Resource Center
Cybersecurity
6 answered so far, with more on the way.
Answers
- Are we too small to be a target for hackers?No. Most attacks are automated and don't check your size first: they look for weak passwords, missing updates, and people who will click. Smaller organizations are often easier targets because they have fewer defenses, and they're a route into larger clients and partners. The good news: a handful of basic controls stop most attacks.
- How do we protect our organization from ransomware?Make it hard to get in, quick to spot, and possible to recover without paying. That means multi-factor authentication everywhere, prompt security updates, endpoint detection with someone watching around the clock, and backups attackers can't reach or delete, tested regularly. Then write down what you'll do on the day it happens.
- How do we stop fake invoices and wire-transfer fraud sent by email?Treat every request to change payment details as suspicious until it's verified by phone, using a number you already had, not one from the email. Add multi-factor authentication so your own mailboxes can't be taken over, set up email authentication so criminals can't send as your domain, and train the people who move money.
- Is it safe to keep a machine running an old version of Windows?Not as-is, but it can be made reasonably safe when replacing it isn't an option. Put it on its own isolated network, allow only the connections it needs, keep it off email and the web, control USB drives, keep a full backup image, and plan for its eventual replacement. Most of the risk comes from what it's connected to.
- Is it safe to put client data into ChatGPT?Not in the free or personal versions. Consumer AI tools can keep what you type and may use it to improve their models, and you have no contract covering it. Business versions, such as Microsoft 365 Copilot or ChatGPT Business and Enterprise, don't train on your data and come with commercial terms. Even then, a written policy should say what data is allowed.
- What's the difference between EDR and MDR?EDR (endpoint detection and response) is software on each computer that watches for suspicious behavior and can stop it. MDR (managed detection and response) adds people: a security team that monitors those alerts around the clock, investigates, and responds. EDR is the tool; MDR is the tool plus the team watching it.
Talk to a person, not a ticket
Tell us what's going on. We'll listen, ask good questions, and give you a straight answer about whether we can help.