<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[MSP Today]]></title><description><![CDATA[Practical cybersecurity insights for small and midsize businesses — real incident breakdowns, plain-language risk explanations, and steps you can actually take]]></description><link>https://www.msptodaynews.com</link><image><url>https://substackcdn.com/image/fetch/$s_!NTAD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb348339-fb2d-4b12-b120-06bf157572bf_1254x1254.png</url><title>MSP Today</title><link>https://www.msptodaynews.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 07 Oct 2026 22:37:40 GMT</lastBuildDate><atom:link href="https://www.msptodaynews.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[MSP Today]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[msptoday@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[msptoday@substack.com]]></itunes:email><itunes:name><![CDATA[MSP Today]]></itunes:name></itunes:owner><itunes:author><![CDATA[MSP Today]]></itunes:author><googleplay:owner><![CDATA[msptoday@substack.com]]></googleplay:owner><googleplay:email><![CDATA[msptoday@substack.com]]></googleplay:email><googleplay:author><![CDATA[MSP Today]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[It Took 72 Days to Notice a €1 Million Fraud]]></title><description><![CDATA[One clicked link. Three weeks of silent watching. Then a real invoice, followed by a fake one, and nobody caught the difference for over two months.]]></description><link>https://www.msptodaynews.com/p/it-took-72-days-to-notice-a-1-million</link><guid isPermaLink="false">https://www.msptodaynews.com/p/it-took-72-days-to-notice-a-1-million</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Wed, 07 Oct 2026 16:47:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rRRC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rRRC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rRRC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!rRRC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!rRRC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!rRRC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rRRC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69245,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214189444?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rRRC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!rRRC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!rRRC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!rRRC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d097299-a269-4b3b-a862-59a9477739b9_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A finance controller at an international organization noticed a large payment hadn&#8217;t arrived. That single observation unraveled a fraud that had been running, quietly and patiently, for more than two months, and had already moved roughly a million euros to accounts the organization didn&#8217;t control.</p><h2>How the Attack Unfolded</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E4h9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E4h9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!E4h9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!E4h9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!E4h9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E4h9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70416,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214189444?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E4h9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!E4h9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!E4h9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!E4h9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46607887-c202-4501-a75a-4ee0d8f57a7c_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It started with an ordinary-looking phishing email sent to multiple staff. One employee clicked the link and entered their login credentials into a fake portal. The organization had multi-factor authentication in place. The attacker got in anyway, using the harvested credentials to access the mailbox of the finance controller directly.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Then, for three weeks, nothing visibly happened. The attacker wasn&#8217;t stealing money yet. They were reading. They studied how invoices were sent, who approved payments, and critically, how the company handled requests to change a supplier&#8217;s bank account details, learning the organization&#8217;s own &#8220;new supplier form&#8221; process well enough to use it convincingly later.</p><p>On day 21, the attacker made their move, but not by inventing a fake invoice from scratch. They waited for the real finance controller, still completely unaware their account was compromised, to send a legitimate invoice to a real client. Right after, the attacker followed up from the same real account with updated bank details, routing the payment to an account they controlled. Investigators later described this as attackers exploiting the organization&#8217;s own legitimate workflow rather than trying to fake one from outside.</p><p>The attacker tried to expand twice more, attempting to compromise additional employee accounts on days 23 and 28. Both attempts failed. It didn&#8217;t matter. By day 44, fraudulent payments were already flowing to attacker-controlled accounts across multiple parts of the organization. Nobody noticed until day 72, when a payment simply didn&#8217;t show up where it should have, and someone finally asked why.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>The number that should concern any business here isn&#8217;t the million euros. It&#8217;s the 72 days. That&#8217;s how long a fully functional, MFA-protected email account sat compromised, with an active attacker inside it, before a human noticed anything was wrong, and only because a payment failed to arrive rather than because any system flagged the intrusion itself.</p><p>This also wasn&#8217;t a poorly run finance department. The fraud worked precisely because it rode on top of a legitimate process the company already had, a real invoice, from a real account, followed by what looked like a normal correction. Attackers increasingly aren&#8217;t inventing fraud from nothing; they&#8217;re patiently learning a real business&#8217;s actual workflow and then inserting themselves into it at the exact right moment.</p><h2>What Actually Would Have Stopped This</h2><p>Two separate gaps allowed this to run as long as it did, and closing either one alone would have limited the damage significantly. The first is detection: continuous monitoring of the mailbox, watching specifically for new logins, unusual mailbox rules, and unfamiliar locations, would very plausibly have caught the initial compromise within minutes rather than weeks. Security researchers involved in the case estimated that with active monitoring in place, the account takeover could have been detected within about ten minutes of the first suspicious login.</p><p>The second gap is procedural, and it&#8217;s the one within full control of any business regardless of budget: a dual-approval requirement for changing anyone&#8217;s banking details, sometimes called a four-eyes rule, where a second person independently confirms any change to payment instructions, ideally by phone, using a number already on file rather than one in the email. That single process change would have stopped this fraud even with the mailbox still fully compromised.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Require independent verification for any change to banking or payment details</strong>, by phone, using a previously known number, never a number or reply provided in the email itself.</p></li><li><p><strong>Monitor mailbox activity continuously</strong>, especially new inbox rules, forwarding changes, and logins from unfamiliar locations or devices.</p></li><li><p><strong>Treat MFA as a strong layer, not a guarantee.</strong> This organization had MFA and was still compromised through a convincing fake login page.</p></li><li><p><strong>Reconcile payments against original invoices promptly</strong>, rather than only noticing when a payment is overdue.</p></li></ul><p>None of this requires a large security budget. It requires one hard rule around changing payment details, and eyes actually watching mailbox activity instead of assuming MFA has it covered. MSP Today&#8217;s trusted tech partner is<a href="https://www.jkcsi.com/"> JK Computer Solution</a>s. If you want a second set of eyes on your setup,<a href="https://www.jkcsi.com/contact/"> get in touc</a>h.</p><div><hr></div><p></p><p><em>Source: <a href="https://www.eye.security/blog/when-business-email-compromise-nearly-costs-a-million-an-incident-response-story">Eye Security, &#8220;When Business Email Compromise Nearly Costs a Million: An Incident Response Story&#8221;</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[8 Gigabytes of Client Data, No Password Required]]></title><description><![CDATA[A single misconfigured cloud database left client contracts, invoices, and staff emails open to anyone who found it. No hacking involved, just a setting nobody double-checked.]]></description><link>https://www.msptodaynews.com/p/8-gigabytes-of-client-data-no-password</link><guid isPermaLink="false">https://www.msptodaynews.com/p/8-gigabytes-of-client-data-no-password</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Tue, 06 Oct 2026 16:44:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!y1wM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y1wM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y1wM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!y1wM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!y1wM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!y1wM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y1wM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78937,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214191979?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y1wM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!y1wM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!y1wM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!y1wM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F390e1810-59b0-4be7-8dc8-527338d174a8_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In mid-May 2026, security researchers scanning the internet for exposed systems found something that shouldn&#8217;t have been reachable at all: a database belonging to Nextcloud, a major European cloud collaboration company, sitting fully open on the public internet with no authentication required. No password. No login screen. Anyone who found the address could browse straight in.</p><h2>How the Attack Unfolded</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SVLT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SVLT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!SVLT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!SVLT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!SVLT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SVLT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214191979?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SVLT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!SVLT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!SVLT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!SVLT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fdb6e2d-1bc2-4923-bc09-4923ed090878_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Inside was roughly 367,000 records totaling about 8 gigabytes: staff email addresses, client company names and addresses, customer contracts, invoice-related correspondence, and internal scripts the company had built for specific clients. Some of it, notably, sat completely unencrypted, meaning sensitive contact details were readable the moment anyone opened the file.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The company traced the cause to what it called a misconfiguration of its hosting infrastructure, not a flaw in its actual product. Once notified, Nextcloud secured the exposed database within two days. The incident became public roughly two months later.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read a story about a major cloud company and assume the lesson doesn&#8217;t apply to a smaller business. It&#8217;s actually the opposite. This wasn&#8217;t a sophisticated hack. Nobody breached a firewall or exploited a zero-day vulnerability. A database was set up, and at some point in that setup, a setting that should have required a login was left open, the same category of mistake that happens constantly when any business spins up a new cloud service, a new database, or a new file share and moves fast to get it working.</p><p>The researchers who found it made the uncomfortable point directly: if their team found the exposed data through routine scanning, malicious actors likely could too, because bots scanning the internet for exactly this kind of misconfiguration run constantly, at scale, with no target list required. An open database doesn&#8217;t need to be found by someone looking for you specifically. It just needs to be found.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t exotic. It&#8217;s a review step that many businesses skip specifically because cloud services feel like someone else&#8217;s responsibility to secure once you&#8217;ve signed up. They aren&#8217;t. Every cloud database, storage bucket, or search index a business spins up needs its access settings explicitly verified as private, not assumed private by default, because defaults vary by provider and by service, and a single missed checkbox is functionally identical to leaving a filing cabinet unlocked in a public lobby.</p><p>The second piece is routine, ongoing scanning of your own external footprint. The same techniques researchers and attackers use to find exposed systems are available to run against your own organization proactively, and catching a misconfigured database yourself, before anyone else finds it, is the difference between a quiet fix and a public disclosure.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Explicitly verify access controls on every cloud database, storage bucket, and search index</strong>, don&#8217;t assume a service is private by default.</p></li><li><p><strong>Encrypt sensitive data at rest</strong>, not just in transit, so a misconfiguration exposes far less even when it happens.</p></li><li><p><strong>Run regular external exposure scans</strong> against your own domains and cloud infrastructure to catch what an attacker&#8217;s scanner would find first.</p></li><li><p><strong>Review access settings any time a new cloud service is stood up</strong>, especially ones spun up quickly to solve an immediate problem, since speed is exactly when this kind of setting gets missed.</p></li></ul><p>None of this requires enterprise tooling or a dedicated security team. It requires treating &#8220;is this actually private&#8221; as a question to verify, not assume, every time something new gets connected to the internet. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup,<a href="https://www.jkcsi.com/contact/"> get in touc</a>h.</p><div><hr></div><p><em>Source: <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach">TechRadar Pro, &#8220;Nextcloud Leaks 367K Records &#8212; European Cloud Giant Exposes Staff and Clients in Major Breach&#8221;</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Your Headcount Doubled. Did Your IT Budget?]]></title><description><![CDATA[A new CrowdStrike survey of small and mid-size businesses shows most owners feel confident about cybersecurity right up until you ask whether their budget actually matches their risk.]]></description><link>https://www.msptodaynews.com/p/your-headcount-doubled-did-your-it</link><guid isPermaLink="false">https://www.msptodaynews.com/p/your-headcount-doubled-did-your-it</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Fri, 02 Oct 2026 12:02:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!i6QG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i6QG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i6QG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!i6QG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!i6QG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!i6QG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i6QG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73525,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214271252?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i6QG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!i6QG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!i6QG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!i6QG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21f2c2a3-cae9-4efd-8b10-b06423a22b08_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9EOW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9EOW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!9EOW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!9EOW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!9EOW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9EOW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214271252?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9EOW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!9EOW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!9EOW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!9EOW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e2d1f43-d0e8-4f7f-bf2f-65d834263fef_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What a New SMB Cybersecurity Report Found</h2><p>CrowdStrike&#8217;s 2025 State of SMB Cybersecurity Report set out to measure the gap between how prepared small and mid-size businesses think they are and how prepared their budgets actually make them. The numbers land on two very different sides of that line. Ninety-three percent of SMBs consider themselves knowledgeable about cybersecurity risks, and 83% say they have a cybersecurity plan in place. On paper, that looks like a confident, well-prepared population of businesses.</p><p>Then the report asks about money, and the confidence evaporates. Only 36% of SMBs are actually investing in new security tools, and just 11% have adopted AI-powered defenses, the kind of tooling increasingly needed to keep pace with automated attacks. Most strikingly, only 6.5% of SMBs believe their current cybersecurity budget is actually sufficient. That&#8217;s not a company here or there feeling stretched. That&#8217;s the overwhelming majority of small and mid-size businesses in the survey knowing, in plain terms, that what they&#8217;re spending doesn&#8217;t match what they need.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The smallest and often fastest-growing businesses come out worst. Among SMBs with fewer than 50 employees, more than half allocate less than 1% of their annual budget to cybersecurity, and only 47% have a security plan at all, well below the 83% average across the broader SMB population. When it comes to actually choosing tools, 67% of SMBs prioritize affordability over protection against advanced threats, which only 57% ranked as a top priority. That&#8217;s a rational response to a real budget constraint, and also exactly the kind of tradeoff that leaves gaps.</p><p>Those gaps show up as incidents. Among SMBs with fewer than 25 employees that experienced a security incident, 29% involved ransomware, compared with 19% among larger SMBs. Smaller, leaner organizations, the ones most likely to be adding headcount, opening new locations, and growing revenue without a matching IT buildout, are getting hit by the most disruptive category of attack at a higher rate than their larger peers.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>None of this is a story about companies that ignore security. It&#8217;s a story about companies that plan for it on paper and then can&#8217;t fund it in practice, which describes a lot of growing small and mid-size businesses. You hire five people this quarter, open a second office, add a new line of business, and your revenue climbs. Nobody sits down and asks whether the IT budget needs to climb along with it, because IT spending doesn&#8217;t announce itself as urgent the way payroll or rent does. It just quietly falls further behind the size of the company it&#8217;s supposed to protect.</p><p>That&#8217;s exactly the pattern the CrowdStrike numbers describe: a company with a real plan and real awareness, but a budget that was set for a smaller, simpler version of itself. Every new employee is another endpoint, another set of credentials, another person who can click the wrong link. Every new location is another network to secure. If the budget doesn&#8217;t grow with the business, the business is effectively getting less secure every quarter, even while everyone involved believes they&#8217;re doing the right things.</p><h2>What Growing Businesses Should Do Instead</h2><p>The fix isn&#8217;t a bigger budget for its own sake, it&#8217;s a budget that&#8217;s tied to something that actually changes as the company changes, like headcount, locations, or revenue, and gets reviewed at the same cadence as those numbers. A company that reviews its IT and security spending only when something breaks is, by definition, always reviewing it too late. Tying that review to a regular planning cycle, quarterly for fast-growing companies, at minimum annually for everyone else, keeps the budget from quietly falling behind the business it supports.</p><p>It also helps to separate &#8220;do we have a plan&#8221; from &#8220;can we actually execute the plan,&#8221; since the CrowdStrike data shows those two things diverging badly. A written policy that nobody funded isn&#8217;t protection. If affordability is genuinely the deciding factor in every tool purchase, that&#8217;s worth saying out loud to whoever owns the budget, rather than letting it stay an unstated assumption that shapes every decision by default.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Tie your IT budget to growth metrics.</strong> Set a rule, like a percentage of revenue or a per-employee amount, and revisit it every time headcount, locations, or revenue changes materially.</p></li><li><p><strong>Separate having a plan from funding a plan.</strong> A written security plan with no budget behind it protects nothing; check that the two actually match before you count on either.</p></li><li><p><strong>Prioritize protection alongside affordability</strong>, not affordability alone, when comparing tools, especially the smallest, fastest-scaling businesses where budgets are tightest.</p></li><li><p><strong>Review spending on a schedule, not a trigger.</strong> Waiting for an incident to reassess IT investment means the reassessment always comes after the damage is done.</p></li></ul><p>The uncomfortable finding in this report isn&#8217;t that small businesses lack a plan. It&#8217;s that almost none of them believe their budget can actually support the one they have. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: CrowdStrike, &#8220;<a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-unveils-smb-cyber-report-highlighting-protection-gaps/">CrowdStrike Unveils State of SMB Cybersecurity Report: High Awareness, </a>Lagging Protection&#8221;.</em></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Cloud Bill Nobody Budgeted For]]></title><description><![CDATA[After five straight years of getting better at controlling cloud costs, businesses just lost ground &#8212; nearly a third of what they're spending on cloud services is now going to waste.]]></description><link>https://www.msptodaynews.com/p/the-cloud-bill-nobody-budgeted-for</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-cloud-bill-nobody-budgeted-for</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Thu, 01 Oct 2026 12:03:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Plqg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Plqg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Plqg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Plqg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Plqg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Plqg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Plqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77081,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214269362?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Plqg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Plqg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Plqg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Plqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa90045aa-5ed3-48d4-94e4-d5eb9157162d_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!upZe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!upZe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!upZe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!upZe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!upZe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!upZe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66947,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214269362?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!upZe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!upZe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!upZe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!upZe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80f0a201-0e90-431a-9977-b591e399aebd_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What the Data Shows</h2><p>Every year, Flexera surveys IT and finance leaders for its State of the Cloud Report, and for five years running, the trend line on wasted cloud spend had been heading in the right direction. That streak broke in the 2026 report: estimated wasted cloud spend on infrastructure and platform services (IaaS and PaaS) climbed to 29%, the first increase in five years. In plain terms, almost a third of the money organizations are putting into cloud infrastructure is going toward resources that deliver nothing back &#8212; unused capacity, oversized instances, orphaned storage, and services nobody remembered to turn off.</p><p>The report ties the reversal directly to how fast AI adoption is moving. Cloud-based AI workloads are surging, and Flexera notes that &#8220;AI workloads behave differently than traditional cloud services, making visibility, governance and financial controls harder &#8212; but more essential &#8212; than ever.&#8221; Teams are standing up GPU-heavy workloads, new PaaS and SaaS tools, and experimental AI projects faster than their existing cost-tracking processes can keep up with, and the waste number is the receipt.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>It&#8217;s not a new problem, just a worsening one. Flexera&#8217;s 2021 report already found organizations running over their public cloud budgets by an average of 24%, with wasted spend estimated around 30% even then. What&#8217;s changed is the scale: the 2026 report found 76% of large enterprises now spend more than $5 million a month on cloud services, meaning even a modest percentage of waste translates into real money fast. And across company sizes, 85% of respondents said managing cloud spend is their top challenge &#8212; ahead of security and ahead of managing software licenses, which is a notable thing for an industry that spends a lot of energy talking about security first.</p><p>None of this requires a breach, an outage, or a single dramatic &#8220;bill shock&#8221; headline to matter. It&#8217;s the slow, unglamorous kind of cost problem: nobody sets out to waste 29% of a cloud budget, it just accumulates one un-monitored resource, one forgotten test environment, and one &#8220;we&#8217;ll clean that up later&#8221; at a time.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s easy to read &#8220;$5 million a month&#8221; and assume this is purely an enterprise problem. It isn&#8217;t. The mechanics that produce that 29% waste figure &#8212; resources provisioned and never right-sized, services left running after a project ends, nobody clearly owning the monthly cloud bill &#8212; show up at any scale. A 20-person company running its email, backups, line-of-business software, and a couple of AI-powered tools in the cloud can waste the same percentage of its budget as a Fortune 500 company; it&#8217;s just a smaller number that&#8217;s easier to not notice, because nobody&#8217;s finance team is scrutinizing a $400 monthly overage the way they would a $400,000 one.</p><p>That&#8217;s actually the more dangerous version of the problem for a small or mid-size business. A big enterprise has a FinOps team whose entire job is watching this. A smaller business usually doesn&#8217;t have anyone watching it at all &#8212; the cloud bill just gets paid, and it creeps up a little every renewal cycle without anyone asking why. Multiply &#8220;managing cloud spend is our top challenge&#8221; (which 85% of organizations of every size said) by a business with no dedicated person tracking it, and the waste doesn&#8217;t get caught until someone finally looks at a year of invoices side by side.</p><h2>What Businesses Should Do Instead</h2><p>The fix isn&#8217;t exotic &#8212; it&#8217;s the same governance discipline Flexera&#8217;s report points to, just scaled down to fit a smaller IT footprint. Start with a straightforward inventory: what cloud and SaaS services are you actually paying for right now, and does someone specific own reviewing that list on a schedule? Most cloud waste isn&#8217;t malicious or even careless in the moment &#8212; it&#8217;s a resource that made sense when it was set up and was never revisited. A quarterly review that asks &#8220;do we still need this, and is it sized right&#8221; catches most of it.</p><p>Pair that with basic alerting. Every major cloud provider offers budget alerts and cost anomaly detection at little or no extra cost &#8212; the tools exist, they&#8217;re just frequently never turned on. And before adding new cloud or AI tools, it&#8217;s worth asking the boring question up front: who is responsible for this bill going forward, and where does it get reviewed? That single ownership question prevents more waste than almost any tool.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Inventory every cloud and SaaS subscription.</strong> List what you&#8217;re actually paying for and assign someone to review it quarterly.</p></li><li><p><strong>Turn on budget alerts and anomaly detection.</strong> Most cloud providers include this at no extra cost &#8212; it just has to be switched on.</p></li><li><p><strong>Right-size and retire unused resources.</strong> Oversized instances, idle test environments, and orphaned storage are the most common sources of waste.</p></li><li><p><strong>Name an owner for every new cloud or AI tool.</strong> Before adopting anything new, decide who reviews its cost and usage going forward.</p></li></ul><p>Cloud waste rarely announces itself with a single bad bill &#8212; it builds quietly until a year of invoices tells the real story. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Flexera, &#8220;<a href="https://www.flexera.com/about-us/press-center/flexera-finds-cloud-value-is-rising-while-ai-waste-grows">Flexera Finds Cloud Value is Rising While AI Waste Grows</a>&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Password-Guessing Attack That Uncovered a Ransomware Supply Chain]]></title><description><![CDATA[A routine brute-force attempt against one exposed server turned out to be the tip of a much bigger business: criminals who break in, then sell the access to ransomware gangs.]]></description><link>https://www.msptodaynews.com/p/the-password-guessing-attack-that</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-password-guessing-attack-that</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Tue, 29 Sep 2026 12:02:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Cwnf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cwnf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cwnf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Cwnf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Cwnf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Cwnf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cwnf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214193818?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cwnf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Cwnf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Cwnf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Cwnf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f56235-d5be-4640-962e-ed163b74a16a_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It started as one of the most common attack patterns there is: someone exposed a Remote Desktop (RDP) server directly to the internet, and an attacker began systematically guessing passwords against it. Security analysts at Huntress caught the activity through an unusual signal, domain enumeration commands running on the network, and traced it backward to find the login had actually succeeded, one account out of several that were targeted.</p><h2>How the Attack Unfolded</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zqu7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zqu7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!Zqu7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!Zqu7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!Zqu7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zqu7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74919,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214193818?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zqu7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!Zqu7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!Zqu7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!Zqu7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faea902f6-ee6f-472e-a51d-7231788fd2a8_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What the attacker did next was notably unsophisticated in a way that made it easier to catch: rather than using automated credential-hunting tools, they opened Notepad and manually searched through files on the compromised system that looked like they might contain saved passwords. Forensic analysts later reconstructed this activity through the system&#8217;s jumplist records, effectively a log of recently opened files, which showed a methodical, manual search through anything password-themed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Investigators also noticed the compromised account had been logged into from multiple, geographically distributed IP addresses, a signal of shared or rented attacker infrastructure rather than a single individual working alone. Pulling that thread led to something bigger: a network of domains including one directly linked to the Hive and BlackSuit ransomware operations, alongside supporting infrastructure disguised as a legitimate VPN service and other consumer-facing services. Analysts noted the domain naming convention itself echoed language associated with &#8220;big game hunting,&#8221; industry shorthand for deliberately targeting larger, higher-value organizations for ransomware deployment.</p><p>In this case, the network was isolated before ransomware was actually deployed. But the infrastructure uncovered behind it pointed to something worth every business understanding: a functioning marketplace where one group&#8217;s entire job is breaking in and selling that access to someone else&#8217;s ransomware operation.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>The specialization here is the real story. Initial access brokers don&#8217;t need to know anything about ransomware, extortion negotiations, or data theft. Their entire business is finding exposed, poorly defended entry points, like an RDP server open to the internet with a guessable password, and selling that foothold to whoever wants it, often a completely separate criminal group running the actual ransomware operation.</p><p>That division of labor means an exposed RDP server with weak credentials isn&#8217;t just a risk on its own; it&#8217;s inventory in someone else&#8217;s supply chain, and it will be found by scanning, not by anyone researching your company specifically. Size doesn&#8217;t factor into whether a scanner finds an open RDP port. It only factors into what happens after someone buys the access.</p><h2>What Actually Would Have Stopped This</h2><p>The starting point is the most straightforward fix in this entire series: RDP should never be directly exposed to the open internet. It should sit behind a VPN or a Zero Trust access solution requiring authentication before RDP is ever reachable at all, with multi-factor authentication on that access layer specifically. That single architectural change removes the exact door this entire chain walked through.</p><p>Beyond that, this case is also a good example of logging working exactly as intended, even when it&#8217;s noisy. The analysts specifically noted that failed login attempts fill up log channels in large volumes, which can make it tempting to ignore them. Here, that same noisy log data, properly reviewed, was what surfaced the successful compromise and led to the broader infrastructure discovery before ransomware got deployed.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Never expose RDP directly to the internet.</strong> Require VPN or Zero Trust access with MFA before RDP is reachable at all.</p></li><li><p><strong>Use unique, strong passwords and MFA on every remote access point</strong>, not just the ones that feel highest-risk.</p></li><li><p><strong>Actually review failed login patterns</strong>, rather than treating high log volume as noise to ignore. A string of failures followed by a success is a specific, detectable pattern.</p></li><li><p><strong>Isolate quickly on suspicious activity.</strong> In this case, network isolation before ransomware deployment was what kept a compromise from becoming an incident.</p></li></ul><p>An exposed RDP server with a weak password isn&#8217;t a small risk because it seems old and well-known. It&#8217;s exactly the kind of opening a specialized criminal supply chain is built to find and sell. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p><em>Source: <a href="https://www.huntress.com/blog/brute-force-or-something-more-ransomware-initial-access-brokers-exposed">Huntress, &#8220;Brute Force or Something More? Ransomware Initial Access Brokers Exposed&#8221;</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Breach Marriott Bought Without Knowing It]]></title><description><![CDATA[When Marriott acquired Starwood Hotels in 2016, it also acquired an attacker who had been sitting inside Starwood's reservation system for two years &#8212; and nobody found out until it was far too late.]]></description><link>https://www.msptodaynews.com/p/the-breach-marriott-bought-without</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-breach-marriott-bought-without</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Mon, 28 Sep 2026 12:01:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!n41A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n41A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n41A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!n41A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!n41A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!n41A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n41A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80653,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214265966?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n41A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!n41A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!n41A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!n41A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2502229c-4513-4691-ba0b-05c8527cb319_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!myKU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!myKU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!myKU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!myKU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!myKU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!myKU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71162,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214265966?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!myKU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!myKU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!myKU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!myKU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b70c95f-bbdd-4fc6-a6ff-2b6d7ef8383b_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The Guest Who Never Checked Out</h2><p>In September 2016, Marriott closed its acquisition of Starwood Hotels &amp; Resorts, folding brands like Sheraton, Westin, and W Hotels into its portfolio and creating the largest hotel company in the world. What Marriott didn&#8217;t know at the time was that it had also acquired an intruder. According to Marriott&#8217;s own disclosure, attackers had been inside Starwood&#8217;s guest reservation database since 2014, two full years before the acquisition even closed.</p><p>The intrusion stayed hidden through the entire deal and for two more years after it. It wasn&#8217;t until September 8, 2018, that an internal Marriott security tool flagged a suspicious attempt to access the reservation database, using legitimate administrator credentials. Investigators who dug into that alert found a Remote Access Trojan and the credential-theft tool MimiKatz, which together had given the attackers ongoing control of an administrator account. It took Marriott until November 2018 to decrypt what had been taken and understand the scope, and the company went public with the breach on November 30, 2018.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The scale was staggering: up to 500 million guest records, including passport numbers and payment card data. The details of how that data was stored made things worse. Encryption keys for the payment card data were sitting on the same server as the encrypted data itself, and the majority of passport numbers had simply been saved in plain text, not encrypted at all. This wasn&#8217;t a sophisticated new attack technique defeating strong defenses. It was a years-old compromise sitting on top of years-old security shortcuts, and it had been there the entire time Marriott&#8217;s due diligence team was evaluating the deal.</p><p>None of this was Marriott&#8217;s doing in the sense that its own engineers didn&#8217;t build the vulnerable system. But Marriott inherited it anyway, along with the legal, financial, and reputational exposure that came with it. The breach eventually led to regulatory penalties in multiple jurisdictions and a multistate U.S. settlement of $52 million, on top of Marriott&#8217;s own remediation and legal costs. The attacker had already checked in years before the acquisition. Nobody checked the guest list before signing the deal.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s easy to read this and think &#8220;that&#8217;s a Fortune 500 problem.&#8221; It isn&#8217;t. Small and mid-size businesses acquire other small businesses, get acquired themselves, and merge operations with partners constantly, buying out a competitor, absorbing a smaller shop, combining back-office systems after a merger. The dollar amounts are smaller, but the mechanics are identical: you&#8217;re taking on someone else&#8217;s IT environment, their vendor relationships, their old software, and whatever has been quietly living in their network, sometimes for years.</p><p>The difference is that a company the size of Marriott at least ran some due diligence, and a hidden, well-concealed compromise still slipped through. Most small business deals run none at all. IT and security review rarely make the checklist next to financial audits and contract review, because nobody thinks to ask, or nobody on the deal team knows what to ask. That gap doesn&#8217;t get smaller just because the company is smaller. If anything, it gets bigger, because small businesses are less likely to have monitoring in place that would have caught an intrusion in the first place, acquired or not.</p><h2>What Actually Would Have Stopped This</h2><p>Real IT due diligence during an acquisition isn&#8217;t a box to check, it&#8217;s an actual technical review: bringing in someone to look at the target company&#8217;s network for signs of existing compromise, not just asking their IT contact if everything is fine. That means checking for unusual administrator activity, unfamiliar remote access tools, unpatched systems, and data that&#8217;s stored or encrypted improperly, the exact category of issue that let Marriott&#8217;s attackers move payment card data and its encryption keys off the same server for two years without anyone noticing.</p><p>It also means treating the acquired environment as untrusted until it&#8217;s been reviewed, rather than plugging it straight into your existing network and inheriting whatever risk comes with it. A compromise assessment before close, and continued monitoring immediately after, would have given Marriott a real shot at catching this years earlier than a suspicious database query eventually did on its own.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Treat IT review as a deal requirement.</strong> Any acquisition or merger, no matter the size, should include a technical security assessment before you sign, not after.</p></li><li><p><strong>Assume the target&#8217;s network could already be compromised.</strong> Have someone actually look for signs of intrusion rather than taking a verbal assurance at face value.</p></li><li><p><strong>Isolate before you integrate.</strong> Keep an acquired company&#8217;s systems segmented from yours until they&#8217;ve been reviewed and cleaned up, not connected on day one.</p></li><li><p><strong>Check how sensitive data is actually stored.</strong> Encryption only helps if the keys aren&#8217;t sitting next to the data they protect, and unencrypted data in the clear defeats the purpose entirely.</p></li></ul><p>Acquisitions move fast, and IT due diligence is one of the easiest things to skip when everyone&#8217;s focused on the financials. Marriott&#8217;s experience shows how expensive that shortcut can get, even for a company with real resources behind it. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: CSO Online, &#8220;<a href="https://www.csoonline.com/article/567795/marriott-data-breach-faq-how-did-it-happen-and-what-was-the-impact.html">Marriott data breach FAQ: How did it happen and what was the impact</a>?&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The IT Admin Who Locked an Entire City Out of Its Own Network]]></title><description><![CDATA[One network engineer held the only passwords to San Francisco's government systems. When he refused to hand them over, the city found out exactly what it costs to depend on a single person for critical infrastructure.]]></description><link>https://www.msptodaynews.com/p/the-it-admin-who-locked-an-entire</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-it-admin-who-locked-an-entire</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Sun, 27 Sep 2026 12:02:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VW-D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VW-D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VW-D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!VW-D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!VW-D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!VW-D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VW-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75054,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214264152?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VW-D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!VW-D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!VW-D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!VW-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88d3d226-d419-4ca1-aac0-30d9983edd73_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Waq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Waq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!2Waq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!2Waq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!2Waq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Waq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71916,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214264152?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Waq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!2Waq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!2Waq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!2Waq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84ed966a-b524-4635-b37f-9ef419880e84_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Happened</h2><p>In July 2008, Terry Childs was the network administrator responsible for FiberWAN, the network connecting hundreds of San Francisco city and county departments and buildings, including police records and payroll systems, back to a central data center. When a dispute with his supervisors came to a head, Childs refused to hand over the network&#8217;s administrative passwords, even when his managers asked him directly on an open conference line.</p><p>This wasn&#8217;t a hypothetical &#8220;what if the IT person won&#8217;t cooperate&#8221; scenario &#8212; it played out inside a city government with real consequences. According to Network World&#8217;s coverage of Childs&#8217;s criminal trial, he had configured the network&#8217;s routers to store their settings in memory rather than on their hard drives, meaning the devices would lose their configuration entirely if they ever lost power, making any workaround around him dramatically harder. A juror on the case, himself a network engineer, summed it up: &#8220;The city was denied access to the network. He knew the steps he was taking were creating a perfect storm.&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>For roughly 12 days, city officials had no administrative access to the network carrying their own government&#8217;s data. Then-Mayor Gavin Newsom later testified that the city had been &#8220;in peril,&#8221; with officials cut off from police records and payroll data because the one person who held the keys wouldn&#8217;t hand them over. Recovering control cost the city roughly $900,000. Childs was ultimately convicted of a felony count of denying computer services, sentenced to four years in prison, and later ordered to pay nearly $1.5 million in restitution.</p><p>The most uncomfortable detail to come out of the trial wasn&#8217;t really about Childs at all. A juror who worked in networking told reporters that city IT management had &#8220;done everything wrong&#8221; in letting one employee become the sole holder of that much access, with no shared documentation and no one else who could step in. It didn&#8217;t take a hacker breaking in from the outside. It only took one employee and one bad afternoon.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>San Francisco had an entire IT department, and the crisis still came down to one person holding knowledge nobody else had. Most small and mid-size businesses don&#8217;t have that department &#8212; they have one IT employee, or a two-person team, or an owner who&#8217;s been quietly acting as the de facto sysadmin for years. The gap this case exposes isn&#8217;t really about malice; it&#8217;s about what happens when critical access, passwords, and system knowledge exist in exactly one place. Whether that person is uncooperative, unreachable, out sick, or simply gives two weeks&#8217; notice, the effect on the business is the same: nobody else can get in.</p><p>For an SMB, that single point of failure usually isn&#8217;t a dramatic standoff &#8212; it&#8217;s a router nobody remembers the login for, a domain registrar account tied to a personal email address that left with the employee, or a backup system only one person ever configured. It doesn&#8217;t need a courtroom to become a serious problem. It just needs that person to be gone when something breaks.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t more trust in the IT person &#8212; it&#8217;s less dependence on any single one. Administrative credentials for core systems (network devices, domain registrars, cloud consoles, backup platforms) belong in a shared password manager with role-based access, not in one employee&#8217;s head or personal notes. At least one other person, whether that&#8217;s an owner, a second staff member, or an outside partner, should be able to get into every critical system without needing that specific individual available.</p><p>Documentation is the other half of it. A basic, current, written record of what systems exist, where they live, and how they&#8217;re accessed turns a single point of failure into something any competent person can pick up. It doesn&#8217;t need to be elaborate. It needs to exist somewhere more than one person can reach.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Store admin credentials centrally.</strong> Put passwords for network gear, domain registrars, and cloud accounts in a shared business password manager, not one person&#8217;s memory or personal files.</p></li><li><p><strong>Give at least two people access.</strong> Every critical system should have a second authorized person, internal or outside, who can get in if the primary person is unavailable.</p></li><li><p><strong>Keep basic infrastructure documentation current.</strong> A simple written record of what exists and how to reach it is worth more during a crisis than anyone&#8217;s tribal knowledge.</p></li><li><p><strong>Review access when roles change.</strong> Update shared credentials and permissions whenever an IT employee&#8217;s role shifts, not just when they formally leave.</p></li></ul><p>A city with a full IT department still lost control of its own network because access lived in one person&#8217;s head. For a business with one IT employee, that same gap is even easier to fall into &#8212; and even more disruptive to close after the fact. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Network World, &#8220;<a href="https://www.networkworld.com/article/728952/malware-cybercrime-admin-who-kept-sf-network-passwords-found-guilty.html">Admin who kept SF network passwords found guilty</a>&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The VPN Backdoor Nobody Remembers Granting]]></title><description><![CDATA[A 2024 industry survey found that most organizations are still handing out full-network VPN access years after remote work went mainstream, and almost everyone admits it makes them nervous.]]></description><link>https://www.msptodaynews.com/p/the-vpn-backdoor-nobody-remembers</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-vpn-backdoor-nobody-remembers</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Sat, 26 Sep 2026 12:01:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3I1b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3I1b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3I1b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!3I1b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!3I1b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!3I1b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3I1b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91725,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214262924?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3I1b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!3I1b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!3I1b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!3I1b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25d6f45c-5581-420e-86b1-cca6b09b5f45_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f58k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f58k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!f58k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!f58k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!f58k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f58k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214262924?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f58k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!f58k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!f58k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!f58k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13b37f67-c5a6-4152-90d0-94c0ed8a9b77_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What the Data Shows</h2><p>When offices shut down in 2020, businesses everywhere did the same thing in a hurry: they stood up VPN access for anyone who needed to work from home, then kept adding more of it as hybrid schedules became permanent. Four years later, Zscaler&#8217;s ThreatLabz 2024 VPN Risk Report, based on a survey of more than 600 IT, security, and networking professionals, put a number on what that left behind. Fifty-six percent of organizations said they&#8217;d experienced a cyberattack that exploited VPN vulnerabilities in the past year, and 91% said they were concerned that a VPN could lead to a compromising breach.</p><p>The report&#8217;s most telling finding isn&#8217;t about attacks that already happened, it&#8217;s about the access sitting there waiting to be misused. Because VPNs are built to hand out full network access once a login succeeds, 92% of respondents said they were specifically worried about third parties with VPN access, contractors, vendors, former partners, acting as backdoors into systems those third parties had no real reason to reach. That&#8217;s not a hypothetical edge case. It&#8217;s the design of the tool: a VPN doesn&#8217;t usually ask what a user actually needs to touch, it just puts them on the network and lets internal routing sort out the rest.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The consequences of that design show up in the breach data too. Among organizations that were actually compromised through a VPN vulnerability, 53% reported that attackers moved laterally once inside, spreading from the entry point to other systems on the network. That&#8217;s a direct result of the same broad-access problem: a single compromised VPN account isn&#8217;t a single-system problem, it&#8217;s a foothold that can reach almost anywhere the network allows.</p><p>None of this describes a single dramatic incident. It describes an accumulated condition, one that built up gradually as businesses added remote access faster than they audited it, and it&#8217;s exactly the kind of risk that doesn&#8217;t show up until someone goes looking for it.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read a survey like this as an enterprise problem, since large organizations have more VPN concentrators, more contractors, more moving parts to lose track of. But the underlying dynamic scales down just as easily. A ten-person business that went remote in 2020 likely set up VPN or remote-desktop access for employees, maybe a vendor who helped with the transition, maybe an old contractor who did a project two years ago. Small businesses don&#8217;t run identity audits on a schedule the way larger IT departments do, which means that access is more likely to still be there, not less.</p><p>The math is simple and unflattering: fewer people means fewer eyes on who still has a login, and a smaller IT footprint often means nobody owns the job of periodically checking. An account that was reasonable to create in 2020 doesn&#8217;t announce itself as unreasonable in 2026. It just sits there, working exactly the way it was set up to work, until someone other than its intended user finds it.</p><h2>What Actually Would Have Stopped This</h2><p>The fix isn&#8217;t a single tool, it&#8217;s a mindset shift: access should be reviewed on a schedule, not left to exist until someone remembers to remove it. That means a recurring check, quarterly is reasonable for most small businesses, of who has VPN or remote access, whether they still need it, and whether that access grants more of the network than their actual job requires. A departing employee or a finished vendor contract should trigger an access removal the same day, not whenever someone happens to notice.</p><p>The deeper fix is moving away from the assumption baked into traditional VPNs, that a valid login should mean broad network access. Zero Trust approaches, which grant access to specific applications or systems rather than the whole network, directly address the exact worry that 92% of the survey&#8217;s respondents raised about third parties: even if a credential is compromised or a former contractor&#8217;s login is still active, the blast radius stays small because there was never a wide-open network to move laterally across in the first place.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Run a quarterly access review.</strong> List everyone with VPN or remote access and confirm each one still needs it, not just that the account still works.</p></li><li><p><strong>Kill access same-day on offboarding.</strong> Employee departures and vendor contract endings should trigger immediate removal, not a cleanup task for later.</p></li><li><p><strong>Scope access to what&#8217;s needed.</strong> Move away from all-or-nothing VPN access toward tools that grant specific application access instead of the whole network.</p></li><li><p><strong>Treat third-party access as higher risk by default.</strong> Vendor and contractor accounts deserve extra scrutiny and shorter renewal cycles than employee accounts.</p></li></ul><p>Remote access tools don&#8217;t expire on their own, and nobody schedules time to notice the ones nobody&#8217;s using. MSP Today&#8217;s trusted tech partner is<a href="https://www.jkcsi.com/"> JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Zscaler, &#8220;<a href="https://www.zscaler.com/blogs/security-research/new-vpn-risk-report-56-enterprises-attacked-vpn-vulnerabilities">New VPN Risk Report: 56% of Enterprises Attacked via VPN Vulnerabilities</a>&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Home Computer That Cracked a Password Manager]]></title><description><![CDATA[A senior engineer's personal computer, running consumer software far outside any corporate policy, became the single point of failure behind one of the most consequential breaches in recent memory.]]></description><link>https://www.msptodaynews.com/p/the-home-computer-that-cracked-a</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-home-computer-that-cracked-a</guid><pubDate>Fri, 25 Sep 2026 12:03:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Moz6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Moz6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Moz6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Moz6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Moz6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Moz6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Moz6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86496,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214261804?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Moz6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Moz6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Moz6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Moz6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ccc22da-6b25-49fc-9b52-9f8c53bae665_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pD6N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pD6N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!pD6N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!pD6N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!pD6N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pD6N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214261804?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pD6N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!pD6N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!pD6N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!pD6N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63f05fd9-2ed2-4f2f-b709-3bb6e3a4e501_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>How a Personal Computer Became the Way In</h2><p>In 2022, LastPass, the password manager used by more than 30 million people and 85,000 businesses, disclosed a second security incident that traced back to something far more mundane than a sophisticated zero-day attack on its infrastructure. The attacker targeted a senior DevOps engineer, one of only four employees at the company with access to the decryption keys protecting its cloud backups. Rather than attacking LastPass&#8217;s corporate network directly, the attacker went after that engineer&#8217;s home computer.</p><p>According to LastPass&#8217;s own account of the incident, the attacker exploited a vulnerability in a third-party media software package installed on the engineer&#8217;s personal machine to achieve remote code execution and plant a keylogger. That keylogger sat quietly, capturing everything typed on the device, including the moment the engineer authenticated into their LastPass corporate vault with a master password and multi-factor authentication.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>With that captured master password and an active authenticated session, the attacker logged into the engineer&#8217;s corporate vault and exported its contents, including shared folder entries that held the access and decryption keys to LastPass&#8217;s cloud storage environment. Using those stolen keys, the attacker went on to access and decrypt cloud backups containing customer vault data, billing information, and a backup of the company&#8217;s MFA and federation database. The intrusion ran from August 12 to October 26, 2022, before LastPass identified and shut it down, publishing a full account of what happened the following March.</p><p>Nothing about the attack that eventually reached millions of customer vaults started with a flaw in LastPass&#8217;s own network. It started with software the company had no visibility into, running on a device the company did not manage, that happened to hold a live, authenticated line into its most sensitive systems.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read this as a story about a security vendor and move on, but the actual failure point has nothing to do with being in the security business. It&#8217;s a personal device, outside any managed policy, holding an active session into company systems. Every business with employees who check email on their own phone, log into a shared drive from a home laptop, or keep a company app signed in on personal hardware has that same shape of exposure, whether or not anyone has ever written it down as a risk.</p><p>Small and mid-size businesses are, if anything, more exposed to this pattern, not less. A large company at least has some chance of catching unusual account activity through logging and monitoring. Most small businesses have no equivalent visibility into what&#8217;s happening on an employee&#8217;s personal laptop or phone, no way to know what other software is installed on it, and often no written policy establishing what that device is and isn&#8217;t allowed to touch. The device itself becomes an invisible extension of the business network that nobody is actually watching.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t complicated, and it doesn&#8217;t require banning personal devices outright. It requires drawing a clear line around what a personal device is allowed to access and backing that line with technical controls rather than trust alone. Multi-factor authentication should require a second factor the attacker can&#8217;t also capture through a keylogger, such as a hardware security key or an authenticator app tied to a separate device, rather than relying solely on something typed on the same compromised machine. Sensitive access, like the decryption keys a handful of engineers held in this case, should also be walled off so that no single compromised device or account can reach it alone.</p><p>Just as important is simply having a policy that says which devices can touch company systems and what has to be true about them first, patched, monitored, and free of unrelated consumer software, before they&#8217;re trusted with a live session into anything sensitive. Without that line drawn anywhere, every employee&#8217;s personal laptop is a potential front door nobody at the company knows exists.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Write down your device policy.</strong> Spell out which personal devices can access company email, files, or systems, and what conditions they have to meet first.</p></li><li><p><strong>Separate MFA from the device being protected.</strong> Use a hardware key or a separate authenticator app rather than a factor that lives on the same machine a keylogger could compromise.</p></li><li><p><strong>Limit who holds the master keys.</strong> Restrict access to your most sensitive systems and credentials to as few people as the job actually requires.</p></li><li><p><strong>Keep personal and work software apart.</strong> Discourage installing unrelated consumer software, like media servers or file-sharing tools, on any device used to reach company systems.</p></li></ul><p>A single unmanaged personal computer, running software nobody at the company ever approved, was enough to unravel one of the most trusted names in password security. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: CSO Online, &#8220;<a href="https://www.csoonline.com/article/574613/hacked-home-computer-of-engineer-led-to-second-lastpass-data-breach.html">Hacked home computer of engineer led to second LastPass data </a>breach&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Real Cost of Making Employees Wait on IT]]></title><description><![CDATA[A national survey put a dollar figure on something every small business already feels: the hours people lose sitting around while a tech problem gets fixed.]]></description><link>https://www.msptodaynews.com/p/the-real-cost-of-making-employees</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-real-cost-of-making-employees</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Thu, 24 Sep 2026 12:01:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mkgY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mkgY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mkgY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!mkgY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!mkgY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!mkgY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mkgY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74749,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214260083?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mkgY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!mkgY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!mkgY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!mkgY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb940bbec-ab0a-4306-9c29-22bd572fc85d_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iwD5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iwD5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!iwD5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!iwD5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!iwD5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iwD5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63278,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214260083?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iwD5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!iwD5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!iwD5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!iwD5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4854a4-bb2d-4c35-8e03-99abd0b908f4_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What the Numbers Actually Show</h2><p>Most businesses can point to a server outage or a big system failure and name the cost. What&#8217;s harder to see is the slow leak: the fifteen minutes someone spends staring at a frozen screen, the email that sits unread in a support queue, the &#8220;I&#8217;ll just deal with it later&#8221; that turns into an afternoon. A 2023 survey from Electric AI, an IT services company that surveyed 1,049 employed Americans, tried to put a number on exactly that leak, and the number is bigger than most owners would guess.</p><p>The headline figure: employers waste an average of $4,072 per employee every year because of tech issues. That&#8217;s not hardware replacement or software licensing, it&#8217;s the cost of paid time spent waiting, troubleshooting, and working around problems instead of working. Respondents said they spend almost three hours a week dealing with tech issues, which the survey calculated out to more than 140 hours a year, roughly three and a half work weeks, per employee, gone.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The survey also found the pain isn&#8217;t evenly distributed. Remote workers reported the highest rate of wasted time from tech problems, 73%, compared with 41% of hybrid employees and 22% of employees working fully on-site, a gap that tracks with how much harder it is to get quick, in-person help when you&#8217;re not in the building. More than half of respondents, 55%, described their company&#8217;s technology as outdated, and less than half said their company&#8217;s IT support actually resolved their issues effectively when they asked for help.</p><p>One more finding is worth pulling out on its own: when official IT support is slow or absent, the burden doesn&#8217;t disappear, it shifts to coworkers. The survey found that a majority of younger workers specifically felt that being constantly asked for tech help by colleagues held back their own work. In other words, when there&#8217;s no reliable place to send a tech problem, it doesn&#8217;t get solved faster. It just gets handed to whoever&#8217;s desk is closest, and now two people are stuck instead of one.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>Do that math against a real team. A twenty-person company losing even half of that $4,072-per-employee figure, roughly $2,000 a person, is looking at $40,000 a year quietly draining out of productivity nobody put on a budget line. A larger company can absorb that in a rounding error. A twenty-person company feels it in missed deadlines, in a project that always seems to be a week behind, in the same three people fielding &#8220;can you look at this real quick&#8221; questions all day instead of doing their actual jobs.</p><p>This is exactly where being small or mid-size makes the problem worse, not better. Big companies have a dedicated help desk with a ticketing system, defined response times, and staff whose whole job is making tech problems go away quickly. Most small and mid-size businesses don&#8217;t. Instead, IT support is whoever&#8217;s good with computers, handled between their real responsibilities, or it&#8217;s a break-fix vendor you call after something&#8217;s already broken and then wait on. Both setups mean the fifteen-minute problem realistically takes an hour or a day to actually get resolved, and that gap compounds every single week.</p><h2>What Businesses Should Do Instead</h2><p>The fix isn&#8217;t more technology, it&#8217;s a faster, more reliable path to a fix when something goes wrong. That means a real point of contact for IT issues with an actual response-time expectation attached to it, not &#8220;someone will get to it eventually.&#8221; It also means proactively replacing the technology the survey flagged as the biggest drag, aging, outdated equipment, on a planned schedule rather than waiting for it to fail mid-task.</p><p></p><p>It also means measuring this at all. Most small businesses have never tracked how much time their team actually loses to tech problems in a given month, which is exactly why it&#8217;s easy to underestimate. A managed IT provider with defined response-time commitments turns that guesswork into a number you can see, and gives your team someone to call other than the coworker at the next desk.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Set a real response-time standard.</strong> Define how fast a tech issue should get acknowledged and resolved, and hold whoever handles IT, internal or outsourced, to it.</p></li><li><p><strong>Track the hours, not just the tickets.</strong> Ask your team occasionally how much time tech issues actually cost them in a week; most owners are surprised by the answer.</p></li><li><p><strong>Replace aging equipment on a schedule.</strong> Don&#8217;t wait for old hardware to fail mid-task; a planned refresh cycle is cheaper than the downtime it prevents.</p></li><li><p><strong>Give employees one clear place to go.</strong> A defined IT contact, not &#8220;ask whoever&#8217;s nearby,&#8221; keeps the burden off your most tech-savvy staff and gets issues fixed faster.</p></li></ul><p>Three hours a week per employee doesn&#8217;t sound like much until you multiply it across a whole team and a whole year. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Electric AI, &#8220;<a href="https://www.electric.ai/blog/wasted-talent-time-lost-to-tech-issues">Wasted Talent: Time Lost to (Old) Tech Issues</a>&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A $25,000 Lesson From a One-Doctor Neurology Practice]]></title><description><![CDATA[Federal regulators didn't fine this small New York practice for getting hacked. They fined it for never having checked where it was vulnerable in the first place.]]></description><link>https://www.msptodaynews.com/p/a-25000-lesson-from-a-one-doctor</link><guid isPermaLink="false">https://www.msptodaynews.com/p/a-25000-lesson-from-a-one-doctor</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Wed, 23 Sep 2026 12:02:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BHAv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BHAv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BHAv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!BHAv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!BHAv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!BHAv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BHAv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72200,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214258528?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BHAv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!BHAv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!BHAv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!BHAv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb608808-3e1e-4281-943a-4d20d56f1a2a_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fEFQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fEFQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!fEFQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!fEFQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!fEFQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fEFQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69951,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214258528?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fEFQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!fEFQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!fEFQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!fEFQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bd0cb25-8093-4ec2-8f5d-da72b7ca997c_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Happened</h2><p>In December 2020, a ransomware attack hit Comprehensive Neurology, PC, a neurology practice in New York. The attack encrypted the practice&#8217;s IT network and its electronic protected health information, locking staff out of the very systems they needed to run the office. The exposed data included patient names, clinical information, health insurance details, demographic information, Social Security numbers, and driver&#8217;s license numbers, the kind of information that follows a patient around for years, not months.</p><p>The practice reported the breach, and the HHS Office for Civil Rights (OCR), the federal agency that enforces HIPAA, opened an investigation. What OCR found wasn&#8217;t that the practice had ignored some obscure technical requirement. It was more basic than that: Comprehensive had never conducted an accurate and thorough risk analysis to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of the patient data it held. That&#8217;s not a suggestion buried in HIPAA&#8217;s fine print. It&#8217;s one of the foundational, required steps of the Security Rule, the starting point every other safeguard is supposed to build on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In April 2025, OCR announced a settlement: Comprehensive Neurology agreed to pay $25,000 and to operate under a two-year, monitored corrective action plan. That plan requires the practice to actually conduct the risk analysis it had skipped, build a risk management plan to address what that analysis turns up, revise its written HIPAA policies and procedures, and put its staff through HIPAA training tied to their actual job duties. OCR noted this was its 12th ransomware-related enforcement action and the 8th under its Risk Analysis Initiative, a specific enforcement push aimed squarely at practices that never did this foundational work.</p><p>What stands out about this case is its scale. This isn&#8217;t a hospital network or a national health plan; it&#8217;s a single neurology practice, the kind of operation that might have a handful of providers and a small office staff. The fine itself, $25,000, is modest as these things go. But the two-year federal monitoring period, the legal exposure, and the operational disruption of a ransomware attack in the first place are not modest at all for a practice that size.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read HIPAA enforcement news and assume it only applies to organizations with compliance departments and general counsel on retainer. This case says otherwise. OCR didn&#8217;t single out Comprehensive Neurology because it was large or high-profile; it&#8217;s neither. It got flagged because a breach happened, and when regulators looked underneath it, there was no risk analysis to point to. That&#8217;s a gap that exists at plenty of small medical, dental, and healthcare practices right now, not because anyone is being careless, but because a formal risk analysis often just never makes it onto the to-do list of a busy front office.</p><p>The same logic extends past healthcare. Any small business holding sensitive customer data, health records, financial information, personal identifiers, is one incident away from the same kind of scrutiny this practice faced. You don&#8217;t need to be a target of interest to attackers to get hit; ransomware operators are largely opportunistic, and a small practice&#8217;s systems are often easier to break into than a large hospital&#8217;s. The fine here is a reminder that &#8220;we didn&#8217;t know we were vulnerable&#8221; is not a defense once regulators start asking what you did to find out.</p><h2>What Actually Would Have Stopped This</h2><p>A risk analysis isn&#8217;t a technical audit that requires an in-house IT department to perform. It&#8217;s a documented process: inventory where patient or customer data lives, identify what could go wrong with it, unpatched software, unsegmented networks, weak backup practices, missing multi-factor authentication, and write down what you&#8217;re doing about each risk you find. HIPAA has required this for years, and OCR&#8217;s Risk Analysis Initiative exists specifically because so many practices, especially small ones, still haven&#8217;t done it.</p><p>Beyond the paperwork, the practical safeguards that follow from a real risk analysis are the ones that actually blunt a ransomware attack: offline or immutable backups that a network-wide encryption event can&#8217;t reach, multi-factor authentication on remote access and email, and a patched, monitored network that limits how far an attacker can move once they&#8217;re in. None of that requires enterprise budget. It requires doing the assessment first, so you know what to fix.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Conduct a documented risk analysis.</strong> Identify where sensitive data lives, what could compromise it, and put your findings in writing, not just in your head.</p></li><li><p><strong>Keep offline or immutable backups.</strong> A ransomware attack that encrypts your live network shouldn&#8217;t be able to touch your recovery copy too.</p></li><li><p><strong>Require MFA on remote access and email.</strong> This closes one of the most common doors ransomware operators use to get in.</p></li><li><p><strong>Train staff on their specific HIPAA duties.</strong> Generic annual training slides don&#8217;t stick the way role-specific guidance does.</p></li></ul><p>A $25,000 fine and two years of federal monitoring started with a step that costs far less than either: writing down where the risks actually are. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: <a href="https://www.hhs.gov/press-room/ocr-hipaa-racap-np.html">HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation with Neurology Practice</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[When Cyber Insurance Says No: Inside the Industry’s New Underwriting Bar]]></title><description><![CDATA[More than half of security leaders say their insurer has denied a cyber claim in the past year &#8212; and the industry itself says coverage is only getting harder to qualify for.]]></description><link>https://www.msptodaynews.com/p/when-cyber-insurance-says-no-inside</link><guid isPermaLink="false">https://www.msptodaynews.com/p/when-cyber-insurance-says-no-inside</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Tue, 22 Sep 2026 12:03:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_Iha!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Iha!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Iha!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!_Iha!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!_Iha!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!_Iha!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Iha!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81849,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214257399?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Iha!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!_Iha!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!_Iha!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!_Iha!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c8a287-275b-4c8d-92c8-8291795c7184_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BPkr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BPkr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!BPkr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!BPkr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!BPkr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BPkr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73994,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214257399?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BPkr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!BPkr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!BPkr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!BPkr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47075fa3-2bee-45e9-a7e9-4da48506d523_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Insurers Are Raising the Bar, and Claims Are Getting Harder to Collect</h2><p>For years, the standard advice around cyber insurance was simple: buy a policy, file a claim if something happens, get paid. That relationship is changing. According to reporting in Infosecurity Magazine&#8217;s year-end look at the cyber insurance market, 56% of CISOs said their organization had a cyber insurance payout denied over the past year, a statistic attributed to Marie Wilcox, VP at security vendor Binalyze and a board director at the Chartered Institute of Information Security (CIISec).</p><p>The reasons behind those denials are telling. The article reports that rejections increasingly come down to firms lacking &#8220;evidence to prove that they had mitigated risks&#8221; and being unable to &#8220;produce a full timeline of a breach&#8221; when a claim is filed. In other words, insurers aren&#8217;t just asking whether you had a policy in place. They&#8217;re asking whether you can document, after the fact, exactly what your security controls were doing and precisely how the incident unfolded.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Ryan Rubin, EMEA cyber practice lead at risk consultancy Ankura, put the underwriting shift in blunt terms: &#8220;Companies will find themselves having to increasingly demonstrate higher levels of cyber controls maturity before being offered insurance.&#8221; He also noted that insurers are growing more cautious in general, &#8220;given continued large claims relating to ransomware and business interruption costs,&#8221; making them &#8220;more hesitant to offer wide coverage.&#8221; Wilcox added that the outlook for the year ahead &#8220;looks far more challenging&#8221; for the people responsible for security programs, with underwriting criteria tightening and compliance expectations rising alongside it.</p><p>The article also points to the cost of getting this wrong. It cites Jaguar Land Rover&#8217;s August 2025 cyberattack, which had no active cyber insurance policy in place at the time and which the piece estimates cost the UK economy roughly &#163;1.9 billion. By contrast, Marks &amp; Spencer&#8217;s April 2025 incident was covered, with a claim reported around &#163;100 million. Having a policy and having a policy that actually pays out turned out to be two very different things.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read this as an enterprise problem &#8212; big companies, big claims, big consultants weighing in. But the underlying shift applies with more force, not less, to smaller businesses. Large organizations generally have security teams, incident response retainers, and the internal logging infrastructure to reconstruct a breach timeline on demand. Most small and mid-size businesses don&#8217;t have any of that by default, which means exactly the kind of documentation insurers now expect &#8212; proof that controls were in place and working, plus a clear record of what happened &#8212; is often the first thing missing when a claim gets filed.</p><p>The market dynamics work against smaller businesses too. When insurers pull back on &#8220;wide coverage&#8221; and raise the bar on controls maturity industry-wide, that bar doesn&#8217;t get set separately for a 20-person company versus a 2,000-person one. It gets set once, and smaller businesses either meet it with the same rigor or find themselves in the growing group getting a denial, a higher premium, or a non-renewal notice at the worst possible time &#8212; right after an incident, when there&#8217;s no runway left to fix the gap.</p><h2>What Businesses Should Do Instead</h2><p>The practical takeaway isn&#8217;t just &#8220;have security tools.&#8221; It&#8217;s &#8220;have security tools that produce a record you can hand to an insurer, and know where that record lives before you ever need it.&#8221; That means MFA enforced across email, remote access, and admin accounts, not just checked as a box on a renewal questionnaire. It means endpoint detection and response (EDR) that&#8217;s actually logging and alerting, not sitting unmonitored. And it means backups that are tested, offline or immutable, and verified to restore, since &#8220;we had backups&#8221; and &#8220;we can prove our backups worked&#8221; are very different claims to make to an insurer after the fact.</p><p>Just as important: treat your cyber insurance application and renewal process as a real audit, not paperwork. If you can&#8217;t currently answer &#8220;what does our breach timeline documentation look like&#8221; or &#8220;can we prove our MFA coverage is complete,&#8221; that&#8217;s the gap to close before a renewal, not after a claim gets denied.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Enforce MFA everywhere, not selectively.</strong> Email, remote access, and admin accounts all need it, and you should be able to prove coverage is complete when asked.</p></li><li><p><strong>Deploy EDR with active monitoring.</strong> A security tool that isn&#8217;t generating logs and alerts someone reviews doesn&#8217;t help you document an incident later.</p></li><li><p><strong>Test your backups, not just schedule them.</strong> Offline or immutable backups that have been verified to actually restore are what insurers and your own recovery plan both need.</p></li><li><p><strong>Keep incident documentation insurer-ready.</strong> Know in advance how you&#8217;d reconstruct a breach timeline, since that evidence gap is a leading reason claims get denied.</p></li></ul><p>Insurers aren&#8217;t just asking whether you bought a policy anymore &#8212; they&#8217;re asking whether you can prove your controls actually work, and that&#8217;s a harder bar to clear without help. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: <a href="https://www.infosecurity-magazine.com/news-features/the-state-of-cyber-insurance-2025/">Soft Market, Hard Choices: The State of Cyber Insurance</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Anonymous Tip That Turned Into a $65,000 Software Bill]]></title><description><![CDATA[One confidential report to a piracy-reporting website was all it took to trigger a software audit that ended with a housewares company writing a five-figure check.]]></description><link>https://www.msptodaynews.com/p/the-anonymous-tip-that-turned-into</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-anonymous-tip-that-turned-into</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Mon, 21 Sep 2026 12:03:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JXMV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JXMV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JXMV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!JXMV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!JXMV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!JXMV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JXMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214256043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JXMV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!JXMV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!JXMV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!JXMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29540397-252b-480e-8b4f-d2d5811d5bd5_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f6jB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f6jB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!f6jB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!f6jB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!f6jB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f6jB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:61236,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214256043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f6jB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!f6jB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!f6jB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!f6jB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14f590b-80f2-46a5-a80e-0186d49ed802_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>One Report, One Audit, One Settlement</h2><p>Gibson Overseas, Inc., a Commerce, California-based provider of housewares products, found itself on the wrong end of a software compliance investigation after someone submitted a confidential report through BSA | The Software Alliance&#8217;s piracy-reporting website. BSA is the trade group that represents major software publishers, including Microsoft and Adobe, and one of the things it does on their behalf is investigate reports of unlicensed software use inside businesses.</p><p>The report didn&#8217;t need to come from a hacker, a disgruntled ex-employee&#8217;s lawsuit, or a government regulator. It just needed to come from someone who noticed the company was running more copies of software than it had paid for, and who knew where to send that information. From there, BSA opened an investigation into Gibson Overseas&#8217;s use of Adobe and Microsoft software.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The case ended the way most of these do: not in court, but in a negotiated settlement. Gibson Overseas agreed to pay $65,000, delete every unlicensed copy of the software in question, purchase legitimate licenses to replace what it had been using, and put stronger software asset management practices in place going forward. A company representative said in a statement that the audit had let the organization implement processes to make sure licensing issues didn&#8217;t resurface. A BSA vice president added that organizations need to maintain sound procedures to ensure the software running their business is properly licensed.</p><p>Nothing about this case involved a data breach, stolen credentials, or a ransomware note. It started with software that had simply been installed more times, or on more machines, than the license agreement allowed, and it ended with a bill, a licensing cleanup, and a public press release with the company&#8217;s name attached.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read a case like this and assume software licensing enforcement is something that happens to bigger companies with bigger IT footprints. It isn&#8217;t. BSA&#8217;s reporting program exists specifically to catch this kind of thing at businesses of any size, and the trigger is almost always mundane: a spreadsheet of purchased licenses that fell out of sync with what actually got installed, a laptop imaged from an old master copy, an employee who installed a personal copy of Office or Photoshop on a work machine because it was faster than filing a request.</p><p>Small and mid-size businesses are, if anything, more exposed to this kind of drift. There&#8217;s rarely a dedicated person tracking every license against every install, software gets added and removed as staff turn over, and nobody notices the gap until someone outside the company reports it. The report itself can come from almost anyone with visibility into what&#8217;s installed, current employees, former employees, or even competitors. Once BSA has a report, the investigation and the negotiation happen regardless of company size.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t exotic. It&#8217;s a basic software asset management practice: keep an accurate, current record of every software license the business owns and match it against every installation on every device. When someone leaves, when a machine is retired, or when a new license is purchased, that record should get updated the same day, not caught up on once a year. A lot of businesses have some version of this list, but it drifts out of date within months because nobody owns keeping it current.</p><p>The other piece is making license compliance part of routine IT hygiene rather than something only checked when a demand letter shows up. Doing an internal license audit once or twice a year, comparing installed software against paid licenses, catches problems before an outside report does, and it costs a fraction of what a settlement and legal fees would.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Keep a live software license inventory.</strong> Track every paid license against every actual installation, updated the day something changes, not once a year.</p></li><li><p><strong>Run your own internal audit periodically.</strong> Compare installed software to purchased licenses at least annually, before anyone outside the company does it for you.</p></li><li><p><strong>Standardize how software gets installed.</strong> Route new software requests through IT rather than letting employees install what&#8217;s convenient on their own.</p></li><li><p><strong>Retire licenses when machines or staff leave.</strong> Deactivate and reclaim licenses immediately during offboarding or hardware retirement, not months later.</p></li></ul><p>A software licensing gap doesn&#8217;t need a hacker to find it, it just needs one report to a website. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: <a href="https://www.prnewswire.com/news-releases/global-housewares-provider-pays-65000-to-settle-claims-of-unlicensed-software-use-89504332.html">Global Housewares Provider Pays $65,000 to Settle Claims of Unlicensed Software </a>Use.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Five-Month-Old Login That Deleted 456 Servers]]></title><description><![CDATA[A Cisco engineer resigned in April. In September, he still had a way in, and used it to wipe out the infrastructure behind 16,000 customer accounts.]]></description><link>https://www.msptodaynews.com/p/the-five-month-old-login-that-deleted</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-five-month-old-login-that-deleted</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Sun, 20 Sep 2026 12:01:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HhH6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HhH6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HhH6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!HhH6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!HhH6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!HhH6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HhH6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:79656,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214239827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HhH6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!HhH6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!HhH6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!HhH6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b970017-680f-4b09-b1b1-d6ff89921a52_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ADLr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ADLr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!ADLr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!ADLr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!ADLr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ADLr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68290,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214239827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ADLr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!ADLr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!ADLr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!ADLr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443e53b5-938c-44fc-83ac-7d1e4b4f1700_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Happened</h2><p>Sudhish Kasaba Ramesh worked as an engineer at Cisco Systems until he resigned in roughly April 2018. Five months later, in September 2018, he still had a way to reach Cisco&#8217;s cloud infrastructure. According to the Department of Justice, Ramesh accessed Cisco&#8217;s systems without authorization by deploying code from his own personal Google Cloud Project account into Cisco&#8217;s environment, which was hosted on Amazon Web Services.</p><p>The code he ran did real, deliberate damage. It deleted 456 virtual machines that supported Cisco&#8217;s WebEx Teams application. The immediate effect was that more than 16,000 WebEx Teams accounts were shut down, some for as long as two weeks, while Cisco worked to rebuild what had been destroyed. The DOJ press release notes no customer data was compromised in the incident, but the operational damage alone was substantial: Cisco spent approximately $1.4 million on employee time to restore the environment and issued more than $1 million in refunds to affected customers.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Ramesh pleaded guilty in August 2020 to one count of intentionally accessing a protected computer without authorization and recklessly causing damage, under the federal Computer Fraud and Abuse Act. He faced up to five years in prison and a $250,000 fine, with sentencing handled by Judge Lucy H. Koh in the Northern District of California.</p><p>What stands out isn&#8217;t the sophistication of the attack, it wasn&#8217;t sophisticated. It&#8217;s the timeline. This wasn&#8217;t a hacker breaking through Cisco&#8217;s defenses from the outside. It was a five-month gap between an employee&#8217;s last day and the moment his access to company infrastructure was actually, fully cut off.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>Cisco has an entire security operations team, and it still took an intentionally destructive former employee five months to get caught doing this. A small or mid-size business doesn&#8217;t have that team, and it usually doesn&#8217;t have Cisco&#8217;s ability to absorb a two-week outage across a third of its customer base and simply write a $2.4 million check to make it right.</p><p>What makes this case relevant to a 20-person accounting firm or a regional manufacturer isn&#8217;t the scale, it&#8217;s the mechanism. Offboarding is one of the most routine things a business does. Someone quits, someone gets fired, someone gets laid off, and it happens constantly, often without a formal IT step built into the process at all. If a company as resourced as Cisco can leave a five-month hole in its access controls, a smaller business without a dedicated IT or security function is at least as likely to leave an old employee&#8217;s login, VPN credential, or cloud account sitting active long after that person has stopped showing up to work.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t exotic. It&#8217;s a documented, enforced offboarding checklist that runs the same way every single time someone leaves, whether they quit on good terms or get walked out the same day. That means disabling accounts, revoking VPN and remote access, pulling API keys and cloud credentials, and removing the person from every system they ever touched, not just email and the badge reader. The Cisco case involved cloud infrastructure access specifically, the kind of access that&#8217;s easy to overlook because it doesn&#8217;t live in the same list as someone&#8217;s email login.</p><p>The second piece is a regular access audit, not just an offboarding event. A quarterly review of who has access to what, cross-checked against current employees, catches the account that offboarding missed. Ramesh had access for five months after he resigned. A quarterly audit would have caught that within ninety days, and depending on timing, potentially before the September damage occurred at all.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Build one offboarding checklist.</strong> Cover every system, not just email, VPN, and file shares, but cloud consoles, API keys, and any personal-device access tied to work accounts.</p></li><li><p><strong>Revoke access the same day someone leaves,</strong> regardless of whether the departure is voluntary, and regardless of how the person left on good terms.</p></li><li><p><strong>Run a quarterly access audit</strong> that cross-references active accounts against current employees, so a missed revocation gets caught in weeks, not months.</p></li><li><p><strong>Treat cloud and infrastructure credentials as seriously as email.</strong> They&#8217;re often the ones offboarding checklists forget, and they&#8217;re the ones that can do the most damage.</p></li></ul><p>A five-month gap in access revocation turned one departing engineer into a two-week outage and a seven-figure bill for a company with a full security team behind it. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: U.S. Attorney&#8217;s Office, Northern District of California, &#8220;<a href="https://www.justice.gov/usao-ndca/pr/san-jose-man-pleads-guilty-damaging-cisco-s-network">San Jose Man Pleads Guilty to Damaging Cisco&#8217;s Network&#8221;</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[88% of Employees Are Using Cloud Apps IT Never Approved]]></title><description><![CDATA[A year of enterprise traffic analysis found that almost every employee touches a personal cloud app each month &#8212; and more than a quarter of them are uploading actual company data into it.]]></description><link>https://www.msptodaynews.com/p/88-of-employees-are-using-cloud-apps</link><guid isPermaLink="false">https://www.msptodaynews.com/p/88-of-employees-are-using-cloud-apps</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Sun, 20 Sep 2026 12:01:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eZw9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eZw9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eZw9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!eZw9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!eZw9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!eZw9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eZw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80021,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214254891?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eZw9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!eZw9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!eZw9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!eZw9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa323466-481a-4dc4-9911-f49ab4eefc45_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!11i8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!11i8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!11i8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!11i8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!11i8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!11i8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67850,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214254891?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!11i8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!11i8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!11i8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!11i8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f6440e0-ab35-4fb5-a44e-86396be5a98d_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What the Data Shows</h2><p>Netskope Threat Labs spends its time watching what actually flows across enterprise networks, not what IT policy says should flow across them. Its January 2025 Cloud and Threat Report, built from telemetry across its customer base over the course of 2024, put a number on something most IT teams already suspected but rarely have hard data on: 88% of all employees used a personal cloud app, meaning an app instance tied to their own account rather than a company-managed one, at least once a month. That&#8217;s not a niche behavior. That&#8217;s nearly the entire workforce.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The more important number sits inside that one. Of those employees, more than one in four, 26%, weren&#8217;t just logging into a personal Gmail or a personal Google Drive to check something. They were uploading, posting, or otherwise sending data into it. And when Netskope&#8217;s researchers broke down what kind of data was actually crossing that line, the largest category, 60% of all policy violations, was regulated data: personal information, financial records, healthcare data, the kind of information that carries breach-notification obligations the moment it leaves a company&#8217;s control. Behind that came intellectual property at 16%, source code at 13%, and passwords or access keys at 11%.</p><p></p><p>None of this requires a sophisticated attacker or a clever phishing lure. It&#8217;s an employee finishing a report from home on a personal laptop and emailing themselves the file. It&#8217;s someone backing up client records to their own Google Drive because it&#8217;s faster than requesting access to the company&#8217;s system. It&#8217;s a departing employee moving a folder of &#8220;their&#8221; work to a personal OneDrive on the way out. Each individual action looks harmless in the moment. At the scale Netskope measured it, across a full year of traffic, it adds up to a steady, largely invisible drain of regulated and proprietary data into accounts no IT department controls, secures, or can revoke.</p><p></p><p>That&#8217;s the core problem shadow IT creates: not that employees are being reckless, but that they&#8217;re solving real work problems using whatever&#8217;s fastest, and the fastest option is almost never the one IT signed off on. The data doesn&#8217;t go anywhere dramatic. It just goes somewhere IT can&#8217;t see, can&#8217;t audit, and can&#8217;t pull back if that personal account is later compromised, sold in an account-recycling marketplace, or simply left logged in on a shared family computer.</p><p></p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read a stat like &#8220;88% of employees&#8221; and assume it&#8217;s describing a 50,000-person enterprise with sprawling departments nobody can fully monitor. It isn&#8217;t. The behavior underneath that number, an employee moving a file to a personal account because it&#8217;s convenient, doesn&#8217;t scale with company size. A 12-person accounting firm has the exact same dynamic as a Fortune 500 company: people finishing work at home, syncing folders to whatever cloud app they already have open, and reaching for their own login when the company system is slow or the access request would take too long.</p><p></p><p>Small and mid-size businesses are actually in a worse position on this specific risk, not a better one. Larger organizations at least have a chance of running a cloud access security tool that flags this kind of data movement. Most small businesses have no visibility into it at all, which means the first sign of a problem is usually a client asking why their financial records showed up somewhere they shouldn&#8217;t have, or a departing employee&#8217;s personal Drive account turning out to still have last quarter&#8217;s client files sitting in it, discovered only when something goes wrong.</p><p></p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t a lecture about policy. It&#8217;s closing the gap between &#8220;the sanctioned way to do this&#8221; and &#8220;the fastest way to do this,&#8221; because employees will always default to whichever one wins. That means IT-approved cloud storage and file-sharing tools need to actually be as convenient as the personal alternative, accessible from home, easy to request access to, and not gated behind a multi-day approval process that pushes people toward Google Drive out of sheer impatience.</p><p></p><p>The second piece is visibility. A business doesn&#8217;t need enterprise-grade cloud security software to catch most of this; it needs basic controls, like blocking uploads to unmanaged personal cloud accounts at the network or endpoint level, and a clear, low-friction path for employees to request an exception when they genuinely need one. Pair that with an offboarding checklist that actually asks &#8220;what personal apps did this person have company files in&#8221; rather than just disabling their company email, and the two biggest exposure windows, ongoing quiet leakage and departure-day data walking out the door, both shrink substantially.</p><p></p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Make the approved tool the fast tool.</strong> If requesting access to company file storage takes days, employees will default to personal apps out of pure convenience &#8212; fix the friction, not just the policy.</p></li><li><p><strong>Block uploads to unmanaged personal cloud accounts.</strong> Basic DLP or endpoint controls can stop company data from flowing into personal Google Drive, OneDrive, or webmail accounts without slowing down legitimate work.</p></li><li><p><strong>Build shadow IT checks into offboarding.</strong> Ask departing employees directly what personal apps might still hold company files, not just what company accounts to disable.</p></li><li><p><strong>Audit what&#8217;s actually being used, not what&#8217;s approved.</strong> Periodically review network and cloud traffic for personal app usage &#8212; the gap between policy and reality is exactly where this risk lives.</p></li></ul><p>The uncomfortable part of this data isn&#8217;t that employees are trying to cause harm. It&#8217;s that convenience quietly wins over policy almost every time, and most small businesses have no way to even see it happening. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Netskope, &#8220;<a href="https://www.netskope.com/press-releases/netskope-threat-labs-phishing-clicks-nearly-tripled-in-2024-ubiquitous-use-of-personal-cloud-apps-and-genai-tools-require-modern-workplace-security-to-mitigate-risk">Netskope Threat Labs: Phishing Clicks Nearly Tripled in 2024, Ubiquitous Use of Personal Cloud Apps and GenAI Tools Require Modern Workplace Security to </a>Mitigate Risk&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Southwest’s Holiday Meltdown Was a Decade in the Making]]></title><description><![CDATA[A December 2022 winter storm didn't cripple Southwest Airlines on its own &#8212; more than ten years of deferred technology investment did the real damage, and the warnings were on the record the whole time.]]></description><link>https://www.msptodaynews.com/p/southwests-holiday-meltdown-was-a</link><guid isPermaLink="false">https://www.msptodaynews.com/p/southwests-holiday-meltdown-was-a</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Sat, 19 Sep 2026 12:03:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QJF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QJF1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QJF1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!QJF1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!QJF1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!QJF1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QJF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77089,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214247853?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QJF1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!QJF1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!QJF1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!QJF1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff45ba5a1-64af-4d7e-a09a-e93ab802b8b1_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bxox!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bxox!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!Bxox!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!Bxox!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!Bxox!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bxox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a604461b-d883-4811-a536-801d3dbc2f56_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72486,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214247853?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bxox!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!Bxox!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!Bxox!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!Bxox!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa604461b-d883-4811-a536-801d3dbc2f56_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>A Decade of Warnings, Then a Total Meltdown</h2><p>When a winter storm swept the central United States the week before Christmas in 2022, airlines across the country scrambled to reroute crews and rebook passengers. Every major carrier weathered it. Southwest Airlines did not. Over ten days, the airline cancelled roughly 16,700 flights, stranding crews and passengers nationwide in what became one of the worst operational failures in U.S. airline history. The proximate cause, according to Southwest&#8217;s own leadership, was crew-scheduling software that simply could not keep pace once the number of reassignments needed spiked past what the system was built to handle.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>What made the story bigger than one bad week of weather was the paper trail behind it. A Dallas Morning News investigation traced more than a decade of warning signs that Southwest&#8217;s technology was falling behind: a 2011 telecommunications and loyalty-program failure, a 2015 crew-scheduling breakdown during a Chicago snowstorm that drew a $1.6 million Department of Transportation fine, a single router failure in 2016 that cascaded into 2,300 cancellations and cost the airline an estimated $54 million in lost revenue and added expenses, and repeated reservation-system outages through 2021. Union leaders representing pilots, flight attendants, and ground crews had been raising the same complaint for years: the systems running the airline&#8217;s day-to-day operations were old, patched together, and not being replaced fast enough.</p><p></p><p>Southwest&#8217;s own executives acknowledged this pattern on the record, well before December 2022. In 2017, then-Chief Operating Officer Mike Van de Ven told reporters, &#8220;to be real blunt, up until about 2010, it all worked pretty well&#8230; we&#8217;re at that point that we need to make some investments.&#8221; In late 2021, incoming CEO Bob Jordan said employees lacked the tools to manage operational complexity and that the airline needed to modernize. Those were not hidden concerns; they were public statements about known gaps, made a year and five years, respectively, before the gaps caused a nationwide meltdown.</p><p></p><p>The financial reckoning came fast. Southwest ultimately committed to spending $1.3 billion annually on IT upgrades starting in 2023, on top of $500 million already spent on a 2017 reservation-system overhaul and $2 billion committed in mid-2022 for other technology upgrades. The company also faced a $140 million civil penalty from the Department of Transportation over the meltdown, on top of the direct costs of rebooking, refunds, and reputational damage. None of that spending had to happen on an emergency timeline. It could have happened years earlier, at a fraction of the cost of a crisis response.</p><p></p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read a story about a major airline and assume it doesn&#8217;t apply to a 30-person company running a couple of on-site servers. But the mechanism is identical, just at a different scale. Southwest didn&#8217;t fail because one system was old; it failed because years of &#8220;we&#8217;ll get to it next budget cycle&#8221; decisions compounded until an ordinary stress event, a winter storm, hit systems that no longer had the headroom to absorb it. Small and mid-size businesses make that exact same trade-off every year when a server, firewall, or backup appliance quietly ages past its support window and nobody re-evaluates the risk because it&#8217;s &#8220;still running fine.&#8221;</p><p></p><p>The difference is that a small business doesn&#8217;t get a decade of near-misses and public warnings before the bill comes due, and it doesn&#8217;t have $1.3 billion a year to throw at a crisis fix. When aging hardware finally fails, or an unsupported system finally gets exploited, most small businesses are looking at days of downtime, lost customer trust, and a scramble to replace equipment on the worst possible timeline, all at once, with no warning window to plan around.</p><p></p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t exotic. It&#8217;s a documented hardware and software lifecycle plan, reviewed on a regular schedule, that treats &#8220;still running&#8221; as a different question from &#8220;still supported and still able to handle load.&#8221; Servers, network hardware, and line-of-business systems should have a known refresh date tied to vendor end-of-support dates, not to whether they happen to still boot. Southwest&#8217;s own history shows the cost of skipping this: a single aging router failure in 2016 cascaded into a multi-day, $54 million crisis, and it still took another six years and a much larger meltdown before the spending actually happened.</p><p></p><p>Just as important is treating internal warnings the way Southwest&#8217;s union leadership was treated: as data, not noise. If the people closest to the systems, IT staff, an MSP, or frontline employees, are flagging that equipment is aging out or struggling under normal load, that&#8217;s the signal to budget for a refresh before a storm, a traffic spike, or an attacker forces the issue on someone else&#8217;s timeline.</p><p></p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Track support end dates, not just uptime.</strong> Know exactly when every server, firewall, and network device loses vendor support, and budget its replacement before that date, not after something breaks.</p></li><li><p><strong>Treat single points of failure as unacceptable.</strong> A single aging router or server took down thousands of Southwest flights in 2016; identify anything in your environment with no backup or failover path.</p></li><li><p><strong>Listen to your own team&#8217;s warnings.</strong> If staff or your IT provider have flagged aging or struggling systems more than once, that&#8217;s a budget item, not a recurring complaint to note and move past.</p></li><li><p><strong>Plan refreshes on a schedule, not a crisis.</strong> A predictable three-to-five-year hardware refresh cycle costs far less, and causes far less disruption, than replacing everything at once after a failure.</p></li></ul><p>Southwest&#8217;s meltdown didn&#8217;t start with the weather; it started with years of technology decisions that kept getting pushed to next year. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: The Dallas Morning News, &#8220;<a href="https://www.dallasnews.com/business/airlines/2023/02/08/southwest-airlines-december-meltdown-came-after-years-of-tech-failures/">Southwest Airlines&#8217; December meltdown came after years of tech </a>failures&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[When Your Bookkeeper’s Software Vanishes Overnight]]></title><description><![CDATA[A well-funded accounting startup shut its doors with three days&#8217; notice, and thousands of small businesses found out their financial records were locked behind a login page that was about to disappear]]></description><link>https://www.msptodaynews.com/p/when-your-bookkeepers-software-vanishes</link><guid isPermaLink="false">https://www.msptodaynews.com/p/when-your-bookkeepers-software-vanishes</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Fri, 18 Sep 2026 12:04:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tLqY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tLqY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tLqY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!tLqY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!tLqY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!tLqY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tLqY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75862,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214246657?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tLqY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!tLqY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!tLqY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!tLqY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0af3d3c-6e3c-4d4f-9a38-92c0b510b4a1_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xv6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xv6B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!Xv6B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!Xv6B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!Xv6B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xv6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214246657?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Xv6B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!Xv6B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!Xv6B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!Xv6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30ed9532-6ffb-4ee0-aa95-e32c66b9d52e_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Happened</h2><p>On December 27, 2024, customers of Bench Accounting logged in, or tried to, and found a single message where their bookkeeping platform used to be: &#8220;We regret to inform you that as of December 27, 2024, the Bench platform will no longer be accessible.&#8221; No slow wind-down, no months-long transition plan. The Canada-based startup, which had raised $113 million from investors including Shopify and Bain Capital Ventures and employed more than 600 people, simply went dark, according to TechCrunch&#8217;s reporting the same day.</p><p>More than 35,000 U.S. small businesses used Bench to handle their bookkeeping and, for many, their tax preparation. All of that lived inside Bench&#8217;s platform: transaction categorization, financial statements, and the underlying documents accountants and the IRS would eventually want to see. When the platform disappeared, so did straightforward access to all of it, right in the middle of a stretch when small businesses are closing out their books for the year and starting to think about tax season.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Bench&#8217;s own guidance to customers captured how tight the timeline was: download your data by December 30, just three days out, with a hard cutoff for full access by March 2025, and in the meantime, go file a six-month extension with the IRS because your bookkeeping situation is now unresolved. The company also pointed customers toward Kick, a competing startup, as a place to land. Founder Ian Crosby later said on LinkedIn that he&#8217;d been replaced by the board months earlier and that the shutdown followed a change in direction he didn&#8217;t control, which doesn&#8217;t change what customers faced: a vendor that held their financial records was gone, and the clock to get that data out was measured in days.</p><p>For a business owner, none of this involved a hack, a phishing email, or a criminal actor. It was simply a company deciding, or being forced, to stop operating, and taking customer access down with it on a timeline no customer set.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s easy to read this and think &#8220;that&#8217;s an accounting-specific story,&#8221; but the actual lesson has nothing to do with bookkeeping. Small and mid-size businesses routinely hand critical, hard-to-recreate data, financial records, customer histories, project files, communications, to a single SaaS vendor and treat the vendor&#8217;s platform as the only copy. That works fine every single day the vendor is in business. It stops working the day they&#8217;re not, and smaller vendors serving smaller customers don&#8217;t come with the assumption of permanence that a Microsoft or Google carries.</p><p>The businesses hit hardest by the Bench shutdown weren&#8217;t reckless. They picked a well-funded, VC-backed platform that looked stable right up until it wasn&#8217;t. That&#8217;s exactly the point: vendor stability is not something you can judge from the outside, and a funding round or a big customer logo tells you almost nothing about what happens if the company runs out of runway or a board makes a call the founder doesn&#8217;t agree with. The only thing that protects you from that uncertainty is not depending on any single vendor as your only copy of the data.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t complicated, but it does need to be deliberate: export your data out of every SaaS platform you rely on, on a regular schedule, and keep that export somewhere you control, not inside the same vendor&#8217;s ecosystem. For bookkeeping specifically, that means periodic exports of financial statements, transaction detail, and source documents to a format you can open without that vendor&#8217;s login. The same logic applies to CRM data, project management platforms, and anything else where &#8220;the app&#8221; is currently the only place the information lives.</p><p>It&#8217;s also worth reading the contract or terms of service for exactly this scenario before you need it: what happens to your data if the vendor shuts down, how much notice are they obligated to give, and can you get a full export on demand rather than only during a wind-down window. Most businesses never check. The businesses that weren&#8217;t scrambling in December 2024 were the ones already exporting Bench data regularly as a matter of habit, not the ones who happened to get lucky.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Export critical data on a recurring schedule.</strong> Don&#8217;t wait for a shutdown notice; pull financial, customer, and project data out of every core SaaS platform regularly and store it somewhere you control.</p></li><li><p><strong>Read the data-portability terms before you sign up.</strong> Know what a vendor owes you for notice and export access if they ever shut down or discontinue a product.</p></li><li><p><strong>Keep an offline or vendor-independent copy of anything irreplaceable.</strong> A single platform should never be the only place records like tax documents or financial statements exist.</p></li><li><p><strong>Ask your MSP to inventory your SaaS dependencies.</strong> Knowing exactly which vendors hold which critical data makes a sudden shutdown a manageable task instead of a scramble.</p></li></ul><p>A business doesn&#8217;t need to get hacked to lose access to its own records; sometimes a vendor just closes the doors. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: TechCrunch, &#8220;<a href="https://techcrunch.com/2024/12/27/bench-shuts-down-leaving-thousands-of-businesses-without-access-to-accounting-and-tax-docs">Bench shuts down, leaving thousands of businesses without access to accounting and tax docs&#8221;</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[When One Bad Update Took Down the Whole Business]]></title><description><![CDATA[The July 2024 CrowdStrike outage grounded airlines and hospitals, but it also quietly shut down locksmiths, restaurants, and one-person consulting firms who had no way to work around it.]]></description><link>https://www.msptodaynews.com/p/when-one-bad-update-took-down-the</link><guid isPermaLink="false">https://www.msptodaynews.com/p/when-one-bad-update-took-down-the</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Thu, 17 Sep 2026 12:01:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Yb50!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yb50!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yb50!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Yb50!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Yb50!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Yb50!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yb50!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76591,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214245318?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yb50!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!Yb50!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!Yb50!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!Yb50!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6e06ebb-9838-4a4e-b677-8ae235e71e34_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YL1u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YL1u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!YL1u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!YL1u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!YL1u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YL1u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214245318?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YL1u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!YL1u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!YL1u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!YL1u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a69228f-400b-4dd2-8230-b0d585036a4a_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Happened</h2><p>On Friday, July 19, 2024, a faulty software update from cybersecurity vendor CrowdStrike crashed roughly 8.5 million Windows computers worldwide, sending them into repeated reboot loops. The disruption hit airlines, hospitals, and banks first, which is where most of the headlines went. But CrowdStrike&#8217;s customer base extends well past the Fortune 500, and the damage reached far smaller operations that had nothing to do with the mistake and no way to route around it.</p><p>In Manhattan, Tsvetta Kaleynska runs a small consulting firm called RILA Global Consulting. When the outage hit, she couldn&#8217;t pay her employees, missed a Friday contract deadline, and lost a prospective client worth roughly a quarter of her annual earnings because Docusign was unreachable. &#8220;If I were part of a big company, then I would be able to delegate and get support from computer science or security services,&#8221; she told the Associated Press. &#8220;But as a small business owner, I am depending only on myself.&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The pattern repeated across industries. In Melbourne, Australia, locksmith Chris Seabrook lost the ability to send or receive email, access his files, manage his schedule, or create invoices. In Maryland, a virtual mental health practice called Telapsychiatry had therapists locked out of the computers and phone systems they needed to see patients, and had to improvise with Zoom and Ring Central to keep appointments running. A Manhattan restaurant group, Handcraft Hospitality, couldn&#8217;t reach its cloud-based accounting software to view receipts, process invoices, or run employee paychecks.</p><p>None of these businesses had installed CrowdStrike themselves in any meaningful sense, and none of them had done anything wrong. They were simply downstream of a single vendor&#8217;s mistake, with no second system, no offline process, and no alternative way to reach the tools their business ran on. Days after the outage was fixed, many were still working through the backlog.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>The gap the AP kept surfacing in its reporting was resources, not fault. A large enterprise IT department can often fail over to a different tool, work from paper temporarily with a plan already in place, or throw a team of specialists at getting critical systems back online within hours. A one-person locksmith shop or a three-location restaurant group typically has none of that in reserve. As one expert quoted in the coverage put it, big companies have a &#8220;sizable number of experts on their payroll,&#8221; while small businesses face an &#8220;uphill battle&#8221; with far fewer technical resources to draw on when something like this happens.</p><p>That imbalance is exactly why single points of failure matter more, not less, for smaller operations. If your business runs on one cloud provider, one accounting platform, and one email system, with no fallback for any of them, an outage anywhere in that stack becomes an outage in your entire business. You don&#8217;t need to be targeted by an attacker or make a mistake yourself to lose a day of revenue, a client, or your ability to pay employees. You just need to be a customer of whoever had the bad day.</p><h2>What Actually Would Have Stopped This</h2><p>No single business could have stopped CrowdStrike&#8217;s update from shipping, and that&#8217;s the point: the fix here isn&#8217;t preventing the outage, it&#8217;s surviving it. That starts with knowing which of your systems are true single points of failure, the ones where, if they go down, your business simply stops, and building even a basic manual workaround for each one. For the businesses in this story, that would have meant a documented way to process payroll without the primary software, an offline or alternate method for signing contracts, and a backup line of communication with clients that didn&#8217;t depend on one platform staying up.</p><p>It also means treating &#8220;the cloud provider will keep it running&#8221; as a plan you never actually wrote down. A short, practical continuity plan, who does what, using what alternate tool or process, when a core system goes dark, turns a chaotic scramble into a known set of steps your team can execute in the first hour instead of the third day.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Map your single points of failure.</strong> List every system that, if it went down for a day, would stop the business entirely, and start there.</p></li><li><p><strong>Write down a manual fallback</strong> for payroll, invoicing, and client communication, even a simple one, so a platform outage doesn&#8217;t mean a full stop.</p></li><li><p><strong>Diversify where it&#8217;s cheap to.</strong> Don&#8217;t route every critical function, email, e-signature, payments, through the same single vendor when a second option exists.</p></li><li><p><strong>Test your plan before you need it.</strong> A continuity plan nobody has walked through is just a document, not a capability.</p></li></ul><p>The businesses in this story weren&#8217;t breached, careless, or slow to patch. They were simply one vendor away from being unable to operate, and had no plan for that day. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Associated Press via PBS NewsHour, &#8220;<a href="https://www.pbs.org/newshour/economy/many-small-businesses-struggle-to-resume-normal-operations-days-after-global-tech-outage">Many small businesses struggle to resume normal operations days after global tech outage</a>&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Their Backups Were Fine. Recovery Still Failed.]]></title><description><![CDATA[The data copy survived the ransomware attack intact. The business still couldn&#8217;t come back online, because backups and recovery turned out to be two different things.]]></description><link>https://www.msptodaynews.com/p/their-backups-were-fine-recovery</link><guid isPermaLink="false">https://www.msptodaynews.com/p/their-backups-were-fine-recovery</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Thu, 17 Sep 2026 12:01:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7JhY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7JhY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7JhY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!7JhY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!7JhY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!7JhY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7JhY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75169,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214190927?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7JhY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!7JhY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!7JhY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!7JhY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56599681-d72e-4e8a-bab1-d787730d74e0_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ransomware built by a group researchers track as DeadLock represents a shift worth every business owner understanding, not because it encrypts files, all ransomware does that, but because of what it deliberately destroys before it ever touches a single document.</p><h2>How the Attack Unfolded</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!js02!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!js02!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!js02!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!js02!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!js02!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!js02!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78808,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214190927?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!js02!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!js02!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!js02!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!js02!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfac423-684d-4f1a-921a-fe28c3910cdc_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Before encryption starts, DeadLock runs a preparation phase aimed specifically at an organization&#8217;s ability to recover. Microsoft&#8217;s threat intelligence team found it systematically disables Volume Shadow Copy and Windows Backup services, the built-in Windows features many small businesses rely on as their safety net. It goes further, also targeting Hyper-V services that support virtual machines, and Active Directory services that every application and administrator depends on for authentication. Then it empties the recycle bin and clears or disables event logs, cutting off both easy recovery options and the evidence an investigator would need to reconstruct what happened.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>When it runs with administrator access, and it&#8217;s specifically built to try to obtain that access, it gains the ability to touch protected files, interfere with security software, and remove the exact safety nets a business would reach for first.</p><p>The result, in the cases Microsoft studied, wasn&#8217;t simply &#8220;we lost some files.&#8221; It was organizations with backups that were technically intact, discovering that a clean copy of the data alone wasn&#8217;t enough to bring the business back.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>Most businesses think about ransomware protection as a single question: do we have backups? This case shows that&#8217;s the wrong question, or at least an incomplete one. Researchers draw a sharp distinction between restoring and recovering: a restore returns a copy of protected data. A recovery returns a fully working business service, including the identity systems, network configuration, encryption keys, and infrastructure settings that data depends on to actually function.</p><p>That distinction shows up in painfully specific ways. A database can restore successfully while the encryption key needed to read it is gone. A server can come back online without the network routing or naming settings that let anything actually reach it. A recovery plan built months ago can be quietly out of date the moment infrastructure changes, meaning the plan and the live environment no longer match by the time you need them to.</p><p>This matters just as much for a ten-person company running everything through a few cloud services as it does for a large enterprise. The dependency chain, identity, network, keys, configuration, is just as real at small scale. It&#8217;s simply less likely anyone has ever tested whether it actually reconnects after a real failure.</p><h2>What Actually Would Have Stopped This</h2><p>The fix isn&#8217;t a better backup tool. It&#8217;s testing the full recovery, not just the data copy. That means confirming your recovery plan restores identity systems, encryption keys, private networking, DNS, and application configuration, not only files and databases. It means verifying your backups are genuinely immutable against a compromised administrator account, since an attacker with admin rights can otherwise delete or encrypt the backups right along with everything else. And it means actually rehearsing a full recovery on a regular schedule, because environments change faster than backup plans get reviewed, and a plan nobody has tested since it was written is a plan you&#8217;re hoping works, not one you know works.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Confirm backups cover the full dependency chain</strong>, not just data: identity, encryption keys, network configuration, and DNS all need a documented recovery path.</p></li><li><p><strong>Verify immutability against an administrator account</strong>, not just against outside attackers. Backups an admin login can delete are backups ransomware with admin access can delete too.</p></li><li><p><strong>Test a full recovery on a real schedule</strong>, not just a data restore. The gap between &#8220;we have backups&#8221; and &#8220;we can actually recover&#8221; only shows up when you try.</p></li><li><p><strong>Keep a recovery point that predates the compromise</strong>, not just the newest backup available, since some ransomware sits quietly for a period before triggering encryption.</p></li></ul><p>A backup you&#8217;ve never tested recovering from is a plan, not a safety net. The businesses that come back quickly from an incident like this are the ones who found the gaps in a drill, not during the actual emergency. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup,<a href="https://www.jkcsi.com/contact/"> get in touc</a>h.</p><div><hr></div><p></p><p><em>Source: Microsoft Threat Intelligence, on DeadLock ransomwar<a href="https://www.decryptiondigest.com/blog/deadlock-ransomware-backup-not-a-recovery-plan">e, as reported by Decryption Digest, &#8220;DeadLock Ransomware Recovery: Why Backups Alone Aren&#8217;t Enough</a>&#8221;.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading MSP Today Publication! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Backup Plan That Wasn’t: How One Bad Night Closed a Company for Good]]></title><description><![CDATA[Code Spaces had a &#8220;full recovery plan that has been proven to work.&#8221; It still went out of business in about 12 hours, because every backup lived in the same place an attacker could reach.]]></description><link>https://www.msptodaynews.com/p/the-backup-plan-that-wasnt-how-one</link><guid isPermaLink="false">https://www.msptodaynews.com/p/the-backup-plan-that-wasnt-how-one</guid><dc:creator><![CDATA[MSP Today]]></dc:creator><pubDate>Mon, 14 Sep 2026 12:03:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2oaz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2oaz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2oaz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!2oaz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!2oaz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!2oaz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2oaz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71755,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214235061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2oaz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!2oaz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!2oaz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!2oaz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97107576-9cf5-480f-902d-e29bd7edc551_1600x900.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U-A9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U-A9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!U-A9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!U-A9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!U-A9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U-A9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png" width="1456" height="760" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:760,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76622,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://msptoday.substack.com/i/214235061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U-A9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 424w, https://substackcdn.com/image/fetch/$s_!U-A9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 848w, https://substackcdn.com/image/fetch/$s_!U-A9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 1272w, https://substackcdn.com/image/fetch/$s_!U-A9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bc8bd8e-c700-4b13-9a4d-ed7286ba19dd_1629x850.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The Company That Had a Recovery Plan &#8212; And Lost Anyway</h2><p>Code Spaces was a small company offering code hosting and collaboration tools for software teams, built entirely on Amazon Web Services. In June 2014, it was hit with a DDoS attack, and shortly after, an intruder gained access to the company&#8217;s AWS EC2 control panel. The attacker left extortion messages through a Hotmail account, demanding payment to hand back control.</p><p>Code Spaces tried to do the obvious thing: change the passwords and lock the attacker out. But by then the intruder had already set up backup logins of their own. When the team moved to retake the account, the attacker retaliated by systematically destroying what was there. In the company&#8217;s own words, &#8220;he had removed all EBS snapshots, S3 buckets, all AMI&#8217;s, some EBS instances and several machine instances.&#8221; Most of the company&#8217;s data, machine configurations, and offsite backups were partially or completely wiped out in the process.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The bitter irony is that Code Spaces believed it was covered. The company had publicly stated it maintained &#8220;a full recovery plan that has been proven to work,&#8221; including offsite backups. What that plan didn&#8217;t account for was that those backups, along with everything else, were reachable through the exact same AWS control panel the attacker had already compromised, with no multi-factor authentication standing in the way. Separate backups only protect you if an attacker (or a fire, or a flood) can&#8217;t reach them too.</p><p>Code Spaces never came back from it. The company&#8217;s own statement was blunt: the cost of resolving the incident would put them in &#8220;an irreversible position both financially and in terms of ongoing credibility.&#8221; They shut down entirely, spending their final days helping customers pull out what data they could before the business ceased trading for good.</p><h2>Why This Matters If You&#8217;re Not a Big Company</h2><p>It&#8217;s tempting to read this and think &#8220;we&#8217;re not a tech company running on AWS, this doesn&#8217;t apply to us.&#8221; But strip away the cloud-specific details and the failure is completely ordinary: one login, one control panel, one point of failure that touched both the live systems and the backups meant to save them if something went wrong. That&#8217;s not a big-company problem. It&#8217;s the default setup for most small and mid-size businesses that never had someone sit down and design their backups on purpose.</p><p>Most SMBs assume they&#8217;re covered because &#8220;we have backups&#8221; &#8212; a server that copies files somewhere, a NAS in the closet, a folder synced to the cloud. What almost never gets asked is: if the thing that destroys your main system also has access to your backup, are you actually protected? A fire that takes out the office takes out the NAS sitting in it too. A compromised admin account that can delete production data can usually delete the backup copies sitting right next to it. A plan that&#8217;s never been tested against that scenario isn&#8217;t really a plan &#8212; it&#8217;s an assumption.</p><h2>What Actually Would Have Stopped This</h2><p>The fix here isn&#8217;t complicated, but it does take deliberate setup. Backups need to be isolated from the systems they protect &#8212; physically, logically, or both &#8212; so that whatever destroys your production environment (a hacker, a fire, a hardware failure, a ransomware payload) can&#8217;t also reach the copy meant to bring you back. That means offsite or cloud backups with separate credentials from your day-to-day admin account, ideally with multi-factor authentication and some form of immutability or delayed deletion so a single compromised login can&#8217;t wipe out both the original and the backup in one move.</p><p>Just as important: a recovery plan is only real if it&#8217;s been tested. Code Spaces believed its plan worked because it had never been forced to prove otherwise under attack. A backup you haven&#8217;t tried restoring from, on a schedule you actually rehearse, is a hope, not a plan.</p><h2>Security Checklist for Your Business</h2><ul><li><p><strong>Separate your backup credentials.</strong> Don&#8217;t let the same login that manages daily operations also be able to delete your backups &#8212; use distinct accounts with MFA required.</p></li><li><p><strong>Isolate backups from production.</strong> Keep at least one copy offline, air-gapped, or in a separate account/environment that a compromised system can&#8217;t reach.</p></li><li><p><strong>Test your restores on a schedule.</strong> A backup nobody has restored from is unverified &#8212; treat quarterly test restores as non-negotiable, not optional.</p></li><li><p><strong>Write down the actual recovery steps.</strong> Document who does what, in what order, so recovery doesn&#8217;t depend on one person&#8217;s memory during a crisis.</p></li></ul><p>A backup plan only counts if it survives the exact disaster it was built for. MSP Today&#8217;s trusted tech partner is <a href="https://www.jkcsi.com/">JK Computer Solutions</a>. If you want a second set of eyes on your setup, <a href="https://www.jkcsi.com/contact/">get in touch</a>.</p><div><hr></div><p></p><p><em>Source: Help Net Security, &#8220;<a href="https://www.helpnetsecurity.com/2014/06/19/code-hosting-code-spaces-destroyed-by-extortion-hack-attack/">Code hosting Code Spaces destroyed by extortion hack </a></em><a href="https://www.helpnetsecurity.com/2014/06/19/code-hosting-code-spaces-destroyed-by-extortion-hack-attack/">attack</a>&#8221;.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.msptodaynews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>