<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpeedWise IT Services</title>
	<atom:link href="https://speedwise.net/feed/" rel="self" type="application/rss+xml" />
	<link>https://speedwise.net/</link>
	<description>Managed IT Support Services &#38; Solutions For Denver Small Businesses</description>
	<lastBuildDate>Fri, 10 Jul 2026 03:21:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Who Can See What Your AI Note-Taker Records?</title>
		<link>https://speedwise.net/blog/who-can-see-what-your-ai-note-taker-records/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sat, 15 Aug 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<guid isPermaLink="false">https://speedwise.net/?p=7536</guid>

					<description><![CDATA[<p>Article Summary: AI note-takers join your meetings, transcribe everything said, and save the recording and summary to the vendor&#8217;s servers. Who can see that recording depends on the tool. Some keep your data inside your own Microsoft or Google environment and never use it for training, while others store it on their own servers and [&#8230;]</p>
<p>The post <a href="https://speedwise.net/blog/who-can-see-what-your-ai-note-taker-records/">Who Can See What Your AI Note-Taker Records?</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Article Summary: <em>AI note-takers join your meetings, transcribe everything said, and save the recording and summary to the vendor&#8217;s servers. Who can see that recording depends on the tool. Some keep your data inside your own Microsoft or Google environment and never use it for training, while others store it on their own servers and may use it to improve their AI. Some also auto-join meetings from your calendar without anyone pressing record. Before you let one into a client or staff meeting, it&#8217;s worth knowing where the recording goes and getting everyone&#8217;s consent.</em></p><p class="wp-block-paragraph">AI note-takers have become normal in a short time.</p><p class="wp-block-paragraph">You start a Teams, Zoom, or Google Meet call, a bot joins to record the conversation, and minutes later everyone gets a tidy summary with action items.</p><p class="wp-block-paragraph">It saves real time, which is why staff often adopt these tools on their own, before anyone has asked where the recording ends up.</p><p class="wp-block-paragraph">The problem is, every word of the meeting, including the parts you would never put in writing, gets captured, stored somewhere, and read by whoever has access. Few business owners have stopped to ask who that includes, or what happens to the recording afterward.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">What an AI note-taker actually does</h2><p class="wp-block-paragraph">An AI note-taker is a tool that joins a meeting, records the audio and sometimes the video, turns the speech into a written transcript, and produces a summary. Common ones include <a href="https://support.microsoft.com/en-us/office/use-copilot-in-microsoft-teams-meetings-0bf9dd3c-96f7-44e2-8bb8-790bedf066b1">Microsoft 365 Copilot in Teams</a>, <a href="https://otter.ai/">Otter</a>, <a href="https://fireflies.ai/">Fireflies</a>, and <a href="https://fathom.video/">Fathom.</a></p><p class="wp-block-paragraph">Most connect to your calendar so they can join automatically, and some will sit in on any meeting on your schedule unless you turn that setting off.</p><p class="wp-block-paragraph">The recording and transcript do not disappear when the call ends.</p><p class="wp-block-paragraph">They are saved, usually in the cloud, where they can be searched, shared, and exported later.</p><p class="wp-block-paragraph">Where they are saved, and who can reach them, depends on which tool you use.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Who can see the recording?</h2><p class="wp-block-paragraph">Start with the obvious group: anyone the meeting organizer shares the summary with.</p><p class="wp-block-paragraph">Many note-takers email the transcript to every attendee by default, and some send it to people who were invited but never joined. When the meeting covered a sensitive topic, that distribution list matters.</p><p class="wp-block-paragraph">Then there is the tool&#8217;s own access.</p><p class="wp-block-paragraph">With a cloud note-taker, the recording sits on the vendor&#8217;s servers, which means the vendor&#8217;s systems, and in some cases its staff, can reach it under the terms you agreed to.</p><p class="wp-block-paragraph">If the tool auto-joined from someone&#8217;s calendar, the recording may live on an account you do not control, belonging to whichever employee connected the bot.</p><p class="wp-block-paragraph">A law firm publication on the <a href="https://www.smithlaw.com/newsroom/publications/the-silent-guest-in-your-meetings-legal-risks-of-ai-note-takers">legal risks of AI note-takers</a> warned that letting a note-taker vendor access or use your transcripts for its own purposes can even risk waiving attorney-client privilege for businesses that handle legal matters.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Does the tool use your meetings to train its AI?</h2><p class="wp-block-paragraph">This is where tools differ the most, and it is worth checking before you choose one.</p><p class="wp-block-paragraph">Microsoft states that Copilot in Teams does not use your prompts, responses, or meeting content to train its AI models, and that the data stays inside your organization&#8217;s Microsoft 365 environment.</p><p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy">Microsoft&#8217;s privacy documentation</a> says this directly, and notes the content is processed within the Microsoft 365 service boundary rather than on the public version of the AI.</p><p class="wp-block-paragraph">Third-party note-takers vary widely.</p><p class="wp-block-paragraph">Some store your recordings on their own servers and, depending on the terms you accept, may use that data to improve their models.</p><p class="wp-block-paragraph">Others say they do not train on customer data at all. The only way to know is to read the specific tool&#8217;s privacy terms, because two tools that look almost identical can treat your data very differently.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">The consent question</h2><p class="wp-block-paragraph">Recording a meeting is not always yours to decide alone, and the rules change depending on where you and the other people are.</p><p class="wp-block-paragraph">In around a dozen <a href="https://www.justia.com/50-state-surveys/recording-phone-calls-and-conversations/">U.S. states</a>, and in most Australian states, everyone in a conversation has to agree to being recorded.</p><p class="wp-block-paragraph">Federal U.S. law, most other states, and the UK allow recording when one participant consents.</p><p class="wp-block-paragraph">On top of that, the UK and Europe treat recording people as handling their personal data, so under GDPR you generally have to tell participants you are recording, explain why, and have a proper reason for doing it.</p><p class="wp-block-paragraph">That’s why the safest way to go about this is to tell people the meeting is being recorded, explain why, and give them a chance to object before the bot starts.</p><p class="wp-block-paragraph">For client meetings, HR conversations, and anything covered by confidentiality, that matters even more, and in some cases you should check with a lawyer before recording at all.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">How to use AI note-takers safely</h2><p class="wp-block-paragraph">You don&#8217;t have to ban these tools to use them responsibly.</p><p class="wp-block-paragraph">Do this instead:</p><ul class="wp-block-list"><li><strong>Pick an approved tool and say so.</strong> Decide which note-taker your business uses, and ask staff not to connect others to company meetings. This keeps your recordings in one place you control.</li><li><strong>Turn off auto-join.</strong> Set the tool to join only when someone chooses to record, rather than automatically for every meeting on a calendar.</li><li><strong>Announce recording and get consent.</strong> Make it normal to say a meeting is being recorded at the start, and to skip recording when someone objects.</li><li><strong>Prefer tools that keep data in your environment.</strong> A note-taker that stores recordings inside your own Microsoft or Google tenant, and does not train on your data, is easier to control than one that holds everything on its own servers.</li><li><strong>Control who gets the summary.</strong> Check the default sharing setting so transcripts are not emailed to everyone, including people who missed the meeting.</li><li><strong>Keep bots out of sensitive meetings.</strong> For legal, HR, financial, and confidential client conversations, the default should be no recording unless there is a clear reason and everyone agrees.</li></ul><p class="wp-block-paragraph">If you use Microsoft 365, an administrator can <a href="https://learn.microsoft.com/en-us/microsoftteams/copilot-teams-transcription">control whether Copilot and transcription are allowed</a> in Teams meetings. That gives you one place to set the rule, instead of relying on each person to get it right.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Frequently Asked Questions</h2><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Is it legal to record a meeting with an AI note-taker?</h2><p class="wp-block-paragraph">It depends on where everyone in the meeting is. Around a dozen U.S. states and most Australian states require everyone to consent. The UK, federal U.S. law, and most U.S. states allow it with one person&#8217;s consent, though in the UK and Europe you also have to inform people and have a valid reason under data-protection law. The safe approach everywhere is to announce the recording and let people object before it starts.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Does Microsoft Copilot use my meeting data to train its AI?</h3><p class="wp-block-paragraph">No. Microsoft states that Copilot in Teams does not use your meeting content, prompts, or responses to train its foundation AI models, and that the data stays within your organization&#8217;s Microsoft 365 environment.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Can an AI note-taker join a meeting without me knowing?</h2><p class="wp-block-paragraph">Yes. Many tools connect to a user&#8217;s calendar and can auto-join meetings, sometimes ones the user isn&#8217;t even attending. You can turn auto-join off so the bot only records when someone chooses to start it.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Where are AI note-taker recordings stored?</h3><p class="wp-block-paragraph">In the cloud. With Microsoft Copilot, the data stays inside your Microsoft 365 tenant. With many third-party tools, recordings sit on the vendor&#8217;s own servers. Where they live and who can reach them depends on the tool, so check its terms.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Should we let staff use Otter or Fireflies for work?</h3><p class="wp-block-paragraph">You can, with rules in place. Choose one approved tool, turn off auto-join, announce recording and get consent, check how the tool handles your data, and keep it out of legal, HR, and confidential client meetings.</p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph">&#8212;</p><p class="wp-block-paragraph"><a href="https://www.pexels.com/photo/teacher-video-calling-with-his-students-using-a-computer-6937871/" data-type="link" data-id="https://www.pexels.com/photo/teacher-video-calling-with-his-students-using-a-computer-6937871/">Featured Image Credit</a></p><p class="wp-block-paragraph"></p><p>This Article has been Republished with Permission from <a rel="canonical" href="https://thetechnologypress.com/who-can-see-what-your-ai-note-taker-records/" title="Who Can See What Your AI Note-Taker Records?" target="_blank">The Technology Press.</a></p><p>The post <a href="https://speedwise.net/blog/who-can-see-what-your-ai-note-taker-records/">Who Can See What Your AI Note-Taker Records?</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Stop Scammers from Sending Emails in Your Company&#8217;s Name</title>
		<link>https://speedwise.net/blog/how-to-stop-scammers-from-sending-emails-in-your-companys-name/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://speedwise.net/?p=7533</guid>

					<description><![CDATA[<p>Article Summary: Email spoofing is when a scammer sends a message that appears to come from your domain, often to trick your clients or staff into paying a fake invoice or changing banking details. Three DNS records (SPF, DKIM, and DMARC) prove that a message really came from you and tell receiving mail servers to [&#8230;]</p>
<p>The post <a href="https://speedwise.net/blog/how-to-stop-scammers-from-sending-emails-in-your-companys-name/">How to Stop Scammers from Sending Emails in Your Company&#8217;s Name</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Article Summary: <em>Email spoofing is when a scammer sends a message that appears to come from your domain, often to trick your clients or staff into paying a fake invoice or changing banking details. Three DNS records (SPF, DKIM, and DMARC) prove that a message really came from you and tell receiving mail servers to reject the ones that didn&#8217;t. The catch is that DMARC only protects you once it&#8217;s set to &#8220;quarantine&#8221; or &#8220;reject,&#8221; and a lot of businesses leave it on &#8220;none,&#8221; which monitors but does not block.</em></p><p class="wp-block-paragraph">Right now, with no special tools, someone could send an email that looks like it came from your company.</p><p class="wp-block-paragraph">The From line would show your domain, your logo could be pasted into the message, and it could ask one of your clients to pay an invoice or update banking details. This is called email spoofing, and it is one of the most common ways fraud against your clients and suppliers begins.</p><p class="wp-block-paragraph">There are three settings you can add to your domain that make this much harder to pull off.</p><p class="wp-block-paragraph">They&#8217;re called SPF, DKIM, and DMARC.</p><p class="wp-block-paragraph">Most businesses have one or two of them set up and the third missing.</p><p class="wp-block-paragraph">That&#8217;s usually all it takes to let a spoofed email through. This post explains what each one does, the setting most businesses get wrong, and how to check your own domain.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Why scammers can send email in your company&#8217;s name</h2><p class="wp-block-paragraph">Email was built in a more trusting time.</p><p class="wp-block-paragraph">The system that delivers mail does not, on its own, check that the sender is who they claim to be. The From address on an email is about as trustworthy as the return address handwritten on an envelope. Anyone can write anything there, and the mail still gets delivered.</p><p class="wp-block-paragraph">Spoofing takes advantage of that.</p><p class="wp-block-paragraph">A scammer puts your domain in the From field, sends the message, and unless your domain is set up to prevent it, the receiving mail server has no reason to question it. The message lands in your client&#8217;s inbox looking like it came from you. The UK&#8217;s <a href="https://www.ncsc.gov.uk/collection/email-security-and-anti-spoofing">National Cyber Security Centre</a> publishes anti-spoofing guidance for exactly this reason.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">The three records that stop email spoofing</h2><p class="wp-block-paragraph">Three DNS records work together to prove an email really came from your domain. You add them once, at your domain registrar or DNS host, and receiving mail servers check them on every message you send.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">SPF (Sender Policy Framework)&lt;</h3><p class="wp-block-paragraph">SPF is a list of the mail servers allowed to send email for your domain, published as a DNS record. When a receiving server gets a message claiming to be from you, it checks whether the sending server is on that list. If a server that isn&#8217;t on the list tries to send as your domain, SPF flags it.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">DKIM (DomainKeys Identified Mail)</h3><p class="wp-block-paragraph">DKIM adds a tamper-proof signature to every message you send. Your mail server signs outgoing email with a private key, and the matching public key sits in your DNS. The receiving server checks the signature to confirm two things: the message really came from your domain, and nobody altered it along the way.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">DMARC (Domain-based Message Authentication, Reporting and Conformance)</h3><p class="wp-block-paragraph">DMARC ties the other two together and tells receiving servers what to do when a message fails the check. It also confirms that the domain in the visible From address matches the domain SPF and DKIM verified, which is the part that stops someone forging your exact address.</p><p class="wp-block-paragraph">And it sends you reports showing who is sending email using your domain, including the senders who shouldn&#8217;t be.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">The DMARC setting most businesses get wrong</h2><p class="wp-block-paragraph">DMARC has three policy settings, and choosing the wrong one is a common mistake.</p><ol class="wp-block-list"><li><strong>p=none</strong> tells receiving servers to do nothing when a message fails. It only monitors and sends you reports. Your domain can still be spoofed.</li><li><strong>p=quarantine</strong> tells them to send failing messages to the junk folder.</li><li><strong>p=reject</strong> tells them to block failing messages before they ever arrive.</li></ol><p class="wp-block-paragraph">A lot of businesses set up DMARC at p=none, watch the reports come in, and never move past it. At p=none, you get reports but your domain still isn&#8217;t protected.</p><p class="wp-block-paragraph">Real protection only starts at quarantine or reject.</p><p class="wp-block-paragraph"><a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure">Microsoft&#8217;s own guidance</a> is to work toward p=reject once you&#8217;ve confirmed your legitimate mail passes.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">What SPF, DKIM, and DMARC don&#8217;t stop</h2><p class="wp-block-paragraph">These records stop someone from forging your exact domain.</p><p class="wp-block-paragraph">There are two things they don&#8217;t catch, though, and both are worth knowing about.</p><ul class="wp-block-list"><li><strong>Lookalike domains.</strong> A scammer can register a domain that resembles yours, like yourcompany-invoices.com, or yourcompany.co instead of .com, and send from that. Your records protect your real domain, not a different one the attacker owns.</li><li><strong>Display-name spoofing.</strong> The name shown in the From line can read &#8220;Your Company Accounts&#8221; while the real address behind it is a random Gmail account. DMARC checks the domain, not the display name.</li></ul><p class="wp-block-paragraph">For those, you still need the habits that catch any phishing attempt: check the full email address rather than just the display name, and verify any request to change payment details by calling a known number, not one from the email.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Why this matters even if you don&#8217;t send bulk email</h2><p class="wp-block-paragraph"><strong>The first reason is protection.</strong></p><p class="wp-block-paragraph">These records stop scammers from impersonating your domain to your clients, your suppliers, and your own staff.</p><p class="wp-block-paragraph"><strong>The second is deliverability.</strong></p><p class="wp-block-paragraph">The major mailbox providers now require these records from anyone sending in volume.</p><p class="wp-block-paragraph">Since February 2024, Google and Yahoo have required bulk senders, meaning those sending more than 5,000 messages a day, to use SPF, DKIM, and DMARC.</p><p class="wp-block-paragraph">Microsoft <a href="https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730">began applying similar requirements</a> to Outlook.com and Hotmail in 2025, routing non-compliant high-volume mail to junk and then rejecting it.</p><p class="wp-block-paragraph">Even below those thresholds, a domain with proper authentication is more likely to reach the inbox than the spam folder.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">How to check and fix your domain</h2><p class="wp-block-paragraph">You can get a rough sense of where you stand without any technical work.</p><p class="wp-block-paragraph">Several free DMARC and SPF checkers let you type in your domain and see which records exist. That tells you whether the records are present, though not whether they&#8217;re configured correctly.</p><p class="wp-block-paragraph">Fixing them properly is a job for whoever manages your IT or your domain.</p><p class="wp-block-paragraph">The records live in your DNS, and a mistake can send your own legitimate email to spam, so the rollout is done in stages:</p><ol class="wp-block-list"><li>Publish SPF and DKIM so all of your real mail sources are covered.</li><li>Add DMARC at p=none and read the reports to confirm your legitimate mail passes.</li><li>Move DMARC to p=quarantine, then to p=reject, once the reports look clean.</li></ol><p class="wp-block-paragraph">Microsoft recommends this same gradual path, starting at none and working toward reject, so you protect the domain without blocking your own mail on the way.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Frequently Asked Questions</h2><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">What is email spoofing?</h3><p class="wp-block-paragraph">Email spoofing is when someone sends a message with your domain in the From address to make it look like it came from your company. It&#8217;s used to trick your clients, suppliers, or staff into paying fake invoices, changing banking details, or handing over information.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">What are SPF, DKIM, and DMARC in simple terms?</h3><p class="wp-block-paragraph">SPF is a list of servers allowed to send email for your domain. DKIM is a signature that proves a message came from you and wasn&#8217;t altered. DMARC ties the two together, tells receiving servers to reject messages that fail, and reports who is sending email as your domain.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Does DMARC stop all email impersonation?</h3><p class="wp-block-paragraph">No. DMARC stops someone forging your exact domain. It does not stop lookalike domains (like yourcompany-invoices.com) or display-name spoofing, where the sender&#8217;s name says your company but the address behind it is different. Those still need staff awareness and payment-verification habits.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Will setting up DMARC block my own emails?</h3><p class="wp-block-paragraph">Not if you roll it out gradually. Starting at p=none lets you watch the reports and confirm your legitimate mail passes before you move to quarantine and then reject. Skipping straight to reject without checking first is what causes problems.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Do I need these records if I don&#8217;t send many emails?</h3><p class="wp-block-paragraph">Yes. They protect your domain from being spoofed regardless of how much email you send, and they help your messages reach the inbox. Google, Yahoo, and Microsoft now expect proper authentication, and mail without it is more likely to be filtered.</p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph">&#8212;</p><p class="wp-block-paragraph"><a href="https://unsplash.com/photos/closeup-of-mail-app-icon-on-phone-LPZy4da9aRo" data-type="link" data-id="https://unsplash.com/photos/closeup-of-mail-app-icon-on-phone-LPZy4da9aRo" target="_blank" rel="noreferrer noopener">Featured Image Credit</a></p><p class="wp-block-paragraph"></p><p>This Article has been Republished with Permission from <a rel="canonical" href="https://thetechnologypress.com/how-to-stop-scammers-from-sending-emails-in-your-companys-name/" title="How to Stop Scammers from Sending Emails in Your Company&apos;s Name" target="_blank">The Technology Press.</a></p><p>The post <a href="https://speedwise.net/blog/how-to-stop-scammers-from-sending-emails-in-your-companys-name/">How to Stop Scammers from Sending Emails in Your Company&#8217;s Name</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>QR Code Scams: What They Are and How to Protect Your Business</title>
		<link>https://speedwise.net/blog/qr-code-scams-what-they-are-and-how-to-protect-your-business/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://speedwise.net/?p=7530</guid>

					<description><![CDATA[<p>Article Summary: A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that [&#8230;]</p>
<p>The post <a href="https://speedwise.net/blog/qr-code-scams-what-they-are-and-how-to-protect-your-business/">QR Code Scams: What They Are and How to Protect Your Business</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Article Summary: <em>A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company&#8217;s security. Microsoft reported a 146% rise in QR code phishing during the first quarter of 2026.</em></p><p class="wp-block-paragraph">QR codes are part of normal business now.</p><p class="wp-block-paragraph">You scan them to see a menu, pay for parking, connect to Wi-Fi, or open a shared document.</p><p class="wp-block-paragraph">&nbsp;Attackers know that, and they have started hiding malicious links inside QR codes to get past the security tools that would normally catch a bad link in an email.</p><p class="wp-block-paragraph">The technique has a name, quishing, and it works because a QR code is just an image.</p><p class="wp-block-paragraph">Your email filter reads text, so a link encoded into a QR code can pass straight through. When you scan it, you usually do so on your phone, which sits outside most of the protection your work computer has.</p><p class="wp-block-paragraph">This post covers what a QR code scam is, why it gets past your security, what the common ones look like, and the habits that protect your business.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">What is a QR code scam?</h2><p class="wp-block-paragraph">A QR code scam is a phishing attack that uses a QR code in place of a written link.</p><p class="wp-block-paragraph">Instead of a clickable URL your email security can inspect, the attacker encodes the web address into a square image.</p><p class="wp-block-paragraph">You scan it with your phone camera, your phone opens the link, and you land on a page built to steal your login or your payment details.</p><p class="wp-block-paragraph">The page on the other end is the same kind of fake you would see in any phishing attack, a login screen made to look like Microsoft 365 or a payment form that copies your bank. The QR code is only the delivery method that gets you there.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Why QR code scams get past your security</h2><p class="wp-block-paragraph">Two things make these scams effective.</p><p class="wp-block-paragraph"><strong>First, the malicious link is hidden inside an image.</strong></p><p class="wp-block-paragraph">Most email security tools scan the text of a message for known bad links. A QR code is a picture, so the link inside it is not text the filter can read.</p><p class="wp-block-paragraph">The UK&#8217;s <a href="https://www.ncsc.gov.uk/blog-post/qr-codes-whats-real-risk">National Cyber Security Centre</a> points out that not all phishing-detection tools scan images, which is the reason criminals started using QR codes to disguise their links in the first place.</p><p class="wp-block-paragraph"><strong>Second, scanning a code moves you onto your phone.</strong></p><p class="wp-block-paragraph">Your work computer probably has web filtering, endpoint protection, and DNS controls that block known bad sites.</p><p class="wp-block-paragraph">Your personal phone usually has none of that. So the moment you scan, you step outside the protection your business pays for, often without realizing it happened.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">How common are QR code scams?</h2><p class="wp-block-paragraph">The volume is climbing fast. In its report on email threats for the first quarter of 2026, Microsoft said it detected around 8.3 billion email-based phishing threats in those three months.</p><p class="wp-block-paragraph">QR code phishing rose 146% across the quarter, from 7.6 million attacks in January to 18.7 million in March.</p><p class="wp-block-paragraph">By the end of the quarter it had reached its highest monthly volume in at least a year.</p><p class="wp-block-paragraph">Microsoft also found that most of these attacks arrived as PDF attachments, growing from 65% of QR code attacks in January to 70% in March.</p><p class="wp-block-paragraph">The QR code sits inside a PDF, the PDF is attached to an email, and the whole thing looks like an ordinary document until someone scans it.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">What QR code scams look like</h2><p class="wp-block-paragraph">These are the QR code scams that come up most often.</p><ul class="wp-block-list"><li><strong>A &#8220;security&#8221; email. </strong>You get a message that looks like it is from Microsoft or your IT team, telling you to scan a code to re-enroll your multi-factor authentication or keep your account active. The code leads to a fake login page.</li><li><strong>A shared document. </strong>An email says a colleague or client has shared a file, and you need to scan the code to view it. The page asks you to sign in first.</li><li><strong>A fake invoice.</strong> A PDF invoice includes a QR code &#8220;to pay faster.&#8221; The code routes your payment to the attacker.</li><li><strong>A delivery notice.</strong> A text or email about a missed package asks you to scan a code to reschedule. The US <a href="https://consumer.ftc.gov/consumer-alerts/2023/12/scammers-hide-harmful-links-qr-codes-steal-your-information">Federal Trade Commission</a> has warned about this exact scam.</li><li><strong>A sticker in the real world. </strong>Attackers print QR code stickers and place them over legitimate ones on parking meters, posters, and payment terminals. You think you are paying for parking, and instead you are handing your card details to a stranger.</li></ul><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">How to protect your business from QR code scams</h2><p class="wp-block-paragraph">Protecting yourself against Quishing comes down to a few habits:</p><ul class="wp-block-list"><li><strong>Be suspicious of QR codes in emails.</strong> A code that arrives by email, especially one that asks you to log in or pay, deserves the same caution as a strange link. The NCSC&#8217;s advice is to be wary of scanning QR codes inside emails, even though codes in places like restaurants are usually fine.</li><li><strong>Check the web address before you act.</strong> When you scan a code, your phone shows the link before it opens. Read it. If the address is not the official site you expected, close it.</li><li><strong>Go direct instead of scanning. </strong>If an email says your Microsoft account needs attention, open your browser and type the address yourself, or use a bookmark. Don&#8217;t rely on the code to take you to the right place.</li><li><strong>Watch for urgency.</strong> Messages that threaten account closure or a fine &#8220;within 24 hours&#8221; are trying to rush you past your own judgment. That pressure is itself a warning sign.</li><li><strong>Use phishing-resistant MFA.</strong> If a scam does capture a password, phishing-resistant multi-factor authentication (a passkey, a hardware key, or number-matching in an authenticator app) makes that password much harder to use.</li><li><strong>Check physical codes for tampering.</strong> Before scanning a code on a parking meter or payment terminal, look for a sticker placed over the original.</li><li><strong>Tell your team. </strong>Most people have never been warned about QR code scams. Send your staff a short message with a real example so they know what to watch for.</li></ul><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">What to do if someone already scanned one</h2><p class="wp-block-paragraph">If you or someone on your team scanned a QR code and entered details on the page that opened:</p><ol class="wp-block-list"><li>Change the password for that account right away, along with any other account that used the same password.</li><li>Confirm multi-factor authentication is turned on for the account.</li><li>Tell whoever manages your IT, so they can check for unusual sign-ins.</li><li>If card or banking details were entered, call the bank and watch the account closely.</li></ol><p class="wp-block-paragraph">Acting quickly limits what an attacker can do with the details they captured.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading">Frequently Asked Questions</h2><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Are QR codes safe to use?</h3><p class="wp-block-paragraph">Most QR codes are safe. A code on a restaurant table or an official payment terminal is usually fine. The risk comes from codes sent in unexpected emails or texts, and from stickers placed over real codes in public. Treat those with caution.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">What is quishing?</h3><p class="wp-block-paragraph">Quishing is phishing that uses a QR code instead of a written link. The word combines &#8220;QR&#8221; and &#8220;phishing.&#8221; The goal is the same as any phishing attack: to get you onto a fake page that captures your login or payment information.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Can antivirus or email filters stop QR code scams?</h3><p class="wp-block-paragraph">Not always. Many email security tools scan the text of a message for bad links, and a QR code hides its link inside an image, so it can slip through. Some products now scan images for codes, but you should not assume the scam will be caught before it reaches you.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">Why is a QR code in an email more dangerous than a normal link? </h3><p class="wp-block-paragraph">A written link can be inspected by your email security and opened on a managed work computer. A QR code hides the link from those tools and pushes you to scan with your phone, which usually has far less protection than your work device.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading">What should I do if I scanned a scam QR code but didn&#8217;t enter anything?</h3><p class="wp-block-paragraph">If you closed the page without typing anything, the risk is low. Close it, don&#8217;t go back, and let your IT contact know so they can keep an eye out. If you did enter a password or payment details, follow the recovery steps above.</p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph">&#8212;</p><p class="wp-block-paragraph"><a href="https://www.pexels.com/photo/qr-code-on-screengrab-278430/" data-type="link" data-id="https://www.pexels.com/photo/qr-code-on-screengrab-278430/">Featured Image Credit</a></p><p>This Article has been Republished with Permission from <a rel="canonical" href="https://thetechnologypress.com/qr-code-scams-what-they-are-and-how-to-protect-your-business/" title="QR Code Scams: What They Are and How to Protect Your Business" target="_blank">The Technology Press.</a></p><p>The post <a href="https://speedwise.net/blog/qr-code-scams-what-they-are-and-how-to-protect-your-business/">QR Code Scams: What They Are and How to Protect Your Business</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How Small Business Ransomware Attacks Work (And How to Protect Against Them)</title>
		<link>https://speedwise.net/blog/how-small-business-ransomware-attacks-work-and-how-to-protect-against-them/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<guid isPermaLink="false">https://speedwise.net/?p=7434</guid>

					<description><![CDATA[<p>Small businesses are the most common ransomware target by volume of incidents, even though many small business owners assume hackers focus on larger organizations. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research. What follows [&#8230;]</p>
<p>The post <a href="https://speedwise.net/blog/how-small-business-ransomware-attacks-work-and-how-to-protect-against-them/">How Small Business Ransomware Attacks Work (And How to Protect Against Them)</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Small businesses are the most common ransomware target by volume of incidents, even though many small business owners assume hackers focus on larger organizations. A 22-person company has enough revenue to be worth attacking, no dedicated security team to defend it, and a publicly traceable footprint that takes about an hour to research.</p><p class="wp-block-paragraph">What follows is a step-by-step walkthrough of how a small business gets attacked, written from the attacker&#8217;s side. The company in this account is composite, but the methods are accurate to current threat intelligence reporting. After the walkthrough, you&#8217;ll see five specific points where the attack would have been stopped by controls that come bundled with security tools most small businesses already pay for.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Monday: how I picked you</strong></h2><p class="wp-block-paragraph">I work regular hours and run a small volume operation. My spreadsheet has about 40 prospects per month, and I prefer businesses between 10 and 50 staff. The reason for that range is economics. Large enterprises have security teams, incident response contracts, and lawyers who make recovery expensive on my end. At the other end of the scale, sole traders rarely have enough at stake to bother with. A 22-person commercial services company sits in the right zone: payroll, customer database, project files, supplier relationships, and an owner who will pay to get the lot back. The return per hour is better at this size than at either extreme.</p><p class="wp-block-paragraph">I did not find you through a breach or a tip. I found you on a public business records portal. State business registries, federal contract awards, and county-level licensing databases publish enough detail for me to identify your company, look up your name, estimate your revenue, and pick the most useful person inside the business. One search told me your company name, your registered agent, the contract value of a recent municipal job, and the named contact on the submission.</p><p class="wp-block-paragraph">The fact that nothing has gone wrong at your company yet is the strongest signal I get. It tells me your credentials are probably still valid, your staff has not been trained to spot anything, and nobody has had a reason to change a password. A clean record is the first indicator I look for.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Tuesday: building your org chart for free</strong></h2><p class="wp-block-paragraph">I spend about 40 minutes researching your company today using only a browser.</p><p class="wp-block-paragraph">LinkedIn gives me eight of your current employees with their job titles listed. Your office manager has been there for six years and lists “accounts payable, payroll, and supplier invoicing” in her profile summary. Your second admin joined 14 months ago. You list yourself as director, with a sparse profile and a low connection count, which tells me you are unlikely to notice when someone unusual starts engaging with your profile or your company&#8217;s social media.</p><p class="wp-block-paragraph">Public business filings confirm your registered business name and your full legal name. A “meet the team” post from two years ago on your Facebook page lists first names and photos, including someone described as helping out in the office a couple of days a week. One of the commenters shares your surname.</p><p class="wp-block-paragraph">I now know who handles your money, what their name is, how long they have been there, what software they probably use (I will check your job ads on Indeed for the phrase “experience with QuickBooks or Sage”), and who in your business has the authority to approve a payment without a second signature.</p><p class="wp-block-paragraph">That last person is my primary target. You are harder to reach and probably more cautious. Your office manager has system access, handles supplier payments, and is busy enough that one more email in her inbox does not get scrutinized the way it might if she had nothing else to do.</p><p class="wp-block-paragraph">I have not spent a dollar yet.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Wednesday: I bought your credentials for $14</strong></h2><p class="wp-block-paragraph">Stealer logs are credential packages harvested by infostealer malware that infected someone&#8217;s personal device, often months or years earlier. The malware records every username and password typed into the machine, then bundles the data for sale. Marketplaces on Telegram channels and forums let buyers search these logs by company email domain.</p><p class="wp-block-paragraph">I search for your company&#8217;s email domain. Two results come back. One is your office manager&#8217;s work email, with a password that looks like it was saved in her browser. The other is a personal Gmail address that appears to belong to a family member of yours, probably from a device that shared a home network.</p><p class="wp-block-paragraph">I pay $14 for the package. It takes four minutes.</p><p class="wp-block-paragraph">Your office manager&#8217;s password follows a common pattern: a pet or child&#8217;s name combined with a year and an exclamation mark. I check it against <a href="https://haveibeenpwned.com/">HaveIBeenPwned</a>, which is the same free database security professionals use, and find that it appeared in a credential dump from a retail loyalty program breach three years earlier. The password has not been changed since.</p><p class="wp-block-paragraph">Your family member&#8217;s credentials are more interesting than they look at first. The same password, with minor variations, shows up across a streaming service, a gaming account, and your company&#8217;s Microsoft 365 login. The password works. The only thing standing between me and the inbox is the second factor.</p><p class="wp-block-paragraph">Total spend so far: $14.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Thursday: getting past your MFA</strong></h2><p class="wp-block-paragraph">Multi-factor authentication stops a lot of attacks, but the implementation matters more than the checkbox.</p><p class="wp-block-paragraph">Simple push-notification fatigue does not work against your office manager&#8217;s account. Microsoft enabled <a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match">number matching</a> by default for all Microsoft Authenticator push notifications in May 2023, which means she would have to type a code from her login screen rather than just tap approve. Push bombing fails against that configuration.</p><p class="wp-block-paragraph">What still works is adversary-in-the-middle (AiTM) phishing. I send your office manager an email designed to look like a routine Microsoft 365 password reset notification, citing the breach that her password appeared in (the same breach I found her credentials in earlier in the week). The link in the email takes her to a page that mirrors the real Microsoft sign-in screen. That page is a proxy I control.</p><p class="wp-block-paragraph">When she enters her password and approves her MFA prompt, my proxy forwards both to the real Microsoft login server. Microsoft validates the credentials, completes the MFA challenge, and issues a session token back to my proxy. I capture the token. She sees a normal login experience on what she thinks is the real Microsoft site, then a “password updated successfully” message.</p><p class="wp-block-paragraph">I am now signed in as her. The MFA prompt succeeded, and the session token sits in my browser instead of hers. Microsoft sees a valid authenticated session and treats my activity as legitimate.</p><p class="wp-block-paragraph">I had a backup plan in case the email did not get clicked. Earlier in the day, I called your office posing as your IT support company, using a name I found in a Google review you had left 18 months earlier. I told your receptionist that we were seeing unusual login activity on the office manager&#8217;s account and that I would need her to approve a verification push in the next few minutes. She said the office manager was not at her desk. I said no problem, I would try again later. The call cost me nothing.</p><p class="wp-block-paragraph">By Thursday night, I am inside your office manager&#8217;s Microsoft 365 account. I set up an inbox forwarding rule so her emails copy to an address I control without notifying her, then I wait.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Friday 2:47pm: why I waited 36 hours before encrypting</strong></h2><p class="wp-block-paragraph">I spend 36 hours reading email before I encrypt anything. That dwell time is how I size the ransom correctly.</p><p class="wp-block-paragraph">In those 36 hours, I find your cyber insurance policy attached to an email from your broker, with a cyber liability sub-limit of $250,000. A bank reconciliation your office manager sent you two weeks ago shows your business account at around $180,000 at month end. Your customer list sits in a quote template she emailed to herself, and a message thread with a municipal project manager mentions a job starting in three weeks with a hard deadline you cannot afford to miss.</p><p class="wp-block-paragraph">I set my ransom at $65,000 in cryptocurrency. That figure is low enough that you will pay rather than fight it, high enough that it is worth my time, and well within what I know you can access. Ransoms set above 10 percent of visible liquid assets tend to get contested. The figure I picked sits below that line.</p><p class="wp-block-paragraph">I deploy the encryption payload at 2:47pm on Friday. The timing is deliberate. Your bookkeeper finishes at 3pm on Fridays, which I know from an out-of-office reply I saw in the forwarded emails. You are on a job site, with your calendar synced to the shared inbox. The person most likely to notice something wrong and call for help is already gone, and the person with the authority to make decisions is unreachable.</p><p class="wp-block-paragraph">By the time anyone understands what has happened, it is a Friday evening, every file on your shared drive is encrypted, and a ransom note sits on every screen in your office.</p><p class="wp-block-paragraph">Total cost to me: $14 for credentials and about six hours of work spread across the week.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Five places this attack would have died</strong></h2><p class="wp-block-paragraph">The attack on your business worked because five ordinary things were not in place. None of them were expensive. Most were already bundled into security tools you already pay for.</p><p class="wp-block-paragraph"><strong>1. The credential purchase on Wednesday.</strong></p><p class="wp-block-paragraph"><a href="https://haveibeenpwned.com/">HaveIBeenPwned</a> is free. Microsoft Entra password protection can detect and block reused or commonly-compromised passwords across your accounts. Enforcing unique passwords per account, through a password manager and through Entra&#8217;s policies, makes a stolen credential purchase useless for me.</p><p class="wp-block-paragraph"><strong>2. The MFA bypass on Thursday night.</strong></p><p class="wp-block-paragraph">Microsoft already blocks the simpler push-bombing attack, because <a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match">number matching</a> has been enabled by default for all Microsoft Authenticator push notifications since May 2023. The current dominant credential-based bypass is adversary-in-the-middle phishing. Defenses include phishing-resistant MFA (FIDO2 hardware keys, passkeys, or Windows Hello for Business), Conditional Access policies that require a compliant or hybrid-joined device, and anti-phishing protection in Microsoft Defender for Office 365. Any one of these would have either prevented the session token capture or made the captured token unusable from my IP address.</p><p class="wp-block-paragraph"><strong>3. The inbox forwarding rule.</strong></p><p class="wp-block-paragraph">Microsoft 365 allows admins to <a href="https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding">block external email forwarding rules</a> at the tenant level. With that block in place, the inbox forwarding rule I used to read 36 hours of email would not have worked. I might have encrypted anyway, but I would have been guessing on the ransom size.</p><p class="wp-block-paragraph"><strong>4. The 36-hour dwell time.</strong></p><p class="wp-block-paragraph">Microsoft Defender for Business, included in Microsoft 365 Business Premium, generates an alert when a new inbox forwarding rule is created. If anyone had been watching those alerts, or if the alerts had been routed somewhere visible, I would have been detected on Thursday night. The most impactful change for a business your size is rarely a new product purchase. The improvement comes from someone reviewing the security alerts that the tools you already pay for are already generating.</p><p class="wp-block-paragraph"><strong>5. The public business records.</strong></p><p class="wp-block-paragraph">You cannot unpublish a state contracting registry or a federal contract award. That data will stay public. What you can control is what your team chooses to post about their specific responsibilities. Your office manager&#8217;s LinkedIn profile listed her financial responsibilities in enough detail to make her the obvious target. That detail is worth a conversation with your team, framed as practical security awareness rather than a rule about what people can post.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Three questions to send your IT provider</strong></h2><p class="wp-block-paragraph">These three questions cover most of where the example attack failed. Each one corresponds to a control that comes bundled with security tools you most likely already pay for.</p><ol class="wp-block-list"><li>Are we using phishing-resistant MFA (FIDO2 keys, passkeys, or Windows Hello for Business) for finance, admin, and executive logins?</li><li>Is external email forwarding blocked at the tenant level?</li><li>Are our security alerts going somewhere, and is someone reviewing them?</li></ol><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Frequently asked questions</strong></h2><p class="wp-block-paragraph"><strong>Do hackers target small businesses?</strong></p><p class="wp-block-paragraph">Yes. Most ransomware operations target small and mid-sized businesses because the ratio of payout potential to defensive resources is higher than at either extreme of company size. The volume sweet spot is roughly 10 to 50 staff, where there are assets worth encrypting but no dedicated security team to defend them.</p><p class="wp-block-paragraph"><strong>What is adversary-in-the-middle (AiTM) phishing?</strong></p><p class="wp-block-paragraph">AiTM phishing is a technique where the attacker hosts a proxy page that mirrors a real login screen, such as Microsoft 365 or Google Workspace. When the user enters credentials and approves the MFA prompt, the proxy captures the resulting session token. The legitimate service treats the login as successful, but the session token ends up in the attacker&#8217;s browser. AiTM has become the dominant credential-based attack vector against Microsoft 365 tenants after the default rollout of number matching ended simpler push-bombing attacks.</p><p class="wp-block-paragraph"><strong>What is a stealer log?</strong></p><p class="wp-block-paragraph">A stealer log is a package of credentials harvested by infostealer malware from an infected personal device. The logs include browser-saved passwords, session cookies, and stored authentication tokens, and they are sold on underground markets for $10 to $20 per package. The malware that creates them typically infects personal computers through pirated software or malicious browser extensions.</p><p class="wp-block-paragraph"><strong>How much does it cost an attacker to compromise a small business?</strong></p><p class="wp-block-paragraph">In the example walkthrough above, the total spend was $14 for stolen credentials and about six hours of work. Costs vary, but the threshold to attempt the kind of attack described in this post sits well below $100.</p><p class="wp-block-paragraph"><strong>Are there free tools that would have stopped this attack?</strong></p><p class="wp-block-paragraph">Several of the controls referenced in the walkthrough come bundled with Microsoft 365 Business Premium licenses that businesses in this size range typically already hold. External forwarding restrictions and Defender for Business alerts are configuration changes rather than new purchases. HaveIBeenPwned is a free check available to anyone. Phishing-resistant MFA hardware keys are a small per-user cost compared with the cost of a successful ransomware incident.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Sources and further reading</strong></h2><ul class="wp-block-list"><li><a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA: Stop Ransomware Guide</a> — federal guidance on the controls referenced throughout this walkthrough.</li><li><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match">Microsoft Learn: How number matching works in MFA push notifications</a> — Microsoft&#8217;s documentation on the default-enabled Authenticator feature that blocks push-bombing attacks.</li><li><a href="https://haveibeenpwned.com/">HaveIBeenPwned</a> — the free database used to check whether an email address has appeared in known breaches.</li><li><a href="https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding">Microsoft Learn: Configure external email forwarding in Microsoft 365</a> — how to block tenant-level external forwarding rules.</li></ul><p class="wp-block-paragraph"><em>If any of this walkthrough sounded uncomfortably similar to your environment, the three questions above are a good starting point. Your IT provider should be able to confirm what is in place and what is not within an hour or two. And if you don&#8217;t have an IT provider, feel free to reach out to us and we&#8217;ll help you sort it.</em></p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph">&#8212;</p><p class="wp-block-paragraph"><a href="https://unsplash.com/photos/macbook-pro-turned-on-JJPqavJBy_k" target="_blank" rel="noreferrer noopener">Featured Image Credit</a></p><p>This Article has been Republished with Permission from <a rel="canonical" href="https://thetechnologypress.com/how-small-business-ransomware-attacks-work-and-how-to-protect-against-them/" title="How Small Business Ransomware Attacks Work (And How to Protect Against Them)" target="_blank">The Technology Press.</a></p><p>The post <a href="https://speedwise.net/blog/how-small-business-ransomware-attacks-work-and-how-to-protect-against-them/">How Small Business Ransomware Attacks Work (And How to Protect Against Them)</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy</title>
		<link>https://speedwise.net/blog/how-to-answer-cyber-insurance-renewal-questions-without-voiding-your-policy/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sat, 25 Jul 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<guid isPermaLink="false">https://speedwise.net/?p=7437</guid>

					<description><![CDATA[<p>If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled in last time. It&#8217;s also more specific. Each new question maps to a control that, if missing, allowed a major 2023 or 2024 claim to escalate. The wording reflects how carriers responded to losses they paid [&#8230;]</p>
<p>The post <a href="https://speedwise.net/blog/how-to-answer-cyber-insurance-renewal-questions-without-voiding-your-policy/">How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled in last time. It&#8217;s also more specific. Each new question maps to a control that, if missing, allowed a major 2023 or 2024 claim to escalate. The wording reflects how carriers responded to losses they paid in 2023 and 2024, and how you answer the form matters more than it used to.</p><p class="wp-block-paragraph">This post covers why the application got longer, what each new section is asking, how to answer honestly without overstating your controls, and what to fix in the 30 days before submission. The expensive mistake on a cyber insurance application is rescission, where a future claim is denied because the carrier finds that the controls you declared were not in place at the time.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Why the renewal application got longer</strong></h2><p class="wp-block-paragraph">The current generation of cyber insurance applications was shaped by three specific claim events from 2023 and 2024.</p><p class="wp-block-paragraph">The <a href="https://www.cybersecuritydive.com/news/moveit-breach-timeline/687417/">MOVEit supply-chain breach</a> surfaced on May 28, 2023, when Progress Software received the first reports of unusual activity from customers. The Cl0p ransomware group had been exploiting a previously unknown vulnerability in Progress Software&#8217;s MOVEit Transfer file-sharing tool, with activity detected by some researchers as early as February of that year. By late 2023, more than 2,650 organizations and over 66 million individuals had been affected, with totals rising further into 2024. Carriers paid claims across that footprint, and the experience reshaped how underwriters ask about third-party software risk.</p><p class="wp-block-paragraph">Then the <a href="https://www.hipaajournal.com/biggest-healthcare-data-breaches-2024/">Change Healthcare ransomware incident</a> in February 2024 froze US healthcare claims processing for weeks. The attacker gained network access on February 12, 2024, and deployed ransomware on February 21, with downstream impact on pharmacies, providers, and patients across the country. HIPAA Journal&#8217;s coverage noted that the absence of multifactor authentication on a key entry point made the initial intrusion possible. Industry analysts have estimated the cyber insurance loss from this single event at over $250 million, and the response was tighter questions about backup immutability and incident response readiness.</p><p class="wp-block-paragraph">The <a href="https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo/">Arup deepfake wire fraud</a>, also from early 2024, reframed how underwriters approach social engineering. A finance employee at the engineering firm&#8217;s Hong Kong office transferred $25.6 million across 15 wires after a video call with what appeared to be the company&#8217;s CFO and other executives, all of whom were AI-generated deepfakes. The fraud went undiscovered for about a week, until the employee contacted Arup headquarters about a “secret transaction.” Out-of-band callback verification for wire transfers is now on every underwriter&#8217;s checklist.</p><p class="wp-block-paragraph">If you run an e-commerce store handling cardholder data, a healthcare practice with PHI, an accounting firm or law firm moving client funds, or a real estate brokerage handling escrow, your application is the longest of all. You sit in the loss categories carriers got burned on.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>The backup question changed</strong></h2><p class="wp-block-paragraph">The backup question on cyber insurance applications has tightened materially since 2023. What used to be a single yes/no question now asks whether those backups are immutable or air-gapped, when they were last tested, and whether they can be deleted by your domain administrator credentials.</p><p class="wp-block-paragraph">Expect wording on your form like: <em>“Are backups stored in an immutable or air-gapped state, tested for restoration within the past 12 months, and inaccessible to domain administrator credentials?”</em></p><p class="wp-block-paragraph">An immutable backup is one that nobody can delete or alter during a fixed retention window, including someone using stolen administrator credentials. Air-gapped means the backup copy sits on infrastructure that cannot be reached from your production network. CISA&#8217;s Stop Ransomware Guide lists immutable, tested backups as a baseline control, which is the same standard most cyber insurance carriers now apply.</p><p class="wp-block-paragraph">“Microsoft 365 backup” is no longer a passing answer on its own. Native Microsoft 365 retention isn&#8217;t a backup in the sense the carrier means. Third-party backups that share the same identity perimeter as your production tenant can be wiped by a compromised global admin.</p><p class="wp-block-paragraph">For the immutable backup question, the strongest answer references a backup platform with object lock or write-once-read-many storage enabled, an immutability window of at least 14 days (with 30 days now preferred), credentials separated from your production admin accounts, and a recent successful restore test. Weaker answers describe daily backups to a NAS on the same network with no recent restore test, which typically triggers follow-up underwriting and sometimes a premium adjustment. Answers that leave the immutability question unclear are the ones most likely to push a renewal toward sub-limits or non-renewal.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>MFA questions go deeper than one checkbox</strong></h2><p class="wp-block-paragraph">MFA was once captured as a single yes/no question on most applications. The current generation asks whether MFA is enforced on email, VPN, remote desktop (RDP), all administrator accounts, and privileged service accounts. The answer needs to be yes on all five for a clean pass.</p><p class="wp-block-paragraph">SMS-based MFA is now treated as a weaker control. SIM-swap attacks and SS7 vulnerabilities have made text codes the weakest authentication factor available. Several carriers ask specifically whether your MFA uses an authenticator app, hardware token, or push with number matching, rather than SMS. If you&#8217;re still on SMS for admin accounts, expect a follow-up question or a premium adjustment.</p><p class="wp-block-paragraph">The privileged access management (PAM) question is the one most owners haven&#8217;t seen before. PAM is a category of tool that keeps administrator credentials out of regular password managers. A PAM platform vaults privileged credentials, rotates them on use, and logs every session, which means a stolen admin password can&#8217;t be used unnoticed for weeks before someone catches it.</p><p class="wp-block-paragraph">A strong PAM answer describes a vaulting tool with credentials rotated on use and session logging enabled. Weaker answers, like admin passwords stored in a shared password manager with annual rotation, will usually trigger follow-up underwriting. Shared admin accounts that never rotate and produce no audit log of who used them are the configuration most likely to result in sub-limits or non-renewal.</p><p class="wp-block-paragraph">Will cyber insurance be denied if you don&#8217;t have MFA everywhere? Not always denied outright. Expect significant premium increases, sub-limits on ransomware coverage, or exclusions for any incident that traces back to the unprotected entry point.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>The wire transfer and deepfake verification questions</strong></h2><p class="wp-block-paragraph">After the Arup case and a string of business email compromise losses, carriers added callback verification questions to their applications. Callback verification means that before sending any wire above a defined threshold (commonly $10,000 or $25,000), the person authorizing the transfer calls the recipient at a phone number previously verified and stored, not the number on the request email.</p><p class="wp-block-paragraph">Expect wording like: <em>“Does your organization require out-of-band verification using a previously known phone number for all funds transfer requests above [threshold], including requests appearing to come from executives?”</em></p><p class="wp-block-paragraph">Several current applications now ask separately whether staff have been trained on AI voice cloning and deepfake video risks. The Arup case made that question relevant for every carrier writing in professional services.</p><p class="wp-block-paragraph">Accounting firms, law firms with escrow or trust accounts, and real estate brokers will see this section scrutinized most carefully. Anyone moving other people&#8217;s money is a soft target and an expensive claim when wire fraud lands.</p><p class="wp-block-paragraph">A strong answer references a written wire transfer policy requiring callback verification to a verified number for transfers above a stated threshold, dual approval, and annual social engineering training that includes deepfake awareness. Informal verification practice without a written policy will usually be flagged for follow-up. Wire transfers authorized by email approval alone are the configuration carriers are now declining to cover at all.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>EDR, MDR, and the end of the “we have antivirus” answer</strong></h2><p class="wp-block-paragraph">Traditional antivirus scans files against a list of known threats. Endpoint Detection and Response (EDR) watches behavior on each device and flags suspicious activity, such as a process trying to encrypt files or escalate privileges. Managed Detection and Response (MDR) is EDR plus a 24/7 team watching the alerts and responding when something fires at 2am on a Sunday.</p><p class="wp-block-paragraph">Current applications ask whether you have EDR deployed, whether it covers 100% of endpoints including servers, and whether a 24/7 security operations center (SOC) monitors and responds to alerts. The MDR question is increasingly yes or no, and the no answer has pricing consequences.</p><p class="wp-block-paragraph">If you don&#8217;t have MDR yet but plan to add it, say so plainly with a timeline. Underwriters can work with “MDR deployment scheduled for Q2 with vendor selected.” They cannot work with vague answers about future plans.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>The vendor risk questions</strong></h2><p class="wp-block-paragraph">Supply chain questions used to be a single yes/no item. After MOVEit and Change Healthcare, carriers now want a full section on the software vendors holding your data.</p><p class="wp-block-paragraph">Expect questions like: <em>“List your top five software vendors with access to sensitive data and confirm whether each provides a SOC 2 Type II report or equivalent.”</em> If you&#8217;ve never asked your practice management software vendor for a SOC 2 report, that conversation is overdue.</p><p class="wp-block-paragraph">You&#8217;re not expected to audit every vendor&#8217;s security program in detail. The carrier wants to see that you know who your top vendors are, what data they hold, and that you&#8217;ve asked the basic questions like SOC 2 attestation. An honest “we&#8217;ve identified our top five vendors and requested SOC 2 reports from three, with two outstanding” reads better than a confident answer that falls apart in discovery.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>The mistake to avoid: misrepresentation and rescission</strong></h2><p class="wp-block-paragraph">The most expensive answer on a cyber insurance application is the one that overstates the security controls you have in place. Cyber insurance applications are warranty documents. If a forensic investigation after a claim finds your environment didn&#8217;t match what you declared, the carrier can rescind the policy.</p><p class="wp-block-paragraph">Rescission means the policy is treated as if it never existed, your claim is denied, and any prior payouts under the same policy term can be clawed back. Some courts have found that the carrier doesn&#8217;t need to prove a direct link between the misrepresentation and the loss. The misrepresentation itself is enough.</p><p class="wp-block-paragraph">The cleanup approach is direct. If a question asks about MFA on all admin accounts and you have a gap, declare the gap and include a remediation date. Carriers reward honest gaps with a plan more than they reward polished answers that don&#8217;t survive forensic review.</p><p class="wp-block-paragraph">Checking “no” or “in progress” on the form may raise your premium or tighten your coverage terms. That cost is predictable. Misrepresentation discovered after a claim can void the policy entirely, and the timing means you absorb the full incident cost yourself.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>The 30-day pre-renewal checklist</strong></h2><p class="wp-block-paragraph">Work through this in order. Most items are achievable in a month if you start now.</p><p class="wp-block-paragraph"><strong>Week 1. </strong>Confirm MFA on email, VPN, remote desktop, all administrator accounts, and any service accounts that support it. Move admin MFA off SMS to an authenticator app or hardware token.</p><p class="wp-block-paragraph"><strong>Weeks 1 to 2. </strong>Verify your backups are immutable or air-gapped. Run a test restore, and document the result with date and screenshots.</p><p class="wp-block-paragraph"><strong>Week 2. </strong>Write a one-page wire transfer policy requiring callback verification to a previously verified phone number for any transfer over your chosen threshold. Get it signed by anyone who can authorize payments.</p><p class="wp-block-paragraph"><strong>Weeks 2 to 3. </strong>Confirm EDR is deployed on every endpoint and server. If you only have traditional antivirus, get quotes for EDR or MDR now so you can answer with a deployment timeline.</p><p class="wp-block-paragraph"><strong>Week 3. </strong>Identify your top five software vendors and request SOC 2 reports or equivalent attestations. Note who responded.</p><p class="wp-block-paragraph"><strong>Weeks 3 to 4. </strong>Document or update your incident response plan, then run a 60-minute tabletop exercise with your leadership team. Keep the notes. That&#8217;s your “tested in the past 12 months” evidence.</p><p class="wp-block-paragraph"><strong>Week 4. </strong>Sit down with the application and answer honestly. Flag anything you couldn&#8217;t fix, with a specific remediation date.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Frequently asked questions</strong></h2><p class="wp-block-paragraph"><strong>What does rescission mean on a cyber insurance policy?</strong></p><p class="wp-block-paragraph">Rescission means the carrier voids the policy from inception after discovering material misrepresentation on the application. The policy is treated as if it never existed, the current claim is denied, and any prior payouts under the same policy term can be clawed back.</p><p class="wp-block-paragraph"><strong>Will my cyber insurance be denied if I don&#8217;t have MFA on everything?</strong></p><p class="wp-block-paragraph">Not always denied outright. Expect a significant premium increase, sub-limits on ransomware coverage, or exclusions for incidents that trace back to the unprotected entry point. The most common gap is MFA on privileged or service accounts.</p><p class="wp-block-paragraph"><strong>What is the difference between EDR and MDR on an insurance application?</strong></p><p class="wp-block-paragraph">EDR (Endpoint Detection and Response) is the technology that watches device behavior and flags suspicious activity. MDR (Managed Detection and Response) is the same technology plus a 24/7 team watching the alerts and responding. Carriers increasingly want both, and the application often asks about each separately.</p><p class="wp-block-paragraph"><strong>Why are cyber insurance renewal applications longer than they used to be?</strong></p><p class="wp-block-paragraph">Carriers added detailed sections in response to specific 2023 and 2024 losses, including the MOVEit supply-chain breach, the Change Healthcare ransomware incident, and the Arup deepfake wire fraud. Each event drove changes to backup, MFA, vendor risk, or wire transfer questions on subsequent applications.</p><p class="wp-block-paragraph"><strong>Can my cyber insurance claim be denied if I answered the application incorrectly?</strong></p><p class="wp-block-paragraph">Yes. Material misrepresentation on a cyber insurance application can trigger rescission, which voids coverage retroactively. Many courts have found that the carrier does not need to prove a causal link between the misrepresentation and the specific loss.</p><p class="wp-block-paragraph"><strong>What does immutable backup mean on a cyber insurance application?</strong></p><p class="wp-block-paragraph">A backup that cannot be modified or deleted for a defined retention period, even by someone using stolen administrator credentials. Cloud object lock and write-once-read-many storage are common implementations. Most carriers want a window of at least 14 days, with 30 days now preferred.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Sources and further reading</strong></h2><ul class="wp-block-list"><li><a href="https://www.cybersecuritydive.com/news/moveit-breach-timeline/687417/">Cybersecurity Dive: MOVEit breach timeline</a> — detailed timeline of the 2023 vulnerability exploitation and the scale of the affected population.</li><li><a href="https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo/">Fortune: Arup deepfake $25M fraud</a> — coverage of the January 2024 Hong Kong deepfake wire fraud and how it unfolded.</li><li><a href="https://www.hipaajournal.com/biggest-healthcare-data-breaches-2024/">HIPAA Journal: Biggest healthcare data breaches of 2024</a> — analysis of the February 2024 Change Healthcare incident and its industry-wide impact.</li><li><a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA: Stop Ransomware Guide</a> — federal guidance on the security controls cyber insurance applications now ask about.</li></ul><p class="wp-block-paragraph"><em>If you have a cyber insurance renewal coming up and the gap between where your controls are and where the form wants them to be feels wider than 30 days, your IT provider should be able to walk through the application with you and identify what&#8217;s fixable in the time you have. And if you don&#8217;t have an IT provider, feel free to reach out to us and we&#8217;ll help you sort it.</em></p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph">&#8212;</p><p class="wp-block-paragraph"><a href="https://www.pexels.com/photo/white-papers-on-the-table-8369207/" data-type="link" data-id="https://www.pexels.com/photo/white-papers-on-the-table-8369207/" target="_blank" rel="noreferrer noopener">Featured Image Credit</a></p><p class="wp-block-paragraph"></p><p>This Article has been Republished with Permission from <a rel="canonical" href="https://thetechnologypress.com/how-to-answer-cyber-insurance-renewal-questions-without-voiding-your-policy/" title="How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy" target="_blank">The Technology Press.</a></p><p>The post <a href="https://speedwise.net/blog/how-to-answer-cyber-insurance-renewal-questions-without-voiding-your-policy/">How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why Bad Onboarding Is the Real Cause of Messy Offboarding</title>
		<link>https://speedwise.net/blog/why-bad-onboarding-is-the-real-cause-of-messy-offboarding/</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[IT Management]]></category>
		<guid isPermaLink="false">https://speedwise.net/?p=7440</guid>

					<description><![CDATA[<p>By the time an employee hands in their notice, the decisions that will make their departure clean or messy have already been made. They were made in the first weeks of the person&#8217;s tenure, when nobody was paying close attention because the new hire had just arrived and there were a hundred other things to [&#8230;]</p>
<p>The post <a href="https://speedwise.net/blog/why-bad-onboarding-is-the-real-cause-of-messy-offboarding/">Why Bad Onboarding Is the Real Cause of Messy Offboarding</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">By the time an employee hands in their notice, the decisions that will make their departure clean or messy have already been made. They were made in the first weeks of the person&#8217;s tenure, when nobody was paying close attention because the new hire had just arrived and there were a hundred other things to do. A shared login here, a quick SaaS sign-up there, a personal laptop used until the company hardware arrived. By month six, none of those feel like decisions at all. They feel like how things are.</p><p class="wp-block-paragraph">This post covers what&#8217;s really going wrong when offboarding takes three weeks, the four onboarding shortcuts that guarantee a painful exit, how to retrofit hygiene on the team you already have, and what your IT provider should be doing at onboarding that probably isn&#8217;t happening.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>What&#8217;s really going wrong when offboarding takes three weeks</strong></h2><p class="wp-block-paragraph">A clean offboarding takes about 90 minutes of IT time. An account is disabled in your identity provider, which cascades access revocation across every tool connected via single sign-on. The device is remotely wiped or collected and wiped on-site. Email is forwarded to a manager or converted to a shared mailbox. The departing person&#8217;s accounts in your CRM and project tools are reassigned. A handover note, already templated because it was templated at onboarding, gets filled in and filed.</p><p class="wp-block-paragraph">The messy version of the same process can take three weeks. It starts with a manual list of tools nobody can fully remember, which usually means asking the departing employee to help reconstruct it. You find a Figma account, a Loom workspace, a Notion instance, and an Airtable base, all set up independently, all with passwords sitting in the departing employee&#8217;s personal password manager. The laptop is at their house and they&#8217;re not in any rush. A client emails to say they received a strange message from a personal address. Six weeks later, a vendor charges the company card for a seat you thought you cancelled.</p><p class="wp-block-paragraph">Whether your offboarding is clean or chaotic depends on what was set up during onboarding.</p><p class="wp-block-paragraph">In the identity management world, this is called the “joiner, mover, leaver” lifecycle. Microsoft and most identity vendors use the same three-phase model. A rushed joiner phase compresses months of identity cleanup into the two weeks after the resignation lands.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>Four onboarding shortcuts that guarantee a messy exit</strong></h2><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>Letting new hires sign up for SaaS tools on their own</strong></h3><p class="wp-block-paragraph">When a staff member signs up for a tool independently, using their work email and a password only they know, that account is functionally theirs. You can&#8217;t reset it without triggering a notification to them. You may not even know the account exists until a vendor invoice shows up, or until the account goes dark after they leave and a client project breaks.</p><p class="wp-block-paragraph">This is the most common source of the “we can&#8217;t find half the logins when someone leaves” problem. The fix is provisioning every tool through a central identity system, where any new SaaS application gets connected to your single sign-on before the first user logs in.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>Tolerating personal devices “just until we get them sorted”</strong></h3><p class="wp-block-paragraph">Personal devices that get used for work don&#8217;t stay temporary. The employee installs apps, connects to client systems, downloads files, and what was a temporary fix becomes how they work permanently. When they leave, you have no ability to wipe company data from a device you don&#8217;t own and never enrolled in a management system. You&#8217;re relying on their goodwill, which is usually fine, but it is not a security control.</p><p class="wp-block-paragraph">The fix is to issue company-owned devices on day one and enroll them in mobile device management. When you do allow a personal device, require managed app access for company email and files. Browser-saved credentials are not a substitute.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>Shared logins for tools you didn&#8217;t want to pay per-seat for</strong></h3><p class="wp-block-paragraph">Shared credentials are the worst offender at offboarding. When five people use the same login for a tool, you can&#8217;t remove one person&#8217;s access without changing the password for everyone. You usually find this out at the worst possible time, when the person leaving is the one who set up the account and nobody else remembers the password at all.</p><p class="wp-block-paragraph">Per-seat is the cost of doing this properly. The savings from shared logins reappear during offboarding as wasted hours and exposed access.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>Letting client relationships live in one person&#8217;s inbox</strong></h3><p class="wp-block-paragraph">This one is specific to agencies and professional services. When a senior account manager or consultant leaves, their client relationships often leave with them. The context, the email history, the preferences, and the half-finished threads lived in one person&#8217;s inbox. With the person gone, all of that becomes inaccessible or awkward to retrieve.</p><p class="wp-block-paragraph">From the client&#8217;s side, your business just doesn&#8217;t know who they are anymore.</p><p class="wp-block-paragraph">The fix is a shared inbox or CRM where client communication is logged. Even a Microsoft 365 shared mailbox with a clear expectation that client threads are CC&#8217;d to it is a meaningful improvement over what most small businesses have today.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>How to retrofit hygiene on the team you already have</strong></h2><p class="wp-block-paragraph">The cleanup most businesses need is for the team they already have, before the next hire arrives. You can&#8217;t go back and re-onboard your existing staff, but you can audit what&#8217;s there and close the gaps before the next departure.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>The SaaS audit</strong></h3><p class="wp-block-paragraph">Pull three months of credit card statements (every card that gets used for business expenses) and list every recurring SaaS charge. For each one, find out who set it up, who has the login, whether the account uses a personal or company email, and whether anyone else can access it if that person left tomorrow.</p><p class="wp-block-paragraph">You&#8217;ll find tools nobody remembers signing up for, tools used by one person with no backup access, and accounts where the original owner has already left while you&#8217;re still paying for the seat. None of this is a technical exercise. All it takes is a spreadsheet and an afternoon.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>The device register</strong></h3><p class="wp-block-paragraph">Build a simple list: who has what, when each device was issued, whether it&#8217;s enrolled in a management system, and what company data each device can access. If you don&#8217;t have one, build it now. Ask every staff member to confirm the devices they use for work, including personal ones. The goal is to map what you&#8217;re working with. Most employees are happy to confirm what device they use once they know nothing punitive will come of it.</p><p class="wp-block-paragraph">For any personal device that has been used to access company systems, the minimum is making sure company email and file access happens through managed apps that can be remotely disconnected.</p><p class="wp-block-paragraph"></p><h3 class="wp-block-heading"><strong>Client communication in shared places</strong></h3><p class="wp-block-paragraph">Move client communication into shared places so the relationship belongs to the business when an individual moves on. Continuity is the goal. Set up a shared inbox or alias for client-facing communication, and use a CRM where contact history and notes are logged. Even a shared Microsoft 365 mailbox with a clear expectation that client threads are CC&#8217;d to it is a meaningful improvement over what most small businesses do today.</p><p class="wp-block-paragraph"></p><h2 class="wp-block-heading"><strong>What your IT provider should be doing at onboarding</strong></h2><p class="wp-block-paragraph">Most IT providers get called when someone resigns. They show up, disable the account, collect the laptop if they can find it, and do their best with whatever documentation exists. That&#8217;s the wrong end of the lifecycle to be involved in. If that&#8217;s the only time your IT provider is involved in staff transitions, you&#8217;re not getting much value from the relationship.</p><p class="wp-block-paragraph">The model that works puts your IT provider at onboarding too. They set up the new account in your identity provider, enroll the device in your mobile device management system, and provision access through single sign-on so every tool the new hire uses is connected to a central identity that can be switched off in one action. They should also maintain a handover document for each staff member, updated periodically, listing every system the person accesses, every client relationship they own, and every credential tied to their identity.</p><p class="wp-block-paragraph">When that&#8217;s in place, offboarding becomes a checklist and an hour rather than a three-week excavation. Ask your IT provider what they do at onboarding. If the answer is “not much” or “we usually just get called when someone leaves,” that&#8217;s worth a conversation.</p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph"><strong>A 60-day plan before your next round of departures</strong></p><p class="wp-block-paragraph">You don&#8217;t need to know the exact date of the next resignation to start. The work is more manageable when nothing is urgent.</p><p class="wp-block-paragraph"><strong>Weeks 1 and 2: </strong>Run the credit card SaaS audit. Build a list of every tool, every account owner, and every login that only one person controls. Flag the ones where access would be lost or complicated if that person left this week.</p><p class="wp-block-paragraph"><strong>Weeks 3 and 4: </strong>Build the device register. Confirm what every staff member uses for work. For personal devices with company access, implement managed app access at minimum. Enroll company-owned devices in a management system if they aren&#8217;t already.</p><p class="wp-block-paragraph"><strong>Weeks 5 and 6: </strong>Audit client-facing communication. Identify any client relationships that exist primarily in one person&#8217;s inbox or on someone&#8217;s mobile phone. Set up shared mailboxes or CRM logging for the highest-risk accounts first.</p><p class="wp-block-paragraph"><strong>Weeks 7 and 8: </strong>Write the onboarding process you wish you&#8217;d had. Use everything you found in the previous six weeks as the input. Apply it to your next hire from day one, and use it as the template for a handover document for every existing staff member.</p><p class="wp-block-paragraph">Most of this is an operational task rather than a technology project. A spreadsheet, some honest conversations with your team, and a few hours of your IT provider&#8217;s time will cover the bulk of it.</p><p class="wp-block-paragraph"><strong>Frequently asked questions</strong></p><p class="wp-block-paragraph"><strong>How long should offboarding take in a small business?</strong></p><p class="wp-block-paragraph">With proper onboarding hygiene and centralized identity, the IT side of offboarding takes about 60 to 90 minutes. Take that foundation away and the same task can stretch to two or three weeks of scattered cleanup.</p><p class="wp-block-paragraph"><strong>How do I find SaaS tools my team signed up for without telling me?</strong></p><p class="wp-block-paragraph">The fastest way is a three-month review of every credit card statement used for business expenses. Most shadow SaaS shows up as a recurring charge somewhere on the card.</p><p class="wp-block-paragraph"><strong>Can I wipe a personal device after someone leaves?</strong></p><p class="wp-block-paragraph">Only the company data, and only if you set that up while they were still employed. Mobile device management or managed app access lets you remove company email, files, and credentials from a personal device without touching the rest of it. If those tools weren&#8217;t in place during their employment, your options are limited.</p><p class="wp-block-paragraph"><strong>What&#8217;s the role of single sign-on in offboarding?</strong></p><p class="wp-block-paragraph">Single sign-on means every tool a user accesses is tied to a central identity. Disabling that identity in one place revokes access everywhere. Without single sign-on, you have to manually log into each platform and remove the user.</p><p class="wp-block-paragraph"><strong>Should I make my employees use only company devices?</strong></p><p class="wp-block-paragraph">Where practical, yes. For personal devices, enrolling them in a management system or requiring managed app access is the next best thing. A personal device with saved company credentials and no management is the highest-risk configuration for offboarding.</p><p class="wp-block-paragraph"><strong>Sources and further reading</strong></p><ul class="wp-block-list"><li><a href="https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows">Microsoft Learn: What are lifecycle workflows in Microsoft Entra?</a> — Microsoft&#8217;s framing of the joiner / mover / leaver lifecycle and the workflows that automate it.</li><li><a href="https://learn.microsoft.com/en-us/intune/app-management/protection/overview">Microsoft Learn: App Protection Policies overview (Intune)</a> — how managed app access works for personal devices, including selective wipe of company data.</li></ul><p class="wp-block-paragraph"><em>If your offboarding process feels harder than it should be, that&#8217;s a good signal that your onboarding needs attention. Your IT provider should be able to walk you through both ends of the lifecycle and help you tighten what&#8217;s loose. And if you don&#8217;t have an IT provider, feel free to reach out to us and we&#8217;ll help you sort it.</em></p><p class="wp-block-paragraph"></p><p class="wp-block-paragraph">&#8212;</p><p class="wp-block-paragraph"><a href="https://www.pexels.com/photo/a-man-and-a-woman-shaking-hands-9301879/">Featured Image Credit</a></p><p class="wp-block-paragraph"></p><p>This Article has been Republished with Permission from <a rel="canonical" href="https://thetechnologypress.com/why-bad-onboarding-is-the-real-cause-of-messy-offboarding/" title="Why Bad Onboarding Is the Real Cause of Messy Offboarding" target="_blank">The Technology Press.</a></p><p>The post <a href="https://speedwise.net/blog/why-bad-onboarding-is-the-real-cause-of-messy-offboarding/">Why Bad Onboarding Is the Real Cause of Messy Offboarding</a> appeared first on <a href="https://speedwise.net">SpeedWise IT Services</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Database Caching using Disk (Request-wide modification query)

Served from: speedwise.net @ 2026-08-16 14:10:09 by W3 Total Cache
-->