CYBERSECURITYIS SEXY
Scottsdale & Phoenix Business Owners
Presenter Notes — Joseph @ cybersecurityissexy.io
Local Business Owner Briefing • 2026

Protecting Your
Arizona Business

A practical guide for Arizona business owners — what you can do today, what you should never touch alone, and how to know the difference.

Run of Show 20-30 min

What We'll Cover Today

1. Why This Matters

The current threat landscape for local businesses, with clean numbers and no doom theater.

2. How Attacks Actually Happen

The practical patterns: phishing, vendor fraud, ransomware, AI-assisted impersonation, and weak defaults.

3. What You Can Fix Yourself

The baseline controls every owner can start this week: Multi-Factor Authentication (MFA / 2FA), updates, password management, backups, and email authentication.

4. Your 30-Day Plan

A short, realistic sequence for reducing risk without turning the business upside down.

The Reality

Cybercrime by the Numbers

43%
annual breach likelihood for under-protected SMBs
Verizon DBIR / industry baseline
$10.5T
projected global cybercrime cost by 2025
Cybersecurity Ventures
193/day
new vulnerabilities published in 2026 — up 48% YoY
SecurityVulnerability.io
$16B
in reported cybercrime losses — 859K complaints in 2024
FBI Internet Crime Report 2024
63%
of ransomware attackers now demand $1M or more
Cobalt.io / ransomware trends
45%
of employees now use unapproved AI tools at work
Verizon DBIR 2026

Your 43% Annual Risk vs. Everyday Odds

3.6x
more likely than
getting the flu
17x
more likely than
a car accident
18–43x
more likely than
an IRS audit
72x
more likely than
matching on Tinder
Context

Why Local Small Businesses Are Targeted

Most Phoenix and Scottsdale owners think: "We're too small to be targets."

In reality, automated bots scan the entire internet continuously. They don't care about your size — they care about your weak spots: default passwords, unpatched software, and missing email authentication.

"Automated attacks scan everyone indiscriminately. They don't target who you are; they target security gaps."

The Pivot Point

Attackers often target business connections to reach larger partners through shared email, vendor portals, or integrations.

The Cost of Downtime

A single ransomware incident can shut operations for weeks. For a local clinic, real estate office, or consultancy — that means lost clients, trust, and revenue.

Legal Liability

Arizona data breach notification law (A.R.S. § 18-552) requires you to notify affected individuals. Failure carries fines up to $500K.

The Timeline

What Actually Happens After a Breach

Months Before "Day 1"

Attacker gains access through a phishing email or stolen password. They quietly explore your network, steal credentials, and map your systems.

Day 1 — You Notice

Ransomware locks your files, or a client alerts you to a fraudulent wire. Panic sets in. You realize you can't access email, files, or billing systems.

Days 2-14 — Scramble Mode

Hire emergency forensics. Legal counsel reviews notification obligations. Staff works off personal phones. Client trust erodes rapidly.

Weeks 3-12 — Recovery

Rebuild systems from scratch (if backups exist). Issue legally-required breach notifications. Face potential regulatory scrutiny and client churn.

Average Dwell Time

Attackers often have time to explore before detection. They're not always smashing windows; sometimes they're quietly reading email, testing credentials, and learning who approves payments.

The Good News

Most of this is preventable. The basics — MFA, patching, proper backups, and email authentication — stop the vast majority of attacks before they start.

Self-Assessment

Where Are You Right Now?

You don't need a $10,000/month security suite. Implementing these five fundamentals eliminates the vast majority of attack vectors targeting small businesses:

"Attackers choose the path of least resistance. Make your business slightly harder to breach than the next one, and they move on."

Click items on the right to honestly test your readiness →

One Size Doesn't Fit All

What MFA looks like for a two-person real estate office looks nothing like a 40-person medical practice. Today covers the principle — not your specific playbook. That part takes a conversation.

MFA / 2FA on Email & Financial Accounts START HERE
Not SMS — use an authenticator app or hardware key
Automatic Security Updates Enabled
OS, browsers, and critical business apps — no exceptions
Unique Passwords via a Password Manager
If one password leaks, nothing else falls
Offsite & Isolated Backups (Tested!)
Backups that ransomware can't reach or encrypt
Email Authentication (SPF, DKIM, DMARC)
Stops scammers from sending fake mail from your domain: • SPF: A "guest list" of servers allowed to send your emails.
• DKIM: A "wax seal" proving the email hasn't been tampered with.
• DMARC: A "bouncer" telling servers to block emails that fail the tests.
If you only do one thing — it's this one. Your email is the master key to everything else: banking, payroll, client portals, password resets. Protect it first.
Main Takeaway 2-3 min

What You Actually Need to Walk Away Knowing

Three Real Takeaways

  • Every business holds valuable assets, data, and trusted relationships that attackers seek to exploit.
  • Your email is the first thing to protect because it controls resets, payments, and access everywhere else.
  • If a setting, outage, or security task feels unclear, stop before you improvise and get help.

The Goal

Cybersecurity is not a side hobby for a business owner. You do not need to learn how to do everything yourself.

What matters is recognizing risk early, making one or two owner-safe improvements, and having the right support before something expensive breaks.

Threat Intelligence

Current Threats Hitting Arizona Businesses

Business Email Compromise (BEC / Email Hijacking)

Attackers hack or spoof a vendor's email, then send "updated" wire instructions. You send real money to fraudulent accounts. Scottsdale real estate and title companies have lost millions.

Quishing (QR Code / Smartphone Phishing)

Emails with QR codes that bypass traditional link-scanning filters. Employees scan with their phone and enter credentials on convincing fake login pages.

Fake Recruitment / Resume Scams

Phishing campaigns disguised as job applicants submitting resumes. The attached "Resume.pdf" is actually malware that executes on open.

Callback Phishing (Vishing / Phone Scams)

An email says "Call this number to cancel your subscription." You call, and a live human walks you through installing remote access software on your computer.

Emerging Risk

AI-Powered Threats: The New Frontier

AI Is Already in Business Workflows

U.S. Census data showed roughly 17% to 20% of businesses were already using AI in business functions from December 2025 through May 2026, with more expecting to adopt it soon. This is not theoretical anymore.

Source: U.S. Census Bureau BTOS, May 26, 2026

Voice Cloning

AI can make impersonation calls much more convincing, especially when an attacker has public audio or video of the target. The risk is urgent money movement that sounds like it came from someone familiar.

Deepfake Video Calls

In early 2024, a Hong Kong firm lost $25 million after an employee joined a video call with AI-generated deepfakes of their entire leadership team.

AI-Written Phishing

Gone are the days of broken-English scam emails. AI generates flawless, personalized phishing using data scraped from your LinkedIn and website.

Your Defense

  • Do not paste sensitive business data into public AI tools. SBA warns small businesses not to feed sensitive or proprietary information into free AI systems.
  • Keep a human reviewer in the loop. SBA specifically recommends having another person review AI-generated output before business use.
  • Verify through a separate channel. Got a call from your "CEO"? Hang up and call them back on a known number.
  • Establish code words for wire transfers and sensitive requests — something AI can't guess.
  • Require dual approval for any financial transaction above a threshold (e.g., $1,000).

Sources: SBA AI for Small Business guidance; FBI BEC guidance

Strategy — Part 1

What You Can Safely Start

Turn On MFA for Business Email

If you do one technical thing yourself, make it this. Start with Google Workspace or Microsoft 365 email, use an authenticator app, and stop if the setup stops being obvious.

Start a Password Manager Conversation

Bitwarden and 1Password are both solid. The owner-safe move is deciding the team needs one and getting help rolling it out cleanly instead of texting passwords forever.

Learn the Red Flags

Urgent wire changes, fake login pages, QR-code phishing, and boss-text scams are all owner-level things to recognize. Awareness is a legitimate security control.

Ask the Right Questions

Who manages our email? Who has admin access? Who handles backups? Who would we call if we got locked out tomorrow? Those questions alone surface a lot of risk.

Complete a Free Efficiency & Security Assessment

The safest business-owner move is obtaining a clear translation of what matters in your environment. You can request a free, human-led efficiency and security checkup at myaz.tech/efficiencyworksheet to map out your setup before altering any settings.

High-Risk Email Setup to Fix First

If your business is still running on free consumer email, or if the owner's everyday mailbox is also the Global Admin or Super Admin account, you are carrying unnecessary risk. Both Microsoft and Google recommend separate admin accounts for privileged work, not day-to-day email use.

Official guidance: Microsoft admin/security docs and Google Workspace admin best practices both recommend separate privileged accounts and limiting use of admin accounts for routine work.

Strategy — Part 2

Call a Pro — Here's Why

The Consequences of DIY Here
  • Backups You Haven't Tested

    Ransomware is designed to find and destroy reachable backups first. An untested, unprotected backup is false security — you won't know it failed until you need it most.

    Critical
  • Firewall & Network Configuration

    One misconfigured firewall rule is how ransomware spreads to every machine you own. A consumer router from Best Buy is not a business firewall.

    Infrastructure
  • Incident Response

    Handling a breach incorrectly can destroy forensic evidence, void your cyber insurance claim, and expose you to regulatory penalties. This is not a Google-it situation.

    Legal
Also Worth Professional Eyes
  • Vulnerability & Penetration Testing

    Running professional scans against your network, web apps, and cloud services to find holes before attackers do.

    Compliance
  • Cyber Insurance Policy Review

    Many policies exclude claims when "reasonable security" wasn't maintained. A pro can check your posture against your policy — before you need to file a claim.

    Financial
  • Formal Security Awareness Training

    Beyond casual talks — simulated phishing campaigns, tracked completion, and compliance documentation for insurance or partners.

    Ongoing
  • Someone Proactively Watching Your Back

    The National Institute of Standards and Technology (NIST — the U.S. agency that sets cybersecurity standards) treats detection and monitoring as a core security function. In practice, that means someone needs to watch alerts, admin changes, suspicious logins, backup failures, and endpoint warnings before they become expensive surprises.

    Coverage
Security is not a DIY sport or a one-size-fits-all checklist. Trying to handle infrastructure and defense alone is the fastest way to leave gaps or accidentally void your cyber insurance.
Business Case 3 min

Why Delegation Is Usually the Cheaper Option

Switching Costs Are Real

Peer-reviewed workplace research found that frequent interruptions drive higher stress, frustration, and time pressure. In other words: every time you become your own help desk, you pay twice.

Source: Mark, Gudith, & Klocke, CHI 2008

Delegation Improves Outcomes

Peer-reviewed leadership research links delegation with greater psychological empowerment and more feedback-seeking from employees. Good delegation is not losing control. It is building a healthier operating system around you.

Source: Zhang et al., Frontiers in Psychology 2017

Simple Owner Math

If your time is worth even $100/hour and tech problems steal just 1 hour a month, you have already burned more value than a basic support relationship costs.

1 hour of owner distraction > low-end monthly IT support

The more expensive your time is, the faster delegation wins.

Illustrative math: adjust using your own billable rate or owner-hour value
Business Reality

Worst Case Is Not Theoretical

Operations Can End

In 2025, the collapse of UK logistics firm KNP after a ransomware attack was publicly tied to a guessed password. The reported result: a 158-year-old business gone and roughly 700 jobs lost.

Source: BBC reporting referenced by multiple trade outlets, July 2025

Money Leaves Fast

The FBI says business email compromise is one of the most financially damaging online crimes. It works because businesses already rely on email for invoices, approvals, and account changes.

Source: FBI BEC guidance / IC3 public service alert

The Response Becomes Legal

The FTC's breach-response guidance makes the business reality clear: preserve evidence, fix vulnerabilities, notify affected parties when required, and coordinate with law enforcement, counsel, and service providers. This is no longer just "computer trouble."

Source: FTC Data Breach Response Guide for Business

Quick Reference

Red Flags Cheat Sheet — Share This With Your Team

Urgency

"Act within 2 hours or your account will be suspended." Legitimate companies don't threaten you with immediate deadlines via email.

Mismatched URLs

Hover before you click. Does the link say "microsoft-secure-login.sketchy-domain.com"? The real domain is always right before the first slash.

https://microsoft-login.fake-portal.com/auth

Wire Changes

"We've updated our bank details — please use these new routing numbers." Always verify payment changes by phone on a known number.

Boss Impersonation

"Hey, I'm in a meeting. Can you buy 5 gift cards and send me the codes?" Real executives don't urgently request gift cards via text.

iMessage • Today
"Hey, I'm stuck in a meeting. Need to send 5 Apple gift cards to clients right now. Can you grab them and text me the codes? Will verify expense later. Thanks."

Unexpected Attachments

Files you didn't request — especially .zip, .exe, or documents asking you to "Enable Macros." When in doubt, call the sender first.

Too-Good Offers

"You've been selected for a $50,000 SBA grant — click here to claim." Verify all government offers directly on .gov websites.

Operations + Security

Responsiveness Is a Security Control

Fast Reporting Matters

Official U.S. phishing guidance says reporting suspicious phishing activity is one of the most efficient methods for protecting organizations. Delayed reporting gives attackers more time to reuse credentials, move laterally, or target coworkers.

Source: CISA / NSA / FBI / MS-ISAC phishing guidance, 2023

Slow Verification Gets Expensive

The FBI's BEC guidance says to verify payment or account-change requests using a known number and to be especially cautious when someone is pressing you to act quickly.

Source: FBI Business Email Compromise guidance

Texts Count Too

Federal phishing guidance now explicitly includes SMS and chat platforms like Teams, Slack, Signal, WhatsApp, and iMessage. That does not mean you should run approvals, money movement, or admin access by text.

Source: CISA / NSA / FBI / MS-ISAC phishing guidance, 2023

Channel Rule for Owners

Email and text are where scams arrive. They are not where sensitive decisions should end. Use them to notice, acknowledge, and escalate quickly. For money movement, account changes, payroll, privileged access, or anything unusual, move the decision to a verified channel and documented process.

Practice Scenario 4-5 min

What Would You Do?

The Email

A vendor you trust emails your office manager at 4:42 PM:

"We changed banks today. Please use the attached routing instructions for tomorrow's payment. Our phones are down, so reply here if you have questions."

AskLook For
What changed?New payment instructions, urgency, and a reason not to call.
How do we verify?Use a known phone number from your records, not the email signature or attachment.
Who approves?Require a second person before any bank detail change or large transfer.
What do we document?Save the email, verification call notes, approver, and final decision.
Action Plan

Your First 30 Days — A Realistic Plan

  Week 1 — Lock the Front Door

✓ Enable MFA on all email accounts (Google/Microsoft admin panel)
✓ Roll out a password manager to the team
✓ Enable disk encryption on every company device

  Week 2 — Check Your Exposure

✓ Run a free domain scan at cybersecurityissexy.io
✓ Verify SPF, DKIM, and DMARC on your email domain
✓ Google your business name + "data breach" to check history

  Week 3 — Verify Your Safety Net

✓ Confirm you have backups (not just "the cloud" — actual backup copies)
✓ Test a restore — can you actually recover a file from last week?
✓ Review your cyber insurance policy exclusions

  Week 4 — Build the Culture

✓ Hold a 10-minute team security talk using the Red Flags slide
✓ Set a simple rule: suspicious email, wire change, MFA alert, or boss-text gets same-day response and verification
✓ Decide who is proactively watching alerts, backups, and admin/account changes
✓ Establish a code word for wire transfer verification
✓ Decide which items need professional help & get quotes

Questions & Next Steps

Let's Build Stronger
Arizona Businesses

Want to know exactly where your business stands? Book a 20-minute intro call and we'll help you sort out what is safe to handle, what needs support, and what should never be touched alone.

Book Your 20-Min Intro Call

The downloadable checklist also includes a clearly labeled bonus morale link to the IT Survival Guide as a fun extra, not as security guidance.

Scottsdale Living Offer

$20 off per user for the first month when Scottsdale Living attendees enroll in our complete protection package. Mention the presentation when you book.

Scan to book — scheduling.yourpersonal.ninja/#/intro-call

Scan to book your 20-minute intro call

← → navigate N notes F fullscreen