The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Startups & Founders/The Franchise Academy Podcast
The Franchise Academy Podcast artwork

Cybersecurity 101: Safeguarding Your Franchise Today

The Franchise Academy Podcast · 2025-04-27

0:00--:--

Kathy Myron, CEO of E Silo and a cybersecurity expert with over two decades of experience, walks franchise owners through the real threats their businesses face daily. The discussion covers phishing emails, ransomware attacks that hold data hostage for hundreds of thousands in Bitcoin, business email compromise (BEC) where compromised employee accounts lead to fraudulent wire transfers, and sophisticated tech support scams targeting even well-educated business people. Myron emphasizes that any business with a digital presence - including those not primarily online - has an attack surface. For franchise operators, she recommends a layered defense approach: enabling multi-factor authentication (MFA) on all accounts, using password managers for complex passwords, installing business-grade anti-malware software rather than free consumer versions, and implementing Managed Detection and Response (MDR) or Extended Detection and Response (XDR) solutions for organizations with multiple employees. She also advises having backup and recovery plans assuming breach will occur, and offers E Silo's services as fractional CIO/CISO support for security assessments, regulatory compliance readiness (SOC2, ISO 27001, HIPAA, FTC safeguards), and security questionnaire preparation.

Key takeaways

  • →Phishing emails and business email compromise (BEC) are the most common attack vectors for franchise operations, often resulting in fraudulent wire transfers when employee credentials are stolen and used to insert fake payment instructions into vendor email threads.
  • →Multi-factor authentication (MFA), complex passwords stored in password managers, and business-grade anti-malware software on all devices create multiple defense layers that significantly reduce breach risk at relatively low cost.
  • →Assume you will be breached and maintain offline backups of critical systems and data so you can restore operations and minimize financial losses and downtime from ransomware or other attacks.
  • →Business-grade security software powered by AI and monitoring tools like MDR/XDR are worth the investment because they correlate activity across devices and locations to detect targeted attacks that individual users would miss.
  • →Franchise companies should provide centralized security software and monitoring to all franchisees to identify attacks affecting the broader network and protect the franchisor's reputation and data.

Guests

Kathy Myron

Topics in this episode

Multi-factor authentication (MFA)Business Email Compromise (BEC)Password managersPhishing emailsSoC2 complianceRansomwareManaged Detection and Response (MDR)Extended Detection and Response (XDR)Tech support scamsNext-generation anti-malware software

Questions this episode answers

What is business email compromise (BEC) and how do attackers execute it?

BEC occurs when phishing emails trick employees into entering their email credentials on fake login pages, allowing attackers to steal account access. Once inside, they create email rules to hide payment-related messages, then impersonate the account holder to insert fraudulent wire or ACH instructions into vendor conversations.

Is multi-factor authentication (MFA) foolproof protection against account takeover?

No - while MFA adds a critical security layer, sophisticated attackers can steal session cookies from authenticated users, allowing them to interact with systems like Microsoft 365 as if they were the legitimate user. MFA should be combined with other defenses like strong passwords and security software.

Should I use free antivirus software or pay for security tools?

Business owners should invest in business-grade security software rather than free consumer versions; paid tools fund ongoing threat detection development and can cost as little as $100 per year for multiple devices, whereas free versions often lack monitoring and AI-powered threat detection.

What should a franchise owner do if they suspect they've been targeted by a phishing email?

Do not click links or call numbers in suspicious emails. Instead, independently open a browser or app and log in directly, check your account status through official channels, or call the vendor's publicly listed support number to verify any claims.

What is E Silo's role for franchise businesses?

E Silo acts as a fractional Chief Information Officer or Chief Information Security Officer, providing executive-level guidance on technology spending, cyber insurance, regulatory compliance readiness (SOC2, ISO 27001, HIPAA, FTC safeguards), and security questionnaire preparation across industries and countries.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B78%
  • Speaker A22%

Most-used words

cyber21security20email17phone16call14software14franchise10somebody10money10insurance10help9account9number9kathy8industry8attack7

Episode notes

On this episode of The Franchise Academy Podcast , host Tom Scarda welcomes Cathy Miron , CEO of eSilo and a cybersecurity expert with over 15 years of experience in IT and audit. As cyberattacks grow more frequent and sophisticated, Cathy shares the essential knowledge every business owner needs to protect their data and financial systems. Whether you're a seasoned franchise operator or just starting out, this episode reveals: What ransomware is (and how it could shut down your entire operation) The shocking simplicity of modern email scams How attackers manipulate ongoing conversations to steal your money Why passwords are no longer enough, and how Multi-Factor Authentication (MFA) is your first line of defense The role of password managers in securing sensitive business accounts From phishing to wire fraud, Cathy shares real stories, practical tools, and clear action steps you can take right now to secure your systems - without needing to be a tech expert. This is Cybersecurity 101 for every modern business. Don’t wait for a wake-up call - learn how to protect your company before it's too late.

Full transcript

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to another episode of the Franchise Academy. My name is Tom Scarta. I am a franchise advisor by day and I apparently am a podcaster by night. And so I work with folks all over the country, help them figure out if franchising is the right business for them. I match people based on their skills, their personality, their goals, like the eharmony of business is what I like to call it. And so if you're thinking about a franchise, give me a call. I've owned and operated franchises myself, had some great success. I had one mega failure, which I was always embarrassed to talk about, but now I look at it as a blessing because I could talk to people like you and say, you know what, I've done it and I didn't just read it in a book. So we should have a conversation. Today is exciting because I have a friend of mine, Kathy Myron, with us who is an expert in in cyber security. We're going to learn all about what this all means because I am not sure. Kathy is the CEO of E Silo. She's a cyber security expert for more than two decades. She knows it, she knows auditing, she helps businesses safeguard. Most importantly, you're going to say you want to safeguard your business against cyber threats. And she also serves on multiple advisory boards in this space. Kathy, thank you for being on the Franchise Academy.

Speaker B: Thanks Tom. Um, happy to be here.

Speaker A: Uh, this is so cool. What the heck is cyber threat? We read about it in the newspaper. There's been a breach and maybe, maybe your personal information has been let out. Do I need to be concerned about this? If I own a franchise or if I'm a franchise company, probably I have to be concerned about it. What is it?

Speaker B: If you're a human and you do things on the Internet, yes, you need to be concerned. That's the simple answer. Cyber threats are really any technology related threat. The terms that you would be familiar with are sort of hacker or adversaries, bad actors. These are people who are trying to break into your systems to steal your data or immobilize your day to day operations. If you've heard of the term ransomware, it's, it's think about kidnappings that you hold someone for hostage for a ransom. This is holding your data and systems for hostage for a ransom. Usually hundreds of thousands if not millions of dollars in Bitcoin or some other currency. Any business today that has a computer that is doing any sort of business online, even if that's social media lead generation, but you're not an E commerce business. Or you don't consider yourselves a digital first business, you still have what we call is an attack surface, right, a digital presence on the Internet. And you are therefore potentially susceptible to these type of attacks and bad guys. If you've heard of phishing emails, right, where someone is trying to send you an email and they look like a vendor or a customer or somebody that you might trust, like Microsoft, and there's a really good reason why you need to act urgently and click now, right? You've already been a victim of an attempted cyber attack. And depending on whether you open the email, if you clicked on anything, you may also have been a victim of a cyber attack.

Speaker A: I get one probably per day these days. I just got a really authentic looking one from Google about my business account that somebody has taken over to be manager. Click here if that's okay, or something like that. And I'm like, what? And I was about to click and I stopped and I didn't. And then I went on Google, I look for things and there's no such thing as what they were saying. Um, on this, this email to me, I was like, but it's, but it was like@google.com and I'm like, did they spell it differently? Like, how do they. I don't know what they did and maybe it was Google, but I don't know.

Speaker B: So there's definitely a lot of different sort of ground that you just mentioned. Phishing emails will have a couple of characteristics in common that everybody should watch for. So if you ever get a communication, and not just in an email, it can be a voicemail, it could be a live person on a phone call where there's something urgent that they want you to act quickly before you have a chance to maybe stop and think or check with anybody else. And it's either something really scary or something too good to be true, like you just won the lottery or you have this money and we want to give you, those are two red flags that you might be dealing with a phishing email. In your scenario, you did exactly what I would have recommended, which is if you receive something from your bank, from Google, from somebody that you think there's a problem, independently open up a web browser, go directly to the site, or get to the site however you normally would, or open the app on your phone and check to check your notifications, submit a ticket to support. If you need to ask about an issue or about the status of your account, you can call whoever the vendor is. Just don't call the phone number in the email. They're smart enough to know, and they've changed the phone number. They may have a signature in the email that looks like your banker, but they've changed the digits on the phone number. So if you call from the number in that email, you're going to route yourself directly to the scammers and they'll have a very convoluted story for you. I'll tell you that people who are really smart, who are well educated, who've been in the business world for a long time, have fallen victim to these scams. I know of one personally where I got involved in this scenario. Somebody called me because they were standing in line at the bank waiting to wire $30,000 to someone who was a complete stranger. They knew the name and account number and address and. But they thought they were doing the right thing. It sounds crazy to say this, but, um, they were victim of what we call a tech support scam. So they had been browsing on the Internet, reading some news articles, clicked on some of that clickbait at the bottom, like very enticing photograph with a juicy headline. And so they clicked on it. It looked like a regular ad, but it wasn't. Took them to a site where all of a sudden their computer screen filled up with an error message, like your computer has been infected with a virus. And then there's a alarm sound at max volume coming out of their speakers and all of this overwhelms their senses and they don't know what to do. And on the pop up it says, call this number to call Microsoft to get it remediated. And so person thought they were smart enough, they're like, let me just shut it down. Like they panicked, close the lid, booted it back up. Same thing happened. It didn't go away. So they thought, I don't know what else to do, I'm going to call the phone number. For the next four hours they were on the phone with these people. Supposedly it was Microsoft. And then Microsoft said they saw something unusual. I'm going to transfer you. And they asked these questions of, uh, were you doing anything sensitive today? Oh, I was in my trading platform. Oh, let's pull up your trading platform. They got him to click on links so that he could, they could view the screen, right? And see get. Basically they're doing reconnaissance and we're getting an understanding of what kind of assets does this person have. How savvy are they on the computer? They supposedly transferred them to the trading platform and then to someone at the bank. Or long story short, over uh, the course of these four hours, they were convinced that there was a law enforcement sting happening, and they were helping law enforcement catch these bad guys who infect these computers. And in order to do all of this, they needed to wire all this money to. To a third party. But they said, here's the. Print this out. It was the account number of the person who was going to receive the money, and it was a script. So this is what you tell the bank teller, because the banks are pretty savvy to this. And it happens to older people all the time where they, oh, this is money to help a family member buy a house. So this is part of a down payment. That's why it's in someone else's name. That's why I'm wiring this large sum of money. And thankfully, the spouse, the wife, called me from the teller line because they waited in line 20 minutes to actually get to a live person. And in those 20 minutes, they were on. On the phone, but stopping and thinking, does this feel right? And I talked to them. I said, hang up the phone immediately. Talk to the teller, explain what happened, and we'll get you. We'll get your system scrubbed top to bottom. And that happens every day.

Speaker A: Every day. Every day. Everybody knows somebody who's been involved in one of these scams to. To the point where my mom, who's in her 80s, got a call, and they knew my son's name, so her grandson. And they said, oh, this is so and so Police department. We have. Your son gave the name, he's being held, he's okay, but his friends had drugs in the car. They're going to get arrested, but you need to speak to the detectives. And so my wife was a New York City police officer. So my mom gets on the phone and says, my daughter was a police officer, so I'm going to get her on the phone. Oh, don't do that, ma'.

Speaker B: Am.

Speaker A: We don't want to get her involved. She doesn't need to be involved. And then they're like, hang on, your grandson wants to talk to you. And they put some guy on the phone. He starts crying, grandma Grand. Next thing you know, my mom is on her way to Best Buy because they wanted whatever it was. I forget now. A thousand, two thousand, three thousand dollars in gift cards. And then all of a sudden, she got this sense, like a sobering moment in the parking lot at Best Buy. And she called me and she's wait. I'm like, uh, mine. It's 10:00am he's probably still in Bed. I see his car outside. Then she's like freaking out. So I go inside. Sure enough, he's in, he's sleeping. She's are you lying to me? I'm like, what? And all of a sudden she starts crying and then tells me what happened. And luckily she didn't wire any money or codes or whatever she was. But this happens all the time and more I'm spending time talking about it because people need to know about this and they need to warn their parents, especially because it like the things that are going on these days. I know we could spend hours on it. So many things. But for a business, is there anything people could do that would, that you could recommend to protect themselves? Like inexpensively? Is there, is it a smart thing to download? Like, uh, what is a Norton Cyber Security block system or something? What do you recommend?

Speaker B: So for businesses, the version of the story that I hear from businesses all day long is somebody sent our AP person, our accounts payable person, an email, right? It's a vendor or a customer. We've done a lot of business with them. And they said that they changed their bank and they gave us new wire instructions or new ACH instructions. And we didn't verify because it's part of an email thread that we've been having on this project for months and months. And so we went ahead and sent this payment and lo and behold, we come to find out that our vendor actually never received the money. So that's the business version of the stories that we were just telling. That happens all the time. How can you prevent that? So there's a lot of different things you can do. Typically when we see what the story I just described, that's called a business email compromise. BEC is the industry lingo. When we see a bec, it's usually because some staff member got a phishing email and they clicked on it. And more often than not, what happens is we, when they click on the link, it takes them to what looks like if you're a Microsoft shop, your Microsoft email login, right, your 365login page. So they put in their username and password and then boom, their account credentials are stolen. Those bad guys are now in your inbox reading everything. They're often going to do a couple of things when they first get access. One, they're going to create rules in your inbox, where maybe they're going to start by saying all emails that have, um, invoice or payment in the subject line, move them to this folder, or any sent items that have payment or invoice related, automatically delete them. And what they're doing is starting to cover their tracks so that they can jump into the middle of conversations as if they were you send the other party, oh, our wire instructions have changed, right? And then they want to delete all traces of that having happened. So you, if you knew what to look for at this point, you don't usually suspect anything. You would be looking in the trash bin, right? You would see these emails. You would also look in your Outlook rules and you would see all these are new rules that I didn't create automatically archive everything or delete these certain types of emails. I've even seen it so sophisticated. It was, there was one vendor in particular, it was a whale of a vendor and they only wanted to delete the emails back and forth to that vendor. And over the course of three and a half weeks, they, the bad guys were wired a million and a half dollars and the client got it back because the bank was really smart about it. So essentially they got lucky. Had the bank not been completely on top of things and had that not been a brand new account that all of a sudden had this influx cache that wouldn't have tripped off any red flags. So those are some of the things that, that you can look for. How do you prevent it? One of the easiest things that you can do is on your email account turn on what they call two step verification or multi factor authentication. Mfa, that is what is mfa. MFA requires that you have something which is your password and something that you have which is usually a code that's going to come to your phone. You have to have a combination of multiple factors to authenticate who you are to the system. So it's easy to, it's relatively easy to steal passwords. They get leaked on the Internet all the time. People choose really bad passwords that are easy to guess or they reuse them all over the place. So passwords, as a general rule are not very good for security. Turning on MFA gives you another layer where you have to have compromised the phone or the device or however you're getting that code. So that's one. I will tell you though that I have plenty of clients who have MFA turned on their email systems and they are still having these business email compromise incidents occur. And the reason for that is just that mfa, like every single security protection out there, is not foolproof. If it's implemented poorly, it can have its own vulnerabilities. And there is, there are sophisticated attacks that can steal. I don't Want to get too technical for your audience. But sessions where you're already logged in with your username, with your password and your MFA code, and if there was a savvy attacker who is targeting you, they could steal that session and interact with Microsoft as if they were you, because they stole the session that's happening, the session cookie. So what I would say back to low and no cost ways to protect yourself. You want multiple layers of defense. So as a simple example, long complex passwords that you don't reuse and that you're not, you're not picking things that are easy to guess, like a combination of birth dates and names and things like that. You want to store those passwords in a password manager or password vault because if you choose good passwords, it'll be impossible for you to remember them. So you'll need a tool, a security tool to help you manage that. And then you want to have MFA on all of your accounts. So that's already two layers, two, three layers of defense. That makes it significantly harder for someone to break into your accounts. The other thing that's really low or no cost, uh, low cost to do it right, is to have security software installed on all of your devices. So you mentioned Norton antivirus. I think people are very familiar with the term antivirus. I would say antivirus is a bit 1990s. There are much more advanced tools nowadays that are more predictive and they're powered by AI. The distinction between the two is antivirus. And especially the free ones that come included with your computer when you buy a cable subscription, right? They bundle stuff. There's a saying in the industry that if the product is free, you're the product. Just you get what you pay for. So anybody, anybody listening to this podcast, I would assume is a serious business owner. And as a serious business owner, you want to invest in business grade security tools. And they don't even cost a lot. You can 100 bucks. You can get a subscription that covers four or five devices in your house. It's probably the most value for money that you're going to get. So you want to use a business grade. We call it either anti, like next gen anti malware software, um, or if you have a real organization where you have multiple employees, multiple locations, there's something called Managed Detection and Response, mdr and there's other acronyms. There's vert. XDR is extended detection and response. The whole point of this being it is anti malware software that has a monitoring component. So there are humans, but also algorithms that are then monitoring all of the data coming off of these devices in a central single pane of glass. And they're able to identify, oh, there's unusual activity. There's Tom's logging in from his desktop in Florida, but someone's also logging into Tom's email from Romania. Uh, and Tom's got a session over here. And Sally in another department also has some unusual activity. And they can correlate this to say the organization right now is under a targeted attack. Any one individual isn't necessarily going to pick up and see all of that. So especially for your franchisors, you want to think about what level of centralized security software and tools and capabilities you're providing to all of your franchisees. Anyways, security software in every device is critically important. The other thing I'll say, because everyone asks, I'm just going to preempt the question. You need security software on your phone. I don't care if it's an iPhone. And they're great at security and privacy and everything else that the marketing says, whether it's an Android, you should have just like you have it on your computer, Whether you have a Mac or PC, have security software on your phone as well.

Speaker A: I did not realize that. So I, I use avg. I don't know that one.

Speaker B: Uh, yeah, they're the makers of Avast. Do you pay for the plan?

Speaker A: Yeah, I pay a lot. A lot in my mind. But it's $40 a month or something.

Speaker B: Okay. Yeah. When you're paying for backup software or security software and you know that because you're paying, that is funding the development of additional features and therefore enabling the software to better detect emerging threats and new vulnerabilities. Right. That's what you're looking for. Free is great if that's all you can afford. Right. I appreciate that there are people in that situation and do whatever you can, but from a business planning perspective, picking the right software is really important. And then I guess the last thing that I would say for low or no cost solutions is we talk a lot about prevention. Right? Oh, secure your accounts, have this security software. There's a million other things you need to do, especially if you're running a physical brick and mortar location or use a lot of cloud tools. But you can't prevent everything. I, when I do training with people, I have a slide that says hackers only need to be lucky once. Right. So you have to be lucky or good every single day. You cannot make a single mistake. Hackers just need to find one way in So I think it's worth, no matter what your security budget is, putting a little bit of money aside for the reactive response to a cyber attack. So assume you're going to get breached, what is going to be most detrimental to the business or to you as an individual and put protections around that so you have a recovery plan. And so for businesses that's usually having a backup copy of their systems and data so that they can restore and keep operating, minimize downtime, minimize the financial losses associated with it. For individuals, it might be something different. But definitely think about what is your plan if you do get breached, what do you do the next day? How do you continue to operate and work?

Speaker A: That's great. Yes, it's good stuff. Do you think that, would you say that you act as a remote chief, a CIO kind of person for like you, that's your role, right?

Speaker B: That's exactly what we do. We often act as the fractional or part time chief information officer or information security officer. And what that really means is that you may have a day to day IT person or team or company that manages the user, uh, questions or helping to install software, buying new computers, setting up new locations. But oftentimes what businesses that are in that small to medium space are lacking is more executive level guidance on what should we be spending on technology, what are the big risks? Should we have cyber insurance? Do we have enough cyber insurance? How do we even qualify for cyber insurance? Because it's a 15 page application in all of its Greek. Those types of things are often where we tend to get involved. And then the other one is where if you operate in an industry that has a lot of regulation, or your customers are very security minded and they have a lot of regulation, you're going to be asked to fill out security questionnaires or they'll ask you, are you SOC2? Have you done a SOC2 audit? Are you ISO 27001 compliant? Are you HIPAA compliant? Or do you follow FTC safeguards? And we will often work with companies to do readiness assessments to see how well prepared they are for those standards and give them a gap list for here's the stuff you don't have, here's how to go implement it. If you need help, either we can help you or we'll recommend some vetted third parties who can help implement those things. You have a complete roadmap to get you to where you need to be.

Speaker A: So you can do that for really any franchise, you're saying, oh, that's awesome.

Speaker B: Any franchise, any industry, almost Any country.

Speaker A: Any country. Wow.

Speaker B: Yeah. When I worked for ge, I was completely international for five years. We were multinational conglomerate. I spent a lot of time in financial services, healthcare, but the aviation industry, energy industry, you name it, I've done it. Did a lot with European privacy regulations. Now those things change a lot. And, uh, I'm not going to tell you, I do that stuff all day long. But what you find is that if you do this enough, what constitutes good cybersecurity and good IT management is pretty universal, regardless of what industry, what regulation, what three letter agency you have to deal with. And so most of the time when we talk to prospective customers, they're starting from a place where they really don't know where to start. They don't know what to do. They aren't, they're very uncertain and a little bit scared. And so we can always help move them towards whatever the finish line is. We may not be the official certification body to give you the stamp of approval, but we'll get you ready so that when you do hire them, you have a much higher likelihood of passing the certification, getting the approval and moving on with your life.

Speaker A: Yeah, no, it's fantastic. Most people, they know their business, but they don't know all this tech stuff.

Speaker B: Hundred percent. Yeah.

Speaker A: So just like you would have an accountant and an attorney and all these kind of people part of your team, you need somebody like you as well because this is becoming more and more, uh, involved in our lives and businesses. We can't operate without computers. To your point earlier about the ransom software, they know if they take down a company's computers just for a day, in some cases, they'll lose hundreds of thousands of dollars because they can't operate.

Speaker B: Yeah. And the newer thing lately is AI. How do I effectively take advantage of all of these AI tools but without creating unnecessary risk for my business? Right. For my franchise, for my customers. So how do I do that safely and smartly. And I think that organizations that don't have a strategy around what is going to be safe and effective use of AI that helps the business move forward and helps the business be innovative, I think are in for a world of hurt because their staff members are probably already leveraging it and you don't even know it. And so that's a new area where there's a lot of cybersecurity and privacy considerations, but just good technology. And in a world that is very cloud connected, everybody. Oh yeah, I want to use cloud tools. I can work from anywhere and that's amazing. But you want to Have a cohesive technology strategy so you understand where all your data is going, you understand how to then protect it and all the places that it's at. And also so that your costs don't balloon over time, there's a lot of different facets to what franchises and franchisors need to consider.

Speaker A: That's so fantastic. This has just been absolutely great. Is there any kind of last thoughts that you would want to leave with the listeners now?

Speaker B: I would say if you don't have MFA on every account that matters and every account that supports it, please take the next couple of minutes to go and do that. That's the number one best defense that you can have. And then the second thing would be, uh, I would ask all of you out there, when was the last time you had someone just look at or evaluate your cybersecurity? Typically, for most organizations, franchises aside, we recommend that you do that at least once every three years. Folks that are in a regulated industry have to do it sometimes more often than that. But it's worth. Anytime you've made a big set of changes, you've moved systems, the company has grown. Just pausing and taking a look and having somebody come in and give you an opinion on, hey, these things are great. And here's a couple things that you're missing. It goes a long way to reducing your risk. I know technology is expensive, right? It's sometimes other than people. It's one of the biggest line items on your expense list. But I can't tell you how many people that I've spoken to after a cyber attack. There isn't an amount of money that they wouldn't give to undo everything that happened to save themselves the hassle, the lost revenue, the lost productivity. And so if we could just rationalize or look at it objectively before those things have happened, what is it worth to you to have that peace of mind, to know what you can do and plan for 20, 25, put it in the budget, and to make your business more resilient. I think we all owe to ourselves. We work so hard in our organizations. In the case of franchise, uh, you're. You're investing into growing this thing. You want to make sure that a silly mistake by a member of the team doesn't put all of that at risk.

Speaker A: Absolutely. And to your point, would you not have liability insurance? Somebody slips and falls in your business, whatever it is, and you're like, oh, I don't need insurance. Don't worry about it. And that's like, what you're saying, oh, I don't need cyber security. Don't worry about it. And then when it happens and you go out of business because you don't have it, that is a problem.

Speaker B: And I'll tell you that nowadays, uh, so there is cyber liability insurance. I tell people on the reactive side, you got two things. Backups are insurance for your data and your systems. And then of course you have cyber insurance for the financial outlays and cost of these types of events, whether it's a cyber attack or not. You could just, your server can melt down, right? And you can use your cyber insurance to, to help cover some of those costs if you have a good policy. The problem these days is that it's really hard to get cyber insurance because everybody's getting breached, right? You open up the headlines and some other massive. If a large enterprise is going to fall victim and they have almost unlimited resources and unlimited dollars, then certainly a small business does not stand a good chance to prevent those things from happening. If you have the right defenses in place, that cyber liability cost comes down and it's just, it's good, it's good for the business, right? So it's a double benefit.

Speaker A: So cool. Kathy, if people listening and they want to contact you, what's the best way to reach you?

Speaker B: LinkedIn is great. I would also say if you want to have a conversation about anything, maybe unique in your world, if you go to meet Kathy.com, kathy with a C, all one word that pops you right over to my calendar, you can schedule a quick 15 minute conversation. I don't ever charge people to talk to them. I like to help people. I think this is very much an us versus them. The more, you know, the more powerful you can be to defend against the bad guys. And then we do. If it's okay, Tom, um, I'll just mention that, uh, on our website we have a free IT health check where you can answer some questions and we can give you a report that gives you a super high level view of where you might be in terms of risk profile and cyber readiness. So you can find that@esilo.com ithealthcheck sorry, it checkup.

Speaker A: Yeah, and it's E, as in, um, Edward Silo, right? S I L O. Yep dot com.

Speaker B: Yep.

Speaker A: Slash IT checkup. Kathy, this has been great. Thank you for your time. It's just amazing just to have somebody like you give us these golden nuggets on how to just be more cognizant of the threats in cyberspace which we're all involved in 247 these days.

Speaker B: It's my pleasure. Thank you, Tom, for having me.

Speaker A: Now this is great. And if you want to learn more about Kathy and her company Esilo, you can go to the franchiseacademy.com her information will be there. And reach uh, out with any questions. Thank you so much and we'll see you again soon.

Speaker B: Mhm.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Building a Cybersecurity Culture in Your Company (Encore)The Backup Wrap-Up · on Ransomware86 / 100
  • Stop Buying Trucking Tech Emotionally: The Better Way to Choose Software with Nate JohnsonBehind The Freight · on SoC2 compliance86 / 100
  • Reframing Cyber Risk with Jane Frankland MBEBCG on Compliance · on Ransomware84 / 100
  • Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 97UnHacked · on Business Email Compromise (BEC)82 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Ransomware80 / 100
  • Inverted Podcast #26: Hacklore Debunking Common Security Myths with Bob LordThe Inverted Podcast · on Password managers75 / 100

More from The Franchise Academy Podcast

All episodes →
  • A Great Unique Franchise Concept54 / 100
  • Deciphering The Franchise Disclosure Document
  • From Operator to Visionary: How CEOs Build Self-Sustaining Businesses
  • The Secret to Attracting and Retaining Top Part-Time Talent
  • Franchising 101:Myths, Success Strategies & Private Equity
Explore the best B2B Startups & Founders podcasts →
All The Franchise Academy Podcast episodes →