The Rnits Company

The Rnits Company Enterprise cybersecurity experts: cloud, endpoint, IAM, GRC, CI/CD AppSec—cut risk ensure compliance.

If your practice turned on an AI scribe this year, here is a question nobody in the building may have asked: did anyone ...
08/11/2026

If your practice turned on an AI scribe this year, here is a question nobody in the building may have asked: did anyone ask the patient?

HIPAA covers what happens to the health information in that recording. It says almost nothing about whether you were allowed to record in the first place. That is state wiretap law, and it carries criminal penalties HIPAA does not.

Most articles about AI scribes lump Massachusetts and New Hampshire together as "all-party consent" states. That is wrong about one of them. Massachusetts prohibits secret recording, where actual knowledge is the test rather than permission. New Hampshire requires consent from everyone. New Hampshire is the stricter of the two, which surprises most people.

In April, patients filed a class action against two health systems over exactly this. The AI vendor was not named as a defendant. The providers were.

We wrote up what compliance actually looks like, including the consent sentence to say out loud and why the "mandatory 2026 HIPAA requirements" you are being sold are not law yet.

https://www.rnits.com/blog/hipaa-compliant-ai-medical-practice-scribes-consent/

HIPAA is only half the problem when AI listens to a patient visit. Massachusetts and New Hampshire recording law is the other half, and the rules differ.

A client got their customer's annual vendor security questionnaire last month. Same packet as always, except it was four...
08/07/2026

A client got their customer's annual vendor security questionnaire last month. Same packet as always, except it was four pages longer, and the new pages were all about AI.

His first instinct was to write "we don't use AI." He knew that was false while he was thinking it. His office manager had been drafting proposals in ChatGPT since March, and his bookkeeper was using Copilot in Excel because it came with a license they already paid for.

Here's the part almost nobody gets right. If you bought an enterprise AI plan with a HIPAA BAA, you are probably not as covered as you think. Anthropic publishes exactly which parts of Claude the BAA covers, and the excluded list includes connectors, enterprise search, and the browser extension. In other words, the integrations that make the tool useful in the first place. "We have a BAA" is not an answer. Which surfaces you turned on is the answer.

We wrote up what those questionnaires actually ask now, and the four things you need in place before you can answer honestly. None of them require buying anything new.

https://www.rnits.com/blog/ai-security-questionnaire-guardrails-smb

Vendor security questionnaires now have an AI section. Here is what it asks, why "we have a BAA" fails it, and the four things you need in place first.

Last month we wrote about the five kinds of work that eat a small business week — proposals, repetitive forms, email, in...
08/01/2026

Last month we wrote about the five kinds of work that eat a small business week — proposals, repetitive forms, email, intake, and the marketing that quietly stopped happening. The follow-up question everybody asked was the same: fine, but where do I start?

The answer depends entirely on what business you're in, so we wrote it out industry by industry. Contractors, medical and dental practices, law firms, accounting firms, machine shops, property managers. What the paperwork actually is in each one, what the credible data says (and which numbers came from companies selling the fix), and the single workflow we'd build first.

Here's the part that surprises people: in every one of these, the first workflow is not the famous one. We would not start a medical practice on prior authorization, even though that's a 13-hour-a-week problem. We would not start a law firm on document drafting. The right first project is high-volume, low-judgment, and cheap to check — because that's the one that earns enough trust to make the second one possible.

Read it here: https://www.rnits.com/blog/ai-automation-by-industry-where-to-start/

Contractors, medical practices, law firms, accountants, manufacturers, property managers. Six industries, six different piles of paperwork, and where each one should actually begin.

Somebody in your office is retyping the same fifteen fields into a portal they've used four hundred times. Somebody else...
07/31/2026

Somebody in your office is retyping the same fifteen fields into a portal they've used four hundred times. Somebody else is rebuilding a quote from a price list and a phone call, the way they did on Tuesday and will again on Friday. A third person has 180 unread emails and no real method for deciding which twelve matter today.

That's a normal week at a normal small business, and none of it is a technology problem. The tools got cheap and capable this year. What's missing is that nobody has sat down and looked at how work actually moves through your office.

Our new post walks through the five places automation pays in almost any business: proposals and bids, the same form filled out over and over, email triage, requests arriving through five different doors, and the marketing upkeep that quietly stopped. Plus the part most people skip and regret, which is mapping the process before you automate it. Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, and the failures are almost never the technology.

https://www.rnits.com/blog/ai-business-process-automation-small-business/

Proposals, intake forms, email triage, ticket routing, website upkeep. The work eating your week is a process nobody wrote down — not a technology problem.

Something happened this summer that most small business owners missed.In about ten weeks, all three major AI companies s...
07/28/2026

Something happened this summer that most small business owners missed.

In about ten weeks, all three major AI companies shipped a package aimed specifically at small business. Anthropic launched Claude for Small Business on May 13. Microsoft made Microsoft 365 Business with Copilot generally available July 1. OpenAI shipped ChatGPT Work on July 9, then followed with a small business training program in late July.

When three competitors independently decide the same neglected market is worth building for, it usually was.

It also means you're about to get pitched all three, probably by people who haven't read past the press release. So we wrote the buyer's guide instead.

What's in it: why survey headlines say 63% of small businesses use AI while Census data says 17-20%, what the businesses in that 17% are actually getting back (roughly 5.6 hours per employee per week), a straight table for picking between the three based on where your data already lives, the five tasks worth automating first, and what you should never hand an AI.

We're not a reseller for any of them, which is why we can tell you Microsoft's is usually the right answer for an M365 shop even though there's nothing in it for us either way.

Including who should skip this entirely: https://www.rnits.com/blog/ai-automation-small-business-claude-chatgpt-copilot/

Survey headlines say 63% of small businesses use AI. Census data says 17%. Claude, ChatGPT, and Copilot all shipped small business tools in 2026 — here's how to choose.

Researchers just documented something new: a ransomware attack where no human was driving.It's called JADEPUFFER. An AI ...
07/24/2026

Researchers just documented something new: a ransomware attack where no human was driving.

It's called JADEPUFFER. An AI agent broke into a server, looked around, stole every credential it could find, moved across the network, gave itself an admin account, encrypted the data and wrote the ransom note. Start to finish. Nobody at a keyboard.

The detail that stuck with us: partway through, one of its steps failed. Instead of stopping like a normal script would, it diagnosed the error, rewrote its own code, and got it working — in 31 seconds.

Before you panic, here's the part the scary headlines skip. Look at how it got in:

• A server with a patch available since 2025, unpatched
• An object store still using its factory default password
• A config server trusting its published default signing key
• API keys sitting in plaintext on an internet-facing box

The AI didn't defeat a single security control. It walked through gaps where controls were missing. Patch that one server and the whole attack never happens.

Also worth knowing: the ransom was unpayable. The agent lost its own encryption key. Nobody could have decrypted that data at any price — which means your backups aren't the cheap option anymore, they're the only option.

Full breakdown, plus the 8-item checklist we'd actually work through: https://www.rnits.com/blog/agentic-ransomware-jadepuffer-smb-lessons/

Researchers documented the first ransomware attack run start to finish by an AI agent. It got in through an unpatched server and default passwords. Here's what actually changed.

One of our clients — a construction firm outside Nashua — nearly got breached last month because an estimator tried to i...
07/20/2026

One of our clients — a construction firm outside Nashua — nearly got breached last month because an estimator tried to install "the ChatGPT desktop app." He clicked the first search result, ran the installer, and it turned out to be an infostealer already digging through his saved passwords.

This is exploding in 2026. Attacks disguised as ChatGPT, Claude, and DeepSeek installers jumped 5x this year. The attackers aren't tricking anyone into wanting AI — your team already wants it. They just make sure the fake download is the one that gets clicked.

The fixes are mostly free: remove local admin rights, publish an approved-tools list, and turn on the endpoint protection you're probably already paying for. No six-tool "AI security stack" required.

Here's how the scam works and how to shut it down 👇
https://www.rnits.com/blog/fake-ai-tools-malware-chatgpt-claude-installer-scam/

Attacks disguised as ChatGPT and Claude installers jumped 5x in 2026. An employee downloads a 'free AI app,' and it's an infostealer. Here's how the scam works and how to shut it down.

If you own or run a franchised hotel, your flag sets the IT standard: guest WiFi that performs, a network that passes PC...
07/18/2026

If you own or run a franchised hotel, your flag sets the IT standard: guest WiFi that performs, a network that passes PCI, payment systems locked down. And it holds YOU responsible for meeting it.

Here's the part nobody explains at the franchise meeting: the brand's approved vendors know you feel captive, and they price like it. Meeting the standard is what matters — not paying premium rates to the one vendor who told you that you had no choice.

Our new post breaks down the three systems franchisees ask us about most — guest WiFi, the network underneath it, and cloud phones — plus the PCI floor beneath all three. Real numbers: 92% of guests rank WiFi as a top booking factor, and 72% of hospitality breaches target payment systems.

We're in Tyngsboro, MA, onsite across NH and MA within 150 miles.

https://www.rnits.com/blog/hotel-it-support-brand-standards-wifi-network-cloud-pbx/

Your flag mandates the WiFi, network, and PCI standards — and holds you responsible. Here's how to meet them without paying brand-vendor markup.

Every MSP blog on the internet says the same thing: break-fix IT is dead, sign the monthly contract. We're an MSP, and w...
07/14/2026

Every MSP blog on the internet says the same thing: break-fix IT is dead, sign the monthly contract. We're an MSP, and we'll tell you the truth — for a lot of small businesses, break-fix still works.

The math nobody shows you: a 10-person business needs about 85 hours of billable IT work a year before a typical managed contract wins on cost. A landscaping company with eight crew members who never touch a computer? They might use 15.

So why does every MSP push the contract? Partly because proactive maintenance is genuinely good. And partly because MSP valuations are built on monthly recurring revenue — break-fix clients add almost nothing to what an MSP is worth when it sells.

Our new post walks through all four pricing models — break-fix, block hours, all-in managed, co-managed — with honest math about who each one actually fits. Including the businesses that shouldn't hire us monthly.

https://www.rnits.com/blog/msp-pricing-models-break-fix-vs-managed-it/

Every MSP blog says break-fix is dead. It isn't. Here's an honest walkthrough of MSP pricing models, the real cost math, and who each one actually fits.

A dental office manager in Nashua forwarded us an email last week and asked, "Is this real?" It looked like a shared-fol...
07/11/2026

A dental office manager in Nashua forwarded us an email last week and asked, "Is this real?" It looked like a shared-folder notice from a vendor. It sent her to the actual Microsoft sign-in page and asked her to type in a short code to "connect the workspace." No fake login. No misspelled domain. She was halfway through before something felt off.

Good thing she stopped. That was device code phishing — an attack going around all summer that never asks for your password and doesn't fight your MFA. It gets you to approve a login the attacker already started. You pass the MFA prompt for him, and he walks into your Microsoft 365 with a valid session.

The fix is mostly settings you already own: block the device code flow if you don't use it, put Conditional Access rules behind your logins, and teach your team one rule — never approve a login or type in a code you didn't personally start. We break it all down here.

https://www.rnits.com/blog/microsoft-365-device-code-phishing-mfa-bypass-smb/

A phishing attack making the rounds this summer never asks for your password. It asks you to approve a real Microsoft login, and small businesses keep saying yes.

Address

404 Middlesex Road, Suite 9
Tyngsboro, MA
01879

Alerts

Be the first to know and let us send you an email when The Rnits Company posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share