top of page
Search


Still on Windows 10? Here's Why You're Putting Your Business at Risk
Image source Windows 10 reached the end of Microsoft support on October 14, 2025, which means it no longer gets security updates. The computers still work, but any new flaw found in Windows 10 will never be fixed, which makes them easier to attack and can cause problems with compliance and cyber insurance. You have three options: upgrade eligible PCs to Windows 11 for free, pay for Extended Security Updates as a short-term bridge, or replace machines too old to upgrade. Micro
Michelle
Aug 285 min read


What Are Passkeys, and Should Your Business Use Them?
Image source A passkey lets you sign in to an app or website using the same fingerprint, face, or PIN you use to unlock your phone or laptop, with no password to type. It's built on a security standard called FIDO that can't be phished, because the passkey only works on the real site and there's no password to steal or reuse. Most major platforms and a growing list of business tools support passkeys, and Microsoft 365 includes them at no extra cost. For most businesses, it's
Michelle
Aug 245 min read


QR Code Scams: What They Are and How to Protect Your Business
Image source A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company's security. Microsoft reported a 146% rise in QR code phishing during the first quarter of 2026. QR codes are part of normal business now. You scan th
Michelle
Aug 196 min read


How to Stop Scammers From Sending Emails in Your Company's Name
Image source Email spoofing is when a scammer sends a message that appears to come from your domain, often to trick your clients or staff into paying a fake invoice or changing banking details. Three DNS records (SPF, DKIM, and DMARC) prove that a message really came from you and tell receiving mail servers to reject the ones that didn't. The catch is that DMARC only protects you once it's set to "quarantine" or "reject," and a lot of businesses leave it on "none," which moni
Michelle
Aug 146 min read


What to Do in Case of a Cyberattack (Step by Step)
Image source If your business is hit by a cyberattack, the first hour matters. Disconnect the affected devices from the network instead of powering them off, call your IT provider by phone, and leave the evidence in place. If money was wired to a scammer, call your bank right away. This post is the step-by-step plan, plus where to report an attack in the US, UK, and Australia. If a cyberattack hits your business, what you do in the first hour really matters. It's also the eas
Michelle
Aug 105 min read


Who Can See What Your AI Note-Taker Records?
Image source AI note-takers join your meetings, transcribe everything said, and save the recording and summary to the vendor's servers. Who can see that recording depends on the tool. Some keep your data inside your own Microsoft or Google environment and never use it for training, while others store it on their own servers and may use it to improve their AI. Some also auto-join meetings from your calendar without anyone pressing record. Before you let one into a client or st
Michelle
Aug 55 min read


Why Bad Onboarding Is the Real Cause of Messy Offboarding
Image source Offboarding is the final step of a process that started on the employee's first day. Shared logins, forgotten SaaS subscriptions, untracked personal devices, and client relationships locked inside one person's inbox are almost always traceable to informal onboarding shortcuts taken months earlier. Tightening the onboarding side turns each future departure into a 90-minute checklist instead of a three-week cleanup. By the time an employee hands in their notice, th
Michelle
Jul 308 min read


How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy
Image source Cyber insurance applications have grown longer because of specific claim trends from 2023 and 2024, including the MOVEit supply-chain breach, the Change Healthcare ransomware incident, and the Arup deepfake wire fraud. Each new section asks about specific security controls including immutable backups, layered MFA, callback verification on wires, EDR or MDR coverage, vendor risk, and tested incident response. Answers that overstate your security posture can trigge
Michelle
Jul 279 min read


How to Prepare Microsoft 365 Permissions for a Safe Copilot Rollout
Image source Microsoft 365 Copilot retrieves files, emails, and chats using each user's existing Microsoft 365 permissions. In most tenants, those permissions are broader than anyone has mapped, because access accumulates across years of projects and staff changes. A safe Copilot rollout begins with auditing those permissions, fixing the gaps, and applying sensitivity labels to confidential content. Microsoft publishes specific guidance on this cleanup, structured into a pilo
Michelle
Jul 227 min read


What Immutable Backup Means on Your Cyber Insurance Form
Image source Immutable backups are backup copies that nobody can change or delete during a fixed retention period, including administrators and attackers using stolen credentials. Cyber insurance carriers ask about them on renewal applications because ransomware operators routinely destroy backups before encrypting production systems. A backup sitting on your network under regular admin credentials does not qualify. Cyber insurance applications include a question that catches
Michelle
Jul 176 min read


5 Microsoft 365 Settings Worth Checking in Your Tenant
Image source Microsoft has tightened several Microsoft 365 defaults over the past few years, but those changes do not always apply retroactively. Tenants set up before 2022, or configured by a previous IT provider and left alone since, often still have legacy settings in place around file sharing, external email forwarding, third-party app consent, audit log retention, and MFA enforcement. Five settings worth verifying. Microsoft has tightened several default settings in Micr
Michelle
Jul 146 min read


How Small Business Ransomware Attacks Work (And How to Protect Against Them)
Image source Most ransomware operations target small businesses at volume, running through dozens of prospects per month. A 22-person company can be researched in 40 minutes using public records, attacked using session-token theft after a single phishing click, and ransomed within a week. What follows is a step-by-step walkthrough of how that attack unfolds, written from the attacker's perspective, plus the five specific controls that would have stopped it. Each control is in
Michelle
Jul 109 min read


The “Zombie” SaaS Audit: Finding the 3 Apps Your Former Employees Still Access
Image source Most businesses remove a departing employee’s email access quickly, but leave their SaaS access scattered across other tools. Zombie accounts are the leftover logins, tokens, and permissions that remain active after someone leaves or changes roles. A practical SaaS offboarding audit finds where these accounts hide and closes them before they turn into a security incident. Someone leaves the company on a Friday. By Monday, their email account is disabled, and thei
Michelle
Jun 264 min read


Stop the Bleeding: How Revoking Admin Rights Eliminates Support Tickets
Image source Local admin rights used to make software installs and troubleshooting faster, but today they create avoidable risk and constant support noise. Removing admin access reduces malware exposure, limits configuration drift, and eliminates common ticket types caused by unapproved installs and high-impact setting changes. The most time-consuming ticket in your queue is rarely a hardware failure. It’s the PC infection that started when a user installed something they sho
Michelle
Jun 234 min read


What Is Passkey Migration and How Can It Help Your Team Eliminate Passwords?
Image source Passwords remain a leading cause of breaches, yet most teams still rely on them for daily access. Passkey migration replaces passwords over time with device-bound, cryptographic credentials that can’t be phished, reused, or stolen from a server. This shift reduces credential risk and helpdesk friction, and most teams already have the core infrastructure needed to begin. Your team locks everything down with passwords. Some are strong, some are not, and most have b
Michelle
Jun 184 min read


Is Your Invoice a Deepfake? Securing Your Accounts Payable Process Against Voice and Email Cloning
Image source AI-enhanced fraud is changing how criminals target finance teams, especially Accounts Payable. Attackers can use AI to produce convincing emails, realistic invoices, and even cloned voices that bypass the red flags teams once relied on. The most effective defence combines stronger verification steps, tighter payment processes, and a culture where pausing to confirm details is always supported. It’s a statistic that sends a shiver down the backs of SME owners, man
Michelle
Jun 124 min read


Why Human Habits Are Your Biggest Security Risk
Image source Personal web habits are one of the least visible cybersecurity risks businesses face, especially when work and personal life share the same devices, browsers, and identities. Routine behaviour like checking personal email, reusing passwords, or signing into familiar apps can expose business data without anyone intending it. The safest approach reduces exposure with clear guardrails, stronger defaults, and practical coaching rather than restrictive rules that driv
Michelle
Jun 84 min read


Adversary-in-the-Middle Attacks: How Phishing Sites Steal Your Active Login
Image source Adversary-in-the-Middle (AiTM) attacks are a modern phishing technique that steals active login sessions, not just passwords. Understanding how AiTM works helps businesses reduce exposure to phishing-resistant sign-ins, tighter session controls, and faster detection of suspicious access. You click a link, sign in, approve the MFA prompt, and get on with your day. Completely unaware that someone else just logged into your account at the same moment. That scenario
Michelle
Jun 24 min read


LinkedIn "Social Engineering": Protecting Your Staff from Fake Recruitment Scams
Image source A fake recruiter message is one of the cleanest social engineering tricks around because it doesn’t look like a trick. That’s why LinkedIn recruitment scams work so well inside real businesses. They don’t arrive as malware. They arrive as a normal conversation that nudges someone toward one small action: click this link, open this file, “verify” this detail, move the chat to a different app. A few simple checks, a couple of hard-stop rules, and an easy way to rep
Michelle
May 274 min read


Micro-SaaS Vetting: The 5-Minute Security Check for Browser Add-ons
Image source Browser add-ons have a funny reputation. They feel “small”. A quick install. A tiny productivity boost. A harmless little helper that lives in your toolbar. But in practice, a browser extension is more like a micro-SaaS vendor sitting inside your browser session. It can see what you see, interact with the pages you open, and sometimes access the same cloud apps your business runs on all day. That’s why a browser extension security check matters. Not because every
Michelle
May 224 min read
bottom of page
