8776363957
Connect with us:
LinkedIn link
Facebook link
Twitter link
YouTube link
Gigabit Systems logo
Link to home
Who We AreManaged ServicesCybersecurityOur ProcessContact UsPartners
The Latest News in IT and Cybersecurity

News

A cloud made of diagonal linesA cloud made of diagonal lines
A pattern of hexagons to resemble a network.
Cybersecurity
Science

An Astronaut Isn’t Wearing a Suit. They’re Wearing a Spacecraft.

September 6, 2026
•
20 min read

An Astronaut Isn’t Wearing a Suit. They’re Wearing a Spacecraft.

Between a human body and death are layers of fabric.

Look at an astronaut floating outside the International Space Station and your brain sees clothing.

Very complicated clothing.

But clothing nonetheless.

That’s completely wrong.

NASA describes a fully equipped spacesuit as essentially a one-person spacecraft.

And once you understand what is actually happening inside that white suit, it’s easy to understand why.

Outside is a vacuum.

There is no breathable atmosphere.

There is no atmospheric pressure keeping the human body functioning normally.

Temperatures during a spacewalk can range from approximately -250°F to +250°F depending on exposure to sunlight. Tiny pieces of debris can be moving many times faster than a bullet.

And inside all of that:

A human being has to stay alive.

Breathe.

Remain pressurized.

Control body temperature.

Move.

See.

Communicate.

Drink.

Operate tools.

And perform extremely complicated work.

So engineers effectively wrapped a tiny spacecraft around the astronaut.

Start With the Human

The first problem is surprisingly ordinary.

Astronauts get hot.

Space may be cold in the popular imagination, but an astronaut doing strenuous physical work inside a sealed pressure suit produces metabolic heat.

Sweat isn’t going to solve that problem normally.

So underneath the pressure suit, astronauts wear the Liquid Cooling and Ventilation Garment, or LCVG.

It looks somewhat like long underwear.

Except woven through it is a network of small tubes carrying water around the astronaut’s body.

NASA explains that the garment covers most of the body, excluding the head, hands and feet, and circulating water removes excess heat during the spacewalk.

You’re essentially wearing your cooling system.

And that’s only the beginning.

Then You Need to Bring an Atmosphere With You

Your body evolved to operate inside Earth’s atmosphere.

Take that atmosphere away and you have a serious problem.

So the suit has to create one.

The pressure bladder contains the gas inside the suit and maintains the pressure necessary around the astronaut’s body.

NASA engineers have a wonderfully simple analogy for it:

Think of a balloon.

The bladder wants to expand when pressurized.

Which immediately creates another engineering problem.

You don’t want your astronaut walking around inside a human-shaped balloon.

So Another Layer Has to Hold the Balloon Together

Outside the bladder is a restraint layer.

Its job is structural.

The bladder contains the gas.

The restraint layer contains the bladder.

NASA describes this as an extremely strong fabric structure that prevents the pressurized bladder from expanding uncontrollably and maintains the suit’s shape.

That’s an important distinction.

One layer doesn’t have to solve everything.

One component creates the pressure environment.

Another component handles the structural forces created by that pressure.

The system survives because the jobs are separated.

Then There’s Space Trying to Destroy Everything

Now that we’ve created a pressurized environment around our astronaut, we have to protect it.

NASA’s EMU includes a Thermal Micrometeoroid Garment, or TMG.

Its job is right there in the name.

Thermal protection.

Micrometeoroid protection.

NASA technical documentation describes multiple insulation layers, including aluminized Mylar, along with an outer protective fabric designed for abrasion and flame resistance.

So now we’re building outward.

Human.

Cooling.

Pressure.

Structural restraint.

Thermal protection.

Impact protection.

Outer protection.

Layer after layer.

Because Space Doesn’t Need a Big Hole

When we think about something threatening an astronaut, we imagine a dramatic collision.

That’s not necessarily the danger.

NASA specifically designs suits to protect against tiny particles traveling at tremendous velocity.

Something doesn’t have to be large when it’s moving incredibly fast.

NASA describes space dust as potentially moving many times faster than a bullet.

And there is another uncomfortable fact:

The astronaut is surrounded by vacuum.

A tiny failure matters.

The integrity of the pressure system matters continuously for the entire spacewalk.

The White Exterior Isn’t a Fashion Decision Either

Even the iconic appearance of a spacesuit is functional.

NASA explains that the white outer layer helps reflect heat from sunlight.

The outer fabric itself combines materials selected for different properties, including water resistance, strength and fire resistance.

Virtually everything you’re looking at exists for a reason.

Then Put a Backpack on the Spacecraft

The layers themselves aren’t enough.

Look at the enormous backpack on an astronaut’s back.

That’s the Primary Life Support Subsystem.

It carries oxygen.

It removes the carbon dioxide the astronaut exhales.

It supplies electricity.

A fan circulates oxygen through the suit.

A water tank supports the cooling system.

Think about what that means.

The astronaut isn’t connected to some giant building HVAC system.

They’re carrying the mechanical systems keeping them alive.

Air supply.

CO₂ removal.

Cooling.

Power.

Ventilation.

All on their back.

That’s not a jacket.

That’s infrastructure.

And There’s Even a Tiny Emergency Spacecraft Attached to the Spacecraft

There is one more fascinating component.

Attached to the EMU is something called SAFER:

Simplified Aid for EVA Rescue.

It contains small thrusters.

If an astronaut became untethered and began floating away from the station, SAFER provides a means of maneuvering back.

So an astronaut on a spacewalk is wearing a personal spacecraft…

with a tiny emergency propulsion system attached to it.

And Somehow the Astronaut Still Has to Work

This may be the most impressive engineering challenge.

Keeping a person alive inside a rigid protective container would be relatively useless.

Astronauts need to:

Bend their arms.

Move their fingers.

Turn.

Grab handrails.

Manipulate tools.

Connect equipment.

Perform repairs.

And sometimes spend hours doing it.

Pressure makes all of this harder.

Imagine trying to bend an inflated balloon.

The suit is constantly resisting movement.

So spacesuit engineering isn’t simply:

How do we keep someone alive in space?

It’s:

How do we keep someone alive in space while allowing them to remain useful?

Those are very different problems.

It’s a Perfect Example of Layered Security

And this is where spacesuit engineering becomes a beautiful cybersecurity analogy.

There isn’t one magical layer protecting the astronaut.

Cooling doesn’t provide pressure.

Pressure doesn’t stop micrometeoroids.

Micrometeoroid protection doesn’t remove carbon dioxide.

The outer garment doesn’t supply oxygen.

The oxygen system doesn’t provide emergency propulsion.

Each system assumes other systems exist around it.

Survival comes from layers.

Cybersecurity works exactly the same way.

A firewall isn’t cybersecurity.

MFA isn’t cybersecurity.

Endpoint protection isn’t cybersecurity.

Backups aren’t cybersecurity.

Employee training isn’t cybersecurity.

Email filtering isn’t cybersecurity.

Monitoring isn’t cybersecurity.

Incident response isn’t cybersecurity.

They’re layers.

Each Layer Is Designed for a Different Failure

That’s the important part.

Your firewall may stop one attack.

MFA may stop the stolen password that gets through.

Endpoint security may detect malicious code that reaches the computer.

Application controls may prevent it from executing.

Network segmentation may limit where it can travel.

Monitoring may detect abnormal behavior.

Immutable backups may help you recover.

Incident response determines what happens when everything before it wasn’t enough.

No individual layer has to be perfect.

The architecture has to survive imperfection.

That’s exactly what makes layered engineering so powerful.

Good Engineering Assumes Something Will Eventually Go Wrong

This is a principle that appears everywhere.

Aviation.

Nuclear power.

Medicine.

Spaceflight.

Cybersecurity.

Critical infrastructure.

You don’t design around the assumption that every component will behave perfectly forever.

You ask:

What happens when this component fails?

What’s behind it?

Can another system contain the failure?

Will we detect it?

Can the system continue operating?

Can the human survive?

That’s resilience.

The Spacesuit Makes the Concept Visible

NASA says flexible portions of the ISS EMU can contain as many as 16 layers of material.

Not because NASA engineers enjoy adding complexity.

Because space presents multiple problems.

Pressure.

Temperature.

Abrasion.

Micrometeoroids.

Mobility.

Heat generated by the astronaut.

Oxygen.

Carbon dioxide.

Communication.

Visibility.

Radiation.

Every threat requires a response.

And often that response requires another layer.

Your Business Should Look More Like a Spacesuit

Not literally.

But architecturally.

Ask yourself:

If this control fails, what happens next?

If an employee gives away their password, does MFA stop the attacker?

If MFA is bypassed, does Conditional Access notice something unusual?

If a computer becomes compromised, can it freely reach everything else?

If ransomware reaches a server, can it destroy the backups?

If someone compromises Microsoft 365, will anybody notice?

If your security provider misses an alert, does another control catch the behavior?

If the internet disappears, can the company function?

If your primary server fails, what happens Monday morning?

That’s defense in depth.

The Goal Isn’t an Impenetrable Layer

Because it probably doesn’t exist.

The goal is making sure failure of one layer doesn’t automatically become failure of the entire system.

That’s why the spacesuit is such a good engineering lesson.

If all NASA needed was one miraculous fabric that could simultaneously manage pressure, temperature, abrasion, impacts, mobility and life support, spacesuit engineering would be much simpler.

Instead, engineers divided the problem.

Different materials.

Different systems.

Different responsibilities.

All working together.

And All of It Sits Between a Human Being and Nothing

That’s what makes the spacesuit so extraordinary.

Take away the white exterior and you’re looking at an incredibly sophisticated combination of:

Materials science.

Mechanical engineering.

Thermal engineering.

Fluid systems.

Electrical engineering.

Life-support engineering.

Human factors.

Communications.

Safety engineering.

Redundancy.

All compressed into something a person can wear.

NASA has been developing and refining this technology for more than half a century, and current spacesuit development continues to build on those lessons.

So the next time you see an astronaut floating outside a spacecraft, don’t think:

That’s an incredible suit.

Think:

That’s a human being who brought a tiny piece of Earth with them.

Pressure.

Oxygen.

Temperature control.

Water.

Protection.

Communication.

Mobility.

All engineered into a personal environment separating a living person from the vacuum of space.

NASA’s description really is the best one:

They’re not wearing clothes.

They’re wearing a spacecraft.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #SpaceTechnology #Engineering #Technology #ManagedIT


An astronaut’s spacesuit can have up to 16 layers between their body and the vacuum of space. It’s not clothing. It’s a spacecraft you wear.

AI
Technology

One education system sees a danger. Another sees a necessary skill.

September 2, 2026
•
20 min read

New York Is Banning AI for 600,000 Students. China Is Teaching It.

One education system sees a danger. Another sees a necessary skill.

New York City is about to make one of the biggest educational technology decisions in America.

Beginning this school year, nearly 600,000 public-school students from preschool through eighth grade will largely be prohibited from using student-facing generative AI in school.

No ChatGPT writing the essay.

No AI tutor answering the homework question.

No chatbot helping a seventh grader work through an assignment.

The restrictions cover roughly two-thirds of the nation’s largest public-school system.

And I understand why.

I’ve written recently about the MIT experiment that found substantially different cognitive engagement when people used an LLM to write essays compared with people who performed the work themselves.

Children need to learn to:

Read.

Write.

Calculate.

Remember.

Struggle.

Analyze.

Form arguments.

Solve problems.

Think.

We absolutely should not hand a seven-year-old ChatGPT and allow it to do those things for them.

But there’s another side to this decision that bothers me.

AI isn’t going away.

And while New York is restricting children from using it, China is deliberately teaching children how it works.

China Chose Almost the Opposite Approach

In 2024, China’s Ministry of Education issued guidance calling for AI education to become a regular component of primary and secondary education.

And Beijing subsequently established a particularly concrete requirement.

Beginning with the 2025 fall semester, schools across Beijing were instructed to provide at least eight class hours of AI education every school year, covering students from primary school through high school.

But here’s what’s particularly interesting.

They aren’t teaching every age the same way.

For younger primary-school students, the emphasis is awareness and exposure.

As children get older, the curriculum progresses toward understanding and using AI.

By high school, students move toward practical applications, projects and innovation.

And the curriculum explicitly incorporates AI ethics and responsible use.

That’s very different from:

Here’s ChatGPT. Have fun.

It’s education.

And that distinction matters enormously.

Maybe We’re Asking the Wrong Question

The debate in America often becomes:

Should children use AI?

I don’t think that’s the right question anymore.

The question should be:

What should a child understand about AI at each age, and when should they be permitted to use it?

Those aren’t the same thing.

A six-year-old probably shouldn’t be asking an LLM to write a book report.

But should a six-year-old begin understanding that computers can generate information and that information isn’t necessarily true?

Absolutely.

Should a ten-year-old understand that AI can fabricate convincing answers?

Yes.

Should a twelve-year-old understand prompts, hallucinations, bias, privacy and why you shouldn’t paste personal information into an AI system?

I think so.

Should an eighth grader understand how to use AI to challenge an argument without having AI create the argument for them?

I’d argue that’s becoming basic digital literacy.

We Made This Mistake With Technology Before

For years, schools treated technology as something separate from education.

Then suddenly every profession required computers.

We had to teach computer literacy.

Then the internet arrived.

Schools initially worried about students using the internet.

Understandably.

The internet contained misinformation.

Pornography.

Predators.

Distractions.

Plagiarism.

Viruses.

Scams.

So we built filters.

Created acceptable-use policies.

Taught internet safety.

Developed digital literacy.

And eventually recognized something obvious:

Protecting children from the internet could not mean raising children who didn’t understand the internet.

AI presents the same problem on a much larger scale.

The MIT Study Actually Strengthens the Argument for Teaching AI

At first glance, the recent MIT research seems like a great argument for New York’s approach.

Researchers had participants write essays using an LLM, a search engine, or no technological assistance while measuring their brain activity with EEG.

The people who performed the task without technological assistance showed the strongest neural connectivity.

LLM users showed the weakest.

They also had more difficulty recalling their own work.

That’s concerning.

But one of the experiment’s most interesting findings came when researchers changed the conditions.

Participants who first performed the intellectual work themselves and later gained access to AI showed stronger engagement and recall than those who began by outsourcing the task to an LLM.

The lesson may not be:

Don’t use AI.

It may be:

Learn to think before you learn to outsource thinking.

And that’s precisely why schools need an AI curriculum.

Teach the Brain First. Then Give It the Machine.

This is the educational model I’d rather see.

A student gets a question:

What caused the American Revolution?

Before touching AI:

What do you remember?

Write your argument.

Identify the evidence.

Organize your thoughts.

Explain your reasoning.

Then AI becomes available.

Now ask:

Challenge my argument.

What important factor did I overlook?

Give me an opposing interpretation.

Which of my claims requires stronger evidence?

Don’t rewrite this. Tell me where my reasoning is weak.

Suddenly AI isn’t doing the student’s thinking.

It’s forcing the student to think harder.

That’s an extraordinary educational tool.

But students have to be taught to use it that way.

Because They’re Going to Use AI Anyway

This is the practical problem with prohibition.

A seventh grader leaves school.

Pulls out an iPhone.

Opens ChatGPT.

Or Gemini.

Or another AI application.

Or uses AI embedded inside software that doesn’t even look like an AI chatbot.

The school hasn’t eliminated AI.

It has simply moved AI use outside the environment where a teacher can teach the student how to use it properly.

That’s what concerns me.

Banning a technology isn’t the same as teaching someone to resist its weaknesses.

Imagine Schools Had Banned Google Until High School

There’s a legitimate argument that Google made certain kinds of learning easier.

Why memorize something when you can search it?

Why know where something is when Google Maps can navigate?

Why remember a phone number when your phone remembers?

Technology absolutely causes cognitive offloading.

But imagine responding by telling children:

You may not use a search engine until ninth grade.

That would protect some traditional skills.

It would also produce eighth graders who had never been systematically taught:

How to search.

How to evaluate sources.

How to distinguish an advertisement from information.

How to identify misinformation.

How to compare conflicting sources.

How to recognize a fraudulent website.

Those became essential literacy skills.

AI literacy is heading in the same direction.

The Future Employee Won’t Be Asked Whether They Know AI

Think about the students entering kindergarten today.

They graduate high school around 2039.

What does the workplace look like then?

I don’t know.

Nobody does.

But I would make one fairly safe prediction:

Artificial intelligence will not be less important.

Medicine will use AI.

Law will use AI.

Accounting will use AI.

Engineering will use AI.

Cybersecurity will use AI.

Software development will use AI.

Finance will use AI.

Marketing will use AI.

Manufacturing will use AI.

Education itself will use AI.

We’re preparing children for a labor market we cannot fully imagine.

Teaching them nothing about one of its foundational technologies until high school seems like a strange solution.

China Understands This as a Competition

This is the part Americans should pay attention to.

China’s Ministry of Education didn’t frame AI literacy merely as a convenient classroom tool.

Its guidance says the objective includes cultivating innovative talent capable of confronting future challenges, developing thinking and problem-solving abilities, and improving digital literacy.

Beijing’s curriculum goes from basic understanding toward reasonable use and eventually innovative application.

And this isn’t some tiny experimental program.

By the end of 2025, Beijing reported AI applications had reached 87.7% of its schools.

There is an obvious strategic component here.

The countries that dominate AI won’t merely be the countries with the largest models.

They’ll need:

Researchers.

Engineers.

Entrepreneurs.

Scientists.

Cybersecurity professionals.

Doctors.

Teachers.

Lawyers.

And millions of ordinary workers who understand how to collaborate effectively with intelligent machines.

That’s workforce development.

But New York Isn’t Crazy

There’s another side to this.

And it’s important.

New York City isn’t saying:

AI doesn’t matter.

In fact, NYC Public Schools’ own guidance explicitly acknowledges that AI is already shaping careers and industries and says students need to learn how to use it responsibly.

The school system is worried about something legitimate.

Young children are still developing foundational cognitive abilities.

If AI supplies the paragraph before a child learns to construct one, that’s a problem.

If AI solves the math problem before the child develops number sense, that’s a problem.

If AI summarizes the book instead of the child reading it, that’s a problem.

If AI answers every difficult question before the student experiences the frustration of figuring something out:

That’s a problem too.

Learning isn’t merely acquiring the correct answer.

The process of getting there matters.

So I Agree With Half of New York’s Idea

Protect foundational learning.

Absolutely.

There should be assignments where AI is completely prohibited.

There should be classrooms where screens disappear.

Children should write by hand.

They should memorize things.

They should read entire books.

They should calculate.

They should debate.

They should sit with a difficult problem without immediately asking a machine for the answer.

They should learn what their own brain can do before delegating everything to one in the cloud.

But that does not require pretending AI doesn’t exist until ninth grade.

Teach AI Without Letting AI Do the Work

Imagine an elementary-school AI curriculum where students don’t even need unrestricted access to an LLM.

A teacher shows an AI-generated picture.

What’s wrong with it?

A chatbot provides three facts.

Which one did it invent?

The class compares a human-written paragraph with an AI-generated one.

Which is better?

Why?

Students learn:

AI can sound confident and be wrong.

AI doesn’t “know” something simply because it says it.

Don’t give AI private information.

AI can reproduce bias.

AI-generated pictures and videos can be fake.

People can use AI to impersonate others.

Verify important information.

That’s AI education.

And frankly, children may need those lessons before high school.

By Middle School, I’d Go Further

Teach prompting.

But not:

Write my homework.

Teach:

Explain this concept three different ways.

Quiz me without giving me the answer.

Challenge my reasoning.

Give me hints one at a time.

Help me understand why my answer is wrong.

Ask me questions until I can explain this myself.

That’s the difference between using AI as an answer machine and using AI as a learning machine.

One can weaken the educational process.

The other could potentially make personalized tutoring available to almost every child.

That possibility is too important to dismiss.

AI Literacy Should Include Knowing When NOT to Use AI

This may be the most important lesson of all.

Real AI literacy isn’t knowing how to prompt ChatGPT.

It’s knowing:

When AI is useful.

When it isn’t.

When to trust it.

When to verify it.

What information never belongs in it.

When using it would defeat the purpose of an assignment.

When you need to struggle yourself.

When AI should challenge your thinking.

And when you should close the laptop and think.

That is a sophisticated skill.

It requires education.

This Is Also a Cybersecurity Issue

Children are growing up in a world of AI-generated:

Voices.

Photos.

Videos.

Messages.

Websites.

Emails.

Scams.

Impersonation.

Misinformation.

Eventually they will receive a phone call that sounds exactly like their mother.

A video that looks real.

A message supposedly written by their boss.

A website generated specifically to manipulate them.

AI literacy isn’t merely career preparation anymore.

It’s becoming a cybersecurity skill.

Teaching children how generative AI works may ultimately be as important to digital safety as teaching them not to share their passwords.

America’s Students Shouldn’t Become AI Consumers

This is the strategic risk I see.

If one education system teaches children:

Understand this technology. Experiment with it. Learn its limitations. Eventually build with it.

And another teaches:

Stay away from it until you’re older.

Which group is more likely to become creators?

Which becomes consumers?

Which develops intuition earlier?

Which is more comfortable experimenting?

Which is more likely to build the next generation of technology?

Obviously, eight hours of AI instruction in Beijing doesn’t guarantee China wins the AI race.

And banning student-facing generative AI through eighth grade doesn’t doom New York students.

But the philosophies are worth comparing.

Because they’re radically different responses to the same technological revolution.

We Don’t Protect Children by Preparing Them for Yesterday

New York is right about the danger.

AI can short-circuit learning.

It can make cheating effortless.

It can replace productive struggle.

It can hallucinate.

It can expose children’s information.

And used badly, it can allow a student to produce impressive work while learning almost nothing.

Those are real problems.

But AI will also be one of the defining technologies of these children’s lives.

So the answer cannot ultimately be:

Keep it away from them.

It has to become:

Teach them to control it before it controls how they think.

Protect foundational skills.

Restrict AI where the learning requires independent thought.

Delay unrestricted use for younger children.

But simultaneously teach AI literacy from an early age.

Teach what it does.

Teach what it cannot do.

Teach how it manipulates.

Teach how it fails.

Teach how to verify it.

Teach privacy.

Teach ethics.

Teach prompting.

Teach deepfakes.

Teach students to create with it.

And above all:

Teach them that the machine should amplify their intelligence—not replace it.

China appears to understand that AI literacy is part of preparing children for the future.

New York understands that children’s brains need protection while they’re developing.

The smartest education system will figure out how to do both.

70% of all cyber attacks target small businesses, I can help protect yours.

#ArtificialIntelligence #Education #Cybersecurity #AILiteracy #FutureOfWork


New York is banning AI for nearly 600,000 students through 8th grade. Beijing requires children to learn it. One of them may be making a very expensive mistake.

what technology should today’s schools prepare this child to understand?

Cybersecurity
Technology

Florida is axing Flock - the cameras that track your car and invade your privacy.

•
20 min read

Florida Is Taking Down the Cameras Watching Your Car

The surveillance network grew faster than the rules governing it.

Remember those little solar-powered cameras we’ve been talking about?

They’re mounted on poles.

They don’t look particularly intimidating.

You drive past one.

It photographs your vehicle.

Reads your license plate.

Records identifying characteristics.

Stores the information.

And depending on policies and permissions, law enforcement can search that information later.

They’re automated license plate readers, commonly associated with Flock Safety⁠.

We’ve written about them before because Flock has quietly built an enormous network across America.

Now Florida has decided:

Enough.

On August 31, the Florida Department of Transportation revoked permits for automated license-plate readers installed within rights-of-way on Florida’s State Highway System.

Local agencies have 30 days to remove them.

If they don’t?

FDOT says the state can remove the cameras itself.

And new applications to install them there will no longer be approved.

Read Florida’s Explanation Carefully

This wasn’t framed as a budget decision.

FDOT specifically cited the:

“exponential increase in deployments”

along with reports of misuse, data-privacy concerns and what the department called “surveillance schemes.”

The agency said immediate action was warranted to protect Floridians’ sovereignty and quality of life.

That’s unusually strong language for a transportation department talking about cameras.

And it gets directly to the problem we’ve been discussing.

The technology isn’t necessarily the frightening part.

Scale is.

One Camera Isn’t Particularly Interesting

Imagine police are investigating a kidnapping.

They know the suspect’s license plate.

A camera spots the vehicle.

Police get an alert.

They find the victim.

That’s an extraordinarily compelling use of technology.

And Florida law-enforcement agencies have cited real examples where these systems assisted in locating missing people, murder suspects and human-trafficking victims.

That’s why this debate isn’t as simple as:

Camera bad. Privacy good.

These systems can provide legitimate investigative value.

But now imagine the camera isn’t alone.

There are ten.

Then 100.

Then 10,000.

Then tens of thousands spread across the country.

Suddenly you’ve built something fundamentally different.

A Network of Cameras Can Become a Movement Database

One camera tells you:

Your car was here.

A network potentially tells you:

Your car was here Monday morning.

Here Monday afternoon.

Here Tuesday night.

Here Wednesday morning.

Here Saturday.

And here again Sunday.

Now search backward.

Instead of asking:

“Where is this suspect right now?”

you can potentially ask:

“Where has this vehicle been?”

That’s a completely different capability.

The technology crosses an invisible line.

License-plate recognition becomes location intelligence.

Flock Has Become Enormous

Recent reporting puts Flock’s network at more than 120,000 cameras nationwide.

That’s what makes the discussion so important.

No single police department necessarily sat down one morning and said:

Let’s build a nationwide vehicle-surveillance network.

One town buys cameras.

Another county buys cameras.

A sheriff’s department installs some.

Another city joins.

More agencies gain access.

More cameras appear.

Data becomes searchable.

Systems become interconnected.

Eventually you look up and discover:

The infrastructure exists.

The policy debate comes afterward.

That’s backwards.

And We’ve Already Seen What Happens When Someone Abuses It

Days before Florida’s announcement, Wired reported an extraordinary example from Georgia.

An Alpharetta police officer allegedly used Flock searches repeatedly to track vehicles associated with his former romantic partner and another officer.

According to the internal investigation reported by Wired, he searched his former partner’s vehicle 56 times and the other officer’s vehicle 29 times.

Search justifications reportedly included things such as “Wanted Person” and “Traffic Infraction,” despite investigators finding no legitimate law-enforcement basis for the searches.

The officer resigned, and a criminal investigation is ongoing.

Think about what that demonstrates.

You can have:

Authorized users.

Passwords.

Logging.

Policies.

Training.

Search justifications.

Auditing.

And someone with legitimate access can still potentially misuse the system.

Cybersecurity professionals have a name for that problem:

Insider threat.

The Database Doesn’t Know Why You’re Looking

This is something every business should understand.

Technology can authenticate:

Who are you?

It can authorize:

Are you allowed to search?

But determining:

Should you be searching for this person for this reason?

is considerably harder.

That’s true whether we’re talking about:

Police databases.

Medical records.

Employee files.

Customer information.

Banking systems.

Security cameras.

Microsoft 365.

An administrator can have completely legitimate access to a system and still use that access illegitimately.

That’s why cybersecurity requires more than passwords.

It requires:

Accountability.

This Is Why Logging Matters

Imagine that officer’s searches weren’t logged.

How would anyone know?

That’s the difference between:

Access control

and

auditable access control.

Sensitive systems should record who accessed information, what they searched for, when they accessed it and—where appropriate—why.

But collecting logs isn’t enough.

Somebody has to review them.

That’s where organizations frequently fail.

They log everything.

Then nobody looks unless something goes wrong.

Good security asks another question:

What behavior should trigger an investigation automatically?

An employee repeatedly searching one person’s records?

An administrator accessing hundreds of mailboxes?

Someone downloading 50,000 customer records?

A user accessing systems at unusual times?

An account suddenly searching information unrelated to its normal job?

Logs tell you what happened.

Behavioral monitoring can tell you something strange is happening while it’s happening.

There’s Another Problem: False Matches

License-plate readers aren’t infallible.

A dirty plate.

An obscured character.

Bad lighting.

Similar characters.

Different jurisdictions.

Camera angle.

Software interpretation.

All can matter.

Recent reporting has highlighted cases in which erroneous plate reads contributed to wrongful police stops and arrests, adding another dimension to the backlash surrounding automated license-plate readers.

A computer producing an answer doesn’t make that answer true.

That’s an increasingly important lesson as artificial intelligence enters policing, healthcare, cybersecurity, hiring and financial decisions.

Automation increases speed. It doesn’t eliminate error.

Florida Isn’t Alone

The backlash is becoming national.

Tempe, Arizona has ended its relationship with Flock.

Austin allowed its agreement to expire.

Other municipalities have reconsidered or terminated deployments.

And last week, U.S. Senator Josh Hawley opened a Senate investigation into Flock, asking the company for information about data collection, retention, camera locations and law-enforcement access.

This isn’t fitting neatly into traditional partisan politics either.

Privacy concerns surrounding mass surveillance have increasingly attracted people from both the political left and right.

Different motivations.

Same question:

Who gets to know where I go?

Florida’s Decision Is Already Spreading Locally

Here’s where today’s announcement gets particularly interesting.

Florida didn’t order every local Flock camera removed.

FDOT’s authority here concerns cameras within state highway rights-of-way.

But local agencies immediately began making their own decisions.

Putnam County Sheriff H.D. DeLoach announced that his department would discontinue its Flock program entirely and remove its 18 cameras, citing concerns surrounding privacy, data sharing, governmental oversight and future regulation.

Other Florida sheriff’s departments have also announced changes following the state’s action.

So Florida’s state-highway decision may produce something considerably larger:

A chain reaction.

This Isn’t Really a Story About Cameras

It’s a story about databases.

The camera gets everyone’s attention because you can physically see it.

But the important questions happen after the photograph is taken.

What information was collected?

How long is it retained?

Where is it stored?

Who can search it?

Which other agencies can access it?

Can searches cross jurisdictions?

What constitutes a legitimate search?

Who audits those searches?

Can an employee misuse it?

Can someone export the information?

What happens if credentials are stolen?

Can the database be breached?

Can historical movement be reconstructed?

Those are fundamentally:

Data governance questions.

And businesses have exactly the same problem.

Your Company Probably Collects Too Much Too

Every organization accumulates data because storage is cheap.

Email forever.

Customer records forever.

Security footage forever.

Employee records forever.

Logs forever.

Backups forever.

Cloud files forever.

Nobody wants to delete anything because:

“We might need it someday.”

Then you get breached.

And suddenly ten years of information becomes ten years of liability.

There’s an uncomfortable cybersecurity truth:

Data you don’t have can’t be stolen.

Retention should be intentional.

Ask Why You’re Collecting It

Every organization should be able to answer four questions about sensitive information:

Why are we collecting this? How long do we need it? Who can access it? Who checks whether that access is being abused?

If nobody knows the answers, you don’t have a data-retention strategy.

You have a data collection habit.

Healthcare organizations should ask this about patient information.

Law firms about client files.

Schools about student records.

SMBs about customer and employee information.

And governments should ask exactly the same questions about surveillance data.

The Flock Debate Is Really About Power

Flock cameras can help solve crimes.

That’s real.

They can help locate stolen vehicles and missing people.

That’s real too.

But technology doesn’t have to be useless to be dangerous.

The most consequential technologies are often extremely useful.

That’s precisely why they spread.

The question isn’t:

“Can this technology do good?”

Of course it can.

The better question is:

“What happens when this technology is everywhere?”

Because capabilities change when systems reach scale.

One camera helps investigate a crime.

Thousands of interconnected cameras can potentially reconstruct movement.

One administrator can maintain a system.

Thousands of administrators with poorly governed access create an insider-risk problem.

One database solves a problem.

Enough interconnected databases can create something nobody explicitly decided to build.

We’ve Seen This Pattern Before

Technology arrives.

It’s useful.

Deployment accelerates.

Everybody celebrates the benefits.

Governance comes later.

Then somebody discovers an abuse case.

Or a breach.

Or an unintended capability.

And society finally asks:

Wait. What exactly did we build?

We did it with social media.

We’re doing it with artificial intelligence.

We’re doing it with biometrics.

We’re doing it with facial recognition.

And we’re doing it with automated license-plate readers.

The lesson isn’t:

Stop building technology.

It’s:

Build the rules before the infrastructure becomes impossible to unwind.

Florida Just Did Something Unusual

Governments usually respond to technology problems by announcing:

A study.

A committee.

A task force.

New guidelines.

Florida did something much simpler.

Take the cameras down.

Not everywhere.

Not permanently necessarily.

And not because license-plate recognition has no legitimate use.

But because, according to FDOT, deployments had increased exponentially while concerns about misuse, privacy and surveillance were mounting.

That’s what makes this moment significant.

The question surrounding Flock is shifting from:

“Should we install these cameras?”

to:

“Did we install too many before deciding what the rules should be?”

And Florida has just given its answer for state highways.

Yes.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #DataPrivacy #Surveillance #DataProtection #IoTSecurity


Florida just ordered Flock cameras off its state highways. The question isn’t whether they catch criminals—it’s what else we built along the way?

Technology
Cybersecurity
Science

Children and teenagers need better protection from social-media companies.

September 1, 2026
•
20 min read

Protect Kids From Social Media. But Don’t Build a Surveillance System to Do It.

Protecting children shouldn’t require identifying everybody else.

Children and teenagers need better protection from social-media companies.

I don’t think that’s particularly controversial anymore.

The more difficult question is:

What are we willing to build in order to protect them?

Because buried inside Meta’s enormous child-safety settlement is something potentially much bigger than screen-time limits.

Age assurance.

Meta has agreed to implement stronger systems for determining whether Facebook and Instagram users are actually the ages they claim to be.

That sounds reasonable.

Until you think about the technical problem.

How does Instagram know you’re 16?

More importantly:

How does Instagram know you’re 46?

Meta Just Settled One of the Biggest Cases in Tech History

Meta agreed to pay states up to approximately $17.1 billion over ten years to resolve litigation accusing Facebook and Instagram of harming children through addictive product design and improperly collecting children’s information.

Meta denies wrongdoing.

The settlement includes significant changes for younger users.

Among them are a combined two-hour daily Facebook and Instagram limit, mandatory interruptions during extended usage, overnight restrictions, reduced school-hour notifications, stronger parental controls, age-appropriate content protections and new age-assurance measures.

Those are significant changes.

But there’s another part of this story receiving much less attention.

Meta Is Now Advertising for Its Competitors to Join It

Shortly after settling, Meta began publicly calling on TikTok and YouTube to adopt comparable protections.

Meta's public announcement⁠

Meta’s message is essentially:

We did it. Now you should too.

That sounds admirable.

Except Meta also has billions of dollars riding on whether its competitors agree.

Follow the $5.3 Billion

Meta’s settlement is structured unusually.

Approximately 70%—around $12.7 billion—is scheduled to be paid over the ten-year period.

The remaining approximately:

$5.3 billion

is conditional.

According to Meta itself, those funds are released only if TikTok and YouTube both implement specified protections—including age assurance, Night Mode and a one-hour daily limit—and make matching payments.

In other words:

Meta has a multibillion-dollar financial interest in its competitors adopting similar rules.

That doesn’t make those rules bad.

But it’s important context when Meta purchases advertisements encouraging the rest of the industry to “join us in supporting teens.”

This isn’t purely advocacy.

There is a very large financial incentive attached.

And Then There’s Age Assurance

This is the part cybersecurity and privacy professionals should be watching.

Social networks have historically had an obvious problem.

A website asks:

What is your birthday?

A 12-year-old enters:

I’m 18.

Problem solved.

Except nothing was solved.

So regulators increasingly want something stronger.

The Meta settlement calls for “robust age assurance.”

That means platforms need better ways to determine whether someone claiming to be an adult actually is one.

And that’s where child safety collides with privacy.

How Does the Internet Prove You’re an Adult?

There are several possibilities.

You could provide:

A government-issued ID.

A credit-card verification.

A facial image used for age estimation.

A third-party digital identity credential.

Or the platform could infer your likely age using information it already possesses.

Reuters reports that Meta historically has used clues including things like birthday-related information and school-related content, and the settlement requires stronger methods for identifying children.

Think about that second category.

You don’t explicitly prove your age.

The system determines it.

That’s a completely different privacy model.

Meta Already Has Age-Estimation Technology

This isn’t hypothetical technology.

Meta has previously used facial age-estimation technology from Yoti⁠ as one method for verifying ages in certain situations.

A person can submit a video selfie.

Technology analyzes facial characteristics.

The system estimates an age.

That may sound preferable to uploading a driver’s license.

And perhaps in some circumstances it is.

But biometrics create their own privacy questions.

Yoti Has Already Run Into a Regulator

Spain’s data-protection regulator sanctioned Yoti over its Digital ID application.

Yoti says the fine was €950,000 and that it is appealing the decision.

The controversy involved alleged GDPR violations concerning biometric processing, retention and consent associated with the Digital ID application.

Yoti strongly disputes the regulator’s conclusions and emphasizes that the decision did not involve a breach or compromise of users’ information.

That’s an important distinction.

But the case demonstrates the problem.

We want reliable age verification.

Reliable age verification requires information.

The more reliable we demand that determination become:

The more information the system may need.

The Privacy Paradox

Imagine an adult wants to use Instagram.

The platform needs to determine:

Adult or child?

How certain should it be?

60%?

80%?

95%?

99.9%?

Every additional nine creates pressure for additional evidence.

Maybe your birthday isn’t enough.

So analyze your face.

Maybe facial estimation isn’t certain enough.

Check your ID.

Maybe we don’t want IDs.

Analyze account history.

Your social graph.

Who you communicate with.

How long your account has existed.

What content you interact with.

What school references appear.

Other signals.

Individually, some of these approaches may preserve considerably more privacy than uploading identification.

But collectively they raise another question:

How much should a social network analyze about you simply to decide how old you are?

We’re Solving Two Different Problems

This distinction is getting lost.

Problem one:

Children need better protection online.

Problem two:

Platforms need a mechanism for identifying who is a child.

Those are related.

They are not identical.

And the second problem creates infrastructure that has capabilities extending beyond the first.

Once a platform can reliably distinguish:

  1. 12.

  2. 13.

  3. 14.

  4. 15.

  5. 16.

It has created an age-based identity layer.

That capability doesn’t disappear when the original child-safety debate ends.

Your Phone Can Already Limit Your Child’s Instagram

Here’s another uncomfortable part of the discussion.

Both Apple and Google already provide extensive parental controls at the operating-system level.

Parents can restrict:

App usage.

Screen time.

Nighttime access.

Downloads.

Purchases.

Websites.

Content.

Communications.

Notifications.

Entire applications.

A parent can effectively say:

Instagram gets one hour.

Or:

Instagram doesn’t work after 9 PM.

Or:

My child cannot use Instagram at all.

And the operating system can enforce that without requiring every adult Instagram user to establish their age with Instagram.

That doesn’t mean platform-level controls are unnecessary.

Far from it.

Because operating-system parental controls cannot fix:

Recommendation algorithms.

Dangerous content.

Predatory interactions.

Platform design.

Harmful engagement mechanisms.

Inadequate moderation.

Those are the platform’s responsibility.

But it does mean we should distinguish between:

Controlling children’s devices

and

identifying everyone using a service.

Meta Still Controls the Algorithm

This is where the debate should stay focused.

Suppose Instagram perfectly identifies every 14-year-old tomorrow.

Great.

Now what?

Age verification doesn’t automatically make the recommendation engine healthy.

It doesn’t automatically remove harmful material.

It doesn’t eliminate predatory accounts.

It doesn’t necessarily solve compulsive product design.

It doesn’t create independent oversight.

It simply gives Meta better information about:

Who is a child.

That’s useful.

But identifying the user and protecting the user are two different technical problems.

The Settlement Does Address Product Design

To be fair, this settlement doesn’t stop at age assurance.

It imposes substantial product restrictions.

Among them:

Two-hour combined daily limits.

Mandatory pauses.

Midnight-to-6 a.m. restrictions.

School-hour notification restrictions.

Stronger parental controls.

Options involving algorithmic feeds.

Restrictions involving likes and appearance-related features.

Additional protections around harmful content.

Those provisions deserve attention.

And some may genuinely improve children’s experiences online.

The mistake would be treating every technology introduced under the banner of child safety as automatically privacy-preserving because the objective is admirable.

Good intentions don’t eliminate cybersecurity architecture.

Australia Is Wrestling With the Same Problem

This isn’t uniquely American.

Governments around the world are trying to answer the same question:

How do you keep children out of inappropriate digital environments without constructing an unnecessarily invasive identity system for everybody else?

That’s an extraordinarily difficult engineering problem.

Age assurance exists on a spectrum.

At one end:

“Tell us your birthday.”

Almost no privacy intrusion.

Almost no assurance.

At the other:

“Prove exactly who you are.”

Much stronger assurance.

Much greater privacy consequences.

The goal should be finding the least intrusive mechanism capable of accomplishing the legitimate safety objective.

Not simply maximizing certainty.

Cybersecurity People Should Recognize This Problem Immediately

We deal with this tradeoff constantly.

Security wants more information.

More logs.

More telemetry.

More identity.

More monitoring.

More authentication.

And sometimes that’s absolutely necessary.

But every additional piece of information collected creates something else:

Data that now needs protecting.

If millions of people submit identity documents to prove their ages:

Those documents become valuable.

If millions provide facial information:

That information becomes sensitive.

If behavioral signals determine age:

Those behavioral profiles become consequential.

If third-party identity providers participate:

We’ve introduced additional companies into the trust chain.

Security doesn’t eliminate risk.

It moves risk around.

Biometrics Deserve Special Treatment

You can reset a password.

You can cancel a credit card.

You can change an email address.

Your face is considerably harder to replace.

That doesn’t mean facial age estimation is inherently unsafe.

Some systems are specifically engineered to minimize retention and avoid identifying the individual.

But when biometric information enters any system, businesses and regulators should ask difficult questions.

What exactly is collected?

Is an image stored?

Is a biometric template created?

How long does anything persist?

Can it be reused?

Who processes it?

Can it be linked to another account?

Can governments request it?

What happens after verification?

Can the information be deleted?

What happens if the provider is breached?

Those aren’t anti-technology questions.

They’re cybersecurity questions.

Now Imagine Age Verification Becomes Normal

This is where the settlement becomes bigger than Instagram.

Suppose every major platform adopts robust age assurance.

TikTok.

YouTube.

Instagram.

Facebook.

Snapchat.

Reddit.

Gaming platforms.

Messaging platforms.

AI platforms.

Adult-content websites.

Online marketplaces.

Suddenly proving—or having systems infer—your age becomes a routine part of internet access.

Maybe that’s where society ultimately decides to go.

But we should understand what we’re building before we get there.

Because infrastructure created for one legitimate purpose has a habit of finding additional purposes.

Identity Systems Create Enormous Power

Identity is valuable.

Knowing:

Who someone is.

Approximately how old they are.

Which accounts belong to them.

Which devices belong to them.

Where they authenticate.

Which services they use.

Which restrictions apply to them.

creates tremendous capability.

Sometimes we want that capability.

Banks need identity verification.

Governments need identity systems.

Healthcare organizations need to know which patient they’re treating.

Companies need to authenticate employees.

But anonymous and pseudonymous participation has also been part of the internet since its beginning.

Moving toward universal age assurance changes that balance.

Perhaps gradually.

Perhaps dramatically.

But it changes it.

Child Safety Shouldn’t End the Privacy Debate

This is where I think both sides get something wrong.

One side says:

Think of the children. Build whatever verification is necessary.

The other says:

Privacy. Therefore don’t regulate anything.

Neither is sufficient.

We should be capable of holding two thoughts simultaneously:

Social-media companies should be required to protect children.

And:

The systems used to accomplish that protection should collect the minimum information necessary.

Those positions aren’t contradictory.

That’s what responsible cybersecurity looks like.

Require Privacy by Design

If governments mandate stronger age assurance, then governments should simultaneously require strong privacy protections around it.

The objective should be:

Verify the attribute without unnecessarily identifying the person.

For example:

“This user is over 18.”

may be all Instagram needs.

Instagram doesn’t necessarily need:

“This is John Smith, born March 4, 1987, living at 123 Main Street, driver’s license number XXXXXXXX.”

That’s an important architectural distinction.

Modern cryptography and digital-identity systems increasingly make attribute verification possible without transmitting an entire identity.

That’s where regulators should push the industry.

Prove what needs proving.

Reveal nothing else.

Businesses Should Learn From This Too

The principle applies far beyond social media.

Organizations constantly collect more information than they actually need.

A form asks for ten fields when four would accomplish the task.

A database keeps records indefinitely.

An application stores identity documents after verification is finished.

An employee exports customer information “just in case.”

A vendor wants an entire dataset when it only needs one attribute.

Then everybody acts surprised when a breach becomes catastrophic.

There’s a simple data-protection principle every SMB should understand:

You cannot lose data you never collected.

And you cannot expose data you already deleted.

Data minimization is cybersecurity.

Meta’s Settlement Could Become an Industry Standard

This is why the $5.3 billion structure deserves attention.

Meta isn’t merely implementing these controls itself.

It has a substantial financial incentive for TikTok and YouTube to adopt comparable restrictions.

Meta openly says it wants an industry-wide framework.

If competitors agree, today’s settlement terms could become tomorrow’s industry baseline.

Then regulators look at everyone else and ask:

Why aren’t you doing it too?

That’s how standards spread.

Which means decisions being made today about age assurance architecture could eventually affect enormous portions of the internet.

Protect the Kids. Protect Everyone Else Too.

I strongly support giving parents more control over what children encounter online.

I support preventing adults from contacting children inappropriately.

I support restricting dangerous content.

I support making recommendation systems safer.

I support interrupting endless scrolling.

I support forcing technology companies to consider children’s welfare alongside engagement metrics.

And I think platforms should be held accountable when their product decisions create foreseeable harm.

But none of those beliefs require giving technology companies unlimited permission to build identity infrastructure.

We can demand both:

Safer technology for children.

And:

Privacy-preserving technology for everyone.

The best age-assurance system isn’t necessarily the one that knows exactly who you are.

It’s the one that can establish what it needs to know—and then knows as little else about you as possible.

Because there’s a dangerous habit developing in technology policy:

Identify a genuine problem.

Build an enormous data-collection system to solve it.

Then promise everyone the data will be protected.

Cybersecurity professionals know how that story sometimes ends.

Children deserve protection from technology companies.

Adults deserve protection too.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #DataPrivacy #OnlineSafety #DataProtection #TechPolicy


Protect kids from social media. Absolutely. But should every adult have to prove they’re an adult to use it?

Cybersecurity
Technology

Remote access doesn’t let someone watch your computer. It can let them operate it.

August 31, 2026
•
20 min read

Remote Access: The Moment You Click “Allow,” They Can Become You

Remote access doesn’t let someone watch your computer. It can let them operate it.

One of the most dangerous sentences you can hear on the phone is:

“I just need to connect to your computer for a minute.”

Remote access itself isn’t malicious.

IT departments and managed IT providers use remote-access software every day to troubleshoot computers, install software, maintain servers and help employees.

But scammers use many of the exact same tools.

And that’s what makes remote-access scams so effective.

There may be no sophisticated hacking involved.

No zero-day vulnerability.

No attacker breaking through your firewall.

You install the software. You approve the connection. You open the door yourself.

Once you understand what remote access can actually give another person, you’ll understand why that approval should be treated almost like handing someone your unlocked computer.

What Does “Remote Access” Actually Mean?

Remote-access software allows another computer to interact with yours over the internet.

Depending on the software and permissions granted, the remote person may be able to see your screen, move your mouse, type on your keyboard, open applications, browse files, download or upload information, change settings, install software, access websites you’re already signed into and potentially establish persistent access.

In other words:

They may be sitting 5,000 miles away, but your computer can behave as though they’re sitting in your chair.

Common legitimate remote-support products include TeamViewer⁠, AnyDesk⁠, ConnectWise ScreenConnect⁠ and Microsoft’s built-in Quick Assist⁠.

These are legitimate tools.

The danger is who you’re giving control to.

The Scam Can Start With Something Completely Innocent

You get a phone call.

“This is your bank’s fraud department.”

Or a popup:

“Your computer has been infected. Call Microsoft immediately.”

Or an email:

“There’s a problem with your account.”

Or someone claiming to be:

Your company’s IT department.

Microsoft.

Apple.

Amazon.

Your bank.

QuickBooks support.

Your internet provider.

The IRS.

A software vendor.

The attacker doesn’t necessarily need to hack your computer.

They need to convince you to give them access.

The FTC specifically warns about tech-support scammers asking victims to provide remote access to their computers, and the FBI has repeatedly warned about criminals using remote-desktop software in financial scams.

Then They Ask You to Install Something

This is the moment that should immediately raise your defenses.

They may tell you:

“Go to this website.”

“Download this support tool.”

“Read me the number on your screen.”

“Click Allow.”

The software might be completely legitimate.

That’s important.

Your antivirus might not block it because there’s nothing inherently malicious about the application.

The scammer is abusing a legitimate administrative tool.

That’s sometimes called living off trusted tools.

Instead of breaking into the house:

They convince the homeowner to hand them the key.

What Can They See?

Potentially, almost anything you can see.

Your desktop.

Your email.

Your browser.

Documents.

Photos.

Accounting software.

Customer information.

Company files.

Browser tabs.

Cloud applications.

Depending on the environment and authentication state, that could include sensitive business systems.

Remember something extremely important:

Being logged in is itself valuable.

Suppose your Microsoft 365 account has MFA.

Excellent.

But you’re already logged into Outlook.

The attacker remotely controls your computer and opens Outlook.

Your MFA hasn’t been “hacked.”

Your authenticated session may already be sitting there waiting for them.

The same concept can apply to other applications and websites.

Can They See Your Passwords?

Sometimes.

If you type a password while someone can view or control the computer, assume they may be able to observe it.

They may also try to get you to reveal credentials directly, access passwords stored insecurely, manipulate browser sessions, install additional malware or convince you to authenticate something yourself.

This is why a scammer might say:

“For security, please log into your bank.”

That sentence should terrify you.

You’re authenticating yourself.

For them.

Can They Access Your Bank Account?

If you’re logged in—or they convince you to log in—the consequences can be severe.

A common remote-access scam involves convincing the victim that a refund, fraud investigation or account correction requires access to online banking.

The scammer may manipulate what appears on the screen or attempt to persuade the victim to transfer money.

The FBI has specifically warned that criminals use remote desktop software in fraudulent schemes involving financial accounts.

Your bank account didn’t necessarily get “hacked.”

You logged into it from your legitimate computer, and someone else was controlling that computer.

That’s an important distinction.

Can They Steal Files?

Potentially, yes.

Many remote-access platforms support file transfer.

Even without an obvious file-transfer feature, an attacker with sufficient access could potentially copy information through other means or install additional software.

For businesses, that means remote access can expose:

Customer records.

Employee information.

Tax documents.

Contracts.

Financial statements.

Legal documents.

Medical information.

Intellectual property.

Passwords and credentials.

Cyber insurance information.

And potentially access to other systems.

This is where a simple scam can become a data breach.

Can They Install Something That Lets Them Come Back Later?

This is one of my biggest concerns.

There’s an enormous difference between:

One-time support access

and:

Unattended access.

Some remote-management products are intentionally designed so authorized IT personnel can reconnect later without someone sitting at the computer approving every session.

That’s extremely useful for legitimate IT management.

It’s also extremely dangerous when configured by an attacker.

A scammer may attempt to install additional remote-management software, configure unattended access, create accounts, establish persistence or deploy malware.

So closing the window does not necessarily answer the important question:

Can they get back in?

“I Disconnected Them. Am I Safe?”

Don’t assume so.

If an unknown person had remote access to your computer, treat the incident seriously.

The question isn’t only what you watched them do.

It’s:

What could they have done while they had access?

If you realize you’ve given a scammer remote access, disconnect the computer from the internet if practical and contact your organization’s IT department or MSP immediately.

For a personal computer, get trusted technical assistance and review the machine for unauthorized remote-access software or other persistence before using it for sensitive activity again.

Then, from a known-clean device, change passwords for accounts that may have been exposed, beginning with email and financial accounts, review MFA methods and active sessions, and contact your bank immediately if financial information or banking access was involved.

If it’s a business computer, don’t simply uninstall the remote-access application and declare victory.

It may now be an incident-response issue.

Businesses Have an Additional Problem

Remote-access software isn’t only a scam problem.

It’s an administrative-security problem.

Ask your MSP:

“Which remote-access applications are permitted on our computers?”

Then ask:

“Can employees install another one?”

If every employee can download arbitrary remote-control software, your carefully designed cybersecurity stack has an enormous hole.

An attacker doesn’t necessarily need to defeat your approved remote-management system.

They can convince an employee to install their own.

Your Cybersecurity Tools May See Legitimate Software

This is what makes the problem tricky.

An EDR platform may recognize TeamViewer or another tool as legitimate software.

Because it is.

The malicious part is intent.

A hammer isn’t malware.

Neither is a remote-support application.

The question is:

Who is holding it?

Organizations should therefore control which remote-management tools are permitted, restrict unauthorized applications, monitor their installation and use, remove unnecessary software, enforce least privilege and train employees to recognize unexpected support requests.

For healthcare IT, law firms and schools, this becomes especially important because a single remotely controlled endpoint may expose highly sensitive patient, client or student information.

Create One Simple Company Rule

Every employee should know this:

Never grant remote access because someone unexpectedly called, emailed or texted you.

If “Microsoft” calls:

Hang up.

If “your bank” calls:

Hang up and call the number you already trust.

If someone says they’re your MSP:

Call your MSP using the number you already have.

If your CEO supposedly needs someone connected urgently:

Verify independently.

The legitimate technician won’t be offended by verification.

Your employees don’t need to become cybersecurity experts.

They need permission to say:

“I’ll call our IT department first.”

And Never Trust Caller ID

A phone displaying your bank’s name does not prove your bank is calling.

A Microsoft logo doesn’t prove Microsoft created the popup.

An email signature doesn’t establish identity.

A person’s knowledge of your name, company or computer doesn’t establish identity either.

Attackers build credibility before asking for access.

The remote-access request is often simply the final step.

There’s a Powerful Cybersecurity Principle Here

We spend enormous amounts of money trying to keep attackers outside.

Firewalls.

MFA.

EDR.

Email security.

DNS filtering.

Zero Trust.

Conditional Access.

Encryption.

Then someone calls an employee and says:

“Click Allow.”

And suddenly the attacker may be operating from an endpoint we’ve already trusted.

That’s why cybersecurity cannot only protect machines.

It has to prepare people.

Before You Give Anyone Remote Access, Ask One Question

Did I initiate this support request?

If you called your trusted IT provider because your printer isn’t working and they ask to connect:

Normal.

If somebody unexpectedly contacts you and then asks to control your computer:

Stop.

Verify them independently.

Because once somebody remotely controls your computer, the important question is no longer:

“Can they hack me?”

It’s:

“What can I do on this computer that they can now potentially do too?”

And that’s why remote access should be treated like a physical key.

You wouldn’t let a stranger who called you unexpectedly into your office and leave them alone at your desk.

Don’t do the digital equivalent.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ManagedIT #RemoteAccess #ScamAwareness #DataProtection


If a stranger gets remote access to your computer, assume they can do almost anything you can. Here’s what that actually means.

Technology
Cybersecurity
Must-Read

China Hacked NASA. Your Router May Have Helped.

August 30, 2026
•
20 min read

China Hacked NASA. Your Router May Have Helped.

The hackers didn’t need their own infrastructure. They borrowed ours.

NASA.

The Federal Reserve.

The Department of Justice.

The Department of Energy.

The Department of Health and Human Services.

The National Institutes of Health.

The United States Senate.

Hospitals.

Financial institutions.

Power companies.

Defense contractors.

According to the U.S. government, Chinese state-sponsored hackers have spent years attacking some of America’s most sensitive networks.

This week, the Justice Department and FBI announced that they had disrupted two of the platforms allegedly helping them do it:

QScan and QTRouter.

And buried underneath the spectacular list of government targets is a cybersecurity lesson every small business should understand.

The infrastructure used to hide these attacks wasn’t necessarily sitting inside some secret Chinese intelligence facility.

It included ordinary compromised devices scattered around the world.

Routers.

Security cameras.

Other Internet of Things equipment.

Potentially the same kinds of devices sitting inside millions of American businesses right now.

First, Meet QScan

According to the Justice Department, a China-based group known as QTFY operated QScan.

QScan essentially searched the internet looking for vulnerable IoT devices.

When it found exploitable equipment, it could automatically compromise those devices.

Thousands of infected devices could then be fed into the second part of the operation:

QTRouter.

Now things get considerably more interesting.

QTRouter Made China Look Like Your Neighborhood

Imagine I’m sitting in China and want to attack an organization in New York.

If I connect directly from China, defenders might immediately become suspicious.

They see:

Login from China.

Block.

Investigate.

Alert the SOC.

So instead, imagine I’ve compromised a router inside a completely unrelated American business.

I route my attack through that router.

The target doesn’t necessarily see:

Attacker in China.

It sees:

Traffic coming from somewhere in America.

Potentially somewhere very close to the victim.

That’s essentially the purpose of an obfuscation network.

The Justice Department says QTRouter combined compromised IoT devices with commercial proxy devices and leased virtual private servers to conceal the Chinese origin of malicious activity.

The FBI says compromised equipment existed across more than 130 countries.

The hacker is thousands of miles away.

The attack appears to be coming from down the street.

That’s an Extremely Powerful Cybersecurity Weapon

Security systems use context.

Where is this connection coming from?

Has this IP address been malicious before?

What country is it in?

Does the geography make sense?

Is it associated with a hosting provider?

Is it a known VPN?

Is it a residential ISP?

Attackers understand those controls.

So they disguise themselves.

A compromised router inside a legitimate American network gives an attacker something valuable:

Reputation.

The IP address may not look malicious.

The geography may not look suspicious.

The device may have existed there for years.

Nobody bought infrastructure specifically for the attack.

Nobody necessarily noticed anything strange.

It’s someone else’s equipment.

That’s why compromised routers and IoT devices have become such useful infrastructure for sophisticated attackers.

Now Look at Who They Targeted

According to court documents, QTFY’s activity dates back to at least 2018.

Targets and victims identified by U.S. authorities included NASA, the Federal Reserve, DOJ, DOE, HHS, NIH and the U.S. Senate, along with organizations in critical infrastructure and the private sector.

Reuters reports that investigators traced an attempted 2019 NASA intrusion involving exploitation of a Pulse Secure VPN vulnerability back to infrastructure and accounts connected to China.

The campaign continued for years.

The FBI was still investigating activity connected to an attack targeting the U.S. Senate in 2026.

Think about that timeline.

  1. 2018.

  2. 2019.

  3. 2020.

  4. 2021.

  5. 2022.

  6. 2023.

  7. 2024.

  8. 2025.

  9. 2026.

Cyber espionage isn’t necessarily somebody smashing through your firewall one night.

Sophisticated campaigns are infrastructure businesses.

Attackers build systems.

Maintain access.

Develop tools.

Acquire vulnerable devices.

Build proxy networks.

Sell services.

Replace infrastructure that gets discovered.

Then keep operating.

This Was Apparently a Business Too

This is another fascinating part.

The Justice Department alleges QTFY works through a Chinese company called Nanjing Xinjiuwei Network Technology Company.

According to U.S. authorities, the company offered hacking services to paying customers—including China’s Ministry of State Security and People’s Liberation Army.

Think about what that means.

We sometimes picture nation-state hacking as government employees sitting inside military buildings.

Modern cyber operations can be much messier.

Private contractors.

Hackers-for-hire.

Government customers.

Commercial infrastructure.

Stolen infrastructure.

Compromised consumer equipment.

Proxy services.

Botnets.

It’s an ecosystem.

The FBI described the company as operating within a complex network of hackers-for-hire and government customers.

Cybercrime and cyber espionage have supply chains too.

So How Did America Shut It Down?

This part is wonderfully simple.

The FBI didn’t need to find every compromised camera and router around the world.

Investigators identified something the system depended upon:

Three domain names.

According to the FBI affidavit, they were:

qtproxy.xyz

qt-proxy.org

qt-team.com

Those domains performed essential functions for QScan and QTRouter, including communication and authentication.

The government obtained court-authorized seizure warrants.

Then it seized them.

And because those domains were hard-coded into the platforms, DOJ says the seizures rendered QScan and QTRouter inoperable.

That’s a beautiful incident-response lesson.

You don’t necessarily have to destroy every component of an attack.

Find what the system depends on and break that dependency.

Your $80 Router Can Become Part of a Nation-State Operation

Here’s where this stops being a Washington story.

Imagine you run a 25-person business.

You have:

A firewall.

Three wireless access points.

Six security cameras.

A network video recorder.

Two smart TVs.

A door-access controller.

A printer.

A thermostat.

A conference-room system.

Maybe an old router installed by a vendor six years ago.

Which of those devices are being patched?

Who manages them?

What firmware versions are running?

Are default credentials still configured?

Can they be reached from the internet?

Do they have unnecessary remote-management services enabled?

Does your MSP even know they exist?

If you can’t answer those questions:

Neither can your cybersecurity program.

IoT Devices Are Computers

Businesses don’t think about them that way.

That’s the problem.

A security camera looks like a camera.

A printer looks like a printer.

A thermostat looks like a thermostat.

A router looks like an appliance.

But increasingly they’re all:

Computers connected to your network.

They have:

Operating systems.

Processors.

Memory.

Passwords.

Network services.

Firmware.

Cloud connections.

Remote-access capabilities.

Vulnerabilities.

And sometimes extraordinarily poor security.

The attacker doesn’t care that you call it a camera.

They see a Linux computer connected to the internet.

This Is Why Asset Inventory Matters

Here’s a cybersecurity exercise every SMB should perform.

Ask your MSP:

“Show me everything connected to my network.”

Not just Windows computers.

Everything.

Laptops.

Servers.

Phones.

Printers.

Cameras.

Access points.

Switches.

Firewalls.

Door controllers.

HVAC equipment.

Conference-room systems.

Smart TVs.

IoT devices.

Vendor equipment.

Unknown devices.

Then ask:

“Which of these are we actually responsible for securing?”

That second question usually gets more interesting.

Find the Forgotten Equipment

Some of the riskiest technology inside a business isn’t new.

It’s forgotten.

The camera installer put something in five years ago.

The HVAC contractor installed a gateway.

The phone vendor left a box.

The previous MSP installed a router.

Nobody remembers the password.

Nobody knows whether firmware updates exist.

Nobody knows whether the manufacturer still supports it.

But it’s still:

Powered on.

Connected.

Talking to the internet.

Attackers love forgotten technology.

Because defenders aren’t watching it.

Cameras Deserve Special Attention

Security cameras are particularly interesting.

Companies install them specifically to improve physical security.

Then forget that they’re network devices.

Check:

Are they segmented from employee computers?

Can they reach the internet?

Can the internet reach them?

Are default passwords gone?

Is remote access enabled?

Is firmware supported?

Who has administrator access?

Does the installer still have access?

Where does footage go?

What cloud services are involved?

If your camera gets compromised, the problem isn’t merely somebody potentially watching it.

It can become somebody else’s computer inside your network.

That’s a much bigger problem.

Stop Exposing Things Directly to the Internet

This lesson keeps appearing across cybersecurity incidents.

If something does not need to accept unsolicited connections from the public internet:

Don’t let it.

Especially:

Routers.

Cameras.

NAS devices.

Remote-management interfaces.

Industrial controllers.

Building automation.

Old VPN appliances.

Remote Desktop.

Internet-connected storage.

Reduce the attack surface.

Use secure remote-access architectures.

Patch internet-facing equipment aggressively.

Replace unsupported devices.

Disable unnecessary services.

Segment IoT networks.

Monitor outbound connections.

Use strong unique credentials.

And where supported, enable MFA.

Basic cyber hygiene becomes extremely powerful when performed consistently.

Network Segmentation Matters Here Too

Imagine an attacker compromises your security camera.

What can that camera reach?

If the answer is:

Employee laptops.

Servers.

Accounting systems.

Backups.

Domain controllers.

Printers.

Everything.

You have another problem.

IoT equipment should generally live on networks appropriate to its function, with tightly controlled communication to other environments.

Your cameras don’t need to talk to accounting.

Your guest Wi-Fi doesn’t need to reach your server.

Your smart television doesn’t need access to your backup infrastructure.

Your thermostat doesn’t need to communicate with employee laptops.

Make attackers cross walls.

Don’t hand them a flat network.

Geographic Blocking Isn’t Enough

This attack also demonstrates an important limitation of country blocking.

I like geographic restrictions where appropriate.

If your 30-person New York business has no employees, customers or vendors in certain countries, there may be very little reason to accept authentication attempts or remote-management traffic from them.

That’s useful.

But don’t confuse it with complete protection.

Because sophisticated attackers know exactly what you’re doing.

They route through:

Compromised American routers.

Residential proxies.

Cloud infrastructure.

VPNs.

Other victims.

The attacker can be sitting in Beijing while your firewall sees:

New Jersey.

That’s why cybersecurity can’t rely on IP geography alone.

Identity.

Device health.

Behavior.

MFA.

Conditional Access.

Least privilege.

Endpoint security.

Logging.

Those layers matter.

This Is Also Why “Trusted IP” Can Be Dangerous

Businesses love allowlists.

This IP address belongs to our vendor. Trust it.

Be careful.

IP addresses aren’t identities.

Infrastructure gets compromised.

Credentials get stolen.

Cloud systems change.

VPN exit points get abused.

A request coming from an expected network location does not automatically mean:

The expected human generated it.

Modern Zero Trust architecture is built around exactly this assumption:

Don’t trust something simply because of where it came from.

Verify.

The Government Didn’t End Chinese Cyber Espionage

Another important distinction:

The FBI disrupted these platforms.

That doesn’t mean the underlying threat disappeared.

The seized domains were important enough that DOJ says QScan and QTRouter became inoperable.

That’s significant.

But sophisticated threat actors rebuild.

New domains.

New malware.

New exploits.

New proxies.

New compromised devices.

New contractors.

This is why cybersecurity isn’t a project you finish.

It’s an operating function.

We’ve Seen This Movie Before

This isn’t even the first time the FBI has disrupted Chinese state-backed infrastructure built from other people’s compromised devices.

In 2023, the FBI disrupted a botnet used by Volt Typhoon to conceal attacks against critical infrastructure.

In 2024, authorities disrupted infrastructure involving hundreds of thousands of compromised IoT devices associated with Flax Typhoon.

In 2025, the FBI removed PlugX malware from more than 4,000 U.S. computers associated with the China-linked Mustang Panda operation.

And now:

QScan and QTRouter.

There’s a pattern here.

Other people’s vulnerable devices are useful national-security infrastructure.

Make sure yours aren’t among them.

Cybersecurity Isn’t Just About Protecting Your Data

This is the bigger lesson.

Most business owners think cybersecurity means:

Protect my company from being hacked.

That’s obviously important.

But an insecure device can create another problem.

Your infrastructure can be weaponized against somebody else.

Your router.

Your camera.

Your server.

Your compromised cloud account.

Your website.

Your email.

Your IP address.

Suddenly your company isn’t necessarily the ultimate target.

You’re infrastructure.

That’s why patching a forgotten router matters even if there’s “nothing important on it.”

The attacker may not want what’s inside the router.

They want where the router is.

A legitimate American IP address.

A foothold.

A proxy.

A place to hide.

And according to the U.S. government, Chinese state-sponsored hackers built an entire operation around exactly that idea.

NASA and the Federal Reserve make spectacular headlines.

But the cybersecurity lesson is sitting somewhere much closer to home:

That forgotten camera or router in the corner isn’t too insignificant for a nation-state hacker.

It might be exactly what they’re looking for.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ManagedIT #IoTSecurity #DataProtection #SMB


China hacked NASA and the Federal Reserve by hiding behind ordinary routers and cameras. Is yours patched?

Technology
AI
Cybersecurity

Meta didn’t just settle. It agreed to change the product.

August 28, 2026
•
20 min read

Meta Just Agreed to Pay $17 Billion. The Money Isn’t the Biggest Part.

Meta didn’t just settle. It agreed to change the product.

Last week, I wrote about what was being called social media’s “Big Tobacco moment.”

Meta was heading into federal court in California facing accusations from states across America that Facebook and Instagram were deliberately designed in ways that encouraged compulsive use among children and teens.

Meta denied the allegations.

The numbers being discussed were almost absurd.

Meta’s attorneys warned that the states’ theories could theoretically produce penalties reaching:

$1.4 trillion.

The states suggested something closer to $200 billion.

The trial began August 18.

Eight days later:

It’s over.

Meta has agreed to a landmark multistate settlement worth up to approximately $17.1 billion, along with significant mandatory changes to Facebook and Instagram. The agreement resolves claims involving 47 states plus Washington, D.C. and U.S. territories, although the federal case itself involved claims from 29 states.

And once again, I think everybody is going to focus on the wrong number.

$17 Billion Is Enormous

Let’s not minimize it.

State officials are calling this the largest state consumer-protection settlement in American history outside the tobacco settlements of the 1990s.

Texas alone says it will receive more than:

$1 billion.

Tennessee expects approximately:

$752 million.

Washington, D.C. says it will receive somewhere between approximately:

$90 million and $129 million.

Meta is also resolving separate privacy litigation involving the Cambridge Analytica scandal, with California, Illinois, New Mexico and Washington, D.C. receiving another $459.3 million related to those cases.

This is real money.

But Meta makes real money.

That’s why the more consequential sentence in this settlement may not contain a dollar sign.

Meta Has to Change Instagram and Facebook

This wasn’t simply:

Pay the states and continue doing business.

Meta agreed to change how its platforms operate for younger users.

According to Reuters, the settlement requires nationwide safeguards including:

Daily usage limits.

Restrictions on nighttime usage.

Additional protections intended to prevent minors from accessing age-inappropriate material.

Other reporting on the settlement describes additional changes involving school-hour notifications, parental controls and certain appearance-altering filters.

Think about what that means.

For years, the central question was:

Should parents control how much social media their children consume?

This settlement pushes the conversation somewhere very different:

What responsibility does the company designing the product have to prevent children from consuming too much of it?

That’s a profound shift.

The Product Was the Case

This distinction is critical.

The states weren’t simply arguing:

“Bad content exists on Instagram.”

That becomes complicated because Section 230 has historically provided technology platforms substantial protection from liability for content created by third parties.

Instead, prosecutors attacked the design of the product itself.

The algorithms.

Notifications.

Engagement mechanisms.

Features designed to keep people returning.

Age verification.

Data collection.

The allegation was essentially that the harm wasn’t merely happening on the product.

The states argued portions of the harm were being created by how the product was engineered.

Meta has denied wrongdoing in agreeing to the settlement.

But agreeing to redesign parts of Facebook and Instagram is very different from simply paying a fine.

Think About the Business Model

Social-media platforms have an unusual economic incentive.

You generally aren’t paying Instagram every month.

Advertisers are paying Meta.

That makes one resource extraordinarily valuable:

Your attention.

The longer you stay:

More content can be served.

More advertisements can be displayed.

More behavioral information can be gathered.

More opportunities exist to bring you back.

That doesn’t mean every engagement feature is malicious.

Notifications can be useful.

Recommendations can be useful.

Autoplay can be convenient.

Personalization can improve a product.

But when the user is a child, society is increasingly asking whether the same engagement-maximizing machinery should operate under different rules.

The Meta settlement suggests regulators believe the answer is:

Yes.

Imagine This Rule Applied to Other Industries

This is where the precedent gets interesting.

For decades, technology companies have essentially optimized:

Make the product as engaging as possible.

That’s considered good product design.

More daily active users.

More time in the app.

More engagement.

Higher retention.

Those are metrics executives celebrate.

But what happens when maximizing engagement becomes legally dangerous for certain users?

Now the product team has competing objectives:

Increase engagement.

But enforce time limits.

Increase return visits.

But restrict notifications.

Personalize content.

But restrict what younger users can encounter.

Grow the user base.

But improve age assurance.

Suddenly:

Safety isn’t merely a feature. It’s an engineering constraint.

That idea could spread far beyond Meta.

The AI Part Shouldn’t Be Overlooked

There was another fascinating allegation in the case.

The states alleged Meta collected personal information from children under 13 without proper parental notification or consent in violation of the Children’s Online Privacy Protection Act.

And according to Reuters, prosecutors alleged that some of that information was used to train:

Machine-learning and generative AI models.

This was one of the most important parts of our previous article.

AI has changed the meaning of data retention.

Twenty years ago, if a company improperly collected a database, remediation might mean:

Find it.

Delete it.

Confirm deletion.

Done.

AI complicates that.

What happens when information has already contributed to training a model?

Deleting the original record doesn’t necessarily reverse whatever influence it had during training.

That’s going to become one of the defining data-protection questions of the AI era.

Every Business Using AI Should Learn From This

Your company probably isn’t Meta.

You probably aren’t training a frontier AI model.

But employees are increasingly putting company information into AI systems.

Customer records.

Contracts.

Meeting transcripts.

Email.

Support tickets.

Employee information.

Financial information.

Patient information.

Student information.

Source code.

Internal documents.

Before allowing that, ask:

Do we actually have the right to use this data this way?

That’s the question businesses keep skipping.

“We Already Had the Data” Doesn’t Mean “We Can Train AI With It”

This distinction will become enormously important.

Imagine a customer gave you their information to process an order.

That doesn’t automatically mean:

Use my information to train an AI system.

An employee gave HR personal information.

A patient gave a healthcare provider medical information.

A parent gave a school information about a child.

A client gave an attorney confidential documents.

The organization may legitimately possess that information.

That doesn’t automatically authorize every possible future use of it.

Data governance needs to distinguish between:

We possess it.

and:

We’re permitted to use it for this purpose.

Those aren’t the same thing.

Healthcare Needs to Be Extremely Careful

Healthcare organizations are rushing toward AI because the productivity possibilities are enormous.

Summarize records.

Draft notes.

Analyze documents.

Automate administrative tasks.

Assist clinicians.

But healthcare IT teams need to know exactly what happens when patient information enters an AI system.

Is the vendor permitted to receive PHI?

Is there an appropriate agreement?

Is information retained?

Can humans review it?

Can the provider use it to improve or train models?

Where is it processed?

Can it be deleted?

What logs exist?

Who has access?

A clever AI feature isn’t worth accidentally creating a data-protection problem.

Law Firms Have the Same Issue

Law firms possess some of the most sensitive information imaginable.

Attorney-client communications.

Litigation strategy.

M&A documents.

Financial records.

Trade secrets.

Evidence.

Personal information.

Uploading a document into an AI tool isn’t merely:

“Using software.”

You’re potentially transferring highly sensitive information into another computing environment.

Law Firm IT needs approved AI platforms, defined policies and technical controls rather than simply hoping every attorney understands the difference between consumer and enterprise AI services.

Schools Should Pay Particular Attention to This Settlement

This case is literally about children.

Meanwhile, schools are rapidly introducing:

AI tutoring.

Learning analytics.

Cloud platforms.

Student monitoring.

Educational applications.

Automated assessments.

Behavioral systems.

School Technology departments need to understand what those systems collect and what happens afterward.

What student information does the vendor retain?

Does it train models?

Can parents request deletion?

Does deleting the student’s account delete the underlying information?

Who owns generated data?

How long is it retained?

Can the vendor change its terms later?

Schools shouldn’t discover the answers after millions of student records have already entered a platform.

SMBs Need AI Governance Before They Think They Need AI Governance

This sounds like something only giant corporations need.

It isn’t.

A 30-person company can create an AI data problem remarkably quickly.

All it takes is one employee discovering:

“ChatGPT can summarize these customer files for me.”

Now hundreds of documents are being uploaded.

Was that approved?

Which account did they use?

What data was inside?

Was confidential information included?

What are the provider’s data controls?

Nobody knows.

That’s Shadow IT accelerated by AI.

Your MSP or managed IT provider should help establish:

Approved AI tools.

Acceptable-use rules.

Data classifications.

Access controls.

Employee training.

Logging where appropriate.

Vendor security reviews.

And clear rules governing confidential information.

Don’t wait until an employee has already uploaded three years of company history.

The Settlement Also Shows Why Regulators Care About Defaults

Cybersecurity professionals understand this extremely well.

Defaults matter.

Most people don’t change settings.

Give someone optional MFA?

Many won’t enable it.

Make MFA mandatory?

Almost everyone suddenly has MFA.

Give parents an optional screen-time control buried six menus deep?

Some will find it.

Change the platform’s default behavior?

Now you’ve changed behavior at scale.

That’s why product design can become more powerful than a warning label.

The architecture determines what happens automatically.

That’s a Lesson for Cybersecurity Too

Businesses frequently make the same mistake.

They tell employees:

Don’t click suspicious links.

Use strong passwords.

Don’t share confidential information.

Be careful.

Wonderful.

Then they leave the environment configured so one mistake can destroy the company.

Good cybersecurity doesn’t merely tell users to behave correctly.

It builds systems where mistakes are harder to make and less catastrophic when they happen.

MFA.

Least privilege.

EDR.

Email filtering.

Immutable backups.

Network segmentation.

DNS filtering.

Conditional Access.

Application controls.

Data Loss Prevention.

That’s the cybersecurity equivalent of changing the product rather than merely changing the warning.

Don’t just tell people to be safe. Design safety into the environment.

Meta Still Faces More Litigation

This settlement doesn’t make Meta’s legal problems disappear.

Reuters reports that Meta, Snap, YouTube and TikTok still face thousands of lawsuits from individuals, governments and school districts alleging that their platforms contributed to harms among children and teenagers.

Meta also suffered major losses earlier this year.

A New Mexico jury ordered the company to pay $375 million.

A judge later ordered another $567 million and imposed youth-safety requirements.

That’s $942 million in that case alone, although Meta has said it will appeal.

So today’s settlement isn’t necessarily the end of social media’s legal reckoning.

It may be the beginning of the template.

This Is Bigger Than Meta

Watch what happens next.

If one of the largest technology companies in the world agrees to:

Usage limits.

Nighttime restrictions.

Stronger protections for minors.

More parental oversight.

Age-related safeguards.

Other platforms will face a simple question:

Why aren’t you doing the same thing?

That’s how standards change.

First something is considered optional.

Then responsible.

Then expected.

Then regulators ask why everyone isn’t doing it.

Cybersecurity followed exactly the same path with MFA, encryption, breach notification and other protections.

AI governance may follow it next.

The Most Important Number Isn’t $17 Billion

The $17 billion headline is spectacular.

It will dominate the coverage.

But Meta once warned that its theoretical exposure could reach $1.4 trillion.

The states suggested roughly $200 billion.

Meta ultimately agreed to something dramatically smaller.

Financially, settling eliminated enormous uncertainty.

Meta’s stock actually rose following news of the agreement.

But here’s what Meta couldn’t purchase with the settlement:

The ability to keep everything exactly as it was.

That’s what makes this historic.

The government didn’t merely say:

You owe us money.

The settlement says, in effect:

The product has to change.

And that should get the attention of every technology company building systems designed to capture human attention, collect personal information or train AI.

Because the regulatory question is evolving.

It isn’t simply:

Did you protect the data?

It’s becoming:

Should you have collected it?

Should you have used it that way?

What did you build from it?

And did you design the technology itself to protect the people using it?

Meta agreed to pay billions.

But the precedent may ultimately be worth considerably more.

For Big Tech, “we gave users a choice” may no longer be enough.

Regulators increasingly want safety built into the product itself.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #DataProtection #ArtificialIntelligence #OnlineSafety #TechRegulation


Meta faced a theoretical $1.4 TRILLION bill. It settled for $17 billion—and agreed to change how Instagram works.

Cybersecurity
Technology

Your work emails may outlive the company that employed you.

August 26, 2026
•
20 min read

Google Just Put a $10 Million Price Tag on Employees’ Old Emails

Your work emails may outlive the company that employed you.

Spirit Airlines is gone.

Its planes are being dealt with.

Its employees have been laid off.

Its operations have stopped.

But something remarkably valuable survived:

The conversations its employees left behind.

Google has agreed to pay $10 million in Spirit Airlines’ bankruptcy proceedings for access to a massive collection of the airline’s internal business data.

The reason?

Among other product-development uses:

Training artificial intelligence.

And the scale of what’s being sold is extraordinary.

Approximately:

100 million emails.

500 million Microsoft Teams messages.

Plus internal documents, spreadsheets, calendars, operational information, marketing data, productivity data and software.

Think about what that actually represents.

Years of employees:

Asking questions.

Solving problems.

Arguing.

Making decisions.

Explaining procedures.

Scheduling meetings.

Fixing mistakes.

Writing reports.

Collaborating.

Managing an airline.

Spirit’s aircraft were obviously valuable physical assets.

But in the AI economy, there was apparently another asset sitting quietly on its servers:

A gigantic recording of how thousands of humans actually work.

Why Would Google Want 500 Million Teams Messages?

Because AI companies have an enormous problem.

The internet contains staggering amounts of information.

But internet text isn’t necessarily a good representation of how employees actually perform their jobs.

Wikipedia can teach an AI about aviation.

A corporate archive can potentially teach it how people operate an airline.

Consider what exists inside years of internal communications.

Someone reports a problem.

Someone else diagnoses it.

A manager escalates it.

Employees debate possible solutions.

A decision gets made.

Someone implements it.

Something goes wrong.

They fix it.

Multiply that across millions of conversations.

You’re no longer looking at a collection of messages.

You’re looking at something resembling an enormous dataset of:

Problem → reasoning → decision → action → outcome.

That’s incredibly interesting training material for AI systems designed to perform knowledge work.

The Runner-Up Tells You Something Important

Google wasn’t alone.

Mercor reportedly bid $7.5 million for the dataset and is the backup purchaser if Google’s transaction doesn’t close.

Mercor operates in the AI ecosystem and works with human expertise and data used to improve AI systems.

That makes this more interesting than Google simply buying leftover corporate software.

There was competitive bidding for the information itself.

Corporate exhaust has become an asset class.

We’ve Seen a Tiny Version of This Before

There’s a fascinating precedent.

Enron.

When Enron collapsed, roughly half a million employee emails eventually became a famous public research dataset.

The Enron Email Dataset has subsequently been used for decades by researchers studying:

Natural-language processing.

Spam detection.

Social networks.

Organizational communication.

Email classification.

Machine learning.

It became extraordinarily valuable precisely because authentic corporate email is difficult to obtain.

Now compare roughly half a million Enron messages with:

100 million Spirit emails.

And then add:

500 million Teams messages.

The difference isn’t merely size.

Teams captures a different kind of communication.

Shorter.

Faster.

More conversational.

More informal.

More collaborative.

Many workplace conversations that would once have occurred verbally or disappeared entirely are now permanently recorded in Slack, Teams and similar platforms.

We created an extraordinarily detailed dataset of how modern offices function without necessarily realizing we were creating one.

The Employees Weren’t Writing AI Training Data

This is where the story becomes uncomfortable.

An employee writing:

Hey, did we ever figure out why that report keeps failing?

isn’t thinking:

“I’m contributing another sample to a future machine-learning corpus.”

They’re doing their job.

When employees communicated with coworkers, they understood they were using corporate systems.

They presumably understood the company retained those records.

But there’s a meaningful difference between:

“My employer stores my Teams messages.”

and:

“Years after I write this, these conversations might become an asset sold during bankruptcy to train someone else’s artificial intelligence.”

That’s the ethical question this case puts directly on the table.

The Data Is Supposed to Be De-Identified

There is an important safeguard.

Reporting says a third party will process the information before delivery to Google.

Personally identifiable information is supposed to be removed, and customer information isn’t part of the transaction.

That’s significant.

This isn’t Google simply receiving a searchable inbox containing employee names, customer records and credit-card information.

But de-identification doesn’t eliminate the larger question.

Who owns the knowledge created through everyday work?

The employee?

The employer?

The bankruptcy estate?

And if that information has economic value after the company dies, should employees have any say in how it’s subsequently used?

Legally, workplace communications created on company systems generally belong to the employer, subject to applicable contracts, policies and privacy laws.

AI is making the implications of that old reality much more visible.

Bankruptcy Changes How You Look at Data

Imagine a company shuts down.

What remains?

Buildings.

Computers.

Vehicles.

Furniture.

Patents.

Domain names.

Software.

Customer relationships.

Traditionally, those are the assets people expect to see sold.

Now add:

Every email employees ever wrote.

Every Teams conversation they ever had.

Every internal document they created.

Every workflow they developed.

Every operational problem they solved.

AI has potentially changed the liquidation value of information.

A database that once represented storage expense can now represent training material.

That’s a remarkable economic shift.

Your Company May Be Sitting on an AI Dataset Right Now

Forget Spirit for a moment.

Think about your own Microsoft 365 environment.

How many years of email exist?

How many Teams messages?

How many SharePoint documents?

How many support tickets?

How many meeting transcripts?

How many recorded calls?

How many internal procedures?

How many customer-service conversations?

How many Slack messages?

How many CRM notes?

Ten years ago, much of that was considered historical business data.

Today it can potentially be something else:

A dataset describing how your organization thinks.

That’s valuable.

And anything valuable needs governance.

This Creates a New Data-Protection Question

Most businesses ask:

How long do we need to retain this data?

AI gives us another question:

What could someone eventually do with it?

That’s much harder.

Your employee handbook may explain that corporate email belongs to the company.

But does your privacy policy explain whether employee communications can someday be:

Analyzed by AI?

Used to train models?

Licensed?

Sold?

Transferred during an acquisition?

Transferred during bankruptcy?

De-identified and monetized?

Most organizations wrote their data-retention policies before anyone seriously contemplated these possibilities.

They should revisit them.

“Deleted” and “Gone” Aren’t Always the Same Thing

Businesses should also understand where information actually exists.

An employee deletes an email.

Is it gone?

Maybe not.

It might still exist in:

Retention policies.

Litigation holds.

Backups.

Archives.

Security platforms.

Journaling systems.

Cloud repositories.

Third-party backup products.

eDiscovery systems.

The same applies to Teams and other collaboration platforms.

Modern businesses deliberately retain enormous amounts of information for legal, compliance and operational reasons.

That’s often necessary.

But retention has a security consequence:

You cannot lose data you no longer possess.

Every year of retained information increases the historical dataset that potentially exists during a breach, acquisition, lawsuit—or bankruptcy.

Don’t Retain Everything Forever Just Because You Can

This is where your MSP, cybersecurity team, attorneys and compliance professionals need to work together.

Data retention shouldn’t be:

“Storage is cheap, keep everything.”

Organizations should establish defensible retention schedules based on:

Legal requirements.

Regulatory obligations.

Operational needs.

Litigation requirements.

Contractual commitments.

Security risk.

Privacy.

Different information deserves different retention periods.

Keeping unnecessary information indefinitely creates unnecessary liability indefinitely.

There Is Also a Cybersecurity Gold Mine Here

Think about this dataset from an attacker’s perspective.

Corporate communications can reveal:

Internal terminology.

Organizational structure.

Vendor relationships.

Technology platforms.

Business processes.

Employee behavior.

Escalation procedures.

Historical incidents.

Internal projects.

Security discussions.

Even when obvious personal information is removed, organizational knowledge can remain extraordinarily valuable.

That’s why companies shouldn’t think about email security only as:

“Prevent someone from reading today’s inbox.”

A compromised Microsoft 365 environment may expose years of corporate memory.

Law Firms Should Be Extremely Careful

Imagine this principle applied to a law firm.

Years of internal email and Teams messages could contain:

Litigation strategy.

Client discussions.

Negotiation approaches.

Privileged information.

M&A activity.

Personnel matters.

Investigations.

Even where legal and ethical rules impose substantial restrictions on transferring or using such information, the underlying lesson remains:

Corporate communications can become enormously valuable datasets.

Law Firm IT needs retention, classification and access controls designed around that reality.

Healthcare Has an Even Higher Bar

Healthcare organizations face HIPAA and other privacy obligations that make sensitive patient information fundamentally different from ordinary corporate communications.

But they also generate massive quantities of operational data.

Internal workflows.

Scheduling communications.

Billing processes.

IT tickets.

Administrative conversations.

AI makes previously mundane operational information potentially valuable.

Healthcare IT teams therefore need clear data classification.

What is PHI?

What is employee information?

What is operational data?

Who owns it?

How long is it retained?

Who can use it?

Could it ever be provided to an AI system?

“It’s internal” is no longer a sufficient data classification.

Schools Should Think About This Too

Schools increasingly generate enormous digital archives.

Email.

Google Workspace.

Microsoft 365.

Student systems.

Staff chats.

Learning platforms.

Documents.

Recordings.

AI tools.

School Technology leaders need policies covering not merely storage and cybersecurity, but future use.

Especially when student information or employee communications are involved.

Employees Need to Understand One Brutal Rule

Don’t use company systems as if they’re personal systems.

Your corporate email account isn’t your diary.

Teams isn’t your private living room.

Slack isn’t disappearing conversation.

Your work laptop isn’t your personal computer.

That doesn’t mean employees should be paranoid.

It means they should understand the environment they’re communicating in.

If something is deeply personal and unrelated to work, don’t put it in the corporate archive unnecessarily.

Because corporate information can survive:

Your resignation.

Your termination.

Your manager.

The CEO.

An acquisition.

And apparently:

The company itself.

Businesses Need an AI Data Governance Policy Now

This shouldn’t wait until bankruptcy.

Every organization adopting AI should answer:

What corporate information may be submitted to AI systems?

Which AI vendors are approved?

Can vendors train on our information?

How long do they retain prompts?

Are employee communications included?

What happens to uploaded documents?

Can confidential information be used?

Can customer information be used?

Who approves new AI tools?

What happens when an employee leaves?

And critically:

What rights exist over our data if the vendor—or we—cease operations?

This is becoming part of cybersecurity and data protection.

Your MSP shouldn’t merely secure where your data lives.

Organizations increasingly need to understand where their data can go.

The $10 Million Lesson

Spirit’s wind-down began in May 2026 after years of financial problems.

But its digital history didn’t disappear when the airplanes stopped flying.

Google looked at that history and reportedly saw enough potential value to offer:

$10,000,000.

Not primarily for passenger profiles.

Not for a pile of old laptops.

For internal business information and software that could help develop products and train AI.

That’s the part every executive should understand.

Your organization’s emails, chats, documents and workflows aren’t merely records anymore.

Collectively, they may represent a model of how your company operates.

And models of how humans actually perform work are becoming extremely valuable in the AI economy.

So before you hit Send on the next Teams message, remember something uncomfortable:

The company may eventually disappear.

Your message might not.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ArtificialIntelligence #DataPrivacy #DataProtection #ManagedIT


Spirit Airlines died. Its employees’ emails didn’t. Google just bid $10 million for them.

Cybersecurity
Technology

Iranian Hackers Just Turned Off a British Power Plant

August 25, 2026
•
20 min read

Iranian Hackers Just Turned Off a British Power Plant

The hackers didn’t steal the data. They stopped the machine.

For years, we’ve talked about cyberattacks as though the worst thing that can happen is somebody stealing your information.

Your passwords get stolen.

Your customer database gets leaked.

Your files get encrypted.

Your credit card gets compromised.

But there’s another category of cyberattack that should make every business owner considerably more uncomfortable:

The computer gets hacked—and something in the physical world stops working.

That reportedly just happened in Britain.

Iran-linked hackers successfully forced a small British energy facility offline for four days, according to reporting this weekend.

Employees reportedly spent those four days getting the facility operational again.

The plant hasn’t been publicly identified.

The exact vulnerability hasn’t been disclosed.

And British officials say the facility was small enough that the attack never threatened the country’s overall electricity supply.

That’s reassuring.

But don’t miss what actually happened.

Someone sitting behind a computer reportedly reached across the internet and stopped an energy facility from operating.

This Wasn’t a Nationwide Blackout

That’s important.

Some headlines make this sound as though Iranian hackers nearly turned Britain’s lights off.

That’s not what the available reporting says.

A government source characterized the affected generator as extremely small relative to overall grid capacity, and the government says there was “at no point” a risk to the wider British energy system.

So this wasn’t:

London goes dark.

Hospitals lose electricity.

Millions of homes lose power.

The national grid collapses.

But cybersecurity professionals shouldn’t dismiss the incident because it was small.

In some ways, the small scale is what makes it interesting.

You Don’t Test a Capability on the Biggest Target First

We don’t yet know the attackers’ actual objective, so this part is important to distinguish from the reported facts.

But from a cybersecurity perspective, a smaller facility can be an attractive target.

Why?

Potentially weaker security.

Older operational technology.

Fewer cybersecurity personnel.

Legacy remote-access systems.

Less sophisticated monitoring.

Third-party vendors.

Equipment designed decades before anyone imagined connecting it to the internet.

An attacker doesn’t necessarily begin by trying to shut down an entire national grid.

They may begin by proving:

Can we get in?

Can we reach operational systems?

Can we manipulate them?

Will anyone detect us?

Can we force the operator to shut something down?

Those answers can be extraordinarily valuable.

The Difference Between IT and OT

This story is a perfect example of something businesses increasingly need to understand.

IT is Information Technology.

Laptops.

Email.

Microsoft 365.

Servers.

Databases.

Applications.

OT is Operational Technology.

These are computers controlling physical processes.

Pumps.

Valves.

Generators.

Motors.

Production equipment.

HVAC systems.

Industrial machinery.

Water treatment systems.

Electrical infrastructure.

Building automation.

When someone compromises IT, information can disappear.

When someone compromises OT:

Things can move.

Things can stop.

Pressure can change.

Production can halt.

Buildings can become unusable.

And in extreme environments, people can get hurt.

This Is Why Critical Infrastructure Is Such an Attractive Target

Imagine trying to pressure another country using conventional military force.

Aircraft.

Missiles.

Ships.

Personnel.

Logistics.

Enormous expense.

Enormous geopolitical consequences.

Now compare that with cyber operations.

A relatively small team may potentially probe thousands of organizations remotely.

Find exposed infrastructure.

Search for known vulnerabilities.

Steal credentials.

Compromise vendors.

Establish persistence.

Wait.

That’s what makes cyber capabilities so strategically valuable.

The attacker doesn’t necessarily need to destroy infrastructure.

Sometimes merely demonstrating that they can reach it changes the calculation.

The Timing Makes This More Interesting

The British incident reportedly occurred in July, around the same period as attacks against water and wastewater infrastructure across 12 U.S. states that were also linked in reporting to Iranian actors.

That doesn’t automatically prove every incident was coordinated by the same people.

But it reinforces a broader point.

Critical infrastructure is now part of the cyber battlefield.

Water.

Electricity.

Telecommunications.

Transportation.

Healthcare.

Manufacturing.

These aren’t hypothetical targets.

They’re networks.

And networks can be attacked.

Your Business Probably Has OT Too

This is where SMB owners tend to tune out.

They hear:

“Iran hacked a British power plant.”

Interesting story.

Nothing to do with me.

Except many businesses have their own miniature versions of operational technology.

Your building may have:

Internet-connected HVAC.

Door-access systems.

Security cameras.

Elevators.

Lighting controls.

Generators.

Environmental monitoring.

Manufacturing equipment.

Warehouse systems.

Refrigeration.

Building management systems.

Network-connected controllers.

And there’s one question I love asking:

Who is responsible for securing them?

IT?

Facilities?

The HVAC company?

The electrician?

The alarm company?

Your MSP?

The equipment manufacturer?

Nobody?

That last answer appears far too often.

Please Stop Putting Industrial Equipment Directly on the Internet

This should be basic cybersecurity hygiene.

If a piece of equipment doesn’t need to be publicly accessible from the internet:

Don’t expose it.

Operational systems should be segmented.

Remote access should be tightly controlled.

Default passwords should be removed.

MFA should be used wherever technically possible.

Vendor accounts should be reviewed.

Unused services should be disabled.

Firmware should be maintained.

Logs should be collected.

Internet-facing devices should be inventoried.

Backups of critical configurations should exist.

And businesses should know how to operate manually when automation disappears.

That last one matters enormously.

Ask Yourself One Uncomfortable Question

Suppose your building automation system stopped working tomorrow.

Not forever.

Four days.

What happens?

Can you still enter the building?

Can employees work?

Does refrigeration continue?

Does manufacturing stop?

Can you control HVAC?

Can doors be opened manually?

Can alarms function independently?

Can equipment be operated locally?

Do you even know who to call?

Cybersecurity resilience isn’t merely preventing an attacker from getting in.

It’s knowing how the business operates after they do.

Network Segmentation Can Turn a Disaster Into an Annoyance

Imagine a manufacturing company.

Its office computers and production equipment all sit on essentially the same flat network.

Someone compromises an employee laptop.

Now the attacker begins moving laterally.

Production controllers are reachable.

Security cameras are reachable.

Building systems are reachable.

Servers are reachable.

Backups are reachable.

One compromised employee becomes a company-wide problem.

Now imagine proper segmentation.

Employee computers live here.

Servers live here.

Production equipment lives here.

Security cameras live here.

Building automation lives here.

Guest Wi-Fi lives somewhere completely separate.

Traffic between those environments is tightly controlled.

The attacker compromises the same laptop.

But now:

The walls matter.

Segmentation doesn’t magically prevent cyberattacks.

It prevents one cyberattack from automatically becoming everybody’s problem.

Vendor Remote Access Is a Huge Blind Spot

This deserves special attention.

Operational equipment often needs maintenance.

So the installer says:

Don’t worry. We can remote into it if anything breaks.

Wonderful.

Now ask:

How?

What remote-access product?

Whose account?

Is MFA enabled?

Is the account shared?

Does the vendor have permanent access?

Can you see when they connect?

Is access restricted to their equipment?

When was the password last changed?

What happens when one of their employees leaves?

Does your MSP even know this connection exists?

Businesses routinely secure their own employees while leaving a permanent digital side door open for a vendor.

Attackers know that too.

Healthcare Should Pay Particular Attention

Healthcare IT doesn’t exist entirely in laptops and servers.

Modern healthcare environments contain enormous amounts of connected technology.

Building controls.

Medical devices.

Imaging systems.

Environmental controls.

Access systems.

Pharmacy systems.

Network-connected equipment.

A cyberattack doesn’t have to steal patient records to become an emergency.

If technology affects the delivery of care, availability becomes a cybersecurity issue.

Healthcare organizations need downtime procedures that assume certain technology simply won’t work.

Not for ten minutes.

For days.

Schools Have the Same Problem

Schools increasingly contain connected:

Door systems.

Cameras.

HVAC.

PA systems.

Phones.

Digital signage.

Attendance systems.

Network infrastructure.

Classroom technology.

A cyberattack against a school isn’t merely a data-protection issue.

It can become an operations problem very quickly.

School Technology teams need to know which systems are critical, which networks they’re connected to and how the building functions if those systems become unavailable.

SMB Manufacturers Should Be Extremely Careful

Manufacturing is where the IT/OT distinction becomes particularly dangerous.

Production equipment may last:

10 years.

20 years.

30 years.

Sometimes longer.

The machine may still work perfectly.

The operating system controlling it may be ancient.

That’s a cybersecurity nightmare.

You can’t simply tell the owner:

“Replace the $900,000 machine because Windows is old.”

Instead, cybersecurity architecture becomes critical.

Isolate it.

Restrict communication.

Monitor it.

Control remote access.

Prevent unnecessary internet connectivity.

Limit who can reach it.

Assume it cannot defend itself.

Legacy equipment needs modern protection around it.

Have a Manual Mode

One detail from recent attacks on critical infrastructure keeps coming back to the same lesson:

Manual operations matter.

If automation fails, can humans continue?

Businesses have become extraordinarily dependent on technology.

That’s efficient.

Until the technology disappears.

Your incident-response planning should include:

How do we operate without this system?

Print the procedure.

Don’t store the only copy on the server that just got encrypted.

Keep emergency contacts somewhere accessible.

Know how to disconnect critical equipment.

Know how to restore configurations.

Know who has authority to shut something down.

And practice it.

Four Days Is a Long Time

Think about your own business.

Imagine your core operational system disappeared tonight.

Tomorrow: unavailable.

Day two: unavailable.

Day three: unavailable.

Day four: still unavailable.

Payroll.

Orders.

Phones.

Email.

Production.

Customer records.

Scheduling.

Building access.

What starts breaking?

That’s the exercise I want SMB owners to perform.

Not:

“Could Iran hack my company?”

That’s the wrong question.

Ask:

“What technology could shut my business down for four days?”

Then protect that technology accordingly.

Cybersecurity Is No Longer About Protecting Computers

That’s the larger lesson.

Twenty years ago, cybersecurity largely meant protecting information stored on computers.

Today computers control the physical world.

Electricity.

Water.

Factories.

Hospitals.

Buildings.

Transportation.

Communications.

Supply chains.

When those computers are compromised, the consequences don’t necessarily stay inside the computer.

According to the current reporting, this particular attack involved a small British generator and never threatened the national power supply.

Good.

But somebody reportedly still demonstrated that they could turn a functioning energy facility into a nonfunctioning one for four days.

That’s the line businesses should pay attention to.

The next cyberattack may not steal your data.

It may simply turn off the thing your business cannot operate without.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #CriticalInfrastructure #ManagedIT #DataProtection #CyberAttack


Iranian hackers didn’t steal files from this power plant. They turned the plant off—for four days.

Previous
Next
About
Managed ServicesCybersecurityOur ProcessWho We AreNewsPrivacy PolicyTerms & Conditions
Help
FAQsContact UsSubmit a Support Ticket
Social
LinkedIn link
Twitter link
Facebook link
Have a Question?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Copyright © {auto update year} Gigabit Systems All Rights Reserved.
Website by Klarity
Gigabit Systems Inc. BBB Business Review