top of page
Search


AI Governance for Small Law Firms: What Happens When Your Employees Are Already Using AI
Your law firm may already be using AI, even if you never officially approved it. I look at shadow AI, client information, AI policies, Microsoft Copilot and the practical steps small law firms can take to put AI governance in place without making it unnecessarily complicated.

Shay
2 days ago14 min read


Can You Trust AI With Your Business Data? It's the Wrong Question.
Can you trust AI with your business data? I think that's the wrong question. See how I approach AI governance, Microsoft 365 security, employee access, acceptable AI use and responsible AI adoption for small businesses.

Shay
3 days ago12 min read


Cyber Insurance Requirements for Small Businesses: Can You Answer the IT Questions on Your Application?
Cyber insurance applications are asking businesses more detailed questions about MFA, encryption, backups, wire fraud and other security controls. But what if you don't know how to answer them? Here's what those questions can mean for your business and why verifying the answers matters.

Shay
4 days ago13 min read


Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?
Your Microsoft 365 may be working, but is anyone actually managing it? Microsoft changes, your business changes and configurations can drift over time. Here’s what small businesses should know about security, licensing, permissions, Copilot and knowing what is really in place.

Shay
4 days ago9 min read


Cybersecurity for Small Law Firms: Microsoft 365 and Business Email Compromise
A law firm's Microsoft 365 environment contains email, client information and conversations involving financial transactions, which makes business email compromise particularly concerning. I look at how BEC works, the Microsoft 365 protections I want configured, why MFA isn't enough by itself, and why firms should periodically check for configuration drift.

Shay
6 days ago11 min read


CMMC Level 1 Requirements: All 15 Explained in Plain English
In my last article, I talked about a landscaping client who unexpectedly ran into CMMC while working on a bid. They were asked whether their company was CMMC Level 1, Level 2 or Level 3, and they had no idea how to answer the question. Once a small business figures out that CMMC Level 1 may apply, the next question is usually pretty straightforward. What do I actually have to do? CMMC Level 1 has 15 cybersecurity requirements. On paper, that sounds manageable, especially when

Shay
Aug 1415 min read


Microsoft 365 HIPAA Compliance: What Does a Small Medical Practice Actually Need?
I have worked with small healthcare organizations that believed they were HIPAA compliant because they were using Microsoft 365. I understand how they got there. Microsoft talks about HIPAA, provides a Business Associate Agreement for covered services and offers security tools that can be used to protect electronic protected health information, commonly called ePHI. If you are a small practice owner who depends on an outside IT company to manage all of this for you, it is rea

Shay
Aug 1312 min read


CMMC Level 1 for Small Businesses: What Do I Actually Need to Do?
If you own a small business that currently performs work for the Department of War (DoW), or you are considering bidding on DoW contracts for the first time, CMMC Level 1 is something worth understanding before an opportunity lands in front of you. I have seen how quickly this can come up. A client of mine was working on a bid when they came across a question asking for their CMMC level. They own a landscaping company and had never had a reason to think about CMMC before. Now

Shay
Aug 1215 min read


FCI vs. CUI: What Small Government Contractors Actually Need to Know
CMMC can show up on a bid even if you have never thought of your business as a government contractor. I recently had this happen to a small business client who was asked whether they were CMMC Level 1, 2 or 3 and had no idea what the question meant. In this article, I explain FCI, CUI and CMMC in plain language, with examples that make sense for small businesses.

Shay
Aug 1212 min read


Cyber Insurance Readiness: What Small Businesses Need to Know Before Their Next Renewal
Your cyber insurance renewal questionnaire got longer. A lot longer. Carriers aren't asking if you have security anymore — they want proof it's working. Screenshots, policy exports, tested backup dates, sign-in logs. If you can't produce the documentation, you're looking at higher premiums, coverage limits, or a denial. Here's what they're actually asking for, why it maps to CIS IG1, and what it means for your Microsoft 365 tenant, Google Workspace, file server, NAS, and Acti

Shay
Jun 514 min read


Microsoft 365 Tenant Security Review: What I Look for During a Microsoft 365 Audit
Your Microsoft 365 environment may be working every day, but that doesn't mean it is configured, secured or managed the way you think it is. A Microsoft 365 Tenant Audit looks beneath the surface at licensing, identity, devices, Defender, SharePoint, third-party applications, vendor access, backup, AI readiness and the controls protecting your business.

Shay
Jun 227 min read


CMMC Level 1 for Small Businesses: What One Landscaping Company Learned
What does CMMC Level 1 actually look like for a small business? See how one landscaping company strengthened Microsoft 365, identity, endpoints and security while building a better foundation for future government work.

Shay
May 2913 min read


How I Use Claude Cowork to Run My Own IT Business
Claude Cowork is a mode inside the Claude desktop app that works through multi-step tasks on its own, inside an isolated virtual machine on your computer. Here is how I run it on a dedicated machine to handle backup monitoring, security alerts, expenses, and mileage for my IT business, safely.

Shay
May 2714 min read


How I Set Up Claude Teams for a Small Business (Safely)
Claude Teams gives a small business a shared, secure AI workspace, but the tool is only half the job. The other half is governance: a written AI Acceptable Use Policy, clear rules for what data can and cannot go into the tool, and guardrails that match the business's compliance obligations. Done right, it turns multi-hour weekly tasks into minutes without creating a data-leak or compliance problem.

Shay
May 2220 min read


Summer Cybersecurity for Small Business: Why Vacation Season Is Peak Attack Season
Quick Answer Cybercriminals plan around your calendar. When key staff are out, when finance teams are working short, and when employees are checking email from hotel Wi-Fi, attackers move in. Summer cybersecurity for small business is not about adding more tools. It is about closing the gaps that vacation season opens up. That means tightening Microsoft 365 access controls, training your team on travel-specific phishing, locking down public Wi-Fi behavior, and putting wire tr

Shay
May 712 min read


CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2
Small government contractors working toward CMMC Level 1 or Level 2 still have to turn cybersecurity requirements into technical controls that actually work. I explain how I approach CMMC technical implementation at SNL-Tech Services, from understanding the existing IT environment and hardening servers, Active Directory and networks to protecting CUI, documenting the environment and maintaining those controls over time.

Shay
May 118 min read


Microsoft 365 Backup for Small Business: Why Your Data Is Not as Protected as You Think
Most Small Businesses Have This Wrong Their email is in Microsoft 365. Their files are in OneDrive or SharePoint. Everything is in the cloud. So it must be backed up. That assumption is one of the biggest risks I see with Microsoft 365 backup for small business environments. And it is completely understandable. Microsoft is a trusted platform. The data is in the cloud. It feels safe. But there is a difference between availability and backup. And that difference matters a lot

Shay
Apr 216 min read


HIPAA Compliance for Law Firms: What Your Practice Needs to Know
HIPAA compliance for law firms The Assumption That Puts Law Firms at Risk A law firm reached out to me because they were dealing with an email spoofing problem. Unauthorized parties were sending messages that looked like they came from the firm's own domain. Clients were receiving fake emails. The firm had no idea how long it had been happening. When I got into their environment, the email issue was just the beginning. All company files lived on one staff member's computer. E

Shay
Apr 177 min read


AI Governance for Small Businesses: Read This Before Rolling Out AI
AI governance for small businesses showing Shadow AI risks and security controls A client reached out before rolling out AI. That changed everything. A client emailed me recently. Not because something broke.Not because there was a security issue. But because they are starting to use AI tools across their business and wanted to make sure they were doing it the right way. They have already been building workflows. Testing use cases. Figuring out where AI can help their team. N

Shay
Apr 165 min read


Microsoft 365 Security for Small Business: What Actually Needs to Be Configured
Microsoft 365 is more than email and Office apps. Learn what small businesses should know about Business Premium, MFA, device management, email security, SharePoint, backups, third-party applications and preparing Microsoft 365 for AI.

Shay
Apr 1421 min read
bottom of page
