If a work laptop gets stolen, a login password won't stop anyone. They pull the drive out and read every file. Encryption is what makes it unreadable, and it's already built into Windows and Mac. Turn it on for every laptop that leaves the office, start with anyone who travels. #cybersecurity #encr
Geekpoint
@geekpoint.bsky.social
Geekpoint provides no-contract IT solutions, managed services, and cybersecurity for small & micro businesses.
Whoever controls your domain name controls your whole business. Your domain is the address behind your website and your email. It sits in an account at whatever company you registered it with, like GoDaddy. Anyone who can log into that account can point your website and email wherever they like.
Your team is using AI right now, whether you have a policy on it or not. ChatGPT, Gemini, Copilot, Claude, and a dozen niche business tools are in the workflow of someone in your business this week. These tools learn from what you type, sometimes retain it for training, and live outside whatever da
Smishing is text message phishing, and it's now more effective at reaching people than email phishing. The reason is mechanical. Most businesses spent the last decade hardening their email gateways and training people on suspicious links. Almost nobody applied the same effort to text messages. The
Your salesperson stops at a coffee shop between meetings. They set up at a table, open their laptop, order a drink, and walk back to the counter when their name is called. The laptop is unattended for 90 seconds. That's enough time for someone to ruin your business week. The attacker doesn't need t
On May 19, 2026, Google Cloud's automated abuse-detection system incorrectly suspended Railway, one of its largest customers. The decision took Railway's entire platform offline for eight hours and pulled thousands of small businesses down with it. Railway is a platform other businesses use to run
Google Cloud suspended major customer Railway.com without cause, causing outage
Google Cloud suspended major customer Railway.com without cause, causing outage
theregister.com
When an employee leaves your business, the security gap is usually bigger than you'd guess. A typical 25-person business has dozens of cloud accounts per employee. Email, payroll, file storage, CRM, accounting, internal tools, and third-party SaaS subscriptions. When the employee leaves, every
On May 7, 2026, an Amazon Web Services data center overheated and took out an entire availability zone in US-East-1, AWS's most popular region. Several core AWS services went down, and any business application hosted in that zone was unreachable for hours. Cloud outages happen to every major provid
The AWS outage explained: What happened, who was impacted, and what services are back online?
The AWS outage explained: What happened, who was impacted, and what services are back online?
itpro.com
The quarterly review with your IT provider is one of the most useful meetings on your calendar, but it's easy to let it run on autopilot. Walk in with six real questions and you turn it from a status update into a strategic check-in. Six to ask at your next review: 1. What changed in our security
If you deleted a OneDrive file recently and went looking for it in your Recycle Bin… surprise, it's not there. Starting in May 2026, files deleted from OneDrive or SharePoint in the cloud no longer appear in your local Recycle Bin or Trash. They are removed directly from your device and can onl
In May 2026, hackers breached Instructure, the company behind the Canvas learning platform used by thousands of schools and universities. The attackers claimed data on 275 million users across more than 9,000 institutions. That breach didn't just affect Instructure. Every one of those 9,000 institu
“PAY OR LEAK”: Hackers Target Big Higher Ed Vendor
“PAY OR LEAK”: Hackers Target Big Higher Ed Vendor
insidehighered.com
The old rules about strong passwords are out of date. For years the standard advice was eight characters, mix uppercase and lowercase, throw in a number and a symbol. NIST, CISA, and Microsoft's own identity team all moved off that advice years ago. The current recommendation is simpler and stronge
In May 2026, Intuit announced it would lay off around 3,000 employees to refocus the company on AI. Intuit owns QuickBooks, TurboTax, Mailchimp, and Credit Karma. Most small businesses use at least one of these. The layoffs are part of a bigger pattern across the tech industry, where companies buil
Intuit to lay off over 3,000 employees to refocus on AI | TechCrunch
Intuit to lay off over 3,000 employees to refocus on AI | TechCrunch
techcrunch.com
Your office printer is probably the least secured device on your network. Default admin passwords are still in place. The hard drive inside it stores copies of every document scanned or printed in the last few months. Its web interface is exposed to anyone on the same network, and many printers hav
You probably can't list every SaaS tool your business pays for, and that's the first problem. Your business probably runs dozens of SaaS subscriptions, and a lot of them were signed up for once and forgotten. Some are duplicates, some are still paid by people who left, and a few have data sitting i
If you signed up for AI tools over the past 18 months and haven't reviewed them since, you're probably wasting money. A March 2026 audit of 102 small businesses found that 87% had significant waste in their AI subscriptions, with a median of $18,000 wasted per year. Most owners go through the sa
When the same person designs your IT systems and protects them, you've got a built-in conflict of interest. Even a great IT person can't reliably check their own work. Backups, firewall rules, access reviews, incident post-mortems: every one of those checks is done by the same person who built the
In May 2026, Google launched a one-click tool that imports your team's Microsoft 365 user accounts directly into Google Workspace. The feature is built into the Workspace setup flow for very small and small businesses. It pulls user accounts from M365 in a single step, and a separate import handles
Google Workspace Updates: Small businesses can now seamlessly import users from Microsoft to Google Workspace
Google Workspace Updates: Small businesses can now seamlessly import users from Microsoft to Google Workspace
workspaceupdates.googleblog.com
Your primary work email is on every business card, contract, and website. It's also the first thing attackers look for when they're targeting your business. Phishing crews scrape your company website and LinkedIn for the format and patterns of your email addresses. Once they have one address, they
A ransomware group called "The Gentlemen" is one of the fastest-growing names in cybercrime right now. You probably haven't heard of them. In April 2026, The Gentlemen accounted for roughly 10% of all logged ransomware attacks worldwide and climbed into the top three most active ransomware operatio
Cyber Threats Spike in April 2026 as Ransomware Expands and Attack Volumes Climb After Short-Lived Moderation - Check Point Blog April 2026 Cyber Attack Trends: Ransomware & GenAI Risks Surge
Cyber Threats Spike in April 2026 as Ransomware Expands and Attack Volumes Climb After Short-Lived Moderation - Check Point Blog April 2026 Cyber Attack Trends: Ransomware & GenAI Risks Surge
blog.checkpoint.com
Most of the tools your team uses to get work done are probably not on your IT list. Some examples: personal Dropbox accounts for client files, ChatGPT with confidential information pasted in, a Trello board the marketing team set up a year ago, a Notion workspace someone in operations runs from the
If you've ever spent 5 minutes hunting through Teams trying to find a meeting recording, there's a feature you should be using. It's called the Meet app, and it's already built into Teams. No Copilot license required. The Meet app gives you a single dashboard for every meeting you've had or are
Windows 10 hit end of life on October 14, 2025. Microsoft stopped sending free security updates that day. Every new vulnerability discovered since then sits unpatched on every Windows 10 machine that isn't enrolled in Microsoft's paid Extended Security Updates program. The list grows every month. A
If someone asks whether your business has backups, you probably say yes. Disaster recovery is a different question. A backup is a copy of your data. Disaster recovery is the plan that brings your business back to running condition after something goes wrong. The two get confused all the time, and t
In April 2026, ransomware hit Adaptavist, an Atlassian platinum partner that builds and supports tools for thousands of business customers. Adaptavist makes ScriptRunner and similar add-ons that plug into Atlassian products like Jira and Confluence. When attackers got into Adaptavist's systems, eve
Adaptavist Group breach: Ransomware crew claims mega-haul
Adaptavist Group breach: Ransomware crew claims mega-haul
theregister.com
Your incident response plan needs to live on paper, because the second you need it, your computers and email are the thing that's broken. A one-page version beats nothing. The most important piece is the contact list, because those are the phone numbers you can't get to once your systems are down.
"We're too small to be a target" is the most expensive belief in small business security today. The math behind modern attacks runs the opposite direction. Attackers don't sit at desks picking targets one by one. They run automated scans that hit millions of IP addresses every day looking for known
Your business email is worth more than your bank account. Stolen Microsoft 365 credentials remain the most common starting point for SMB breaches in 2026, and the reason isn't just that attackers can read your messages. Once someone has access to your email, they can reset the password for every
In May 2026, the US government's cybersecurity agency added a top-severity Cisco vulnerability to its "fix this now" list. The flaw lives in Cisco SD-WAN controllers. These are the devices many businesses use to connect remote offices, branch locations, or remote workers to their main network. The
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
thehackernews.com
The first 24 hours after a suspected breach decide whether the next six months are manageable or catastrophic. Most of the damage in those hours comes from actions that feel productive but cost you later. The order that works: 1. Stop. Don't touch infected machines or systems. The forensic evidenc