Money Matters TV, hosted by Doug Hepburn, CPA/PFS, CFP of Hepburn Financial Advisors, with co-host Dana. The player opens at the cybersecurity segment.
SEVN-X CEO Matt Barnett joined Doug Hepburn on Money Matters TV to talk about where organizational risk has actually moved, how his team breaks into companies for a living, and the specific scams landing on people’s phones. The most useful thing he said costs nothing, requires no software, and takes ten minutes.
The Short Version
Doug described getting a call from someone in Missouri claiming a FedEx package had arrived carrying his name and phone number. He ignored it. Matt told him that was the right instinct, and added that anything genuinely important will come back around on its own.
Then he gave the advice that outperforms most of what gets sold as protection. When something lands demanding action right now, do not act on it. Go get a cup of coffee. Do anything else for ten minutes.
His figure was that nine times out of ten, you will work out on your own that it was fraud. The reason is mechanical rather than mystical. Every one of these campaigns is engineered to hold you inside the first few seconds of your reaction, before the part of your mind that notices inconsistencies has caught up. Ten minutes is roughly how long that takes. Matt’s phrasing was that your logic center kicks back in.
Which means the countermeasure is a habit, not a purchase. Any message that punishes you for pausing is telling you something about itself.
“A long time ago we figured out how to build a firewall.”
Matt Barnett, CEO, SEVN-X
Matt’s point was that the technical perimeter is mature. Firewalls are good, endpoint protection is good, and that category of problem has largely been handled. Attackers responded the way anyone would, by going around it.
What is left is the end user, and the lever is urgency pushed in one of two directions. Either something good is about to happen and you have to claim it, a prize or a gift card, or something bad is about to happen and you have to stop it, losing your job or having an account shut off. Both produce the same outcome, which is a person acting before thinking.
So most attacks now open by compromising a person rather than a system. An email account, a set of corporate credentials, some foothold that belongs to a human instead of a machine.
Doug asked how an organization tests its security, which is a harder question than it sounds. Matt used fire suppression to explain why. You can test a fire alarm by pulling it, and you will learn that the alarm works. You will learn nothing about whether the sprinklers would have put out the fire. Testing security properly means running the whole system against a real attempt, which is why organizations hire an outside firm to behave like an actual attacker.
Then he walked through what that looks like in practice:
What matters most varies by organization. Matt listed the usual candidates: every Windows machine, the banking system, member records, tax returns, whatever the proprietary data happens to be. He described the work as finding one small gap in the armor, then using it to reach the next piece, and the next.
Worth noticing what is absent from that chain. No novel exploit. No zero day. The first two steps use public information, the third depends on somebody having chosen a bad password, and the fourth is a conversation between colleagues. That is the honest shape of most intrusions, and it is why testing that only scans for software vulnerabilities tends to return a clean report on an environment that is trivially reachable.
Matt’s note on AI was not about autonomous attacks. It was that AI has cleaned up the writing. The broken grammar and obvious misspellings that used to give a scam away are gone, so the old advice about spotting typos has quietly stopped working.
The familiar one. A message asks you to click, the link takes you somewhere hostile, and something bad happens. Most people have at least heard of this.
This is the one worth reading twice. Your phone rings and the caller presents as your corporate help desk. There is a problem with your account, and it needs a password reset. They then tell you the specific password to set. You set it. They log in with it.
Notice what that does. Almost every awareness program teaches people that nobody legitimate will ever ask for your password, and that instinct is genuinely useful. This attack never asks. It gives you one. The single rule most staff have internalized simply does not fire, which is what makes it effective against people who consider themselves careful.
SMS versions run on logistics and money: a package has been delivered, an unexpected charge for a new phone, a link that claims to come from the IRS. Cheap to send at enormous volume, and they only need to reach someone who happens to be expecting a delivery.
Asked how corporate security differs from personal security, Matt drew the comparison in defenses first. Organizations run multifactor authentication on everything, or at least they should. They run endpoint protection, which he described as antivirus on steroids wearing a bulletproof vest. They run email gateways and phishing mitigation and a stack of specialist tools. Individuals are working with whatever came bundled with their internet service.
Then he made the sharper point, which is about incentives rather than tools. Losing a thousand dollars of company money is a problem, but it is somebody else’s balance sheet. Losing a thousand dollars from your own checking account is a different experience entirely, and the fear it produces is exactly the thing the attacker is steering. His phrasing was that at that moment they have their hooks into you.
Weaker defenses combined with higher emotional stakes is why going after people in their personal lives works better than going after them at their desks. If you are a business owner, that has an uncomfortable implication: the account most likely to give an attacker their first foothold may not be one your company controls.
“The brain is the gateway to all of the threats.”
Matt Barnett, CEO, SEVN-X
Matt kept returning to this. Whatever the medium, the attack has to pass through your judgment first, which makes that the control worth investing in.
He used drunk driving as the analogy. Not everyone on the highway is impaired, but you know some people are, so you watch for it and you leave room. The volume of these campaigns keeps rising because sending them at scale keeps getting cheaper, and every new breach publishes more raw material to work from.
Not simply a code by text. The actual definition combines two of three categories: something you know, something you have, and something you are. A password plus a code from your phone. A password plus a hardware key on a USB drive. A password plus a biometric, whether that is face, fingerprint, retina, or voice. Any two of the three, so that a stolen password on its own gets nobody anywhere.
Matt declined to endorse a brand and was blunt that consumer antivirus is weak compared to what businesses deploy. He was equally clear that weak beats nothing and it is worth installing. The real danger is what it does to your confidence.
“Vaccines only go so far.”
Matt Barnett, CEO, SEVN-X
Installing something and concluding you are now immune is worse than installing nothing and staying careful.
When this aired, the fresh incident was National Public Data, an aggregator that compiled records for background checks. Matt explained why aggregators draw this kind of attention: they concentrate everything in one place, so a single intrusion yields far more than attacking any individual source would. He put Cambridge Analytica and the wider data brokerage business in the same category.
The scale in that case ran to Social Security numbers for most of the country. As he put it, we had always assumed this data was circulating somewhere for every American, and now there was no need to assume.
Dana asked what it means for the public, and Doug raised the obvious follow-up: with a name, address, birth date, and Social Security number, someone can open credit in your name. Matt walked through the process that normally follows a breach of that size. A forensic investigation, typically funded by the insurer as part of remediation, produces a list of affected people, who then receive a notification explaining what happened and what is being offered, whether that is credit monitoring, identity protection, or reimbursement.
Then he flagged the part almost nobody plans for. That notification is a gift to the next set of attackers.
Register a plausible domain about the breach. Email people telling them they were affected. Offer to enroll them in identity protection. Collect Social Security numbers through the form. You have told someone their most sensitive number is exposed, then invited them to hand it over so you can keep it safe, and it works because the premise is true.
The practical rule follows directly. Treat any message about a breach as a likely scam regardless of whether the breach is real. Do not use the link. Go to the company yourself, type the address, and find the notice on their site. If you want to close off credit fraud specifically, placing a freeze with each of the three major bureaus is free and does not affect existing accounts, and it is a reasonable step whether or not you have been notified.
Asked where the public can keep up, Matt’s answer scaled to appetite. For anyone who wants the deeply technical layer, the r/netsec community is where new exploits and freshly published CVEs, the catalog of Common Vulnerabilities and Exposures, tend to surface first. The security community on X remains active, though it is less concentrated than it once was. For most people, following mainstream coverage and simply knowing the categories of attack is enough to matter.
For the business owners watching
LinkedIn to email convention to weak password to VPN to crown jewels. We run it for real and hand you the map, including which of your people said yes and why. That is what penetration testing is supposed to tell you.
Meet with an expertWait before responding. Matt Barnett’s advice on the show was to step away for ten minutes when something demands immediate action, because urgency is the mechanism these attacks depend on. Most people work out on their own that it was fraud once the pressure to act right now has passed.
All three are social engineering delivered through different channels. Phishing arrives by email, vishing by phone call, and smishing by text message. The goal is the same in each case, which is to get you to hand over credentials or access while you are reacting rather than thinking.
Yes, with realistic expectations. It is considerably weaker than what businesses deploy, and it will not stop an attack that works by convincing you to cooperate. Install it, and do not let it persuade you that you are protected.
Two of three categories: something you know such as a password, something you have such as a phone code or hardware key, and something you are such as a fingerprint or facial scan. A password plus a security question is not multifactor, because both are things you know.
Go to the company’s website directly rather than clicking any link you were sent, and read their notice there. Turn on multifactor authentication for your email first, since email is what attackers use to reset everything else. A credit freeze with each of the three major bureaus is free and blocks new accounts being opened in your name.