
Security Incidents Involving Family Members
Should an Employee Report Security Incidents Involving Family Members? Is your business or job at risk if a bad actor gets access to your family. Will they gain access to you?
Redbot Security’s team often has clients ask our opinion about new technologies they are implementing, remediation strategies, and potential risks. Well, this was an interesting question raised by one of our clients that stirred a lively debate among the security team.
Hey, CSOs and CISOs, here’s an interesting question: Does your yearly risk analysis include what happens to family members of employees? Redbot Security works closely with over 500 companies on and off the clock. This is part of our core values to provide the ‘human element through kindness’ as a trusted advisor before, during, and after security engagements. We don’t charge our clients to provide input for questions about potential security concerns.
“Should employees self-report to the CISO/CSO any potential security incidents that happen to family members?”
Here’s the rub, family members are not employees, and there is a concern that self-reporting, such as account compromises for social media, personal email, or credit cards, could be seen as an invasion of privacy. Typically, what happens to an employee or their family on devices or accounts not controlled by the organization should be considered personal, and organizations should not cross that line. However, given the following situation and potential attack vector, would it be appropriate to have a heads-up from the employee?
Background: Little Suzy, a teenage daughter of Ralph, an executive leader at the local water and waste treatment facility, is a social media influencer among her peers. She constantly shares on Facebook, TikTok, YouTube, and Instagram. Ralph encourages her activity and closely monitors her content for age-appropriate material. Ralph also has a second daughter, Kendra, an accomplished gamer who spends many hours dialed into the latest and greatest games, chat boards, and social events.
Targeting: A malicious actor intends to target the SCADA network where Ralph works. Through OSINT, the malicious actor identifies Ralph as a key individual and stumbles upon his children’s social activities. The malicious actor poses as another gamer and establishes a close relationship with Kendra. Soon the conversation gets a little personal, asking about things like a grandparents’ birthday, the name of the dog, where they went on vacation last year, etc. What Kendra didn’t know was that the conversations provided answers that were the security questions to Suzy’s social media accounts.
The Attack: Within a few hours, the malicious actor has compromised Suzy’s Facebook account and is now sending directed messages with malicious links. Ralph sees a message from Suzy’s account and logs in from a personal computer to review. “Hi, Daddy; I thought this was funny, and you should get one for Mom. [Malicious_Link].”
Outcome: The malicious threat actor executed a payload on Ralph’s personal computer and can now monitor everything he does. As this is a home computer, it didn’t have the protections necessary to identify or alert the malicious code execution to the security staff of the water treatment facility. The family quickly realizes that Suzy’s account was compromised and begins steps to recover her account while looking for potential malware. Nothing is mentioned to the organization, as this was a personal, family issue. The facility was compromised three months later, and the account used to gain the initial foothold belonged to Ralph.
So, let’s begin the debate! Should Ralph have reported his family member’s security incident to the IT or security staff at the waste and water facility? There is no clear answer, and there could be an ethical divide.
From a security professional’s point of view, the most obvious answer is that it would have been beneficial for Ralph to alert the organization. However, Ralph is an executive and may not have wanted to make it publicly known within the company that his family had an issue due to personal or reputational reasons, possibly rooted in fear. Another reason would be that it was a private home computer; he may have felt it was irrelevant to the organization.
Generally, suppose an employee’s family member experiences a cybersecurity event. In that case, it might only be necessary to alert the company’s Chief Security Officer (CSO) or Chief Information Security Officer (CISO) if the incident is directly related to the company, its systems, or its data.
However, there are circumstances where alerting the CSO or CISO could be beneficial:
In any case, fostering a culture of openness and education about cybersecurity is crucial. Employees should feel comfortable reporting potential security issues, and organizations should have clear protocols in place to deal with such incidents. This includes defining what constitutes a reportable incident, who should be notified, and what steps should be taken to address it. Remember that each case is unique, and companies must weigh the potential risk and the employee’s privacy in each situation.
Redbot Security encourages security and IT staff who come across this blog to start an internal dialog that addresses this very issue. Each organization’s outcome will differ and is driven by the ethics or ethos of the individuals participating. Consider adding family awareness and self-reporting of security incidents originating outside the organization as part of the annual security awareness program.
Andrew has 20+ years of hands-on security experience leading teams or working individually on highly technical engagements for a wide variety of commercial and government industries in IT and OT security. Andrew is an active security community leader/member that has developed Redbot Security’s penetration testing methodologies, security policies, attack tools, social engineering tactics, and application and IoT testing guidance. Andrew is able to hack his way into a variety of IT/OT networks, devices and applications and has been known take over entire cities, Simulating Real World Attacks – Before they Become Real…
Senior Level Hands-on-Keyboard
Manual Testing
Get a Project QuoteShould an Employee Report Security Incidents Involving Family Members? Is your business or job at risk if a bad actor gets access to your family. Will they gain access to you?
The likelihood of a cyber attack on a mobile platform is significantly high, but how difficult is it for a malicious actor to generate malware? You might be surprised.
Insecure Direct Object Reference (IDOR) vulnerabilities pose a significant risk to the security of web applications, allowing attackers unauthorized access to sensitive data and functionalities. By understanding the implications of IDOR and adopting secure coding practices, web developers can protect their applications and users from potential exploitation.
Mass Assignment Vulnerability occurs when a web application allows users to submit a more extensive set of data than is intended or safe. The potential consequences of this vulnerability can be severe
Attackers can manipulate the serialized data to execute malicious code, compromise the application, or gain unauthorized access.
Kerberos Authentication Service Response (AS-REP) Roasting, a technique similar to Kerberoasting, has gained prominence as a method for attackers to compromise Active Directory (AD) authentication systems.
Becoming proficient in Operational Technology (OT), Industrial Control Systems (ICS), and Supervisory Control and Data Acquisition (SCADA) network testing can appear daunting as there are fewer learning resources.
Machine Learning (ML) is a subset of AI, and, more than likely, closely aligns with what we consider to be AI in the media.
Recent reports of significant cybersecurity layoffs in the United States have raised concerns about the nation’s preparedness to defend against cyber threats
The FBI released its FY 2024 IC3 Annual Report on April 24, 2025, detailing 859,532 complaints and a record $16.6 billion in losses. In this post, we highlight how phishing, BEC, and cryptocurrency fraud continue to surge, why ransomware remains a top threat to critical infrastructure, and which demographics are most at risk. Plus, discover Redbot Security’s proven strategies,from manual penetration testing to red teaming, that can help you turn IC3 data into actionable defenses.
From API-server exploits to supply-chain threats, this checklist shows how the best penetration testing companies harden Kubernetes. Boost resilience now.
Cybercriminals are ditching malware and exploiting trusted tools already inside your systems. Learn how Living off the Land (LotL) attacks work, and how to stop them.
From pipelines and water systems to power grids and transit networks, U.S. critical infrastructure is under siege. With CISA budget slashed, is a national cyber disaster inevitable?
Understanding NIST 800 and Its Impact on Penetration Testing Requirements.
Internal network penetration testing is essential for identifying security gaps within an organization’s infrastructure. Attackers exploit misconfigured permissions, weak credentials, and unpatched vulnerabilities to escalate privileges and move laterally within networks. A thorough penetration test helps uncover these risks before they are exploited, ensuring stronger security controls, improved access management, and compliance with industry standards. Redbot Security’s expert-led penetration testing provides in-depth assessments to fortify your internal network against evolving threats.
Redbot Security’s senior-level cloud security team brings years of expertise in AWS, GCP, and Azure security. Our approach is rooted in manual-controlled testing and deep-dive security analysis, ensuring that we uncover hidden vulnerabilities that automated tools often miss.
Cymbiotic Hive: The Simple, Rapid-Deployment Solution to Access Management
With data breaches surging by 68% last year alone, cybersecurity has evolved from a low-key technical matter into a defining issue demanding top-level attention.
Increasingly, investors see proactive cybersecurity spending as a hallmark of strong corporate governance. It can be factored into how they value a company’s resilience and risk profile
Our nation is under attack and overwhelmed. Modern Security teams face numerous challenges in managing network and application security effectively.
Our nation is under attack and overwhelmed. Modern Security teams face numerous challenges in managing network and application security effectively.
Is your security team sharing sensitive data unknowingly?
Through repeated random sampling, allows us to simulate a wide array of social engineering attacks with a depth and breadth previously unimaginable.
While penetration testing is valuable in identifying technical vulnerabilities, red teaming provides a more holistic assessment by simulating realistic threat scenarios. By embracing red teaming, organizations can bolster their defenses, uncover weaknesses, and stay one step ahead of sophisticated adversaries.
Malicious actors leveraging OSINT to uncover confidential and sensitive information that is publicly available online. Learn how to prevent risks.
Client-side desyncs are a class of browser-powered HTTP smuggling attacks. What you need to know and how to prevent a malicious actor from taking advantage of this vulnerability.
Active Directory Certificate Services (AD CS) presents various security risks for organizations. This article will help you understand a Relay Attack.
What is an API? APIs, including local and remote, come in various forms and are fundamental to modern software development. They serve as the bridge between different software components, enabling them to work together seamlessly.
While plenty of articles cover the Modbus protocol with varying degrees of detail and usage, this article aims to examine the Modbus protocol with an offensive security lens.
Malicious actors prey on weak configurations like locusts. Microsoft, despite knowing that their operating systems, have inherent weaknesses have done little to enhance their initial security outside of remediation for publicly known vulnerabilities.
The following article is a discussion about helping you to best utilize your military skills to successfully transition into the commercial space.
The following article is a discussion that explores JavaScript Web Tokens
The following article is a discussion that explores Wave Behaviors to Locate Wireless Access Points and Devices
Today, cybercriminals have plenty of entry points to exploit. Therefore, it has become crucial for organizations to improve their attack surface visibility to have more effective protection. This is where attack surface management (ASM) comes into play. This article will explore all about attack surface management (ASM), including its importance, working principle, and benefits.
Check out the latest cybersecurity news around the globe
Over 40 leading cybersecurity professionals and infosec experts have signed an open letter […]
A high severity flaw affecting Broadcom’s Brocade Fabric OS (FOS) has allowed attackers to run […]
width="2490" height="1400" sizes="(max-width: 2490px) 100vw, 2490px">Auf Berlins Info- und […]
CISOs seeking insights into the latest cyberattack trends should note that cybercriminals’ […]
Die Ransomware-Gruppe Akira soll bei Hitachis IT-Services- und Infrastruktur-Tochter zugeschlagen […]
Our expert team will help scope your project and provide a fast and accurate project estimate.
Contact Redbot Security