CTO Sidekick

CTO Sidekick "Catch you on the Secure Side!"

Your team is using AI right now whether you have a policy on it or not. 🤖ChatGPT Gemini Copilot Claude and many niche to...
07/31/2026

Your team is using AI right now whether you have a policy on it or not. 🤖

ChatGPT Gemini Copilot Claude and many niche tools are already in the workflow. These systems learn from what people type sometimes retain the data for training and live outside your normal data security controls.

Without a written policy you have no visibility into what client data is being pasted into prompts what decisions are made with AI or how your insurance would view it if something goes wrong.

A simple AI Acceptable Use Policy does not need to be long. One page covers the basics: approved tools forbidden data inputs disclosure rules for AI generated work and who must review output before it goes to clients.

At CTO Sidekick we help businesses create and enforce practical AI policies that reduce risk without slowing down innovation.

Middle Tennessee business owners want to see how AI is being used in your business and what risks it introduces?

Run your free ROI snapshot here 🔎 https://roi.ctosidekick.com

Smishing is text message phishing and it is now more effective than email phishing. 📱'Businesses spent years hardening e...
07/30/2026

Smishing is text message phishing and it is now more effective than email phishing. 📱
'
Businesses spent years hardening email gateways and training people on suspicious links. Almost nobody did the same for text messages. The result is a channel where employees tap first and think later.

Common patterns include fake delivery failures CEO impersonation gift card requests account lockouts and urgent coworker requests.

These work because texts feel personal. They land on the same screen as messages from family and coworkers which makes the brain default to trust.

Give your team these rules:

1. No business decisions happen over text. No wires vendor changes payroll changes gift cards or password resets.
2. If a text claims to be from a coworker verify through a different channel like Slack or a phone call.
3. Never click login links in texts. Go directly to the app or website.
4. Forward suspected smishing texts to 7726 which spells SPAM. Carriers use it to block sources.

At CTO Sidekick we include smishing awareness and blocking as part of our security training and tools.

Middle Tennessee business owners want to see how well protected your team is against these attacks?

Run your free ROI snapshot here 🔎 https://roi.ctosidekick.com

Your salesperson stops at a coffee shop between meetings. They set up at a table open their laptop order a drink and wal...
07/29/2026

Your salesperson stops at a coffee shop between meetings. They set up at a table open their laptop order a drink and walk back to the counter when their name is called. The laptop sits unattended for 90 seconds. That is enough time for someone to ruin your business week. ☕

The attacker does not need to be sophisticated. A 40 dollar USB device called a Rubber Ducky plugs in and acts like a keyboard. It types pre loaded commands faster than any human. In 90 seconds it can open a terminal download remote access tools install them and disable lock notifications.

When the salesperson returns the laptop looks exactly the same. The next time they connect to your network the attacker has a path inside.

This attack has been demonstrated at security conferences for over 10 years and the hardware is cheaper now.

**Defend against it like this:
=Set every laptop to lock automatically after 30 seconds of inactivity and train the team to lock before walking away.
=Disable USB auto execute across your fleet.
=Deploy endpoint detection and response software that flags suspicious new processes and connections quickly.

At CTO Sidekick we lock down endpoints and monitor for these kinds of physical attacks as standard practice.

Middle Tennessee business owners want to see how well protected your laptops and endpoints are?

Run your free ROI snapshot here 🔎 https://roi.ctosidekick.com

On May 19 2026 Google Clouds automated abuse detection system incorrectly suspended Railway one of its largest customers...
07/28/2026

On May 19 2026 Google Clouds automated abuse detection system incorrectly suspended Railway one of its largest customers. The decision took the entire platform offline for eight hours and pulled thousands of small businesses down with it. ☁️

Railway spends over 10 million dollars a year on Google Cloud. That spend did not matter when an automated system flagged the account. The suspension was instant and it took hours for a human to fix it.

This matters to your business even if you have never heard of Railway. Your tools depend on platforms you do not control. Most of those platforms can override their own SLAs when an automated system decides something looks suspicious.

A cloud providers automated decision can take you down as fast as a hacker and you have less recourse.

Do this work this month:
=Build or update your dependency map. Know which cloud each major SaaS tool runs on.
=Identify which workflows have manual fallbacks. Can you take orders process payroll or serve customers without the usual tools?
=Have an out of band contact list for your critical vendors so you can escalate fast when automation fails.

At CTO Sidekick we help businesses build these resilience plans so single provider issues do not stop the business.

Middle Tennessee business owners want to see how dependent and exposed your operations are?

Run your free ROI snapshot here 🔎 https://roi.ctosidekick.com

When an employee leaves your business the security gap is usually bigger than you would guess. 🚪A typical 25 person busi...
07/27/2026

When an employee leaves your business the security gap is usually bigger than you would guess. 🚪

A typical 25 person business has dozens of cloud accounts per employee. Email payroll file storage CRM accounting and many other SaaS tools.

When they leave most businesses only disable the obvious ones like email and computer login. The rest sit dormant with the old credentials still active and accessible if those credentials were ever leaked.

That is how a former employee from 18 months ago becomes the entry point for next years breach.

The fix is a written offboarding checklist that covers everything:
1. Day of departure disable email computer login VPN and single sign on accounts.
2. Within 48 hours revoke access in every SaaS tool admin panel.
3. Within 7 days change any shared credentials they knew.
4. Within 30 days do a did we miss anything review with their team.

Without this checklist what did this person have access to becomes impossible to answer months later.

At CTO Sidekick we build and enforce proper offboarding processes for our clients.

Middle Tennessee business owners want to see how well your current access controls hold up?

Run your free ROI snapshot here ▶️ https://roi.ctosidekick.com

On May 7, 2026, an Amazon Web Services data center overheated and took out an entire availability zone in US-East-1, AWS...
07/26/2026

On May 7, 2026, an Amazon Web Services data center overheated and took out an entire availability zone in US-East-1, AWS's most popular region. Several core AWS services went down, and any business application hosted in that zone was unreachable for hours.

Cloud outages happen to every major provider, not just AWS. Azure, Google Cloud, Cloudflare, Microsoft 365, Salesforce, and Slack have all gone down long enough to break a business day in the last three years.

If your business loses meaningful money during downtime, you need a "the cloud is down" plan. The plan has three parts.

A dependency map. Every critical workflow in your business should be mapped to the SaaS or cloud service it depends on. Your accountant uses QuickBooks Online, which runs on AWS. Your sales team uses HubSpot, which also runs on AWS. Your phones might be VoIP, which depends on a carrier you've never named. The map doesn't need to be pretty, but it does need to exist.

An out-of-band communications path. Phone numbers for your key vendors, your insurance broker, your IT provider, and a contact for every team lead. This list lives on paper or on a phone that doesn't depend on your office network. Use the same list from your incident response plan.

A decision tree for what stops and what continues. Some work has to keep happening even when systems are down (taking orders, handling client emergencies). Other work can wait. Pre-decide which is which, so that conversation isn't happening for the first t

The quarterly review with your IT provider is one of the most useful meetings on your calendar, but it's easy to let it ...
07/25/2026

The quarterly review with your IT provider is one of the most useful meetings on your calendar, but it's easy to let it run on autopilot. Walk in with six real questions and you turn it from a status update into a strategic check-in.

Six to ask at your next review:

1. What changed in our security posture since last quarter? Not "what did you do." What CHANGED. The answer should reference specific risks reduced.
2. Which CISA Known Exploited Vulnerabilities are still unpatched in our environment, and why?
3. When did we last test our backup restore on a real workload, and what did the test show?
4. How many user accounts have privileged or admin access, and is that list smaller than it was last quarter?
5. What incidents (security events, near-misses, alerts) did we have this quarter that I didn't hear about, and why didn't I hear about them?
6. If we were hit by ransomware tonight, what's our realistic Recovery Time Objective for the most important systems?

If your IT provider can answer all six with specifics, they're operating at the standard you're paying for. Hedging or "let me get back to you" on more than one is information worth acting on.

If you deleted a OneDrive file recently and went looking for it in your Recycle Bin… surprise, it's not there.Starting i...
07/25/2026

If you deleted a OneDrive file recently and went looking for it in your Recycle Bin… surprise, it's not there.

Starting in May 2026, files deleted from OneDrive or SharePoint in the cloud no longer appear in your local Recycle Bin or Trash.

They are removed directly from your device and can only be recovered from the OneDrive or SharePoint web‑based recycle bin.

1. Go to onedrive.com or your SharePoint site

2. Click "Recycle bin" in the left menu

3. Right-click the file and select "Restore"

You typically have 30 days before files move to the second‑stage recycle bin (which most people don’t know about), and up to 93 more days there, depending on your organization’s settings.

After about 123 days, they’re gone for good.

In May 2026 hackers breached Instructure the company behind the Canvas learning platform used by thousands of schools. T...
07/24/2026

In May 2026 hackers breached Instructure the company behind the Canvas learning platform used by thousands of schools. They claimed data on 275 million users across more than 9000 institutions. ⚠️

The breach did not just hit Instructure. Every one of those institutions now has to handle breach notification laws in every state where affected users live. That is a lot of different rules and deadlines.

Your business probably does not use Canvas but the same thing happens when one of your vendors gets breached. You become responsible for notifying your own customers under your states laws often within 60 days or less. You cannot just wait for the vendor to fix it.

Do this work this week:
--Pull your SaaS vendor list from the recent audit.
--Note what customer data each vendor holds and which state laws apply.
--Call your cyber insurance broker and get the breach notification playbook your policy provides. If they do not have one that is important to know now.
--A vendor breach becomes your legal problem the day they tell you about it. ----
--Preparation has to happen earlier. 📋

At CTO Sidekick we help businesses prepare for these vendor and compliance risks.

Middle Tennessee business owners want to see your vendor and compliance exposure?

Run your free ROI snapshot here ➡️ https://roi.ctosidekick.com

The old rules about strong passwords are out of date. 🔑For years the advice was eight characters with uppercase lowercas...
07/23/2026

The old rules about strong passwords are out of date. 🔑

For years the advice was eight characters with uppercase lowercase numbers and symbols. NIST CISA and Microsoft have all moved on. The better approach is simpler and much stronger: use long passwords or passphrases and stop forcing regular changes.

The math is clear. Modern cracking tools can break a complex eight character password in under an hour. A 16 character passphrase made of common words takes centuries. Length beats complexity because every extra character multiplies the attackers work.

Update your policy like this:

- Set a minimum of 14 characters for normal accounts and 16 plus for admin or sensitive ones.
- Stop forcing password rotation. It creates more weak passwords than it prevents.
- Drop strict complexity rules that push people toward predictable patterns.
- Block passwords from known breach lists.
- Require MFA everywhere it is supported.

If your business is still using eight character passwords with quarterly changes you are following 2010 rules. The new ones are easier for your team and much harder for attackers. 🔥

At CTO Sidekick we implement these modern password and MFA policies for our clients.

Middle Tennessee business owners want to check how strong your current password practices really are?

Run your free ROI snapshot here ▶️ https://roi.ctosidekick.com

Address

214 Overlook Cir, Ste 200/311
Brentwood, TN
37027

Alerts

Be the first to know and let us send you an email when CTO Sidekick posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share