top of page
Search


Microsoft 365 Compliance for Small Business: Building a Better Environment Without Making Work Harder
Moving to Microsoft 365 is only the beginning. This article looks at how Teams, SharePoint, managed devices, backup, access controls, and documentation can work together in a compliance-first environment without making everyday work harder.

Shay
5 days ago16 min read


AI Governance for Small Law Firms: What Happens When Your Employees Are Already Using AI
Your law firm may already be using AI, even if you never officially approved it. I look at shadow AI, client information, AI policies, Microsoft Copilot and the practical steps small law firms can take to put AI governance in place without making it unnecessarily complicated.

Shay
Aug 2114 min read


Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?
Your Microsoft 365 may be working, but is anyone actually managing it? Microsoft changes, your business changes and configurations can drift over time. Here’s what small businesses should know about security, licensing, permissions, Copilot and knowing what is really in place.

Shay
Aug 199 min read


Cybersecurity for Small Law Firms: Microsoft 365 and Business Email Compromise
A law firm's Microsoft 365 environment contains email, client information and conversations involving financial transactions, which makes business email compromise particularly concerning. I look at how BEC works, the Microsoft 365 protections I want configured, why MFA isn't enough by itself, and why firms should periodically check for configuration drift.

Shay
Aug 1711 min read


Microsoft 365 HIPAA Compliance: What Does a Small Medical Practice Actually Need?
I have worked with small healthcare organizations that believed they were HIPAA compliant because they were using Microsoft 365. I understand how they got there. Microsoft talks about HIPAA, provides a Business Associate Agreement for covered services and offers security tools that can be used to protect electronic protected health information, commonly called ePHI. If you are a small practice owner who depends on an outside IT company to manage all of this for you, it is rea

Shay
Aug 1312 min read


Cyber Insurance Readiness: What Small Businesses Need to Know Before Their Next Renewal
Your cyber insurance renewal questionnaire got longer. A lot longer. Carriers aren't asking if you have security anymore — they want proof it's working. Screenshots, policy exports, tested backup dates, sign-in logs. If you can't produce the documentation, you're looking at higher premiums, coverage limits, or a denial. Here's what they're actually asking for, why it maps to CIS IG1, and what it means for your Microsoft 365 tenant, Google Workspace, file server, NAS, and Acti

Shay
Jun 514 min read


Microsoft 365 Tenant Security Review: What I Look for During a Microsoft 365 Audit
Your Microsoft 365 environment may be working every day, but that doesn't mean it is configured, secured or managed the way you think it is. A Microsoft 365 Tenant Audit looks beneath the surface at licensing, identity, devices, Defender, SharePoint, third-party applications, vendor access, backup, AI readiness and the controls protecting your business.

Shay
Jun 227 min read


CMMC Level 1 for Small Businesses: What One Landscaping Company Learned
What does CMMC Level 1 actually look like for a small business? See how one landscaping company strengthened Microsoft 365, identity, endpoints and security while building a better foundation for future government work.

Shay
May 2913 min read


Summer Cybersecurity for Small Business: Why Vacation Season Is Peak Attack Season
Summer travel changes how small businesses work. Learn how to protect Microsoft 365, company devices, email, remote access and business data during vacation season, plus what to review as employees return and summer winds down.

Shay
May 714 min read


CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2
Small government contractors working toward CMMC Level 1 or Level 2 still have to turn cybersecurity requirements into technical controls that actually work. I explain how I approach CMMC technical implementation at SNL-Tech Services, from understanding the existing IT environment and hardening servers, Active Directory and networks to protecting CUI, documenting the environment and maintaining those controls over time.

Shay
May 118 min read


Microsoft 365 Backup for Small Business: Is Your Data Actually Recoverable?
Microsoft 365 includes built in recovery tools, but does your business know what it can actually recover when something goes wrong? Learn how Microsoft 365 backup, OneDrive, SharePoint, retention, and a layered recovery strategy can help protect your small business data.

Shay
Apr 2110 min read


HIPAA Compliance for Law Firms: What Your Practice Needs to Know
Does HIPAA apply to your law firm just because you handle medical records? Not necessarily. I explain when HIPAA may apply to a law firm, what that means for your technology, and what I discovered during an IT Baseline Assessment that uncovered problems with backups, shared accounts, Microsoft 365 security, access controls, and documentation.

Shay
Apr 1720 min read


Microsoft 365 Security for Small Business: What Actually Needs to Be Configured
Microsoft 365 is more than email and Office apps. Learn what small businesses should know about Business Premium, MFA, device management, email security, SharePoint, backups, third-party applications and preparing Microsoft 365 for AI.

Shay
Apr 1421 min read


Microsoft 365 Email Security for Law Firms: What I Found After an Email Account Was Compromised
A suspicious email led to the discovery that a law firm’s Microsoft 365 account had been compromised for months. See what I found, how I investigated the firm’s email environment, and the security changes I implemented to better protect its email, identities, and Microsoft 365 environment.

Shay
Jun 13, 202516 min read


Microsoft Entra ID vs. Local Accounts: What an IT Baseline Assessment Revealed at a Law Firm
What started as a concern about backups turned into a full IT Baseline Assessment and technology overhaul for a small law firm. I uncovered shared accounts, unmanaged computers, an ineffective backup solution, and years of client files stored on an employee’s everyday PC. Here’s how I rebuilt the environment with dedicated file storage, Microsoft Entra ID, stronger Microsoft 365 security, backup, monitoring, and documentation.

Shay
May 30, 202516 min read


Microsoft 365 Security for Small Business: Why You Must Lock It Down by Country
Most small businesses using Microsoft 365 do not realize their accounts are open to the world by default. In this post, I share a real-world example of how I helped a client recover from an email breach, then took their security further with country-based restrictions, passkeys, and Microsoft Defender for Business. Learn how to protect your accounts and keep your data safe.

Shay
May 13, 20258 min read


The Truth About MFA: Why It Wasn't Enough for This Small Business
A real Microsoft 365 account compromise showed why having MFA enabled is only part of the security conversation. Learn how passkeys, phishing resistant authentication, Conditional Access, and Microsoft's changing authentication requirements are reshaping how small businesses protect their accounts.

Shay
Apr 30, 202515 min read


From Outdated IT to HIPAA Readiness: HIPAA Compliance for Small Business
A healthcare business came to me needing to address HIPAA requirements and CARF accreditation, but first we had to understand where their technology stood. This real client story covers the IT Baseline Assessment, security improvements, cloud transition, incident response planning, and how those changes helped the business stay operational when a severe storm later damaged its office and IT equipment.

Shay
Apr 17, 202520 min read
bottom of page
