Online Security III

By Ken McMurray on July 1, 2026

In light of recent cyber security news, we thought it would be a good idea to update you with some of our recommendations on keeping yourself safe in today’s online world.

Secure Your Password(s)

For all financial web sites (investments, banking, insurance, etc.) it is recommended to use very secure passwords: a minimum of 10 characters long, with upper case and lower-case letters, numbers, and special characters. While this may seem complicated, it’s quite simple to do. For example, take a favorite phrase and change a character or two from letters to symbols or numbers. For example, if your phrase is blueboat, change it to Blu3b0aT5%. The position of the keys on a keyboard makes it easy to substitute the numbers on the keys just above certain letters and then add a special character by hitting shift for a second strike of a number key. It speeds the typing and makes remembering the password easier.

Other general guidelines for passwords: never use the same password across sites and change your password every six months (ninety days is even better). Many institutions are already mandating changes to passwords after set time periods.

One way to help keep passwords secure and organized is to use a password tool (RoboForm and Lastpass are just a couple of examples). These tools will help you keep your passwords organized and can help generate secure passwords. Many such tools also analyze your current passwords and tell you how secure they are.

It’s also a good idea to take advantage of Two-Factor Authentication (2FA) whenever you can. The two factors in question are first your regular log in credentials – username and password – and second a unique key code for each new log in. Such key codes can be generated in several ways. In one, the website sends the key code to the email address or cell number of record once the first authentication test – the correct log in credentials – has been passed. Alternatively, a site can work with an Authenticator App (several are available for most smart phones Symantec, Microsoft Authenticator) to request that it generate a code. Both these methods add an extra layer of security.

Two-Factor Authentication is becoming the de facto standard for most financial institutions, so even if your current vendor doesn’t use it today, they probably will very soon.For all financial web sites (investments, banking, insurance, etc.) it is recommended to use very secure passwords: a minimum of 10 characters long, with upper case and lower-case letters, numbers, and special characters. While this may seem complicated, it’s quite simple to do. For example, take a favorite phrase and change a character or two from letters to symbols or numbers. For example, if your phrase is blueboat, change it to Blu3b0aT5%. The position of the keys on a keyboard makes it easy to substitute the numbers on the keys just above certain letters and then add a special character by hitting shift for a second strike of a number key. It speeds the typing and makes remembering the password easier.

Other general guidelines for passwords: never use the same password across sites, and change your password every six months (ninety days is even better). Many institutions are already mandating changes to passwords after set time periods.

One way to help keep passwords secure and organized is to use a password tool (RoboForm and Lastpass are just a couple of examples). These tools will help you keep your passwords organized, and can help generate secure passwords. Many such tools also analyze your current passwords and tell you how secure they are.

It’s also a good idea to take advantage of Two-Factor Authentication whenever you can. The two factors in question are first your regular log in credentials – user name and password – and second a unique key code for each new log in. Such key codes can be generated in several ways. In one, the website sends the key code to the email address or cell number of record once the first authentication test – the correct log in credentials – has been passed. Alternatively, a site can work with an Authenticator App (several are available for most smart phones) to request that it generate a code. Both of these methods add an extra layer of security.

Two-Factor Authentication is becoming the de facto standard for most financial institutions, so even if your current vendor doesn’t use it today, they probably will very soon.

Be Careful Where & When You Click

As a general rule, it’s best to not click on links in emails from financial institutions. It’s much safer to go directly to the institution’s own website, log in there and see if the message of the email is legitimate.

Many phishing emails these days are well crafted and appear quite genuine. But when you really look at the links they contain, you can see that that pleasant looking enquiry from your bank is in fact a nefarious attempt to steal your information.

When using search engines, visually inspect the links before clicking on them to see if they appear valid. If the link shows it’s going to www.microsoft.com.xyz instead of www.microsoft.com, it’s a safe bet that it’s going to send you to a bogus site.

Inspecting links can also be done in email messages, too. Just hover your mouse pointer over a particular link without clicking on it and at the bottom of the window, or in a small pop-up, the underlying link will be displayed. If it doesn’t match what you’re expecting, then the link is probably not good.

Keep Your Computer Safe and Secure

You should always run Anti-Virus software on your computers or devices used to access financial platforms. If you don’t already have some sort of security program installed, make sure you get one. There are paid and free versions. The free versions are often almost as good as those that charge a subscription fee. The primary difference between many paid and free versions is that the paid versions may automate many scan and check routines where these functions will need to be run manually on a periodic basis.

You should also make sure that all security patches for your computer’s operating system are up to date on your devices. Many of the exploits that hackers use can be prevented with the latest security patches.

Lastly, it is a good habit to reboot your devices weekly. This will help to ensure your systems are fully up to date as many update routines only run while your computer is rebooting..

How Does Schultz Collins Protect Our Clients?

For SC clients, we have recently implemented two programs: Trusted Contact and Secret Word.

The Trusted Contact rule directs brokerage firms to obtain the name and contact information for a “trusted contact” for all accounts that are newly opened or updated. The Rule, as espoused by FINRA, enables a firm to communicate with the designated trusted contact whenever there are concerns about a client’s financial management decisions. Such communications will not violate investor privacy or account confidentiality restrictions. Under current standards, the trusted contact does not have any management authority over client assets – unless he is also appointed attorney in fact.

While not yet a widespread practice in the financial industry, the Secret Word will probably become the norm within a few years. The Secret Word comes in handy when someone calls an advisor representing that he is a client, but no one present in the office is familiar with the client’s voice. If the caller can provide the Secret Word, even a new employee who has never met him can feel confident that the caller is indeed the client. It has been a longstanding SC policy to call to confirm all requests regarding financial transactions with our clients directly. So, if we see an email stating “Hi there, I need $50,000 ASAP,” we’re going to call to confirm that this is in fact a legitimate request. The Secret Word is the way we shall do so henceforth management decisions. Such communications will not violate investor privacy or account confidentiality restrictions. Under current standards, the trusted contact does not have any management authority over client assets – unless he is also appointed attorney in fact.

While not yet a widespread practice in the financial industry, the Secret Word will probably become the norm within a few years. The Secret Word comes in handy when someone calls an advisor representing that he is a client, but no one present in the office is familiar with the client’s voice. If the caller can provide the Secret Word, even a new employee who has never met him can feel confident that the caller is indeed the client.

It has been a longstanding SC policy to call to confirm all requests regarding financial transactions with our clients directly. So, if we see an email stating “Hi there, I need $50,000 ASAP,” we’re going to call to confirm that this is in fact a legitimate request. The Secret Word is the way we shall do so henceforth.

What to do if you think or are a victim of cyber-attack?

Should you find yourself the victim of an attack these are a few things you should consider doing immediately, depending on the severity of the breach:

  • Contact your financial advisor
  • Contact your banking and credit card issuers, especially those immediately affected
  • Check your credit reports for any new or suspicious activity
  • Freeze your credit reports (prevents anyone from signing up with for new credit with your stolen information). Thanks to a new federal law that went into effect September 21, 2018, there are no longer charges to freeze/unfreeze your credit file (details on the law https://www.consumer.ftc.gov/blog/2018/09/free-credit-freezes-are-here)
  • Put a fraud alert on your credit report. By the same law change above, these now last a year, rather than 90 days
  • Obtain copies of your credit report. In the case of fraud or identity theft these are usually free upon request from all bureaus every 12 months
  • Change your email password(s)
  • Change your login credentials to all financial sites
  • It may be a good idea to file a police report regarding the breach, as your insurance company may require it for any claims filed
  • Report the theft/breach to the FTC (https://www.identitytheft.gov)
  • Contact telephone and utility companies
  • (Ongoing) Monitor your credit report for any activity. If you have frozen your report, there should be no activity
  • Subscribe to an Identity Protection service such as LifeLock, Identity Guard, PrivacyGuard or many others
  • Other suggestions can be found at https://identitytheft.gov/Steps

Conclusion

These are just a few ways that you can protect yourself while you are navigating the online world. Some of them may sound a bit laborious (securing passwords), but once you get into the practice of protecting your information, you’ll find that you’ll feel more secure in your interactions with all your financial institutions. However laborious these steps may be, a stitch in time saves nine, as the saying goes. We urge you not to neglect them.

Your safety is paramount to us, and we hope you find the information provided not only educational but also reassuring. Should you have any questions or concerns, please don’t hesitate to reach out to one of our team.

Kenneth S. McMurray
SC Information Technologist

Download a copy of the article here.

Third-party links and references are provided solely to share social, cultural and educational information. Any reference in this post to any person, or organization, or activities, products, or services related to such person or organization, or any linkages from this post to the web site of another party, do not constitute or imply the endorsement, recommendation, or favoring of Schultz Collins or Hightower Advisors, LLC, or any of its affiliates, employees or contractors acting on its behalf. Hightower Advisors, LLC, does not guarantee the accuracy or safety of any linked site.


Schultz Collins Investment Counsel is a group comprised of investment professionals registered with Hightower Advisors, LLC, an SEC registered investment adviser. Some investment professionals may also be registered with Hightower Securities, LLC (member FINRA and SIPC). Advisory services are offered through Hightower Advisors, LLC. Securities are offered through Hightower Securities, LLC.

This is not an offer to buy or sell securities, nor should anything contained herein be construed as a recommendation or advice of any kind. Consult with an appropriately credentialed professional before making any financial, investment, tax or legal decision. No investment process is free of risk, and there is no guarantee that any investment process or investment opportunities will be profitable or suitable for all investors. Past performance is neither indicative nor a guarantee of future results. You cannot invest directly in an index.

These materials were created for informational purposes only; the opinions and positions stated are those of the author(s) and are not necessarily the official opinion or position of Hightower Advisors, LLC or its affiliates (“Hightower”). Any examples used are for illustrative purposes only and based on generic assumptions. All data or other information referenced is from sources believed to be reliable but not independently verified. Information provided is as of the date referenced and is subject to change without notice. Hightower assumes no liability for any action made or taken in reliance on or relating in any way to this information. Hightower makes no representations or warranties, express or implied, as to the accuracy or completeness of the information, for statements or errors or omissions, or results obtained from the use of this information. References to any person, organization, or the inclusion of external hyperlinks does not constitute endorsement (or guarantee of accuracy or safety) by Hightower of any such person, organization or linked website or the information, products or services contained therein.

Click here for definitions of and disclosures specific to commonly used terms.

SCHULTZ COLLINS

Legal & Privacy

Form Client Relationship Summary ("Form CRS") is a brief summary of the brokerage and advisor services we offer.
HTA Client Relationship Summary
HTS Client Relationship Summary

Hightower Advisors, LLC is a SEC registered investment adviser. brokercheck.finra.org
© 2026 Hightower Advisors. All Rights Reserved.

Powered By Hightower Logo