| Member Resources |
On Wednesday, August 16, SAMCAR Brokers and Managers were invited to expand their understanding of cyber security with John Wondolowski, Chief Technology Officer from CMI (Chouinard & Myhre, Inc.), who explained best practices and provided a list of "to-do's" for brokers and agents to follow to protect their personal and professional data as a lead-up to REALTOR® Safety Month in September. The Broker/Manager Meeting was planned by SAMCAR's Professional Development Committee. Special thanks to committee Chair Joanne Wondolowski and Vice Chair Bobbi Decker, as well as Board of Directors Liaison Eric W. Berggren for planning and organizing this interesting meeting.
In his presentation, Wondolowski offered numerous statistics to emphasize that every business faces cyber security challenges, no matter the size or the industry. Small businesses, he noted, are just as vulnerable, with 72% of cyber attacks affecting companies with less than 100 employees. It is especially prudent for small business to guard against cyber vulnerabilities since the average amount of money it takes for a small business to recover from a cyber attack is $188,242, and many small businesses (up to 60%) close within six months of a cyber attack.
These statistics are indeed overwhelming, usually leaving the audience stunned and wanting to just "hide under the bed," Wondolowski acknowledged; but there are simple steps that businesses and employees can take to prepare to face these challenges and avoid catastrophe. The overarching message that John had for brokers and office managers was to create a culture of cybersecurity in their offices as well as at home.
In every real estate brokerage, agents are dealing with sensitive documentation and transaction information, which must be kept secure. Wondolowski suggests considering, in advance, how you would recover from a severe cyber security attack and preparing accordingly. The first step he mentions is to identify what you want to protect, the "crown jewels," as he calls them. This priority data can include your personal data and that of your clients like financial records and essentially any other information that would have value on a black market exchange. Once you know what you're trying to secure, you can better identify what tools to use and what practices to implement. The same goes at home as in the office. John offered the following "to do" list for steps you can take this month to implement a culture of cyber security in your office and at home.
Backup Your Data Consistently
Know What it Takes to Restore The Data
Secure Your Wi-Fi
Understand Dangers of Public Wi-Fi
Use a Passwords Manager
Protect Mobile Devices
Regularly Update Security Patches on Computers and Servers
Get an Office Cyber Health Check
Wondolowski is a proponent of using cloud backup for your files, which can be easier to recover and, in many cases, more secure than portable hard drives, providing that the cloud backup service you choose complies with industry standards and certifications (see below). Additionally, he mentioned cyber insurance as an extra precaution to help you recover from down time subsequent to a cyber attack and mitigate your liability with holding clients' personal data.
The biggest take-aways from John's presentation were to exercise caution on all your devices, and be prepared by backing up your data and implementing security procedures—and don't wait, do it now.

Presentation slides shared with permission.
The answer obviously differs by company depending on the specific regulatory concerns that the company is subject to. But here are some basic certifications / standards that nearly all cloud providers should be able to obtain:
According to the AICPA, a SOC 1 is a report on the controls at a service organization relevant to the user's internal controls for financial reporting. A SOC 2 is the same kind of report, but focusing on security and privacy controls. A SOC 3 is much the same as a SOC 2, but intended for a different audience. Pretty much any cloud provider will have one, two or all of these reports on their cloud infrastructure, and will make them available to their customers or prospective clients for the asking.
ISO 27001 is a set of internationally recognized security model designed to secure information assets. It is generally used as a framework for creating an information security management system (ISMS). The ISO 27001 standard is difficult to achieve for a small to medium size business, mainly due to the complexity and strength of the various security controls necessary to comply with the model. But seeing this certification with a cloud provider generally means that their environment has achieved a level of security maturity within their organization.
The Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) is a program developed by the CSA for security assurance in a cloud environment. It consists of a cloud controls matrix and a Consensus Assessments Initiative Questionnaire (CAIQ) that companies can use to evaluate a cloud provider's overall security practices.
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards created by the major credit card companies and financial entities to ensure that companies that accept, process, store or transmit credit card information maintain a secure environment. Most companies are familiar with the PCI in one form or another, as it is the standards that must be adhered to in order to process credit card transactions. Most cloud providers have achieved or can help their customers achieve PCI certification.
This is just a few of the many certifications that are available, and that companies can use to determine the maturity of the security programs of a cloud provider. HITRUST is used by the healthcare industry, ITAR certifications in the manufacturing industry and FCRA / CFPB in the financial services vertical are all important to consider as well. A company should ask to see the cloud provider's certification and security program, as well as any controls that they can share to help the company with their own compliance concerns, before making a decision on a cloud provider.