MacBook Pro turned-on

Small businesses are the most common ransomware target by volume of incidents, even though many small business owners assume hackers focus on larger organizations. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research.What follows is a step-by-step walkthrough of how a small business gets attacked, written from the attacker’s side. The company in this account is composite, but the methods are accurate to current threat intelligence reporting. After the walkthrough, you’ll see five specific points where the attack would have been stopped by controls that come bundled with security tools most small businesses already pay for.Monday: how I picked youI work regular hours and run a small volume operation. My spreadsheet has about 40 prospects per month, and I prefer businesses between 10 and 50 staff. The reason for that

Free Close-up of a businessman holding and reviewing documents on a wooden desk. Stock Photo

If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled in last time. It’s also more specific. Each new question maps to a control that, if missing, allowed a major 2023 or 2024 claim to escalate. The wording reflects how carriers responded to losses they paid in 2023 and 2024, and how you answer the form matters more than it used to.This post covers why the application got longer, what each new section is asking, how to answer honestly without overstating your controls, and what to fix in the 30 days before submission. The expensive mistake on a cyber insurance application is rescission, where a future claim is denied because the carrier finds that the controls you declared were not in place at the time.Why the renewal application got longerThe current generation of cyber insurance applications was shaped by three specific

Free Business professionals completing a successful deal with a handshake in a modern office setting. Stock Photo

By the time an employee hands in their notice, the decisions that will make their departure clean or messy have already been made. They were made in the first weeks of the person’s tenure, when nobody was paying close attention because the new hire had just arrived and there were a hundred other things to do. A shared login here, a quick SaaS sign-up there, a personal laptop used until the company hardware arrived. By month six, none of those feel like decisions at all. They feel like how things are.This post covers what’s really going wrong when offboarding takes three weeks, the four onboarding shortcuts that guarantee a painful exit, how to retrofit hygiene on the team you already have, and what your IT provider should be doing at onboarding that probably isn’t happening.What’s really going wrong when offboarding takes three weeksA clean offboarding takes about 90 minutes of

a blue background with four different colored squares

A safe Microsoft Copilot rollout starts with a permissions audit before any trial license is enabled. Microsoft 365 Copilot retrieves files, emails, and chats using each user’s existing Microsoft 365 permissions. In most tenants, those permissions are broader than anyone has mapped, because access tends to accumulate across years of projects, ad-hoc sharing, and staff changes. Microsoft itself now recommends a specific cleanup before any trial: map who currently has access to what, fix the permissions that have drifted out of scope, and apply sensitivity labels to confidential content.This post covers what Microsoft 365 Copilot does with permissions, where oversharing tends to show up in a typical tenant, the kinds of content Copilot can return when permissions are broad, how to run the audit Microsoft recommends, and what to fix before any rollout.How Microsoft 365 Copilot accesses your dataCopilot answers questions and generates content by retrieving information through Microsoft Graph,

Free A concentrated professional working at a computer in a modern office setting. Stock Photo

Microsoft has tightened several default settings in Microsoft 365 over the past few years. Newer tenants get more protection out of the box than tenants set up before 2022 or so. The problem is that legacy configurations stay in place. A setting changed for new tenants in 2024 doesn’t retroactively change in yours, and historical user consents, inbox rules, or sharing links granted before the change are still active.Here are five settings worth checking in your tenant, especially if it’s more than two or three years old, was set up by a previous IT provider, or has not been audited in a while.A few caveats before we start. Some of these settings require Microsoft 365 Business Premium, E3, or E5 licensing to change, so if a toggle is grayed out, your license tier is most likely the reason. A couple of these changes will generate support tickets from your team

Free Close-up of hands analyzing insurance policy paperwork with pen on table. Stock Photo

Cyber insurance applications include a question that catches a lot of small business owners off guard: “Do you maintain immutable, air-gapped, or offline backups of your critical business data?”Carriers added that question to renewal forms because ransomware operators worked out that the fastest way to force a payout is to wipe the backups first and encrypt everything else after. CISA, the FBI, and the Internet Crime Complaint Center have all documented this pattern as one of the most common moves in current ransomware playbooks. A business whose backup copies can be deleted using the same admin credentials an attacker just stole has no recovery path other than paying the ransom.This post covers what immutable backup means, three common backup setups that do not qualify, the questions to send your IT provider before you sign the form, and what to do if your honest answer is no.Immutable backup, definedAn immutable backup

Free hacker computer programming vector

Most cyberattacks do not start with a sophisticated intrusion. They start with a click on a personal email, a reused password, or a file uploaded to a familiar cloud service because the approved option felt slower.The Verizon Data Breach Investigations Report found that 68% of breaches involve the human element. Not a zero-day exploit. Not a brute-force attack on a hardened system. Human behavior, in the course of an ordinary working day.For businesses running cloud-based workflows across multiple devices, the personal and professional overlap is now the rule. Understanding where that overlap creates risk is no longer optional. It is a core part of modern security strategy.The Risk Sitting Outside Your Security StackPersonal web habits are not reckless behavior. They are normal behavior.Checking a personal inbox on a work laptop. Logging into a social account during a break. Saving a work password in a browser already loaded with personal accounts. Uploading

Free laptop computer keyboard vector

Your team locks everything down with passwords. Some are strong, some are not, and most have been reused somewhere over the years. Every month, IT fields reset requests. Every year, the same breach reports list stolen credentials as the leading cause.There is now a more effective path, and it does not require users to memorize anything. Passkey migration is the process of moving from traditional passwords to passkeys: a form of phishing-resistant authentication that uses your device’s built-in security instead of a shared secret. It is practical, it is already supported by most major platforms, and the business case is hard to argue with.Why Passwords Are Still the Biggest RiskPasswords have had sixty years to prove themselves. The data tells a consistent story.More than 80% of data breaches involve compromised credentials, a figure that has remained consistent year after year, according to the Verizon Data Breach Investigations Report.The underlying problem has not

Free Detailed view of a silver laptop showing keyboard and multiple ports. Stock Photo

Someone leaves the company on a Friday. By Monday, their email account is disabled, and their laptop is back in the pile.What nobody checks is their login to the project management tool they signed up for in Q3, the cloud storage folder they shared with a contractor, or the CRM access they still have from two roles ago. Three months later, those sessions are still active.This is how zombie accounts form. nNot through negligence, but through an offboarding process built around corporate IT assets that no longer reflects how people actually use software. The average company now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three.What a Zombie Account Actually IsA zombie account is an active login that belongs to someone who no longer works for you. The name is informal. The risk is not.What makes zombie accounts particularly dangerous is that they are valid credentials.There

Person using laptop photo

The most time-consuming ticket in your queue is rarely a hardware failure. It’s the PC infection that started when a user installed something they shouldn’t have been able to. Or it’s the broken configuration left behind after someone changed a setting IT can’t trace.Local administrator rights (the ability to install software, modify system settings, and override security controls) are given to end users far more often than the risk warrants. The usual reason is efficiency. The practical result is the opposite. Machines that drift from baseline, infections that spread before they are caught, and remediation tickets nobody planned for. Revoking local admin rights directly removes the root cause of most of those tickets.The Admin Rights and Support Ticket ConnectionA standard user account limits what software can be installed, what system settings can be changed, and what processes can run at an elevated level. These limits are not arbitrary friction. They are the

1 2 3 21