
Have you felt more secure from cyberattacks because you have a smaller business? Maybe you thought that you couldn’t possibly have anything that hackers could want? Maybe you didn’t think they even knew about your small business.
A new report by cybersecurity firm Barracuda Networks debunks this myth. Their report analyzed millions of emails across thousands of organizations. It found that small companies have a lot to worry about when it comes to their IT security.
Barracuda Networks found something alarming. Employees at small companies saw 350% more social engineering attacks than those at larger ones. It defines a small company as one with less than 100 employees. This puts small businesses at a higher risk of falling victim to a cyberattack. We will explore why below.
Why Are Smaller Companies Targeted More?
There are many reasons why hackers see small businesses as low-hanging fruit. They are becoming larger targets of hackers out to score a quick illicit buck.
Small Companies Tend to Spend Less on Cybersecurity
When you’re running a small business, it is often a juggling act of where to prioritize your cash. You may know cybersecurity is important but it may not be at the top of your list. At the end of the month, cash runs out and it is moved to the “next month” wish list of expenditures.
Small business leaders often don’t spend as much as they should on their IT security. They may buy an antivirus program and think that is enough to cover them. However, with the expansion of technology to the cloud, that is just one small layer. You need several more for adequate security.
Hackers know all this and see small businesses as an easier target. They can do much less work to get a payout than they would trying to hack into an enterprise corporation.
Every Business Has “Hack-Worthy” Resources
Every business (even a 1-person shop) has data that is worth scoring for a hacker. Credit card numbers, SSN's, tax ID numbers and email addresses are all valuable. Cybercriminals can sell these on the Dark Web. From there, other criminals use them for identity theft.
Here are some of the data that hackers will go after:
- Customer records
- Employee records
- Bank account information
- Emails and passwords
- Payment card details
Small Businesses Can Provide Entry Into Larger Ones
If a hacker can breach the network of a small business, they can often make a larger score. Many smaller companies provide services to larger companies. This can include digital marketing, website management, accounting, etc.
Vendors are often digitally connected to certain client systems. This type of relationship can enable a multi-company breach. While hackers don’t need that connection to hack you, it is a nice bonus. They can get two companies for the work of one.
Small Business Owners Are Often Unprepared for Ransomware
Ransomware has been one of the fastest-growing cyberattacks of the last decade. So far in 2022, over 71% of surveyed organizations experienced ransomware attacks.
The percentage of victims that pay the ransom to attackers has also been increasing. An average of 63% of companies pay the attacker money in hopes of getting a key to decrypt the ransomware.
Even if a hacker can’t get as much ransom from a small business as they can from a larger organization, it’s worth it. They often can breach more small companies than they can larger ones.
When companies pay the ransom, it feeds the beast and more cyber criminals join in. Those newer to ransomware attacks will often go after smaller, easier-to-breach companies.
Employees at Smaller Companies Usually Aren’t Trained in Cybersecurity
Employee cybersecurity training is not usually high on the list of priorities for a small business owner. They may be doing all they can just to keep good staff. Priorities are often sales and operations.
Training employees on how to spot phishing and password best practices often isn’t done. This leaves networks vulnerable to one of the biggest dangers - human error.
In most cyberattacks, the hacker needs help from a user. It’s like the vampire needing the unsuspecting victim to invite them inside. Phishing emails are the device needed to get that unsuspecting cooperation.
Phishing causes over 80% of data breaches.
A phishing email sitting in an inbox can’t usually do anything. It needs the user to either open a file attachment or click a link that will take them to a malicious site. This then launches the attack.
Teaching employees how to spot these ploys can significantly increase your cybersecurity. Security awareness training is as important as having a strong firewall or antivirus.
Need Affordable IT Security Services for Your Small Business?
Reach out today to schedule a technology consultation. We offer affordable options for small companies. This includes many ways to keep you protected from cyber threats.
Give us a call at (860) 577-8060 or use our convenient contact form.
We all know that customer experience is the key to success. Improving customer experience can be a challenge. It is important to stay ahead of the curve and make it a priority. Improving the experience that prospects and customers have when interacting with your company directly impacts your bottom line. It can also be done through the use of modern technology.Read more

The pandemic has been a reality that companies around the world have shared. It required major changes in how businesses operate. The status quo of having everyone work in the office no longer made sense for everyone. Many organizations needed to quickly evolve to becoming a digital workplace.
During the worst of the pandemic, it is estimated that 70% of full-time workers were working from home. Even now that the pandemic has hit a new waning phase, remote work is still very much a reality. 92% of surveyed employees expect to still work from home at least 1 or more days per week.
This transformation has forced companies to rethink the tools and policies that they use. Many have also needed to completely revamp how they work. They needed to switch to a cloud-based digital workspace to enable a hybrid team.
This transition has brought newfound benefits such as:
- Lower costs for employees and employers
- Better employee work/life balance
- Higher morale
- The same or improved productivity
- More flexibility in serving clients
However, the transition to a digital workplace has also brought challenges and risks. These include:
- Vulnerable networks and endpoints
- Employees feeling disconnected
- Communication problems
- Difficulty tracking productivity and accountability
- Increased risk of data breaches
20% of organizations experienced a breach during the pandemic due to a remote worker.
Overcoming the challenges and reaping the benefits takes time and effort. It often takes the help of a trained IT professional to avoid costly mistakes.
Below are some of the biggest company mistakes when building a digital workplace. For the statistics, we referenced IGLOO’s State of the Digital Workplace report.
1. Poor Cloud File Organization
When companies go virtual for their workflows, files live in a cloud-accessible environment. If those cloud storage environments aren’t well organized, it becomes a problem. It can be difficult for employees to find the files that they need.
About 51% of employees have avoided sharing a document with a colleague for this reason. They either couldn’t find it or thought it would be too hard to find. It is notable that this is the highest percentage recorded for this stat in the IGLOO report. This means that the problem is getting worse.
Some tips for making shared cloud storage files easier to locate are:
- Keep file structure flat (2-3 folders deep)
- Create a consistent hierarchy and naming structure
- Don’t create a file for fewer than 10 documents
- Archive and delete older files monthly to reduce clutter
2. Leaving Remote Workers Out of the Conversation
No one likes to hear people start talking about something at a meeting and realize they're lost. They missed an important piece of an earlier conversation. Many companies haven’t yet overcome in-person vs remote communication challenges.
In fact, nearly 60% of remote workers say they miss out on important information. This is because colleagues first communicated it in person. Efficiency suffers when in-office workers make decisions without regard for remote colleagues.
Managers and bosses must lead the way in changing this culture. While old habits do take a while to change, mindset can transition to be more inclusive of the hybrid world.
3. Not Addressing Unauthorized Cloud App Use
Unauthorized cloud app use (also known as Shadow IT) was already a problem before the pandemic. That problem escalated once people began working from home because they are often using their personal devices.
Over half (57%) of employees use at least one unauthorized app in their workflow. When this happens, organizations can suffer in many ways.
Some of the risks of shadow IT include:
- Data leakage from non-secured apps
- Date privacy compliance violations
- Redundancies in app use that increase costs
- Unprotected company data due to a lack of visibility
- The employee leaves and no one can access the data in the unauthorized app
4. Not Realizing Remote Doesn’t Always Mean From Home
Remote employees aren’t always working from home and connected to their home Wi-Fi. They may also be working from airports, hotels, a family member’s home or local coffee shops.
Companies that don’t properly protect company data used by remote employees can be at risk of a breach. Public networks are notorious for enabling “man-in-the-middle” attacks. This is where a hacker connects to the same public network. They can then use software to access data transmissions from others on that network.
It is advisable to use a business VPN for all remote work situations. VPNs are fairly inexpensive and easy to use. The employee simply enables the app on their device. The app then reroutes their data through secure, encrypted servers.
5. Using Communication Tools That Frustrate Everyone
Are virtual meetings giving your team problems? As many as 85% of remote workers say that they have had 1-2 meetings interrupted by technology. It is getting so you can hardly have a virtual meeting without someone having a technical issue.
Communication is the oil that makes the engine of a digital workplace run. Effective cloud-based video calls, audio calls and chats depend on the right technology. This facilitates a smooth experience.
Don’t rush to use just any communication tools. Take your time and test them out. Get help optimizing settings to improve your virtual meetings. Additionally, ensure your remote team has tools to foster smooth communications. This includes headsets, VoIP desk sets, webcams, etc.
Boost the Productivity of Your Hybrid Office
Reach out today to schedule a technology consultation. We can help you improve the efficiency and productivity of your digital workplace.
Give us a call at (860) 577-8060 or contact us via our convenient contact form.

More employees are working remotely which means that the bring your own device (BYOD) trend has grown in popularity.
58.3% of surveyed employees said their use of personal devices for work increased during the COVID-19 pandemic.
BYOD programs can offer a number of benefits for businesses including increased productivity and flexibility. However, there are also security risks that come with BYOD programs.
In order to reduce these risks, businesses should take the following steps:
Define The Scope of The BYOD Program.
The first step in creating a secure BYOD program is to define the scope of the program.
- What devices will be allowed?
- What apps and data will employees be able to access?
By defining the scope of the program, businesses can set clear expectations for employees and reduce the risk of unauthorized access to company data.
Be sure to differentiate between devices that are for work and devices that are for personal use. Devices that are for work should be dedicated to work tasks and should not be used for personal tasks.
There should be a clear definition of what devices are allowed on the network in order to maintain BYOD programs. This will ensure that only approved devices are used and that will minimize security risks.
Develop Policies and Procedures for Employees.
Once the scope of the BYOD program has been determined, businesses should develop policies and procedures for employees.
These policies should cover topics such as:
- Device Security
- Data Security
- Acceptable Use
By having clear policies in place, businesses can ensure that employees are aware of their responsibilities and the risks involved with BYOD.
Employees should be made aware of any changes to the policies and they should also be given the opportunity to ask questions and provide feedback.
Educate Employees on Security Risks.
One of the most important steps in creating a secure BYOD program is educating employees on the security risks involved. Employees should be made aware of the risks of downloading malicious apps, accessing unsecured Wi-Fi networks and sharing company data.
By educating employees on the risks, businesses can help reduce the likelihood of a security breach.
When it comes to security, ignorance is not bliss.
Businesses should also provide employees with the necessary tools to help them secure their devices. This can include mobile device management (MDM) software, data encryption and antivirus protection. Employees should be trained on how to use these tools and how to keep their devices secure.
Implement Security Measures.
In order to further reduce the risk of a security breach, businesses should implement security measures such as:
- Mobile device management (MDM)
- MDM can help businesses control which apps are installed on employee devices and remotely wipe data if a device is lost or stolen.
- Data encryption
- Data encryption can help protect company data if a device is lost or stolen.
- Antivirus protection
- Antivirus protection can help protect devices from malware and other malicious software.
- Firewalls
- Firewalls can help protect devices from malicious traffic.
These are just a few of the many security measures businesses can take to reduce the risk of a security breach.
By implementing these measures, businesses can help keep their data and devices safe from harm.
Monitor the BYOD Program.
Businesses should monitor their BYOD program on an ongoing basis. They should keep track of which devices and apps are being used as well as any security breaches that occur. By monitoring the BYOD program, businesses can quickly identify and address any security risks.
Businesses can also ensure that employees are complying with BYOD policies. For example, you can track which devices are accessing corporate data and ensure that only authorized devices are being used.
By keeping track of which devices and apps are being used, businesses can quickly identify and address any security risks.
60 percent of endpoints are mobile devices and are woefully under-protected.
Review and Update the BYOD Program Regularly.
The BYOD program should be reviewed and updated on a regular basis. As new devices and apps become available, the program should be updated to reflect these changes. Businesses should also review the program if there are any changes in the company’s security posture.
Reviewing and updating the BYOD program is essential for businesses to keep their data secure. By keeping the program up-to-date, businesses can ensure that only authorized devices are being used to access corporate data.
Be Proactive with Help from Sound Computers.
These are just a few of the many steps businesses can take to create a secure BYOD program. By being proactive and taking the necessary steps, businesses can help reduce the risk of a security breach.
Breaches cost businesses time, money and resources. It is important to do everything you can to prevent them.
Do you have a BYOD program in place? What steps have you taken to ensure the security of your data?
No matter what size company you have, security is important. Contact us at (860) 577-8060 or via our contact form to learn more about our security solutions.
It seems you can’t read an article on cybersecurity without the word phishing coming up. That is because phishing is still the number one delivery vehicle for cyberattacks.
A cybercriminal may want to steal employee login credentials or wish to launch a ransomware attack for a payout. They may possibly plant spyware to steal sensitive info. Sending a phishing email can do them all.
80% of surveyed security professionals say that phishing campaigns have significantly increased post-pandemic.
Phishing continues to work and is also increasing in volume due to the move to remote teams. Many employees are now working from home. They don't have the same network protections they had when working at the office.
Why has phishing continued to work so well after all these years? Aren’t people finally learning what phishing looks like?
It's true that people are generally more aware of phishing emails and how to spot them than they were a decade ago. But it's also true that these emails are becoming harder to spot as scammers evolve their tactics.
One of the newest tactics is particularly hard to detect. It is the reply-chain phishing attack.
What is a Reply-Chain Phishing Attack?
Just about everyone is familiar with reply chains in email. An email is copied to one or more people. One person replies and that reply sits at the bottom of the new message. Then another person chimes in on the conversation by replying to the same email.
Soon you have a chain of email replies on a particular topic. It lists each reply one under the other so everyone can follow the conversation.
You don’t expect a phishing email tucked inside that ongoing email conversation. Most people are expecting phishing to come in as a new message rather than as a message included in an ongoing reply chain.
The reply-chain phishing attack is particularly insidious because it does exactly that. It inserts a convincing phishing email in the ongoing thread of an email reply chain.
How Does a Hacker Gain Access to the Reply Chain?
How does a hacker gain access to the reply chain conversation? By hacking the email account of one of those people copied on the email chain.
The hacker can email from an email address that the other recipients recognize and trust. They also gain the benefit of reading down through the chain of replies. This enables them to craft a response that looks like it fits.
For example, they may see that everyone has been weighing in on a new product idea for a product called Superbug. So, they send a reply that says, “I’ve drafted up some thoughts on the new Superbug product. Here is a link to see them.”
The link will go to a malicious phishing site. The site might infect a visitor’s system with malware or present a form to steal more login credentials.
The reply won’t seem like a phishing email at all. It will be convincing because:
- It comes from an email address of a colleague. This address has already been participating in the email conversation.
- It may sound natural and reference items in the discussion.
- It may use personalization. The email can call others by the names the hacker has seen in the reply chain.
Business Email Compromise is Increasing
Business email compromise (BEC) is so common that it now has its own acronym. Weak and unsecured passwords lead to email breaches. So do data breaches that reveal databases full of user logins. Both are contributors to how common BEC is becoming.
In 2021, 77% of organizations saw business email compromise attacks. This is up from 65% the year before.
Credential theft has become the main cause of data breaches globally. There is a pretty good chance of a compromise of one of your company’s email accounts at some point.
The reply-chain phishing attack is one of the ways that hackers turn that BEC into money. They either use it to plant ransomware or other malware or to steal sensitive data to sell on the Dark Web.
Tips for Addressing Reply-Chain Phishing
Here are some ways that you can lessen the risk of reply-chain phishing in your organization:
- Use a Business Password Manager:
This reduces the risk that employees will reuse passwords across many apps. It also keeps them from using weak passwords since they won’t need to remember them anymore.
- Put Multi-Factor Controls on Email Accounts:
Present a system challenge (question or required code). Using this for email logins from a strange IP address can stop account compromise.
- Teach Employees to be Aware:
Awareness is a big part of catching anything that might be slightly “off” in an email reply. Many attackers do make mistakes.
How Strong Are Your Email Account Protections?
Do you have enough protection in place on your business email accounts to prevent a breach? Let us know if you would like some help! We have email security solutions that can keep you better protected.
You can contact us at (860) 577-8060 or use our convenient contact form.

You know how it goes. We are working on our PC's at one moment and enjoying how things are going. The next moment there is a notification that pings. You need to allow the most recent updates. Without thinking, we hit the "remind me later" button. We say we are busy and there is so much to do today. We say we can always do it later. Read more
Few things invoke instant panic like missing a mobile device or laptop. These devices hold a good part of our lives. This includes files, personal financials, apps, passwords, pictures, and videos.
The information they hold is more personal than even that which is in your wallet. It's because of all your digital footprints. This makes a lost or stolen device a cause for alarm.
It is not the device that is usually the biggest concern. It is the data on the device and access the device has to cloud accounts and websites. The thought of that being in the hands of a criminal is quite scary.
There are approximately 70 million lost smartphones every year. The owners only recover about 7% of them. Workplace theft is all too common. The office is where 52% of stolen devices go missing.
If it is a work laptop or smartphone that goes missing, it is even worse. This can mean the company is subject to a data privacy violation. It could also suffer a ransomware attack originating from that stolen device.
In 2020, Lifespan Health System paid a $1,040,000 HIPAA fine. This was due to an unencrypted stolen laptop breach.
The Minutes After the Loss of Your Device Are Critical
The things you do in the minutes after missing a device are critical. This is the case whether it is a personal or business device. The faster you act means the less chance there is for exposure of sensitive data.
What Types of Information Does Your Device Hold?
When a criminal gets their hands on a smartphone, tablet or laptop, they have access to a treasure trove. This includes:
- Documents
- Photos & videos
- Access to any logged-in app accounts on the device
- Passwords stored in a browser
- Cloud storage access through a syncing account
- Emails
- Text messages
- Multi-factor authentication prompts that come via SMS
Steps to Take Immediately After Missing Your Device
As we mentioned, time is of the essence when it comes to a lost mobile device. The faster you act means the more risk you mitigate for a breach of personal or business information.
Here are steps you should take immediately after the device is missing.
Activate a “Lock My Device” Feature
Most mobile devices and laptops will include a “lock my device” feature. It allows for remote activation if you have enabled it. You will also need to enable “location services.” While good thieves may be able to crack a passcode, turning that on immediately can slow them down.
What about “find my device?”
There is usually also a “find my device” feature available in the same setting area. Only use this to try to locate your device if you feel it has been misplaced rather than stolen. You don’t want to end up face to face with criminals!
Report the Device Missing to Your Company If It is Used for Work
If you use the device for business, notify your company immediately. Even if all you do is get work email on a personal smartphone, it still counts. Many companies use an endpoint device manager. In this case, access to the company network can be immediately revoked.
Reporting your device missing immediately can allow your company to act fast. This can often mitigate the risk of a data breach.
Log Out & Revoke Access to SaaS Tools
Most mobile devices have persistent logins to SaaS tools. SaaS stands for Software as a Service. These are accounts like Microsoft 365, Trello, Salesforce, etc.
Use another device to log into your account through a web application. Then go to the authorized device area of your account settings. Locate the device that is missing and log it out of the service. Revoke access if it is an option.
This disconnects the device from your account so the thief can’t gain access.
Log Out & Revoke Access to Cloud Storage
It is very important to include cloud storage applications when you revoke access. Is your missing device syncing with a cloud storage platform? If so, the criminal can exploit that connection.
They could upload a malware file that infects the entire storage system. They could also reset your device to resell it and delete files from cloud storage.
Active a “Wipe My Device” Feature
Hopefully, you are backing up all your devices. This ensures that you have a copy of all your files in the case of a lost device.
Does it look like the device is not simply misplaced? Has it been stolen or lost for good? If so, then you should use a remote “wipe my device” feature if it has been set up. This will wipe the hard drive of data.
Need Mobile Device Security Solutions?
No matter what size company you have, mobile device management is vital. Contact us at (860) 577-8060 or via our contact form to learn more about our endpoint security solutions.

To capitalize on a future of work that is more flexible, Google is releasing improvements to its suite of productivity tools. Managing a business has never been simple. Companies have faced various difficulties in the last couple of years ranging from adjusting to a remote world to reduced innovation and teamwork. Read more

Productivity can be challenging to track regardless of where employees are working. How do you know they’re using their tools as effectively as possible? How can you enable them to adopt best practices?
These are questions that managers often ask themselves. If they’re looking at the wrong things, it can get in the way of empowering their team. For example, you can’t grade productivity simply by “clock in/clock out” times.
In today’s hybrid and mobile offices, the value and work product an employee brings is a better gauge. However, you also must look at what may be getting in the way of great employees doing great work.
Technology tools can slow down dedicated workers if they’re not familiar with them. Employees may be doing things the way that they always have done them and not realize that there is a better (and faster) way.
But productivity can be a tricky area to address. You don’t want to invade a remote employee’s privacy by tracking their every keystroke. That wouldn't boost morale either.
What is the answer?
If your company uses Microsoft 365, you have a tool that you can use to find nuggets of productivity gold. This tool is Microsoft Productivity Score.
What Does Microsoft Productivity Score Do?
Microsoft Productivity Score looks at some core areas of your employees’ workflow. It also looks at them in aggregate. Because it’s looking at your team as a whole, you avoid issues with employees feeling personally spied on.
The tool gives you helpful insights that you can share with your staff. These insights help to boost their performance. It also includes hardware-related information. You can use this to see if your company tools are holding people back.
MS Productivity Score looks at the following areas.
People Experiences
This category looks at how people work. Are they using best practices for collaboration or are they doing things the hard way? Do meetings go on forever? Are employees still emailing attachments instead of using shared cloud storage links?
One example of an insight from this category is as follows. Each employee can save an average of 100 minutes per week by collaborating with online files. Productivity Score can show you where your team stands in this metric and many others.
Saving 100 minutes per week is equal to approximately 86.6 hours per year. That is over 2 full weeks of work!

All Productivity Score images are from Microsoft.
The subcategories within people experiences are:
- Communication
- Content Collaboration
- Mobility
- Meetings
- Teamwork
Technology Experiences
Technology experiences look at the health and performance of your devices. Do you have hardware and software on endpoints that are causing issues? Is it slowing your team down? Are there network connectivity problems? Are apps updated as they should be?
This category will look at the technology that your team works with and let you know of any risk areas. When technology is not functioning well or isn’t secure, it can slow your business down.
You will find these three subcategories in the technology experiences area:
- Endpoint analytics (You need Intune for these)
- Network connectivity
- Microsoft 365 apps health
Special Reports
Besides the people and technology experiences, Microsoft Productivity Score has a special reports area. It provides details on business continuity.
This report can show you how employee collaboration and other activities are changing. It looks at these as your company goes through transitions (such as when you transition to remote working or back to in-office work). This report tells you how these changes impact your team’s productivity.

How Productivity Score Helps Your Company
Automatic Metrics Tracking
Microsoft Productivity Score tracks your team’s use of Microsoft 365 applications automatically. It then will provide you with helpful information on how staff use their digital tools.
These metrics give you a good picture of whether employees are using best practices. They may simply need guidance to learn a more efficient way of doing something.
Insights to Understand the Data
The tool provides you with helpful insights to understand the data. You won’t only get the metrics. You will get the context. This allows you to educate yourself. Then you can educate your employees on things that improve workflow and save time.
For example, getting a response quickly to a question saves time. You may not realize that using @mentions can help achieve that. Productivity Score will tell you how many people use @mentions in team communications and how much this increases the response rate.

Recommended Actions to Take
The third piece of guidance that you gain is what to do about the information. Productivity Score will give you actionable recommendations to improve a metric. This helps you to improve productivity.
The combination of the metric, insight and recommendation make this a comprehensive tool.
Would You Like to Get Started with Microsoft Productivity Score?
We can help you get your organization started with this great tool and provide solutions to increase company productivity. Give us a call at (860) 577-8060 or use our convenient contact form to get in touch.

Over the past two years, there has been a profound and significant impact on work experience. The expectations of employees concerning where, how and when they work has changed and continues to evolve. While these work evolutions affect all workforces, they have had a particular impact on sales professionals' expectations since they have needed to adjust to a more digital workplace while using outdated sales tools. As a result, Microsoft came up with a solution called Viva Sales. Read more
