Cybersecurity Insights
15 articles on Cybersecurity for NY/NJ businesses, from the Comserv Connect team.
A reply lands in a thread you started, from your vendor's genuine account, asking you to send this month's payment somewhere new. Nothing about the sender is fake. Here is how that works, how mailbox rules keep you from finding out, and why New York law can put a clock on it even when no money moves.
Read More →In August we wrote that Authenticator app users would be passed by quietly. That was wrong. What decides whether an account gets the passkey nudge is whether it is still enabled for text or phone codes in the tenant policy, not what your staff tap every morning.
Read More →We build voice AI for businesses. The same technology is now rented to criminals by the call. Here is what researchers documented it costing, where those calls went, and the one question to ask about your own logins.
Read More →Pokemon Center customers had their details exposed by a company they had never heard of. Trezor customers had the same week for the same reason. Neither company was breached, and the standard advice about knowing your vendors would not have helped either of them.
Read More →More than a thousand charities were told to assume their entire supporter database was taken. None of them did anything wrong, and no checklist would have saved them. Here is the honest version, and the part that is actually in your control.
Read More →Small charities and churches used to assume attackers skipped them. The leak sites say otherwise. Here is the affordable, high-impact way for a tight-budget nonprofit to be ready.
Read More →Microsoft is making passkeys the default sign-in for Microsoft 365 and retiring its own text and phone-call codes in early 2027. It is a change with plenty of runway. Here is the plain-English plan.
Read More →Microsoft 365 does not arrive secure. It arrives configurable. Here are the protections you are already paying for that sit switched off until someone turns them on.
Read More →Cyber premiums have actually softened. What hasn't is the list of controls an insurer wants proof of before it will bind coverage at all. None of it is New Jersey law: it's what carriers underwriting in this market ask for, and it's substantially the same list nationally.
Read More →So many breach stories this year open the same way: an employee clicked, answered, or let them in. Training is one of the least expensive controls you can add, and it defends the door the tools do not cover.
Read More →Cyber-insurance premiums have softened, but underwriting scrutiny has not. Denied claims usually trace to a gap between what you attested to and what was actually true. Here is how to close that gap.
Read More →One stolen identity plus a stolen session token can mean a full cloud takeover: no malware, no exploit, the attacker just logs in. Identity is the new perimeter.
Read More →In about half of ransomware cases the attacker steals your data before encrypting it, so backups fix the outage but never the leak. Here's what actually protects you.
Read More →Managed IT keeps systems running and productive; cybersecurity assumes something is already wrong and hunts for it. They're different operating models, and you need both.
Read More →Small and mid-size businesses face many of the same threats as big companies, with fewer resources to defend. The myth that you're too small to hack died years ago.
Read More →