How to Protect Your Title Agency from Cyberattacks | Ep 19

Episode Summary

Genady Vishnevetsky, CISO at Stewart Title for nine years, breaks down the cybersecurity threats facing title agencies today. He explains why phishing and social engineering remain the top attack vectors, how password breaches like the 10 billion credential Rockyou2024 leak expose agencies, and why multi-factor authentication everywhere is non-negotiable. Genady shares free security awareness tools, incident response protocols, and practical advice for small agencies without dedicated IT staff. He also addresses the weakest link in transactions: unsecured realtor email accounts and how voice cloning and deepfakes are emerging threats.

About Genady Vishnevetsky

Genady Vishnevetsky is the Chief Information Security Officer at Stewart Information Services Corporation, where he has led cybersecurity initiatives for over nine years. With more than 20 years of experience as a security leader, Genady previously held similar roles at two payment processors in the financial services industry. He publishes a weekly cybersecurity update every Friday at 8 a.m. Central on the ALTA Open Forum, providing title agents with current threat intelligence, attack techniques, and best practices. Genady specializes in making complex security concepts accessible to non-technical audiences in the title insurance industry.

Key Takeaways

  • Phishing and social engineering remain the number one attack vector in title insurance, with adversaries targeting the 24-48 hour window before closing when urgency is highest.
  • The Rockyou2024 breach exposed 10 billion username-password combinations, making multi-factor authentication mandatory for every account that supports it.
  • Email encryption and secure data exchange are inexpensive to add to Microsoft 365 and essential for protecting sensitive client information and avoiding liability.
  • Start security awareness training slowly and never penalize employees for failing phishing tests—embrace good behavior and turn mistakes into teachable moments.
  • Small agencies should hire a professional to conduct a gap assessment and establish an IT retainer relationship before an incident occurs, not after.
  • Realtors using unsecured personal email accounts are the weakest link in title transactions, and agencies must implement vigilance protocols like verifying wire instructions via phone.
  • Voice cloning tools cost as little as five dollars per month, making voice and video impersonation a growing threat that requires keyword verification protocols for high-stakes transactions.

Episode Chapters

Time Topic
00:00 Intro and Genady’s background
03:45 Current cybersecurity landscape for title
08:12 Cloud migration and vendor risk management
11:30 Most common cyber threats: phishing, smishing, password breaches
18:45 Essential cybersecurity best practices for title agencies
23:20 Understanding social engineering tactics
26:40 Protecting sensitive client data in transactions
31:15 Employee training: human risk over computer-based training
38:50 Balancing security with user-friendly operations
43:10 Incident response: first steps after a data breach
47:25 Mitigating the realtor weak link
50:30 Emerging threats: AI, voice cloning, and deepfakes

Full Transcript

Show Full Transcript (9,185 words)

never let the good securities incident go to waste. So just read the news, read security announcements, read the incidents and dive into it and find out how the company was breached and turn it into a teachable model. In a world where change is the only constant, Mo Shamil stands at the forefront, guiding title professionals to not just grow their businesses, but to master the art of innovation. With every episode, you're handed the keys to unlock unparalleled growth and stay ahead of the curve. Get ready for a transformative journey.

Getting to know more sophisticated, protective, sensitive client information has never been more important. Get ready for a deep dive into best practices, emerging trends, and actionable strategies to keep your business secure. Welcome Gennady. Thank you for having me. To start off, please give us a little background about your business career and education, all that fun stuff.

Sure. Yeah, I'm leading cybersecurity at Stewart Title, Stewart Information Services Corporation. I've been here for over nine years now and in this role of security leader, I've been in this role for over 20 years. My previous two endeavors were in financial services. I worked for two payment processors in a similar role.

So title insurance was new to me, but at the end of the day, I think information technology and the security crosses many boundaries. There are some caveats and differences. It depends on the industry. For the majority of companies, basic hygiene, security hygiene, security principles are the same. That's awesome.

The reason I reached out to you to get you in the podcast is I follow your posts. It's you at Alta Open Forum. If you're not subscribing to Alta Open Forum, you should. It's really some amazing information. And Gennady, whenever, every maybe a few weeks, you post something very scary, but all the threats are out there.

These are real. They're not fictitious. It's really amazing how bad actors keep innovating. Yeah. Thank you for promotion, Mo.

This is actually weekly. I do a weekly post unless I'm on vacation or traveling. I try to stick to the cadence. It's on Friday around 8 a.m. Central time.

And as Mo says, these are things that are happening within the last week or two. So this is not something that happens five years ago, three months ago. And I try to make it non-technical. It always will have some best practices. And I try to make it resonating, but explain to my audience, which is title agents, what's the dynamics of the cyber world?

What are the new tactics and techniques bad guys are using to attack us? Awesome. Can you give us an overview of the current cybersecurity landscape and particularly how it impacts the title industry? Sure. I'm sure everybody has known and heard of generative AI.

It's been around since the last year where it made its strides. And it changes every industry to a different degree. It enters our industry as well. Primarily, it's generative AI. It's a chat GPT.

Many companies and agents are looking at how do they use the technology to optimize and make their workday easier and efficient. There's a lot of companies, including Microsoft and Google, that introduced the co-pilots. Co-pilot is a term of generative AI that kind of drives the questions and answers and allow to look at the data and summarize it. I think the most common use today is a meeting summarizations, document summarizations. But many large underwriters and the companies start looking into how can we use the AI internally to aggregate our data, to ask the questions and let the data lead us to the answer.

Cloud exposure over the last four or five years, we're moving from traditional office. Remember that server sits in your closet over the last 25 years. We're taking the servers now and moving them to a cloud. Cloud computing storage becomes cheaper every day. That comes with its own risks and threats.

Because remember, in cloud, everything is a program. Everything is a software. In your closet, in your data center, you have physical devices that actually connect with the cables and the wires to each other. And to a degree, serve as a protecting mechanism. It's all sort of driven in the cloud.

So you need to be aware of that exposure. And then we see a lot of small company come into the market specifically in our industry to connect these dots. As our tools moving into the clouds, and as we embrace any new tools to optimize and make our process efficient, these vendors are producing point solutions that kind of connect the dots. It connects the technologies that haven't connected before and are able to get the data extracted from one tool or one technology and move it to another technology and then provide a different feedback. So that comes with its own risk because now you're taking your data and passing it along to your vendor.

So the vendor risk management becomes essential part of it. And then lastly, your data is everywhere. So you have to be aware of that. This is from an attacker perspective. They use it in social engineering.

I'm sure we'll talk about further down on about threats, etc. But just be aware that your data is everywhere and you need to safeguard it. I think it's this day and age, it's almost, I wouldn't say impossible, it's very difficult to still host your own network like locally, to keep up with all the patches and all the updates. And for those who still have the hosting their data locally, we're almost forced to move to the clouds. I don't think it's an option anymore.

So what advice do you give to people that still have local networks? Start shifting to the cloud. It's inevitable. So for better or worse, you have to move to the cloud. So before it was hard, it was expensive, it was complex.

Think about the business continuity. A server that sits in the closet in your office doesn't have a continuity for it. You may or may not have a backup. It definitely sits in one location. So if that location, if you don't have a network or power is out in that location, or just recently survived Hurricane Barrel here in Houston, some of us were without the electricity for a couple weeks.

So how do you get access to that data? A cloud provides that redundancy. Cloud provides it resilience at the lower cost that you build. So start thinking about we used to have a mail server sitting in our closet. Now, the Microsoft 365, Google Suite, all of these solutions are cheaper, they're more affordable, they have a better security, they're just better.

What are some of the most common cyber security threats that telecompanies face today? And how can they protect themselves against these risks? Believe it or not, they haven't changed in the last five to 10 years. So phishing is, they change a little bit. So phishing and social engineering is still number one attack and attack vectors in our industry.

What has changed slightly is we start seeing attacks using slishing, that the SMF-based phishing email. Those are extremely dangerous, and let me tell you why. Because traditionally, these are using what's known as a URL shortener. So when you receive the text message and it has a link, remember that long link that you see in your web browser, usually when you click on something, that gets shortened using these different tools called URL shorteners, and it's small. And the problem with it is, until you actually click on it, you don't know where you can land it.

You can no longer eyeball it and say, oh yeah, I'm going where I'm supposed to go. That's why they've become dangerous. Already spoofing, we've seen for years, for the last several years, we've seen pretty sophisticated attacks where adversaries will actually send an email followed by a text message to an escrow officer, followed by a phone call, and portraying to be from a bank or a lender, etc. So it's very easy. Those tools are easily and readily available for phone spoofing.

They've been available for decades, but not as widely as popular as it is right now. Some will go as low as $20 a month. You can pay $20 a month to have full access to anonymization called RID spoofing technology. Password attacks and breaches, even in the last three months, literally in the last month and a half, we've seen two major breaches. One is a national public data of 2.9 billion unique records.

Now, it's not 2.9 individuals, it's unique records, but that includes the data. This is a company that has the data for a background check. This is your knowledge-based answers to the questions that Nexus Lexus collects and answers. These are the social security and privacy data. This is your education.

We've seen two major breaches. One is a national public data, 2.9 billion unique records. Now it's not to 2.9 individuals, it's unique records, but that includes the data. This is a company that housed the data for a background check. This is your knowledge-based answers to the questions that Nexus Lexus collects and answers.

These are the social security and privacy data. This is your education, your birth certificate, et cetera. Anything you ever provided for a background check was in that database, 2.9 billion records. Roku 2024 passwords. It's funny how these breaches now collate the data.

They take the data from different breaches. They collate it into the one large database and sell it with a year. And every year they gather more data. So this Roku to Roku started in 2019, and now it's 2024, it has 10 billion passwords, username and the password. So these passwords are used in efficient attacks, and they're also used in what is called password spray attacks.

When the adversary takes these passwords, plug it into a tool, then they just run slow attack against your bank account, against your insurance, against your corporate account, against your email, against every account to see where it meets. Lately, we've seen an attack on the service desk or your IT for a password reset. This is new, relatively new, and you also use one of the attacks that's more sophisticated but we start seeing in our industry as well, is the SMS swapping. That's a technique when attackers call the telephone company, portray to be a legitimate user, say, hey, I'm on vacation in XYZ country, I lost my phone, I just bought my phone, new phone, and I need to port the SIM card into this phone. And they just answer basic knowledge-based answers that now readily available from the NTD bridge, and they can bypass your phone security service desk and get the password reset.

And then for larger companies and larger underwriters, we see an attacks for the elevated privilege. So attackers know from your link profiles, from your public appearance, from social media, from all those different resources, they know who you are. So they are targeting people who have an IT or security in a title or administrator or engineer or a developer because they know they will have elevated privileges to a corporate network, so they're targeting those. What are the key cybersecurity best practices that every telecompanies should implement to safeguard their operations? First and foremost, know your inventory.

You can secure what you don't know exists. So that's my first recommendation to any IT agent. And you need it in the incident triage, and don't limit your inventory to a computer and that server in the closet that you still have. So take the big pictures. Look at every SaaS, which is a software as a service.

Do you use a CRM? Do you use, is it Salesforce and something else? Maybe for a smaller agent, it's still a CRM. It's probably a cloud solution. Do you use any financial system, maybe a QuickBooks for a smaller agent?

So these are rely on something that you are not, you're accessing maybe daily, weekly, or monthly, but you don't think about it every day because when you come to the office, you just see your servers, your laptops, your monitors. Look bigger. Where are your backup? Or your key partners? Or your key vendors?

Where do you store your contacts? Where is your contact list? Is it on that server? Because if that server is encrypted and you don't have a backup of that contact list, how are you going to contact? Number two, MFA everywhere.

Multi-factor authentication everywhere. I don't care. You can start slow, but you need to, every single account that supports, which is pretty much every account under the sun nowadays, you have to set up the MFA because 10 billion passwords in the Rock you 2024 password breach, 10 billion. So you can imagine all your passwords CPU views are in that breach. And guess what?

You could have shopped with your reusing the password. You could have shopped at some mall website vendors, or you're buying flowers or cookies. When that's website is breached and all the credentials are stolen and made it to the dark web for reseller, they don't have to file with SEC. They don't have to inform regulators. You probably will never know.

So reusing passwords is pretty bad, but also the passwords that were leaked, the amount of passwords that were leaked in the last couple of years is just enormous. So MFA everywhere. Invest in security awareness. That's the key. This is how you keep and educate your employees.

Doesn't matter. It could be DRM into the Alta community to read my blogs or just write something once a week or once a month, providing a formal training, et cetera. Security, very important. And from technology investment, I would invest into two technologies. One is the email and one is a web security technology.

Those are help you tremendously because if you think about it, outside of the social engineering, your only two connections or exposure to the internet where you can get infected is your email and your web browser. So if you can put the layers of security, additional layers of security to both of these channels, you're reducing your risk significantly. That's great. Can you touch a little bit on social engineering, make sure our listeners understand what that means? And that's probably the most incidents for tele-agencies through social engineering, not really infiltrating our systems.

That would be accurate. Yes. So the social engineering is a technique where the adversary provides or steers you to do something that you didn't intend it to do. And then normally they will support this or drive this with a context that resonates with you. For example, if I send you an email and saying, saying, Mo, have you watched, I saw you at the last night at the football game at the local field, et cetera.

You don't go into football if you're not even a fan of football, you probably will dismiss it. But now if I tell you, if I connected to you over social media or somehow get an access to your social media feeds and know your love of baseball and you have two kids and your kids were playing baseball last Friday night for a local tournament, et cetera. If I provide you in my contacts this information, hey, Mo, it was great to see you at the football games. Your kids are so great at the baseball. So I'm giving you now contacts you immediately will respond to because it resonates.

That's basically a tactics that the social engineer reviewed. Once of the most, one of the most common tactics is a sense of urgency. And that's important to understand because in our business, it's all about the closing. Closing cannot move. Closing has to go on and adversary knows this.

So they monitored all these transactions up till last minute and they close it. And most of their attacks are coming in 48 to 24 hours. And in our business, protecting client's data is very crucial. What steps can title companies take to ensure that sensitive information remains secure throughout transaction process? You need to make sure you encrypt the data at rest and in motion.

So what that means is the data you store on the server or in the cloud needs to be encrypted at rest. And there are multiple ways to do this. This is not a technical podcast. So I'm not going to go through the details, but your IT staff will know how to do this. And you also need to protect the data that moves either from you to anywhere else or from anywhere else to you.

That today, in 99% of the cases are protected through the web TLS or SSL encryption or security. But you need to make sure that this, your data is encrypted at rest and motion because all of the regulators and all the compliance standards requires us to do that. So not doing that, you're increasing your chances to be penalized if you are in a security incident. Number two, don't store the data you don't need for any regulatory or business requirements. We tend to store infinite, our data infinite.

The prior files is a key for us or any transactions want to go to a prior files and look at the history of that property and history of that files, but just distill because most of the prior files don't have any sensitive data. Don't take all of the data, just distill it only to the data you need and try to store your data to the medium. And then also we talk about the vendors and how our ecosystem is growing. You need to understand your vendors and partners' ecosystem. What data is going where and how does your partner and vendor protect your data?

Because remember, you're still liable. If this is your data and it's leaked and all of a sudden bank comes to you and saying, you lost the data of our customers, they're not going to be interested in your excuse that it was lost by your partner. So make sure you understand that. to the meeting. And then also we talk about the vendors and how our ecosystem is growing.

You need to understand your vendors and partners' ecosystem. What data is going where and how does your partner and vendor protect your data? Because remember, you're still liable. If this is your data and it's leaked and all of a sudden bank comes to you and saying, you lost the data of our customers, they're not gonna be interested in your excuse that it was lost by your partner. So make sure your partner's agreements, your MSAs and other contractual obligations with your partner you're exchanging the data with, they're meeting your standard, your data retention, not theirs.

And then lastly, use email for email encryption and say data exchange or communicating with your clients, with your customers, et cetera. Our customers' generation is getting younger. They're a little bit more tech savvy. So we start seeing our customers asking the question, are you encrypting the data you're gonna send to me in communication? So they're a little bit more acute to a technology and they're asking for all of the safety and security because this is non-repudiation for you.

If you can definitively say that, I send a sensitive document over encrypted channels and you have a proof of this, you know, you're better protected. Yeah, I think that email encryption, that should be, it's not even a question, that should be automatic at this day and age. And especially it's a little not expensive as inexpensive to add encryption to Microsoft 365, like a few dollars per user, it's worth that expense. That's another reason to move. You still have a mail server in your closet to move into modern cloud-based solutions like Microsoft and Google.

Yeah. You're absolutely right. Now we'll move to employee training. Human error is often a significant risk factor in cybersecurity. How important is employee training and what should be included in the cybersecurity training program for title professionals?

That's a good question. My first recommendation, don't penalize your users. A scared and stick kind of approach is no longer working. Everybody makes mistakes. So you need to embrace the good behavior and correct the bad behavior.

So entice users to perform well and understands the good behavior and what the security, so educate them what the phishing emails looks like. Do a periodic testing, but also don't penalize them if they fail. Again, explain where they fail and move on. As a matter of fact- To be an opportunity for further training, like when people fail. Yeah, but here's an interesting shift.

So I start seeing shift from, so what traditionally used to be a CBT-based training, it's a computer-based training. We're all accustomed to it. You sit in 30 or 45 minutes staring at the screen. Somebody is playing the roles and videos security awareness training. That doesn't work anymore because while we see that the employees are watching that video, they're actually multitasking.

They're doing something on another screen. And a cell phone- That doesn't work. It can also tell you that not two employees are equal and there are some predispositions to be more sensitive and fall for the emails. Maybe they're less technical. You don't understand the terms, et cetera.

All different. So now this industry is shifting into a human risk. And a human risk in the context, it's not just, first of all, it's a continuous training, but it's a continuous training and evaluation and testing exercise based on the behavior. Based on the behavior and based on who you are and what your role is. And what some of these newer systems will start seeing and showing up on the market allows you to do is to tune your program towards the people who actually need this program.

So you can actually endorse and embrace people who are exhibiting good behavior and you can do a teachable moments or you can do a small nimble adjustments to the folks who are not. Example, some of these tools looks not only just lives in its own ecosystem, but they plug into other tools. For example, your endpoint detection and response tools or your email security tools or your chat or your Microsoft 365 tenant or Office 365 tenant. So it knows how user responds to the email. First of all, it knows the user role and you have to define what are critical roles or not.

Probably the escrow officer is a critical role or a wire fraud, or maybe IT or security administrator would be a critical role for elevated privileges, et cetera. So they all will have different attacks. And now you can imagine various different attacks and different training opportunities for different roles. But again, it looks at other telemetry. It looks how you behave on your system.

It looks how you behave on the web. It looks what sites you're visiting, what information you're receiving and sending and what you're downloading. And it creates this risk profile and allows the company or a business focus really on people and folks who needs help. That's basically what's where the industry is shifting to. Also, there is an old saying, never let the good securities incident go to waste.

So just read the news, read the security announcement, read the incidents and dive into it and find out how the company was breached and turn it into a teachable moment. And so there is a wealth of information where you can actually, and it's a factual and it will resonate with the people because they saw it in the news. Yeah, but employee training is a fundamental. This is the first and foremost, first most focus area for, I think, for any title agent. Are there any training tools or services out there for title agents that are not a size of a steward?

Yes, there are a million tools. And by the way, many vendors provide a free option, free or low cost option. This is probably the most underappreciated industry is the security awareness. There is tons of information available from SANS Institute. They provide it for free.

CISA cybersecurity information, security agencies provide some free information. The well-known and the large vendors like KnowBe4 and CoFans provide a free training. You can do a free assessment. Some of them provide a free assessment where you can enter your domain or upload the list of your users. And actually they will send the free phishing emails and will give you a results who responded to the phishing email.

You can get a CBT-based training from many of these companies for free. And you can actually alternate. You can build, you can basically build the security awareness training for free. Not to mention that all of them will allow you to subscribe to a security awareness newsletter. You'll get, your employees will get to the inbox anywhere from once a week to once a month to once every couple months.

You don't have to enroll everybody. You can just enroll yourself or one person at the company and have them forward to everyone. Can you just say those names again? One is SAMS. SAMS, S-A-M-S, SAMS.

Okay, what's the second one? CISA, it's a C-I-S-A.gov. CISA.gov, okay. Yes, and the couple of vendors that I can recommend, KnowBe4, K-N-O-W-B-E-4.com. And another one is CoFense.

It's a C-O-F-E-N-S-E.com. That used to be Fishme. They rebranded their name. Okay. Thank you.

It's going to be very helpful and useful to our audience here. In pursuit of security, there's often a concern about making systems too complex for users. How can thought of companies balance robust cyber security measures with user-friendly operations? My first recommendation, start slow. If you try to ramp up the train to 120 miles an hour, you're probably not going to get there.

Let me give you, let's take as an example, multi-factor authentication. You can start slow by enabling multi-factor authentication, given all the possible ways. Like for example, Microsoft will support the phone call where the user will be called, user's preferred phone number will be called, and all they have to do is press the star or pound to accept that. It can send SMS message. It can send an email message.

You can use an application and so on and so forth. So you can start by enabling all of these features and functionalities for multi-factor authentication to get the user start slowly adopt. Once you pass the first phase and you start adopting, then you start removing the weak or what we know as a fish resistant or start implementing fish resistant multi-factor authentication options and remove the weak one. And we'll talk about the weak one. For example, phone call is a weak one because it's prone to what is called MFA bombing.

It's a type of attacks when the adversary or bad guys try to make a repetitive, for example, they try to log in, they already stole your credentials somewhere. And they try to log in into your email with those credentials. And they see that email initiates the multi-factor authentication. They probably don't know what it is, but every time they try to log in, you receive the phone call. And if you didn't initiate or didn't log in, call is a weak one because it's prone to the what it's called MFA bombing.

It's a type of attacks when the adversary or bad guys try to make a repetitive, for example, they try to log in, they already stole your credentials somewhere and they try to log in into your email with those credentials and they see that email initiates the multi-factor authentication. They probably don't know what it is but every time they try to log in you receive the phone call and if you didn't initiate or didn't log in you probably will say I'm not gonna do it is but they do it repeated repeatedly and sometimes they'll do it is in the early hours or in the middle of the night or late night or at the end of the day they're causing the repetitive prompt causing fatigue and eventually user will press just for it to go away and that's all they need. So you start as you maturing that process as your users become more accustomed to this type of authentication and get comfortable with it. It's comfortable that's a keyword in our industry. Remember we're trading this we're not a technology industry.

A lot of folks are not comfortable because they don't know how this technology works, they don't understand the technology, don't understand applications. Now you're shifting them to a more phish-resistant. Your application, push your application token or apply it to either USB or a key fob key. The next one is allowed to opt-in. Start slow and say we'll have an opportunity to do an XYZ and have a people opt-in because somebody will get in and somebody will try it in the rumor will spread around to say it's not as bad as I expected and that will get an adoption.

Where possible when you whatever you implementing give users two options. Give them the option the most desired option where you want it to be with the highest level security appropriates for whatever it is. Whether you implemented security, technology or implementing training etc. But give them the other option and have them choose and then you can slowly shift and take one option away once they become comfortable but in the process entice and reward the people who chose the higher option. I don't know, give them a gift card, give them a Starbucks gift card.

Entice them because again the rumor will spread around and people will support each other. Try to make it frictionless. There are some technologies, for example email and web security, they are relatively frictionless. All of this technology intended or designed to be behind the scenes and non-intrusive to users. Now where there are certain times there are some fallouts and something needs to be whitelisted or blacklisted or adjusted.

In not over 99% of the cases it's frictionless. So make sure when you implement the security technology and you look at this, you look how it works behind the scenes seamlessly and not interfering or impeding anything that the user does. And then I guess the password managers, this will be my only recommendation. It's hard, again start it slow. Maybe for privileged account, maybe your title agents or escrow officer was accessing to a title production system.

You'll say you're required to have a complex password and here is a free password manager. Those password managers are not that expensive. So if you pay for a password managers for your employees, if you help them to understand how it affects their personal life, if you educate them to say hey these passwords are going back to the billions of passwords. These passwords are out there. So if you're using the same password for your bank or your title production software for your insurance or whatever else, you're probably in danger.

So here's a tool for you. Start using change password for your bank because it's all adaptations. People will get used to it and they'll get on board. In the unfortunate event of a data breach, what should be the first steps a title company takes to mitigate damage and secure systems? That's a good question.

A couple years ago, Alta Cybersecurity Working Group actually created a checklist. It's published on Alta's website. Anybody with Alta access can download it. But my answer is it depends. It depends on the size of your company or your business.

It depends on the size and the type of incident. It will be different but the participants in your incidents response would be your insurance carrier. Whether it's a part of DNO or whether you have a separate cyber insurance policy, you need to contact at some point, you need to contact your carrier. But even before you do in the preparation for the incident, you have to contact your carrier and find out who is on the proof panel or proof list from your carrier. Because they will have outside counsels, they will have incidents response firms, they will have a forensic firms, they'll have ransom negotiators, etc.

They will have a portfolio of panelists or approved vendors that you can use during your incident. That's important to understand it. Like I said, it depends on the size and different circumstances. That may not be your first call but at least you need to understand. Because at the end of the day, some of the expenses will be covered by your insurance carrier, so you need to play by the books.

Otherwise, they'll deny your claim. If you don't have an IT or security resources who can help you to leave and take you through the incident, you need to make sure the IT, you have an IT retainer. You need to make sure you have somebody. This is not IR. We'll get to the IR in a minute.

It's an IT. Somebody who can help you to log in or you can log in to your desktops and laptops. They're encrypted. You can't access to your printer, etc. You need someone who can help you decipher what happens.

You need someone who can incidents response retainer firm or someone else can walk through and help in kind of triage this incident. And this is actually a key. Our business, our industry and our business becomes more technical than it used to be 10 to 15 years ago. So we can no longer brush it off and say it's too technical. It's not gonna apply to me.

It will never happen because it will. Crime is, I tell it everywhere and to everyone, cybercrime is an opportunistic business. They're not way bad guys are not waking up and say, oh we're gonna target or we're gonna attack this company today. It's all opportunistic. They'll find an opportunity.

They follow the breadcrumbs and it could be an aftermath or artifacts that could be fallout, etc. I'll give you one example. They can go after realtor or after after sellers, send the patient email and compromise the sellers or realtors email credentials who don't have a MFA. They get into their system, pretend to be them. Now they have exposure and access to a larger transaction or to entire transaction and a larger audience.

Now they know you and now they know a broker. Now they know lender. So they just in the five minutes by circumventing or stealing the credentials of someone else, they just learn about you. Guess what? Now you're a target.

Now they're gonna send you a phishing email. But they didn't wake up and say I'm gonna send the phishing email to this title agent. You just came as a collateral. So remember that. So you need the IT, you need the IR firm.

So you need the IR firm for incidence response who can help you with the backup system recovery, who can help you to determine what happens, when it happens, etc. Because unless you know exactly what happens, in our industry we tell in security, we tell to find the patient zero. Until you find the patient zero, you can never unwind what happens to you. If you don't know how this happens to you, you'll always be at the risk that will happen to you again because you don't know how to roll it back, how to fix it. And then so your IR firm need to be part of this and then legal and regulatory counsel, whether it's if you are a larger agent and have your own, otherwise the one on the retainer or on the panel from your insurance company, you need to understand what your legal obligation and regulatory.

This were not in any particular order, but like I said, it will depends on the size and the type of incident. The key point to understand here is your regulatory compliance or regulatory disclosure. A lot of regulations have a very short window to disclose the incident. So as a preparation for incidence response, I highly recommend to look at the state where you're operating and understand all the regulatory requirements in your state. And most importantly, understand what your obligation to regulator for disclosure of securities, because that penalty could be very.

Most if not all telecompanies, we feel like we have our act together. We do all these precautions to keep our data safe. And how do we mitigate against like the weakest link, which is realtors and the transaction? Lenders have their act together. We have our act together pretty much.

Then realtors still using hotmail, AOL account. And we have an incident happened to us, but almost a couple of years ago with somebody impersonating a realtor. Actually, they hacked the agent's, the realtor's email and sent us like a wrong payoff. And we sent money to the wrong account. And luckily, we recovered most of it.

But I was just, everything was authentic. The right email, I think was correct. How do we mitigate against this like the weakest link, which is like the real estate agents? Correct. It's vigilance.

You just pay attention. So I can tell you because I've been in this situation many times, we know this. us almost a couple of years ago with somebody impersonating a realtor, actually they hacked the agent's, the realtor's email and sent us like a wrong payoff and we sent money to the wrong account and luckily we recovered most of it but I was just, everything was authentic. The right email I think was correct. How do we mitigate against this, like the weakest link which is like the real estate agents?

Correct. It's vigilance. You just pay attention. So I can tell you because I've been in this situation many times. We know this by heart.

Most of us, most of the escrow officers, title examiners, et cetera, most of the folks in our agencies can do it with their eyes closed. They can do it by heart because they've been doing it for many years. That's actually our Achilles heel. So this is what's killing us because we're flying an autopilot. We know it's, because remember I said these guys know the 24 to 48 hours window is crucial.

We're now moving and collating all of these documents and we need to make sure everything is meeting all of the requirements and we're ready to close. It knows it. This is when they attack in the most vulnerable times. But you will find the breadcrumbs everywhere. And I can tell you generative AI is now, has, so there's a lot of speculations and generative AI, one of the kind of downside of generative AI in our industry, it removes this poor language and punctuations and all of these emails that were typical for phishing emails and isn't recognizable and makes these attacks almost perfect.

But to be completely honest with you, if you're still relying on this to be an attributes and parameters, you're behind eight. This is why I said there are some security technology who takes it to the next level and actually look at all of the metadata behind the email. But to answer your question, you will, so if you slow down, we tend to have too many interactions, we have too many emails floating, et cetera. We always assume the email we reply to is the latest and greatest and correct. But in most of these attacks, if you scroll through the entire chain of the emails, you will find a flaw.

You will find where that guy, so granted or to be fair, if the realtor using Gmail don't have an MFA and using password one, two, three, there's nothing you can do. So if the bad guy impersonated the realtor and now portraying to be a realtor, this is one attack we have absolutely no defense. But in many cases, I would say over 90% of the cases is they will create the emails at the free domains like Hotmail and Yahoo and Gmail, et cetera, and they will portray to be someone else and they will change the user display name, there will be some attributes within that chain that will give a red flags. But unfortunately, that's the only way to combat this is to just to be careful, go with your guts. If it's suspicious, if it looks to be suspicious, et cetera, it probably is, there is no silver bullet.

I'm sorry, Mark. And we have no influence. We see this a lot where agents will notify us saying, I received this email from somebody portrayed to be from Stuart and I look at the email, it didn't even come from Stuart. Remember, if it didn't come from Stuart, it's not in my ecosystem, it never came through my mail system. So all of my emails defense is pointless because it never came from my system, came directly to you, for example, as an agent from the bad guy who created an account as our escrow officer slapped all of our logos and all of our signature, fabricated that email and came to the Gmail servers.

The answer is until all of this free email providers will start cooperating and work together in a holistic ecosystem, sharing this threat intelligence and sharing this metadata, not going to be able to reach you. I would think if there is a way to, in the title transaction, to completely eliminate email and then just communicate through inside the title production software, I'm not going to name names, but a lot of them have that communication inside, it's encrypted and secure. We try to force people to just communicate through the platform, but sometimes people resist or don't want to use that as a communication piece. But it's just, isn't that a part of the future that you would think? You said the key word.

So the key word is frictionless experience. Whatever creates the friction, remember, our consumers are realtors and the consumers, buyers and sellers. That's the one who generate the revenue for us. This is who brings the money. This is who brings the consumer or brings the money.

So anytime you create the friction for either of these categories, this is where your business goes south. You're an agent, so if you force the builder, I'm not a builder, the realtor or a builder for that matter, you're working with to use it, I don't know, let's say secure, very secure Dropbox or Box or encrypted email, and they don't want to, they'll just take their business away from you. So you're absolutely right. I think it's the future, but it has to be attractive. And I think that what will have to change and shift, and I said this earlier, I think the new generation is more savvy.

There is a gen Z now that they were native born, they're mobile phone born, they know nothing about anything else. So they will be more attuned if you need to download the application or receive the text notification or do something on their mobile. I think that's our future. As our consumer base and the realtors are aging, the new generation coming in, that's my only hope for shifting this in our lap because today we're dependent on that. What are some emerging cybersecurity trends should startup companies be aware of?

How can they prepare for future challenges? I think the general generative way of juries is out and is still out. So I can see a positive side. We start seeing the positive side. It's great today.

The co-pilots are great today in the summarizations meeting. You don't no longer have to attend the meeting or record the meeting, send in their summary. It's a lot of savor in the time. I can see the generative AI improving our workflow and productivity in our business because remember, it's all about data mining, connecting the data, filling out the form. I see a lot of opportunity where generative AI can make our life easier, but it's also our ecosystem is growing.

So our applications become more modern. We're connecting. We'll want to do more with this applications. We'll want to share data more. And I think this is where we start losing track of our data and that's dangerous.

And how do you, since we're talking about AI, I forgot a term and the voice impersonation and the video impersonation, it's getting so scary. Like we implemented like the, it's in our leadership team, like there's the password, like a key phrase. So if somebody impersonates me, like just to pay for it, if we don't know the phrase that it's not me kind of thing. Can you talk a little more about that and how can we prepare ourselves against the voice? Yeah.

Voice cloning. I've done some presentations and won't close. And I actually subscribed. You'll laugh at this. I've subscribed to, I'm not going to mention the vendor, to a voice cloning tool.

It costs $5 a month, $5 a month. And so voice cloning has become, remember when you couple voice cloning with ability to orchestrate or fabricate a caller ID, and then look at the next level, a deep fake where now it's not deep fake, but it's a visual and everything else. I don't know what the future is. My gut feeling is we're going to get to the old world where we have to, for critical transactions where we'll use the phone communications or walk into each other's office and say, did you send this? Or do you want it?

That's cool. There is some technology. I see some emerging technology that looks, that start looking at the parameters behind a video or documents, et cetera, and can detect the signature of this being generated with AI. But I can tell you looking from a cyber world, like we're all constantly fighting with the bad guys. As soon as we address something, some vulnerability, or as soon as we find a way to mediate some risk, they'll find something else, and we're always behind the eight ball.

This will be a same game. We determine how to battle this or combat this, they'll find some other ways to do this. There is a lot of talks about now, not just in our industry, but up on the hills, about requiring the watermarking and requiring identification. That to me has a future because the small bits of information will be embedded into an image, into a document, and everything else that will indicate anything from it's being generated by generative AI, to copyright protections, et cetera. So that materialized, but again, this could be one of those blockchain, but yes, the three one I'm rightfully sure to get out of my mouth is generative AI, voice cloning, and deep bank.

That's an emerging. So it's got to be an ongoing dance as you create the defensive mechanism, then the bad actors evolve and innovate, and then it's literally back and forth, it's almost a tennis match. You're absolutely right. And as a matter of fact, I do recommend, you rightfully said this, I do recommend to develop the keywords or a phrase that are used in the different transactions, but my gut's feeling they'll circumvent it as well. We're going to get this to red key or blue key, or remember the two key to control nuclear arsenal.

You create the defensive mechanism, then the bad actors evolve and innovate, and then it's literally back and forth, and it's almost a tennis match. You're absolutely right. And as a matter of fact, I do recommend, you rightfully said this, I do recommend to develop the keywords or a phrase that are used in the different transactions, but my gut's feeling they'll circumvent it as well. We're gonna get this to red key or blue key, remember, the two key to control a nuclear arsenal. Where you'll have to have two people with two different knowledge, different bits and pieces of knowledge to be able to complete something, put together and complete.

Time will show, I don't have crystal. For title agents and companies that may not have extensive IT resources, what would be your top advice to enhance their cybersecurity posture? If you've never done any of this before, my first recommendation is hire the professional. Find somebody who can come in and do a gap analysis for you or gap assessment and tell you where you're at. Maybe you're good.

Maybe you just need 10%. Maybe you're at 10% and you need 90%. And then my second advice is get an IT retainer or IT help. Like I said earlier, this is very technical. This world becomes very technical and you can, a lot of small agents just can't afford or don't have a full-time IT.

Gotta be able to call someone. Fractional. And it doesn't have to be full-time, it can be fractional like that. Correct, yes. This is fractional, yeah.

That's what the retainer is. You get the fractional. There are multiple ways to do this, but you need to add someone on a retainer. Because the minute something happens to you, that's a bad time to start opening raw data or yellow pages and code. Do you think, you know how New York requires a data audit?

They're very tough on cybersecurity and data. Do you think all states should probably adopt that required audit, like a data audit? That's probably where the industry is going because we've seen the New York DFS quite 100 rule came first. And since then, I think it's 2017 when they first introduced it. I think since then, a lot of other states are adopting.

And unfortunately, a lot of states take kind of their own stance and they try to develop their own standards. I wish they would all come and agree to the standard framework that every state can adopt. But yes, it's very plausible that states will have the audit rights or will have a clause similar to New York DFS in their requirements, cyber require. So how do you stay up to date with the latest developments and what resources do you recommend to other professionals in the tower industry? And besides the publications you mentioned earlier?

Yeah, guess what? ChatGPT and Generative AI makes it easier. So Bing now has a co-pilot. Google has a co-pilot. All of the major browsers have a co-pilot.

My personal favorite one is Perplexity. It's Perplexity.ai. It's one of the major ChatGPT. And I like Perplexity because it's more natural. So it was developed, not the question and answer.

It was developed as a researcher tool. So the biggest benefit I think of using Perplexity is for every person you can have a conversation with it, it gives you a clues or cues of what potentially additional questions you might want to ask or will be interesting to know easily. But most importantly, because it started as a research tool, it has a citation everywhere. So every answer is supported by a link on the website. So you can just summarize if that's all you need is just to get the grasp or question answer, that's good.

But if you want to dive deeper or see where it came from, it actually has the links to the source, which many of the copilots don't do it very effective. But again, depends on your technical level skills. There are a number of subscriptions that you can sign up or they'll give you this information. But I don't have a general recommendation because your technical level and interests could be different. We're getting close here to the end of the episode.

I have a couple of final questions to ask every guest. Do you have a favorite quote? Favorite quote, my favorite security quote, I can't protect what I don't see or do. That's awesome, that's perfect. And how about a favorite book that you read recently or your all time favorite book?

So I don't have one favorite book. So I've read some books on the leadership. So this is common question that I get asked and let me tell you my perspective. So you have to be generalist. So while I have interest in cybersecurity and I read a lot of cybersecurity books, this range from anything to different threats, different and some of the books are very technical.

Also in our industry, so you need to be a general. So I read leadership, I read leadership books, I read books in history, I read books on government, et cetera. I can't say I have a favorite. Any final words for our audience? Listen, this is a hard word.

Like I said, this is no longer- It's a war, wow, that's a strong word, yeah. It's a technical world and you can't brush it off anymore. I tell folks, it's not a matter of if, it's a matter of when. Thank you so much. Thank you for joining us on this episode of the Tyler Agents podcast.

I hope you found our conversation with Gennady as informative as I did. Cybersecurity is vital for safeguarding your title business and the insights shared today can help you strengthen your defense. Don't forget to subscribe for more expert interviews and practical tips. Stay tuned for our next episode where we continue to explore the strategies that keep title professionals at the top of their game. Until next time, stay secure and keep innovating.

Thank you, Gennady. Thank you. And that's a wrap on today's journey with Mo Shamil from the Title Agents podcast, reminding you that mastering the art of innovation is key in the title industry's fast-paced world. If you're finding it tough to keep up with the changes and challenges, remember, you're not alone. Our calendar is open for you.

Find the link in the show notes and let's connect. Make sure to hit subscribe to not miss out on strategies that elevate and insights that empower. Together, we'll navigate the future of the industry. I look forward to our next meeting in the upcoming episode. Keep pushing, keep innovating, and see you in the next episode.

Top Producer?

Build your book at Alltech — DC's #1 title company.

Join Alltech →

Agency Owner?

Sell some chips off the table. Keep your future.

Partner With Us →