Lewis IT, LLC

Lewis IT, LLC Computer / IT consulting and repair service for your home or business. Managed IT Service Provider

07/13/2026

If someone asks whether your business has backups, you probably say yes. Disaster recovery is a different question.

A backup is a copy of your data. Disaster recovery is the plan that brings your business back to running condition after something goes wrong. The two get confused all the time, and the confusion costs real money when ransomware or a hardware failure hits.

A good backup setup follows the 3-2-1-1-0 rule: three copies of every important file, on two different types of storage, with one copy stored offsite, one copy that's immutable so ransomware can't encrypt it, and zero errors in your last test restore.

That last one is what most businesses skip. Untested backups are not backups.

They're an unverified promise.

Pick a normal file, an email, and a full server volume, then try to restore each one to a different location.

If the restore works, you have backups. If it doesn't, you have a problem you can fix today instead of during an attack.

Disaster recovery goes one layer further. It's the playbook for what your business does when it can't function. Things like which systems come back first, which people make decisions, which vendors get called, and how long each step is supposed to take. Without that playbook, even a working backup leaves you guessing during the worst week of your year.

In April 2026, ransomware hit Adaptavist, an Atlassian platinum partner that builds and supports tools for thousands of ...
07/12/2026

In April 2026, ransomware hit Adaptavist, an Atlassian platinum partner that builds and supports tools for thousands of business customers.

Adaptavist makes ScriptRunner and similar add-ons that plug into Atlassian products like Jira and Confluence. When attackers got into Adaptavist's systems, every customer connected to those tools was suddenly downstream of a breach they didn't cause.

This is the supply chain attack pattern. Your business doesn't have to be the target. It just has to share a vendor with the target.

Three things worth doing this month:

-Make a one-page list of every SaaS vendor your business depends on. Email, accounting, payroll, CRM, helpdesk, file storage, project management. The list is usually longer than you'd expect.
-For each vendor, find their security and breach notification page online. If you can't find it in five minutes, that's information worth knowing.
-For the top five vendors by data sensitivity, ask three questions in writing: do you have a current SOC 2 Type II report, what's your breach notification SLA, and how do you handle credentials inside your support tooling.

You can't control every vendor's security. Pick the ones that take it seriously.


: Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole

07/11/2026

Your incident response plan needs to live on paper, because the second you need it, your computers and email are the thing that's broken.

A one-page version beats nothing. The most important piece is the contact list, because those are the phone numbers you can't get to once your systems are down. Print this list and keep one copy at the office and one at home.

Six contacts to have on paper:

1. Your cyber insurance broker. They open the door to every other resource your policy covers. Save the after-hours line, not just the main number.
2. Your breach attorney. Not your business attorney. A specialist in cyber incidents. Their first job is to create legal privilege over the response.
3. Your incident response firm. If your insurance assigns one, save the IR firm's name and 24/7 line on this same page.
4. Your IT provider or MSP. Direct line for the senior engineer, not the front desk.
5. Law enforcement. FBI IC3 (1-800-CALL-FBI / ic3.gov) and your state cyber unit if you have one.
6. Two business lifelines. Your bank's fraud line and your payroll provider's emergency line. Both can freeze transactions if an attack is in progress.

Once ransomware locks your email and laptops, the only contact list you can reach is the one you printed.

07/10/2026

"We're too small to be a target" is the most expensive belief in small business security today.

The math behind modern attacks runs the opposite direction. Attackers don't sit at desks picking targets one by one. They run automated scans that hit millions of IP addresses every day looking for known vulnerabilities. Once a scan finds an open port, an unpatched server, or a leaked password that still works, the attacker rolls in. They don't know or care how big your business is until they're already inside.

Industry data is consistent here. The Verizon DBIR, FBI IC3 reports, and Sophos State of Ransomware all show small and medium businesses make up the majority of confirmed cybercrime victims year after year. The volume keeps climbing.

The reason is simple. You hold most of the same data the big ones do (customer records, payment info, employee information), and you have fewer people watching for attacks. That makes your business faster to compromise and easier to monetize. Attackers don't need a billion-dollar prize. They need a quick, simple win, and your business qualifies.

If you've ever skipped a security investment because your business felt too small to matter, the math says otherwise.

In May 2026, the US government's cybersecurity agency added a top-severity Cisco vulnerability to its "fix this now" lis...
07/09/2026

In May 2026, the US government's cybersecurity agency added a top-severity Cisco vulnerability to its "fix this now" list.

The flaw lives in Cisco SD-WAN controllers. These are the devices many businesses use to connect remote offices, branch locations, or remote workers to their main network. The vulnerability scored a 10.0 out of 10 on the standard severity scale, which means an attacker who reaches the device over the internet can take it over completely. Once they're in, they have the keys to the network the device sits on.

CISA's "fix it now" list, formally called the Known Exploited Vulnerabilities catalog, is the list of bugs that hackers are already actively using. Federal agencies have a hard deadline to patch anything on it. Your business should be just as fast.

If you use Cisco SD-WAN, your IT team or MSP should already be on this. If you're not sure, ask them today: "Do we have any Cisco SD-WAN devices anywhere in our network?" The answer is yes, no, or "let me check." Only the third one needs follow-up.

The CISA KEV catalog is free, public, and updated weekly. It's the closest thing to a "what to patch first" list for businesses without a full security team.


CISA added CVE-2026-20182, a CVSS 10.0 Cisco Catalyst SD-WAN Controller authentication bypass flaw, to its KEV catalog.

07/08/2026

The first 24 hours after a suspected breach decide whether the next six months are manageable or catastrophic.

Most of the damage in those hours comes from actions that feel productive but cost you later. The order that works:

1. Stop. Don't touch infected machines or systems. The forensic evidence on them is what determines whether your insurer covers you and whether you can prosecute later.
2. Call your cyber insurance broker. They will assign you an incident response firm and a breach attorney, often within the hour. Both fees are usually covered by your policy.
3. Call your breach attorney before you call your IT person. The attorney creates legal privilege over everything that follows, which protects you if the incident ends up in court.
4. Let the incident response firm lead. They contain the attack, collect evidence, and advise on ransom decisions. Your job is to authorize the work, not perform it.
5. Notify law enforcement. FBI IC3 at ic3.gov, or your state's cyber unit. Required in some states, helpful in all of them.
6. Don't tell your team, customers, or social media anything until your attorney clears the message.

The first call you make matters more than every action that follows.

07/07/2026

Your bookkeeper picks up a call after hours. The voice on the other end sounds exactly like the founder, asking for a $40,000 wire to a new vendor before the bank closes.

That kind of call is happening more often in 2026. Attackers can now clone a voice from just a few seconds of public audio, and the result is a phone-call-shaped scam that almost no business owner has trained their team against.

Three seconds of LinkedIn video, a podcast clip, or a webinar recording. Any of those is enough to feed an AI voice model. Once the model has the voice, the attacker types whatever they want and your founder's voice says it back. Banks and accounting teams don't catch this in the moment. The voice is too good.

The fix is older than the technology. Set up a verification code word inside your business this week. Any wire transfer, vendor change, payroll change, or unusual money request requires the person making the call to say the code word first. No code, no money. Tell your team this rule out loud, write it down somewhere paper-based, and remind them every 90 days.

The attacker can clone your voice. They can't clone your code word.

07/06/2026

MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.

The attacker already has the password (bought from a leak or stolen from another site). They log in. The MFA push hits your employee's phone. They tap "Deny." The attacker tries again 10 seconds later. Then again at 2am. Then during lunch. Eventually someone taps "Approve" just to make it stop. The attacker is in.

Uber got hit this way in 2022. Cisco too. It still works on small businesses every week because passwords keep leaking and the push prompt looks identical to a real login.

Three things close the gap, and none of them are expensive. Switch your team from "tap to approve" to number matching, which both Microsoft Authenticator and Duo support out of the box and takes about 10 minutes to enable in your tenant. Then turn on geo-blocking or impossible-travel rules in your identity platform so logins from countries you don't operate in get blocked before the push ever fires. Last, give your team one rule: if you get an MFA prompt you didn't ask for, deny it AND report it. The report is what catches the attacker mid-attempt.

The attacker doesn't need a fancy hack. They just need someone tired enough to tap "Approve."

Microsoft's phishing report for the first quarter of 2026 shows how much phishing has changed in the past year.In three ...
07/05/2026

Microsoft's phishing report for the first quarter of 2026 shows how much phishing has changed in the past year.

In three months:

-8.3 billion phishing threats detected
-QR code phishing up 146% from last year, with a 336% spike in March 2026 alone for QR codes hidden inside emails
-Phishing pages hiding behind CAPTCHA puzzles jumped 125%. CAPTCHAs make the pages look real AND stop security scanners from checking them.
-10.7 million business email compromise attempts in one quarter

Hackers moved from text to images, codes, and CAPTCHAs because text-based filters can't read them. Even an expensive email gateway misses most of this.

If your phishing training still shows examples of misspelled emails from "Nigerian princes," you're teaching your team history, not security.

What to do this month:

-Update your phishing training. If it doesn't include QR code emails and fake CAPTCHA login pages, you're testing 2023 skills against 2026 attacks.
-Tell your team one rule: any QR code that arrives in an email is suspicious. No exceptions.
-Ask your email security vendor what they catch for image and QR phishing. Get the answer in writing.

Train your team for the phishing they'll actually see this year.


Microsoft noted a marked increase in QR-code attacks and CAPTCHA delivery methods.

07/04/2026

The ransom is usually the smallest cost of a ransomware attack on a small business.

A 25-person company often takes 3 to 6 weeks to fully recover from one. Most of that cost has nothing to do with the criminals.

What 3 to 6 weeks of downtime actually costs you:

-Payroll. 25 people getting paid for a month or more with almost no productive output. Easily $200K to $400K, depending on your industry.
-Lost revenue. Whatever your business normally pulls in over that window, gone.
-Lost customers. Public breaches drive customer churn, especially in industries built on trust. Different studies put the rate anywhere from 5% to 30% in the year after.
-Outside costs. Incident response firm fees, breach lawyers, state notification rules, credit monitoring for affected customers.
-Higher insurance. Cyber premiums often double or triple at your next renewal.

You might pay the ransom once. The downtime bills you for months.

Want a fair estimate of your real exposure? Take your monthly payroll, multiply by 1.5. Add your monthly revenue times 1.5. Add 20% on top for everything else. That's the kind of number to put in front of your leadership team the next time someone asks why you're spending on security.

Address

Waldorf, MD

Alerts

Be the first to know and let us send you an email when Lewis IT, LLC posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share