TorchLight Secured & Managed It

TorchLight Secured & Managed It TorchLight Secured & Managed IT is an established provider of Information Technology and Information Security services across the United States.

The 2026 questionnaire is not the same as the one in 2024. The questionnaire is now an audit.Whatever you attest to on t...
06/10/2026

The 2026 questionnaire is not the same as the one in 2024. The questionnaire is now an audit.

Whatever you attest to on the way in gets re-checked against forensic evidence on the way out, and the average global ransomware claim more than doubled to roughly $713,000 between 2024 and 2025.

This week’s blog post covers what actually changed, the one control that decides whether the claim pays, the business-interruption math that should worry you more than the forensic bill, and the five moves worth making before your next renewal.

If your renewal is inside the next ninety days, the question in the closer is one I would definitely benchmark against your current attestation.

TorchLight Blog Post link in the first comment.

Your compliance team is focused on SEC Regulation S-P requirements. Your IT team says your cybersecurity is solid.Both d...
06/09/2026

Your compliance team is focused on SEC Regulation S-P requirements.
Your IT team says your cybersecurity is solid.
Both depend on the same IT foundation.

S-P compliance requires specific security measures. If your IT infrastructure doesn't deliver, compliance fails. Think of it like HVAC and electrical in a building. Both systems are required to pass inspection.

Most firms hire separate vendors to handle these separately. Two teams. Two solutions. Two invoices.

TorchLight take a different approach. One partner. One solution. One invoice.

Nearly two decades in regulated industries. Our clients pass SEC exams on the first attempt. Cyber insurance premiums drop by up to 35 percent. Critical response hits 30 minutes, around the clock.

SEC Regulation S-P isn't a checkbox. It's your IT and cybersecurity roadmap.

Download our SEC Regulation S-P Cybersecurity Checklist for RIAs. (Link in Comments) See exactly what regulators expect and where most firms miss the mark.

Would your team second-guess a link that points to the real chatgpt website?Most people wouldn't, and that's the problem...
06/03/2026

Would your team second-guess a link that points to the real chatgpt website?

Most people wouldn't, and that's the problem.

Criminals are now hiding malware on pages hosted right on ChatGPT and Claude. Because the link is a genuinely trusted AI domain, the usual advice to check the URL before clicking silently fails. The trap is a fake “ChatGPT is busy, download our app” page that serves malware disguised as the desktop app.

Security researchers call it the LLMShare attack, and it's the same social engineering as last year’s ClickFix scam, just wearing a brand everyone trusts. Whether your business already leans on AI tools or is only starting to, the time to put guardrails in place is now.

We walk through how it works, and how to protect your team, in the article linked in the comments.

05/29/2026

A time lapse of the 2 hour storm passing through last night .Pretty gnarly storm for our section of the country.

Nearly half of all exploited zero-days last year targeted edge infrastructure: firewalls, VPNs, and security appliances....
05/29/2026

Nearly half of all exploited zero-days last year targeted edge infrastructure: firewalls, VPNs, and security appliances. For healthcare clinics, community banks, and wealth management firms, that's a wake-up call.

Your perimeter devices run with high privilege and are often the least monitored. New vulnerabilities in Cisco, VMware, and others are already active. If you'd like to discuss how to strengthen your defenses, we're here to help.

Device Login Phishing is spreading faster than most security teams have heard about.Over 340 organizations: Credit Union...
05/27/2026

Device Login Phishing is spreading faster than most security teams have heard about.

Over 340 organizations: Credit Unions, Healthcare Practices, Law Firms, Nonprofits, you name it; fell victim to a new attack that bypasses both MFA and password-based defenses.
Employees did everything right. They went to a real Microsoft login page and entered real multifactor authentication, and were still compromised.

The real worry? This attack works because most mid-market organizations have never disabled or restricted device code flow.
Regulators at the NCUA, OCR, and SEC are now watching for these breaches because token-based compromise is harder to detect than password theft.

View our Full Blog Post in the comments!

The deadline to patch was on May 12th. ConnectWise ScreenConnect Vulnerability!If you haven't patched yet, do so immedia...
05/14/2026

The deadline to patch was on May 12th.

ConnectWise ScreenConnect Vulnerability!

If you haven't patched yet, do so immediately!

Click the link below to view the full Blog Post and learn more!

05/11/2026

PALO-ALTO FIREWALLS are being actively exploited right now, and patches don't land until May 13.

If you run a credit union, RIA, or healthcare clinic, Palo Alto Networks firewalls protect your perimeter.

That's true for an estimated 70%+ of mid-market organizations in regulated industries. And right now, all PA-Series and VM-Series firewalls face a critical unauthenticated buffer overflow in the Captive Portal service, discovered and published May 6.

This isn't theoretical. CISA's Known Exploited Vulnerabilities Catalog confirms in-the-wild exploitation is already happening.

The patch window is seven days. If you haven't already scheduled your update, this week is the week to do it. Any delay puts your perimeter, your client data, and your audit stance at risk.

Have you confirmed your Palo Alto devices are covered in your current patch schedule? Your security team should have answers by Monday.

05/08/2026

HEADS UP:
Critical flaws in ConnectWise ScreenConnect are being actively exploited right now.

We're talking CVSS 9.0 CRITICAL SEVERITY.
Attackers can hijack sessions using extracted machine keys. If your organization uses ScreenConnect, upgrade to version 26.1 immediately.

Not sure if you're covered?
Reach out, we're here to help make sure you're protected.

Address

23505 East Appleway Avenue Suite 200
Spokane Valley, WA
99019

Alerts

Be the first to know and let us send you an email when TorchLight Secured & Managed It posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share