News

Why You Should Scroll Past the First Result on Google

When you search Google for a program to download or a website to log into, the first thing result on Google you see is usually an ad. It sits at the top, marked “Sponsored,” and most people click it without a second thought, because the top result is normally what you wanted.

Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it’s the official page.

Read More »
Free scam phishing fraud illustration

How to Spot a Scam Email Now That They Look Real

For years, the advice for spotting a scam email was simple: look for bad spelling and clumsy grammar. A real bank or supplier writes properly, the thinking went, so a message full of mistakes was probably fake. It was easy to teach, and for a long time it worked.

It doesn’t anymore. Scammers now use AI to write their emails, and AI writes cleanly. The typos and awkward phrasing that used to give phishing away are gone, and the messages landing in your team’s inbox read as well as anything from a real company. Worse, they can be written to sound like they came from someone you already know.

Read More »
What to Do in Case of a Cyberattack (Step by Step)

What to Do in Case of a Cyberattack (Step by Step)

Article Summary: If your business is hit by a cyberattack, the first hour matters. Disconnect the affected devices from the network instead of powering them off, call your IT provider by phone, and leave the evidence in place. If money was wired to a scammer, call your bank right away. This post is the step-by-step plan, plus where to report an attack in Australia.

If a cyberattack hits your business, what you do in the first hour really matters.

It’s also the easiest time to make a costly mistake, like turning off the wrong machine, deleting evidence, or replying from an email account the attacker is already reading.

The steps below tell you what to do, in order, so you’re not guessing in the moment.

Doing these steps doesn’t require technical knowledge.

Read More »
What Are Passkeys, and Should Your Business Use Them?

What Are Passkeys, and Should Your Business Use Them?

Article Summary: A passkey lets you sign in to an app or website using the same fingerprint, face, or PIN you use to unlock your phone or laptop, with no password to type. It’s built on a security standard called FIDO that can’t be phished, because the passkey only works on the real site and there’s no password to steal or reuse. Most major platforms and a growing list of business tools support passkeys, and Microsoft 365 includes them at no extra cost. For most businesses, it’s worth starting to roll them out, beginning with the most sensitive accounts.

Passwords are the weak point in most businesses.

People reuse them across accounts, write them on sticky notes, and type them into convincing fake login pages without realizing it.

Passkeys are the technology built to replace passwords, and they fix the parts that cause the most trouble.

A passkey lets you sign in with the same fingerprint, face scan, or PIN you already use to unlock your phone or laptop. There’s no password to type, so there’s nothing for an attacker to steal, guess, or trick out of you.

Read More »
Still on Windows 10? Here's Why You're Putting Your Business at Risk

Still on Windows 10? Here’s Why You’re Putting Your Business at Risk

Article Summary: Windows 10 reached the end of Microsoft support on October 14, 2025, which means it no longer gets security updates. The computers still work, but any new flaw found in Windows 10 will never be fixed, which makes them easier to attack and can cause problems with compliance and cyber insurance. You have three options: upgrade eligible PCs to Windows 11 for free, pay for Extended Security Updates as a short-term bridge, or replace machines too old to upgrade.

Microsoft stopped supporting Windows 10 on October 14, 2025.

If your business is still running it, and plenty are, your computers aren’t getting security updates anymore.

Everything still turns on and works like normal, which is exactly why it’s easy to put off doing anything about it. The trouble is, the longer you stay on Windows 10, the more security holes pile up that nobody is ever going to fix.

So what does it mean for your business, and what are your options?

There are three: upgrade to Windows 11, pay for extended updates to buy some time, or replace the machine.

Read More »
Who Can See What Your AI Note-Taker Records?

Who Can See What Your AI Note-Taker Records?

Article Summary: AI note-taker join your meetings, transcribe everything said, and save the recording and summary to the vendor’s servers. Who can see that recording depends on the tool. Some keep your data inside your own Microsoft or Google environment and never use it for training, while others store it on their own servers and may use it to improve their AI. Some also auto-join meetings from your calendar without anyone pressing record. Before you let one into a client or staff meeting, it’s worth knowing where the recording goes and getting everyone’s consent.

AI note-takers have become normal in a short time.

You start a Teams, Zoom, or Google Meet call, a bot joins to record the conversation, and minutes later everyone gets a tidy summary with action items.

It saves real time, which is why staff often adopt these tools on their own, before anyone has asked where the recording ends up.

The problem is, every word of the meeting, including the parts you would never put in writing, gets captured, stored somewhere, and read by whoever has access. Few business owners have stopped to ask who that includes, or what happens to the recording afterward.

Read More »
How to Stop Scammers from Sending Emails in Your Company's Name

How to Stop Scammers from Sending Emails in Your Company’s Name (Spoofing)

Article Summary: Email spoofing is when a scammer sends a message that appears to come from your domain, often to trick your clients or staff into paying a fake invoice or changing banking details. Three DNS records (SPF, DKIM, and DMARC) prove that a message really came from you and tell receiving mail servers to reject the ones that didn’t. The catch is that DMARC only protects you once it’s set to “quarantine” or “reject,” and a lot of businesses leave it on “none,” which monitors but does not block.

Right now, with no special tools, someone could send an email that looks like it came from your company.

The From line would show your domain, your logo could be pasted into the message, and it could ask one of your clients to pay an invoice or update banking details. This is called email spoofing, and it is one of the most common ways fraud against your clients and suppliers begins.

There are three settings you can add to your domain that make this much harder to pull off.

They’re called SPF, DKIM, and DMARC.

Most businesses have one or two of them set up and the third missing.

That’s usually all it takes to let a spoofed email through. This post explains what each one does, the setting most businesses get wrong, and how to check your own domain.

Read More »
QR Code Scams: What They Are and How to Protect Your Business

QR Code Scams: What They Are and How to Protect Your Business

Article Summary: QR code scams, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company’s security. Microsoft reported a 146% rise in QR code phishing during the first quarter of 2026.

QR codes are part of normal business now.

You scan them to see a menu, pay for parking, connect to Wi-Fi, or open a shared document.

 Attackers know that, and they have started hiding malicious links inside QR codes to get past the security tools that would normally catch a bad link in an email.

The technique has a name, quishing, and it works because a QR code is just an image.

Your email filter reads text, so a link encoded into a QR code can pass straight through. When you scan it, you usually do so on your phone, which sits outside most of the protection your work computer has.

This post covers what a QR code scam is, why it gets past your security, what the common ones look like, and the habits that protect your business.

Read More »
How Small Business Ransomware Attacks Work (And How to Protect Against Them)

How Small Business Ransomware Attacks Work (And How to Protect Against Them)

Small businesses are the most common ransomware target by volume of incidents, even though many small business owners assume hackers focus on larger organisations. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research.

What follows is a step-by-step walkthrough of how a small business gets attacked, written from the attacker’s side. The company in this account is composite, but the methods are accurate to current threat intelligence reporting. After the walkthrough, you’ll see five specific points where the attack would have been stopped by controls that come bundled with security tools most small businesses already pay for.

Read More »
How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy

How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy

If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled in last time. It’s also more specific. Each new question maps to a control that, if missing, allowed a major 2023 or 2024 claim to escalate. The wording reflects how carriers responded to losses they paid in 2023 and 2024, and how you answer the form matters more than it used to.

This post covers why the application got longer, what each new section is asking, how to answer honestly without overstating your controls, and what to fix in the 30 days before submission. The expensive mistake on a cyber insurance application is rescission, where a future claim is denied because the carrier finds that the controls you declared were not in place at the time.

Read More »

Looking for something else? You can navigate through our menu or use this search bar:

Search