She was somebody I had met once at an event. I could not tell you which event or when, and I do not remember much about the evening. Somewhere in it she must have learned what I did for a living, because months later, at 2:47 in the morning, she called me.
She had no idea what had happened. She only knew her computer was unusable and that her things were gone, and she was in complete and utter panic. No vocabulary for any of it. Just please help.
I drove over with every recovery tool I owned.
Why keep working on something you know is hopeless?
It was obvious from the moment I sat down. The ransom note was on the screen. This was early enough that the tools which exist now did not exist, and I knew within a few seconds that there was nothing I was going to be able to do.
I worked until dawn anyway.
Partly because I am not one to give up, and partly because those photographs mattered to her. Wedding pictures. A baby’s first steps. Her mother’s last Christmas before the cancer. If there had been a millionth of a chance, I was going to give it the old college try.
There was not. When the light came up I told her they were gone and that there was nothing she could do. I advised her not to pay the ransom.
I learned later that she paid anyway. Five hundred dollars. She did not get the photographs back, and she called me again in a panic to ask what to do, and by then there was truly nothing left to try.
What is the second half of a ransomware attack?
Everybody understands the loss. Your files are locked and you cannot get to them. That is the version in the news and it is the smaller half of the problem.
The other half is that somebody was inside the machine. Whoever put the malware there had a look around first. Anything of value can be sold to other people. Anything with blackmail potential gets used for exactly that. Anything scandalous gets posted.
The real downside of ransomware is that they have your things, and they can do whatever they want with them, and you will never find out which of those they chose.
What was the obvious thing I had missed?
I had spent decades protecting corporate networks and million-dollar systems, and I had aimed my entire career at the wrong population.
People do not worry about bank security, and they are not entirely wrong not to. It is FDIC insured. If a bank loses a million dollars, the general reaction is that this is somebody else’s problem, and in a narrow sense that is true. Corporate security is a corporate issue.
Households are where the losses land on a person.
They lose files because they have no adequate backup. Exactly what happened that night. If she had been keeping copies, I could have ignored the ransomware entirely and rebuilt the machine from scratch, and the whole thing would have been an irritating Tuesday. In those days almost nobody had backups, because backing up was a genuine nuisance and the good tools had not arrived yet. I strongly suspected before I drove over that there would be nothing to restore from. It would have been enough if she had been copying the important files to a floppy disk now and then. She was not doing anything wrong. She simply did not know, and nobody had told her.
They lose bandwidth to a neighbor helping himself, and in the metered days that cost real money. They lose data to somebody who got onto an unsecured network and went looking.
And the theft is the part that horrifies people, more than the loss. They keep their lives on these machines. Now they keep them on their phones, and almost nobody treats a phone as a computer. Every photograph. Banking. Everything precious, carried in a pocket, and plenty of people will not even put a PIN on it. They leave a tablet on the table while they go and collect their food. A minute is enough, and with no security on the front of the device it is wide open.
What do you do in the first hour?
Get off the internet. That is the first thing, before anything else, and most people do the opposite because their instinct is to start looking things up on the infected machine.
Simplest version: turn off your router.
The reason is that plenty of malware is not finished when it arrives. It pulls down more of itself from the internet, so a nuisance can become a catastrophe while you sit there deciding what to do. Worse, an attacker can take control of the system directly. Cutting the connection stops both.
Second, run a virus scanner.
Bitdefender is a good first line of defense. Hitman Pro makes an excellent secondary scanner, and it is the one that will give you the clearest picture of the damage. Plenty of people run Microsoft Defender, the one that comes with Windows, and it is fine. It works reasonably well and it is better than nothing by an enormous margin.
Whichever you use, the scan is diagnosis before it is treatment. You could find a hundred separate infections and learn that the machine is hopeless. You could find something minor. You could find nothing at all. Until you know what you have, there is very little you can sensibly do, and the guessing is what turns a bad morning into a bad month.
Hitman Pro will clean up most of it and sometimes all of it. Bitdefender will clean up a great deal. Defender will clean up a fair amount.
And there is one more piece of information hiding in that step: a scan that will not run at all. A large amount of malware disables the antivirus as its first act, because a program that can see it is a program that can remove it. A scanner that will not start has told you the answer, and that is the point where you stop and call somebody who does this for a living.
How do you secure a family phone?
Treat the phone as seriously as the computer, because it is one, and almost nobody does.
Everything precious is on it. Photographs. Banking. Messages. Accounts that reset every other password you own. And plenty of people will not put a PIN on the thing, or will leave a tablet on a restaurant table while they go and collect their food. A minute is enough. With nothing on the front of the device it is simply open.
The list is short and unglamorous. Run a scanner. Take the updates and install them instead of dismissing the notification for the fourth time. Lock the screen. And back it up.
Backup is the one that matters most, for the same reason it mattered at that kitchen table at 2:47 in the morning. Mine goes to Google’s cloud, the path of least resistance on Android, and Apple has its own version that works the same way. The platform hardly matters. What matters is that it is running, and that you have verified it at some point, because a backup nobody has verified is a belief instead of a backup.
Why did the first version of this book fail?
I wrote it. It was called Safe Computing Is Like Safe Sex, and at the time I thought that title was extremely clever.
It was a stupid title. It welds together two things that have nothing to do with each other, and people could not work out what the book was about from looking at it.
Everything else about that book was done properly. It was the first real book I published, and I put everything I had into it. I hired an artist for the illustrations. I had it edited twice. I read through it over and over. I had it beta read by Steve Levenson, a security expert who ran PCI audits for me at Trader Joe’s, and by Jimmy James, who was our network man there. It was complete and it was correct.
It sold about twelve or fifteen copies.
Two reasons. The first is that nobody cares about home security. That is the problem the book exists to address and is also why it is difficult to sell a book about it. The second is that I had no idea how to promote anything. I ran straight into what I call the wall of marketing, which is a subject I had to learn the hard way and eventually wrote its own book about.
What changed in the rewrite?
About a year ago I decided to redo all of my books, bringing them up to modern publishing standards and my own current standards. Larger, more complete, better made. Every book I have written is now redone and republished, and this was one of them.
Family Cybersecurity is a complete rewrite instead of a new cover on old material.
The aim narrowed. The original was about cybersecurity in general, written for anybody with a computer. This one is written for families specifically: the home computers, the phones, the laptops, the tablets, whatever computing lives in the house and whoever lives there with it.
That includes the parts of the problem that are not technical at all. Talking to children about it without frightening them. Teenagers and where the privacy line sits. Helping parents who did not grow up with any of this and are the ones being targeted deliberately.
What was the hardest part to get right?
Keeping it out of my own language.
This book had every opportunity to become deeply technical, because I am capable of writing it that way and it is more comfortable for me. That would have made it useless. The people who need it are not technical, and a book they cannot read protects nobody.
So I kept the technical language down, wrote in plain English, and held the reading level to somewhere around high school.
That lesson applies well outside security. Understand your audience and write to that audience. Write past them and you lose them, and it does not matter how correct you were.
Cybersecurity has been near the center of my working life for a long time. I was doing security work on VAX/VMS at the start of my career, and PCI compliance at Trader Joe’s toward the end of it. I still keep a toe in the field, because it matters and because I enjoy it. I also run what I recommend: layers of backup, layers of protection, audited and monitored, checked regularly instead of assumed.
The argument comes down to one line. The people getting hurt are not the ones with a security department. They are the ones at a kitchen table at 2:47 in the morning with no idea what just happened to them, and nobody has ever written for them.
The Guides That Get Your Book Written, Published, and Sold
Four short, practical guides on writing, publishing, and selling your book, plus the occasional note when there's something worth your time. No fluff, no daily inbox clutter. Drop your email and they're yours.
We use MailerLite to manage our list and send these emails. Your address is used only to send you what you signed up for. We will not sell it, share it, or use it for anything else, and you can unsubscribe anytime.
