Blog
Guidance for your firm
Practical IT and security guidance for professional service firms. Choose your industry to see what was written for you.
Account takeover: the risk financial advisers can't delegate
For an advisory practice, the most damaging attack is someone signing in as you. Here is how it happens and the controls that prevent it.
Read articleAntivirus is not enough: what EDR adds
Antivirus and EDR do different jobs. Here is what each one catches, why modern attacks get past antivirus alone, and what a small firm needs on every computer.
Read articleBackup gets your files back. Business continuity keeps you working.
Backup and business continuity are often sold as one thing. They solve different problems. Here is the difference, the two numbers that define what you need, and how to decide.
Read articleProtecting policyholder data at an insurance agency
An agency holds personal, financial and sometimes health details for every client. Here is where that information is exposed and what to put in place.
Read articleRansomware and the project deadline: what design firms should prepare
Architecture and engineering firms depend on large files, specialist software and fixed deadlines. Here is why that makes them a target and how to be ready.
Read articleSecurity awareness training that people don't ignore
Most security training is an annual video nobody remembers. Here is what works for a small firm, how simulated phishing fits in, and what records to keep.
Read articleSIEM and MDR, explained for a firm without a security team
What security monitoring does, how SIEM and MDR differ, and how to tell whether a small professional firm needs them.
Read articleVulnerability scan or penetration test: which does your firm need?
Clients and insurers ask for both and firms often confuse them. Here is what each one is, what it costs in effort, and when a small firm should do it.
Read articleWhat a help desk should do for a professional firm
A help desk is more than someone to call when the printer stops. Here is what good support looks like, how to measure it, and the signs yours is costing you time.
Read articleWhat email security does that your inbox doesn't
Microsoft 365 and Google Workspace filter spam. Targeted phishing and impersonation are a different problem. Here is what dedicated email security adds and how to tell if you need it.
Read articleWhat RMM is, and why your IT provider depends on it
Remote monitoring and management is the tool behind almost everything a managed IT provider does. Here is what it does on your computers and what to ask about it.
Read articleYour client's security team will ask about yours
Large companies now treat their consultants as part of their own security risk. Here is why, what they'll ask, and how a small consultancy gets ready.
Read articleCloned voices and payment fraud: the call-back rule that stops it
AI can copy a voice from a few seconds of audio. Here is how the fraud works, why professional firms are targets, and the simple procedure that defeats it.
Read articleDoes Microsoft 365 back up your data?
Most firms assume their email and files are backed up because they live in the cloud. They are kept available, which is a different thing.
Read articleHow AI changed phishing, and what to look for now
The old advice was to watch for bad spelling and odd phrasing. AI removed those tells. Here is what a phishing email looks like today and how firms defend against it.
Read articleMulti-factor authentication: the first thing to fix
If your firm does one thing for its security this month, turn on multi-factor authentication for email. Here is what it is, why it matters, and how to roll it out.
Read articleTen questions to ask before you hire an IT provider
Most firms choose an IT provider on price and a good first meeting. These ten questions show how a provider really works, and what a good answer sounds like.
Read articleThe 15-point security checklist for professional firms
A free checklist any law, accounting or advisory firm can work through in an afternoon to find where its client data is exposed.
Read articleThe first hour of a ransomware attack
What to do, in order, when a screen at your firm shows a ransom note. A plain plan you can print and keep by the phone.
Read articleThe same-day offboarding checklist
When someone leaves your firm, their access should end that day. This is every place it tends to linger, in the order to deal with it.
Read articleWhat cyber insurers ask, and how to be ready
Cyber insurance applications have turned into security audits. These are the questions professional firms are asked, what each one is really checking, and how to answer with evidence.
Read articleWhat managed IT costs a professional firm
How per-person pricing works, what drives the price up or down, the costs that hide outside the monthly fee, and how to compare two quotes fairly.
Read articleWhy software updates matter more than they used to
Attackers increasingly get in through software that hasn't been updated. Here is why that's happening and what a small firm should do about it.
Read articleWire fraud at closing: how it happens and how to stop it
Real estate closings are the most reliable target for payment fraud. This is the playbook attackers follow, what AI has added to it, and the controls that protect a buyer's funds.
Read articleYour firm's passwords are on the dark web. Now what?
What it means when staff credentials turn up in stolen data, how they got there, and the three steps to take when you find out.
Read articleYour staff are using AI tools. Here is a policy that works.
People at your firm are already pasting text into AI chatbots. Banning it doesn't work and ignoring it is a risk. This is a practical policy a small professional firm can adopt.
Read articleA cybersecurity checklist for small law firms
Twelve practical controls a small law firm should have in place to protect client information, and how to tell whether yours are working.
Read articleHow to answer a client security questionnaire
Corporate clients increasingly send their law firms, accountants and consultants a security questionnaire. Here is how to answer one honestly and keep the work.
Read articleTax season phishing: what accounting firms should watch for
The phishing emails that target accounting and tax practices during busy season, and the defenses that stop them.
Read articleThe written information security plan: what tax preparers need to know
What a written information security plan (WISP) is, why tax and accounting practices are expected to have one, and what goes in it.
Read articleSee what it costs for your firm.
Build a plan in two minutes. No call required.
