SoHo Integration

SoHo Integration www.soho-integration.com
With our expertise, you can reduce or eliminate the stress, challenges, and costs of trying to meet your own IT needs.

Running and growing a business can be one of the most rewarding things you do in life...it can also be one of the most frustrating and challenging accomplishments you embark on. As a small business owner myself, I understand that you need solutions that enable you to run your business the way you want without putting a strain on your two most valuable resources - time and money.

06/19/2026

Hardest sentence in cybersecurity:

"I thought I did the right thing."

We turned on MFA last year.

We bought the antivirus the bank recommended.

We trained the team every quarter.

We had backups.

And then a phishing email got past everything, an attacker proxied the MFA token, and a wire to a "vendor" left the account before anyone noticed.

This isn't a story about bad owners. It's a story about a moving target. The control list that was enough in 2022 isn't the same control list that's enough in 2026. AiTM phishing kits make standard MFA defeatable. 340+ Microsoft 365 tenants were hit by the EvilTokens device-code phishing kit between February and April this year (The Hacker News, March 2026). 67% of all 2026 incidents traced back to identity attacks (Sophos 2026), not vulnerabilities.

If "we did the right things" doesn't always equal "we're protected," then the most useful thing an owner can do is calibrate where their readiness actually sits today, not where it was when they last reviewed it.

That calibration is the entire purpose of the Cybersecurity Self Assessment. 15 minutes. Plain language. A real picture of where you are.

https://security.sohomsp.net/

06/16/2026

A 22-employee marketing agency owner told me last month:

"We finally fired our $89/seat IT guy. We were saving $1,000 a month."

Then she sent me the invoice from the breach.

$14,200 in incident response.

$4,800 in client credits (two clients churned, one stayed).

$8,000 increase on her next cyber insurance renewal.

Three weeks of nights and weekends she'll never get back.

She wasn't saving $1,000 a month. She was financing $27,000 against her business with monthly payments she didn't know she was making.

This isn't a fear post. It's a math post.

"Cheap IT" usually means three things:
- A one-person shop with no after-hours coverage
- A stack of consumer tools held together with tape
- No documentation, no playbook, no insurance-grade controls

You don't need to pay enterprise rates. You need to pay for IT that's designed for your size and configured correctly the first time.

For a 10-50 person business, the right number is somewhere between $125 and $250 per user per month for fully-managed IT and cybersecurity. Less than that and you're buying a person, not a stack. More than that and you're paying for capabilities you won't use until you're 100+ people.

The cheap IT bill always comes due. The only question is what month it's going to show up.

https://getstarted.sohomsp.net/

06/15/2026

What's the worst IT advice you've ever gotten from a vendor, an MSP, or a well-meaning "IT-savvy" friend?

I'll start.

"You don't need MFA, just have a strong password." 2019. From a vendor. We were six people. We turned MFA on anyway.

06/13/2026

Myth: "Our backup is in the cloud, so we're fine."

The reality: there are three different things people call "cloud backup" and only one of them protects you from a ransomware event.

1. **OneDrive / SharePoint sync.** This is file storage with version history. If ransomware encrypts a file, the encrypted version syncs to the cloud and overwrites the good version. Version history can save you, but only if you catch it within the retention window (default 30 days, often misconfigured).

2. **Microsoft 365 itself.** Microsoft does not back up your M365 data the way you think it does. Their shared responsibility model covers infrastructure availability, not your ability to restore deleted or maliciously encrypted data after retention windows close. If a user (or attacker) wipes a mailbox or SharePoint site, your standard M365 plan will not restore it after 30-93 days depending on the data type. This surprises owners every single time.

3. **Third-party SaaS backup (the actual backup).** A dedicated backup tool like Veeam, Datto, Acronis, or Barracuda, with immutable storage, retention you control, off-network copies, and tested restores. This is what "backed up" means in 2026 if you're serious about it.

The question isn't "are we backed up?" The question is "if a user clicks the wrong link tomorrow and our M365 tenant gets encrypted, can we restore the last 90 days of everything, and have we tested it in the last quarter?"

If you can't say yes to both halves, you're using the word "backup" to mean something different than what your insurer means by it.

You hit 15 employees and something quietly broke.Most owners I talk to can name three of these from memory. Some can nam...
06/12/2026

You hit 15 employees and something quietly broke.

Most owners I talk to can name three of these from memory. Some can name all five before I finish the carousel.

The fix is not enterprise complexity. It is a stack designed for your size, built to grow with you.

https://getstarted.sohomsp.net/

06/11/2026

If something hit your business at 2am on a Sunday, who responds?

Not who gets the email. Who actually opens a laptop, logs into your systems, and starts containing it.

If you've never had that conversation with your IT provider, you're not alone. Most growing businesses haven't.

It's also one of the most useful questions to think through, because 88% of ransomware payloads in 2026 detonate outside business hours (Sophos Active Adversary Report 2026). It's not a coincidence. Attackers run the math too.

The Cybersecurity Self Assessment includes this question, in plain English. The point isn't to scare you. The point is to give you a clear-eyed answer to a question that most owners have never been asked.

15 minutes. Self-assessment. Not an audit, not a sales call.

https://security.sohomsp.net/

06/10/2026

If you've been quietly wondering whether you should fire your MSP, you're not alone, and you're probably right.

The nine signs that reliably predict an MSP has stopped keeping up:

1. They can't tell you your security score on a recognized framework
2. Same tickets keep recurring quarterly
3. MFA is "on" but not enforced, and they haven't flagged it
4. They've never produced cyber insurance documentation for you
5. Response times have crept from 30 minutes to 4 hours
6. ...

I wrote the full nine, plus the 60-day playbook for switching MSPs without losing email, files, or downtime.

https://soho-integration.com/9-signs-time-to-switch-msp

06/09/2026

We saw this in a client's Microsoft 365 tenant last week.

A reasonable, growing business. 38 employees. They turned on MFA last year. They have an MSP. They were doing the right things.

We were doing a routine readiness review and we pulled up the list of third-party apps that had been granted access to their tenant over the past three years.

There were 47 of them.

Most were fine. Slack. Zoom. DocuSign. The usual.

But mixed in were a Chrome extension a marketing intern installed in 2023 that had Mail.ReadWrite and Files.Read.All permissions. A "PDF converter" that had been authorized by a sales rep who left in 2024. A "calendar assistant" nobody could identify.

These weren't hackers. They were forgotten permissions. Each one is a quiet doorway someone left propped open.

The owner asked the right question: "How would I have ever noticed this?"

Answer: you wouldn't. Nobody looks at the OAuth consent app list. It's not on any standard dashboard. It's not in any standard report. It just builds up over years until someone decides to look.

This is the kind of area worth considering that doesn't show up until you go look for it. It's one of the things the Cybersecurity Self Assessment surfaces, because the question on the assessment is "do you regularly review third-party app permissions in your Microsoft 365 tenant?" and the honest answer for most growing businesses is "no, because nobody ever told us to."

Areas like this aren't dangerous because someone's actively attacking them. They're worth considering because they accumulate.

https://security.sohomsp.net/

06/08/2026

77% of employees share sensitive company data with AI tools.

63% of organizations have no AI governance policy. (IBM Cost of a Data Breach 2025; Cyberhaven 2026)

The math on this isn't dramatic. It's just inevitable. If you don't define what AI tools your team can use, with what data, your team will use whichever ones they want, with whatever data is convenient.

The fix isn't banning AI. Banning doesn't work and tanks morale. The fix is a one-page AI Acceptable Use Policy that approves the good tools, restricts the risky ones, and gives employees a clear answer when they're not sure.

I wrote the template, the 7 sections every SMB AUP needs, and a 90-day rollout plan that won't kill productivity.

https://soho-integration.com/ai-acceptable-use-policy-template-2026

06/07/2026

We saw this in a client's Microsoft 365 tenant last week.

Sales rep left the company in November 2024. Standard departure. Final paycheck, exit interview, polite goodbye.

Eighteen months later we're doing a readiness review. We pull a report of all active accounts. There's her name.

Active. Mailbox still receiving mail. License still being paid for.

We checked her sign-in logs. She hadn't signed in since the day she left.

But:
- One forwarder rule on her mailbox was sending every email to a personal Gmail address.
- Three SharePoint documents were still showing her as the owner.
- Her account was in two distribution lists that received customer escalations.

This happens constantly. It's nobody's fault specifically and everybody's fault generally. HR notifies someone, that someone wasn't the right someone, the ticket was closed, the account stayed active.

The fix isn't a tool. The fix is a documented offboarding checklist with one person accountable for the M365 piece, executed within 24 hours of the last day. Disable account, revoke mailbox access, kill active sessions, reassign owned SharePoint and Teams content, remove from distribution lists, transfer OneDrive, deactivate any third-party app grants.

We see this so often that it's the second question on our readiness review (right after MFA enforcement). Most growing businesses have at least one of these quietly sitting in their tenant. Worth a look this week.

Address

701 N Hermitage Road, Building 2, Suite 17
Hermitage, PA
16148

Opening Hours

Monday 8am - 4:30pm
Tuesday 8am - 4:30pm
Wednesday 8am - 4:30pm
Thursday 8am - 4:30pm
Friday 8am - 4:30pm

Telephone

+17246387646

Alerts

Be the first to know and let us send you an email when SoHo Integration posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to SoHo Integration:

Share