info_outline
Scams, AI Threats & IT Security with Lori Crooks
04/27/2026
Scams, AI Threats & IT Security with Lori Crooks
Cybersecurity isn't just an IT problem anymore — it's a business problem, a consumer problem, and honestly, a people problem. In this episode, we sit down with Lori Crooks, Founder and CEO of Cadra, Inc., a security assessment and management firm helping organizations navigate the complex and ever-evolving world of information security. With nearly two decades of experience across NIST, FedRAMP, HIPAA, PCI, and SOC compliance frameworks, Lori has seen it all — from enterprise-level data breaches to the everyday scams that are catching regular people completely off guard. We get into the compliance side that B2B founders and marketing leaders need to understand, the AI-powered threats that are making scams smarter and harder to spot, and the practical steps anyone can take right now to better protect themselves and their business. This is one of those episodes that hits different whether you're a six-figure founder or just someone who got a sketchy text last week. In this episode we cover: What's actually changed in cybersecurity with the rise of AI The most common scams targeting everyday consumers right now Why third-party tools in your tech stack are a bigger risk than you think How to know when your business needs a real security strategy What FedRAMP and NIST compliance actually mean for growing companies The one thing you can do this week to meaningfully improve your security posture CONNECT WITH LORI Website: cadra.com LinkedIn: Lori Crooks FAQ What is cybersecurity and why does it matter for small businesses? Cybersecurity is the practice of protecting systems, networks, and data from digital attacks. For small and growing businesses, a single breach can mean lost revenue, lost client trust, and serious legal liability — especially if you handle any sensitive customer data. What is FedRAMP and do I need it? FedRAMP (Federal Risk and Authorization Management Program) is a government-wide compliance framework for cloud service providers working with federal agencies. If you're trying to land government contracts or sell into enterprise, understanding FedRAMP is a non-negotiable starting point. What is NIST and how does it apply to my business? NIST (National Institute of Standards and Technology) publishes cybersecurity frameworks that serve as the gold standard for security best practices. Even if you're not in a regulated industry, NIST frameworks give you a solid roadmap for building a security-first culture. How is AI making scams more dangerous? AI is allowing bad actors to create highly personalized phishing emails, deepfake voice calls, and fake websites that are nearly indistinguishable from the real thing. The days of spotting a scam by its bad grammar are largely over. What are the most common scams targeting consumers right now? Phishing emails, smishing (SMS scams), fake invoice fraud, AI voice cloning scams, and social media impersonation are among the most prevalent — and they're getting more sophisticated every year. How do I know if my SaaS tools are putting my business at risk? Start by auditing every third-party tool that has access to your data. Ask vendors for their security documentation, SOC 2 reports, or compliance certifications. If they can't produce them, that's a red flag. What's the difference between a security assessment and a compliance audit? A security assessment evaluates the overall health and risk exposure of your systems. A compliance audit measures whether you meet a specific standard (like HIPAA or PCI DSS). You often need both — assessment first, then audit. Where can I learn more about working with Lori or Cadra? Head to cadra.com or connect with Lori directly on LinkedIn.
/episode/index/show/7900f781-cf84-4c21-9020-4816714b7b9d/id/40766950