Latest
It’s Not X, It’s Y: The AI Tell Shakespeare Wrote FirstWho Gets Rich From AI Data Centers? The Local, National and Global EconomyAre AI Data Centers Bad for the Environment? What’s True and What Isn’tAI Data Centers and Geopolitics: Chips, China, Spies and PowerAI Derangement Syndrome: Who Cares If the Cover Was Made With AI?How to Write a Plot Twist Readers Never See ComingBook Ads Getting Clicks but No Sales? The Problem Is the PageCan Writing a Memoir Make You Sick? The Toll Nobody Warns You AboutWhen Caregiving Ends and the Words Won’t ComeCan You Publish a Clean and a Spicy Version of the Same Book?Do You Need a Writing Buddy? What Works and What Doesn’tCan You Put Someone Who Wronged You in Your Novel?Kindle Unlimited or Wide? Where to Publish Your Debut NovelWriting Vampires: How to Build Your Own Vampire RulesWhat Software Do Novelists Use to Write a Book?What If Your Family Doesn’t Support Your Writing?ARC Reviews: Real Follow-Through Numbers, and Do Reviews Sell Books?The AI Singularity: Would a Conscious AI Even Care About Us?“Forbidden” AI Prompts: Why Viral Prompt Lists Are Mostly JunkAuthor Scam Emails: Fake Agents, Flattery and the $500 PitchWill AI Steal My Book? Turn Off Training Before You UploadThe Fear of Being Judged for Your Memoir: My Father Told Everyone to Burn MineShould You Only Use “Said” in Dialogue Tags? My Rules for Tags and AdverbsWhy a Good Book Isn’t Enough: Agents, Quiet Novels and What SellsShe Asked How to Format Her Comic for KDP. The Thread Went to War Over AI.Why Are Writing Groups So Hostile?My Ghostwriter Stopped Responding. What Do I Do?My Ghostwriter Missed the Deadline. What Are My Options?I Hate My Ghostwriter’s First Draft. Now What?Can I Get a Refund From a Ghostwriter?How Many Revisions Should a Ghostwriter Include?Can My Ghostwriter List My Book in Their Portfolio?My Family Doesn’t Want Me to Publish My Ghostwritten Memoir. Now What?Should a Ghostwriter Write a Free Sample Chapter?How Much Does a Ghostwriter Take Up Front?Can a Ghostwriter Get Me a Book Deal or a Literary Agent?Can I Work With a Ghostwriter Over Zoom or From Another Country?Ghostwriting a Tribute Book, Eulogy or Obituary for Someone You LostCan a Ghostwriter Write My Book in Spanish?Ghostwriting a Book for a Dental or Chiropractic PracticeWhy Keynote Speakers Need a Ghostwritten BookGhostwriting a Science or Research Book for General ReadersGhostwriting a Book for Teachers and EducatorsHiring a Ghostwriter for a Pilot’s or Aviation MemoirHiring a Ghostwriter for a Musician’s MemoirCan a Ghostwriter Help Me Write a Whistleblower Memoir?Hiring a Ghostwriter for an Immigrant’s StoryCan a Ghostwriter Help Me Write About Losing Someone to Suicide?Can a Ghostwriter Help Me Write a Depression or Mental Illness Memoir?Hiring a Ghostwriter for a Special-Needs Parent’s Memoir

Behind the Book: Family Cybersecurity

TL;DR: A woman I barely knew called me at 2:47 in the morning because ransomware had taken thirty years of family photographs. I drove over and knew within seconds there was nothing I could do, and I worked until dawn anyway. The book that came out of it took two attempts. The first had a clever title, was edited twice, beta read by two security professionals, and sold about twelve copies. The second is a complete rewrite aimed at families instead of at computer users, and the hardest part was keeping it out of my own language.

She was somebody I’d met once at an event. I couldn’t tell you which event or when, and I don’t remember much about the evening. Somewhere in it she must have learned what I did for a living, because months later, at 2:47 in the morning, she called me.

She had no idea what had happened. She only knew her computer was unusable and that her things were gone, and she was in complete and utter panic. No vocabulary for any of it. Just please help. I drove over with every recovery tool I owned.

How did Richard Lowe realize the ransomware attack was hopeless?

It was obvious from the moment I sat down. The ransom note was on the screen. This was early enough that the tools which exist now didn’t exist, and I knew within a few seconds that there was nothing I was going to be able to do. I worked until dawn anyway. Partly because I’m not one to give up, and partly because those photographs mattered to her. Wedding pictures. A baby’s first steps. Her mother’s last Christmas before the cancer. If there had been a millionth of a chance, I was going to give it the old college try.

There wasn’t. When the light came up I told her they were gone and that there was nothing she could do. I advised her not to pay the ransom. I learned later that she paid anyway. Five hundred dollars. She didn’t get the photographs back, and she called me again in a panic to ask what to do, and by then there was nothing left to try.

What’s the second half of a ransomware attack?

Everybody understands the loss. Your files are locked and you can’t get to them. That’s the version in the news and it’s the smaller half of the problem. The other half is that somebody was inside the machine. Whoever put the malware there had a look around first. Anything of value can be sold to other people. Anything with blackmail potential gets used for exactly that. Anything scandalous gets posted. The real downside of ransomware is that they have your things, and they can do whatever they want with them, and you’ll never find out which of those they chose.

That uncertainty is what I hate most about ransomware. A burglar takes the television and at least you know it’s gone. With ransomware you can spend years wondering where your family’s pictures ended up and who’s looking at them.

What obvious risk had Richard Lowe missed at home?

I’d spent decades protecting corporate networks and million-dollar systems, and I’d aimed my entire career at the wrong population. People don’t worry about bank security, and they aren’t entirely wrong not to. It’s FDIC insured. If a bank loses a million dollars, the general reaction is that this is somebody else’s problem, and in a narrow sense that’s true. Corporate security is a corporate issue.

Households are where the losses land on a person.

They lose files because they have no adequate backup. Exactly what happened that night.

If she had been keeping copies, I could have ignored the ransomware entirely and rebuilt the machine from scratch, and the incident would have been an irritating Tuesday. In those days almost nobody had backups, because backing up was a nuisance and the good tools hadn’t arrived yet. I strongly suspected before I drove over that there would be nothing to restore from. It would have been enough if she had been copying the important files to a floppy disk now and then. She wasn’t doing anything wrong. She simply didn’t know, and nobody had told her.

They lose bandwidth to a neighbor helping himself, and in the metered days that cost real money. They lose data to somebody who got onto an unsecured network and went looking.

And the theft is the part that horrifies people, more than the loss.

They keep their lives on these machines. Now they keep them on their phones, and almost nobody treats a phone as a computer. Every photograph. Banking. Everything precious, carried in a pocket, and plenty of people won’t even put a PIN on it. They leave a tablet on the table while they go and collect their food. A minute is enough, and with no security on the front of the device it’s wide open.

What do you do in the first hour of a ransomware attack?

Get off the internet. That’s the first thing, before anything else, and most people do the opposite because their instinct is to start looking things up on the infected machine.

I understand the instinct. You’re scared, and the machine in front of you is the only place you know how to look for help. Every minute it stays connected is another minute the attacker keeps working, so cut the connection first and do your research on a different device.

Simplest version: turn off your router. The reason is that plenty of malware isn’t finished when it arrives. It pulls down more of itself from the internet, so a nuisance can become a catastrophe while you sit there deciding what to do. Worse, an attacker can take control of the system directly. Cutting the connection stops both. Second, run a virus scanner.

Bitdefender is a good first line of defense. Hitman Pro makes an excellent secondary scanner, and it’s the one that will give you the clearest picture of the damage.

Plenty of people run Microsoft Defender, the one that comes with Windows, and it’s fine. It works reasonably well and it’s better than nothing by an enormous margin.

Whichever you use, the scan is diagnosis before it’s treatment. You could find a hundred separate infections and learn that the machine is hopeless. You could find something minor. You could find nothing at all. Until you know what you have, there’s very little you can sensibly do, and the guessing turns a bad morning into a bad month.

Hitman Pro will clean up most of it and sometimes all of it. Bitdefender will clean up a great deal. Defender will clean up a fair amount.

And there’s one more piece of information hiding in that step: a scan that won’t run at all. A large amount of malware disables the antivirus as its first act, because a program that can see it’s a program that can remove it. A scanner that won’t start has told you the answer, and that’s where you stop and call somebody who does this for a living.

How do you secure a family phone?

Treat the phone as seriously as the computer, because it’s one, and almost nobody does.

Everything precious is on it. Photographs. Banking. Messages. Accounts that reset every other password you own. And plenty of people won’t put a PIN on the thing, or will leave a tablet on a restaurant table while they go and collect their food. A minute is enough. With nothing on the front of the device it’s simply open. The list is short and unglamorous. Run a scanner. Take the updates and install them instead of dismissing the notification for the fourth time. Lock the screen. And back it up.

Backup is the one that matters most, for the same reason it mattered at that kitchen table at 2:47 in the morning.

Mine goes to Google’s cloud, the path of least resistance on Android, and Apple has its own version that works the same way. The platform hardly matters. What matters is that it’s running, and that you’ve verified it at some point, because a backup nobody has verified is a belief instead of a backup.

What was Family Cybersecurity called in its first edition?

I wrote it. It was called Safe Computing Is Like Safe Sex, and at the time I thought that title was extremely clever. The title was stupid. It welds together two things that have nothing to do with each other, and people couldn’t work out what the book was about from looking at it.

Everything else about that book was done properly. It was the first real book I published, and I put everything I had into it. I hired an artist for the illustrations. I had it edited twice. I read through it over and over. I had it beta read by Steve Levenson, a security expert who ran PCI audits for me at Trader Joe’s, and by Jimmy James, who was our network man there. It was complete and it was correct.

It sold about twelve or fifteen copies.

Two reasons. The first is that nobody cares about home security. That’s the problem the book exists to address and is also why it’s difficult to sell a book about it. The second is that I had no idea how to promote anything. I ran straight into what I call the wall of marketing. That’s a subject I had to learn the hard way and eventually wrote its own book about.

What changed in the Family Cybersecurity rewrite?

About a year ago I decided to redo all of my books, bringing them up to modern publishing standards and my own current standards. Larger, more complete, better made. Every book I’ve written is now redone and republished, and this was one of them.

Family Cybersecurity is a complete rewrite instead of a new cover on old material.

The aim narrowed. The original was about cybersecurity in general, written for anybody with a computer. This one is written for families: the home computers, the phones, the laptops, the tablets, whatever computing lives in the house and whoever lives there with it. That includes the parts of the problem that aren’t technical at all. Talking to children about it without frightening them. Teenagers and where the privacy line sits. Helping parents who didn’t grow up with any of this and are the ones being targeted deliberately.

The parents are the part that makes me angriest. Scammers go after older people on purpose because they’re trusting and polite on the phone, and the industry has done almost nothing to explain the threat to them in words they can use. The people who know better have left them to learn it from the scammers.

What was hardest to get right in Family Cybersecurity?

Keeping it out of my own language.

This book had every opportunity to become deeply technical, because I’m capable of writing it that way and it’s more comfortable for me. That would have made it useless. The people who need it aren’t technical, and a book they can’t read protects nobody.

So I kept the technical language down, wrote in plain English, and held the reading level to somewhere around high school. That lesson applies well outside security. Understand your audience and write to that audience. Write past them and you lose them, and it doesn’t matter how correct you were.

Cybersecurity has been near the center of my working life for a long time. I was doing security work on VAX/VMS at the start of my career, and PCI compliance at Trader Joe’s toward the end of it. I still keep a toe in the field, because it matters and because I enjoy it. I also run what I recommend: layers of backup, layers of protection, audited and monitored, checked regularly instead of assumed.

The argument comes down to one line. The people getting hurt are the ones at a kitchen table at 2:47 in the morning with no idea what just happened to them, and nobody has ever written for them.

Frequently Asked Questions

Does a home cybersecurity book have to be technical?
No, and keeping it non-technical was the hardest part of writing it. The reading level sits around high school and the language is plain English. The audience is people who own devices without any professional background in protecting them, and a book they can’t read would protect nobody.
Can a bad title kill a good book?
Mine did. My first published book was called Safe Computing Is Like Safe Sex, professionally edited twice, illustrated and beta read by two security professionals, and it sold roughly twelve copies. The title welded together two unrelated ideas, so nobody could tell what the book was about. I also had no idea how to market it. The rewrite exists because the material deserved a second chance under a name that says what it is.
Why does ransomware do more damage than losing your files?
Because somebody was inside the machine before the files got locked. Whatever has resale value can be sold. Whatever has blackmail potential gets used that way. Whatever is scandalous can be posted. Paying the ransom doesn’t undo any of that, and most victims never learn which parts were taken.
Would a backup have saved her photographs?
Completely. With copies of the important files anywhere else, the ransomware would have been an irritation instead of a catastrophe. The machine gets rebuilt and the photographs come back. She had no backups. Normal at the time, because backing up was a nuisance and the modern tools didn’t exist yet.
Why write about home security instead of corporate security?
Because in a family, the losses land on an actual person. Corporate breaches are insured and absorbed. A family that loses thirty years of photographs, or has its data sold on, has no department and no budget and nobody whose job includes any of this. The attacks that destroy people don’t target banks.
Does the book cover phones and tablets?
Yes, and they get particular attention, because almost nobody treats a phone as a computer. Photographs, banking, messages and accounts all live there, and plenty of people won’t even set a PIN, or will leave a tablet on a restaurant table while they collect their food. A minute is enough.
What’s the first thing to do if you think you’ve been infected?
Disconnect from the internet, and the simplest way is to turn off the router. A lot of malware isn’t finished when it arrives and downloads more of itself, and an attacker can take direct control of a connected machine. After that, run a virus scanner, because until you know the damage there’s very little you can sensibly do.
What does it mean if your antivirus won’t run?
It means you have your answer. A great deal of malware disables the antivirus as its first act, because a program that can see it’s a program that can remove it. A scanner that won’t start has told you the answer, and it’s the point to call somebody who does this professionally.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment