In this episode of EWA’s FIN-LYT Podcast, Matt Blocki and Chris Pavcic break down the cybersecurity threats most likely to impact individuals today and what you can do right now to protect yourself. While these steps apply to everyone, they are especially critical if you have significant assets at a custodian like Fidelity or Charles Schwab. With the average data breach costing over $4 million globally and ransomware attacks happening every 11 seconds, this conversation is more relevant than ever.
Matt and Chris walk through the layers of protection every person should have in place, starting with your custodians. They cover what Fidelity and Charles Schwab do behind the scenes to protect client accounts, including 24/7 monitoring, insurance coverage, and the ability to lock down outgoing transactions so money cannot be moved without your direct authorization.
From there, they get practical. The conversation covers SIM swap protection, why app-based two-factor authentication is significantly more secure than a text code, how to use a VPN on public Wi-Fi, the importance of a password manager, freezing your credit with all three bureaus, and tools like LifeLock, DeleteMe, and Incogni to monitor and scrub your personal data from the internet. Matt also shares how he uses a dedicated travel phone with no financial accounts when traveling internationally.
This episode is designed to be the 80/20 guide to cybersecurity. You could have all of these steps in place within one to two hours, and they will protect you from the vast majority of threats individuals face today. If you have any questions or want help setting these up, reach out to the EWA team.
Speaker 1 – 00:00
Average data breach now is over $4 million globally. And 80% of small businesses suffered at least one cyber
attack in 2026. And 72% of organizations experience ransomware attempts. There’s all these data brokers that
exist now, and especially with AI, I mean, your information just gets out there.
Speaker 2 – 00:14
If there’s a big data breach, people can buy that data and do anything with it. So that’s what these companies do.
Speaker 1 – 00:20
There’s a huge level of protection difference between getting a text message or an email code versus using an app
based authentication. What can you do to lock yourself down? What should you be looking for someone that
handles your money? What is the 20% of effort you can put in that will get you 80% of the results and protection of
high level risk that we see out there. Everyone should be taking these in the age of 2025 with how easily it is to get
your identity compromised, how much cyber security crime exists out there today? All right, welcome everybody.
Chris, we’re excited to talk about cyber security today. I think why there’s some crazy statistics that we pulled up.
So average data breach now is over $4 million globally. In the US it’s over 10.2 million for business under 500
employees, 3.3 million on average.
Speaker 1 – 01:11
And 80% of small businesses suffered at least one cyber attack in 2026. And 72% of organizations experience
ransomware attempts. And a ransomware attack hits somewhere in the world every 11 seconds. Just crazy. So
obviously this is something, you know, human error is the cause of 60 to 90% of breaches, you know, depending on
the studies that are shown. So today we’re talking about, you know, really three aspects. One, what can you do as
an individual, as a client of ewa or even if you’re not a client, like what can you do to lock yourself down? What
should you be looking for someone that handles your money? So for our clients, like what are we doing behind the
scenes?
Speaker 1 – 01:56
And then third, I think you know, is what, who’s the actual custodian of your money and what is that company doing
to lock and protect your accounts, your money, your hard earned life’s work that you have saved up somewhere. So
three layers. Let’s, you know, let’s cover from a custodian standpoint. So Fidelity and Charles Schwab are main
custodians. So Chris, do you want to hit on a couple points that our custodians do and why we pick those two?
Yeah.
Speaker 2 – 02:25
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
1 / 11
So one of the protections that both Fidelity and Schwab offer are protections around money going in and out of the
accounts. So you can set it up where you have to authorize all outgoing transactions. So whether you know, just
simply need to take a distribution or any monthly recur if you’re retired, anything that’s moving out of the account
needs your authorization.
Speaker 1 – 02:47
So if you’re not planning a distribution,.
Speaker 2 – 02:49
That’s a smart idea. Just have it locked down.
Speaker 1 – 02:52
Yeah, absolutely. And so this, I mean this is something you can, you know, if you think you’ve been compromised,
it’s easy to call. You can call us, we’ll do it on your behalf or you can call, you know, Fidelity or Schwab to do it as
well. So I mean Fidelity from an insurance side has 500,000, you know, of coverage on the SPIC. They also carry
Lloyd’s of London up to 1 billion per customer of securities and 1.9 million per cash per account for cash awaiting
investment. And then Schwab has similar, you know, protocols in place, but they do a ton of monitoring 247 and
infrastructure. And you know, generally speaking, if they’re at fault, you know, these custodians are going to cover
losses. EWA as a firm, you know, we do several things.
Speaker 1 – 03:43
We’ve done a podcast already that we can reference on, you know, what we do from a cybersecurity perspective.
And you know, today we want to talk about primarily what you can do as a client. We have several. I would view
this as not a catch all but you know, what is the 20% of effort you can put in that will get you 80% of the results and
protection of high level risk that we see out there. So Chris, let’s go through these, you know, one by one. What’s
the first one you’d recommend?
Speaker 2 – 04:12
The first one we recommend is to lock your phone number. So SIM swap attacks are one of the easiest ways for
criminals to basically hijack what’s coming through your phone. So think of, if you get a two factor code, somebody
can utilize this method to get that code. Essentially act as you to get in to your accounts or bank accounts,
investment accounts, whatever it is. So you can call your phone carrier, Verizon, AT&T, whoever it is and request
SIM swap protection and port out protection. And what that does is you set up an account PIN that’s specific to
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
2 / 11
you that only you know and anytime like you need that code specifically. So there’s no way for somebody to go in
and change that and basically hijack your phone number.
Speaker 1 – 04:58
Yeah. So key I mean, because I mean think about if someone had your phone, had your, like you didn’t have that.
Yeah, they can pretty much log into everything.
Speaker 2 – 05:06
Yeah, everything. Right.
Speaker 1 – 05:07
So, you know, it’s, it’s crazy how much we carry, how much risk we carry just in this tool. So to go above that, I
always recommend if you’re an international travel like me. So I did a ton of research. I went to the Amazon
rainforest about a little over a year ago just for get off the grid retreat, do some think time. Caught some piranhas
and I came in. While I was there, I had a guide that was pretty crazy. He caught anaconda. He showed me pictures.
We did not catch anaconda, but this guy was fun. But anyway, so just doing research because you know, in Brazil
it’s not the safest, you know, area to get an out of. So I actually didn’t even carry my main phone with me. I got a
travel phone that doesn’t have any financial accounts.
Speaker 1 – 05:48
I was just assuming, okay, someone steals my phone, what’s at risk? They can literally get into my Uber account.
And I even set up a separate travel email specifically for that to link different accounts to. So probably a little bit
over the top from a cautious caution perspective, but anywhere, anytime I leave the United States or anytime I think
I’m in any kind of dangerous city, I’m not carrying my main phone around me. I’m carrying my travel phone that
doesn’t have any financial or two factor authentication to any major account to it. Yeah. So, okay, what’s the
second. Now you mentioned this, but just to reiterate, locking down your financial accounts, this is just a really
simple one. If, if most of your money is at Fidelity or Schwab. So like personally I keep very little in cash.
Speaker 1 – 06:34
If you have a, an investment manager like ewa, something we can set up on your behalf. But again, just give us a
quick hits on how easy this is and if someone needs to lift it. How easy it is to get money out if they need to.
Speaker 2 – 06:45
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
3 / 11
Yeah, it’s simple. It’s just a phone call. So you just need to set it up. And then once it’s, you need to authorize those
transfer flows in and out of the account.
Speaker 1 – 06:54
So, so hypothetically, if Chris, if you have your money at Fidelity and someone gets your login credentials and gets
in, if you have these locks in place, they cannot move money out without calling Fidelity going through a voice
recognition, going through other couple other protocols to actually get the Money out. So even if someone you
know has your credentials having these locks in place, you know, no one’s actually getting the money out. Yeah,
yeah. Which is key. So we recommend this as a default. Unless you’re in distribution mode. Maybe let that one
account that’s handling the distributions. We’ve even for our retired clients, set up a separate account that just
handle the distributions. That way the majority of the account is invested and it’s not touchable in the case of a
breach. So just an extra protocol as well.
Speaker 2 – 07:40
Right.
Speaker 1 – 07:41
So, okay, what’s our third recommendation?
Speaker 2 – 07:44
Yeah, I think this is a good one to follow up on what you’re talking about with travel. Because anytime you’re at an
airport, coffee shop or anything, just killing downtime. It’s easy to jump on a public network. So most people like if
you leave your house and everything, you lock your doors or shut the garage door. But if you’re a lot of people
traveling, you’ll just hop on a public WI FI network with no checks and balances. So that’s one of the easiest ways
for somebody to get your data because somebody that’s sitting on that same wifi network can basically see
everything that’s passing between your device and the public server. So you can use a VPN to basically encrypt
your connection. So there’s a lot of options. I think NordVPN is a big one.
Speaker 1 – 08:32
I use ExpressVPN, I think 12amonth.
Speaker 2 – 08:35
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
4 / 11
And.
Speaker 1 – 08:36
Yeah. No, it’s literally you log. You know, you log in the WI fi. You hit that and then it shows different ip. It’s all
locked down. Yeah. The easiest thing to do is, if you have a cell phone is you can turn this into its own encrypted
hotspot. And that would be secure because then you’re not off the. Someone would need the password.
Speaker 2 – 08:51
Yeah.
Speaker 1 – 08:52
Showed on your phone to get in.
Speaker 2 – 08:53
Right.
Speaker 1 – 08:53
So, yeah, that. That’. Struggle hanging fruit. Never get on a public WI FI network without a VPN attached to it. Or in
lieu of a public. Like a coffee shop, connect to your phone.
Speaker 2 – 09:05
Yeah, for sure.
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
5 / 11
Speaker 1 – 09:06
Or if you have no other. If you don’t have an express, don’t have a phone. Don’t do any serious stuff where you’re on
the WI fi. Like don’t log into any financial accounts, don’t log into your email.
Speaker 2 – 09:17
Right.
Speaker 1 – 09:17
Etc.
Speaker 2 – 09:18
Yeah.
Speaker 1 – 09:18
Maybe check sports.
Speaker 2 – 09:19
And that’s it. Yeah, works.
Speaker 1 – 09:21
All right, so step three or step four, Password manager. You know, don’t use. Don’t repeat the same passwords for
Everything this is, you know, seems common but super important. And there’s other options like Apple has like a
password Manager, there’s LastPass, you know, use a password manager and we’ll get into this. But you can have
keys to get into that. There’s, there’s multiple ways and then the step four is all about two factor authentication. But
there’s a huge difference. We talked about the SIM protection. There’s a huge level of protection difference
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
6 / 11
between getting a text message or an email code versus using an app based authentication. So walk us through,
you know, why two factors important and then what the best kind is.
Speaker 2 – 10:01
So yeah, text based is kind of, that’s like the bare minimum. But if you have like Google Authenticator, Microsoft
Authenticator, like one of those apps, it creates a code that’s specific to the device that you’re using so nobody, no
one else can get it. And it expires after I think like 30 seconds usually. So rather than getting a text code where if
somebody does the SIM thing that were talking about, they could access that code, if you have the two factor, like
an app based two factor, then that gets around that.
Speaker 1 – 10:30
Yeah, anything that accepts two factor I have turned on. Microsoft has it, Google has it. You know, those are pretty
much widely accepted with most big companies. You know, you can lock, add that onto your Fidelity login, your
Schwab login, your, you know, your bank should have it as well.
Speaker 2 – 10:46
Yeah.
Speaker 1 – 10:46
Amazon, if you purchase a lot of stuff, I mean just check everything and try to do the app based authentication if
you can. Yeah, so very easy to do. You know, you go in your app, you scan the, you scan it and then it just
automatically hooks it up. So if you have questions on that in your EWA client, we’re happy to walk you through
how to do that as well. So okay then next step is freeze and credit.
Speaker 2 – 11:09
Yep.
Speaker 1 – 11:10
What, why is this important and how do you do just.
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
7 / 11
Speaker 2 – 11:13
It locks down your credit file so nobody can take out loans or anything in your name. So there’s three bureaus,
Experian, Equifax and TransUnion. So it’s free to do. It doesn’t affect your credit score and you can just lock it and
unlock it whenever based on when you need to take out credit. If you’re buying a car or house or something like
that. If you’re not doing any of those things, you may as well just have it locked so nobody can.
Speaker 1 – 11:35
Yeah. So think about it like, so you have all your money at Fidelity, you have your accounts logged in. So even if
someone gets credentials and gets in, they can’t do anything. Now, someone could take your. They could open up a
loan, they could steal your credit card. Credit cards are protecting against fraud. You know, if you have a big bank
like Chase bank or American Express is getting a capital one, there’s someone steals your car, they’ll get rid of the
charge immediately and they’ll fight it for you behind the scenes. So try to do as much purchasing you can with
credit. Now, the last thing where people get in trouble, if someone opens up a loan in your name, no one’s going to
cover that. So freezing your credit prevents someone from opening up a fraudulent loan in your name.
Speaker 1 – 12:15
You know, whether that’s a line of credit against an asset you own or just an unsecured line of credit. And then on
top of that, we’d recommend, you know, sign up for, you know, LifeLock, for example. We’re going to talk about
monitoring and what to do, how to remove, you know, data brokers out there. But the reason I personally use
LifeLock, the reason I’ve frozen all my credit now, I’m not planning on purchasing anything or taking out any loans
right now. I have my Fidelity accounts frozen and I also have lifelock because if something happens, even with all
of that security, they’re going to cover up to a million dollars, covering legal fees of fighting it and up to a million
dollars.
Speaker 2 – 12:50
Of fraud as well.
Speaker 1 – 12:50
So that’s 30 or 40 bucks a month I recommend, you know, to do as well. So with that being said, there’s other
places you can go to get yourself scrubbed because there’s all these data brokers that exist now, and especially
with AI, I mean, your information just gets out there so quickly. So what are some of the ones we recommend and
what are the prices for those?
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
8 / 11
Speaker 2 – 13:09
Yeah, DeleteMe and Incogni are two good options. They’re both 10, 15amonth. And it continuously scrubs your
data where if anything’s out there, it’s proactively deleting that for you. So well worth it. Relatively cheap and, you
know, protects against any sort of breach or anything like that, because people can, if there’s a big data breach,
people can buy that data and do anything with it. So that’s what these companies do. They’ll scrub and kind of
clean your,.
Speaker 1 – 13:38
Clean your data up. Yeah, yeah. Incogni. So I’ve been a user of Delete Me for a couple years and Incogni recently,
within the last 12 months what I’ve noticed with the cogni though actually it reduces like the spam. I used to get
spam calls like six or seven times a day and I’ll say that’s gone down to like one a day because my phone number
and everything has been eliminated from most places and it’s a constant battle. They’re constantly get a monthly
report from these two places. These are each 10 or 15amonth. But it just the time save just from not checking the
phone when you hear that notification like six times versus one. I mean that’s worth it alone. But also just keeping
yourself scrubbed out of the universe of the dark web out there.
Speaker 1 – 14:15
And so then just to be clear, the gold standard if you really want to protect is get like a Yubikey. It’s 40, 80 bucks. If
you have significant assets. This is a physical, you know, you cannot, you know, someone have to physically get it.
So get that, put it in a safe. If you wanted the absolute gold standard of protecting an account that’s you’re not
going to check regularly and you go into that safe to get it. So. Okay, well. Any closing thoughts, Chris? These are,
this is meant to be not an all encompassing. These are just the basic steps if you haven’t taken, everyone should
be taking these in the age of 20, 26 with how easily it is to get your identity compromised. How much cybersecurity
crime exists out there today?
Speaker 1 – 14:58
This is the 8020 analysis, the 20% of effort you can put in. You know, you could have all of these things done within
one to two hours especially you know, with our help. And it will prevent the majority of what could happen to you
user error on a day to day basis.
Speaker 2 – 15:12
Yeah, no, I think we covered everything so we have that guide built out so we’ll have it on our site and if any clients
have.
Speaker 1 – 15:19
Meeting Title: EP 1 Cybersecurity (to piggyback) on
client inacti…
Meeting created at: 22nd Jun, 2026 – 9:12 AM
9 / 11
Questions, reach out and I would just close with this. You know the other, the majority of cybersecurity crimes that
are going to happen on an individual basis, it could because someone steals something from you physically. So
you know, be careful about your decisions about, you know, where you are, who you’re around and what you carry.
And then secondly is it’s going to be user error. So if you get an email or a call and it’s someone that’s smooth and
suddenly you’re getting information that you shouldn’t be getting, you know, you gotta be on guard. AI voice
impersonation. So the majority of you know, ways that you could still be subject even if you take these is, you
know, criminals are getting smarter and smarter in the age of AI, so you gotta be on high alert.
Speaker 1 – 16:05
You know, in general, do not give your information out. Do not click links in an email that you don’t recognize. You
know, double check, even if it’s from your mom or your brother or whoever is emailing, check the actual email
address and make sure it’s them before you go clicking or responding or, you know, giving any kind of information
over an email or phone call or a text message.
Speaker 2 – 16:24
Yeah, don’t buy gift cards for your CEO or anything like that. It’s probably fake. So that’s a big scam. Have you heard
about that one?
Speaker 1 – 16:31
No, no.
Speaker 2 – 16:32
Well, you’ll get an email. Like, it’ll be from Matt, like, hey, Chris, I’m in a meeting. I need $550 at Best Buy or
something. Like, can you get it? And people fall for it, so. Oh, my goodness. Yeah, yeah, this. Because the gift
cards, they can’t be tracked after you buy it. Just do whatever you want with it.
Speaker 1 – 16:49
So you can buy me some gift cards if you want, Chris.
Speaker 2 – 16:52
All right, send me an email.
Speaker 1 – 16:53
I’ll sell it. Sounds good. Thanks for joining, everybody. We’ll. We’ll catch you next week.