WEBVTT

1
00:00:00.080 --> 00:00:03.160
<v Speaker 1>You know that feeling your computer screen just freezes up,

2
00:00:03.520 --> 00:00:05.719
<v Speaker 1>and then this weird pop up appears, looks like it's

3
00:00:05.719 --> 00:00:09.640
<v Speaker 1>from Window Security, but it's demanding a bitcoin to unlock

4
00:00:09.679 --> 00:00:10.119
<v Speaker 1>your files.

5
00:00:10.199 --> 00:00:11.679
<v Speaker 2>Oh yeah, that immediate panic.

6
00:00:11.880 --> 00:00:15.160
<v Speaker 1>It's a horrible feeling exactly. And while that fear of

7
00:00:15.160 --> 00:00:17.600
<v Speaker 1>your own PC getting hit is totally valid, what if

8
00:00:17.640 --> 00:00:20.079
<v Speaker 1>I told you that's just well the tip of a

9
00:00:20.199 --> 00:00:22.000
<v Speaker 1>much much bigger digital iceberg.

10
00:00:22.440 --> 00:00:26.000
<v Speaker 2>That's right, Malware today isn't just about one machine. It's

11
00:00:26.039 --> 00:00:29.839
<v Speaker 2>targeting whole networks, servers, stealing really personal data.

12
00:00:30.280 --> 00:00:34.359
<v Speaker 1>It's evolve into a massive industry, right, especially with ransomware.

13
00:00:34.719 --> 00:00:36.520
<v Speaker 1>The stakes are incredibly.

14
00:00:36.039 --> 00:00:38.520
<v Speaker 2>High, millions sometimes billions involved.

15
00:00:38.640 --> 00:00:41.200
<v Speaker 1>Welcome to the deep dive. This is where we take

16
00:00:41.240 --> 00:00:43.640
<v Speaker 1>expert sources, cut through the noise and pull out the

17
00:00:43.679 --> 00:00:45.679
<v Speaker 1>key insights to get you informed fast.

18
00:00:45.960 --> 00:00:50.200
<v Speaker 2>And today we're diving into the let's say, fascinating and

19
00:00:50.280 --> 00:00:52.880
<v Speaker 2>sometimes pretty terrifying world of Windows malware.

20
00:00:53.039 --> 00:00:55.920
<v Speaker 1>Yeah, our mission here is really for you, the curious learner.

21
00:00:56.240 --> 00:00:59.240
<v Speaker 1>We want to demystify these threats, give you the knowledge

22
00:00:59.240 --> 00:01:02.200
<v Speaker 1>not just to defend you, but also crucially how to

23
00:01:02.280 --> 00:01:03.960
<v Speaker 1>spot them and get rid of them if they do

24
00:01:04.040 --> 00:01:05.079
<v Speaker 1>strike and our.

25
00:01:05.000 --> 00:01:08.200
<v Speaker 2>Main guide for this is a really solid source Windows

26
00:01:08.280 --> 00:01:13.879
<v Speaker 2>Virus and Malware Troubleshooting by Microsoft MVPs Andrew Bettany and

27
00:01:13.959 --> 00:01:14.640
<v Speaker 2>Mike Halsey.

28
00:01:14.920 --> 00:01:17.719
<v Speaker 1>So we're going to dig into some surprising history, look

29
00:01:17.760 --> 00:01:20.760
<v Speaker 1>at the threats we face right now, and get beyond

30
00:01:20.879 --> 00:01:25.680
<v Speaker 1>those scary headlines to you know, practical understanding and actual solutions.

31
00:01:25.959 --> 00:01:26.840
<v Speaker 1>Ready to jump in.

32
00:01:26.959 --> 00:01:29.239
<v Speaker 2>Let's do it. What's really interesting when you look back

33
00:01:29.480 --> 00:01:32.719
<v Speaker 2>is where computer viruses actually started. It might surprise you

34
00:01:32.760 --> 00:01:35.799
<v Speaker 2>not Windows then, No, not initially the very earliest ones,

35
00:01:35.840 --> 00:01:38.280
<v Speaker 2>believe it or not, for Apple two and macintos systems.

36
00:01:38.480 --> 00:01:41.439
<v Speaker 2>They'd write themselves onto the boots sector of floppy discs.

37
00:01:41.599 --> 00:01:44.680
<v Speaker 1>Floppy discs wow, so every time you use the disc.

38
00:01:44.560 --> 00:01:47.359
<v Speaker 2>And go it executed. Sneaky stuff even back then.

39
00:01:47.599 --> 00:01:50.640
<v Speaker 1>But then came the IBM PC and MS DOSS and

40
00:01:50.719 --> 00:01:54.359
<v Speaker 1>personal computer started popping up everywhere, especially in businesses, and.

41
00:01:54.319 --> 00:01:57.439
<v Speaker 2>That's when things really took off. Virus wise. They were

42
00:01:57.480 --> 00:02:01.719
<v Speaker 2>tiny programs back then, often doing well, almost quaint things.

43
00:02:01.760 --> 00:02:04.280
<v Speaker 1>Like that story about the virus playing Yankee Doodle Dandy

44
00:02:04.319 --> 00:02:07.239
<v Speaker 1>every day at five pm on an old Olive EDDYPC

45
00:02:07.519 --> 00:02:09.879
<v Speaker 1>back in ninety one. Seems almost terming.

46
00:02:09.639 --> 00:02:14.560
<v Speaker 2>Now agrease simpler times, definitely, but things escalated pretty fast.

47
00:02:14.759 --> 00:02:17.479
<v Speaker 2>The Morris worm late eighty eight. That was a real

48
00:02:17.520 --> 00:02:20.159
<v Speaker 2>turning point. The first Internet virus.

49
00:02:19.919 --> 00:02:22.199
<v Speaker 1>Essentially written by a student, wasn't it yeah.

50
00:02:22.039 --> 00:02:24.759
<v Speaker 2>Cornell grad student. It wasn't actually meant to be harmful

51
00:02:25.000 --> 00:02:27.800
<v Speaker 2>to see how big the Internet was. But a mistake

52
00:02:27.840 --> 00:02:30.879
<v Speaker 2>in the code, oh yeah, it turned it infectious, became

53
00:02:30.919 --> 00:02:34.360
<v Speaker 2>a denial of service attack by accident, basically took down

54
00:02:34.400 --> 00:02:36.879
<v Speaker 2>thousands of computers. Huge cleanup job.

55
00:02:36.919 --> 00:02:40.280
<v Speaker 1>And we've seen some incredibly destructive ones since. Stuck snit

56
00:02:40.560 --> 00:02:45.520
<v Speaker 1>for instance, targeting Iran's nuclear program that was huge, news, huge.

57
00:02:45.319 --> 00:02:48.360
<v Speaker 2>And code read back in two thousand and one. That

58
00:02:48.400 --> 00:02:51.199
<v Speaker 2>thing was infecting what over three hundred thousand computers a day,

59
00:02:51.479 --> 00:02:55.639
<v Speaker 2>defacing websites, launching attacks. It really felt like the Wild West.

60
00:02:55.360 --> 00:02:57.439
<v Speaker 1>Online, It really did. And this is where we see

61
00:02:57.439 --> 00:03:00.280
<v Speaker 1>that big shift you mentioned earlier, right, the motivation change.

62
00:03:00.360 --> 00:03:03.240
<v Speaker 2>Exactly stop being about just getting famous or proving you

63
00:03:03.280 --> 00:03:07.159
<v Speaker 2>could do it, and became curely about money, cold hard cash.

64
00:03:07.360 --> 00:03:08.800
<v Speaker 1>Enter the bots and ransomware.

65
00:03:08.919 --> 00:03:12.439
<v Speaker 2>Precisely, bots are like these hidden agents. They can infect thousands,

66
00:03:12.479 --> 00:03:15.199
<v Speaker 2>millions of computers. And just sit there waiting waiting for

67
00:03:15.240 --> 00:03:19.400
<v Speaker 2>what for instructions, Control of these botnets get sold on

68
00:03:19.439 --> 00:03:22.240
<v Speaker 2>the dark web. They use them for well, all sorts

69
00:03:22.240 --> 00:03:25.960
<v Speaker 2>of things, key logging, to steal your passwords, creating backdoors

70
00:03:25.960 --> 00:03:30.400
<v Speaker 2>into systems, launching massive DDUS attacks to crash websites.

71
00:03:30.080 --> 00:03:33.319
<v Speaker 1>DDAs distributed denial of service that's where they flood a

72
00:03:33.400 --> 00:03:34.240
<v Speaker 1>site with traffic.

73
00:03:34.319 --> 00:03:36.479
<v Speaker 2>That's the one overwhelm it completely.

74
00:03:36.599 --> 00:03:40.240
<v Speaker 1>And then ransomware that's the one that really gives people nightmares,

75
00:03:40.240 --> 00:03:41.639
<v Speaker 1>individuals and businesses alike.

76
00:03:41.759 --> 00:03:45.479
<v Speaker 2>Oh absolutely, Imagine all your files, your photos, your documents

77
00:03:45.520 --> 00:03:49.280
<v Speaker 2>just locked up encrypted and you get this demand for

78
00:03:49.360 --> 00:03:51.599
<v Speaker 2>bitcoin to maybe get them back.

79
00:03:51.360 --> 00:03:52.639
<v Speaker 1>And businesses are paying.

80
00:03:52.919 --> 00:03:56.080
<v Speaker 2>Sources say yes, hundreds of millions are made this way

81
00:03:56.159 --> 00:04:00.719
<v Speaker 2>every year. Universities, hospitals, big companies, even government agencies. They

82
00:04:00.759 --> 00:04:04.759
<v Speaker 2>often pay quietly because the cost of downtime is even higher.

83
00:04:04.800 --> 00:04:07.479
<v Speaker 1>It's a horrible calculation to have to make, it really is.

84
00:04:07.719 --> 00:04:10.840
<v Speaker 2>And it's important to remember malware isn't just a Windows problem.

85
00:04:10.960 --> 00:04:13.879
<v Speaker 2>It's everywhere Android, iOS, mac os.

86
00:04:14.080 --> 00:04:16.680
<v Speaker 1>But Windows is the main focus for today's deep dive

87
00:04:17.040 --> 00:04:18.560
<v Speaker 1>just because it's so widely used.

88
00:04:18.759 --> 00:04:22.480
<v Speaker 2>Right though, it's worth noting those newer ARM based Windows

89
00:04:22.519 --> 00:04:26.319
<v Speaker 2>ten systems, they are generally a bit less susceptible, more

90
00:04:26.360 --> 00:04:29.959
<v Speaker 2>modern architecture, but not immune, not totally immune, no, because

91
00:04:30.000 --> 00:04:33.399
<v Speaker 2>they can still run older legacy Windows code, and that's

92
00:04:33.439 --> 00:04:35.040
<v Speaker 2>often what malware targets.

93
00:04:35.279 --> 00:04:38.319
<v Speaker 1>And looking forward, the Internet of Things IoT, that's a

94
00:04:38.360 --> 00:04:40.079
<v Speaker 1>whole new frontier, isn't it.

95
00:04:40.079 --> 00:04:44.439
<v Speaker 2>It is smart fridges, cameras, dermostats. A lot of these

96
00:04:44.439 --> 00:04:48.920
<v Speaker 2>devices have pretty weak security out of the box, default passwords, things.

97
00:04:48.759 --> 00:04:51.439
<v Speaker 1>Like that, so they become an easy way into your network.

98
00:04:51.199 --> 00:04:54.600
<v Speaker 2>Potentially, yes, a gateway for attackers to get to your

99
00:04:54.879 --> 00:04:57.720
<v Speaker 2>more important devices like your PC or your phone.

100
00:04:57.959 --> 00:05:00.399
<v Speaker 1>So if operating systems like Windows are getting more secure

101
00:05:00.439 --> 00:05:03.360
<v Speaker 1>all the time, why are we still seeing so many infections?

102
00:05:03.360 --> 00:05:04.040
<v Speaker 1>What's the gap?

103
00:05:04.240 --> 00:05:08.040
<v Speaker 2>That's a great question. Historically, Yeah, older OS versions like

104
00:05:08.120 --> 00:05:11.439
<v Speaker 2>early Windows, had real security flaws. Malware could just run

105
00:05:11.839 --> 00:05:12.879
<v Speaker 2>sometimes automatically.

106
00:05:12.920 --> 00:05:15.360
<v Speaker 1>That's why Mac and Unix always felt safer back then,

107
00:05:15.759 --> 00:05:18.120
<v Speaker 1>less admin writes by default, that was a big.

108
00:05:18.000 --> 00:05:22.600
<v Speaker 2>Part of it. Yes, but modern Windows, say from Vista onwards,

109
00:05:23.000 --> 00:05:26.519
<v Speaker 2>really up the game. Features like user count control, UAC,

110
00:05:26.720 --> 00:05:29.079
<v Speaker 2>secure mood. They made a huge difference.

111
00:05:29.279 --> 00:05:31.600
<v Speaker 1>So the attackers changed tactics they had to.

112
00:05:31.759 --> 00:05:34.680
<v Speaker 2>They shifted focus from just exploiting technical bugs in the

113
00:05:34.680 --> 00:05:40.319
<v Speaker 2>OS to exploiting well leus human psychology. How so, malware

114
00:05:40.360 --> 00:05:45.279
<v Speaker 2>started dressing up as something harmless or useful or even.

115
00:05:45.120 --> 00:05:47.040
<v Speaker 1>Fun like what give me an example.

116
00:05:47.160 --> 00:05:50.480
<v Speaker 2>Think about needing a special video codec to watch something online,

117
00:05:51.079 --> 00:05:53.839
<v Speaker 2>or downloading a pirated app that promises all the features

118
00:05:53.839 --> 00:05:55.879
<v Speaker 2>for free, or maybe even something that looks like a

119
00:05:55.920 --> 00:05:58.279
<v Speaker 2>Windows update, but you got it from some random website.

120
00:05:58.399 --> 00:06:01.360
<v Speaker 1>Ah okay. So it relies on tricking the user.

121
00:06:01.319 --> 00:06:04.399
<v Speaker 2>Exactly, and this is where you become the weakest link. Potentially.

122
00:06:04.480 --> 00:06:07.720
<v Speaker 2>People are busy, they're tired, maybe just curious. You click

123
00:06:07.879 --> 00:06:11.160
<v Speaker 2>allow on a security prompt without really reading it, or.

124
00:06:11.160 --> 00:06:13.399
<v Speaker 1>You grant admin rights just to make that annoying pop

125
00:06:13.480 --> 00:06:15.920
<v Speaker 1>up go away or get that cat video to play right.

126
00:06:16.279 --> 00:06:19.560
<v Speaker 2>And the scary thing is one person granting those rights

127
00:06:19.720 --> 00:06:22.040
<v Speaker 2>can open the door for malware to spread across an

128
00:06:22.199 --> 00:06:25.720
<v Speaker 2>entire company network, accessing shared files and resources.

129
00:06:25.800 --> 00:06:28.680
<v Speaker 1>So the defense isn't just technical anymore.

130
00:06:28.600 --> 00:06:33.439
<v Speaker 2>Not solely. No, The two biggest defenses are one technically

131
00:06:33.439 --> 00:06:36.279
<v Speaker 2>preventing users from just running any old code or installing

132
00:06:36.319 --> 00:06:41.519
<v Speaker 2>random software, and two maybe even more important education training

133
00:06:41.560 --> 00:06:44.199
<v Speaker 2>people on what's safe to click and what definitely isn't.

134
00:06:44.360 --> 00:06:46.439
<v Speaker 1>It really makes you stop and think, doesn't it. How

135
00:06:46.480 --> 00:06:49.399
<v Speaker 1>often do we really read those prompts before clicking yes

136
00:06:49.680 --> 00:06:52.920
<v Speaker 1>or install. It's a habit we probably all.

137
00:06:52.759 --> 00:06:54.079
<v Speaker 2>Need to work on definitely.

138
00:06:54.160 --> 00:06:56.879
<v Speaker 1>Now, we've been using the term malware as a catch all,

139
00:06:57.560 --> 00:06:59.480
<v Speaker 1>but there are different types, right, What are the main

140
00:06:59.519 --> 00:07:00.759
<v Speaker 1>distinctions we should understand?

141
00:07:00.800 --> 00:07:03.680
<v Speaker 2>You're right, it's an umbrella term. Malware covers a lot

142
00:07:03.680 --> 00:07:06.800
<v Speaker 2>of ground. The key types often different in how they

143
00:07:06.879 --> 00:07:07.800
<v Speaker 2>spread or what they.

144
00:07:07.680 --> 00:07:10.480
<v Speaker 1>Do, Like viruses versus worms. What's the difference there.

145
00:07:10.519 --> 00:07:13.160
<v Speaker 2>It's mainly about propagation, how they get around. A virus

146
00:07:13.199 --> 00:07:15.680
<v Speaker 2>needs help to spread, like attaching itself to a file

147
00:07:15.720 --> 00:07:17.720
<v Speaker 2>that you then share, maybe on a USB stick or

148
00:07:17.839 --> 00:07:20.720
<v Speaker 2>email attachment, physical contact.

149
00:07:20.199 --> 00:07:23.319
<v Speaker 1>Almost like a biological virus pretty much.

150
00:07:23.439 --> 00:07:25.519
<v Speaker 2>A worm, on the other hand, is designed to spread

151
00:07:25.560 --> 00:07:28.519
<v Speaker 2>by itself across a network. It burrows from one computer

152
00:07:28.600 --> 00:07:31.839
<v Speaker 2>to another, replicating as it goes, without needing you to

153
00:07:31.920 --> 00:07:33.079
<v Speaker 2>actively share a file.

154
00:07:33.560 --> 00:07:35.680
<v Speaker 1>Okay, so that's how they spread. What about what they

155
00:07:35.720 --> 00:07:38.319
<v Speaker 1>actually do once they're inside? Let's talk about the ones

156
00:07:38.360 --> 00:07:39.279
<v Speaker 1>that steal information.

157
00:07:39.920 --> 00:07:43.120
<v Speaker 2>Spyware spyware does exactly what it says on the tin.

158
00:07:43.240 --> 00:07:46.360
<v Speaker 2>It spies on you, gathers information about what you do

159
00:07:46.480 --> 00:07:49.800
<v Speaker 2>online maybe offline too, often includes a keylogger.

160
00:07:50.000 --> 00:07:52.199
<v Speaker 1>Keylogger records everything I type.

161
00:07:52.040 --> 00:07:55.959
<v Speaker 2>YEP, passwords, bank details, private messages, then sends it all

162
00:07:56.000 --> 00:07:59.319
<v Speaker 2>back to whoever created the spyware. Pretty nasty stuff.

163
00:07:59.120 --> 00:08:01.240
<v Speaker 1>And adwere that sounds less harmful?

164
00:08:01.480 --> 00:08:04.800
<v Speaker 2>Generally? Yes, AdWords mostly about showing you unwanted ads usually

165
00:08:04.800 --> 00:08:09.240
<v Speaker 2>pop ups annoying, but rarely a direct threat, unlike unless

166
00:08:09.279 --> 00:08:12.040
<v Speaker 2>it comes bundled with something else, like a keylogger hidden inside.

167
00:08:12.160 --> 00:08:14.279
<v Speaker 2>So even seemingly harmless adware can be risky.

168
00:08:14.360 --> 00:08:17.199
<v Speaker 1>Okay, got it? What about trojans trojan horses?

169
00:08:17.560 --> 00:08:22.360
<v Speaker 2>Right? These disguise themselves as legitimate software, could be anything

170
00:08:22.360 --> 00:08:24.759
<v Speaker 2>a Kodak, a browser plug in. Maybe that powered app

171
00:08:24.800 --> 00:08:27.560
<v Speaker 2>we mentioned looks fine on the outside, took inside it's

172
00:08:27.560 --> 00:08:31.240
<v Speaker 2>carrying a hidden, malicious payload. Once you install the useful thing,

173
00:08:31.680 --> 00:08:33.480
<v Speaker 2>the nasty bit gets installed too.

174
00:08:33.480 --> 00:08:36.279
<v Speaker 1>And it was technically a Greek horse, not trojan you

175
00:08:36.320 --> 00:08:37.960
<v Speaker 1>mentioned well grease Yeah.

176
00:08:37.799 --> 00:08:41.840
<v Speaker 2>Yeah, pedantic point, But the principle of deception is identical.

177
00:08:41.960 --> 00:08:45.600
<v Speaker 1>Deception is key, and that leads us to bots right,

178
00:08:46.279 --> 00:08:47.879
<v Speaker 1>creating these botnets exactly.

179
00:08:48.159 --> 00:08:52.360
<v Speaker 2>Bots infect machines, thousands, sometimes millions of them and turn

180
00:08:52.440 --> 00:08:55.320
<v Speaker 2>them into a kind of zombie army, a botnet.

181
00:08:55.000 --> 00:08:57.120
<v Speaker 3>And these botnets are used for often for those D

182
00:08:57.240 --> 00:09:00.519
<v Speaker 3>Days attacks we talked about flooding websites, but they almost

183
00:09:00.600 --> 00:09:03.960
<v Speaker 3>always have keyloggers and back doors built into for stealing

184
00:09:04.039 --> 00:09:05.679
<v Speaker 3>data or taking remote control.

185
00:09:06.039 --> 00:09:09.200
<v Speaker 2>Microsoft and law enforcement have actually had some success taking

186
00:09:09.240 --> 00:09:11.279
<v Speaker 2>down major bot nets, which is good news.

187
00:09:11.399 --> 00:09:13.799
<v Speaker 1>That is good news. Now, root kits and bootkits some

188
00:09:13.919 --> 00:09:14.919
<v Speaker 1>particularly nasty.

189
00:09:14.919 --> 00:09:17.159
<v Speaker 2>They are. They dig in really deep, hiding in the

190
00:09:17.159 --> 00:09:20.080
<v Speaker 2>boot partitions of your hard drive. Basically, they load before

191
00:09:20.080 --> 00:09:21.279
<v Speaker 2>your operating system.

192
00:09:20.960 --> 00:09:24.360
<v Speaker 1>Even starts, so they're hidden from normal security software.

193
00:09:24.639 --> 00:09:27.960
<v Speaker 2>Often, yes, they can gain complete control of the system

194
00:09:28.320 --> 00:09:32.159
<v Speaker 2>while staying invisible. That's why things like Intel's Secure boot

195
00:09:32.360 --> 00:09:33.200
<v Speaker 2>are so important.

196
00:09:33.320 --> 00:09:36.559
<v Speaker 1>Secure boot checks the digital signatures during startup right.

197
00:09:36.879 --> 00:09:40.320
<v Speaker 2>It verifies the firmware and the OS itself before loading.

198
00:09:40.960 --> 00:09:44.519
<v Speaker 2>If something's been tampered with, like by a bootkit, it

199
00:09:44.600 --> 00:09:45.679
<v Speaker 2>ideally shouldn't start.

200
00:09:45.759 --> 00:09:48.039
<v Speaker 1>But you mentioned that can be an issue for older

201
00:09:48.039 --> 00:09:50.159
<v Speaker 1>OT's like Windows seven or Linux.

202
00:09:50.240 --> 00:09:53.600
<v Speaker 2>Yeah, they don't always support secure boot natively without some

203
00:09:53.679 --> 00:09:58.080
<v Speaker 2>configuration changes, so some users might disable it, which unfortunately

204
00:09:58.159 --> 00:09:59.759
<v Speaker 2>opens the door for these kinds of attacks.

205
00:10:00.159 --> 00:10:02.440
<v Speaker 1>Back Doors are they separate things or part of these

206
00:10:02.480 --> 00:10:03.840
<v Speaker 1>other malware types.

207
00:10:03.679 --> 00:10:06.399
<v Speaker 2>Often part of others. A backdoor is just what it

208
00:10:06.480 --> 00:10:08.519
<v Speaker 2>sounds like, a hidden way for someone to get remote

209
00:10:08.519 --> 00:10:11.879
<v Speaker 2>access and control your PC later bypassing all the normal

210
00:10:11.919 --> 00:10:14.679
<v Speaker 2>security checks, give them access to your files, your network.

211
00:10:14.759 --> 00:10:17.960
<v Speaker 1>Okay. And finally, ransomware the big one, the.

212
00:10:17.879 --> 00:10:21.519
<v Speaker 2>Most unpleasant, definitely and often the most financially damaging. It

213
00:10:21.600 --> 00:10:24.759
<v Speaker 2>encrypts your files, documents, photos, videos.

214
00:10:24.480 --> 00:10:26.840
<v Speaker 1>Everything, scrambles theme completely, makes.

215
00:10:26.639 --> 00:10:31.399
<v Speaker 2>Them totally inaccessible. Sometimes it encrypts the entire disc or

216
00:10:31.480 --> 00:10:34.360
<v Speaker 2>the file directory system itself, the master list of where

217
00:10:34.360 --> 00:10:37.480
<v Speaker 2>everything is then pops up the demand for bitcoin for

218
00:10:37.519 --> 00:10:38.440
<v Speaker 2>the decryption key.

219
00:10:38.799 --> 00:10:41.519
<v Speaker 1>And because we SINNC everything to the cloud now it.

220
00:10:41.440 --> 00:10:44.960
<v Speaker 2>Can spread fast, encrypt files on your network drives, even

221
00:10:45.000 --> 00:10:47.759
<v Speaker 2>in your cloud storage if it sinks fast enough. And

222
00:10:47.799 --> 00:10:49.919
<v Speaker 2>as we said, organizations often pay up.

223
00:10:50.080 --> 00:10:52.639
<v Speaker 1>Why do they pay just the cost of recovery?

224
00:10:52.759 --> 00:10:57.559
<v Speaker 2>Often yeah, downtime, data loss. It can be catastrophic. The

225
00:10:57.639 --> 00:11:00.960
<v Speaker 2>criminals know this. They price the ransom accordingly high, but

226
00:11:01.000 --> 00:11:03.519
<v Speaker 2>maybe just low enough to make paying seem like the

227
00:11:03.639 --> 00:11:04.399
<v Speaker 2>lesser evil.

228
00:11:04.799 --> 00:11:07.279
<v Speaker 1>But paying doesn't always guarantee you get your files back

229
00:11:07.440 --> 00:11:09.320
<v Speaker 1>right or that it's over exactly.

230
00:11:09.919 --> 00:11:13.039
<v Speaker 2>Sometimes the decryption key doesn't work, or worse, the key

231
00:11:13.120 --> 00:11:16.679
<v Speaker 2>itself contains another piece of malware. It's a truly vicious cycle.

232
00:11:16.879 --> 00:11:19.399
<v Speaker 1>Okay, so that's a pretty grim picture of the threats.

233
00:11:19.440 --> 00:11:22.120
<v Speaker 1>How do we actually start defending ourselves? What's the approach?

234
00:11:22.279 --> 00:11:25.639
<v Speaker 2>The core concept is defense in depth, think layers, not

235
00:11:25.720 --> 00:11:28.919
<v Speaker 2>just one big wall, right, because even the best single solution,

236
00:11:29.519 --> 00:11:33.039
<v Speaker 2>say just an antivirus, can potentially be lie passed. You

237
00:11:33.080 --> 00:11:35.759
<v Speaker 2>need multiple layers of protection that back each other up.

238
00:11:36.360 --> 00:11:37.799
<v Speaker 2>Redundancy is key.

239
00:11:37.639 --> 00:11:39.840
<v Speaker 1>And Microsoft has built a lot of these layers directly

240
00:11:39.879 --> 00:11:41.360
<v Speaker 1>into Windows, now, haven't.

241
00:11:41.039 --> 00:11:43.720
<v Speaker 2>They They really have, Especially in Windows seven, eight point

242
00:11:43.720 --> 00:11:47.279
<v Speaker 2>one to ten. You've got the Security Center or Security

243
00:11:47.279 --> 00:11:50.039
<v Speaker 2>of Maintenance in Windows ten that's your main dashboard.

244
00:11:50.120 --> 00:11:53.639
<v Speaker 1>The traffic light system green, amber, red, YEP.

245
00:11:53.519 --> 00:11:56.399
<v Speaker 2>Gives you a quick visual check. Green is good, Amber

246
00:11:56.440 --> 00:11:59.639
<v Speaker 2>means check something, Red means there's a problem. Like your

247
00:11:59.639 --> 00:12:01.480
<v Speaker 2>anti viruses offer out of date.

248
00:12:01.440 --> 00:12:04.519
<v Speaker 1>And User Account control UAC. You mentioned that earlier.

249
00:12:04.600 --> 00:12:07.039
<v Speaker 2>Yeah, UAC is like your first line of defense against

250
00:12:07.159 --> 00:12:11.600
<v Speaker 2>unauthorized changes when something tries to install software or change

251
00:12:11.600 --> 00:12:15.600
<v Speaker 2>system settings, UAC pops up that prompt in a secure environment.

252
00:12:15.840 --> 00:12:17.320
<v Speaker 1>Secure environment, what does that mean?

253
00:12:17.480 --> 00:12:20.120
<v Speaker 2>It means the rest of the desktop is dimmed and inactive,

254
00:12:20.159 --> 00:12:24.240
<v Speaker 2>so malware can't like hijack your mouse quick and approve itself.

255
00:12:24.480 --> 00:12:26.919
<v Speaker 2>It's designed to make you consciously interact with the prompt.

256
00:12:27.039 --> 00:12:29.879
<v Speaker 1>Clever and the built in firewall.

257
00:12:29.600 --> 00:12:33.080
<v Speaker 2>Windows Firewall is actually very effective. A lot of companies

258
00:12:33.120 --> 00:12:36.159
<v Speaker 2>still use third party ones, maybe for centralized management, but

259
00:12:36.240 --> 00:12:38.879
<v Speaker 2>the built in one, especially the Advanced firewall, gives you

260
00:12:39.000 --> 00:12:43.960
<v Speaker 2>really granular control over which app supports and services can communicate.

261
00:12:44.279 --> 00:12:48.320
<v Speaker 1>What about the Malicious Software Removal Tool MSRT? Is that

262
00:12:48.360 --> 00:12:49.360
<v Speaker 1>the main antivirus?

263
00:12:50.000 --> 00:12:52.960
<v Speaker 2>No think if MSRT is an extra cleanup tool. It

264
00:12:53.000 --> 00:12:58.519
<v Speaker 2>targets specific, really widespread major threats. Microsoft updates it every

265
00:12:58.559 --> 00:13:01.879
<v Speaker 2>month through Windows Update. It runs quietly in the background usually,

266
00:13:02.200 --> 00:13:04.279
<v Speaker 2>but you can download and run it manually if you

267
00:13:04.320 --> 00:13:05.879
<v Speaker 2>suspect something nasty got through.

268
00:13:05.960 --> 00:13:10.039
<v Speaker 1>And Windows Update itself is crucial for security.

269
00:13:09.600 --> 00:13:13.759
<v Speaker 2>Absolutely essential, not just for features, but for patching vulnerabilities

270
00:13:13.759 --> 00:13:17.559
<v Speaker 2>that malware exploits. Windows ten make security and stability updates

271
00:13:17.639 --> 00:13:19.200
<v Speaker 2>mandatory for this reason.

272
00:13:19.120 --> 00:13:22.879
<v Speaker 1>Though you can delay some updates. In pro and enterprise versions, you.

273
00:13:22.840 --> 00:13:25.320
<v Speaker 2>Can defer the big feature updates for a while. Yeah yeah,

274
00:13:25.360 --> 00:13:29.120
<v Speaker 2>but those critical security patches they come through regardless, which

275
00:13:29.159 --> 00:13:29.639
<v Speaker 2>is important.

276
00:13:29.639 --> 00:13:32.480
<v Speaker 1>Okay, let's talk about protecting the startup process. That seems

277
00:13:32.519 --> 00:13:33.840
<v Speaker 1>like a really vulnerable time.

278
00:13:34.159 --> 00:13:39.120
<v Speaker 2>BitLocker BitLocker drive encryption is fantastic, especially on laptops available

279
00:13:39.120 --> 00:13:42.320
<v Speaker 2>in pro and enterprise editions. It encrypts your entire.

280
00:13:42.080 --> 00:13:45.279
<v Speaker 1>Hard drive, so if someone steals my laptop, they can't

281
00:13:45.320 --> 00:13:45.879
<v Speaker 1>just pull out.

282
00:13:45.759 --> 00:13:47.759
<v Speaker 2>The hard drive and read your data. Even when the

283
00:13:47.759 --> 00:13:51.080
<v Speaker 2>PC is signed out, the drive stays locked. It's like

284
00:13:51.120 --> 00:13:53.159
<v Speaker 2>a digital safe for your data at rest.

285
00:13:53.519 --> 00:13:56.679
<v Speaker 1>Really important and secure boot. We touched on that regarding.

286
00:13:56.360 --> 00:14:00.279
<v Speaker 2>Bootcuts right developed by Intel mandatory since Windows A point

287
00:14:00.320 --> 00:14:02.840
<v Speaker 2>one on new PCs. It's that digital bouncer at the

288
00:14:02.879 --> 00:14:06.240
<v Speaker 2>door checks the signatures of the firmware and the OS before.

289
00:14:06.039 --> 00:14:09.120
<v Speaker 1>They load, preventing unauthorized code from running early on.

290
00:14:09.200 --> 00:14:12.279
<v Speaker 2>Exactly stops malware trying to sneak in before Windows are

291
00:14:12.320 --> 00:14:15.159
<v Speaker 2>your anti virus is even up and running again. Can

292
00:14:15.200 --> 00:14:18.080
<v Speaker 2>sometimes need disabling for older ocs or Linux, which is

293
00:14:18.080 --> 00:14:18.600
<v Speaker 2>a trade off.

294
00:14:18.639 --> 00:14:21.120
<v Speaker 1>After secure boot, there's trusted boot yes.

295
00:14:21.279 --> 00:14:24.399
<v Speaker 2>In Windows eight point one to ten, Trusted Boot takes

296
00:14:24.440 --> 00:14:27.360
<v Speaker 2>over once secure boot is done. It checks the integrity

297
00:14:27.399 --> 00:14:30.639
<v Speaker 2>of the actual Windows kernel, the core system, files, drivers,

298
00:14:31.159 --> 00:14:32.559
<v Speaker 2>everything as it loads.

299
00:14:32.320 --> 00:14:34.279
<v Speaker 1>And if it finds something modified.

300
00:14:34.039 --> 00:14:37.039
<v Speaker 2>It'll try to repair it automatically. It's another layer ensuring

301
00:14:37.080 --> 00:14:39.120
<v Speaker 2>the OS hasn't been tampered with before you get to

302
00:14:39.159 --> 00:14:40.159
<v Speaker 2>your desktop.

303
00:14:39.840 --> 00:14:42.519
<v Speaker 1>And early launch anti malware.

304
00:14:42.240 --> 00:14:45.679
<v Speaker 2>Elim ELAM is crucial to It lets your anti virus

305
00:14:45.840 --> 00:14:49.720
<v Speaker 2>driver load very early in the boot process before potentially

306
00:14:49.759 --> 00:14:54.080
<v Speaker 2>malicious drivers can. It establishes this chain of trust.

307
00:14:54.000 --> 00:14:56.399
<v Speaker 1>So it checks drivers against a list.

308
00:14:56.440 --> 00:14:59.720
<v Speaker 2>Basically, yeah, if a driver isn't digitally signed and trusted,

309
00:15:00.000 --> 00:15:02.960
<v Speaker 2>ELAM can prevent it from loading, stopping a common way

310
00:15:03.200 --> 00:15:04.879
<v Speaker 2>malware tries to hook into the system.

311
00:15:04.960 --> 00:15:08.480
<v Speaker 1>Okay, so that's boot security. What about active protection While

312
00:15:08.519 --> 00:15:10.200
<v Speaker 1>Windows is running smart Screen?

313
00:15:10.360 --> 00:15:13.200
<v Speaker 2>Windows smart Screen is an online reputation service. When you

314
00:15:13.240 --> 00:15:15.679
<v Speaker 2>download a file or visit a website, it checks it

315
00:15:15.720 --> 00:15:19.840
<v Speaker 2>against Microsoft's constantly updated lists of known malicious sites and files.

316
00:15:19.919 --> 00:15:21.600
<v Speaker 1>Sounds useful. Any downsides?

317
00:15:21.960 --> 00:15:25.120
<v Speaker 2>Well, the warnings can sometimes be a bit vague, users

318
00:15:25.200 --> 00:15:27.799
<v Speaker 2>might just click through them, and unfortunately, it can sometimes

319
00:15:27.799 --> 00:15:30.639
<v Speaker 2>be disabled fairly easily. In browser settings or Windows Settings

320
00:15:30.799 --> 00:15:33.159
<v Speaker 2>without triggering a UAC prompt.

321
00:15:33.320 --> 00:15:36.720
<v Speaker 1>Right. And then there's the main antivirus itself, Windows Defender

322
00:15:37.320 --> 00:15:39.360
<v Speaker 1>or Security Essentials on Windows seven.

323
00:15:39.679 --> 00:15:44.440
<v Speaker 2>Yes, Microsoft's free build in anti virus. It used to

324
00:15:44.440 --> 00:15:46.879
<v Speaker 2>be seen as just basic, but honestly has become quite

325
00:15:46.960 --> 00:15:50.159
<v Speaker 2>robust and deeply integrated into Windows ten and eleven.

326
00:15:49.960 --> 00:15:51.799
<v Speaker 1>So it's good enough for most people.

327
00:15:51.840 --> 00:15:56.799
<v Speaker 2>For baseline protection. Absolutely, it's lightweight, always on. Many businesses

328
00:15:56.840 --> 00:15:59.759
<v Speaker 2>still opt for third party solutions for more advanced features

329
00:15:59.799 --> 00:16:04.120
<v Speaker 2>or central management, but Defender is a solid foundation.

330
00:16:04.399 --> 00:16:07.200
<v Speaker 1>And Defender offline for really tough infections.

331
00:16:07.360 --> 00:16:10.879
<v Speaker 2>That's a really powerful tool built into Windows ten settings,

332
00:16:11.240 --> 00:16:13.879
<v Speaker 2>or you can create a bootable USB for other versions.

333
00:16:14.240 --> 00:16:17.360
<v Speaker 2>It reboots your PC into a special clean environment outside

334
00:16:17.399 --> 00:16:18.159
<v Speaker 2>of Windows to.

335
00:16:18.200 --> 00:16:20.159
<v Speaker 1>Scan before the malware can load.

336
00:16:20.039 --> 00:16:23.679
<v Speaker 2>Exactly, especially good for rootkits that hide from regular scans.

337
00:16:24.120 --> 00:16:26.480
<v Speaker 2>It scans the drive before the main OS and any

338
00:16:26.519 --> 00:16:28.720
<v Speaker 2>resident malware has a chance to interfere.

339
00:16:29.000 --> 00:16:31.519
<v Speaker 1>What about app containers you mentioned those briefly.

340
00:16:31.320 --> 00:16:33.919
<v Speaker 2>Yeah, this is more about how modern Windows store apps work.

341
00:16:34.000 --> 00:16:36.559
<v Speaker 2>They run these isolated containers. Think of them like mini

342
00:16:36.639 --> 00:16:39.559
<v Speaker 2>virtual machines with their own protected storage and memory.

343
00:16:39.639 --> 00:16:41.679
<v Speaker 1>So if one gets infected, it can't easily.

344
00:16:41.360 --> 00:16:45.799
<v Speaker 2>Spread precisely, it's sandboxed. Makes those apps much more resilient

345
00:16:45.799 --> 00:16:48.759
<v Speaker 2>to malware compared to traditional desktop applications.

346
00:16:49.000 --> 00:16:51.960
<v Speaker 1>And even the PC architecture matters thirty two bit versus

347
00:16:52.000 --> 00:16:52.759
<v Speaker 1>sixty four.

348
00:16:52.559 --> 00:16:55.240
<v Speaker 2>Bit it does pretty much. All modern PCs are sixty

349
00:16:55.279 --> 00:16:59.039
<v Speaker 2>four bit now, and that's generally more secure. Why Mainly

350
00:16:59.080 --> 00:17:02.679
<v Speaker 2>because sixty four bit Windows requires hardware and software drivers

351
00:17:02.679 --> 00:17:03.759
<v Speaker 2>to be digitally signed.

352
00:17:03.919 --> 00:17:06.960
<v Speaker 1>Ah that driver signing thing again, yep.

353
00:17:07.160 --> 00:17:09.759
<v Speaker 2>Unsigned drivers are a classic way for malware to get

354
00:17:09.799 --> 00:17:13.640
<v Speaker 2>deep system access, and sixty four bit Windows largely closes

355
00:17:13.720 --> 00:17:17.920
<v Speaker 2>that door. Plus sixty four bit supports virtualization features better,

356
00:17:18.079 --> 00:17:19.799
<v Speaker 2>which underpins some security tech.

357
00:17:19.960 --> 00:17:24.000
<v Speaker 1>Okay, last point on defense, restricting file access. This sounds

358
00:17:24.000 --> 00:17:25.240
<v Speaker 1>critical for ransomware.

359
00:17:25.319 --> 00:17:28.480
<v Speaker 2>Absolutely critical, But it's tricky, especially with cloud backups.

360
00:17:28.519 --> 00:17:30.200
<v Speaker 1>Why tricky? Aren't cloud backups good?

361
00:17:30.759 --> 00:17:33.839
<v Speaker 2>They are? But think about how ransomware works. It encrypts

362
00:17:33.839 --> 00:17:37.359
<v Speaker 2>your files instantly, and your cloud backup software it's designed

363
00:17:37.359 --> 00:17:38.759
<v Speaker 2>to sync changes instantly too.

364
00:17:38.880 --> 00:17:41.240
<v Speaker 1>Oh no, so it backs up the encrypted files often.

365
00:17:41.319 --> 00:17:44.359
<v Speaker 2>Yes, Overwriting your good copies in the cloud with the

366
00:17:44.440 --> 00:17:47.400
<v Speaker 2>useless encrypted versions happens frighteningly. Fast.

367
00:17:47.720 --> 00:17:50.200
<v Speaker 1>So how do you protect your files in this instant

368
00:17:50.240 --> 00:17:52.279
<v Speaker 1>sinc world? Is there a reliable way?

369
00:17:52.920 --> 00:17:56.440
<v Speaker 2>The source strongly suggests the button approach, though not perfect,

370
00:17:56.759 --> 00:18:01.000
<v Speaker 2>is maintaining a periodic completely offline backup a separate external

371
00:18:01.000 --> 00:18:03.160
<v Speaker 2>hard drive that you can act back up to and

372
00:18:03.200 --> 00:18:04.319
<v Speaker 2>then disconnect.

373
00:18:03.880 --> 00:18:07.640
<v Speaker 1>Completely, the digital equivalent of putting valuables in a separate safe.

374
00:18:08.000 --> 00:18:11.240
<v Speaker 2>Exactly that, Because yeah, Murphy's low says, the ransomware will

375
00:18:11.279 --> 00:18:14.240
<v Speaker 2>hit just before your next backup is due, but having

376
00:18:14.319 --> 00:18:17.119
<v Speaker 2>that offline copy is still your best insurance against total

377
00:18:17.160 --> 00:18:17.759
<v Speaker 2>data loss.

378
00:18:17.960 --> 00:18:22.079
<v Speaker 1>Makes sense? Okay, let's shift gears. How do we actually

379
00:18:22.480 --> 00:18:25.960
<v Speaker 1>recognize when an attack might be happening? What are the signs?

380
00:18:26.200 --> 00:18:29.279
<v Speaker 2>Well, Windows PCs are still the biggest target right backwards

381
00:18:29.279 --> 00:18:33.880
<v Speaker 2>compatibility users often running as admin, open networking, just this

382
00:18:33.960 --> 00:18:36.400
<v Speaker 2>sheer number of users, Yeah, it makes them attractive.

383
00:18:36.599 --> 00:18:38.839
<v Speaker 1>And the symptoms what should you look out for?

384
00:18:39.200 --> 00:18:41.880
<v Speaker 2>The common ones are pretty noticeable. Usually your PC suddenly

385
00:18:41.880 --> 00:18:45.039
<v Speaker 2>gets really slow, lots of unexplained disk activity or network traffic.

386
00:18:45.039 --> 00:18:49.400
<v Speaker 1>You don't recognize files not opening or opening strangely.

387
00:18:49.200 --> 00:18:53.480
<v Speaker 2>Yeah, or weird pop ups. Maybe your desktop background changes unexpectedly,

388
00:18:53.599 --> 00:18:57.799
<v Speaker 2>freaking crashes or hangs. Basically, your computer just starts acting weird,

389
00:18:58.319 --> 00:18:59.960
<v Speaker 2>not behaving like it normally does.

390
00:19:00.119 --> 00:19:03.160
<v Speaker 1>Okay, and the source mentioned three main types of viruses

391
00:19:03.160 --> 00:19:04.359
<v Speaker 1>that cause these infections.

392
00:19:04.640 --> 00:19:09.480
<v Speaker 2>Broadly speaking, yes, file infectors, boots sector viruses or root kits,

393
00:19:09.519 --> 00:19:10.799
<v Speaker 2>and macroviruses.

394
00:19:10.880 --> 00:19:13.799
<v Speaker 1>File infectors attached to other files.

395
00:19:13.359 --> 00:19:18.000
<v Speaker 2>Right, They latch onto executables like dot ex files. Antivirus

396
00:19:18.039 --> 00:19:20.880
<v Speaker 2>often catches these by looking for their known signature, a

397
00:19:21.000 --> 00:19:24.440
<v Speaker 2>unique pattern in their code. Remember that fake scanty example,

398
00:19:24.799 --> 00:19:26.480
<v Speaker 2>a fake antivirus program.

399
00:19:26.559 --> 00:19:28.440
<v Speaker 1>Oh yeah, the ones that pop up fake warnings and

400
00:19:28.480 --> 00:19:29.799
<v Speaker 1>demand money exactly.

401
00:19:29.839 --> 00:19:33.400
<v Speaker 2>They'd scare you into paying, sometimes even block legitimate programs

402
00:19:33.400 --> 00:19:35.839
<v Speaker 2>from running. Classic file infector.

403
00:19:35.480 --> 00:19:38.160
<v Speaker 1>Tactic and root kits and boot sector viruses. We know

404
00:19:38.200 --> 00:19:39.680
<v Speaker 1>they're hard to detect, very.

405
00:19:39.519 --> 00:19:42.960
<v Speaker 2>Hard because they load so early, hiding from Windows and

406
00:19:43.000 --> 00:19:46.960
<v Speaker 2>security software. Their payloads can be nasty backdoors for remote

407
00:19:47.000 --> 00:19:50.319
<v Speaker 2>access packet sniffers to steal data traveling over your network,

408
00:19:50.519 --> 00:19:52.960
<v Speaker 2>turning your PC in too part of the DAS botnet.

409
00:19:53.160 --> 00:19:56.759
<v Speaker 1>This is where that nuke it from orbit quote feels appropriate.

410
00:19:56.400 --> 00:19:59.920
<v Speaker 2>Agrees pretty much captures the feeling. Yeah, Removing them cleanly

411
00:20:00.079 --> 00:20:03.200
<v Speaker 2>it can be incredibly difficult. Sometimes a full wipe and

412
00:20:03.240 --> 00:20:05.599
<v Speaker 2>reinstall is the only guaranteed way.

413
00:20:05.640 --> 00:20:07.680
<v Speaker 1>And macroviruses I thought they'd died out.

414
00:20:08.000 --> 00:20:10.480
<v Speaker 2>They did declined for a while after about two thousand.

415
00:20:11.400 --> 00:20:15.400
<v Speaker 2>Macros were originally for automating tasks in office docs, but

416
00:20:15.440 --> 00:20:19.480
<v Speaker 2>they've made a comeback. Modern ones use powerful code like VBA.

417
00:20:19.279 --> 00:20:21.680
<v Speaker 1>Or JavaScript, so they hide in word docks or Excel

418
00:20:21.720 --> 00:20:22.680
<v Speaker 1>sheets exactly.

419
00:20:22.880 --> 00:20:25.359
<v Speaker 2>Microsoft puts warnings up now when you open a dock

420
00:20:25.400 --> 00:20:29.279
<v Speaker 2>with macros, but social engineering tricking you into clicking enable

421
00:20:29.359 --> 00:20:33.480
<v Speaker 2>content is still effective. Once enabled, they can infect your

422
00:20:33.519 --> 00:20:36.640
<v Speaker 2>office templates, so every new document you create gets infected too.

423
00:20:36.920 --> 00:20:39.400
<v Speaker 1>Sneaky, and it comes back to that human factor again.

424
00:20:39.599 --> 00:20:42.000
<v Speaker 1>Email and the Internet are just delivery mechanism.

425
00:20:42.400 --> 00:20:45.000
<v Speaker 2>Precisely, they carry the malware, but it needs you to

426
00:20:45.039 --> 00:20:48.440
<v Speaker 2>click the link, open the attachment, enable the macro. That's

427
00:20:48.480 --> 00:20:49.440
<v Speaker 2>the activation step.

428
00:20:49.480 --> 00:20:51.839
<v Speaker 1>And the scams are getting better, more convincing.

429
00:20:51.640 --> 00:20:55.599
<v Speaker 2>Definitely better wording using graphics from real companies, PDFs that

430
00:20:55.599 --> 00:20:58.480
<v Speaker 2>look legit but have hidden executables. It's much harder to

431
00:20:58.519 --> 00:21:01.839
<v Speaker 2>spot the fakes. Sometimes your vigilance is often the last

432
00:21:01.880 --> 00:21:02.599
<v Speaker 2>line of defense.

433
00:21:03.000 --> 00:21:05.440
<v Speaker 1>So even with all this protection, why do so many

434
00:21:05.480 --> 00:21:08.079
<v Speaker 1>PCs still get infected every year more than half.

435
00:21:08.119 --> 00:21:12.279
<v Speaker 2>You said, it's a frustrating reality. Several reasons. Sometimes the

436
00:21:12.279 --> 00:21:15.160
<v Speaker 2>antivirus just isn't running, or it's way out of date.

437
00:21:15.599 --> 00:21:19.359
<v Speaker 2>It's that constant cat and mouse game. New malware variants

438
00:21:19.359 --> 00:21:22.200
<v Speaker 2>appere daily. Security software has to catch.

439
00:21:22.039 --> 00:21:24.920
<v Speaker 1>Up old unpatched applications, big.

440
00:21:24.880 --> 00:21:31.240
<v Speaker 2>Vulnerability, incorrect security configurations, and sometimes weirdly, having multiple antivirus

441
00:21:31.240 --> 00:21:34.480
<v Speaker 2>programs installed can cause conflicts and actually leave you less

442
00:21:34.480 --> 00:21:36.960
<v Speaker 2>protected than having one good one running properly.

443
00:21:37.039 --> 00:21:39.920
<v Speaker 1>And the motivation is now profit, not fame.

444
00:21:39.920 --> 00:21:42.799
<v Speaker 2>Overwhelmingly profit. Yeah. So malware is designed to be stealthy.

445
00:21:43.000 --> 00:21:45.279
<v Speaker 2>It uses rootkit techniques to hide and might try to

446
00:21:45.279 --> 00:21:48.319
<v Speaker 2>disable your security software, and its main goal is usually

447
00:21:48.400 --> 00:21:52.200
<v Speaker 2>stealing data, your identity or holding your system hostage for ransom.

448
00:21:52.319 --> 00:21:54.799
<v Speaker 1>And if it gets onto a network, its goals.

449
00:21:54.519 --> 00:21:57.720
<v Speaker 2>Are usually to establish backdoors for later access, spread to

450
00:21:57.759 --> 00:22:01.079
<v Speaker 2>other machines on the network, and potentially gain remote control

451
00:22:01.160 --> 00:22:03.920
<v Speaker 2>for launching wider attacks or stealing more data.

452
00:22:03.960 --> 00:22:07.799
<v Speaker 1>Are there specific Windows networking features that are often exploited?

453
00:22:08.160 --> 00:22:11.640
<v Speaker 2>Yeah, vulnerabilities can exist if things aren't locked down properly.

454
00:22:11.920 --> 00:22:16.880
<v Speaker 2>File sharing protocols like SMB network printers, those hidden administrative shares.

455
00:22:17.359 --> 00:22:21.160
<v Speaker 2>They can all be potential entry points if not secured.

456
00:22:20.880 --> 00:22:23.799
<v Speaker 1>Which is why network level security is becoming more important.

457
00:22:23.920 --> 00:22:29.039
<v Speaker 2>Absolutely, having dedicated appliances or services scanning traffic before it

458
00:22:29.079 --> 00:22:32.920
<v Speaker 2>even hits individual PCEs adds a really valuable layer. Security

459
00:22:32.920 --> 00:22:34.240
<v Speaker 2>as a service is a growing area.

460
00:22:34.359 --> 00:22:37.799
<v Speaker 1>So the ideal is both network protection and endpoint protection

461
00:22:37.960 --> 00:22:38.720
<v Speaker 1>on each device.

462
00:22:38.839 --> 00:22:42.160
<v Speaker 2>That's the gold standard. Yes, defense and depth again, cover

463
00:22:42.200 --> 00:22:44.000
<v Speaker 2>the perimeter and protect the individual nodes.

464
00:22:44.160 --> 00:22:47.079
<v Speaker 1>Okay, let's talk about where attacks come from. Moster external right,

465
00:22:47.160 --> 00:22:47.920
<v Speaker 1>the vast majority?

466
00:22:48.000 --> 00:22:51.160
<v Speaker 2>Yeah, over eighty percent in some reports, things like direct

467
00:22:51.160 --> 00:22:56.160
<v Speaker 2>attacks on firewalls, DDS attacks, the usual email viruses and ransomware,

468
00:22:56.640 --> 00:22:59.920
<v Speaker 2>spear phishing and targeted hacking of specific applications.

469
00:23:00.240 --> 00:23:02.759
<v Speaker 1>Firewall attacks and didos Are they just trying to break

470
00:23:02.799 --> 00:23:04.200
<v Speaker 1>in or is there more to it?

471
00:23:04.359 --> 00:23:06.519
<v Speaker 2>Sometimes it's a brute force attempt to find a way.

472
00:23:06.559 --> 00:23:09.200
<v Speaker 2>In other times didos is used as a distraction, a

473
00:23:09.279 --> 00:23:12.200
<v Speaker 2>smoke screen, flood the target with traffic to tie up

474
00:23:12.200 --> 00:23:15.440
<v Speaker 2>their security team while the real attack, maybe data theft,

475
00:23:15.440 --> 00:23:19.680
<v Speaker 2>happens elsewhere. Remember that rustock botnet two point four million

476
00:23:19.759 --> 00:23:23.799
<v Speaker 2>infected PCs just pumping out spam and potentially launching attacks

477
00:23:24.000 --> 00:23:24.880
<v Speaker 2>huge scale, and.

478
00:23:24.880 --> 00:23:27.279
<v Speaker 1>Email attacks still work depressingly well.

479
00:23:27.400 --> 00:23:30.839
<v Speaker 2>They do because they target people. Attackers use tricks like

480
00:23:30.960 --> 00:23:34.720
<v Speaker 2>encrypting or compressing malware attachments to try and sneak past scanners.

481
00:23:35.160 --> 00:23:38.880
<v Speaker 2>We mentioned crypto Locker extorted thirty million dollars. That shows

482
00:23:38.880 --> 00:23:41.480
<v Speaker 2>how effective ransomware via email can be.

483
00:23:41.640 --> 00:23:43.119
<v Speaker 1>How do you even spot ransomware?

484
00:23:43.119 --> 00:23:45.960
<v Speaker 2>Sometimes often it announces itself pretty loudly with a ransom

485
00:23:45.960 --> 00:23:48.680
<v Speaker 2>note pop up, but you might also see specific files,

486
00:23:48.720 --> 00:23:51.880
<v Speaker 2>It creates changes to your system registry keys, or sometimes

487
00:23:51.880 --> 00:23:54.680
<v Speaker 2>it even changes your desktop wallpaper to the ransom demand,

488
00:23:55.000 --> 00:23:56.519
<v Speaker 2>like that p clock two example in.

489
00:23:56.559 --> 00:23:57.880
<v Speaker 1>The source and spearfishing.

490
00:23:58.240 --> 00:24:01.000
<v Speaker 2>That sounds more targeted, much more target it. It's not

491
00:24:01.119 --> 00:24:04.839
<v Speaker 2>generic spam. They use information about you, maybe from your

492
00:24:04.880 --> 00:24:09.160
<v Speaker 2>LinkedIn profile, company, website, social media, to craft a personalized,

493
00:24:09.279 --> 00:24:13.200
<v Speaker 2>highly believable email or message designed to trick you specifically,

494
00:24:13.680 --> 00:24:14.680
<v Speaker 2>much harder to spot.

495
00:24:14.759 --> 00:24:18.640
<v Speaker 1>Then there's hacking specific applications like the talk talk brooch that.

496
00:24:18.720 --> 00:24:21.759
<v Speaker 2>Was a huge one. Yeah twenty fifteen, a teenager used

497
00:24:21.759 --> 00:24:24.279
<v Speaker 2>a basic skal injection attack because talk talk had an

498
00:24:24.319 --> 00:24:27.799
<v Speaker 2>outdated database component on their website, cost them around seventy

499
00:24:27.799 --> 00:24:29.599
<v Speaker 2>five million dollars in fines in recovery.

500
00:24:29.759 --> 00:24:32.480
<v Speaker 1>Wow. So it highlights the need to check everything, not

501
00:24:32.519 --> 00:24:33.640
<v Speaker 1>just the OS.

502
00:24:33.480 --> 00:24:37.799
<v Speaker 2>Everything all your applications, especially webfacing ones, and critically ensuring

503
00:24:37.880 --> 00:24:40.920
<v Speaker 2>any third party services or contractors you use meet your

504
00:24:40.960 --> 00:24:45.200
<v Speaker 2>security standards. Remember the FriendFinder network leak hundreds of millions

505
00:24:45.200 --> 00:24:48.039
<v Speaker 2>of accounts exposed. Application security is vital.

506
00:24:48.119 --> 00:24:51.000
<v Speaker 1>Okay, so external threats are huge, but what about attacks

507
00:24:51.000 --> 00:24:51.759
<v Speaker 1>from inside?

508
00:24:51.880 --> 00:24:55.680
<v Speaker 2>Internal threats are a serious and sometimes overlooked risk. Malicious

509
00:24:55.720 --> 00:24:59.599
<v Speaker 2>activity from current or former employees, contractors, even visitors. It

510
00:24:59.640 --> 00:25:01.640
<v Speaker 2>can be deliberate or purely.

511
00:25:01.319 --> 00:25:03.359
<v Speaker 1>Accidental, accidental like how.

512
00:25:03.319 --> 00:25:07.119
<v Speaker 2>The source puts it starkly, human error opens more doors

513
00:25:07.119 --> 00:25:11.880
<v Speaker 2>to hackers than technical shortcomings. Insiders, intentionally or not, are

514
00:25:11.920 --> 00:25:15.960
<v Speaker 2>involved in maybe a quarter of all attacks, accidentally clicking

515
00:25:16.000 --> 00:25:19.319
<v Speaker 2>a fishing link, bringing in an infected USB drive from home,

516
00:25:19.599 --> 00:25:22.200
<v Speaker 2>ignoring security procedures because they're inconvenient.

517
00:25:22.319 --> 00:25:24.160
<v Speaker 1>It all comes back to people, it often does.

518
00:25:24.240 --> 00:25:27.559
<v Speaker 2>And then there's deliberate social engineering from the inside or

519
00:25:27.920 --> 00:25:31.440
<v Speaker 2>targeting insiders. It's like old school spycraft, manipulating people to

520
00:25:31.440 --> 00:25:33.000
<v Speaker 2>gain access or information, like.

521
00:25:32.920 --> 00:25:37.200
<v Speaker 1>Those WWII keep It under your Hat posters, same idea exactly.

522
00:25:36.880 --> 00:25:40.839
<v Speaker 2>The same psychology. Common tactics today include pretexting, making up

523
00:25:40.839 --> 00:25:44.839
<v Speaker 2>a believable story to get info, baiting, leaving infected USB drives,

524
00:25:44.880 --> 00:25:49.440
<v Speaker 2>labeled salaries or something tempting, lying around, tailgating, just physically

525
00:25:49.480 --> 00:25:51.039
<v Speaker 2>following someone through a secure door.

526
00:25:51.160 --> 00:25:54.839
<v Speaker 1>And the Ashley Madison hack that was suspected to be internal.

527
00:25:54.720 --> 00:25:58.480
<v Speaker 2>Strongly suspected yes, and the fallout was devastating because the

528
00:25:58.519 --> 00:26:01.720
<v Speaker 2>data was so sensitive. Suicide ruined lives. This is a

529
00:26:01.720 --> 00:26:04.279
<v Speaker 2>stark reminder that for businesses holding that kind of data,

530
00:26:04.440 --> 00:26:07.440
<v Speaker 2>security has to be paramount almost to any cost because

531
00:26:07.480 --> 00:26:08.680
<v Speaker 2>the risk is just too high.

532
00:26:08.839 --> 00:26:13.640
<v Speaker 1>Okay, so defenses attacks. If the worst happens and you

533
00:26:13.680 --> 00:26:17.039
<v Speaker 1>suspect an infection, what tools does Microsoft provide to help

534
00:26:17.079 --> 00:26:17.799
<v Speaker 1>you fight back?

535
00:26:18.279 --> 00:26:21.079
<v Speaker 2>Microsoft actually has a pretty good support ecodsystem. The first

536
00:26:21.119 --> 00:26:23.960
<v Speaker 2>place to look is often the Malware Protection Center. It's

537
00:26:24.000 --> 00:26:28.480
<v Speaker 2>their main online security portal. Lots of info, updates, downloads,

538
00:26:28.519 --> 00:26:30.240
<v Speaker 2>and step by step troubleshooting guides.

539
00:26:30.279 --> 00:26:31.680
<v Speaker 1>That sounds useful. What else?

540
00:26:31.839 --> 00:26:35.039
<v Speaker 2>They publish the Microsoft Security Intelligence Report twice a year

541
00:26:35.559 --> 00:26:37.920
<v Speaker 2>that gives you a really good overview of the latest

542
00:26:37.960 --> 00:26:41.000
<v Speaker 2>threats and trends. Helps you understand what attackers are doing

543
00:26:41.079 --> 00:26:41.480
<v Speaker 2>right now?

544
00:26:41.759 --> 00:26:44.200
<v Speaker 1>Are there tools to check your systems configuration?

545
00:26:44.519 --> 00:26:49.759
<v Speaker 2>Yes, the Microsoft Baseline Security Analyzer MBSA. It's free and

546
00:26:49.839 --> 00:26:53.480
<v Speaker 2>it scans your system for common security misconfigurations like missing

547
00:26:53.480 --> 00:26:57.839
<v Speaker 2>security patches or weak user account settings. Surprisingly useful and

548
00:26:57.880 --> 00:26:59.039
<v Speaker 2>not many people know about it.

549
00:26:59.079 --> 00:27:00.799
<v Speaker 1>And Windows Defender it self of course.

550
00:27:00.920 --> 00:27:03.960
<v Speaker 2>Right you're built in antivirus, you can easily go into

551
00:27:03.960 --> 00:27:06.759
<v Speaker 2>Windows Security Settings to check its status, make sure real

552
00:27:06.799 --> 00:27:09.759
<v Speaker 2>time protection is on, see what threats it's found in quarantined,

553
00:27:09.960 --> 00:27:12.440
<v Speaker 2>and manage any false positives where it flags a safe

554
00:27:12.480 --> 00:27:13.279
<v Speaker 2>file by mistake.

555
00:27:13.559 --> 00:27:16.200
<v Speaker 1>Beyond the built in stuff, Microsoft offers other tools.

556
00:27:16.279 --> 00:27:20.759
<v Speaker 2>Yes. Alongside the well known third party options like AVG, Norton, Kasperski,

557
00:27:20.839 --> 00:27:24.680
<v Speaker 2>et cetera. Microsoft has specific removal tools. We mentioned the

558
00:27:24.680 --> 00:27:29.480
<v Speaker 2>Malicious Software Removal Tool MSRT already that monthly updater.

559
00:27:29.200 --> 00:27:32.079
<v Speaker 1>For major threat delivered via Windows updates second Tuesday.

560
00:27:32.240 --> 00:27:35.720
<v Speaker 2>That's the one. Then there's Windows Defender Offline, which we

561
00:27:35.759 --> 00:27:39.480
<v Speaker 2>talked about booting outside Windows for deep scans crucial for rootkits.

562
00:27:39.599 --> 00:27:41.400
<v Speaker 1>How do you launch that in Windows ten?

563
00:27:41.599 --> 00:27:44.720
<v Speaker 2>It's usually right there in the Windows Security Settings under

564
00:27:44.799 --> 00:27:48.480
<v Speaker 2>Virus and Threat Protection scan options, or you can create

565
00:27:48.839 --> 00:27:51.279
<v Speaker 2>bootable media like a USB stick for.

566
00:27:51.279 --> 00:27:52.880
<v Speaker 1>It any other scanners.

567
00:27:52.480 --> 00:27:55.920
<v Speaker 2>There's the Microsoft Safety Scanner. It's a standalone tool you download.

568
00:27:56.359 --> 00:27:59.480
<v Speaker 2>It's designed for one time, on demand scans and expires

569
00:27:59.519 --> 00:28:02.559
<v Speaker 2>after ten days ensure you always get the latest definitions

570
00:28:02.599 --> 00:28:05.160
<v Speaker 2>when you download it. Handy if you think your main

571
00:28:05.200 --> 00:28:07.359
<v Speaker 2>antivirus might be compromised.

572
00:28:06.799 --> 00:28:09.480
<v Speaker 1>And for big companies anything more advanced.

573
00:28:09.799 --> 00:28:13.480
<v Speaker 2>For enterprises, there's the Diagnostics and Recovery tool set DART.

574
00:28:13.960 --> 00:28:16.640
<v Speaker 2>It's part of a larger management pack. It includes offline

575
00:28:16.680 --> 00:28:21.240
<v Speaker 2>tools for troubleshooting and malware hunting, though interestingly the latest

576
00:28:21.279 --> 00:28:25.519
<v Speaker 2>DART ten doesn't bundle Defender anymore. They recommend using Defender

577
00:28:25.559 --> 00:28:27.160
<v Speaker 2>offline separately now.

578
00:28:27.039 --> 00:28:30.480
<v Speaker 1>And the really high end stuff using AI and cloud.

579
00:28:30.359 --> 00:28:35.119
<v Speaker 2>That would be Windows Defender Advanced Threat Protection or ATP now.

580
00:28:35.200 --> 00:28:39.160
<v Speaker 2>Part of the broader Microsoft Defender suite for enterprises uses

581
00:28:39.240 --> 00:28:43.440
<v Speaker 2>machine learning and massive cloud analytics, drawing data from billions

582
00:28:43.440 --> 00:28:46.079
<v Speaker 2>of devices worldwide via Azure.

583
00:28:45.759 --> 00:28:48.000
<v Speaker 1>To spot really advanced attacks.

584
00:28:47.640 --> 00:28:52.359
<v Speaker 2>Exactly, things like zero day exploits or sophisticated targeted attacks

585
00:28:52.599 --> 00:28:55.799
<v Speaker 2>like the Neodemium attack. It detected. It's about spotting subtle

586
00:28:55.799 --> 00:28:58.359
<v Speaker 2>patterns and anomalies across a huge data set.

587
00:28:58.440 --> 00:29:01.960
<v Speaker 1>Very powerful, but what if none of the automatic tools work,

588
00:29:02.240 --> 00:29:05.119
<v Speaker 1>say for a brand new zero day threat. Is manual

589
00:29:05.160 --> 00:29:06.519
<v Speaker 1>removal ever an option?

590
00:29:06.759 --> 00:29:10.160
<v Speaker 2>It's the absolute last resort. Extremely risky if you don't

591
00:29:10.160 --> 00:29:12.920
<v Speaker 2>know exactly what you're doing, but sometimes necessary. The source

592
00:29:12.960 --> 00:29:15.279
<v Speaker 2>walks through an example using a safe test virus from

593
00:29:15.319 --> 00:29:18.640
<v Speaker 2>researchers at cqrt PL just illustrate the process.

594
00:29:18.759 --> 00:29:20.880
<v Speaker 1>What's the very first step sounds critical?

595
00:29:21.240 --> 00:29:25.720
<v Speaker 2>Isolate the PC immediately disconnected from the network, unplug the

596
00:29:25.759 --> 00:29:29.440
<v Speaker 2>Ethernet cable, turn off Wi Fi, stop it spreading further,

597
00:29:29.799 --> 00:29:33.160
<v Speaker 2>or calling home to its command server. Crucial first step.

598
00:29:33.279 --> 00:29:36.200
<v Speaker 1>Then you have to find the actual malware process.

599
00:29:35.839 --> 00:29:39.480
<v Speaker 2>Running right identify the running process. Task manager might not

600
00:29:39.519 --> 00:29:42.000
<v Speaker 2>show it if it's well hidden. You typically use a

601
00:29:42.000 --> 00:29:44.839
<v Speaker 2>more advanced tool like process explore from the CS internal

602
00:29:44.880 --> 00:29:47.839
<v Speaker 2>suite Cause everything else to reduce noise. Then look for

603
00:29:47.880 --> 00:29:51.480
<v Speaker 2>suspicious executables. Process explore can help you find where the

604
00:29:51.480 --> 00:29:54.799
<v Speaker 2>file is located and how it's starting automatically, often via

605
00:29:54.839 --> 00:29:55.440
<v Speaker 2>the registry.

606
00:29:55.559 --> 00:29:57.680
<v Speaker 1>Once you find it, can you just kill the process.

607
00:29:57.880 --> 00:30:00.240
<v Speaker 2>You try to deactivate the malware, but just kill it

608
00:30:00.359 --> 00:30:03.799
<v Speaker 2>might not work. Malware often has washdog processes. That just

609
00:30:03.839 --> 00:30:05.319
<v Speaker 2>restart the main one immediately.

610
00:30:05.400 --> 00:30:06.039
<v Speaker 1>So what do you do?

611
00:30:06.240 --> 00:30:08.839
<v Speaker 2>A trick is to try suspending the process first in

612
00:30:09.000 --> 00:30:12.799
<v Speaker 2>process explorer. That freezes it without terminating it, which might

613
00:30:12.799 --> 00:30:16.920
<v Speaker 2>prevent the watchdog from noticing right away. Then while it's suspended,

614
00:30:17.160 --> 00:30:20.680
<v Speaker 2>you try kill process or kill process tree. You need

615
00:30:20.720 --> 00:30:23.200
<v Speaker 2>to note down the file paths and any registry keys

616
00:30:23.240 --> 00:30:23.680
<v Speaker 2>it's using.

617
00:30:23.839 --> 00:30:25.200
<v Speaker 1>Then you check if it worked.

618
00:30:25.119 --> 00:30:29.720
<v Speaker 2>Yep, test the results. Restart the PC, open process explore again.

619
00:30:30.119 --> 00:30:33.839
<v Speaker 2>Did it come back? The test virus often does, maybe

620
00:30:33.839 --> 00:30:36.599
<v Speaker 2>with a slightly different name, and it puts its startup

621
00:30:36.720 --> 00:30:37.920
<v Speaker 2>entry back in the registry.

622
00:30:38.039 --> 00:30:40.119
<v Speaker 1>So if it reappears, you need stronger medicine.

623
00:30:40.119 --> 00:30:43.839
<v Speaker 2>Exactly. Retest the PC, this time maybe using auto runs.

624
00:30:44.000 --> 00:30:48.240
<v Speaker 2>Another great sance Internal's tool auto runs shows everything set

625
00:30:48.279 --> 00:30:52.599
<v Speaker 2>to start automatically. You look for unsigned entries, often highlighted pink,

626
00:30:53.000 --> 00:30:56.480
<v Speaker 2>especially things loading with wind login. You can uncheck entries

627
00:30:56.519 --> 00:30:58.160
<v Speaker 2>and auto runs to disable.

628
00:30:57.720 --> 00:30:59.039
<v Speaker 1>Them, and then you delete the files.

629
00:30:59.319 --> 00:31:02.720
<v Speaker 2>Finally, yeah, remove the malware. Go to the file locations

630
00:31:02.759 --> 00:31:05.880
<v Speaker 2>you found like Windows temp maybe and delete the actual

631
00:31:05.920 --> 00:31:09.160
<v Speaker 2>malware executables. Then you need to manually edit the registry

632
00:31:09.200 --> 00:31:12.000
<v Speaker 2>to remove the startup entries. You found Auto runs helps

633
00:31:12.039 --> 00:31:15.680
<v Speaker 2>identify these complex malware might have files in registry keys

634
00:31:15.680 --> 00:31:17.880
<v Speaker 2>scattered all over, so it's meticulous.

635
00:31:17.359 --> 00:31:21.279
<v Speaker 1>Work, and removing rootkits is even harder requires booting from Linux.

636
00:31:21.519 --> 00:31:25.480
<v Speaker 2>Rootkit removal often does yes because they hide and protected

637
00:31:25.519 --> 00:31:28.359
<v Speaker 2>boot partitions. You need to boot from a separate OS

638
00:31:28.599 --> 00:31:31.720
<v Speaker 2>like a Linux Live CD or USB to even see

639
00:31:31.759 --> 00:31:35.279
<v Speaker 2>those partitions and files. But messing around in there is

640
00:31:35.319 --> 00:31:39.799
<v Speaker 2>incredibly risky. Playing delete the wrong file and Windows won't

641
00:31:39.799 --> 00:31:42.359
<v Speaker 2>boot at all. Extreme caution needed.

642
00:31:42.359 --> 00:31:45.039
<v Speaker 1>And really advanced users might use bcd eat it.

643
00:31:45.240 --> 00:31:48.119
<v Speaker 2>For the truly brave. Yes, bcd eat it is a

644
00:31:48.160 --> 00:31:51.519
<v Speaker 2>command line tool to edit the boot configuration database. You

645
00:31:51.559 --> 00:31:54.759
<v Speaker 2>could potentially find and remove malicious boot entries, but again,

646
00:31:55.200 --> 00:31:57.359
<v Speaker 2>one wrong command like delete on the wrong entry and

647
00:31:57.400 --> 00:31:59.960
<v Speaker 2>your system is brecked. Definitely expert territory.

648
00:32:00.559 --> 00:32:03.400
<v Speaker 1>So quite a journey. We've gone from floppy diss viruses

649
00:32:03.480 --> 00:32:06.359
<v Speaker 1>to sophisticated ransomware, through layers of defense and into the

650
00:32:06.400 --> 00:32:09.519
<v Speaker 1>weeds of manual removal. It seems clear modern Windows is

651
00:32:09.599 --> 00:32:10.400
<v Speaker 1>much more secure.

652
00:32:10.440 --> 00:32:13.200
<v Speaker 2>It absolutely is compared to older versions. The built in

653
00:32:13.240 --> 00:32:15.279
<v Speaker 2>defenses are significant.

654
00:32:14.920 --> 00:32:17.359
<v Speaker 1>Butt, and it's a big butt that protection relies on

655
00:32:17.480 --> 00:32:21.319
<v Speaker 1>keeping things updated, not messing with default settings, and most importantly,

656
00:32:21.480 --> 00:32:24.039
<v Speaker 1>user vigilance, being aware of what you're clicking.

657
00:32:24.319 --> 00:32:26.839
<v Speaker 2>That's the crux of it, and it's vital to remember.

658
00:32:26.920 --> 00:32:32.240
<v Speaker 2>This landscape changes constantly. Malware evolves, new tools appear, old

659
00:32:32.279 --> 00:32:35.519
<v Speaker 2>ones fade, new threats emerge. You have to stay alert,

660
00:32:35.920 --> 00:32:38.880
<v Speaker 2>keep systems patched, keep users trained.

661
00:32:38.799 --> 00:32:43.440
<v Speaker 1>Because ultimately the biggest vulnerability often isn't the technology.

662
00:32:43.039 --> 00:32:47.880
<v Speaker 2>It's the human element. Building that security awareness, that proactive culture,

663
00:32:48.200 --> 00:32:50.680
<v Speaker 2>whether it's just for yourself or across a whole organization,

664
00:32:50.960 --> 00:32:53.240
<v Speaker 2>that's probably your strongest long term defense.

665
00:32:53.440 --> 00:32:56.319
<v Speaker 1>The source makes a chilling point. The next war will

666
00:32:56.359 --> 00:32:59.799
<v Speaker 1>be fought online, and as hacking gets technically harder, maybe

667
00:32:59.799 --> 00:33:02.880
<v Speaker 1>we'll the attackers focus more on physical access. That infected

668
00:33:03.000 --> 00:33:05.359
<v Speaker 1>USB stick left in the parking lot becomes the way.

669
00:33:05.240 --> 00:33:09.319
<v Speaker 2>In It forces us to think about security holistically, digital

670
00:33:09.519 --> 00:33:10.160
<v Speaker 2>and physical.

671
00:33:10.279 --> 00:33:13.799
<v Speaker 1>Absolutely, So the final thought for you listening is what

672
00:33:13.920 --> 00:33:17.240
<v Speaker 1>steps will you take today, right now to start fortifying

673
00:33:17.279 --> 00:33:18.440
<v Speaker 1>your own digital castle
