Security Insights
Expert tips, industry trends, and practical advice to keep your business secure.
Evaluating a Managed IT or Cybersecurity Provider: Criteria That Matter and Red Flags to Watch
Vetting an IT support partner is due diligence, not distrust. This guide covers the specific questions, criteria, and warning signs Canadian and US businesses should use before signing a contract.
Read Article →Vendor Payment Fraud: How Fake Supplier Emails Steal Real Money
FBI data shows US$3.05 billion in reported business email compromise losses in 2025. This post explains how a fake supplier bank-detail email works and how to stop the wire before it clears.
Read Article →Microsoft 365 Anyone With the Link: Finding and Fixing Anonymous Sharing
Microsoft 365 'anyone with the link' sharing creates unauthenticated access that cannot be audited. One provider's audit found more than 35,000 active anonymous links in a roughly 3,000-user environment. Here is how to find yours and close them.
Read Article →Ransomware Now Targets Cloud Credentials: Lessons from a Claimed Attack on a Canadian Distributor
A ransomware group claims to have stolen AWS keys, API credentials, and customer data from a Canadian electrical distributor. Whether verified or not, the pattern is real and the questions every SMB should be asking are the same.
Read Article →A Stolen AI API Key Ran Up $600,000 in Three Weeks at METR
An attacker bypassed login on an employee's AI agent, asked it for its API key, and used about $600,000 in AI credits over three weeks. Why a stolen AI API key is a direct financial risk, and how to limit it.
Read Article →Cybersecurity Assessment for Small Business: What It Actually Covers
A cybersecurity assessment for small business should produce a prioritized list of findings, not a scare list. Here is what a useful one examines and what you should receive at the end.
Read Article →Windows 11 24H2 End of Support Hits October 13, 2026
Windows 11 24H2 Home and Pro stop getting security updates on October 13, 2026. Here's why some managed business fleets won't auto-upgrade to 25H2 in time, and what to check first.
Read Article →Workforce AI Security's 2-Week Trial Maps Your AI Exposure
A 2-week Workforce AI Security trial inventories every AI tool, browser extension, coding agent, and MCP connection your employees use, then delivers a written report of your organization's AI exposure.
Read Article →966 Flaws, Two Zero-Days: Microsoft's September Patch Tuesday Exposes a Deeper Windows Problem
Microsoft's September 2026 Patch Tuesday fixed a record 966 vulnerabilities, including two actively exploited zero-days. Here's why the count keeps climbing, why it isn't only a Microsoft problem, and what SMBs need to automate now.
Read Article →ScreenConnect Is Becoming a Favorite Attacker Tool: How to Detect and Block It
A worm-like campaign is using compromised ScreenConnect installs to spread a four-stage VBScript payload between machines. Here's why remote-access tools keep showing up in incidents, how to spot the signs, and what to block.
Read Article →Chrome's Sixth Zero-Day of 2026: Why Google Keeps Shipping Emergency Patches
Google's emergency fix for CVE-2026-85046 is the sixth actively exploited Chrome zero-day of 2026. Here's what changed, why the pace keeps increasing, and what it costs a business still patching browsers on a monthly cycle.
Read Article →AI Agents Have Deleted Databases: The Guardrails Most Businesses Skip
AI coding agents have wiped production databases and home directories in 2025 and 2026 — one while testing the very safeguard meant to stop it. Here's what reduces the odds of AI mistakes becoming disasters.
Read Article →