Top 5 Ways You Get Hacked

Top 5 Ways You Get Hacked

🎙 John Hammond 👥 2.2M 📅 September 4, 2025 ⏱ 22 min 👁 22K 📄 opinion experte 🧭 2026-08-17
Available in: English (current) Français

Keywords

MFAransomwareedge devicesnetwork segmentationservice accounts

Summary

In this video, John Hammond reacts to and discusses a blog post by Security Aura titled ‘Ransomware in SMBs: Top 5 Missing or Incomplete Controls.’ The post, written by an active incident responder, outlines the five most common security gaps that lead to ransomware attacks in small and medium businesses. These are: 1) lack of multi-factor authentication (MFA) on external remote services, 2) exposed or unpatched edge devices, 3) lack of basic network segmentation, 4) improper configuration of service accounts, and 5) absence of antivirus/EDR solutions or monitoring. Hammond emphasizes that these are basic IT hygiene issues, not advanced AI threats, and that addressing them can significantly reduce the risk of ransomware. He also discusses the importance of having someone monitor security alerts and the value of Windows Defender as a baseline. The video includes a sponsor segment for Drata, a GRC platform, and concludes with a call to action for SMBs to start small and implement these controls.

159 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights from real-world incident response experience, highlighting that ransomware attacks often succeed due to basic security lapses rather than sophisticated exploits. The argumentation is clear and practical, emphasizing that implementing these five controls can significantly reduce risk. The points are well-supported by examples and the presenter’s credibility, though the reliance on anecdotal evidence and lack of formal data limits the scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The video is based on a blog post by Security Aura, an active incident responder, which adds practical credibility. However, the blog post is not peer-reviewed and lacks formal citations. The title accurately reflects the content. The video includes a sponsor segment for Drata, which is disclosed. The sources cited in the description include the blog post link and affiliate links, but no additional scientific references are provided.

149 words

Title / Content Match

The title accurately reflects the content, which lists and explains the top five ways organizations get hacked, based on the blog post.

Quality & Reliability

8/10

The video is based on a blog post by an active incident responder (Security Aura) and is presented by John Hammond, a well-known cybersecurity educator. The content is practical, based on real-world experience, and aligns with industry best practices. However, it is largely anecdotal and lacks formal citations or peer-reviewed sources.

Key Moments

Cited Sources

Concurring Sources

  • CISA Known Exploited Vulnerabilities Catalog — Mentions CVE-2024-55591, which is listed in this catalog.

External References

Contribution & Novelties

The video provides a practical, experience-based overview of common ransomware attack vectors in SMBs, emphasizing that basic security hygiene is more critical than advanced AI threats. It offers actionable recommendations for improving security posture.

Pour aller plus loin :

70 words

Radar Profile

The radar profile shows high scores in information quantity and quality, indicating a content-rich video with practical insights. The technical level is moderate, making it accessible to a broad audience. The overall reliability is good, but the lack of formal citations and reliance on anecdotal evidence slightly lowers the score.

Reliability 7/10