top of page
Search


Cyber Insurance Readiness: What Small Businesses Need to Know Before Their Next Renewal
Your cyber insurance renewal questionnaire got longer. A lot longer. Carriers aren't asking if you have security anymore — they want proof it's working. Screenshots, policy exports, tested backup dates, sign-in logs. If you can't produce the documentation, you're looking at higher premiums, coverage limits, or a denial. Here's what they're actually asking for, why it maps to CIS IG1, and what it means for your Microsoft 365 tenant, Google Workspace, file server, NAS, and Acti

Shay
6 hours ago14 min read


What I Check When I Do a Microsoft 365 Tenant Security Review
Most Microsoft 365 tenants I work with have security features that are licensed but never configured, policies that exist but aren't enforcing anything, and accounts that should have been cleaned up months ago. A proper tenant review covers licensing, identity and access controls, email protocol security, device management, Defender configuration, and more. If nobody has walked through your tenant, there's a good chance it's not as secure as you think. I was working in a clie

Shay
3 days ago10 min read


Summer Cybersecurity for Small Business: Why Vacation Season Is Peak Attack Season
Quick Answer Cybercriminals plan around your calendar. When key staff are out, when finance teams are working short, and when employees are checking email from hotel Wi-Fi, attackers move in. Summer cybersecurity for small business is not about adding more tools. It is about closing the gaps that vacation season opens up. That means tightening Microsoft 365 access controls, training your team on travel-specific phishing, locking down public Wi-Fi behavior, and putting wire tr

Shay
May 712 min read


CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2
Three Contractors. Three Different Spots. Same Problem. In the last few months, three different small contractors have reached out to me about CMMC. None of them were in the same place. The first one needs Level 2. They handle CUI, they have a contract that requires it, and we are deep in the work right now. They have a gap assessment from a few years ago, so I am already knocking out the quick-fix items from that list while we get the bigger pieces moving. A C3PAO firm is no

Shay
May 114 min read
bottom of page
