Latest
Why Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreBlack Tuesday: The Web Ring War Nobody Outside It NoticedThe Web Got Fenced: What AI Search Costs Small SitesWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Publish Your BookBehind the Book: Real World SurvivalBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBayBehind the Book: Show Don’t TellBehind the Book: Street-Smart Management WisdomBehind the Book: Stuck in the MiddleBehind the Book: The ADHD MarketerBehind the Book: Suddenly UnemployedBehind the Book: The Blonde With a Violin TattooBehind the Book: The Blog-to-Book BlueprintBehind the Book: The Day Your Website DiedBehind the Book: The Death of ThinkingBehind the Book: The Emasculation of AmericaBehind the Book: The Ethical WorkplaceBehind the Book: The Ghostwriting AdvantageBehind the Book: The Gig EconomyBehind the Book: The Villainization of America

Behind the Book: Family Cybersecurity

This entry is part 18 of 73 in the series Behind the Book
TL;DR: A woman I barely knew called me at 2:47 in the morning because ransomware had taken thirty years of family photographs. I drove over and knew within seconds there was nothing I could do, and I worked until dawn anyway. The book that came out of it took two attempts. The first had a clever title, was edited twice, beta read by two security professionals, and sold about twelve copies. The second is a complete rewrite aimed at families instead of at computer users, and the hardest part was keeping it out of my own language.

She was somebody I had met once at an event. I could not tell you which event or when, and I do not remember much about the evening. Somewhere in it she must have learned what I did for a living, because months later, at 2:47 in the morning, she called me.

She had no idea what had happened. She only knew her computer was unusable and that her things were gone, and she was in complete and utter panic. No vocabulary for any of it. Just please help.

I drove over with every recovery tool I owned.

Why keep working on something you know is hopeless?

It was obvious from the moment I sat down. The ransom note was on the screen. This was early enough that the tools which exist now did not exist, and I knew within a few seconds that there was nothing I was going to be able to do.

I worked until dawn anyway.

Partly because I am not one to give up, and partly because those photographs mattered to her. Wedding pictures. A baby’s first steps. Her mother’s last Christmas before the cancer. If there had been a millionth of a chance, I was going to give it the old college try.

There was not. When the light came up I told her they were gone and that there was nothing she could do. I advised her not to pay the ransom.

I learned later that she paid anyway. Five hundred dollars. She did not get the photographs back, and she called me again in a panic to ask what to do, and by then there was truly nothing left to try.

What is the second half of a ransomware attack?

Everybody understands the loss. Your files are locked and you cannot get to them. That is the version in the news and it is the smaller half of the problem.

The other half is that somebody was inside the machine. Whoever put the malware there had a look around first. Anything of value can be sold to other people. Anything with blackmail potential gets used for exactly that. Anything scandalous gets posted.

The real downside of ransomware is that they have your things, and they can do whatever they want with them, and you will never find out which of those they chose.

What was the obvious thing I had missed?

I had spent decades protecting corporate networks and million-dollar systems, and I had aimed my entire career at the wrong population.

People do not worry about bank security, and they are not entirely wrong not to. It is FDIC insured. If a bank loses a million dollars, the general reaction is that this is somebody else’s problem, and in a narrow sense that is true. Corporate security is a corporate issue.

Households are where the losses land on a person.

They lose files because they have no adequate backup. Exactly what happened that night. If she had been keeping copies, I could have ignored the ransomware entirely and rebuilt the machine from scratch, and the whole thing would have been an irritating Tuesday. In those days almost nobody had backups, because backing up was a genuine nuisance and the good tools had not arrived yet. I strongly suspected before I drove over that there would be nothing to restore from. It would have been enough if she had been copying the important files to a floppy disk now and then. She was not doing anything wrong. She simply did not know, and nobody had told her.

They lose bandwidth to a neighbor helping himself, and in the metered days that cost real money. They lose data to somebody who got onto an unsecured network and went looking.

And the theft is the part that horrifies people, more than the loss. They keep their lives on these machines. Now they keep them on their phones, and almost nobody treats a phone as a computer. Every photograph. Banking. Everything precious, carried in a pocket, and plenty of people will not even put a PIN on it. They leave a tablet on the table while they go and collect their food. A minute is enough, and with no security on the front of the device it is wide open.

What do you do in the first hour?

Get off the internet. That is the first thing, before anything else, and most people do the opposite because their instinct is to start looking things up on the infected machine.

Simplest version: turn off your router.

The reason is that plenty of malware is not finished when it arrives. It pulls down more of itself from the internet, so a nuisance can become a catastrophe while you sit there deciding what to do. Worse, an attacker can take control of the system directly. Cutting the connection stops both.

Second, run a virus scanner.

Bitdefender is a good first line of defense. Hitman Pro makes an excellent secondary scanner, and it is the one that will give you the clearest picture of the damage. Plenty of people run Microsoft Defender, the one that comes with Windows, and it is fine. It works reasonably well and it is better than nothing by an enormous margin.

Whichever you use, the scan is diagnosis before it is treatment. You could find a hundred separate infections and learn that the machine is hopeless. You could find something minor. You could find nothing at all. Until you know what you have, there is very little you can sensibly do, and the guessing is what turns a bad morning into a bad month.

Hitman Pro will clean up most of it and sometimes all of it. Bitdefender will clean up a great deal. Defender will clean up a fair amount.

And there is one more piece of information hiding in that step: a scan that will not run at all. A large amount of malware disables the antivirus as its first act, because a program that can see it is a program that can remove it. A scanner that will not start has told you the answer, and that is the point where you stop and call somebody who does this for a living.

How do you secure a family phone?

Treat the phone as seriously as the computer, because it is one, and almost nobody does.

Everything precious is on it. Photographs. Banking. Messages. Accounts that reset every other password you own. And plenty of people will not put a PIN on the thing, or will leave a tablet on a restaurant table while they go and collect their food. A minute is enough. With nothing on the front of the device it is simply open.

The list is short and unglamorous. Run a scanner. Take the updates and install them instead of dismissing the notification for the fourth time. Lock the screen. And back it up.

Backup is the one that matters most, for the same reason it mattered at that kitchen table at 2:47 in the morning. Mine goes to Google’s cloud, the path of least resistance on Android, and Apple has its own version that works the same way. The platform hardly matters. What matters is that it is running, and that you have verified it at some point, because a backup nobody has verified is a belief instead of a backup.

Why did the first version of this book fail?

I wrote it. It was called Safe Computing Is Like Safe Sex, and at the time I thought that title was extremely clever.

It was a stupid title. It welds together two things that have nothing to do with each other, and people could not work out what the book was about from looking at it.

Everything else about that book was done properly. It was the first real book I published, and I put everything I had into it. I hired an artist for the illustrations. I had it edited twice. I read through it over and over. I had it beta read by Steve Levenson, a security expert who ran PCI audits for me at Trader Joe’s, and by Jimmy James, who was our network man there. It was complete and it was correct.

It sold about twelve or fifteen copies.

Two reasons. The first is that nobody cares about home security. That is the problem the book exists to address and is also why it is difficult to sell a book about it. The second is that I had no idea how to promote anything. I ran straight into what I call the wall of marketing, which is a subject I had to learn the hard way and eventually wrote its own book about.

What changed in the rewrite?

About a year ago I decided to redo all of my books, bringing them up to modern publishing standards and my own current standards. Larger, more complete, better made. Every book I have written is now redone and republished, and this was one of them.

Family Cybersecurity is a complete rewrite instead of a new cover on old material.

The aim narrowed. The original was about cybersecurity in general, written for anybody with a computer. This one is written for families specifically: the home computers, the phones, the laptops, the tablets, whatever computing lives in the house and whoever lives there with it.

That includes the parts of the problem that are not technical at all. Talking to children about it without frightening them. Teenagers and where the privacy line sits. Helping parents who did not grow up with any of this and are the ones being targeted deliberately.

What was the hardest part to get right?

Keeping it out of my own language.

This book had every opportunity to become deeply technical, because I am capable of writing it that way and it is more comfortable for me. That would have made it useless. The people who need it are not technical, and a book they cannot read protects nobody.

So I kept the technical language down, wrote in plain English, and held the reading level to somewhere around high school.

That lesson applies well outside security. Understand your audience and write to that audience. Write past them and you lose them, and it does not matter how correct you were.

Cybersecurity has been near the center of my working life for a long time. I was doing security work on VAX/VMS at the start of my career, and PCI compliance at Trader Joe’s toward the end of it. I still keep a toe in the field, because it matters and because I enjoy it. I also run what I recommend: layers of backup, layers of protection, audited and monitored, checked regularly instead of assumed.

The argument comes down to one line. The people getting hurt are not the ones with a security department. They are the ones at a kitchen table at 2:47 in the morning with no idea what just happened to them, and nobody has ever written for them.

The Guides That Get Your Book Written, Published, and Sold

Four short, practical guides on writing, publishing, and selling your book, plus the occasional note when there's something worth your time. No fluff, no daily inbox clutter. Drop your email and they're yours.

We use MailerLite to manage our list and send these emails. Your address is used only to send you what you signed up for. We will not sell it, share it, or use it for anything else, and you can unsubscribe anytime.

Frequently Asked Questions

Is Family Cybersecurity a technical book?
No, and keeping it non-technical was the hardest part of writing it. The reading level sits around high school and the language is plain English. The audience is people who own devices without any professional background in protecting them, and a book they cannot read would protect nobody.
What was the book called originally?
Safe Computing Is Like Safe Sex. It was my first published book, professionally edited twice, illustrated, and beta read by two security professionals. It sold roughly twelve copies, partly because the title welded together two unrelated ideas and nobody could tell what the book was about, and partly because I had no idea how to market anything.
Why does ransomware do more damage than losing your files?
Because somebody was inside the machine before the files got locked. Whatever has resale value can be sold. Whatever has blackmail potential gets used that way. Whatever is scandalous can be posted. Paying the ransom does not undo any of that, and most victims never learn which parts were taken.
Would a backup have saved her photographs?
Completely. With copies of the important files anywhere else, the ransomware would have been an irritation instead of a catastrophe. The machine gets rebuilt and the photographs come back. She had no backups. Normal at the time, because backing up was a genuine nuisance and the modern tools did not exist yet.
Why write about home security instead of corporate security?
Because that is where the losses land on an actual person. Corporate breaches are insured and absorbed. A family that loses thirty years of photographs, or has its data sold on, has no department and no budget and nobody whose job includes any of this. The attacks that destroy people do not target banks.
Does the book cover phones and tablets?
Yes, and they get particular attention, because almost nobody treats a phone as a computer. Photographs, banking, messages and accounts all live there, and plenty of people will not even set a PIN, or will leave a tablet on a restaurant table while they collect their food. A minute is enough.
What is the first thing to do if you think you have been infected?
Disconnect from the internet, and the simplest way is to turn off the router. A lot of malware is not finished when it arrives and downloads more of itself, and an attacker can take direct control of a connected machine. After that, run a virus scanner, because until you know the damage there is very little you can sensibly do.
What does it mean if your antivirus will not run?
It means you have your answer. A great deal of malware disables the antivirus as its first act, because a program that can see it is a program that can remove it. A scanner that will not start has told you the answer, and it is the point to call somebody who does this professionally.

📁︎ Behind the Book📁︎ Cybersecurity

🏷︎ Cybersecurity

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment