Resource Center
Straight answers to technology questions.
Written in plain language by the people who do the work.
Technology Leadership
All Technology LeadershipManaged IT
All Managed IT- How do we know it's time to replace our IT provider?It's time when leadership has stopped trusting the advice. The usual signs: calls go to voicemail, tickets sit for days, projects stall, you can't tell what you're paying for, and nobody talks to you about where your technology is headed. One bad week isn't a reason to switch. A pattern is.
- Should we outsource IT or hire our own IT staff?Most organizations under about 150 people get more for their money by outsourcing to a good managed IT provider: one salary buys one person with one skill set and no backup. Larger organizations often do best with a blend: an internal IT lead who knows the business, backed by a provider for depth, coverage, and security.
- How do we measure whether our IT provider is doing a good job?Ask for numbers, not adjectives. A well-run provider can tell you how quickly they answer the phone, what percentage of issues they solve on the first call, how long tickets stay open, and how current your computers are on security updates, and should review those numbers with you regularly.
Microsoft 365
All Microsoft 365- Can Teams replace our phone system?For most organizations already on Microsoft 365, yes. Teams Phone gives every user a real phone number that rings on their computer, mobile app, and desk phone if they want one, with auto attendants and call queues. It needs a Teams Phone license plus a way to connect to the phone network, such as a Microsoft Calling Plan.
- Should we move Microsoft 365 away from GoDaddy?If your organization has grown since you bought Microsoft 365 through GoDaddy, usually yes. GoDaddy-provisioned accounts are set up in a way that can limit your administrative control and access to some security features. Moving to direct Microsoft or partner licensing gives you full control. Your email and files stay put during the move.
- Which Microsoft 365 license do we need: Business Standard, Business Premium, or E3?For most organizations under 300 users, Business Premium is the best value: it includes everything in Business Standard plus the security tools, Intune device management, Entra ID P1 for Conditional Access, and Defender for Business, that insurers and auditors now expect. E3 makes sense above 300 users or when you need enterprise-only features.
- Does everyone need a Microsoft 365 Copilot license?Usually not. Copilot Chat, which comes with Microsoft 365 work accounts, covers a lot of everyday drafting and research. The paid Microsoft 365 Copilot add-on earns its cost for people who live in email, meetings, and documents all day. Start with a pilot group, measure what they actually use, then decide who else gets a seat.
- Does Microsoft 365 back up our email and files, or do we need our own backup?Microsoft keeps the service running and holds deleted items for a limited time, but that isn't the same as a backup you control. If files are deleted past the retention window, encrypted by ransomware, or wiped by a departing employee, you need a separate backup. Microsoft now offers one as an add-on, and third-party options exist.
- What is Conditional Access?Conditional Access is a Microsoft Entra ID feature that decides whether a sign-in is allowed based on who is signing in, from what device, and from where. It lets you require multi-factor authentication, block risky locations, or allow access only from managed computers. It requires Entra ID P1, which is included in Business Premium, E3, and E5.
- Will Copilot show employees files they shouldn't see?Copilot only shows people what they already have permission to open. The problem is that most Microsoft 365 tenants overshare: sites open to everyone, "anyone with the link" sharing, and folders that were never locked down. Copilot makes that oversharing easy to find, so fix permissions before you switch it on.
Cybersecurity
All Cybersecurity- Are we too small to be a target for hackers?No. Most attacks are automated and don't check your size first: they look for weak passwords, missing updates, and people who will click. Smaller organizations are often easier targets because they have fewer defenses, and they're a route into larger clients and partners. The good news: a handful of basic controls stop most attacks.
- How do we protect our organization from ransomware?Make it hard to get in, quick to spot, and possible to recover without paying. That means multi-factor authentication everywhere, prompt security updates, endpoint detection with someone watching around the clock, and backups attackers can't reach or delete, tested regularly. Then write down what you'll do on the day it happens.
- How do we stop fake invoices and wire-transfer fraud sent by email?Treat every request to change payment details as suspicious until it's verified by phone, using a number you already had, not one from the email. Add multi-factor authentication so your own mailboxes can't be taken over, set up email authentication so criminals can't send as your domain, and train the people who move money.
- Is it safe to keep a machine running an old version of Windows?Not as-is, but it can be made reasonably safe when replacing it isn't an option. Put it on its own isolated network, allow only the connections it needs, keep it off email and the web, control USB drives, keep a full backup image, and plan for its eventual replacement. Most of the risk comes from what it's connected to.
- Is it safe to put client data into ChatGPT?Not in the free or personal versions. Consumer AI tools can keep what you type and may use it to improve their models, and you have no contract covering it. Business versions, such as Microsoft 365 Copilot or ChatGPT Business and Enterprise, don't train on your data and come with commercial terms. Even then, a written policy should say what data is allowed.
- What's the difference between EDR and MDR?EDR (endpoint detection and response) is software on each computer that watches for suspicious behavior and can stop it. MDR (managed detection and response) adds people: a security team that monitors those alerts around the clock, investigates, and responds. EDR is the tool; MDR is the tool plus the team watching it.
Compliance
All Compliance- Can a healthcare practice use ChatGPT or Copilot under HIPAA?Yes, but only with tools covered by a Business Associate Agreement (BAA) and set up correctly. Free and personal AI accounts have no BAA, so protected health information must never go into them. Microsoft covers Microsoft 365 services under its BAA, and OpenAI offers BAAs only for certain business products. Confirm coverage for the exact product and license before any patient data goes in.
- Do we need a HIPAA risk assessment?Yes, if you're a covered entity or business associate. The HIPAA Security Rule requires an accurate and thorough risk analysis of threats to electronic protected health information, and it's the first thing investigators ask for after a breach. It should be updated regularly and whenever your systems or operations change significantly.
- Does our accounting firm need a written information security plan (WISP)?Yes. Tax and accounting professionals are covered by the FTC Safeguards Rule, which requires a written information security program, and the IRS expects every tax preparer to have one. IRS Publication 4557 explains the requirements, and Publication 5708 provides a sample plan to start from. It needs to reflect what your firm actually does.
- Does the FTC Safeguards Rule apply to our dealership?If your dealership arranges financing or leasing, almost certainly. The FTC treats those dealers as financial institutions under the Gramm-Leach-Bliley Act. The updated Safeguards Rule requires a written information security program, a qualified person in charge of it, risk assessments, multi-factor authentication, encryption, and notifying the FTC of certain breaches.
- What is data classification, and do we need it?Data classification means sorting your information by how sensitive it is, usually into three or four levels such as Public, Internal, Confidential, and Restricted, and labeling it so people and systems handle it properly. Most organizations of 20 or more people benefit, and it matters more once AI tools like Copilot can search across everything.
- What should an AI acceptable-use policy say?Keep it short enough that people read it. It should name the approved AI tools, list the information that never goes into any AI tool, require a person to review anything AI produces before it reaches a client, and say who to ask about a new tool. Review it at least yearly, because the tools change quickly.
Remote Workforce
All Remote Workforce- How do we get laptops to remote employees, and back when they leave?Standardize, pre-configure, and ship from one place. Each laptop should be set up and secured before it ships, enrolled in device management so it can be supported and wiped remotely, and tracked. When someone leaves, send a prepaid return kit, disable their access immediately, and securely wipe the device before it's reused.
- How often should computers be replaced?Plan on about four to five years for most business laptops and desktops, sooner for heavy workloads like engineering design. Past that point, repairs, slowdowns, and lost time usually cost more than a new computer, and older hardware may not support current operating systems and security features. Replacing on a schedule beats replacing on failure.
Business Operations
All Business OperationsGrowth & Acquisitions
All Growth & AcquisitionsVideo tutorials
All 122 videosShort how-tos for Teams, Outlook, Excel, Word, Microsoft 365 sign-in, and more.
Applications we have built and actively manage today
About our applicationsSoftware built, hosted, and supported by our own team.

The encouragework.com platform enables teams of varying sizes work together intentionally towards goals.
Track annual, quarterly, monthly and weekly objectives for each team.
Measure your progress with powerful and flexible Key Performance Indicators.
Create elegant and powerful dashboards.
Keep key stakeholders up to date via dashboards, emails and embedded, live HTML content.

Help keep your team compliant with labor laws and reduce your organization's vulnerability to toxic culture by providing online training to help prevent sexual harassment and all forms of discrimination in the workplace.
The advanced Learning Management System provides engaging training across all modern web platforms as well as SCORM-compatible packages for hosting on your own LMS.
Flexible enrollment and kiosk modes accommodate clients of all sizes and complexities.

Vendor management used to be an "Excel" activity. In today's business climate we are now tasked with gauging and managing risk across all of our business partners. Third Party Toolbox aids institutions of all sizes in tracking vendors, risk profiles, contracts, contract performance and more.
Didn’t find your question?
Ask us. If it’s a question one organization has, others do too, and it may become our next answer.