insider: Partner POV, Simon David Williams, CEO of Quebec, Canada-based ISM Group, continues his conversation with host Katie Bavoso about how individuals and businesses can protect themselves from having private information (PI) exposed on the dark web. Why should you take this risk seriously? What should you do if you are targeted? And, what tools do you need to have in place in order to be protected by most cyber insurance companies? Katie and Simon David answer those questions and more!

Katie Bavoso

Katie Bavoso is a 2017 Regional New England Emmy-nominated broadcaster with over a decade of professional content creation, production, hosting, and interviewing experience. Starting her career off in TV news, she pivoted to the IT channel to help connect vendors, solutions and services providers, and IT buyers through exciting video content and storytelling. Katie is now the host of Channel Insider: Partner POV, a video and podcast series shining a light on the most innovative solution providers of the IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.