<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[SMB Tech & Cybersecurity Leadership Newsletter]]></title><description><![CDATA[Practical weekly cybersecurity guidance that helps SMB owners and leaders reduce risk, make confident decisions, and turn security priorities into action.]]></description><link>https://substack.cpf-coaching.com</link><image><url>https://substackcdn.com/image/fetch/$s_!YfY-!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc0ea6f9-9832-41d8-9807-cbdc9be949f0_640x640.png</url><title>SMB Tech &amp; Cybersecurity Leadership Newsletter</title><link>https://substack.cpf-coaching.com</link></image><generator>Substack</generator><lastBuildDate>Sun, 23 Aug 2026 07:17:36 GMT</lastBuildDate><atom:link href="https://substack.cpf-coaching.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Christophe Foulon]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[info@cpf-coaching.com]]></webMaster><itunes:owner><itunes:email><![CDATA[info@cpf-coaching.com]]></itunes:email><itunes:name><![CDATA[Christophe Foulon 📓]]></itunes:name></itunes:owner><itunes:author><![CDATA[Christophe Foulon 📓]]></itunes:author><googleplay:owner><![CDATA[info@cpf-coaching.com]]></googleplay:owner><googleplay:email><![CDATA[info@cpf-coaching.com]]></googleplay:email><googleplay:author><![CDATA[Christophe Foulon 📓]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[When Trusted Systems Outrun Review: Control Systems, Biometrics, and Private AI]]></title><description><![CDATA[This week's SMB risk briefing covers CISA's Siemens S7 PLC threat warning, the ICO's facial-recognition governance findings, and OpenAI's new zero-data-retention model path, with practical actions, a template, a checklist, and premium implementation guidance.]]></description><link>https://substack.cpf-coaching.com/p/smb-risk-briefing-secure-control</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/smb-risk-briefing-secure-control</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 21 Aug 2026 13:11:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6FdJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If your business still treats industrial control risk, biometric privacy, and enterprise AI privacy as separate conversations, this week offers a better frame. On Tuesday, August 18, 2026, the UK&#8217;s Information Commissioner&#8217;s Office said strong data protection governance is essential to public trust as facial recognition expands. One day later, on Wednesday, August 19, CISA, the NSA, the FBI, the Department of Energy, and the EPA warned that threat actors are actively targeting Siemens S7 Series PLCs, including with AI-generated exploitation scripts disguised as legitimate monitoring tools. Later that same day, OpenAI announced Zero Data Retention for frontier models and previewed Private Safety Processing so eligible customers can use more capable models without keeping the underlying prompts and responses after processing.</p><p>Those signals belong in one briefing because they describe the same leadership problem. Trusted systems are acting before operators can always explain the boundary. A controller can run production, water, facilities, or warehouse logic while sitting one weak access path away from the public internet. A facial recognition or biometric matching workflow can shape how people are treated long before the governance record is mature enough to defend it. And an AI workflow can become genuinely useful only after it touches sensitive information, internal tools, or approved actions, which means privacy architecture stops being a back-office detail and becomes part of the operating model.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6FdJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6FdJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!6FdJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!6FdJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!6FdJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6FdJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:125953,&quot;alt&quot;:&quot;Infographic-style editorial header for SMB leaders with a deep navy background and three labeled panels: Secure exposed control systems, Govern biometric trust, and Keep AI private while it acts. Amber, coral, and cyan accents group the PLC threat, facial recognition governance, and private AI execution signals with short action chips under each panel.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/211971634?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infographic-style editorial header for SMB leaders with a deep navy background and three labeled panels: Secure exposed control systems, Govern biometric trust, and Keep AI private while it acts. Amber, coral, and cyan accents group the PLC threat, facial recognition governance, and private AI execution signals with short action chips under each panel." title="Infographic-style editorial header for SMB leaders with a deep navy background and three labeled panels: Secure exposed control systems, Govern biometric trust, and Keep AI private while it acts. Amber, coral, and cyan accents group the PLC threat, facial recognition governance, and private AI execution signals with short action chips under each panel." srcset="https://substackcdn.com/image/fetch/$s_!6FdJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!6FdJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!6FdJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!6FdJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33ea45c-4b79-427f-94f5-5c8dcea489f9_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Three trust boundaries this week for SMB leaders: exposed control systems, biometric governance, and private AI execution.</figcaption></figure></div><p>Get one concise SMB risk briefing each week, with practical leadership actions and reusable security guidance. Join free, or upgrade for implementation templates and premium guidance.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>1. Control Systems Still Fail at the Exposure Boundary</h2><p>On August 19, 2026, CISA and partner agencies released an advisory warning of an active cyber threat to Siemens S7 Series PLCs. The advisory says threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations, including by using AI-generated exploitation scripts disguised as legitimate monitoring tools. It also says organizations should inventory Siemens S7 Series PLCs, apply critical patches, keep PLCs off the internet, strengthen access controls, harden services and ladder logic integrity, and hunt for anomalies that may indicate compromise.</p><p><strong>Why you should be concerned:</strong> Many SMB operators still assume industrial or building control paths are niche technical infrastructure rather than business execution surfaces. That is a mistake. If a reachable controller can start, stop, meter, unlock, dose, vent, route, or report, then it holds operational authority whether the business sees it that way or not. You do not need to run a giant industrial footprint for this to matter. Warehouses, food and beverage facilities, manufacturing lines, building systems, utilities, and integrator-managed environments all create places where weak exposure becomes business leverage.</p><p><strong>Strategic action:</strong> Treat every reachable control system as privileged infrastructure. The right question this week is not &#8220;Do we think we use Siemens?&#8221; It is &#8220;Which control paths in this business still hold real authority, and what proof exists that they are patched, monitored, and isolated appropriately?&#8221;</p><p>Three steps to take this week:</p><ol><li><p>Confirm whether any Siemens S7 Series PLCs or similar control devices still exist in your environment or in facilities managed by an integrator, landlord, vendor, or parent company.</p></li><li><p>Verify patch status, internet reachability, and remote-access control for every controller that can influence physical operations or continuity.</p></li><li><p>Run one tabletop starting from a controller anomaly instead of a laptop alert: who would know first, what would be isolated first, and what proof would leadership demand in the first hour?</p></li></ol><blockquote><p>Partner resource: <strong><a href="https://chipscyberdefensesolutionsllc.sjv.io/c/4968983/3881772/52169">CHIPS Cyber Defense Solutions, LLC</a></strong> is a practical fit when you need outside help reducing ransomware and operational technology risk before one exposed path becomes a wider business event. </p><p><em><sub>Affiliate note: CPF Coaching may earn a commission if you choose to use it.</sub></em></p></blockquote><h2>2. Biometric Trust Still Fails at the Governance Boundary</h2><p>On August 18, 2026, the UK&#8217;s Information Commissioner&#8217;s Office said strong data protection governance is essential to public trust as facial recognition expands. After proactively auditing five police forces, the ICO said it found inconsistencies in data protection compliance and that significant improvements are still needed. The office framed safeguards, oversight, accountability, and lawful, proportionate use as the conditions for maintaining trust.</p><p><strong>Why you should be concerned:</strong> Many SMB leaders will read that and think it applies only to public-sector policing. That would miss the real lesson. The more a workflow identifies, categorizes, or influences people through faces, biometrics, or sensitive automated judgment, the more the governance story matters. Visitor management, workforce identity checks, customer verification, physical-access systems, AI-driven watchlist matching, and even certain fraud or safety workflows can all slide into a higher-trust zone faster than the evidence trail catches up.</p><p><strong>Strategic action:</strong> Treat sensitive identification systems like formal governance workflows, not clever features. If a system influences how a person is admitted, flagged, challenged, or trusted, then the business needs a named owner, a lawful-use record, a reviewable accuracy story, a retention story, and a clear escalation path when the system is wrong.</p><p>Three steps to take this week:</p><ol><li><p>Inventory every workflow that uses face, identity, or other sensitive matching logic, even if it is embedded inside a vendor platform.</p></li><li><p>Record who owns the lawful basis, the notice, the data source, the retention rule, and the manual review point for that workflow.</p></li><li><p>Save one evidence packet this week showing what the system does, what users are told, how long the data stays, and who can override or stop the decision path.</p></li></ol><div class="callout-block" data-callout="true"><p><strong>Sponsor spotlight: Noted.Solutions</strong></p><p>If this week&#8217;s issue has you thinking less about tools and more about how to explain controls, trust, and evidence clearly, <a href="https://payhip.com/b/jRqmr/af6a55810a9404f">Noted.Solutions </a>is a strong fit. Its GRC and RegTech resources help compliance-minded teams sharpen messaging around safeguards, buyer trust, and stakeholder communication.</p><p><a href="https://payhip.com/b/jRqmr/af6a55810a9404f">Explore Noted.Solutions</a></p><p><sub>Affiliate note: CPF Coaching may earn a commission if you choose to use it.</sub></p></div><p></p><h2>3. Production AI Now Needs a Privacy Architecture, Not Just a Policy Slide</h2><p>On August 19, 2026, OpenAI announced Zero Data Retention for frontier models and previewed Private Safety Processing. OpenAI said eligible API customers can process prompts and responses without retaining the content after the request is handled, while Private Safety Processing aims to identify suspicious patterns across related interactions without OpenAI personnel seeing the underlying content. The larger leadership takeaway is not just that privacy got better. It is that retention design, safety controls, and execution design are now part of the adoption decision for real production AI.</p><p><strong>Why you should be concerned:</strong> Many SMB teams still evaluate AI tools mostly on output quality, price, and enthusiasm. That is no longer enough. Once a workflow reads sensitive data, drafts externally visible content, or takes approved action in business systems, the privacy and safety architecture becomes part of the operating model. If the retention promise is vague, the escalation rules are informal, or the disable path is missing, the business is still scaling trust faster than it is scaling control.</p><p><strong>Strategic action:</strong> Promote AI by architecture, not by novelty. If a workflow is valuable enough to touch sensitive context or do meaningful work, then its retention model, safety review logic, action boundaries, and rollback path need to be clear before it reaches routine use.</p><p>Three steps to take this week:</p><ol><li><p>Classify each live AI workflow by what it may read, what it may send or change, and whether the underlying prompts or outputs are retained.</p></li><li><p>Require one documented escalation rule and one documented disable path before any workflow takes approved action in customer, financial, or operational systems.</p></li><li><p>Review whether your highest-value AI workflow should stay in recommend mode, move to draft-and-review, or be held back until the privacy and safety architecture is clearer.</p></li></ol><div class="pullquote"><p>Partner resource: <strong><a href="https://base44.pxf.io/c/4968983/2049275/25619?trafcat=base">Base44</a></strong> is worth evaluating when you need a faster way to turn policy and approval requirements into scoped internal tools, forms, or workflows, rather than letting ad hoc AI sprawl define the process. </p><p><em><sub>Affiliate note: CPF Coaching may earn a commission if you choose to use it.</sub></em></p></div><h3>Final Thoughts</h3><p>This week is about trusted systems acting before operators can explain the boundary. A control system should not be easily reachable. A biometric workflow should not rely on implied governance. And a production AI workflow should not scale on the assumption that privacy can be solved after adoption.</p><p>If you only do one thing before next week, list the systems in your business that can execute, identify, or act on the company&#8217;s behalf. Then name one owner for containment, one owner for trust evidence. </p><p><strong>Sharing is caring</strong></p><p>Share this issue with another SMB leader who needs a clearer trust boundary around exposed systems, sensitive data, or production AI, and one owner for approval before the workflow grows any further.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/smb-risk-briefing-secure-control?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/smb-risk-briefing-secure-control?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p><strong>Why not subscribe</strong></p><p>Join leaders who want practical implementation guidance and reusable control templates, not just headlines, when technology risk starts acting like operations.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/smb-risk-briefing-secure-control">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Stop Wasting Budget on Inherited SOC 2 Controls]]></title><description><![CDATA[Map your cloud responsibilities, leverage CUECs, and accelerate your Type II assessment timeline.]]></description><link>https://substack.cpf-coaching.com/p/stop-wasting-budget-on-inherited</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/stop-wasting-budget-on-inherited</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 16 Aug 2026 23:27:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ovfL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41bb097a-2a0c-4339-95b5-b787d710d1fb_1024x696.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Which SOC 2 Controls Do You Actually Own?</h1><p>Many SOC 2 readiness projects assume the company is responsible for every control. This approach often leads to unnecessary costs and can be avoided with prop&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/stop-wasting-budget-on-inherited">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This Week's SMB Risk Signals: Patch the VPN Edge, Audit Broker Data, and Tier AI Work]]></title><description><![CDATA[Gunra ransomware, California's first Delete Act case, and premium AI seats all point to one leadership move: assign owners to the hidden systems scaling behind daily work.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch-4c1</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch-4c1</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 14 Aug 2026 13:45:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!c3uL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On August 10, 2026, U.S. and allied agencies published a joint <code>#StopRansomware</code> advisory on Gunra, a ransomware-as-a-service operation that is exploiting internet-facing VPN and firewall weaknesses, stealing data, and then encrypting systems. On August 11, 2026, California privacy regulators announced their first enforcement action under both the CCPA and the Delete Act after a data broker was fined and ordered to change how it handled Californians&#8217; opt-out rights. One day earlier, OpenAI announced Premium seats for ChatGPT Business, which effectively turns heavy AI usage into a more explicit capacity, budget, and governance decision for smaller teams.</p><p>These stories sit in different lanes, but they point to the same management problem. The highest-risk systems in many SMBs now live just outside the main workflow: remote access edges, broker-fed data flows, and shared AI workspaces. If those systems scale faster than ownership, your team can lose control long before anyone feels like they made a &#8220;big&#8221; strategic decision</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c3uL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c3uL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!c3uL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!c3uL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!c3uL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c3uL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:231706,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/211008714?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c3uL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!c3uL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!c3uL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!c3uL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe211ed10-a9a3-4c2d-b257-3ab5a655e7ec_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>.1. Gunra Shows Why Your VPN Edge Is Still a Ransomware Door</p><p>Gunra matters because it is not just another named ransomware family. The August 10 advisory says the group has operated as a formal ransomware-as-a-service program since January 2026, targets organizations across sectors, and prioritizes known weaknesses in internet-facing devices, especially VPN and firewall infrastructure. The same advisory says Gunra actors exfiltrate data before encryption, move laterally with SMB and RDP activity, and have pushed victims into ransom negotiations that start in the tens of millions of dollars.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>This starts where lean teams often defer maintenance:</strong> The advisory says agencies observed Gunra exploiting known vulnerabilities in internet-facing devices, including FortiOS and FortiProxy authentication-bypass flaws.</p></li><li><p><strong>The attack path is operational, not abstract:</strong> Agencies documented use of <code>psexec.py</code>, <code>smbclient.py</code>, session hijacking, modified authentication files, and data theft from OneDrive and SharePoint before encryption.</p></li><li><p><strong>The blast radius is designed to expand fast:</strong> The advisory says victims have spanned healthcare, finance, manufacturing, transportation, government, retail, and professional services, which is a reminder that SMB adjacency does not keep you out of scope.</p></li></ul><p><strong>Strategic Action:</strong> Treat the VPN edge, remote admin tooling, and every exposed authentication layer as a privileged execution surface, not a background utility. The first question for leadership is no longer &#8220;Are we patched eventually?&#8221; It is &#8220;Who proves every externally reachable access path was reviewed this week?&#8221;</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Get a named answer on every internet-facing VPN, firewall, remote desktop, and MSP-managed access path your business depends on.</p></li><li><p>Require proof of patch state and exception state for known exploited flaws, not just a generic claim that devices are &#8220;current.&#8221;</p></li><li><p>Ask how your team would detect SMB/RDP lateral movement and pre-encryption exfiltration if the edge was already compromised.</p></li></ol><div class="pullquote"><p>For SMBs that need tighter endpoint containment when a compromised edge gives an attacker room to move, <strong><a href="https://get.bitdefender.com/ltjvkcuvgy0t-comparison">Bitdefender</a></strong> is a practical fit for improving device-level detection, isolation, and response while you validate remote-access and post-compromise controls.</p><p><sub>Affiliate sponsor</sub></p></div><h2>2. California Just Proved the Delete Act Has Teeth</h2><p>California&#8217;s August 11 action against LocateSmarter matters because it shows data broker compliance is no longer a theoretical future obligation. The California Privacy Protection Agency said LocateSmarter must pay <code>$116,490</code> and change its practices after failing to register on time as a data broker and requiring Californians to provide partial Social Security numbers before they could opt out. The agency also reiterated that, beginning August 1, 2026, data brokers must access the Delete Request and Opt-Out Platform, or DROP, at least once every 45 days and process deletion requests, subject to limited exceptions.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Privacy friction is now an enforcement issue:</strong> Regulators said requiring the last four digits of a Social Security number before an opt-out could intimidate consumers and violate data minimization requirements.</p></li><li><p><strong>One request can now ripple through the broker ecosystem:</strong> California&#8217;s DROP system gives residents one mechanism to direct every covered data broker to delete personal information.</p></li><li><p><strong>Inherited data trails are a leadership problem:</strong> If your CRM, outbound engine, or enrichment stack still depends on bought or broker-fed data, you now need a credible way to trace source, suppression, and deletion proof.</p></li></ul><p>I recognize that many SMB teams did not deliberately design a broker-heavy data estate. They inherited it through old outbound experiments, agency relationships, enrichment tools, and sync jobs that kept running. That is exactly why this topic deserves executive attention now. Hidden data lineage is still data liability.</p><p><strong>Strategic Action:</strong> Inventory where outside personal data enters the business, who can authorize its use, and how a deletion or opt-out request would propagate through your vendor chain. If nobody can produce that map quickly, the business is still relying on a blind spot.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>List every source in your CRM, outbound stack, and marketing tools that did not come directly from first-party customer action.</p></li><li><p>Flag which feeds came from a broker, enrichment vendor, list purchase, or reseller relationship.</p></li><li><p>Assign one owner for deletion proof and one owner for contract review, then make them compare the same source list this week.</p></li></ol><blockquote><p><strong>IF YOU CANNOT TRACE THE DATA BROKER TRAIL, YOU CANNOT DEFEND IT</strong></p><p>California&#8217;s first Delete Act enforcement action is a reminder that broker-fed data now carries operational obligations, not just marketing upside. The weak point for many SMBs is not the policy page. It is the quiet vendor chain behind the customer database.</p><p><strong>Optery</strong> is a strong fit when you need to reduce personal-data exposure, remove records from broker ecosystems, and shrink the amount of discoverable information already circulating about executives and staff.</p><p><strong>Reduce the exposed trail. <a href="https://get.optery.com/s7rzum1ei7dw">See Optery</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><h2>3. Premium AI Seats Turn Experimentation Into Budgeted Operations</h2><p>OpenAI&#8217;s August 10 Premium seats announcement matters because it makes heavy AI usage look less like an informal perk and more like a managed operating lane. OpenAI says Premium seats for ChatGPT Business provide <code>5x</code> more usage than Standard, remove the five-hour usage limit, and let workspace owners mix Standard and Premium seats inside one secure Business workspace. OpenAI also says Premium seats cost <code>$125</code> per user per month, or <code>$100</code> annually, and that eligible early customers can receive <code>$100</code> in workspace credits per Premium seat for up to five seats.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Higher-capacity AI is becoming a seat-allocation decision:</strong> Once you can mix lighter and heavier usage tiers inside one workspace, somebody has to decide who gets which capacity and why.</p></li><li><p><strong>Shared usage is now a budget question:</strong> Premium pricing, credits, and higher limits shift AI from vague experimentation into a spend-managed team resource.</p></li><li><p><strong>The administrative surface is broadening:</strong> Owners and admins can now reassign seats, monitor usage, and manage billing and spend in one place, which means your governance model needs to mature with the tool.</p></li></ul><p><strong>Strategic Action:</strong> Stop treating business AI as if cost, access, and workflow approval will sort themselves out later. Name an owner for seat allocation, usage review, and approved high-value workflows before the team normalizes expensive or sensitive patterns by habit.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Decide which roles in your business truly need higher-capacity AI access and which do not.</p></li><li><p>Define what evidence a team member must show before moving from a standard seat to a premium seat.</p></li><li><p>Add one monthly review for AI seat allocation, high-value workflows, usage spikes, and exception approvals.</p></li></ol><h3>Final Thoughts for Leaders</h3><p>This week&#8217;s signals all point to the same leaSharing is caring</p><p>If this week&#8217;s framing would help another operator or owner, use the native share and referral tools below before the premium section.dership lesson: the systems around your core workflow now deserve named owners before they deserve more scale. Your VPN edge can open the door to a ransomware operator. Your broker-fed data can trigger deletion and minimization duties you are not prepared to prove. Your AI workspace can become a shared budget and policy surface without anyone explicitly taking responsibility for it.</p><p>Put one item on your next executive agenda: list the background systems in your business that can grant access, import outside personal data, or consume shared AI capacity, and assign the owner for each one before next Thursday.</p><p>If another operator on your team needs this framing, use the share and referral tools below before the premium section.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>If you want the implementation pack, ownerWhy not Subscribe</p><p>Paid subscribers get the implementation pack, owner register, checklist, and exercise for this week&#8217;s issue. register, checklist, and tabletop exercise below, the subscribe prompt is the fastest route into the premium section.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch-4c1?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch-4c1?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p>Paid subscribers this week get a backgrounPremium Intelligence: The Background Systems Control Pack</p><p>Welcome, premium subscribers. This week&#8217;s implementation pack is designed for leaders who need to govern the systems that sit behind the frontstage workflow but still carry real operational authority. The goal is to make those systems visible enough to assign ownership, budget, and interruption rules before they become emergency-response problems.</p><h2>1. Gunra Deep Dive: Build an Edge-First Ransomware Response Assumption</h2><p><strong>Technical Detail:</strong> The August 10 joint advisory says Gunra first emerged in April 2025, expanded through a formal ransomware-as-a-service affiliate program in January 2026, and has been observed exploiting known vulnerabilities in internet-facing devices, including <code>CVE-2024-55591</code> and <code>CVE-2025-24472</code> in FortiOS and FortiProxy environments. Agencies also documented SMB-based lateral movement, session hijacking, modifications that bypassed MFA, credential dumping, and exfiltration from Microsoft OneDrive and SharePoint before encryption.</p><ul><li><p><strong>Prioritize the exposed path, not the average server:</strong> Patch and prove the state of every externally reachable VPN, firewall, remote desktop, and vendor-managed edge first.</p></li><li><p><strong>Collect edge evidence weekly:</strong> Save screenshots, version exports, open exception tickets, and logs tied to who approved any delay.</p></li><li><p><strong>Define a post-compromise branch:</strong> If the edge is already assumed hostile, document how you detect lateral movement, isolate endpoints, and decide when a vendor relationship becomes an incident-escalation issue.</p></li></ul><h2>2. Delete Act Deep Dive: Map the Broker Trail Before Requests Arrive</h2><p><strong>Technical Detail:</strong> California regulators said LocateSmarter both failed to register timely as a data broker and unlawfully required Californians to provide partial Social Security numbers before they could opt out. Separately, California&#8217;s DROP rules require data brokers to access the deletion mechanism at least once every 45 days and process consumer deletion requests, subject to limited exceptions.</p><ul><li><p><strong>Source map:</strong> Separate first-party data, partner-shared data, enrichment feeds, broker-sourced lists, and inherited legacy imports.</p></li><li><p><strong>Routing rule:</strong> Define who receives a deletion request internally, which vendors must be contacted, and where confirmation evidence is stored.</p></li><li><p><strong>Suppression control:</strong> Prevent deleted or opted-out records from being reintroduced by the same feed during the next sync cycle.</p></li></ul><h2>3. AI Seat Governance Deep Dive: Tier Usage Before Teams Normalize Spend</h2><p><strong>Technical Detail:</strong> OpenAI says Premium seats for ChatGPT Business provide <code>5x</code> more usage than Standard, remove the five-hour limit, support mixed seat tiers in the same workspace, and allow workspace owners to manage billing, usage, and spend in one place. OpenAI also says the limited-time promotion offers <code>$100</code> in workspace credits per Premium seat, up to five seats, for eligible early customers who join the waitlist by August 20, 2026.</p><ul><li><p><strong>Seat criteria:</strong> Document which roles qualify for heavier AI capacity and what business case must be shown.</p></li><li><p><strong>Promotion discipline:</strong> Do not let a short-term credit offer create long-term seat sprawl without ownership.</p></li><li><p><strong>Monthly review packet:</strong> Track who upgraded, why they upgraded, what workflows justified it, and whether the usage produced measurable value.</p></li></ul><blockquote><p><strong>AI CAPACITY NEEDS AN OWNER BEFORE IT NEEDS AN EXPANSION</strong></p><p>Once higher-capacity AI is available inside one shared workspace, the management challenge becomes seat policy, workflow approval, and data handling discipline rather than simple tool access.</p><p><strong>Airia</strong> is a practical fit when you need policy-aware AI orchestration, clearer approval lanes, and stronger governance over which workflows can touch sensitive data or shared spend.</p><p><strong>Govern the workload before it scales. <a href="https://try.airia.com/hanp3sdhtshf-az7nx">Explore Airia</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><h2>Premium Template: Background Systems Owner Register</h2><p>Use this register for any platform, vendor, or workflow that can grant access, ingest outside personal data, or consume shared AI capacity on the company&#8217;s behalf.</p><ul><li><p><strong>Background system:</strong> The exact platform, vendor lane, or workflow.</p></li><li><p><strong>Authority carried:</strong> What the system can do if left unchecked.</p></li><li><p><strong>Named owner:</strong> The person responsible for policy, review, and exceptions.</p></li><li><p><strong>Sensitive inputs:</strong> Credentials, regulated data, third-party records, contract text, pricing, payroll, or customer exports.</p></li><li><p><strong>Proof artifact:</strong> The report, screenshot, ticket, or acknowledgment that proves control worked.</p></li><li><p><strong>Stop condition:</strong> The event that forces a human checkpoint before the workflow continues.</p></li><li><p><strong>Review cadence:</strong> Weekly, monthly, or event-driven validation frequency.</p></li></ul><h2>Premium Checklist: Seven-Day Background Systems Review</h2><ul><li><p>&amp;#x2610; Confirm the patch and exception state for every internet-facing VPN, firewall, RMM, and remote desktop path in scope.</p></li><li><p>&amp;#x2610; Save one proof artifact showing who reviewed the edge this week.</p></li><li><p>&amp;#x2610; Inventory every outside-data source feeding CRM, outbound, enrichment, or paid targeting systems.</p></li><li><p>&amp;#x2610; Assign the internal owner for deletion proof and the owner for vendor-contract review.</p></li><li><p>&amp;#x2610; Document which team owns AI seat allocation, usage review, and exception approvals.</p></li><li><p>&amp;#x2610; Define which AI workflows are allowed to touch contracts, customer exports, regulated data, or payroll-related material.</p></li><li><p>&amp;#x2610; Publish a one-page owner map covering edge access, broker data, and AI capacity.</p></li></ul><h2>Premium Guide: Five-Day Background Systems Reset</h2><p><strong>Day 1: Identify the systems with quiet authority</strong></p><p>List every system that can open access, import third-party personal data, or consume shared AI capacity without another human checkpoint.</p><p><strong>Day 2: Name the owner and the proof</strong></p><p>For each system, assign the control owner and define the artifact that proves the control worked this week.</p><p><strong>Day 3: Test the interruption path</strong></p><p>Ask what happens when a critical edge advisory lands, a deletion request arrives, or a team asks for a premium AI seat. If the answer depends on informal memory, the process is not ready.</p><p><strong>Day 4: Tighten the boundary</strong></p><p>Pause unknown data feeds, close unowned access paths, and restrict high-risk AI workflows until the owner can explain the rule and the exception path.</p><p><strong>Day 5: Publish the owner register</strong></p><p>Put the system name, authority carried, owner, proof artifact, stop condition, and review cadence in one place leadership can actually use.</p><h2>Premium Exercise: The Background System Already Acted</h2><p><strong>Tabletop Exercise: Hidden Authority, Public Consequences</strong></p><ul><li><p>*Premise:* A VPN appliance misses a critical patch window, a customer asks where broker-sourced information about them came from, and a department requests multiple premium AI seats after normalizing higher-usage workflows.</p></li><li><p>*Exercise Goal:* Test whether the team can name the owner, produce the proof artifact, explain the stop condition, and decide who is authorized to interrupt the workflow.</p></li><li><p>*Use this exercise to:* expose where quiet systems already carry more business authority than leadership has explicitly governed.</p></li></ul><h2>Sources</h2><ul><li><p><a href="https://media.defense.gov/2026/Aug/10/2003976697/-1/-1/0/CSA_STOPRANSOMWARE_GUNRA_RANSOMWARE.PDF">Joint </a><code>#StopRansomware: Gunra Ransomware</code><a href="https://media.defense.gov/2026/Aug/10/2003976697/-1/-1/0/CSA_STOPRANSOMWARE_GUNRA_RANSOMWARE.PDF"> advisory, August 10, 2026</a></p></li><li><p><a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4567025/nsa-joins-fbi-and-others-in-releasing-guidance-to-defend-against-gunra-ransomwa/">NSA press release on the Gunra advisory, August 10, 2026</a></p></li><li><p><a href="https://privacy.ca.gov/2026/08/calprivacy-brings-first-action-against-a-data-broker-under-both-the-ccpa-and-delete-act/">CalPrivacy: first action under both the CCPA and Delete Act, August 11, 2026</a></p></li><li><p><a href="https://cppa.ca.gov/data_brokers/">California DROP requirements for data brokers</a></p></li><li><p><a href="https://openai.com/index/premium-seats-chatgpt-business/">OpenAI: Premium seats are coming to ChatGPT Business, August 10, 2026</a>d-systems owner register, a broker-trail cleanup checklist, an AI seat governance rubric, and a tabletop exercise built to expose who actually controls these quiet systems in your business.</p></li></ul><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="paywall-jump" data-component-name="PaywallToDOM"></div>]]></content:encoded></item><item><title><![CDATA[SMB Risk Briefing: Patch the AI Edge, Tighten the Data Story, and Modernize with Authority]]></title><description><![CDATA[Discover this week's top SMB risk signals. Learn why leaders must immediately patch IBM Langflow vulnerabilities, govern data reuse, and manage AI workflows.]]></description><link>https://substack.cpf-coaching.com/p/smb-risk-briefing-patch-the-ai-edge</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/smb-risk-briefing-patch-the-ai-edge</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sat, 08 Aug 2026 11:28:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!B5NJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2395e274-0a07-44c0-a5ce-ccbfde11c13d_1024x559.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you want a cleaner way to read this week, do not split the signals into separate piles called cyber, regulation, and AI. The more useful pattern is operational proof. On Monday, August 4, 2026, CI&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/smb-risk-briefing-patch-the-ai-edge">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Top 3 Unmanaged Risks Threatening Your SMB Right Now]]></title><description><![CDATA[Discover this week's top SMB risk signals. Learn why leaders must immediately secure MSP control planes, manage data broker deletion rules, and govern AI workflows.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 07 Aug 2026 13:43:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rbkt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On August 2, 2026, N-able published Hotfix 1 for N-central 2026.3 and warned that all N-central instances not running 2026.3.1 should upgrade immediately because of a security issue tied to CVE-2026-18577. One day earlier, California&#8217;s Delete Request and Opt-Out Platform, or DROP, moved into its live deletion phase, which means registered data brokers must start deleting Californians&#8217; personal information when valid requests arrive. On August 4, 2026, OpenAI&#8217;s Enterprise and Edu release notes said long pastes above 10,000 characters now become attachments, and remaining weekly role-based spend limits will automatically move to monthly limits on August 15.</p><p>These are not isolated product updates. They all describe systems that sit just outside day-to-day frontline work but still carry real authority: remote management layers, third-party data pipelines, and shared-pool AI workflows. If you are running a lean SMB team, the immediate leadership question is simple: who owns those control surfaces before they fail under pressure?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rbkt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rbkt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!rbkt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!rbkt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!rbkt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rbkt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:161319,&quot;alt&quot;:&quot;Infographic summarizing weekly SMB risk signals, including patching N-central MSP control planes, managing California DROP data broker deletion requests, and budgeting AI workflows for leadership accountability.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/210041648?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infographic summarizing weekly SMB risk signals, including patching N-central MSP control planes, managing California DROP data broker deletion requests, and budgeting AI workflows for leadership accountability." title="Infographic summarizing weekly SMB risk signals, including patching N-central MSP control planes, managing California DROP data broker deletion requests, and budgeting AI workflows for leadership accountability." srcset="https://substackcdn.com/image/fetch/$s_!rbkt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!rbkt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!rbkt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!rbkt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39e9abda-e13c-4ebf-abcb-fa324e1f06b1_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Weekly SMB Risk Signals:</strong> Essential leadership action items for securing remote management platforms, enforcing data privacy deletions, and governing shared AI workloads.</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>1. Your MSP Control Plane Can Become the Fastest Route Into Every Managed Endpoint</h2><p>N-central matters because it is not just another internal server. It is a remote monitoring and management platform that can touch downstream customer and employee devices at scale. N-able&#8217;s August 2 note said all N-central instances that are not already on 2026.3.1 should apply Hotfix 1 as soon as possible, and its investigation guidance specifically called out suspicious <code>svchost.exe</code>, <code>cloudflared.exe</code>, <code>psexec</code> activity, and inbound connections from listed IP addresses.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>The blast radius is wider than one box:</strong> The NVD entry for CVE-2026-18577 describes an authentication-bypass path that can lead to account takeover in N-central up through 2026.3.1, with a CVSS 8.2 base score.</p></li><li><p><strong>The vendor warning is operational, not theoretical:</strong> N-able said every instance not already on 2026.3.1 should upgrade immediately and supplied concrete triage indicators for administrators to investigate.</p></li><li><p><strong>Managed-service trust can flip into managed compromise:</strong> If your team or MSP uses a privileged control plane to push tools, scripts, or remote sessions, that platform effectively sits in your business&#8217;s administrative bloodstream.</p></li></ul><p><strong>Strategic Action:</strong> Treat every remote management server as a privileged identity and execution system. Your patch process for those tools should be faster than your normal server cadence, and your response plan should assume that compromise could spread through the same automation you usually trust.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Confirm whether your internal team or MSP runs N-central anywhere in your environment and whether the instance is already on 2026.3.1 with Hotfix 1.</p></li><li><p>Ask for proof of the review, not just verbal reassurance: patch evidence, admin-session review, remote-access logs, and any findings tied to the N-able indicators.</p></li><li><p>Freeze nonessential remote automation until the control plane owner confirms both patch state and downstream endpoint review.</p></li></ol><div class="pullquote"><p>For SMBs that need stronger endpoint containment when a remote-management layer goes sideways, <strong><a href="https://get.bitdefender.com/8gk9x38k25bv">Bitdefender</a></strong> is a practical fit for tightening device-level detection, isolation, and response while you verify whether administrative tooling has been misused.</p><p><sub>Affiliate sponsor</sub></p></div><h2>2. California&#8217;s Broker Deletion Rule Turned Data Resale Into a Live Operating Obligation</h2><p>California&#8217;s August 1 DROP milestone matters because it converts consumer privacy rights into an active business process. Attorney General Rob Bonta said Californians can submit one deletion request that reaches more than 500 registered data brokers, and his office said more than 225,000 Californians signed up in less than six weeks after launch. If your business buys enrichment data, lists, audience segments, or broker-sourced records, that is no longer just a marketing input. It is a workflow that can now generate deletion pressure at scale.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>The volume trigger is real:</strong> One validated request can fan out to hundreds of brokers at once, which means deletion, suppression, and proof duties can show up quickly across the vendor chain.</p></li><li><p><strong>Your vendor choices can become your privacy problem:</strong> Even if you are not a registered broker yourself, you can still be exposed if you rely on broker-fed lists or cannot explain how third-party data entered your stack.</p></li><li><p><strong>The rule rewards proof, not intent:</strong> When customers, regulators, or enterprise buyers ask where data came from and whether it was deleted, a good-faith answer without evidence is not enough.</p></li></ul><p><strong>Strategic Action:</strong> Inventory every place your business acquires personal data that did not come directly from the customer. Then decide who owns deletion routing, suppression lists, contract language, and the evidence trail when a vendor must prove a request was honored.</p><p>I recognize that many SMB operators inherited these data feeds from old demand-generation experiments, partner deals, or CRM migrations that still run quietly in the background. That inherited sprawl is exactly what turns a privacy rule into an executive issue. If no one can name the owner of the broker trail, the business is still depending on a blind spot.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>List every current data source in your CRM, marketing automation, and outbound tooling that did not come directly from a first-party customer action.</p></li><li><p>Mark which sources came from a broker, enrichment vendor, lead marketplace, or scraped-data workflow.</p></li><li><p>Assign one owner for deletion proof and one owner for vendor-contract review, then make them compare the same source list this week.</p></li></ol><blockquote><p><strong>IF YOU CANNOT TRACE THE BROKER TRAIL, YOU CANNOT DEFEND IT</strong></p><p>California&#8217;s live deletion workflow is a reminder that people can now challenge broker-held data at scale. The weak point for many SMBs is not the privacy policy. It is the quiet vendor chain behind the marketing database.</p><p><strong>Optery</strong> is a strong fit when you need to reduce personal-data exposure, remove records from broker ecosystems, and cut down the amount of discoverable information already circulating about executives and staff.</p><p><strong>Reduce the exposed trail. <a href="https://get.optery.com/s7rzum1ei7dw">See Optery</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><h2>3. AI Work Is Moving Into Usage-Governed Operating Lanes, Not Side Experiments</h2><p>The August 4 OpenAI Enterprise and Edu update matters because it changes how heavy AI work behaves and how it is budgeted. Pastes longer than 10,000 characters now become attachments instead of inline prompt text, which is a signal that larger working sets are being handled more deliberately. The same note said remaining weekly role-based spend limits in the admin console will automatically move to monthly limits on August 15.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Large working context is becoming normal:</strong> Once long inputs become structured attachments, teams are more likely to treat AI work as a place to move real operational material, not just quick prompts.</p></li><li><p><strong>The cost model is settling into governed capacity:</strong> A weekly-limit culture feels experimental. A monthly-limit model feels like a budgeted shared resource that someone must own.</p></li><li><p><strong>Shared usage can drift without a responsible operator:</strong> If no one owns limits, allowed use cases, and data-ingestion rules, the business can overspend, overshare, or normalize workflows it never explicitly approved.</p></li></ul><p><strong>Strategic Action:</strong> Stop managing AI usage like a loose perk. Treat it like any other shared business platform. Name the owner of limits, define what kinds of content can be pasted or attached, and decide which high-cost or high-risk workflows need approval before they become habitual.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Identify which team owns your shared AI budget, role limits, and admin-console settings today.</p></li><li><p>Decide whether any workflow involving contracts, regulated data, pricing, payroll, or customer exports should be blocked from long-paste or attachment-heavy use without review.</p></li><li><p>Set one monthly review cadence for usage spikes, new workflow requests, and documented exceptions before August 15 arrives.</p></li></ol><h3>Final Thoughts for Leaders</h3><p>This week&#8217;s signals all point to the same leadership lesson: your risk is increasingly concentrated in the systems around the main workflow, not just inside it. Remote-management layers can become privileged execution paths. Broker-fed data can become a deletion and sourcing problem overnight. Shared AI work can turn into an unowned budget and data-governance issue if you let convenience define the rules.</p><p>Put one item on your next leadership agenda: list the control surfaces in your business that can administer devices, source outside personal data, or consume shared AI capacity, then assign the named owner for each one before next week closes.</p><p>If another operator on your team needs this framing, use the share and referral tools below before the premium section.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is by sharing the strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p>If you want the implementation pack, owner register, checklist, and exercise below, the subscribe prompt is the fastest route into the premium section.<strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> Honest looks at which tools are worth the SMB budget.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-patch?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:Paid subscribers this week get a control-surface owner register, a broker-trail deletion checklist, an AI usage-governance sprint, and a tabletop exercise to test whether these quiet systems already outrun accountability in your company.</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"></p><div class="paywall-jump" data-component-name="PaywallToDOM"></div><h2>Premium Intelligence: The Quiet Control Surface Pack</h2><p>Welcome, premium subscribers. This week&#8217;s implementation pack is built for leaders who cannot afford invisible authority inside the business. The goal is to make remote admin, third-party data sourcing, and metered AI work visible enough to govern before they become emergency cleanup projects.</p><h2>1. Control-Plane Deep Dive: Treat RMM as a Privileged Execution Layer</h2><p><strong>Technical Detail:</strong> N-able&#8217;s August 2, 2026 release note said Hotfix 1 addresses a security issue in N-central 2026.3 and that all N-central instances not already on 2026.3.1 should upgrade as soon as possible. The associated NVD record for CVE-2026-18577 describes an authentication bypass that can lead to account takeover in affected N-central versions and assigns a CVSS 8.2 score. N-able&#8217;s published investigation steps called out suspicious <code>svchost.exe</code>, <code>cloudflared.exe</code>, <code>psexec</code>, inbound connections from listed IPs, and checks for unusual <code>Take Control</code> sessions.</p><ul><li><p><strong>Patch proof first:</strong> Save the exact version and hotfix evidence for every N-central instance touching your business or your MSP relationship.</p></li><li><p><strong>Admin identity review:</strong> Rotate or review every privileged credential, API token, and remote-session path attached to the platform.</p></li><li><p><strong>Downstream blast-radius check:</strong> Sample downstream endpoints for unexpected remote-session activity, scripts, tunnel processes, or overnight administrative actions.</p></li><li><p><strong>Escalation threshold:</strong> Predefine when a remote-management anomaly becomes a security incident, a vendor-management escalation, or a customer-notification problem.</p></li></ul><h2>2. Broker-Trail Deep Dive: Deletion Requests Need Routing, Suppression, and Proof</h2><p><strong>Technical Detail:</strong> California&#8217;s Office of the Attorney General said that beginning August 1, 2026, registered data brokers must delete personal information when Californians submit validated requests through DROP. The office also said Californians can direct deletion requests to more than 500 registered brokers through one portal and that signups exceeded 225,000 within six weeks of launch.</p><p><strong>Source inventory:</strong> Separate first-party, partner-shared, broker-bought, enriched, scraped, and inherited data sources.</p><p><strong>Routing map:</strong> Define where a deletion request lands internally, who checks which systems, and how vendor requests are transmitted.</p><p><strong>Suppression logic:</strong> Ensure deleted records stay deleted by preventing the same vendor feed from repopulating them later.</p><p><strong>Proof artifact:</strong> Save request timestamps, vendor acknowledgments, suppression snapshots, and contract clauses that define responsibility.</p><h2>3. AI Usage-Governance Deep Dive: Monthly Limits Mean Monthly Ownership</h2><p><strong>Technical Detail:</strong> OpenAI&#8217;s August 4, 2026 Enterprise and Edu release notes said pastes longer than 10,000 characters now become attachments to preserve context quality. The same note said remaining weekly role-based spend limits in the admin console will automatically migrate to monthly limits on August 15, 2026.</p><ul><li><p><strong>Budget owner:</strong> Name the person who can change limits, approve exceptions, and review high-usage lanes.</p></li><li><p><strong>Attachment policy:</strong> Decide what kinds of internal material may be attached, what must be summarized first, and what should never be moved into a shared workspace.</p></li><li><p><strong>Workflow approval classes:</strong> Separate research support, draft support, and decision-support workflows by risk and allowed data type.</p></li><li><p><strong>Monthly review packet:</strong> Record usage spikes, exception grants, high-cost prompts, and any new teams asking for access expansion.</p></li></ul><blockquote><p><strong>AI WORKLOADS NEED POLICY-AWARE OWNERSHIP</strong></p><p>As AI usage becomes attachment-heavy and monthly-budgeted, the management question shifts from &#8220;who has access&#8221; to &#8220;who governs the workflows, limits, and approved data lanes.&#8221;</p><p><strong>Airia</strong> is a practical fit when you need governed orchestration, policy-aware AI deployment, and clearer control over which workflows can touch sensitive information or shared budgets.</p><p><strong>Govern the workload before it scales. <a href="https://try.airia.com/3bcae15ptpli">Explore Airia</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><h2>Premium Template: Control-Surface Owner Register</h2><p>Use this register for any system that can administer devices, acquire outside personal data, or consume a shared AI budget on the company&#8217;s behalf.</p><ul><li><p><strong>Control surface:</strong> The exact platform, workflow, or vendor lane.</p></li><li><p><strong>Business authority:</strong> What the system can actually do if left unchecked.</p></li><li><p><strong>Named owner:</strong> The person responsible for policy, review, and exceptions.</p></li><li><p><strong>High-risk inputs:</strong> Credentials, regulated data, third-party records, contract text, pricing, or other sensitive material.</p></li><li><p><strong>Proof artifact:</strong> The log, screenshot, ticket, vendor response, or admin report that proves control worked.</p></li><li><p><strong>Stop condition:</strong> The event that forces a human checkpoint before the workflow continues.</p></li><li><p><strong>Review cadence:</strong> Weekly, monthly, or event-driven validation frequency.</p></li></ul><p>Premium Checklist: Seven-Day Quiet-System Review</p><ul><li><p>Confirm version, hotfix, and admin-review evidence for every remote-management platform in scope.</p></li><li><p>Save one downstream endpoint review proving the control plane was checked after the vendor advisory.</p></li><li><p>Inventory every broker-fed or enriched data source currently feeding your CRM, outbound, or advertising stack.</p></li><li><p>Define how a deletion request is routed, how suppression is enforced, and where vendor proof is stored.</p></li><li><p>Name the owner of AI usage limits, attachment rules, and monthly exception handling.</p></li><li><p>Review whether any AI workflow currently touches contracts, regulated data, pricing, payroll, or customer exports.</p></li><li><p>Publish a one-page owner map covering remote admin, broker trail, and AI budget governance.</p></li></ul><h2>Premium Guide: Five-Day Quiet Control Surface Reset</h2><p><strong>Day 1: Identify the quiet systems with authority</strong></p><p>List every platform that can push remote actions, add outside data into your business, or draw down shared AI usage without another person intervening first.</p><p><strong>Day 2: Name the owners and the proof</strong></p><p>For each system, assign the control owner and write down what evidence proves the control worked this week, not in theory.</p><p><strong>Day 3: Test the interruption path</strong></p><p>Ask what happens when a vendor hotfix lands, a deletion request arrives, or a team suddenly needs more AI capacity. If the answer depends on a hallway conversation, the process is not ready.</p><p><strong>Day 4: Tighten the boundary</strong></p><p>Disable nonessential remote actions, pause unknown data feeds, and restrict high-risk AI attachment use until the owner can articulate the rule.</p><p><strong>Day 5: Publish the owner register</strong></p><p>Capture the control surface, owner, stop condition, proof artifact, and review cadence in one place your leadership team can actually use.</p><h2>Premium Exercise: The Quiet System Already Acted</h2><p><strong>Tabletop Exercise: Hidden Authority, Public Consequences</strong></p><ul><li><p><strong>Premise</strong>: A remote-management platform pushes an unexpected session to a production endpoint, a customer asks where broker-sourced information about them came from and why it sti</p><p>ll exists, and a department exceeds its AI usage expectations after attaching internal material to shared workflows.</p></li><li><p><strong>Exercise Goal</strong>: Test whether the team can name the control owner, prove the review artifact exists, identify the stop condition, and decide who has authority to interrupt the workflow.</p></li></ul><p>Use this exercise to: expose where systems surrounding the business still carry more operational power than leadership has explicitly governed.</p><h2>Sources</h2><ul><li><p><a href="https://status.n-able.com/release-notes/">N-able Release Notes, August 2, 2026</a></p></li><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-18577">NVD: CVE-2026-18577</a></p></li><li><p><a href="https://oag.ca.gov/news/press-releases/california-data-protection-just-got-easier-attorney-general-bonta-reminds">California Attorney General, February 26, 2026 with August 1, 2026 effective-date reminder</a></p></li><li><p><a href="https://help.openai.com/en/articles/10128477-chatgpt-enterprise-edu-release-notes">OpenAI Help Center: ChatGPT Enterprise &amp; Edu Release Notes, August 4, 2026</a></p></li></ul><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[SMB Risk Briefing: Shut the Message Door, Read the Rule Shift, and Modernize AI with Human Review]]></title><description><![CDATA[Three practical signals from July 23 through July 29, 2026: CISA's warning on Russian phishing against Zimbra, the EU's AI Omnibus simplification, and Google's new ATLAS data on how AI at work is actually being used.]]></description><link>https://substack.cpf-coaching.com/p/smb-risk-briefing-shut-the-message-93a</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/smb-risk-briefing-shut-the-message-93a</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 31 Jul 2026 10:13:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yC4l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F045bb859-117c-4bdd-9257-827520dc8fc8_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you want a cleaner way to read this week, do not split the signals into separate piles called cyber, regulation, and AI. The more useful pattern is operational authority. On Wednesday, July 23, 20&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/smb-risk-briefing-shut-the-message-93a">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[SMB Risk Briefing: Shut the Message Door, Read the Rule Shift, and Modernize AI with Human Review]]></title><description><![CDATA[Three practical signals from July 23 through July 29, 2026: CISA's warning on Russian phishing against Zimbra, the EU's AI Omnibus simplification, and Google's new ATLAS data on how AI at work is actually being used.]]></description><link>https://substack.cpf-coaching.com/p/smb-risk-briefing-shut-the-message</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/smb-risk-briefing-shut-the-message</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 30 Jul 2026 19:53:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!v56M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd68aa66a-e07e-4c4c-acc3-31ac813392fb_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you want a cleaner way to read this week, do not split the signals into separate piles called cyber, regulation, and AI. The more useful pattern is operational authority. On Wednesday, July 23, 20&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/smb-risk-briefing-shut-the-message">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Agent Zero Trust: Securing AI for SMB Tech Leaders]]></title><description><![CDATA[Are your AI agents running as unchecked insider threats? Learn how small and midsize businesses can implement Agent Zero Trust to secure their environments without a dedicated security team.]]></description><link>https://substack.cpf-coaching.com/p/agent-zero-trust-for-companies-that</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/agent-zero-trust-for-companies-that</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 28 Jul 2026 13:29:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hodz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe53ff6e9-af5e-42d0-9030-3f06872d498e_1024x559.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The biggest labs in AI just told the enterprise to treat its own AI agents as insider threats. Google DeepMind and Anthropic both put out guidance this month pushing the same idea, an approach people&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/agent-zero-trust-for-companies-that">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The npm attacks stopped stealing your tokens. That should worry you more, not less.]]></title><description><![CDATA[Are your security scanners missing the biggest threat? Discover why automated pipelines are the new target for npm attacks and how SMB leaders can adapt.]]></description><link>https://substack.cpf-coaching.com/p/the-npm-attacks-stopped-stealing</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/the-npm-attacks-stopped-stealing</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Sun, 26 Jul 2026 12:21:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s0HF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ed52e59-1509-4fea-9a29-f06e3b015f01_1024x559.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Here is the uncomfortable part of this month&#8217;s software supply chain news. The attackers no longer need to steal anyone&#8217;s password.</p><p>Two compromises landed in July. On the 11th, malicious versions of t&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/the-npm-attacks-stopped-stealing">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[SMB Risk Briefing: Lock the Controllers, Unify the Evidence, and Modernize AI with Real Ownership]]></title><description><![CDATA[Secure your authority surfaces: lock down connected PLCs, unify privacy evidence, and establish clear approval boundaries for new AI workflows.]]></description><link>https://substack.cpf-coaching.com/p/smb-risk-briefing-lock-the-controllers</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/smb-risk-briefing-lock-the-controllers</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 24 Jul 2026 05:11:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bdIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you want a useful way to read this week, do not sort the news into neat boxes labeled cyber, privacy, and AI. The more relevant pattern is authority. On Tuesday, July 22, 2026, CISA, the FBI, the EPA, and other U.S. partners updated their warning about Iranian-affiliated actors targeting internet-connected programmable logic controllers across U.S. critical infrastructure, including local municipalities and water systems. Five days earlier, on Friday, July 17, the European Data Protection Board said regulators need a clearer legal basis to share information across adjacent enforcement domains because complaint volume and complexity are rising, including from the increased use of AI. One day before the CISA update, on Monday, July 21, OpenAI launched a new small business program built around ChatGPT Work, training, AI academies, and partner workflows for lean teams.</p><p>Those are three different domains, but they expose the same leadership problem. A controller can quietly influence operations. A fragmented evidence trail can weaken your compliance posture when regulators coordinate. And a promising AI workflow can spread faster than your approval model. If the system has real authority, you need a named owner, a boundary, and proof that the control works the way you think it does</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bdIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bdIy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!bdIy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!bdIy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!bdIy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bdIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121725,&quot;alt&quot;:&quot;Infographic titled 'Lock, Unify, Own' summarizing the Weekly SMB Risk Briefing. It features three columns: Lock the Controllers (highlighting PLC exposure and CISA warnings), Unify the Evidence (addressing EDPB enforcement and control records), and Own the AI Workflow (focusing on boundaries and human sign-off for new OpenAI tools). The graphic concludes with a leadership directive to find one under-governed system and assign an owner, an approval boundary, and proof.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/208171166?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infographic titled 'Lock, Unify, Own' summarizing the Weekly SMB Risk Briefing. It features three columns: Lock the Controllers (highlighting PLC exposure and CISA warnings), Unify the Evidence (addressing EDPB enforcement and control records), and Own the AI Workflow (focusing on boundaries and human sign-off for new OpenAI tools). The graphic concludes with a leadership directive to find one under-governed system and assign an owner, an approval boundary, and proof." title="Infographic titled 'Lock, Unify, Own' summarizing the Weekly SMB Risk Briefing. It features three columns: Lock the Controllers (highlighting PLC exposure and CISA warnings), Unify the Evidence (addressing EDPB enforcement and control records), and Own the AI Workflow (focusing on boundaries and human sign-off for new OpenAI tools). The graphic concludes with a leadership directive to find one under-governed system and assign an owner, an approval boundary, and proof." srcset="https://substackcdn.com/image/fetch/$s_!bdIy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!bdIy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!bdIy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!bdIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3309de51-e2fa-47b0-ae76-0a601de07ed4_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A quick visual breakdown of this week's authority surfaces: securing connected PLCs, consolidating privacy evidence, and establishing boundaries for AI workflows.</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>1. Internet-Connected Controllers Are Still a Live Operational Threat</h2><p>On July 22, 2026, CISA, the FBI, the EPA, and other U.S. government partners updated their advisory on Iranian-affiliated actors targeting programmable logic controllers across U.S. critical infrastructure. The update added guidance for detecting malicious changes in reusable code modules used within Rockwell Automation PLC programs and expanded the observed manufacturer scope to Schneider Electric, Siemens, and possibly others. The advisory also reinforced a basic but uncomfortable truth: internet-connected operational technology still creates direct business risk when organizations leave access exposed or treat industrial control paths like background infrastructure.</p><p><strong>Why you should be concerned:</strong> This is not just a large-utility story. Many SMBs operate small plants, warehouses, building-management systems, water-facing environments, municipal systems, or vendor-managed industrial assets that sit one step away from physical operations. When adversaries can manipulate HMI or SCADA-facing data, the impact is not abstract. It can become operational disruption, financial loss, and a messy incident narrative about why remotely reachable systems were left in a fragile state.</p><p><strong>Strategic action:</strong> Stop treating connected controllers as someone else&#8217;s black box. Whether you own the asset directly or rely on an MSP, integrator, landlord, or facilities vendor, your leadership team still needs a current answer to a simple question: which control systems are reachable, who approves changes, and how would you know if code or project files were altered?</p><p>Three steps to take this week:</p><ol><li><p>Inventory any internet-connected controller, building-management, or industrial device path your business relies on, including vendor-managed environments and municipal or landlord dependencies.</p></li><li><p>Confirm whether direct internet exposure exists anywhere in those environments and whether remote access is constrained to approved management paths.</p></li><li><p>Ask for proof that controller logic, reusable modules, and project files can be validated against unauthorized changes instead of assuming the vendor would tell you.</p></li></ol><div class="pullquote"><p>Partner resource: <strong><a href="https://get.bitdefender.com/ltjvkcuvgy0t-comparison">Bitdefender</a></strong> is a strong fit when you need better endpoint visibility, network-risk reduction, and incident support around the broader Windows, admin, and remote-access surfaces that usually sit next to these operational systems. <em>Affiliate note: CPF Coaching may earn a commission if you choose to use it.</em></p></div><h2>2. Regulators Are Signaling More Joined-Up Enforcement</h2><p>On July 17, 2026, the European Data Protection Board called for a clear legal basis for cross-regulatory information sharing and said regulators are dealing with rising complaint volume and complexity, including pressure created by AI-related issues. The practical significance is larger than the policy language might suggest. Privacy enforcement is becoming more coordinated, more operational, and less tolerant of fragmented evidence held separately across legal, security, product, marketing, and vendors.</p><p><strong>Why you should be concerned:</strong> A lot of SMB compliance posture still depends on local heroics. The privacy notice lives in one system, the cookie or tag configuration lives in another, security logs live somewhere else, and vendor commitments sit in inboxes or procurement folders. That arrangement works until a complaint, breach, investigation, or customer challenge forces you to reconstruct the story quickly. Once regulators share information more easily across domains, disconnected controls become a liability, not just an inconvenience.</p><p><strong>Strategic action:</strong> Build evidence the way a reviewer would need to see it, not the way internal teams happen to store it. If your business collects personal data, uses third-party tools, or changes digital experiences frequently, you need a simple, reviewable record of what the business says, what the systems do, who owns the control, and where the evidence lives.</p><p>Three steps to take this week:</p><ol><li><p>Choose one live data-processing workflow and map the current evidence trail across notice, consent or disclosure, vendor dependencies, security logging, and owner accountability.</p></li><li><p>Identify where the story breaks because proof is split across teams, inboxes, tools, or contractors.</p></li><li><p>Create one shared control record that ties together policy, implementation owner, validation cadence, and retrieval path for evidence.</p></li></ol><div class="callout-block" data-callout="true"><p>Partner resource: <strong><a href="https://join.copla.com/dc98bimlb0rc">Copla</a></strong> is worth evaluating when privacy, security, and compliance work keeps stalling between advisory language and real operational follow-through. <em>Affiliate note: CPF Coaching may earn a commission if you choose to use it.</em></p></div><h2>3. Small-Business AI Is Getting Easier to Start and Harder to Govern Casually</h2><p>On July 21, 2026, OpenAI launched the ChatGPT for small business program and positioned ChatGPT Work as an accessible way for small businesses to use training, guided workflows, partner integrations, and agents to complete multi-step work. The pitch is understandable. Lean teams want leverage. Owners do wear too many hats. But the leadership question is not whether AI can help. It is whether the workflow you are about to accelerate has a clear owner, a safe data boundary, and a defined approval model.</p><p><strong>Why you should be concerned:</strong> Small-business AI adoption is leaving the experimentation phase. The moment an owner can connect files, apps, memory, prompts, and multi-step automation into something that influences sales, operations, finance, HR, or customer communication, the workflow stops being a harmless assistant experiment. It becomes part of the operating model.</p><p><strong>Strategic action:</strong> Modernize with explicit ownership instead of enthusiasm alone. If you want AI to save time, great. If you want it to draft, route, analyze, or trigger work across core business systems, define the authority boundary first. Decide what the workflow may read, what it may write, what it may suggest, what it may send, and what still needs a named human sign-off.</p><p>Three steps to take this week:</p><ol><li><p>Pick one existing AI workflow and classify it as advisory only, draft and review, or permissioned execution.</p></li><li><p>Document the connected systems, the sensitive data involved, and the exact point where human approval is still required.</p></li><li><p>Reject any rollout that cannot explain how errors are caught, how actions are logged, and how the workflow is disabled if it behaves unpredictably.</p></li></ol><blockquote><p>Partner resource: <strong><a href="https://try.airia.com/hanp3sdhtshf-az7nx">Airia</a></strong> is relevant when your goal is governed AI adoption with clearer workflow boundaries, visibility, and operational control instead of ad hoc sprawl. <em>Affiliate note: CPF Coaching may earn a commission if you choose to use it.</em></p></blockquote><h3>Final Thoughts</h3><p>This week is less about panic than about control design. A controller should not be quietly reachable. A compliance record should not need detective work. An AI workflow should not gain authority by convenience. The common thread is that modern systems collect power faster than most leadership models adapt.</p><p>If you only do one thing before next week, do this: identify one system in your business that can influence operations, evidence, or decisions more than your current oversight model deserves. Then name the owner, define the approval boundary, and demand proof that the control works.</p><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is by sharing the strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> Honest looks at which tools are worth the SMB budget.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/smb-risk-briefing-lock-the-controllers?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/smb-risk-briefing-lock-the-controllers?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul><div><hr></div><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is by sharing the strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> Honest looks at which tools are worth the SMB budget.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward:</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/smb-risk-briefing-lock-the-controllers?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/smb-risk-briefing-lock-the-controllers?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><div><hr></div><blockquote><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p style="text-align: center;"><em>Join a community of SMB leaders who stop reacting to tech shifts and start leading them.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&amp;gift=true&quot;,&quot;text&quot;:&quot;Give a gift subscription&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?&amp;gift=true"><span>Give a gift subscription</span></a></p><p style="text-align: center;"></p><div class="paywall-jump" data-component-name="PaywallToDOM"></div></blockquote><p></p><h2 style="text-align: center;">Premium Implementation Guidance</h2><p>Premium readers get the operating layer: how to turn this week&#8217;s three signals into a compact control model that can survive a real incident, a regulator question, or an overly ambitious automation rollout.</p><h3>1. Control-Surface Triage for Operational Technology and Connected Facilities</h3><p><strong>Technical detail:</strong> The July 22 CISA update matters because it moved beyond a narrow manufacturer assumption and added guidance around malicious changes in reusable code modules, internet-connected PLC deployment, and direct OT exposure. Even when a small business does not think of itself as industrial, the practical risk can still sit in building systems, facilities contractors, smart infrastructure, warehouses, healthcare-adjacent equipment, or municipal dependencies.</p><p><strong>Actionable strategy:</strong></p><p>- Build a control-surface inventory covering PLCs, building controls, remote-access gateways, HMI consoles, SCADA dependencies, and vendor-managed operational assets.</p><p>- Separate business ownership from technical administration so someone accountable exists even when the equipment is managed by an outside party.</p><p>- Treat change validation as part of business continuity, not just engineering hygiene.</p><p><strong>Leadership focus areas:</strong></p><p>- Which internet-connected systems could disrupt operations even if they are not part of the traditional IT inventory?</p><p>- Which vendors or contractors can remotely touch those systems, and what logging or approval path exists?</p><p>- Which assets would create the highest operational pain if manipulated for even a short period?</p><h3>2. Privacy Evidence Design for a More Coordinated Regulatory Environment</h3><p></p><p><strong>Technical detail:</strong> The EDPB&#8217;s July 17 message is a process signal: regulators want more efficient cross-regulatory information sharing, and they explicitly noted the growing volume and complexity of complaints, including those shaped by AI. The risk for SMBs is not that every regulator suddenly appears at once. It is that fragmented governance becomes easier to notice and harder to defend.</p><p><strong>Actionable strategy:</strong></p><p>- Create one reviewable evidence packet for each material workflow that touches personal data.</p><p>- Tie together the notice or disclosure, live implementation, responsible owner, validation cadence, vendor involvement, and retrieval path for logs or screenshots.</p><p>- Rehearse what you would produce within one hour if a customer, insurer, regulator, or board member asked how the workflow is governed.</p><p><strong>Control focus areas:</strong></p><p>- Which workflows depend on vendor promises that the business has not independently validated?</p><p>- Where would your team lose time because evidence is split across legal, marketing, IT, or contractors?</p><p>- Which AI-enabled or analytics-heavy changes could quietly outpace the privacy documentation supporting them?</p><h3>3. AI Modernization with Declared Authority Levels</h3><p><strong>Technical detail:</strong> The July 21 OpenAI program is useful because it lowers the friction for small-business adoption. That is exactly why governance matters more, not less. Once lean teams can combine memory, connected apps, agents, prompts, and partner workflows, the organization needs a declared authority model for AI just like it has for finance approvals or security changes.</p><p><strong>Actionable strategy:</strong></p><p>- Classify each AI workflow by authority: recommend, draft, or execute.</p><p>- Require named approval before a workflow can send external communications, alter records, make customer-impacting decisions, or trigger live system changes.</p><p>- Log the workflow scope, connected tools, sensitive inputs, human reviewer, and rollback path.</p><p><strong>Governance focus areas:</strong></p><p>- Which AI workflows currently look low-risk only because nobody mapped their real data access?</p><p>- Which owners are assuming review will happen informally instead of being designed into the process?</p><p>- Which automation ideas should stay in draft mode until logging, escalation, and disablement are mature?</p><h2>Premium Template: Authority and Evidence Control Record</h2><p>Use this template for any system or workflow that can influence operations, personal data handling, or AI-assisted decisions.</p><p><strong>System or workflow:</strong></p><p><strong>Business owner:</strong></p><p><strong>Technical owner:</strong></p><p><strong>Primary authority carried:</strong> </p><p><strong>Connected systems or vendors:</strong></p><p><strong>Sensitive data involved:</strong></p><p><strong>What the system may read:</strong></p><p><strong>What the system may write or change:</strong></p><p><strong>What still requires human approval:</strong></p><p><strong>Validation cadence:</strong></p><p><strong>Evidence retained:  </strong></p><p><strong>Incident or rollback path:</strong></p><p><strong>Next review date:</strong></p><p></p><h2>Premium Checklist: Friday Control-Surface Sweep</h2><p>- [ ] Inventory any internet-connected controller, facilities, or vendor-managed operational system that could disrupt the business.</p><p>- [ ] Confirm whether direct internet exposure or unmanaged remote access exists for those systems.</p><p>- [ ] Choose one personal-data workflow and assemble its evidence trail in one place.</p><p>- [ ] Identify where privacy proof depends on multiple teams with no shared owner.</p><p>- [ ] Classify one AI workflow as advisory only, draft and review, or permissioned execution.</p><p>- [ ] Record the exact human approval step before the workflow can take meaningful action.</p><p>- [ ] Confirm logs, screenshots, or system records exist for the controls you claim to operate.</p><p>- [ ] Put one under-governed workflow on the next leadership agenda for cleanup.</p><p></p><h2>Premium Exercise: The Quiet Authority Tabletop</h2><p><strong>Scenario</strong>: Your facilities vendor confirms that a remotely reachable controller was changed without a clearly documented approval. At the same time, a customer asks for evidence about how a data-processing workflow is governed, and an AI assistant has been drafting follow-up messages using shared files that nobody formally approved it to access.</p><p><strong>Exercise objectives:</strong></p><p>1. Decide which issue gets contained first and who has authority to lead the response.</p><p>2. Prove what operational, privacy, and AI-governance evidence the business can produce within one hour.</p><p>3. Identify where the organization granted authority by convenience instead of by design.</p><p><strong>Questions to work through:</strong></p><p>1. Which systems in your business currently hold more operational or evidentiary power than their oversight model deserves?</p><p>2. If a regulator or insurer asked for proof today, what could you retrieve immediately without relying on guesswork?</p><p>3. If an AI-enabled workflow caused a customer or operational problem, who would stop it, explain it, and prove the approval trail?</p><p></p><h2>Sources</h2><p>- CISA, FBI, EPA and partners, &#8220;CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers,&#8221; released July 22, 2026: https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting</p><p>- European Data Protection Board, &#8220;EDPB calls for legal basis for cross-regulatory information sharing,&#8221; published July 17, 2026: https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en</p><p>- OpenAI, &#8220;Introducing the ChatGPT for small business program,&#8221; published July 21, 2026: https://openai.com/index/introducing-chatgpt-small-business-program/</p>]]></content:encoded></item><item><title><![CDATA[This Week's SMB Risk Signals: SharePoint Trust, Renewal Law, and AI Presence]]></title><description><![CDATA[CISA SharePoint alerts, 1-800-Flowers auto-renewal fines, and OpenAI Presence governance. Learn why SMB workflow control requires proof, not just patching.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-sharepoint</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-sharepoint</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Thu, 23 Jul 2026 20:37:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!d-Vt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 16, 2026, CISA updated its SharePoint exploitation alert after adding CVE-2026-58644 to the Known Exploited Vulnerabilities catalog, warning that active exploitation of multiple on-premises SharePoint flaws can lead to remote code execution, stolen IIS machine keys, persistence, and malware deployment. On July 22, 2026, New York Attorney General Letitia James secured a $375,000 settlement from 1-800-Flowers after investigators found deceptive automatic subscription renewals, inadequate acknowledgments, and missing renewal notice controls. Also on July 22, 2026, OpenAI introduced Presence, a product for deploying enterprise AI agents with policies, guardrails, approved actions, and human escalation rules.</p><p>These are not three unrelated headlines. They are one operating problem. The workflows that can execute for you, charge for you, or act for you now need clearer consent, containment, and approval boundaries. If a collaboration server can quietly become an execution surface, if a renewal engine can bill customers without clear notice, or if an AI agent can touch systems before your policies are mature, trust is still outrunning control</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d-Vt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d-Vt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 424w, https://substackcdn.com/image/fetch/$s_!d-Vt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 848w, https://substackcdn.com/image/fetch/$s_!d-Vt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!d-Vt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d-Vt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg" width="1024" height="707" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:707,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180722,&quot;alt&quot;:&quot;Here are a few options for the alt-text and caption for your infographic, keeping your SMB tech and cyber leader audience in mind.  Alt-Text Options The alt text should be descriptive for accessibility while natively incorporating your core SEO keywords.  Option 1 (Comprehensive &amp; SEO-focused): Infographic outlining weekly SMB risk signals for tech leaders. A shield graphic illustrates three core areas: securing SharePoint against active exploits, ensuring automatic renewal law compliance with clear consent, and establishing AI governance for OpenAI Presence. The bottom banner states that workflow control requires proof, not just patching.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/208171547?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Here are a few options for the alt-text and caption for your infographic, keeping your SMB tech and cyber leader audience in mind.  Alt-Text Options The alt text should be descriptive for accessibility while natively incorporating your core SEO keywords.  Option 1 (Comprehensive &amp; SEO-focused): Infographic outlining weekly SMB risk signals for tech leaders. A shield graphic illustrates three core areas: securing SharePoint against active exploits, ensuring automatic renewal law compliance with clear consent, and establishing AI governance for OpenAI Presence. The bottom banner states that workflow control requires proof, not just patching." title="Here are a few options for the alt-text and caption for your infographic, keeping your SMB tech and cyber leader audience in mind.  Alt-Text Options The alt text should be descriptive for accessibility while natively incorporating your core SEO keywords.  Option 1 (Comprehensive &amp; SEO-focused): Infographic outlining weekly SMB risk signals for tech leaders. A shield graphic illustrates three core areas: securing SharePoint against active exploits, ensuring automatic renewal law compliance with clear consent, and establishing AI governance for OpenAI Presence. The bottom banner states that workflow control requires proof, not just patching." srcset="https://substackcdn.com/image/fetch/$s_!d-Vt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 424w, https://substackcdn.com/image/fetch/$s_!d-Vt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 848w, https://substackcdn.com/image/fetch/$s_!d-Vt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!d-Vt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F622ed712-a927-4c98-9c11-3c41185a3acb_1024x707.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Three distinct headlines, one core operating problem. Whether you are securing on-premises SharePoint servers, verifying auto-renewal billing controls, or deploying AI agents, workflow control requires proof of consent and containment.</figcaption></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.1. SharePoint Trust Breaks Fast When Old Collaboration Servers Stay Exposed</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The SharePoint story matters because it is not about a fringe system. It is about a platform many organizations still treat as a quiet internal utility even though it can hold documents, workflows, service accounts, and administrative leverage. CISA said active exploitation affects all supported on-premises SharePoint Server versions: Subscription Edition, 2019, and 2016.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>This is already active exploitation:</strong> CISA said threat actors are exploiting CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, not merely scanning for them.</p></li><li><p><strong>Post-exploitation risk is broader than patching:</strong> The alert says the activity includes stealing IIS machine keys and using deserialization techniques to gain persistence and deploy malware.</p></li><li><p><strong>The hardening advice is specific:</strong> CISA urged organizations to apply patches, enable AMSI with Full Mode where feasible, hunt for intrusion artifacts before rotating machine keys, and avoid exposing SharePoint directly to the internet unless it sits behind an authenticated Layer 7 reverse proxy.</p></li></ul><p><strong>Strategic Action:</strong> Treat on-premises collaboration servers as privileged execution surfaces. If your team cannot say whether any SharePoint server is still externally reachable, whether AMSI is fully enabled, or who owns the service-account and machine-key response plan, your containment story is still incomplete.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Confirm whether any supported SharePoint Server instance is still running on-premises, and whether it is exposed directly or indirectly to the internet.</p></li><li><p>Verify that Microsoft&#8217;s latest security updates installed cleanly and that AMSI integration is enabled for each SharePoint web application.</p></li><li><p>Hunt for webshells, suspicious worker-process activity, and machine-key access before rotating secrets or restarting services.</p></li></ol><div class="pullquote"><p>To keep SharePoint, IIS, and emergency admin credentials from turning into shared blind spots, <strong><a href="https://1password.partnerlinks.io/cpf-coaching">1Password</a></strong> gives teams a cleaner way to separate privileged access, rotate secrets, and prove who still has the keys.</p><p><sub>Affiliate sponsor</sub></p></div><h2>2. Auto-Renewal Compliance Is Now an Operating-Control Problem</h2><p>The 1-800-Flowers settlement is useful because it turns recurring billing into a concrete legal and process-control issue for every SMB that sells subscriptions, retainers, support plans, training, or membership-style services. New York&#8217;s attorney general said the company failed to clearly disclose subscription terms, failed to provide the acknowledgment required by New York law, and did not notify subscribers before the subscription renewed automatically.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>The control failures were basic, not exotic:</strong> The public settlement says terms were buried in fine print, linked terms, or pop-out boxes many consumers never opened.</p></li><li><p><strong>Consent and proof both mattered:</strong> New York law requires affirmative consent, a post-purchase acknowledgment, and an easy cancellation process, not just a checkout page that technically mentions renewal somewhere.</p></li><li><p><strong>Recurring revenue can become recurring legal risk:</strong> If your team cannot prove who approved the wording, who owns the acknowledgment email or screen, and who validates reminder notice behavior, the renewal engine is acting on trust alone.</p></li></ul><p><strong>Strategic Action:</strong> Treat recurring-billing workflows like compliance controls, not just growth mechanics. The standard is no longer whether the checkout flow converts. It is whether you can clearly show consent, acknowledgment, reminder, and cancellation evidence when a complaint or regulator asks.</p><p>I know lean SMB teams often inherit billing plugins, SaaS plan logic, and lifecycle emails from several different owners. That is exactly why this issue matters. If no one owns the legal behavior of the renewal flow end to end, the business can keep charging long after the control story has broken.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Review every auto-renewing offer and confirm the renewal term, cancellation policy, and renewal behavior appear clearly before payment.</p></li><li><p>Test whether the customer receives a usable post-purchase acknowledgment and a renewal reminder when the law or policy requires one.</p></li><li><p>Save one evidence packet this week: thIf you want the implementation pack, checklist, and exercise below, the subscribe prompt is the quickest path into the premium section.</p><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.Paid subscribers this week get a trusted-workflow register, a SharePoint hardening checklist, a renewal-control review list, and an AI approval exercise.Premium Intelligence: The Trusted Workflow Control Pack</p><p>Welcome, premium subscribers. This section turns this week&#8217;s three public signals into an implementation pack for SMB leaders, MSP-backed teams, and operators managing too many inherited workflows. The goal is not more commentary. It is clearer control ownership, better evidence, and safer automation.</p><h3>1. SharePoint Deep Dive: Hardening an Execution Surface</h3><p><strong>Technical Detail:</strong> CISA said active exploitation affects SharePoint Server Subscription Edition, 2019, and 2016 through CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. The agency said post-exploitation behavior includes stealing IIS machine keys and using deserialization techniques to gain persistence and deploy malware.</p><ul><li><p><strong>Patch discipline:</strong> Apply Microsoft&#8217;s latest updates and verify they completed successfully, not just that the maintenance window ran.</p></li><li><p><strong>Detection discipline:</strong> Enable AMSI for each SharePoint web application and use Full Mode where feasible. Review telemetry for suspicious worker-process activity, anomalous requests, machine-key access, and webshell behavior.</p></li><li><p><strong>Containment discipline:</strong> Hunt for intrusion artifacts before rotating machine keys or other secrets, or you risk restoring trust into a still-compromised environment.</p></li><li><p><strong>Exposure discipline:</strong> Avoid direct internet exposure unless the server is behind an authenticated Layer 7 reverse proxy or equivalent application-layer control.</p></li></ul><h3>2. Renewal-Law Deep Dive: Consent, Acknowledgment, Notice</h3><p><strong>Technical Detail:</strong> The July 22 settlement says 1-800-Flowers failed to clearly disclose subscription terms, failed to provide the subscription acknowledgment required by New York law, and failed to notify subscribers before automatic renewal. The attorney general&#8217;s office also said New York law requires affirmative consent, a post-purchase acknowledgment, and an easy cancellation path.</p><ul><li><p><strong>Consent baseline:</strong> The renewal term, price, and cancellation path must be obvious before payment, not buried in links or secondary overlays.</p></li><li><p><strong>Acknowledgment baseline:</strong> The business should be able to reproduce the post-purchase acknowledgment message or page and prove when it fired.</p></li><li><p><strong>Notice baseline:</strong> Renewal reminders should be tested, timestamped, and owned by a specific operator or system owner.</p></li><li><p><strong>Complaint baseline:</strong> If a customer says &#8220;I did not know this renewed,&#8221; your team should be able to show the pre-purchase view, acknowledgment, reminder, and cancellation route quickly.</p></li></ul><h3>3. Presence Deep Dive: Policies Before Scale</h3><p><strong>Technical Detail:</strong> OpenAI says Presence helps enterprises deploy trusted agents that can answer questions, resolve issues, use company systems, take approved actions, and escalate to people when needed. OpenAI says each deployment starts with a specific job and limited knowledge and system access, while the company decides what actions require approval and when a person should take over.</p><ul><li><p><strong>Workflow boundary:</strong> Separate agent use cases into retrieve-and-answer, draft-and-review, and permissioned execution. Do not let one approval model cover all three.</p></li><li><p><strong>Access boundary:</strong> Write down exactly what documents, systems, and tools the workflow can touch. &#8220;Internal knowledge&#8221; is not specific enough.</p></li><li><p><strong>Escalation boundary:</strong> Define the events that stop the workflow: uncertain identity, policy conflict, financial impact, legal terms, or access expansion.</p></li><li><p><strong>Improvement boundary:</strong> Track accepted outcome rate, escalation rate, and remediation loop, not only usage growth.</p></li></ul><blockquote><p><strong>AGENTS NEED EXPLICIT OPERATING BOUNDARIES</strong></p><p>Presence makes it easier to imagine agents doing real work across company systems. That only increases the need for visible policy, approved actions, and human takeover rules.</p><p><strong>Airia</strong> is a strong fit when you need governed AI orchestration, clearer policy boundaries, and better control over where agent workflows can and cannot act.</p><p><strong>Put policy around production AI. <a href="https://try.airia.com/3bcae15ptpli">Explore Airia</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><h2>Premium Template: Trusted Workflow Approval Register</h2><p>Use this register for any workflow or system that can execute, charge, or escalate on the company&#8217;s behalf.</p><ul><li><p><strong>Workflow or system name:</strong> The exact platform, automation, or operational flow.</p></li><li><p><strong>What it can do:</strong> Charge a card, issue a response, change data, access documents, create a ticket, or change access.</p></li><li><p><strong>Consent owner:</strong> Who owns the customer, employee, or internal authorization boundary.</p></li><li><p><strong>Containment owner:</strong> Who owns patching, detection, logging, and stop conditions.</p></li><li><p><strong>Approval owner:</strong> Who authorizes high-risk actions, overrides, or expanded access.</p></li><li><p><strong>Evidence artifact:</strong> The screen, log, email, or report that proves the control worked.</p></li></ul><h2>Premium Checklist: SharePoint and Renewal Control Review</h2><ul><li><p>&amp;#x2610; Confirm whether any supported SharePoint Server remains on-premises and exposed beyond a tightly controlled path.</p></li><li><p>&amp;#x2610; Verify SharePoint patches installed successfully and AMSI is enabled for each web application.</p></li><li><p>&amp;#x2610; Hunt for suspicious worker-process activity and machine-key access before rotating secrets.</p></li><li><p>&amp;#x2610; Review one live recurring offer and confirm pre-purchase disclosure is clear and complete.</p></li><li><p>&amp;#x2610; Capture one post-purchase acknowledgment and one renewal reminder as evidence.</p></li><li><p>&amp;#x2610; Test one cancellation path and record how many steps it takes a customer to exit.</p></li></ul><h2>Premium Guide: Seven-Day Trusted Workflow Sprint</h2><p><strong>Day 1: List the workflows with agency</strong></p><p>Inventory the systems that can execute, charge, approve, or escalate on behalf of the business.</p><p><strong>Day 2: Name the three owners</strong></p><p>For each workflow, assign the consent owner, containment owner, and approval owner.</p><p><strong>Day 3: Verify the containment layer</strong></p><p>Check patching, logging, external exposure, and stop conditions on the highest-risk system first.</p><p><strong>Day 4: Verify the consent layer</strong></p><p>Review subscription terms, acknowledgments, reminder logic, internal authorizations, and access boundaries.</p><p><strong>Day 5: Verify the approval layer</strong></p><p>Document which actions require human sign-off and what event forces escalation.</p><p><strong>Day 6: Run the tabletop</strong></p><p>Ask what happens if the collaboration server is exploited, the renewal reminder never fires, or the AI workflow attempts an action outside policy.</p><p><strong>Day 7: Issue the one-page report</strong></p><p>Summarize the reviewed workflows, named owners, unresolved gaps, and the next remediation date.</p><h2>Premium Exercise: The Workflow That Quietly Acts for You</h2><p><strong>Tabletop Exercise: The Silent Authority Problem</strong></p><ul><li><p>*Premise:* Your SharePoint server shows suspicious worker-process behavior two hours after a patch. On the same day, a customer complains they were charged again without clear notice. Meanwhile, an AI workflow wants expanded tool access to resolve support issues faster.</p></li><li><p>*Exercise Goal:* Test whether the team can identify the consent owner, containment owner, approval owner, and stop condition for each workflow before the issue grows into a public incident.</p></li><li><p>*Use this exercise to:* expose where trusted workflows still have authority without visible limits, evidence, or escalation rules.</p></li></ul><h2>Sources</h2><ul><li><p><a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations">CISA, &#8220;CISA Urges SharePoint Hardening After New Exploitations,&#8221; updated July 16, 2026</a></p></li><li><p><a href="https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog">CISA, &#8220;CISA Adds Two Known Exploited Vulnerabilities to Catalog,&#8221; July 22, 2026</a></p></li><li><p><a href="https://ag.ny.gov/press-release/2026/attorney-general-james-secures-375000-1-800-flowers-deceiving-consumers-about">Office of the New York Attorney General, &#8220;Attorney General James Secures $375,000 from 1-800-Flowers for Deceiving Consumers About Automatic Subscription Renewals,&#8221; July 22, 2026</a></p></li><li><p><a href="https://openai.com/index/introducing-openai-presence/">OpenAI, &#8220;Introducing OpenAI Presence,&#8221; July 22, 2026</a></p></li></ul></li></ul></li></ol>
      <p>
          <a href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-sharepoint">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This Week's SMB Risk Signals: Router Hygiene, Genetic Data, and Agentic AI]]></title><description><![CDATA[Trusted systems require explicit ownership. This week's risk signals cover CISA router warnings, the 23andMe data breach, and governing Agentic AI for SMBs.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-router</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-router</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 17 Jul 2026 13:33:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rV11!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 13, 2026, CISA and a broad coalition of U.S. and allied agencies warned that Russian state-sponsored actors <strong>continue to exploit</strong> poorly configured routers across six critical sectors, often by abusing legacy SNMP settings and exposed management paths. On July 14, 2026, a 42-state coalition secured an $18 million settlement from 23andMe after a breach that affected 6.9 million consumers and exposed how weak multifactor authentication, weak monitoring, and vague deletion controls fail under pressure. Also on July 14, 2026, OpenAI argued that agentic AI investments should be measured by useful work per dollar and governed before advanced workflows scale.</p><p>These are not three unrelated headlines. They are one operating problem. The systems you trust most now need explicit credentials, evidence, and approval paths. If a router can quietly hand over configuration data, if a sensitive-data platform cannot prove its basic safeguards were reasonable, or if an AI workflow scales before you can define who approves risky actions, the business is still running on trust it has not recently re-earned</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rV11!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rV11!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!rV11!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!rV11!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!rV11!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rV11!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:367083,&quot;alt&quot;:&quot;An infographic for the July 16, 2026 Weekly SMB Risk Signals briefing titled 'Trusted Systems Need Explicit Owners, Proof, and Limits.' It features three columns: a Cyber Threat section focusing on Router Hygiene and naming a credential owner, a Legal and Privacy section focusing on the 23andMe Fallout and naming an evidence owner, and an AI Modernization section focusing on Useful Work ROI and naming an approval owner.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/207329021?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="An infographic for the July 16, 2026 Weekly SMB Risk Signals briefing titled 'Trusted Systems Need Explicit Owners, Proof, and Limits.' It features three columns: a Cyber Threat section focusing on Router Hygiene and naming a credential owner, a Legal and Privacy section focusing on the 23andMe Fallout and naming an evidence owner, and an AI Modernization section focusing on Useful Work ROI and naming an approval owner." title="An infographic for the July 16, 2026 Weekly SMB Risk Signals briefing titled 'Trusted Systems Need Explicit Owners, Proof, and Limits.' It features three columns: a Cyber Threat section focusing on Router Hygiene and naming a credential owner, a Legal and Privacy section focusing on the 23andMe Fallout and naming an evidence owner, and an AI Modernization section focusing on Useful Work ROI and naming an approval owner." srcset="https://substackcdn.com/image/fetch/$s_!rV11!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!rV11!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!rV11!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!rV11!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef434ca3-6d87-453c-994d-2edfc755b9aa_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>1. Router Hygiene Still Decides Whether an Adversary Gets a Shortcut</h2><p>The July 13 advisory matters because it is not about exotic zero-days. It is about weak operational hygiene on devices that sit close to identity, routing, and network control. CISA said the actors primarily scan for poorly configured networking devices, especially routers, and use SNMP weaknesses, Cisco Smart Install, and exposed management portals to get what they need.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Six sectors were named:</strong> Communications, defense industrial base, energy, financial services, government services, and healthcare were identified as the highest-risk sectors, which is a reminder that routers stay business-critical even when they feel invisible.</p></li><li><p><strong>Legacy settings are still the entry point:</strong> The advisory says the actors look for SNMP agents that accept common or default community strings, then use those settings to copy device configurations and send them off-network.</p></li><li><p><strong>Credential quality is part of network defense:</strong> The mitigation guidance specifically calls for strong, unique passwords, secure storage, and local accounts used only for emergencies.</p></li></ul><p><strong>Strategic Action:</strong> Treat routers, firewalls, and network-device management paths as privileged systems, not background plumbing. If you cannot name who owns their credentials, firmware cadence, and emergency access path, you do not yet control the trust boundary they create.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Confirm which routers, switches, and firewalls still allow SNMPv1, SNMPv2, or broad management access from outside your management network.</p></li><li><p>Require a named owner for every privileged network-device credential and rotate any password that is shared in tickets, notes, or chat history.</p></li><li><p>Ask your MSP or network partner to show whether Cisco Smart Install is disabled and which management ports remain externally reachable by exception.</p></li></ol><div class="pullquote"><p>To <span>prevent router and infrastructure credentials from quietly becoming shared liabilities,&nbsp;</span><strong><a href="https://1password.partnerlinks.io/cpf-coaching"><span>1Password</span></a></strong><span>&nbsp;helps teams keep privileged access unique, auditable, and easier to rotate without passing secrets via</span> email, notes, or tickets.</p><p><sub>Affiliate sponsor</sub></p></div><h2>2. The 23andMe Settlement Raises the Floor for Sensitive-Data Discipline</h2><p>The legal lesson from July 14 is not limited to genetic testing. It is about what regulators and attorneys general may now treat as the minimum reasonable standard when a company stores highly sensitive customer data. The 23andMe case turned a breach into a broad indictment of basic control failures.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>The numbers are large and specific:</strong> The settlement announcement says the breach affected 6.9 million consumers, with some customer data later offered for sale on the dark web.</p></li><li><p><strong>Basic safeguards were part of the case:</strong> New York&#8217;s attorney general said investigators found failures around breached-password blocklists, multifactor authentication, rate limiting, logging, monitoring, unusual-login review, and known-vulnerability remediation.</p></li><li><p><strong>Deletion rights stayed on the table:</strong> The settlement also preserved consumer deletion rights and added new security expectations for the successor organization handling the data.</p></li></ul><p><strong>Strategic Action:</strong> If your business stores health, payroll, identity, or customer-record data, assume a future regulator, insurer, or board member will ask whether your basic safeguards were visible, enforced, and tested before the incident.</p><p>I know many SMB teams inherit sensitive-data platforms without a clean map of who owns account protections, retention settings, or breach detection. That is exactly why the control story has to be explicit now, before an incident writes it for you.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Enforce multifactor authentication on every admin and customer-support role that can view or export sensitive records.</p></li><li><p>Check whether your identity stack blocks known breached passwords and alerts on repeated login spikes, not just outright lockouts.</p></li><li><p>Test your delete, export, and incident-review workflow on one real system this week so you know who approves, who documents, and who confirms completion.</p></li></ol><blockquote><p><strong>SENSITIVE DATA FAILURES ARE ALSO OPERATING FAILURES</strong></p><p>The 23andMe settlement shows how quickly missing logs, weak credential controls, and unclear deletion rights become part of the legal record. If your controls exist only as assumptions, they will not hold up under investigation.</p><p><strong>Noted.Solutions</strong> is a stronger fit when your team needs to explain compliance controls, evidence expectations, and risk outcomes in language buyers and stakeholders actually understand instead of repeating generic trust claims.</p><p><strong>Sharpen the compliance narrative. <a href="https://payhip.com/b/jRqmr/af6a55810a9404f">Explore Noted.Solutions</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><h2>3. Agentic AI Should Be Measured by Accepted Work, Not Excitement</h2><p>OpenAI&#8217;s July 14 guidance is useful because it frames AI modernization as an operating-model decision rather than a model-shopping exercise. It says leaders should judge AI by useful work per dollar: tasks completed, time saved, decisions improved, and workflows ready to scale.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Model economics are moving fast:</strong> OpenAI says the price per million tokens fell 97% from GPT-4 to GPT-5.4, while GPT-5.6 delivered 54% fewer output tokens and 57% less time per task in the cited coding-agent index.</p></li><li><p><strong>Cheap is not the same as effective:</strong> The guidance warns that the lowest token price can still lead to the highest total cost if the workflow fails, retries, or requires extensive correction.</p></li><li><p><strong>Governance is the operating layer:</strong> OpenAI says leaders need to define what context AI can use, which tools it can access, what actions it can take, and who approves higher-risk steps before advanced workflows scale.</p></li></ul><p><strong>Strategic Action:</strong> Do not scale agentic AI because it looks impressive in a demo. Scale the workflows where you can define the quality bar, the approval boundary, the evidence trail, and the cost of an accepted outcome.</p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Choose one workflow where AI can draft or review, but cannot complete the action without named human approval.</p></li><li><p>Measure the cost per accepted outcome rather than the raw token cost or time spent in the tool.</p></li><li><p>Document which data the workflow can access, who can raise limits, and which event triggers manual review.</p></li></ol><h3>Final Thoughts for Leaders</h3><p>Router hygiene, sensitive-data liability, and agentic AI governance all point to the same truth: the systems with the most leverage deserve the clearest ownership. The question is not whether these tools are useful. The question is whether you can prove who controls the credentials, who preserves the evidence, and who approves the action when the stakes rise.</p><p>Put one item on next week&#8217;s agenda: list the systems in your business that can quietly change access, expose sensitive data, or automate work across tools, and assign a credential owner, an evidence owner, and an approval owner to each one.</p><p>If another operator on your team needs this framing, use the share and referral tools below before the premium section.</p><div><hr></div><p></p><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is by sharing the strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> An honest look at which tools are worth the SMB budget.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward.</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-router?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-router?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><div><hr></div><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul><blockquote><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p style="text-align: center;"><em>Join a community of SMB leaders who stop reacting to tech shifts and start leading them.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p></blockquote><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Upgrade&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This post has bonus content for paid subscribers. Upgrade to get full access.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Upgrade"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[SMB Risk Briefing: Patch the Browser, Prove the Cookie Banner, and Keep Humans in the AI Loop]]></title><description><![CDATA[Three practical signals from July 10 through July 14, 2026: critical Chrome desktop fixes, a fresh European cookie-banner enforcement signal, and Microsoft's latest proof that AI-speed defense still needs named human owners.]]></description><link>https://substack.cpf-coaching.com/p/smb-risk-briefing-patch-the-browser</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/smb-risk-briefing-patch-the-browser</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 17 Jul 2026 11:24:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Mul0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e1662dc-7587-4510-b3e0-8ca97a8478fb_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you lead a lean business, the fastest way to lose control is to treat everyday systems as low-stakes infrastructure. This week offered three reminders that ordinary tools are now governance surfac&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/smb-risk-briefing-patch-the-browser">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Can Your Security Tools, Cameras, and Agents Prove Their Work?]]></title><description><![CDATA[This week's SMB leadership brief covers Cisco ISE trust gaps, ICO retail-crime privacy guidance, and Microsoft's AI-speed hardening model with actions to verify now.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-identity</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-identity</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 10 Jul 2026 21:56:09 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4f6202b8-47c2-4f2e-83ce-82e887f18cd6_1024x572.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 6, 2026, Cisco updated its advisory for Cisco Identity Services Engine and Cisco ISE Passive Identity Connector <span>to include two tracked issues, including&nbsp;</span><strong><span>CVE-2026-20181</span></strong><span>, a&nbsp;</span><strong><span>CVSS 9.1</span></strong><span>&nbsp;remote code execution vulnerability, and noted that&nbsp;</span><strong><span>no workarounds are&nbsp;</span>available</strong>. On July 3, 2026, the UK Information Commissioner's Office told small retailers that data protection law still allows them to use personal information, including CCTV footage, to protect staff and premises, while warning that facial recognition carries a high bar due to the risk of wrongful identification. On July 8, 2026, Microsoft said its Secure Future Initiative now uses a multi-agent AI system to evaluate live cloud services at AI speed, but still routes findings through human security engineers for validation and implementation.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1vQm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1vQm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 424w, https://substackcdn.com/image/fetch/$s_!1vQm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 848w, https://substackcdn.com/image/fetch/$s_!1vQm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 1272w, https://substackcdn.com/image/fetch/$s_!1vQm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1vQm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png" width="688" height="384" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:384,&quot;width&quot;:688,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167196,&quot;alt&quot;:&quot;Infographic-style editorial dashboard with three grouped panels covering Cisco ISE trust risk, lawful retail-crime privacy controls, and AI-speed cloud hardening with human validation.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/206291906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infographic-style editorial dashboard with three grouped panels covering Cisco ISE trust risk, lawful retail-crime privacy controls, and AI-speed cloud hardening with human validation." title="Infographic-style editorial dashboard with three grouped panels covering Cisco ISE trust risk, lawful retail-crime privacy controls, and AI-speed cloud hardening with human validation." srcset="https://substackcdn.com/image/fetch/$s_!1vQm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 424w, https://substackcdn.com/image/fetch/$s_!1vQm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 848w, https://substackcdn.com/image/fetch/$s_!1vQm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 1272w, https://substackcdn.com/image/fetch/$s_!1vQm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025d096d-1eaf-4566-a380-0b9473cb243d_688x384.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Trusted systems need explicit owners, proof, and limits.</figcaption></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><p></p><p>These are three versions of the same leadership problem. The systems you trust to enforce access, protect property, and accelerate operations are now high-trust systems in their own right. For SMB leaders, the question is no longer whether these tools are useful. It is whether you can prove who owns them, how quickly they must be patched, what data they can touch, and where a human must still overrule them.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dS9h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dS9h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dS9h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dS9h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dS9h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dS9h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg" width="1024" height="572" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:572,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180811,&quot;alt&quot;:&quot;An infographic titled 'This Week's SMB Risk Signals: Identity Trust, Retail Privacy, and AI Hardening.' It is divided into three sections. Section 1 covers the Cisco ISE trust gap, highlighting CVSS 9.1 and CVE-2026-20181, while emphasizing the need for explicit accountability during MSP handoffs. Section 2 contrasts retail crime with privacy, noting UK ICO guidance that allows practical CCTV use for theft but requires documented reviews for facial recognition. Section 3 illustrates AI-speed hardening, showing multi-agent AI proposing findings to a live cloud, while a human hand clicks 'Validate &amp; Implement' to close the loop. The graphic includes CPF Coaching and Christophe Foulon branding&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/206291906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="An infographic titled 'This Week's SMB Risk Signals: Identity Trust, Retail Privacy, and AI Hardening.' It is divided into three sections. Section 1 covers the Cisco ISE trust gap, highlighting CVSS 9.1 and CVE-2026-20181, while emphasizing the need for explicit accountability during MSP handoffs. Section 2 contrasts retail crime with privacy, noting UK ICO guidance that allows practical CCTV use for theft but requires documented reviews for facial recognition. Section 3 illustrates AI-speed hardening, showing multi-agent AI proposing findings to a live cloud, while a human hand clicks 'Validate &amp; Implement' to close the loop. The graphic includes CPF Coaching and Christophe Foulon branding" title="An infographic titled 'This Week's SMB Risk Signals: Identity Trust, Retail Privacy, and AI Hardening.' It is divided into three sections. Section 1 covers the Cisco ISE trust gap, highlighting CVSS 9.1 and CVE-2026-20181, while emphasizing the need for explicit accountability during MSP handoffs. Section 2 contrasts retail crime with privacy, noting UK ICO guidance that allows practical CCTV use for theft but requires documented reviews for facial recognition. Section 3 illustrates AI-speed hardening, showing multi-agent AI proposing findings to a live cloud, while a human hand clicks 'Validate &amp; Implement' to close the loop. The graphic includes CPF Coaching and Christophe Foulon branding" srcset="https://substackcdn.com/image/fetch/$s_!dS9h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dS9h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dS9h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dS9h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33c6a38f-b7a4-4902-99bd-d50c59b7ff5a_1024x572.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Three critical risk areas this week demand explicit human ownership.</strong> Whether you are patching the Cisco ISE trust gap, balancing retail crime surveillance with privacy laws, or deploying AI-speed cloud hardening, your high-trust systems still require human validation and clear accountability.</figcaption></figure></div><p></p><h2>1. The Tools Deciding Access Can Become the Attack Surface</h2><p>Cisco ISE and ISE-PIC are not ordinary apps. They sit close to identity, policy, and network-admission decisions. That is what makes Cisco's July 6 update important. If the platform making access decisions is itself under urgent patch pressure, the leadership risk is not just a server issue. It is a trust issue at the layer that governs who and what gets onto your environment.</p><ul><li><p><strong>Critical severity changes the conversation:</strong> Cisco's advisory lists <strong>CVE-2026-20181</strong> and <strong>CVE-2026-20190</strong>, <span>assigns the package a&nbsp;</span><strong><span>CVSS&nbsp;</span></strong><span>score of 9.1, and directs</span> customers to software updates rather than workarounds.</p></li><li><p><strong>Identity infrastructure is a force multiplier:</strong> A weakness in ISE or ISE-PIC can put a control system at risk, not just an endpoint, meaning the operational blast radius can be broader than the asset count suggests.</p></li><li><p><strong>Managed environments are still your accountability problem:</strong> Many SMBs do not run these systems directly. A partner, MSP, or network integrator may own the day-to-day work, but your business still owns the exposure and the evidence trail.</p><p></p></li></ul><p><strong>Strategic Action:</strong> Treat identity and network-admission platforms as crown-jewel control systems. They deserve named patch owners, shorter review windows, preserved logs, and explicit rollback plans.</p><p></p><p><strong>This Week's Leadership Move:</strong></p><ol><li><p>Confirm whether your organization or any managed provider runs Cisco ISE or ISE-PIC in any environment.</p></li><li><p>Ask for the current version, the fixed-release path, and the maintenance window that has already been assigned to the update.</p></li><li><p>Preserve admin and policy-change logs before patching, and confirm who has authority to disable or limit access if a patch slips.</p></li></ol><p></p><div class="pullquote"><p>To reduce the odds that an infrastructure weakness turns into a business-wide blind spot, <strong><a href="https://shop.tenable.com/cpf-coaching">Tenable</a></strong> helps teams see exposed assets, prioritize urgent weaknesses, and pressure-test where trusted systems still need faster remediation.</p><p><sub>Affiliate sponsor</sub></p></div><p></p><h2>2. Privacy Law Does Not Block Crime Response, but It Does Demand Discipline</h2><p>The ICO's July 3 guidance matters because it corrects a common SMB mistake from both directions. Some leaders assume privacy law blocks practical responses to crime. Others assume that if theft is rising, any surveillance step is justified. The ICO said neither instinct is strong enough on its own.<br></p><ul><li><p><strong>The operational pressure is real:</strong> The ICO cited British Retail Consortium figures of <strong>almost 5.5 million incidents of theft</strong> and <strong>43,000 incidents of violence against staff</strong> every year across the retail sector.</p></li><li><p><strong>Lawful use is still available:</strong> The regulator explicitly said data protection law enables businesses to use personal information, including CCTV footage, to protect the business, its staff, and its premises.</p></li><li><p><strong>Facial recognition is a separate decision:</strong> The ICO said there is a <strong>high bar</strong> for lawful use of facial recognition in public places because of the sensitivity of the data and the risk of misidentifying someone.</p></li></ul><p></p><p><strong>Strategic Action:</strong> Do not treat privacy as a blocker or a blank check. Treat it as an operating constraint that must be designed into your crime-response workflow before the next incident lands.</p><p></p><p><strong>This Week's Leadership Move:</strong></p><ol><li><p>Write down what information your team captures, shares, and retains when theft, violence, or repeat-shopper incidents occur.</p></li><li><p>Confirm who can access CCTV, who can share clips or names, how long records are retained, and where complaints are routed.</p></li><li><p>Keep facial recognition out of production until you have a written justification, a documented impact review, and a named approval authority.</p><p></p></li></ol><blockquote><p><strong>DON'T CONFUSE URGENCY WITH LEGAL COVERAGE</strong></p><p>Small businesses still need evidence, retention logic, and complaint handling when they respond to crime. If your response process depends on ad hoc judgment, your team will be improvising under pressure.</p><p><strong>Copla</strong> helps teams turn policy ownership, evidence collection, and control reviews into something repeatable instead of something remembered only after an incident.</p><p><strong>Make compliance operational. <a href="https://join.copla.com/cpf-coaching">See Copla</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><p></p><h2>3. AI-Speed Hardening Still Requires Human Owners</h2><p><br></p><p>Microsoft's July 8 post is useful because it does not present AI as a magical replacement for security engineering. It presents AI as a way to evaluate live services faster, with more context, and at a scale humans struggle to maintain alone. The key detail is what Microsoft kept human.</p><p></p><ul><li><p><strong>The architecture is multi-agent, not single-shot:</strong> Microsoft described a multi-agent system that evaluates cloud services against Secure Future Initiative requirements.</p></li><li><p><strong>The context is broader than code scanning:</strong> The system combines code-level vulnerabilities with configuration, identity, network, and runtime context to assess overall service posture.</p></li><li><p><strong>Human validation still closes the loop:</strong> Microsoft said the system generates findings and recommendations that security engineering teams then validate and implement.</p></li></ul><p></p><p><strong>Strategic Action:</strong> If your SMB wants AI in security or IT operations, use it first to compress review time and surface evidence faster. Do not let it close findings, change policy, or touch production systems without named human approval.</p><p></p><p><strong>This Week's Leadership Move:</strong></p><ol><li><p>Select one review workflow in which AI can propose findings but cannot mark the issue as complete.</p></li><li><p>Log what evidence the AI reviewed, who approved the recommendation, and what changed afterward.</p></li><li><p>Expand only after you can measure both the time saved and the quality tradeoffs.</p></li></ol><p></p><h3>Final Thoughts for Leaders</h3><p></p><p>Trusted systems deserve harder scrutiny, not easier trust. Identity engines, retail-surveillance workflows, and AI-assisted hardening all sit close to action. That means your next step is not to buy more dashboards. It is to name a patch owner, an evidence owner, and an approval owner for every system that can materially change access, rights, or operations.</p><p></p><p>If you put only one thing on next week's agenda, make it this: which systems in this business can act with trust we have not recently re-earned?</p><p><br></p><blockquote><p><strong>NEW CPF FRAMEWORK: THE ACTIVE RESILIENCE METHOD</strong></p><p>This is the operating model behind CPF Coaching going forward: <strong>Assess, Reinforce, Monitor</strong>. Assess where compliance pressure is already creating risk. Reinforce the controls, owners, and evidence that need to hold under pressure. Monitor the systems, vendors, and AI-assisted workflows that can drift quietly after the meeting ends.</p><p><a href="http://CPF-coaching.com">CPF Coaching</a> helps 50-500 person healthtech, fintech, and SaaS companies turn compliance pressure into active resilience, without the full-time CISO price tag.</p></blockquote><p>If another operator or business owner on your team needs this framing, use the share and referral tools below before the premium section.<br></p><p>If you want the implementation pack, templates, and tabletop below, the subscribe prompt is the quickest way to access the premium section.<br></p><p>Paid subscribers this week get a trusted-systems owner register, a retail-crime privacy checklist, an AI hardening approval matrix, and a seven-day implementation sprint.</p><blockquote><p><strong>FOR CONSULTANTS, MSPS, AND FRACTIONAL SECURITY LEADERS</strong></p><p>I also published the first ARM-branded Base44 template preview: an <strong>ARM Client Portal Template</strong> for intake, evidence tracking, control reviews, AI-assisted framework guidance, and client-ready dashboards.</p><p>Use it as a starting point if you need a repeatable way to help SMB clients move through Assess, Reinforce, and Monitor without rebuilding the workflow every time.</p><p><strong>Preview the template:</strong> <a href="https://smb-compliance-client-portal-templa-c3d824dd.base44.app/?utm_source=substack&amp;utm_medium=editorial_placement&amp;utm_campaign=arm_template_launch&amp;utm_content=july_9_issue_free_to_paid_bridge">ARM Client Portal Template for Base44</a></p><p><sub>If you are new to Base44, CPF may use a referral link in follow-up materials to support future template updates.</sub></p></blockquote><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is to share strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> An honest look at which tools are worth the SMB budget.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward.</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-identity?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-identity?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul><blockquote><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p style="text-align: center;"><em>Join a community of SMB leaders who stop reacting to tech shifts and start leading them.</em></p></blockquote><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="paywall-jump" data-component-name="PaywallToDOM"></div><p><br></p><h2>Premium Intelligence: The Trusted Systems Response Pack</h2><p><br></p><h3>1. Cisco ISE and ISE-PIC Hardening Review</h3><p><br></p><p><strong>Technical Detail:</strong> Cisco's advisory <code>cisco-sa-ise-multi-G5WP8vv</code> covers <strong>CVE-2026-20181</strong> and <strong>CVE-2026-20190</strong> affecting Cisco Identity Services Engine and Cisco ISE Passive Identity Connector. Cisco's public advisory page shows a <strong>CVSS 9.1</strong> rating, a <strong>last updated date of July 6, 2026</strong>, and <strong>no workarounds available</strong>. One vulnerability is tracked as a remote code execution issue, and the package also includes an information disclosure risk. Even when exploitation requires additional conditions, the leadership lesson is clear: systems shaping access decisions need emergency-grade patch ownership.</p><p></p><ul><li><p><strong>Technical Detail:</strong> ISE and ISE-PIC are closely tied to authentication, admission, and policy enforcement, making them more sensitive than ordinary line-of-business servers.</p></li><li><p><strong>Actionable Strategy:</strong> Confirm the exact release train, the first fixed release for your branch, and the change window that has already been assigned. Do not let "the network team has it" stand in for an actual patch receipt.</p></li><li><p><strong>Vendor / MSP Check:</strong> Ask which partners, consultants, or outsourced network teams still have admin access and whether they will be involved in the patch sequence.</p></li><li><p><strong>Evidence Capture:</strong> Export admin activity, recent policy changes, and configuration backups before the change window opens.</p></li></ul><p><br></p><h3>2. Retail Crime Privacy Controls That Survive Pressure</h3><p></p><p><strong>Technical Detail:</strong> The ICO's July 3 guidance was aimed specifically at small retailers. It said businesses can use personal information, including CCTV footage, to protect staff and premises, but that they need to do so lawfully. The same guidance warns that facial recognition has a high bar for lawful use in public places because of both the sensitivity of the information and the risk of misidentification.<br></p><ul><li><p><strong>Technical Detail:</strong> The published pressure indicators matter: <strong>almost 5.5 million theft incidents</strong> and <strong>43,000 incidents of violence against staff</strong> each year across the sector.</p></li><li><p><strong>Actionable Strategy:</strong> Split your operating model into three lanes: routine CCTV review, incident-driven information sharing, and restricted advanced surveillance proposals such as facial recognition.</p></li><li><p><strong>Complaint Handling:</strong> Make sure a complaint about surveillance, retention, or disclosure has a named destination, response timeline, and evidence set.</p></li><li><p><strong>Retention Discipline:</strong> Keep only what you can justify, and document when clips, notes, or shared images must be deleted.</p></li></ul><p><br></p><h3>3. AI Hardening That Preserves Accountability</h3><p></p><p><strong>Technical Detail:</strong> In its July 8 post, Microsoft said its Secure Future Initiative uses a multi-agent AI system to proactively evaluate live cloud services against security requirements. The system combines code-level vulnerability information with configuration, identity, network, and runtime context, then surfaces findings for security engineering teams to validate and implement.</p><p></p><ul><li><p><strong>Technical Detail:</strong> Microsoft said the system delivered findings and recommendations within a few months of deployment, but did not describe the outcome as autonomous remediation.</p></li><li><p><strong>Actionable Strategy:</strong> Copy the operating pattern, not the scale. Start with AI-assisted review where every finding still needs a named human to accept, reject, or defer it.</p></li><li><p><strong>Approval Boundary:</strong> Separate "AI may review" from "AI may change." Your first success metric is evidence quality and cycle time, not unattended execution.</p></li><li><p><strong>Rollback Rule:</strong> Every AI-assisted change should have an owner, a log location, and a rollback path before it touches a production workflow.<br></p></li></ul><blockquote><p><strong>AI SPEED IS ONLY SAFE WHEN OWNERSHIP STAYS VISIBLE</strong></p><p>Security teams move faster when AI can assemble evidence and surface likely issues, but speed becomes liability when approvals, data boundaries, and change authority stay implicit.</p><p><strong>Airia</strong> is built for organizations that need governed AI orchestration, explicit controls, and clearer boundaries around where agents can and cannot act.</p><p><strong>Put guardrails around agentic work. <a href="https://try.airia.com/3bcae15ptpli">Explore Airia</a></strong></p><p><sub>Affiliate sponsor</sub></p></blockquote><p><br></p><h2>Premium Template: Trusted Systems Owner Register</h2><p></p><p>Use this register for any platform or workflow that can materially influence access, rights, safety, or production operations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EQuD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EQuD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 424w, https://substackcdn.com/image/fetch/$s_!EQuD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 848w, https://substackcdn.com/image/fetch/$s_!EQuD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 1272w, https://substackcdn.com/image/fetch/$s_!EQuD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EQuD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png" width="800" height="560" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:560,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117537,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/206291906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EQuD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 424w, https://substackcdn.com/image/fetch/$s_!EQuD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 848w, https://substackcdn.com/image/fetch/$s_!EQuD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 1272w, https://substackcdn.com/image/fetch/$s_!EQuD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe85ac9a3-a981-44cc-90b2-ab2931873ea5_800x560.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br></p><h2>Premium Checklist: Retail Crime Information-Sharing Controls</h2><ul><li><p>Document when staff may review CCTV and who approves access.</p></li><li><p>Define when footage or incident details may be shared outside the business.</p></li><li><p>Record the lawful basis and retention rule for each incident type.</p></li><li><p>Route complaints or objections to a named owner with a response timeline.</p></li><li><p>Keep facial-recognition proposals in a separate approval lane with higher scrutiny.</p></li><li><p>Confirm signage, notice language, and data-retention practice match real operations.</p></li></ul><p><br></p><h2>Premium Guide: Seven-Day Trusted Systems Hardening Sprint</h2><p></p><p><strong>Day 1: Inventory the trusted systems</strong></p><p>List every platform that can change access, record incidents, approve sensitive activity, or influence production operations.<br></p><p><strong>Day 2: Classify the owner</strong></p><p>Write down the internal owner, the vendor or MSP contact, and the person who approves emergency changes.</p><p><br></p><p><strong>Day 3: Verify patch or control status</strong></p><p>For identity and network-control systems, compare running versions to vendor advisories and preserve admin or policy logs before changes.</p><p><br></p><p><strong>Day 4: Review privacy and complaint handling</strong></p><p>For surveillance or incident-response workflows, document what is captured, who may share it, how long it is retained, and where complaints land.</p><p><br></p><p><strong>Day 5: Define AI approval boundaries</strong></p><p>Split workflows into advisory-only, draft-and-review, and permissioned-execution lanes. Do not let one label cover all use cases.</p><p><br></p><p><strong>Day 6: Run a short tabletop</strong></p><p>Ask what happens if the trusted system is the system under pressure. Who decides? What evidence exists? What stops further action?</p><p><br></p><p><strong>Day 7: Report the gaps</strong></p><p>Deliver a one-page summary showing the systems reviewed, the open gaps, the named owners, and the next remediation date.</p><p><br></p><h2>Premium Exercise: Tabletop for the Tool You Trust Most</h2><p><br></p><p><strong>Tabletop Exercise: The Gatekeeper Has the Emergency</strong></p><ul><li><p><strong>Premise:</strong> A managed provider tells you that a Cisco ISE update must be applied urgently. On the same day, a store manager wants to circulate CCTV stills after a violent incident, and your operations lead wants an AI review tool to auto-close low-confidence findings to save time.</p></li><li><p><strong>Exercise Goal:</strong> Test whether your team can identify the owner, evidence set, approval path, and stop condition for each trusted system before pressure leads to improvisation.</p></li><li><p><strong>Use this exercise to:</strong> expose where authority is assumed, where records are missing, and where legal or security decisions are made by habit rather than by policy.</p></li></ul><p><br></p><h2>Premium Exercise: Trusted Systems Self-Assessment<br></h2><ul><li><p><strong>Exercise Goal:</strong> Consider which tools in your business can grant access, identify a person, or recommend an operational action. Who owns each one? What evidence would you need to defend that process to a customer, regulator, insurer, or board member?</p></li></ul><p><br></p><h2>Sources</h2><ul><li><p>Cisco, "Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities," first published June 17, 2026 and last updated July 6, 2026: https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-ise-multi-G5WP8vv.html</p></li><li><p>Information Commissioner's Office, "How data protection law can help protect businesses from crime," July 3, 2026: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/07/how-data-protection-law-can-help-protect-businesses-from-crime/</p></li><li><p>Microsoft Security Blog, "Protecting Microsoft at AI speed: How SFI proactively hardens our cloud," July 8, 2026: https://www.microsoft.com/en-us/security/blog/2026/07/08/protecting-microsoft-at-ai-speed-how-sfi-proactively-hardens-our-cloud/</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Your Firewall’s Passwords Leaked. Patching Won’t Fix It]]></title><description><![CDATA[Patching your firewall only closes the hole; it doesn't change stolen passwords. Learn why immediate credential rotation is crucial after the FortiBleed leak, even if you are fully patched.]]></description><link>https://substack.cpf-coaching.com/p/your-firewalls-passwords-leaked-patching</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/your-firewalls-passwords-leaked-patching</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 08 Jul 2026 20:16:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ou53!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a37eced-bfbd-4b91-9f78-f8c5db78fa23_1024x559.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In mid-June, security researchers confirmed one of the largest credential-theft campaigns ever recorded against network security devices. The operation, now called FortiBleed, harvested working admin&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/your-firewalls-passwords-leaked-patching">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Infostealers, HIPAA Fallout, and Computer-Using AI]]></title><description><![CDATA[What SMB leaders should verify now before credentials, regulators, or agents move faster than your controls.]]></description><link>https://substack.cpf-coaching.com/p/infostealers-hipaa-fallout-and-computer</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/infostealers-hipaa-fallout-and-computer</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Wed, 08 Jul 2026 19:25:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mT2X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On June 24, 2026, (<em>Sorry, this one slipped through the cracks</em>) Microsoft said its Digital Crimes Unit, working with Europol and industry partners, moved to disrupt more than 200 malicious StealC and Amadey command-and-control domains and IP addresses. Six days earlier, on June 18, 2026, HHS&#8217; Office for Civil Rights announced a $450,000 HIPAA settlement after a ransomware incident at a health plan that potentially affected 10,023 people. Then, on June 24, 2026, Google said computer use is now built directly into Gemini 3.5 Flash, giving teams a mainstream path to AI that can see, reason, and take action across browser, mobile, and desktop environments.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mT2X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mT2X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 424w, https://substackcdn.com/image/fetch/$s_!mT2X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 848w, https://substackcdn.com/image/fetch/$s_!mT2X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 1272w, https://substackcdn.com/image/fetch/$s_!mT2X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mT2X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png" width="1100" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19da882c-120b-442d-ae69-00430599c838_1100x960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1100,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1803391,&quot;alt&quot;:&quot;An infographic titled 'SMB Execution-and-Verification Pack' detailing three cybersecurity operational lessons. The left panel shows infostealers extracting admin cookies and shared credentials from unmanaged endpoints. The center panel illustrates HIPAA fallout, weighing risk analysis against a $450,000 OCR settlement and breach documentation risks. The right panel displays computer-using AI executing cross-platform actions, emphasizing the need for an explicit user confirmation gate.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/203535981?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="An infographic titled 'SMB Execution-and-Verification Pack' detailing three cybersecurity operational lessons. The left panel shows infostealers extracting admin cookies and shared credentials from unmanaged endpoints. The center panel illustrates HIPAA fallout, weighing risk analysis against a $450,000 OCR settlement and breach documentation risks. The right panel displays computer-using AI executing cross-platform actions, emphasizing the need for an explicit user confirmation gate." title="An infographic titled 'SMB Execution-and-Verification Pack' detailing three cybersecurity operational lessons. The left panel shows infostealers extracting admin cookies and shared credentials from unmanaged endpoints. The center panel illustrates HIPAA fallout, weighing risk analysis against a $450,000 OCR settlement and breach documentation risks. The right panel displays computer-using AI executing cross-platform actions, emphasizing the need for an explicit user confirmation gate." srcset="https://substackcdn.com/image/fetch/$s_!mT2X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 424w, https://substackcdn.com/image/fetch/$s_!mT2X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 848w, https://substackcdn.com/image/fetch/$s_!mT2X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 1272w, https://substackcdn.com/image/fetch/$s_!mT2X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19da882c-120b-442d-ae69-00430599c838_1100x960.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Execution without verification creates blind spots. This breakdown highlights the intersecting risks of unmanaged endpoints, regulatory fallout, and autonomous AI agents.</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p></p><p>These are not separate stories. They are one operating lesson told from three angles. The software you trust can steal. The workflows you postpone can become regulatory evidence. And the AI you pilot for convenience can cross the line from draft help to real execution faster than your approval model catches up. If you lead an SMB with limited staff and a long tool list, the real question this week is simple: what inside your business can act before a human verifies it?</p><p></p><h2>Infostealers Are Still Feeding Bigger Attacks</h2><p></p><p>Microsoft said StealC is an infostealer that collects sensitive data from browsers, cryptocurrency wallets, messaging applications, email clients, and gaming platforms, while Amadey acts as a loader that can deliver StealC and other malware. Microsoft also said the disruption action on June 24 targeted more than 200 malicious domains and IPs tied to that infrastructure. The leadership takeaway is not only that one family got hit. It is that the credential-theft economy remains fast, modular, and commercially packaged.</p><p></p><h3>Why You Should Be Concerned:</h3><h3></h3><ul><li><p>Credential theft is still the bridge to bigger damage: Microsoft explicitly tied infostealers to access brokers and downstream ransomware or follow-on operations.</p></li><li><p>The first infection can start outside your most managed systems: Microsoft warned that defenders may only notice the breach after valid credentials are already being abused.</p></li><li><p>Browsers and user tools remain a soft spot: When browsers, email clients, and chat apps become collection points, a single compromised endpoint can lead to a broader identity problem.</p></li></ul><p>Strategic Action: Treat browser-stored access, local endpoints, and admin sessions as one control surface. If you are still separating endpoint protection from identity protection and browser hygiene, you are leaving too much room between infection and detection.</p><p></p><p>Three steps to take this week:</p><ol><li><p>Revoke or rotate privileged sessions, admin cookies, and high-value credentials stored or recently used on unmanaged or lightly managed endpoints.</p></li><li><p>2. Confirm that every leader, finance user, and administrator is using managed endpoint protection and a password or passkey workflow that limits credential sprawl in the browser.</p></li><li><p>3. Review which SaaS admin accounts still allow broad access from a single endpoint without step-up verification or conditional access.</p></li></ol><p></p><div class="pullquote"><p>If your browser, email, and admin sessions are all one infostealer away from becoming an attacker&#8217;s launchpad, <strong><a href="https://get.bitdefender.com/8gk9x38k25bv">Bitdefender</a></strong> is a strong fit for SMB teams that need tighter endpoint visibility, isolation, and response coverage without building a large internal security operation.</p></div><p></p><h2>Regulators Still Expect You to Show Your Work After Ransomware</h2><p>HHS OCR said the ransomware investigation started after a health plan reported a breach tied to unauthorized access in November 2021. According to OCR, 10,023 individuals were potentially affected, and the plan paid $450,000 while agreeing to a two-year corrective action plan. OCR said the plan potentially failed to conduct an accurate and thorough risk analysis before the incident and failed to implement reasonable and appropriate policies and procedures under the HIPAA Privacy, Security, and Breach Notification Rules.</p><p></p><p>Why You Should Be Concerned:</p><ul><li><p>Ransomware response is also a documentation risk: OCR did not stop at the breach itself. It focused on what the organization could not prove it had already assessed and implemented.</p></li><li><p>The data set matters: OCR said names, addresses, phone numbers, email addresses, and Social Security numbers were potentially affected, which raises both operational and trust costs.</p></li><li><p>Regulators spelled out the control expectations: OCR specifically highlighted risk analysis, audit controls, system activity review, authentication, encryption, incident lessons learned, and workforce training.</p></li></ul><p><strong>Strategic Action:</strong> Stop assuming your controls are real because they are familiar. I recognize many SMB teams are stretched thin and rely on a handful of people to cover IT, privacy, and security at once. That is exactly why you need an evidence trail that survives a bad week.</p><p>Three steps to take this week:</p><ol><li><p>Map where regulated or otherwise high-sensitivity data enters, moves through, and leaves your systems, even if you are not a full-scale healthcare organization.</p></li><li><p>Document one current risk analysis for your most sensitive workflow instead of waiting for the perfect enterprise-wide assessment.</p></li><li><p>Verify that audit logging, authentication controls, encryption decisions, and workforce training are not just assumed but named, owned, and reviewable.</p><p></p></li></ol><blockquote><p><strong>AFTER RANSOMWARE, &#8220;WE THOUGHT WE HAD IT COVERED&#8221; IS NOT A CONTROL.</strong></p><p>OCR&#8217;s June 18 settlement shows that enforcement attention lands on the evidence behind your safeguards, not just your incident narrative. If risk analysis, policy maintenance, and control ownership still live across scattered documents and tribal knowledge, the cleanup cost goes up fast.</p><p> <strong>Copla</strong> is well matched for teams that need compliance automation, evidence collection, and expert support across frameworks without rebuilding the whole program from scratch.</p><p>Turn policy into proof. <a href="https://join.copla.com/cpf-coaching">Review Copla here</a></p></blockquote><p></p><h2>Computer-Using AI Is Becoming a Real Operations Design Choice</h2><p>Google said on June 24, 2026, that computer use is now a built-in tool in Gemini 3.5 Flash. Google said this lets developers build agents that can interact across browser, mobile, and desktop environments, and specifically framed the capability as a better fit for long-horizon automation tasks such as continuous software testing and knowledge work across professional applications. Google also said the release includes safeguards that can require explicit user confirmation for sensitive or irreversible actions and can automatically stop a task when indirect prompt injection is detected.</p><p></p><p>Why You Should Be Concerned:</p><ul><li><p>This shifts AI from generation to action: Google is packaging computer use inside a mainstream model, not as a niche experiment.</p></li><li><p>The risk language is already in the launch copy: Prompt injection, sensitive actions, and the need for human-in-the-loop verification were central to Google&#8217;s own safety framing.</p></li><li><p>Your approval model now matters more than your model demo: When AI can click, navigate, and act across tools, the governance question becomes operational rather than hypothetical.</p></li></ul><p>Strategic Action: Define where AI may advise, where it may draft, and where it may act only with approval. If a team cannot explain the trigger, owner, data boundary, and rollback for an agentic workflow, the workflow is not ready for production.</p><p></p><p>Three steps to take this week:</p><ol><li><p>Pick one low-risk workflow where AI can act in a bounded environment and document the exact success condition, stop condition, and human approver.</p></li><li><p>2. Require confirmation for spending, external communication, security changes, and record updates rather than leaving those actions to default agent behavior.</p></li><li><p>3. Log every pilot with the tool used, systems touched, data involved, owner, and rollback path before expanding access.</p></li></ol><p></p><h4>Final Thoughts for Leaders</h4><p>The common thread this week is execution without verification. Infostealers exploit it, regulators punish its absence, and AI that uses computers makes it easy to scale. Your job is no longer just to choose better tools. It is to decide which actions require proof, which systems can act alone, and which identities or agents need tighter boundaries before they can move. Put endpoint credential hygiene, risk-analysis evidence, and AI approval rules on your next leadership agenda before this week ends.</p><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is to share strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> An honest look at which tools are worth the cost for SMB budgets.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward.</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/infostealers-hipaa-fallout-and-computer?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/infostealers-hipaa-fallout-and-computer?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul><p><strong>Subscribe to Unlock the Full Strategy</strong> </p><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p><p></p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/infostealers-hipaa-fallout-and-computer">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[SMB Cyber Risk: Securing the Control Plane and Agentic AI]]></title><description><![CDATA[Why exploited business systems, automated-decision duties, and agentic AI all point to one SMB leadership problem: control.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 03 Jul 2026 17:46:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cr2s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 1, 2026, CISA added a Microsoft SharePoint Server deserialization vulnerability to its Known Exploited Vulnerabilities catalog, with a July 4 remediation due date for federal agencies. Two days earlier, CISA added a SimpleHelp authentication-bypass vulnerability, also with a compressed remediation window. The same recent KEV cluster included enterprise communication, engineering, remote administration, and network-management products from Cisco, PTC, Lantronix, and Ubiquiti. Separately, Colorado&#8217;s revised AI law has shifted the compliance conversation toward automated decision-making technology used in consequential decisions, while Anthropic&#8217;s June 30 announcements pushed more agentic and auditable AI work into everyday business lanes.</p><p>The common thread this week is not a single malware family or vendor. It is control. Attackers are targeting the systems that coordinate work, provide remote help, route communications, manage devices, and store collaboration data. Regulators are asking whether automated decisions can be explained, corrected, and reviewed. AI vendors are making it easier for software to perform more of the work itself. For SMB leaders, the question is no longer whether a tool is useful. It is whether the tool has authority over your business that you can see, limit, and reverse.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cr2s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cr2s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!cr2s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!cr2s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!cr2s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cr2s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df3667c7-215c-452b-a880-8e66702f281e_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Infographic showing three SMB risk zones: control-plane systems, automated decisions, and agentic AI workflows, each connected to review, logging, and approval controls.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infographic showing three SMB risk zones: control-plane systems, automated decisions, and agentic AI workflows, each connected to review, logging, and approval controls." title="Infographic showing three SMB risk zones: control-plane systems, automated decisions, and agentic AI workflows, each connected to review, logging, and approval controls." srcset="https://substackcdn.com/image/fetch/$s_!cr2s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!cr2s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!cr2s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!cr2s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf3667c7-215c-452b-a880-8e66702f281e_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This week&#8217;s risk pattern is control: the tools that coordinate work, make recommendations, or act across systems need faster patching, clearer ownership, and better audit trails.</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>1. Collaboration and Remote-Support Tools Are Now Front-Door Risk</h2><p>CISA&#8217;s most recent KEV additions are a useful leadership signal because they are not clustered in a single obscure product category. SharePoint is a collaboration backbone. SimpleHelp is remote support. Cisco Unified Communications Manager supports voice and collaboration. PTC Windchill and FlexPLM can sit close to product, engineering, and lifecycle operations. Ubiquiti UniFi OS and Lantronix EDS5000 touch network and device administration.</p><p>That matters because these platforms often sit above ordinary endpoint risk. They connect people, vendors, admins, files, devices, and workflows. If an attacker gets leverage there, the blast radius is not just one laptop. It can serve as a route into documents, privileged access, helpdesk workflows, engineering data, customer records, or operational systems.</p><ul><li><p><strong>The exploit window is shrinking:</strong> CISA&#8217;s recent federal due dates are measured in days, not weeks. Even if those due dates formally apply to federal agencies, they are a practical signal for every organization that depends on the same products.</p></li><li><p><strong>Remote support needs more scrutiny than ordinary SaaS:</strong> A remote-support product is supposed to cross trust boundaries. That makes authentication bypass and session-control weaknesses especially sensitive.</p></li><li><p><strong>Collaboration systems are evidence systems:</strong> SharePoint, communications tools, and product systems hold records your team may need during an incident, audit, dispute, or insurance claim.</p></li></ul><p><strong>Strategic Action:</strong>&nbsp;Treat collaboration, remote support, communications, and network management platforms as control-plane systems. They deserve shorter patch timelines, tighter admin review, and separate incident playbooks.<br></p><p><strong>Partner resource: </strong>For the 72-hour exposure review, <a href="https://shop.tenable.com/cpf-coaching">Tenable</a> is a practical fit for teams that need vulnerability and exposure visibility across internet-facing systems, remote-support tooling, and infrastructure. <br><a href="https://shop.tenable.com/cpf-coaching"><sub>Tenable</sub></a><sub> is an affiliate link, which means CPF Coaching may earn a commission if you choose to use it.</sub></p><p></p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Ask your IT owner or managed provider for a list of products that can administer devices, provide remote support, manage network gear, store regulated data, or coordinate internal files.</p></li><li><p>Check whether any product in that list appears in CISA KEV or vendor emergency advisories.</p></li><li><p>Create a 72-hour rule for exploited vulnerabilities in those systems, even if your normal patch cycle is monthly.</p></li></ol><p></p><h2>2. AI Compliance Is Moving From Model Labels to Decision Rights</h2><p>Colorado&#8217;s revised AI law is useful for SMB leaders because it moves the discussion away from abstract AI hype and toward a practical question: when automated decision-making technology materially influences a consequential decision, what does the business owe the person affected?</p><p>The revised law uses an automated-decision framework rather than simply asking whether a tool is branded as &#8220;AI.&#8221; Norton Rose Fulbright&#8217;s analysis notes that the revised Colorado framework focuses on covered automated decision-making technology used in consequential decisions, including employment, housing, financial services, insurance, health care, education, and government services. It also emphasizes notice, explanation, correction, and meaningful human review after adverse outcomes.</p><p>That structure should catch the attention of SMBs even outside Colorado. Many smaller firms use applicant-screening tools, lead-scoring systems, customer-risk flags, insurance workflows, credit tools, clinical intake products, scheduling engines, or automated customer support triage without calling them AI governance issues. The label matters less than the decision's impact.</p><ul><li><p><strong>Inventory beats policy theater:</strong> A generic AI policy does not help if nobody knows where automated recommendations influence customers, employees, tenants, patients, borrowers, or applicants.</p></li><li><p><strong>Human review has to be operational:</strong> It is not enough to say a person is &#8220;in the loop&#8221; if the reviewer cannot see the inputs, correct bad data, override the decision, or explain the outcome.</p></li><li><p><strong>Vendor documentation is now part of your evidence trail:</strong> If a third-party system influences a consequential decision, your contract, configuration, logs, and escalation path matter.</p></li></ul><p><strong>Strategic Action:</strong> Build an automated-decision register before you buy another AI or analytics tool. List where software scores, ranks, recommends, blocks, approves, escalates, or materially influences decisions about people.<br></p><p><strong>Partner resource: </strong>If the automated-decision register turns into a compliance evidence project, <a href="https://join.copla.com/cpf-coaching">Copla</a> can help SMBs organize cyber risk, assessments, and compliance workflows without building an enterprise GRC stack. <br><a href="https://join.copla.com/cpf-coaching"><sub>Copla</sub></a><sub> is an affiliate link, which means CPF Coaching may earn a commission if you choose to use it.<br></sub></p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Pick one department, such as HR, sales, finance, health operations, or customer success.</p></li><li><p>Identify every workflow where software recommends or influences a decision about a person.</p></li><li><p>For each workflow, document the owner, vendor, data source, appeal path, human reviewer, and override authority.</p></li></ol><p></p><h2>3. Agentic AI Is Becoming an Operating Model, Not a Side Experiment</h2><p>Anthropic&#8217;s June 30 release notes point in the same direction as the broader AI market: more agentic everyday work, more specialized AI applications, and more emphasis on auditable artifacts. Anthropic described Sonnet 5 as its most agentic Sonnet model for coding and everyday professional work, and described Claude Science as a customizable app that integrates common research tools, produces auditable artifacts, and provides flexible compute access.</p><p>For SMBs, the specific vendor matters less than the operating pattern. AI tools are moving from &#8220;write a draft&#8221; toward &#8220;use tools, work across systems, produce artifacts, and act inside business workflows.&#8221; That can be valuable. It can also create a silent risk when AI can access customer data, privileged systems, regulated decisions, code, financial workflows, or external communications.</p><ul><li><p><strong>Auditable artifacts are becoming a buying criterion:</strong> If an AI system performs meaningful work, your team needs evidence of inputs, outputs, tools used, approvals, and final changes.</p></li><li><p><strong>Agentic work needs budget and authority limits:</strong> A model that can browse, code, schedule, file, summarize, or update records can create operational cost and operational exposure.</p></li><li><p><strong>Specialized AI apps can bypass central review:</strong> A research, coding, sales, or support tool may enter through one team while raising enterprise-wide data and security questions.</p></li></ul><p><strong>Strategic Action:</strong> Do not approve agentic AI by demo quality alone. Approve it through workflow, authority, data boundaries, logging, rollback, and the business owner.</p><p></p><p><strong>Partner resource: </strong>For leaders experimenting with agentic AI, <a href="https://try.airia.com/CPF-coaching">Airia</a> is worth evaluating when the requirement is governed AI workflow execution, not just another chat window. <br><a href="https://try.airia.com/CPF-coaching"><sub>Airia</sub></a><sub> is an affiliate link, which means CPF Coaching may earn a commission if you choose to use it.</sub></p><p></p><p><strong>This Week&#8217;s Leadership Move:</strong></p><ol><li><p>Select one current or proposed AI workflow and classify it as advisory only, draft-and-review, or permissioned execution.</p></li><li><p>Write the stop condition: when must the workflow pause and ask a human?</p></li><li><p>Confirm where logs, prompts, tool actions, files, and final outputs are retained.</p></li></ol><p></p><h3>Final Thoughts for Leaders</h3><p>This week is about the systems that sit above the work. SharePoint, remote support, communications systems, network management, automated decisions, and agentic AI all carry a common risk: they can coordinate action faster than leadership can inspect it. That is the control-plane problem.</p><p>You do not need a giant security program to respond. You need a shorter list of critical systems, faster action on actively exploited vulnerabilities, an automated-decision register, and clear rules for where AI can advise, draft, or act. Put those four items on the leadership agenda before the holiday week ends.</p><div><hr></div><p></p><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is to share strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> An honest look at which tools are worth the cost for SMB budgets.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward.</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock:</p><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul><blockquote><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p style="text-align: center;"><em>Join a community of SMB leaders who stop reacting to tech shifts and start leading them.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p></blockquote><div class="paywall-jump" data-component-name="PaywallToDOM"></div><h2>Premium Intelligence: The SMB Control-Plane Risk Pack</h2><h3>1. 72-Hour Control-Plane Exposure Review</h3><p><strong>Technical Detail:</strong> CISA&#8217;s recent KEV additions included Microsoft SharePoint Server, SimpleHelp, Cisco Unified Communications Manager, PTC Windchill and FlexPLM, Lantronix EDS5000, and Ubiquiti UniFi OS. The product mix matters because it spans the collaboration, remote support, communications, product lifecycle, network, and device management layers.</p><p>Use this review for any system that can administer devices, provide remote access, store collaboration records, manage network infrastructure, route business communications, or coordinate product data.</p><p><strong>Control Questions:</strong></p><ul><li><p>Who owns emergency patch approval for this system?</p></li><li><p>Who can create, elevate, or disable admin access?</p></li><li><p>What vendor or MSP accounts can access it?</p></li><li><p>Where are admin actions logged?</p></li><li><p>What business process fails if the system is taken offline?</p></li><li><p>What customer, employee, or regulated data can be reached through it?</p></li></ul><p><strong>72-Hour Actions:</strong></p><ol><li><p>Search the product name in CISA KEV and the vendor&#8217;s security advisories.</p></li><li><p>Confirm version, patch status, and internet exposure.</p></li><li><p>Review admin, service, and vendor accounts.</p></li><li><p>Export or preserve audit logs before making major changes.</p></li><li><p>Confirm backup and recovery path for configuration and records.</p></li></ol><p></p><h3>2. Automated-Decision Register for Lean Teams</h3><p><strong>Technical Detail:</strong> The revised Colorado AI framework focuses on automated decision-making technology that materially influences consequential decisions. The practical issue for SMBs is not whether a tool markets itself as AI. It is whether software influences decisions about employment, financial access, insurance, health care, housing, education, government services, or similarly sensitive outcomes.</p><p>Start with a simple register. Do not overbuild it.</p><p>Workflow Tool or vendor Decision affected Data used Human reviewer Override path Evidence retained Candidate screening Interview selection Resume, assessments Customer risk scoring Approval or escalation CRM, payment history Support prioritization Response urgency Ticket text, account tier Credit, billing, or access decision Service access Financial or usage data</p><p><strong>Minimum Evidence Standard:</strong></p><ul><li><p>Tool owner</p></li><li><p>Vendor contract or terms</p></li><li><p>Data fields used</p></li><li><p>Decision category</p></li><li><p>Human review owner</p></li><li><p>Correction path</p></li><li><p>Logs retained</p></li><li><p>Customer or employee notice, where applicable</p></li></ul><h3>3. Agentic AI Authorization Map</h3><p>Use this map before letting AI tools act inside live systems.</p><p>AI workflow Allowed to advise Allowed to draft Allowed to act Data boundary Approval owner Logs retained Stop condition Draft customer response Yes Yes No Customer ticket only Support lead Ticket + AI log Legal, refund, threat, regulated claim Update CRM records Yes Yes Conditional CRM fields approved Sales ops CRM history + AI log Missing source or confidence flag Write or modify code Yes Yes Conditional Repo scope only Engineering owner PR + test output Security-sensitive change Vendor-risk review Yes Yes No Contract and questionnaire only Operations owner Review memo Missing evidence</p><p><strong>Operating Rule:</strong> AI may move faster than your team, but it should not outrun ownership. Every permissioned workflow needs a named owner, explicit data boundary, retained logs, and a rollback path.</p><h2>Premium Template: Friday Control-Plane Briefing</h2><p>Use this in a 30-minute leadership meeting.</p><p><strong>Part 1: Critical Systems</strong></p><ul><li><p>Which collaboration, remote-support, communications, network, and admin tools are business critical?</p></li><li><p>Which have internet exposure?</p></li><li><p>Which have privileged vendor or MSP access?</p></li><li><p>Which appeared in KEV or vendor emergency advisories in the last 30 days?</p></li></ul><p><strong>Part 2: Automated Decisions</strong></p><ul><li><p>Where does software score, rank, approve, deny, escalate, or recommend actions affecting people?</p></li><li><p>Which decisions have a human review path?</p></li><li><p>Which decisions can be explained and corrected?</p></li></ul><p><strong>Part 3: Agentic AI</strong></p><ul><li><p>Which AI workflows can act in live systems?</p></li><li><p>Which can only draft?</p></li><li><p>Which are advisory only?</p></li><li><p>Where are logs and outputs retained?</p></li><li><p>What is the stop condition for each workflow?</p></li></ul><h2>Premium Checklist: 10-Day Control-Plane Sprint</h2><ul><li><p>[ ] Inventory collaboration, remote support, communications, network management, and admin tools.</p></li><li><p>[ ] Check the inventory against CISA KEV and vendor advisories.</p></li><li><p>[ ] Assign a 72-hour patch owner for exploited vulnerabilities in control-plane systems.</p></li><li><p>[ ] Review admin and vendor access for remote-support and collaboration platforms.</p></li><li><p>[ ] Confirm logs are retained for admin actions and remote sessions.</p></li><li><p>[ ] Create an automated-decision register for one department.</p></li><li><p>[ ] Document human review and override paths for sensitive automated decisions.</p></li><li><p>[ ] Classify AI workflows into advisory, draft-and-review, and permissioned-execution lanes.</p></li><li><p>[ ] Write stop conditions for the top three AI workflows.</p></li><li><p>[ ] Preserve evidence: patch receipts, access reviews, decision register, AI logs, and approval notes.</p></li></ul><p></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading the SMB Tech &amp; Cybersecurity Leadership Newsletter! If you have gained value from this post, why not share it with others as well?</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-control?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><p></p><h2>Sources</h2><ul><li><p>CISA, Known Exploited Vulnerabilities Catalog JSON feed, accessed July 3, 2026: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json</p></li><li><p>CISA, Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog</p></li><li><p>Norton Rose Fulbright, &#8220;Colorado enacts revised AI law,&#8221; May 2026: https://www.nortonrosefulbright.com/en-us/knowledge/publications/18733d31/colorado-enacts-revised-ai-law</p></li><li><p>Anthropic, homepage release listings for &#8220;Introducing Sonnet 5&#8221; and &#8220;Announcing Claude Science,&#8221; accessed July 3, 2026: https://www.anthropic.com/</p></li><li><p>The White House, &#8220;Promoting Advanced Artificial Intelligence Innovation and Security,&#8221; June 2, 2026: https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Stolen Logins, AI Agents, and $450K Regulatory Fines]]></title><description><![CDATA[What executes in your business without human verification? A CISO's guide to defending SMBs against infostealers, HIPAA fallout, and agentic AI.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-infostealers</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-infostealers</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 26 Jun 2026 22:30:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cP_k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On June 24, 2026, Microsoft said its Digital Crimes Unit, working with Europol and industry partners, moved to disrupt more than 200 malicious StealC and Amadey command-and-control domains and IP addresses. Six days earlier, on June 18, 2026, HHS&#8217; Office for Civil Rights announced a $450,000 HIPAA settlement after a ransomware incident at a health plan that potentially affected 10,023 people. Then on June 24, 2026, Google said computer use is now built directly into Gemini 3.5 Flash, giving teams a mainstream path to AI that can see, reason, and take action across browser, mobile, and desktop environments.</p><p>These are not separate stories. They are one operating lesson told from three angles. The software you trust can steal. The workflows you postpone can become regulatory evidence. And the AI you pilot for convenience can cross the line from draft help to real execution faster than your approval model catches up. If you lead an SMB with limited staff and a long to-do list, the real question this week is simple: <br><em>What inside your business can act before a human verifies it?</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cP_k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cP_k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!cP_k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!cP_k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!cP_k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cP_k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:810578,&quot;alt&quot;:&quot;nfostealers, ransomware evidence, and computer-using AI all punish unverified action.\&quot; It features three distinct columns summarizing the week's risks and leadership moves:  Cyber Threat (Infostealer Economy): Notes over 200 malicious nodes were disrupted and advises leaders to treat browsers, endpoints, and privileged sessions as a single identity risk surface.  Privacy / Regulatory (HIPAA Proof Gap): Highlights a $450K settlement affecting over 10,000 people and urges leaders to build evidence for safeguards before an incident occurs, not after a regulator asks.  AI / Modernization (Computer-Using AI): Mentions new built-in confirmation safeguards for AI and advises leaders to classify AI into \&quot;advise, draft, and act\&quot; lanes before it touches live systems.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/203533241?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="nfostealers, ransomware evidence, and computer-using AI all punish unverified action.&quot; It features three distinct columns summarizing the week's risks and leadership moves:  Cyber Threat (Infostealer Economy): Notes over 200 malicious nodes were disrupted and advises leaders to treat browsers, endpoints, and privileged sessions as a single identity risk surface.  Privacy / Regulatory (HIPAA Proof Gap): Highlights a $450K settlement affecting over 10,000 people and urges leaders to build evidence for safeguards before an incident occurs, not after a regulator asks.  AI / Modernization (Computer-Using AI): Mentions new built-in confirmation safeguards for AI and advises leaders to classify AI into &quot;advise, draft, and act&quot; lanes before it touches live systems." title="nfostealers, ransomware evidence, and computer-using AI all punish unverified action.&quot; It features three distinct columns summarizing the week's risks and leadership moves:  Cyber Threat (Infostealer Economy): Notes over 200 malicious nodes were disrupted and advises leaders to treat browsers, endpoints, and privileged sessions as a single identity risk surface.  Privacy / Regulatory (HIPAA Proof Gap): Highlights a $450K settlement affecting over 10,000 people and urges leaders to build evidence for safeguards before an incident occurs, not after a regulator asks.  AI / Modernization (Computer-Using AI): Mentions new built-in confirmation safeguards for AI and advises leaders to classify AI into &quot;advise, draft, and act&quot; lanes before it touches live systems." srcset="https://substackcdn.com/image/fetch/$s_!cP_k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!cP_k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!cP_k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!cP_k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feac1c735-fd9a-4724-804f-d3b1b64274d0_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Verify Before It Executes</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>1. Infostealers Are Still Feeding Bigger Attacks</h2><p>Microsoft said StealC is an infostealer that collects sensitive data from browsers, cryptocurrency wallets, messaging applications, email clients, and gaming platforms, while Amadey acts as a loader that can deliver StealC and other malware. Microsoft also said the disruption action on June 24 targeted more than 200 malicious domains and IPs tied to that infrastructure. The leadership takeaway is not only that one family got hit. It is that the credential-theft economy remains fast, modular, and commercially packaged.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Credential theft is still the bridge to bigger damage:</strong> Microsoft explicitly tied infostealers to access brokers and downstream ransomware or follow-on operations.</p></li><li><p><strong>The first infection can start outside your most managed systems:</strong> Microsoft warned defenders may only notice the breach after valid credentials are already being abused.</p></li><li><p><strong>Browsers and user tools remain a soft spot:</strong> When browsers, email clients, and chat apps become collection points, one compromised endpoint can turn into a wider identity problem.</p></li></ul><p><strong>Strategic Action:</strong> Treat browser-stored access, local endpoints, and admin sessions as one control surface. If you are still separating endpoint protection from identity protection and browser hygiene, you are leaving too much room between infection and detection.</p><p>Three steps to take this week:</p><ol><li><p>Revoke or rotate privileged sessions, admin cookies, and high-value credentials stored or recently used on unmanaged or lightly managed endpoints.</p></li><li><p>Confirm that every leader, finance user, and administrator is using managed endpoint protection and a password or passkey workflow that limits credential sprawl in the browser.</p></li><li><p>Review which SaaS admin accounts still allow broad access from a single endpoint without step-up verification or conditional access.</p></li></ol><div class="pullquote"><p>If your browser, email, and admin sessions are all one infostealer away from becoming an attacker&#8217;s launchpad, <strong><a href="https://get.bitdefender.com/8gk9x38k25bv">Bitdefender</a></strong> is a strong fit for SMB teams that need tighter endpoint visibility, isolation, and response coverage without building a large internal security operation.</p></div><h2>2. Regulators Still Expect You to Show Your Work After Ransomware</h2><p>HHS OCR said the ransomware investigation started after a health plan reported a breach tied to unauthorized access in November 2021. According to OCR, 10,023 individuals were potentially affected, and the plan paid $450,000 while agreeing to a two-year corrective action plan. OCR said the plan potentially failed to conduct an accurate and thorough risk analysis before the incident and failed to implement reasonable and appropriate policies and procedures under the HIPAA Privacy, Security, and Breach Notification Rules.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Ransomware response is also a documentation risk:</strong> OCR did not stop at the breach itself. It focused on what the organization could not prove it had already assessed and implemented.</p></li><li><p><strong>The data set matters:</strong> OCR said names, addresses, phone numbers, email addresses, and Social Security numbers were potentially affected, which raises both operational and trust costs.</p></li><li><p><strong>Regulators spelled out the control expectations:</strong> OCR specifically highlighted risk analysis, audit controls, system activity review, authentication, encryption, incident lessons learned, and workforce training.</p></li></ul><p><strong>Strategic Action:</strong> Stop assuming your controls are real because they are familiar. I recognize many SMB teams are stretched thin and rely on a handful of people to cover IT, privacy, and security at once. That is exactly why you need an evidence trail that survives a bad week.</p><p>Three steps to take this week:</p><ol><li><p>Map where regulated or otherwise high-sensitivity data enters, moves through, and leaves your systems, even if you are not a full-scale healthcare organization.</p></li><li><p>Document one current risk analysis for your most sensitive workflow instead of waiting for the perfect enterprise-wide assessment.</p></li><li><p>Verify that audit logging, authentication controls, encryption decisions, and workforce training are not just assumed but named, owned, and reviewable.</p></li></ol><blockquote><p><strong>AFTER RANSOMWARE, &#8220;WE THOUGHT WE HAD IT COVERED&#8221; IS NOT A CONTROL.</strong></p><p>OCR&#8217;s June 18 settlement shows that enforcement attention lands on the evidence behind your safeguards, not just your incident narrative. If risk analysis, policy maintenance, and control ownership still live across scattered documents and tribal knowledge, the cleanup cost goes up fast.</p><p><strong>Copla</strong> is well matched for teams that need compliance automation, evidence collection, and expert support across frameworks without rebuilding the whole program from scratch.</p><p><strong>Turn policy into proof. <a href="https://join.copla.com/cpf-coaching">Review Copla here</a></strong></p></blockquote><h2>3. Computer-Using AI Is Becoming a Real Operations Design Choice</h2><p>Google said on June 24, 2026, that computer use is now a built-in tool in Gemini 3.5 Flash. Google said this lets developers build agents that can interact across browser, mobile, and desktop environments, and specifically framed the capability as a better fit for long-horizon automation tasks such as continuous software testing and knowledge work across professional applications. Google also said the release includes safeguards that can require explicit user confirmation for sensitive or irreversible actions and can automatically stop a task when indirect prompt injection is detected.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>This shifts AI from generation to action:</strong> Google is packaging computer use inside a mainstream model, not as a niche experiment.</p></li><li><p><strong>The risk language is already in the launch copy:</strong> Prompt injection, sensitive actions, and the need for human-in-the-loop verification were central to Google&#8217;s own safety framing.</p></li><li><p><strong>Your approval model now matters more than your model demo:</strong> When AI can click, navigate, and act across tools, the governance question becomes operational rather than hypothetical.</p></li></ul><p><strong>Strategic Action:</strong> Define where AI may advise, where it may draft, and where it may act only with approval. If a team cannot explain the trigger, owner, data boundary, and rollback for an agentic workflow, the workflow is not ready for production.</p><p>Three steps to take this week:</p><ol><li><p>Pick one low-risk workflow where AI can act in a bounded environment and document the exact success condition, stop condition, and human approver.</p></li><li><p>Require confirmation for spending, external communication, security changes, and record updates rather than leaving those actions to default agent behavior.</p></li><li><p>Log every pilot with the tool used, systems touched, data involved, owner, and rollback path before expanding access.</p></li></ol><h3>Final Thoughts for Leaders</h3><p>The common thread this week is execution without verification. Infostealers exploit it, regulators punish its absence, and AI that uses computers makes it easy to scale. Your job is no longer just to choose better tools. It is to decide which actions require proof, which systems can act alone, and which identities or agents need tighter boundaries before they can move. Put endpoint credential hygiene, risk-analysis evidence, and AI approval rules on your next leadership agenda before this week ends.</p><p></p><blockquote><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p style="text-align: center;"><em>Join a community of SMB leaders who stop reacting to tech shifts and start leading them.</em></p></blockquote><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is to share strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> Honest looks at which tools are worth the cost for SMB budgets.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-infostealers?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-infostealers?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p></p><div class="paywall-jump" data-component-name="PaywallToDOM"></div><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue], but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock: </p><p>Premium Intelligence: The SMB Verification-and-Execution Pack</p><p>Premium readers get the implementation layer this week: the controls, decision structure, and working assets that translate the three stories above into operating discipline.</p><h3>1. 72-Hour Infostealer Containment Plan for Lean SMB Teams</h3><p><strong>Technical Detail:</strong> Microsoft said StealC collects data from browsers, wallets, messaging applications, email clients, and gaming platforms, while Amadey helps deliver StealC and other malware. Microsoft also said defenders may only detect a problem after valid credentials are already being abused and that the disruption action covered more than 200 malicious domains and IPs.</p><p><strong>Actionable Strategy:</strong></p><ul><li><p>Inventory the endpoints that hold administrator browser sessions, finance access, and shared SaaS credentials.</p></li><li><p>Force session revocation and password or passkey resets for high-value accounts after any credible infostealer indicator, even before full root cause analysis is complete.</p></li><li><p>Separate daily-use accounts from privileged accounts so an infected user session does not automatically become a business-wide identity event.</p></li></ul><p><strong>Leadership Focus Areas:</strong></p><ul><li><p><strong>Credential concentration:</strong> Which devices and browsers hold the keys to payroll, banking, cloud admin, customer support, and identity providers?</p></li><li><p><strong>Response speed:</strong> Who can disable sessions and revoke tokens after hours without waiting for an approval chain?</p></li><li><p><strong>Detection depth:</strong> Which protections see suspicious browser, mail-client, or credential-store access before the attacker moves downstream?</p></li></ul><h3>2. OCR-Proof Ransomware Readiness for Data-Heavy SMB Workflows</h3><p><strong>Technical Detail:</strong> OCR said the health plan potentially failed to conduct a thorough risk analysis and failed to implement reasonable and appropriate policies and procedures before the ransomware incident. OCR also emphasized audit controls, information-system activity review, authentication, encryption, lessons learned, and workforce training as practical mitigation steps.</p><p><strong>Actionable Strategy:</strong></p><ul><li><p>Build one defensible risk-analysis package around your highest-sensitivity workflow instead of trying to perfect every process at once.</p></li><li><p>Tie each stated safeguard to an owner, a review date, and the evidence location so you can prove its execution later.</p></li><li><p>Run a quarterly ransomware-readiness review that includes both technical recovery controls and documentation quality.</p></li></ul><p><strong>Control Focus Areas:</strong></p><ul><li><p><strong>Evidence chain:</strong> Can you show the last review date, the owner, the control objective, and the supporting artifact for each safeguard?</p></li><li><p><strong>Training relevance:</strong> Does workforce training reflect the actual workflows where sensitive data, admin access, or urgent overrides occur?</p></li><li><p><strong>Auditability:</strong> If regulators or customers ask what changed after an incident, can you show the before-and-after and the approval record?</p></li></ul><h3>3. Computer-Use Agents Need an Approval Map Before They Need a Bigger Budget</h3><p><strong>Technical Detail:</strong> Google said that computer use is now built into Gemini 3.5 Flash for cross-platform tasks and explicitly described enterprise safeguards that may require user confirmation for sensitive or irreversible actions and can stop tasks when indirect prompt injection is detected. Google also positioned the capability for long-horizon tasks such as continuous software testing and knowledge work across professional applications.</p><p><strong>Actionable Strategy:</strong></p><ul><li><p>Classify AI workflows into advisory-only, draft-and-review, and permissioned-execution lanes.</p></li><li><p>Require a short design record before any live rollout: objective, systems touched, data boundary, approval step, stop condition, and rollback path.</p></li><li><p>Keep early pilots inside sandboxed or test environments whenever the workflow can alter systems, records, or customer-facing outputs.</p></li></ul><p><strong>Governance Focus Areas:</strong></p><ul><li><p><strong>Action authority:</strong> Which tasks can an agent complete versus prepare for human approval?</p></li><li><p><strong>Prompt-injection exposure:</strong> Which workflows touch live web content, inboxes, or vendor systems that could manipulate the agent?</p></li><li><p><strong>Economic guardrails:</strong> Who owns usage caps, exception approvals, and the cost of long-running automation?</p></li></ul><blockquote><p><strong>AN AGENT THAT CAN CLICK IS PART OF YOUR OPERATING MODEL, NOT JUST YOUR TOOLSTACK.</strong></p><p>If your organization is moving from chat prompts to computer-using workflows, the hard part is not generating output. It is controlling who can approve actions, what data the agent can touch, and how you recover when a task goes wrong.</p><p><strong>Airia</strong> is built for teams that need stronger AI orchestration, policy controls, and governance as agentic workflows move deeper into real business operations.</p><p><strong>Put guardrails around AI execution. <a href="https://try.airia.com/3bcae15ptpli">Explore Airia here</a></strong></p></blockquote><h2>Premium Template: Execution Authorization Matrix</h2><p>Use this template for any workflow where software, a human identity, or an AI agent can trigger an action that changes access, money movement, customer communication, or regulated records.</p><p><strong>Workflow name:</strong> <strong>Business owner:</strong> <strong>Technical owner:</strong> <strong>System or agent used:</strong> <strong>Trigger event:</strong> <strong>What can happen automatically:</strong> <strong>What requires confirmation:</strong> <strong>Sensitive data touched:</strong> <strong>Approval role required:</strong> <strong>Audit artifact retained:</strong> <strong>Rollback path:</strong> <strong>Budget or spend ceiling:</strong> <strong>Prompt-injection or spoofing exposure:</strong> <strong>Next review date:</strong></p><h2>Premium Checklist: 10-Day Verification Sprint</h2><ul><li><p>Identify the endpoints, browsers, and accounts that hold your most valuable sessions and tokens.</p></li><li><p>Reconfirm which privileged accounts still share devices or browsers for everyday browsing.</p></li><li><p>Document one current risk analysis for a high-sensitivity workflow and store the evidence where others can find it.</p></li><li><p>Verify audit logging, authentication, encryption, and training ownership for the same workflow.</p></li><li><p>Classify your current AI pilots into advise, draft, or act lanes.</p></li><li><p>Add approval gates for spending, external messaging, security changes, and record updates.</p></li><li><p>Name one person who can revoke sessions, disable an agent, or freeze a risky workflow after hours.</p></li><li><p>Test whether your rollback path is real for one automated or semi-automated workflow.</p></li><li><p>Review whether prompt injection or spoofing could reach any agent through inboxes, browsers, or web research tasks.</p></li><li><p>Schedule a follow-up review in 30 days to measure whether the controls changed behavior, not just documentation.</p></li></ul><h2>Premium Exercise: Friday 3:55 PM Verification Tabletop</h2><p><strong>Scenario:</strong> A finance manager reports strange browser prompts and reauthentication requests after visiting a vendor site. At the same time, a business unit asks to fast-track a new AI workflow that can log into internal tools and update project records automatically. Two hours later, legal asks whether the company can prove the current controls around sensitive data review after a recent ransomware scare.</p><p><strong>Exercise objectives:</strong></p><ol><li><p>Decide which sessions, accounts, and devices are frozen within the first 30 minutes, and who has the authority to do so.</p></li><li><p>Decide what evidence the organization can produce today about risk analysis, logging, authentication, and training for the affected workflow.</p></li><li><p>Decide which AI workflows can continue, which must pause, and what approval conditions must be met before it can act again.</p></li></ol><p><strong>Questions to work through:</strong></p><ol><li><p>Which account, device, or browser state would cause the largest business impact if it were silently abused for 24 hours?</p></li><li><p>If a regulator or major customer asked for proof of safeguards tomorrow morning, what artifacts would you actually hand over?</p></li><li><p>If the AI workflow made the wrong update in a live system, who would detect it, stop it, and reverse it?</p></li></ol><h2>Sources</h2><ul><li><p>Microsoft Security Blog, &#8220;StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them,&#8221; published June 24, 2026: https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/</p></li><li><p>HHS Office for Civil Rights, &#8220;HHS&#8217; Office for Civil Rights Settles Ransomware Investigation with Health Plan,&#8221; published June 18, 2026: https://www.hhs.gov/press-room/ocr-settles-ransomware-investigation-health-plan.html</p></li><li><p>Google Blog, &#8220;Introducing computer use in Gemini 3.5 Flash,&#8221; published June 24, 2026: https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-computer-use-gemini-3-5-flash/</p></li></ul><ul><li><p><strong>The &#8220;How-To&#8221; Framework:</strong> A step-by-step breakdown of the [Process/Tool] mentioned above.</p></li><li><p><strong>Resource Toolkit:</strong> Downloadable templates and checklists I use with my private coaching clients.</p></li><li><p><strong>The Bottom Line:</strong> Direct analysis of the ROI and cost-savings associated with this strategy</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Your Website Is Infrastructure: The Joomla Flaw Every SMB Should Act On This Week]]></title><description><![CDATA[Protect your SMB from the CVE-2026-48907 Joomla exploit. Unauthenticated attackers are dropping web shells. Here is your step-by-step incident response plan.]]></description><link>https://substack.cpf-coaching.com/p/your-website-is-infrastructure-the</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/your-website-is-infrastructure-the</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Tue, 23 Jun 2026 20:08:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GPAp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339170d3-a103-4dd1-a0ea-9ccf0af54f71_1024x559.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Last week, CISA added a maximum-severity vulnerability to its Known Exploited Vulnerabilities catalog: CVE-2026-48907, a flaw in the Joomla Content Editor (JCE) that carries the highest possible CVSS&#8230;</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/your-website-is-infrastructure-the">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This Week's SMB Risk Signals: Poisoned Packages, Imposter Losses, and the Arrival of AI Coworkers]]></title><description><![CDATA[SMB leaders: Discover how the Mastra npm hack, $3.5B FTC scam warnings, and AI coworkers impact your risk exposure&#8212;and what to lock down this week.]]></description><link>https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-poisoned</link><guid isPermaLink="false">https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-poisoned</guid><dc:creator><![CDATA[Christophe Foulon 📓]]></dc:creator><pubDate>Fri, 19 Jun 2026 16:06:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!M0jJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On June 17, 2026, Microsoft detailed a supply-chain compromise that poisoned more than 140 npm packages across the <code>mastra</code>  <code>@mastra</code> scopes. Two days earlier, on June 15, 2026, the Federal Trade Commission said people reported losing $3.5 billion to imposter scams in 2025, with business impersonation and fake security alerts driving some of the costliest losses. Then on June 16, 2026, Microsoft moved Copilot Cowork into general availability, pushing long-running, multi-tool AI work from preview into mainstream operating reality.</p><p>The three stories are different on the surface, but they point to the same leadership problem. SMB teams are letting software act faster than their control model can explain, verify, or contain. If your business runs on outsourced code, urgent digital communications, and newly embedded AI agents, your real risk is no longer just the tool. It is the speed of unreviewed execution.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M0jJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M0jJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!M0jJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!M0jJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!M0jJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M0jJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/96977059-b136-43ad-85da-957478905b92_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:708915,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://substack.cpf-coaching.com/i/202550059?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M0jJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!M0jJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!M0jJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!M0jJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96977059-b136-43ad-85da-957478905b92_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>1. Your Software Supply Chain Is Now an Endpoint Problem</h2><p>Microsoft said the Mastra compromise affected 140-plus packages and began with a taken-over npm maintainer account that injected a malicious <code>easy-day-js</code> dependency into published versions. The security team wrote that the poisoned package executed during installation, meaning any developer workstation or CI/CD pipeline that ran <code>npm install</code>  <code>npm update</code> after the compromised versions were published was potentially exposed, even if the package was never imported into application code.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>Install time became execution time:</strong> The malicious <code>postinstall</code> hook ran automatically during dependency installation, not after an engineer consciously invoked suspect code.</p></li><li><p><strong>This hit build systems as well as laptops:</strong> Microsoft explicitly warned that CI/CD environments, tokens, credentials, and downstream software integrity were all in scope.</p></li><li><p><strong>The attacker optimized for persistence, not smash-and-grab noise:</strong> Microsoft described staged delivery, a second-stage payload, cross-platform persistence, and a risk of token or environment exposure. That is an operations problem, not just a dev-team problem.</p></li></ul><p><strong>Strategic Action:</strong> Treat your build and package ecosystem like privileged infrastructure. If an SMB leadership team still thinks dependency hygiene belongs only to engineering, this is the week to correct that assumption.</p><p>Three steps to take this week:</p><ol><li><p>Identify every workstation, build runner, or hosted pipeline that touched affected Mastra package versions on or after June 16, 2026.</p></li><li><p>Rotate developer tokens, CI secrets, and cloud credentials that may have been present where those packages were installed.</p></li><li><p>Require a high-risk dependency review pattern for critical builds: pinned versions, script-aware install review, and a named owner for package exceptions.</p></li></ol><div class="pullquote"><p>If a poisoned dependency can turn a developer laptop or build runner into an execution point, <strong><a href="https://get.bitdefender.com/8gk9x38k25bv">Bitdefender</a></strong> is a practical fit for SMB teams that need stronger endpoint protection, isolation, and response coverage without staffing a large in-house SOC.</p></div><h2>2. Impersonation Is No Longer &#8220;Just Fraud&#8221;</h2><p>The FTC said on June 15, 2026, that imposter scams were the most reported fraud category in 2025 and that reported losses climbed to $3.5 billion. The agency also said nearly one in three fraud reports involved impersonation and that reported losses reached nearly $1 billion for business impersonators and about $920 million for government impersonators. The FTC specifically called out fake security alerts, often posing as banks, as a costly tactic used to convince people to move money to &#8220;protect&#8221; it.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>The attack path is multi-channel:</strong> The FTC said these scams reached people through text, phone, email, social media, and search results. That means the weak point is not one inbox.</p></li><li><p><strong>The financial control gap is obvious:</strong> Fake urgency still works because too many businesses let a single message trigger a rushed action.</p></li><li><p><strong>Impersonation now rides your brand, your vendors, and your bank relationships:</strong> If your email authentication and callback practices are weak, your organization helps create the attack surface.</p></li></ul><p><strong>Strategic Action:</strong> Stop treating impersonation as solely a user-awareness problem. It is a workflow-design problem. The question is whether your payment, approval, and identity-verification paths still assume that a familiar name is good enough.</p><p>Three steps to take this week:</p><ol><li><p>Set a hard callback rule for payment changes, account-recovery requests, and urgent financial instructions, using known numbers only.</p></li><li><p>Lock down who can approve wire changes, vendor-bank updates, and emergency purchases without a second person's verification.</p></li><li><p>Review your email domain protection and anti-spoofing controls to reduce exposure for customers, staff, and partners to fake versions of your brand.</p></li></ol><blockquote><p><strong>IF YOUR DOMAIN CAN BE SPOOFED, YOUR BRAND BECOMES PART OF THE ATTACK CHAIN.</strong></p><p>FTC data shows impersonation losses are scaling because attackers exploit trust faster than most teams validate identity. Email authentication is not glamorous, but it is one of the clearest ways to reduce spoofing and brand-abuse risk.</p><p><strong>EasyDMARC</strong> helps organizations strengthen DMARC, DKIM, and SPF so brand impersonation, phishing exposure, and email-deliverability risk become easier to see and manage.</p><p><strong>Reduce spoofing risk. <a href="https://partners.easydmarc.com/opuv05et0ukc">Review EasyDMARC here</a></strong></p></blockquote><h2>3. AI Coworkers Are Moving Into Real Operating Lanes</h2><p>On June 16, 2026, Microsoft announced the general availability of Copilot Cowork worldwide. Microsoft described it as an agentic system that executes complex, long-running, multi-tool tasks end-to-end and returns completed results, not just drafts or recommendations. The company also emphasized that Cowork is off by default, uses usage-based billing, and now includes admin controls for access, budgets, alerts, and visibility.</p><p><strong>Why You Should Be Concerned:</strong></p><ul><li><p><strong>This is a shift from prompts to execution:</strong> Microsoft is commercializing AI work that runs across tools, data, and time, not just one-off chat outputs.</p></li><li><p><strong>Cost and authority now matter as much as model quality:</strong> The release makes explicit what many SMB leaders have not yet operationalized: agentic AI needs budgets, access controls, and workflow boundaries.</p></li><li><p><strong>The adoption pressure will move downstream fast:</strong> Even if your firm is not buying Copilot Cowork today, the market signal is clear. Vendors are normalizing AI systems that act, spend, and retrieve context at scale.</p></li></ul><p><strong>Strategic Action:</strong> Do not wait until staff brings agentic workflows in through a pilot, a plugin, or a department budget. Define where AI can act, where it can advise, and where a human must still approve.</p><p>Three steps to take this week:</p><ol><li><p>Name three workflows where AI may assist but not execute without review, such as customer promises, financial approvals, or regulated communications.</p></li><li><p>Assign an owner for AI tool budgets, usage review, and data-boundary decisions before you approve broader rollouts.</p></li><li><p>Pilot one agentic use case with a written success metric, a spending cap, and a required post-run review of output quality and side effects.</p></li></ol><h3>Final Thoughts for Leaders</h3><p>The convergence of poisoned dependencies, scaled impersonation fraud, and agentic AI rollout means SMB leadership has to rebuild trust as an operating system, not a slogan. The real question is not whether your team is moving fast. It is whether your approvals, logs, endpoints, domains, and AI rules are mature enough to keep speed from turning into silent exposure. Put software supply-chain ownership, impersonation controls, and AI execution boundaries on your next leadership agenda before this week ends.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">SMB Tech &amp; Cybersecurity Leadership Newsletter is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Help Other Leaders Secure Their Future</h3><p><strong>The Network Effect of SMB Security</strong> </p><p>The most effective way to strengthen our SMB community is to share strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone&#8217;s business.</p><p><strong>Why Share This Subscription?</strong> When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team:</p><ul><li><p><strong>Zero-fluff technical execution:</strong> No high-level theory, just the steps to implement.</p></li><li><p><strong>Cost-saving vendor analysis:</strong> Honest looks at which tools are worth the cost for SMB budgets.</p></li><li><p><strong>Direct coaching frameworks:</strong> Access to the same logic I use with private coaching clients.</p></li></ul><p><strong>Pay It Forward:</strong> Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-poisoned?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-poisoned?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post&quot;,&quot;text&quot;:&quot;Refer a friend&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/leaderboard?&amp;utm_source=post"><span>Refer a friend</span></a></p><p>You&#8217;ve seen the "Why" behind this [Cyber/Tech Issue]&#8212;but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan.</p><p>The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock Premium Intelligence: The SMB Trust-and-Automation Implementation Pack.</p><blockquote><p style="text-align: center;"><strong>Subscribe to Unlock the Full Strategy</strong> </p><p style="text-align: center;"><em>Join a community of SMB leaders who stop reacting to tech shifts and start leading them.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://substack.cpf-coaching.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://substack.cpf-coaching.com/subscribe?"><span>Subscribe now</span></a></p></blockquote><p>Premium readers get the implementation layer: the concrete controls, governance structure, and team exercises that turn this week&#8217;s signals into operating discipline.</p>
      <p>
          <a href="https://substack.cpf-coaching.com/p/this-weeks-smb-risk-signals-poisoned">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>