Security Focus is Essential for Everyone

Sep 9, 2026 | AI, cyber insurance, cybercrime, cybercriminal, cybersecurity, managed services, Security Training

October is Cybersecurity Awareness Month

Looking over the recent articles posted here, it has been a while and the theme is consistent: security, security, security. It may seem we are stuck in a bit of a rut, but the reality is that the need for everyone to focus on maintaining security in all realms is only becoming more necessary. In nearly three decades in the IT industry, there have been many changes, but one consistency is that most people believe that security of company data is someone else’s job – namely the IT department. In the personal realm, most think they will not suffer substantial consequences of a data breach. But the reality is that there is not likely any one of us whose personally identifiable information has not been found and sold on the dark web. Those who refuse to believe that data can be used to damage finances, reputations, and extend those dangers to the companies who employ them are likely to be surprised one day.

Cybercriminals have become adept and sophisticated with the help of shared and inexpensive tools. We have come a long way from the Nigerian prince wanting you to invest, or the Russian bride looking for a partner – notifying you in poorly formatted emails with grammar and spelling errors so glaringly obvious it was really hard to fall for such scams. No, in recent years, as personal data has been lost in breaches, scraped from social media and news stories, and traded on the dark web; we now face email, texts, calls, snail mail and even in-person threats craftily tailored to address us convincingly, coerce us into panicking or dropping our guard and giving away whatever it is they seek. It is not implausible to consider that an employee may be expressly targeted in a manipulative manner to click something, say something or do something that could quite literally bring your business to its knees. These “somethings” are varied and cleverly crafted making it difficult to discern whether they are legitimate or not. Maybe a link to “verify” or “reclaim” an account, or just check a bank balance; maybe they lead us to divulge just enough information in email or conversation that when pieced together with other known information gives the criminal leverage or an in-road. There is a reason for the warnings that your gas company or other entities don’t call you asking you to pay bills in gift cards.

Operations & Growth vs Cybersecurity

Boards and executive management of businesses treat these issues in similar fashion much too frequently. Company management would much rather focus on business strategies and growth than taking a report from IT about the use of BYOD for business, shared passwords, the fact that no one wants to bother with MFA or frequent screenlocks and account logoffs, that old software and equipment needs to be replaced. Training? Why do we need that? Policies? We’ll post them and that should be good enough, right? Wrong. Small business have long enjoyed their small size being a deterrent in terms of attack vulnerability. It used to be more profitable to attack larger entities – because that is what cybercrime is all about. It’s lucrative! New tools, especially AI, make it just as easy for cybercriminals to compromise hundreds of small businesses as a larger one. The only difference now is that small businesses don’t have the defenses that larger corporations do, so they are easier targets.

As more applications move to the cloud and employees work from home or other remote locations, it creates new areas of exposure and risk for a business. New hardware and software often does not seem a good ROI when from all appearances it performs marginally better if at all, may or may not offer desirable functionality and just seems to subtract from the bottom line. What is often not considered is that old software and hardware no longer receive fixes for identified vulnerabilities. Along these lines are choices to lower company overhead by allowing employees to use personal devices for email or logging into business applications. While some people must have the latest and greatest tech that gets all the latest updates, plenty of others use their equipment until it no longer works. Phones and computers in particular can continue to operate for several years beyond support lifecycles. Most are not protectect with quality malware and privacy protection, and further still tend to have default, if not additional, software running that presents its own security risks.

When devices outside central management of the company are allowed on the business network or employees are allowed to work from their own homes or public networks, there is little to no control over what may be introduced in terms of malware or traffic snooping. Consumer-grade routers, wireless access points, printers, cameras, smart-home devices, fitness and wellness apps and tools are developed without serious concern for security. Most people do not bother to look at the security options, change default credentials, check for updates (if they’re even available) with any regularity or segregate devices so they cannot impact each other. From an IT admin’s perspective, there is a whole lot of opportunity for a lot of bad things to go down.

AI Makes the Challenge Greater

It needs to be understood that AI has greatly heated up the threat landscape. Nearly twenty-year-old vulnerabilities are new again. Humans forgot about them, those notes are old and seldom referenced, but AI ingests data, then can search for those vulnerabilities with great speed across any number of boundaries: business verticals, size, geographic boundaries, etc. The means to exploit is known and BOOM! a number of disparate systems are compromised. There are a number of other threats AI brings, but suffice to say, it only makes it all the more essential to ensure your security ducks are in a row. When security is pushed to the back burner, updates deferred, expansions and adoptions taken on without concern for security implications, it means that when the time comes to address the issues, it is that much harder and more expensive. When this happens, it seems overwhelming, futile and just easier to ignore it even longer.

Cyber Insurance

Most business owners are unaware that their business insurance policies likely do not include any kind of coverage in a security breach incident. That coverage is typically an additional policy or rider. (You should confirm this with your agent or carrier.) Cyber insurance has been around for a number of years now, but insurers are seeing an increase in claims and requiring businesses to show evidence that they are doing all that is in their power to ensure their systems and data are protected. Most require the completion of questionnaires before enrollment or renewal and a demonstration that there is a plan of action in the event of a breach. The reality is that in the event of a data breach (loss of employee and/or client sensitive information) a business is very likely under obligation to notify government agencies, those whose data was lost, partners and vendors. If you do business across state lines or internationally, you could very well be subject to additional requirements around data privacy. There can be an enormous financial loss in terms of possible theft, legal fees and compensation along with loss of reputation – never mind the time it will take away from being able to run the business. Large organizations have financial, legal and public relations teams to tackle these issues. They also tend to have greater financial reserves or stakes that insulate them to a degree, but most small businesses lack these assets which means they do not survive.

What’s to be Done?

Essential Tech Solutions was founded to provide small businesses support and tools they need to conduct business, remain relevant and profitable. In recent years, we have added a breach prevention platform that provides an excellent framework to comply with insurance requirements: training, policies, risk assessments, action plans – all documented. Check out the trailer for this year’s annual training. There’s also a program for businesses under HIPAA requirements. Beside the annual trainings are weekly micro-trainings and a monthly newsletter. The micro-trainings typically take less than five minutes to complete. These reinforce the annual training as well as introduce the newest concerns equipping your team to recognize potential issues, avoid vulnerabilities and know how to handle any issues that arise. It is recommended that everyone (even the C-Suite) participate in the training. Contact us for a demo.

Vulnerabilities are not only being exploited by AI, but teams use AI to discover them. The number of discovered vulnerabilities and the rate of discovery have exploded. The time to exploit them, on the other hand, has dropped dramatically, so applying patches in a timely manner is essential. Our managed services deliver updates and monitored protection. As we gain insight into the mechanics of your operations, we are able make recommendations to shore up your defenses and help you secure your environment. If you’re already feeling overwhelmed, give us a call. We break large problems into smaller aspects and prioritize them, this is our modus operandi. Maybe you’re not overwhelmed but want to avoid getting there – we’re here for you, too. We have a well-chosen offering of products and services to secure your business, make it resilient and give you some peace of mind so you can focus on doing what you do best: your business.

Essential Tech Solutions logo

207-608-8900

Essential Tech Solutions, LLC

 

Mon - Fri: 9 AM- 5 PM
By appointment
Sat- Sun: Closed