InnoPrince Inc.

InnoPrince Inc. Helping businesses to keep up with the technology, so they can focus on growing their business. IT Service Provider
https://www.innoprince.com

Passwords are on their way out - passkeys are ready to take their place, right now. Your fingerprint or face confirms it...
04/08/2026

Passwords are on their way out - passkeys are ready to take their place, right now. Your fingerprint or face confirms it's you, so there's no password left to steal or phish. Start with your email and your Microsoft/Google login - those are the ones attackers go after most, since most break-ins still begin with a stolen password.

Anyone can send an email that looks like it came from your company. Three DNS records are what stop it: SPF, DKIM, and D...
03/08/2026

Anyone can send an email that looks like it came from your company. Three DNS records are what stop it: SPF, DKIM, and DMARC. The catch? Most businesses set DMARC to "monitor only" — which just watches spoofed emails go through without actually blocking them. Ask your IT provider one question: Is our DMARC set to reject, or is it still sitting on none?

MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.The attac...
24/07/2026

MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.

The attacker already has the password (bought from a leak or stolen from another site). They log in. The MFA push hits your employee's phone. They tap "Deny." The attacker tries again 10 seconds later. Then again at 2am. Then during lunch. Eventually someone taps "Approve" just to make it stop. The attacker is in.

Uber got hit this way in 2022. Cisco too. It still works on small businesses every week because passwords keep leaking and the push prompt looks identical to a real login.

Three things close the gap, and none of them are expensive. Switch your team from "tap to approve" to number matching, which both Microsoft Authenticator and Duo support out of the box and takes about 10 minutes to enable in your tenant. Then turn on geo-blocking or impossible-travel rules in your identity platform so logins from countries you don't operate in get blocked before the push ever fires. Last, give your team one rule: if you get an MFA prompt you didn't ask for, deny it AND report it. The report is what catches the attacker mid-attempt.

The attacker doesn't need a fancy hack. They just need someone tired enough to tap "Approve."

When an employee leaves your business, the security gap is usually bigger than you'd think.A typical 25-person business ...
23/07/2026

When an employee leaves your business, the security gap is usually bigger than you'd think.

A typical 25-person business has dozens of cloud accounts per employee: email, payroll, file storage, CRM, accounting, internal tools, and other SaaS subscriptions.

When someone leaves, every one of those accounts should be disabled. In most businesses, only the obvious ones get touched — email, computer login. The rest sit dormant for months or years, still active with that person's old credentials.

That's how someone who left 18 months ago becomes the entry point for next year's breach — and if any of that dormant access involves customer or employee personal data, it's also a Data Privacy Act exposure you don't want to explain to the NPC.

The fix: build IT offboarding into your existing clearance process, not as a separate afterthought.

𝗗𝗮𝘆 𝗼𝗳 𝗱𝗲𝗽𝗮𝗿𝘁𝘂𝗿𝗲: Disable email, computer login, VPN, and any single sign-on (SSO) account that gates everything else.
𝗪𝗶𝘁𝗵𝗶𝗻 𝟰𝟴 𝗵𝗼𝘂𝗿𝘀: Revoke access on every SaaS tool by checking the actual admin panel of each one — don't rely on memory.
𝗪𝗶𝘁𝗵𝗶𝗻 𝟳 𝗱𝗮𝘆𝘀: Change any shared credentials the employee knew (shared logins, Wi-Fi passwords, group accounts).
𝗪𝗶𝘁𝗵𝗶𝗻 𝟯𝟬 𝗱𝗮𝘆𝘀: Sign-off is only complete once IT confirms all system access is revoked — make this part of the clearance form itself, alongside HR and finance sign-off.

Without a checklist, "what did this person have access to?" becomes impossible to answer a few months later.

Smishing is phishing over text message, and right now it's working better than email phishing ever did.The reason is sim...
22/07/2026

Smishing is phishing over text message, and right now it's working better than email phishing ever did.

The reason is simple. Businesses spent the last decade locking down email and training people to spot suspicious links. Almost nobody did the same for text messages. So that's the channel where people still tap first and think later.

The patterns keep repeating: a "delivery failed" text asking you to log in through a link, a "this is your CEO" message from an unknown number asking for gift cards or a wire transfer, a fake bank lockout alert that looks completely real, or a "hey, quick favor, I'm in a meeting" text pretending to be someone senior.

These work because texts feel personal in a way email never does. They land on the same screen as messages from your spouse, your kids, your coworkers — so your brain defaults to trusting them. That's really the whole attack.

Give your team these rules:

1. 𝗡𝗼 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗱𝗲𝗰𝗶𝘀𝗶𝗼𝗻𝘀 𝗵𝗮𝗽𝗽𝗲𝗻 𝗼𝘃𝗲𝗿 𝘁𝗲𝘅𝘁. Ever. Not wires, vendor changes, payroll updates, gift card requests, or password resets.
2. 𝗜𝗳 𝗮 𝘁𝗲𝘅𝘁 𝗰𝗹𝗮𝗶𝗺𝘀 𝘁𝗼 𝗯𝗲 𝗳𝗿𝗼𝗺 𝗮 𝗰𝗼𝘄𝗼𝗿𝗸𝗲𝗿, 𝘃𝗲𝗿𝗶𝗳𝘆 𝗮 𝗱𝗶𝗳𝗳𝗲𝗿𝗲𝗻𝘁 𝘄𝗮𝘆 𝗳𝗶𝗿𝘀𝘁. A quick Slack message or phone call kills most of these attempts instantly.
3. 𝗡𝗲𝘃𝗲𝗿 𝗰𝗹𝗶𝗰𝗸 𝗮 𝗹𝗼𝗴𝗶𝗻 𝗹𝗶𝗻𝗸 𝗶𝗻𝘀𝗶𝗱𝗲 𝗮 𝘁𝗲𝘅𝘁. Go to the app or website directly instead.
4. 𝗥𝗲𝗽𝗼𝗿𝘁 𝘀𝘂𝘀𝗽𝗲𝗰𝘁𝗲𝗱 𝘀𝗺𝗶𝘀𝗵𝗶𝗻𝗴 𝘁𝗼 𝘆𝗼𝘂𝗿 𝘁𝗲𝗹𝗰𝗼. PLDT/Smart: text "SPAM" + the number to 7726. Globe/TM: text "REPORT [number]" to 8080. DITO: report through the DITO app. This helps your provider block the source for everyone.

Smishing only works when people react before they think. Train your team to pause, and most of these attacks stall out before the attacker gets anywhere.

Your salesperson stops at a coffee shop between meetings. Laptop open, drink ordered, name gets called at the counter. T...
21/07/2026

Your salesperson stops at a coffee shop between meetings. Laptop open, drink ordered, name gets called at the counter. They step away for 90 seconds.

That's all it takes to ruin your week.

The attacker doesn't need to be a genius. A $40 device called a "Rubber Ducky" plugs into the USB port and pretends to be a keyboard. It types pre-loaded commands faster than any human — open a terminal, download a remote access tool, install it, disable the screen lock warning. All in 90 seconds. No clicks from your salesperson required.

When they get back to the table, everything looks exactly like they left it. Nothing's different — until the next time that laptop connects to your office network, and the attacker has a way in.

This isn't new. It's been demonstrated at security conferences for a decade. What's changed is the hardware's gotten cheaper, so more people can pull it off.

The fix is simple:

𝗔𝘂𝘁𝗼-𝗹𝗼𝗰𝗸 𝗲𝘃𝗲𝗿𝘆 𝗹𝗮𝗽𝘁𝗼𝗽 𝗮𝗳𝘁𝗲𝗿 𝟯𝟬 𝘀𝗲𝗰𝗼𝗻𝗱𝘀 𝗼𝗳 𝗶𝗻𝗮𝗰𝘁𝗶𝘃𝗶𝘁𝘆. Train your team: unattended laptop gets locked, no exceptions.
𝗗𝗶𝘀𝗮𝗯𝗹𝗲 𝗨𝗦𝗕 𝗮𝘂𝘁𝗼-𝗲𝘅𝗲𝗰𝘂𝘁𝗲 𝗮𝗰𝗿𝗼𝘀𝘀 𝘆𝗼𝘂𝗿 𝗱𝗲𝘃𝗶𝗰𝗲𝘀. On Windows, that's AutoPlay settings plus USB blocking through Group Policy or Intune.
𝗥𝘂𝗻 𝗘𝗗𝗥 𝘀𝗼𝗳𝘁𝘄𝗮𝗿𝗲 that flags new processes and suspicious activity within seconds of something being installed.
𝗚𝗶𝘃𝗲 𝗳𝗿𝗲𝗾𝘂𝗲𝗻𝘁 𝘁𝗿𝗮𝘃𝗲𝗹𝗲𝗿𝘀 𝗨𝗦𝗕 𝗱𝗮𝘁𝗮 𝗯𝗹𝗼𝗰𝗸𝗲𝗿𝘀 — small adapters that let a laptop charge but block data transfer. Great for airports and coffee shops.

Most of your security lives in software, but physical security still matters. Don't let those five steps to the counter be the weakest link in your whole setup.

The old rules about strong passwords are outdated.For years, standard advice was 8 characters, mix uppercase and lowerca...
17/07/2026

The old rules about strong passwords are outdated.

For years, standard advice was 8 characters, mix uppercase and lowercase, and add a number and a symbol. NIST, CISA, and Microsoft's own security team all moved away from that years ago. The current recommendation is simpler and stronger: use long passwords or passphrases, and stop forcing scheduled rotations.

The math explains why. Modern cracking hardware can guess a complex 8-character password in under an hour. A 16-character passphrase made of everyday words takes centuries on that same hardware. Length beats complexity — every extra character multiplies the work an attacker has to do, while symbols and numbers only add minor friction.

Here's the update for your business:

- Minimum 14 characters for general accounts, 16+ for admin or sensitive ones
- Drop mandatory rotation — it creates more weak passwords than it prevents
- Drop strict complexity rules too — they push people toward predictable patterns
- Block any password that shows up in known breach databases
- Require MFA on every account that supports it

If your business is still running 8-character passwords with quarterly resets, you're following 2010's rules. The new ones are easier on your team and harder on attackers.

Most of the tools your team actually uses to get work done are probably not on your IT list.Personal Dropbox accounts ho...
16/07/2026

Most of the tools your team actually uses to get work done are probably not on your IT list.

Personal Dropbox accounts holding client files. ChatGPT with confidential info pasted in. A Trello board marketing set up a year ago. A Notion workspace someone in ops runs from their phone. This is shadow IT, and every business has more of it than they think.

The risk hits in two places. First, business data ends up sitting in accounts you don't control and can't delete. When that employee leaves, the data stays exactly where they put it. Second, none of these tools are set up with your security in mind — weak or missing MFA, no data loss prevention, no retention policy, no audit log to check when something goes wrong.

You don't need a crackdown to fix this. Just ask four questions at your next team meeting:

1. What software or tool are you using this week that IT didn't install?
2. Which one would slow you down the most if it disappeared tomorrow?
3. Does it hold any client or company data?
4. Would you be embarrassed if it showed up in a breach?

Treat it as fact-finding, not a lecture. The useful tools get sanctioned. The risky ones get replaced.

You can't protect what you don't know is running.

Your primary work email is on every business card, contract, and website. It's also the first thing attackers go looking...
14/07/2026

Your primary work email is on every business card, contract, and website. It's also the first thing attackers go looking for.

Phishing crews scrape your website and LinkedIn to figure out your email format. Once they have one address, they can guess your entire team's emails in seconds — giving them targets for credential phishing, fake invoices, and CEO impersonation scams.

Email aliases fix this. An alias is an extra address that delivers to your same inbox without exposing your real one. Microsoft 365 allows up to 400 per mailbox. Google Workspace allows up to 30 per user. Both are free and already built in.

A simple setup most small businesses can use:

-𝗣𝘂𝗯𝗹𝗶𝗰-𝗳𝗮𝗰𝗶𝗻𝗴 𝗮𝗹𝗶𝗮𝘀 for anything on your website, cards, or signup forms (info@, hello@, sales@). Keep your real email off public pages entirely.
- 𝗩𝗲𝗻𝗱𝗼𝗿-𝘀𝗽𝗲𝗰𝗶𝗳𝗶𝗰 𝗮𝗹𝗶𝗮𝘀𝗲𝘀 for major suppliers ([email protected], [email protected]). If one leaks and phishing starts hitting that alias, you'll know exactly which vendor was the source.
-𝗢𝗻𝗲 𝘁𝗶𝗴𝗵𝘁𝗹𝘆 𝗵𝗲𝗹𝗱 𝗶𝗻𝘁𝗲𝗿𝗻𝗮𝗹 𝗲𝗺𝗮𝗶𝗹 for sensitive stuff like banking and payroll. That one never appears anywhere public.

If a phishing campaign hits one of your aliases tomorrow, you'll know exactly which list you're on — and you can shut that alias down without touching your main address.



"We're too small to be a target" is one of the most costly myths in small business today.Hackers don't pick targets one ...
10/07/2026

"We're too small to be a target" is one of the most costly myths in small business today.

Hackers don't pick targets one by one — they use automated tools that scan millions of businesses a day looking for easy openings: an unlocked digital "door," an old password that still works, outdated software. Once they find one, they don't check how big you are. They just get in.

The numbers back this up. Reports from Verizon, the FBI, and cybersecurity firms all show small businesses make up the majority of cybercrime victims, year after year.

Why? You have the same valuable stuff big companies do — customer info, payment details, employee records — but usually fewer people watching for trouble. That makes small businesses quicker to break into and easier to cash in on. Hackers aren't looking for a huge payout. They just want an easy win, and small businesses are often exactly that.

If you've ever put off security because your business felt "too small to matter," the numbers say otherwise.

Address

Las Piñas
1740

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm
Saturday 9am - 5pm

Telephone

025527955

Alerts

Be the first to know and let us send you an email when InnoPrince Inc. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to InnoPrince Inc.:

Shortcuts

Share