Cybersecurity
Protecting your users, devices, email and data from evolving threats.
3 articles
Practical guidance on managed IT, cybersecurity, Microsoft 365, backup and business continuity — written for business owners, not for IT specialists.
6 articles
Most businesses do not decide to outsource IT. They reach a point where the current arrangement stops working. Here is how to recognize it early.
Read article
You do not need an enterprise security budget. You do need a small number of controls, configured properly and kept working. Here is the baseline.
Read article
Multi-factor authentication is the highest-value security control available to most small businesses, and one of the least expensive. Here is why, and how to roll it out without a revolt.
Read article
Ransomware is not a single event. It is the visible end of an intrusion that usually began weeks earlier. That changes where the defenses belong.
Read article
A backup job reporting success tells you data was written. It does not tell you the business could recover. Those are different claims.
Read article
Microsoft 365 includes strong security capability. Very little of it is switched on by default. Here is what to review in the environment you already pay for.
Read articleNo articles match your search.
Try a different term, or clear the filters to see all 6 articles.
Most people arrive here holding one of these. Start where you are rather than at the top.
Begin with the security basics and multi-factor authentication. Between them they cover the controls that stop the largest share of what actually happens to small businesses, and neither needs a budget to start.
Read the piece on tested backups, then the one on ransomware. The first is about whether your safety net works; the second is about the event that finds out for you.
Start with the signs a business has outgrown its current setup. It is the least technical piece here and the one most often read by someone who already suspects the answer.
Protecting your users, devices, email and data from evolving threats.
3 articlesGetting more security and more value out of the environment you already pay for.
1 articleMaking sure your data is protected, monitored and genuinely recoverable.
1 articleHow technology gets managed day to day, and what good looks like.
1 articleWhat these are
What these are not
An article can tell you what good looks like. It cannot tell you what is true of your environment, and we will not write as though it can.
We do. Each piece is written by the people who do the work, about problems we have actually had to solve, and nothing here is syndicated filler bought from a marketing library.
That is also why there are six of them and not sixty. We would rather publish something worth the read than fill a content calendar.
No. They are written for the person who has to make the decision and pay for it, not for the person who will implement it. Where a technical term is unavoidable we explain it once rather than assume it.
Much of it, yes, and deliberately so. Turning on multi-factor authentication, testing whether a backup restores, and reviewing who still has access after someone leaves are all things a business can do without hiring anyone.
What we will not pretend is that reading an article is the same as having someone responsible for the outcome. The articles tell you what good looks like; they cannot tell you what is true of your environment.
Threats and products change, and guidance that was right when written can age. Where an article describes something that has materially changed, we update the article rather than leave it and publish a second one contradicting the first.
Yes — quote them, link to them, send them to a colleague or to your current provider. What the site terms ask is that you do not republish them wholesale as if they were someone else’s.
Let’s identify the gaps before they become expensive problems.
Ask it directly. We’ll give you a straight answer, whether or not it leads to working together.