Tag Archive for: cybersecurity

There’s an old saying that it’s better to be lucky than good. When it comes to protecting your business from cyber threats, that’s a gamble worth retiring.

We prefer a different version: the harder you work, the luckier you get. In cybersecurity, the organisations that look lucky when a major threat makes the news are almost always the ones that invested in operational security best practices long before the headline appeared; unglamorous, consistent work that quietly removes risk before any alert is published.

How AI Has Changed the Cybersecurity Threat Landscape

AI has fundamentally changed the economics of a cyberattack. For years, the raw materials for a breach – old leaked credentials, previously disclosed vulnerabilities, forgotten accounts, unpatched devices – have been sitting in the open. What’s changed is that attackers can now use AI to comb through years of those exposures and test them against live networks at a speed and scale that simply wasn’t practical before.

The FortiBleed activity is a recent example. It wasn’t a single, novel zero-day. It was a systematic recycling of vulnerabilities and credential leaks that were already known and already disclosed – assembled by AI into a working attack against internet-accessible firewalls and VPN gateways. The materials were old. The method was new.

That pattern isn’t unique to one vendor or one product. It’s the shape of the modern threat landscape: the cost of patience has dropped to near zero for attackers, which means the margin for “we’ll get to it eventually” has narrowed considerably for everyone else.

Lucky or Prepared? The Real Difference in Cybersecurity

Here’s the encouraging part. For organisations that had been practising sound operational security, an event like FortiBleed wasn’t an emergency; it was a normal course of business. Review the controls, confirm everything was in order, and move on.

That isn’t luck. It’s the compounding return on consistent work. The teams that hadn’t done the work spent that same week in a fire drill. Same threat, very different week.

The difference comes down to a handful of disciplines that, done routinely, quietly remove most of the risk before any alert is published.

Operational Security Best Practices: The Fundamentals That Work

Operational security isn’t a product you buy. It’s a set of habits you keep. The ones that matter most:

Routine firmware updates.

The devices that run your network – firewalls, switches, access points – need firmware maintained on a schedule, not whenever someone remembers. Outdated firmware is one of the most common ways old vulnerabilities stay exploitable long after a fix exists. If your team discovered FortiBleed through the news rather than through a patch notification, that’s a gap worth closing.

Managed software patching.

Patching should run on a defined cadence and be verified, not assumed. “The update was available” and “the update is installed and the system rebooted” are very different things, and only one of them protects you.

Strong credential management.

Most modern attacks don’t break in, they log in. A business-wide password manager, enforced multifactor authentication (MFA) on every account that matters, and the elimination of generic or default logins close off the easiest path an attacker has. Credentials are the new perimeter; treat them that way.

A minimised attack surface.

Management interfaces shouldn’t be reachable from the public internet. Unnecessary accounts and services should be turned off. Every door you don’t need is one you don’t have to defend.

Routine review of controls.

Security configurations drift over time as people change roles, projects launch, and systems are added. A regular review – confirming that the controls you put in place are still in place and still working – is what keeps a strong posture from quietly eroding.

None of these are exotic. That’s precisely the point. They reward consistency, not cleverness.

Why Operational Security Is Your Best Defence Against AI-Powered Attacks

In an environment where attackers move at machine speed, disciplined operational security may be your single most effective defence – paired with AI-assisted detection and response that can spot and contain trouble at the same pace threats are moving. One side reduces how much can go wrong; the other shortens how long it takes to catch what does.

But tools and tactics only go so far without one more ingredient: treating IT security as a core business competency, with genuine leadership support behind it. Threats like FortiBleed don’t reward the organisations that bought the most software. They reward the ones that operate well, every day – and that takes leadership deciding security is worth doing properly.

Strengthening Your Operational Security With Go West IT

Insisting that security be a core competency doesn’t mean building all of it in-house. The execution and the guidance can be entrusted to a partner who does this work every day – keeping firmware and software current, managing credentials and access, hardening your platforms, and reviewing your controls so nothing drifts.

That’s where Go West IT comes in: helping you put the right fundamentals in place, keep them running, and turn the next industry-wide scramble into a routine exercise.

The harder you work on the fundamentals, the luckier you’ll look when the next threat comes around. We’d be glad to help you do that work.

If you’d like to review where your organisation stands on operational security, we’re here.

Further reading: CISA, “CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure” (June 2026)

Frequently Asked Questions About Operational Security

What is operational security in IT?

Operational security (OpSec) in an IT context refers to the ongoing discipline of maintaining controls that protect a business’s systems, data, and network. This includes routine practices such as firmware and software patching, credential management, MFA enforcement, minimising the attack surface, and regularly auditing that existing controls are still working. Unlike a one-time security audit, operational security is a set of continuous habits – the consistent work that reduces risk before a threat materialises.

What does the FortiBleed vulnerability mean for my business?

FortiBleed refers to a wave of attacks exploiting previously disclosed vulnerabilities in Fortinet devices – particularly firewalls and VPN gateways – combined with leaked credentials. Attackers used AI to systematically test known exposures against live networks. If your business uses Fortinet or similar edge devices and has not applied recent firmware updates or rotated credentials following prior disclosures, it is worth reviewing your posture. CISA published guidance in June 2026 specifically urging organisations to harden Fortinet devices and review credential exposure.

What is the single most important step I can take to improve my business’s cybersecurity right now?

If you’re starting from scratch, enforcing multifactor authentication (MFA) across all key accounts – email, remote access, admin portals – delivers the most immediate reduction in risk. Most successful breaches involve compromised credentials; MFA closes off that path even when a password is known. From there, a structured firmware and patching schedule, combined with a regular review of who has access to what, will address the majority of the remaining exposure.

Once a business starts using paid AI models like OpenAI or Anthropic’s Claude, something predictable happens. Someone – often not a developer by title – builds something. An app. An agent. A workflow that automates a task the team used to dread. And it works. It brings real, measurable value.

That’s the moment the ground shifts. Because in the age of capable AI, we’re all developers now – and AI app hosting is no longer a question just for technical teams. Deciding where your AI-built applications live, who controls them, and how they’re kept secure is a business decision. Getting the answer right early makes everything easier.

Why AI App Momentum Doesn’t Stop at One

Our experience at Go West IT is that once a business sees what’s possible, this doesn’t stay a one-time event. The first useful app inspires the second. A colleague sees it and builds their own. Within a few months, what started as one person’s experiment has become a small portfolio of tools the business is starting to rely on.

That’s really exciting, and it’s also where the important questions begin.

The Right Questions to Ask Before You Host AI Applications

As your team builds more, four questions quickly matter:

  • Where are these apps hosted and who is responsible for keeping them running?
  • Where does the code live, and who controls it if a key person leaves?
  • How do you manage access, is this internal only, or will clients interact with it?
  • How do you ship updates as the app evolves and improves?

These aren’t roadblocks. They’re the sign that something experimental is becoming something real. The businesses that answer them early turn a pile of promising experiments into durable, supportable assets.

How We Host AI-Built Apps at Go West IT: Our Azure Setup

We’re already well down this path internally, and we made a deliberate decision from the start: rather than scatter applications across personal accounts and consumer-grade tools, we’d build on a secure environment we already manage and trust.

In practice, that means:

Hosting in Azure. Our applications run in a managed cloud environment with redundancy, backups, and room to grow – not on someone’s laptop or a free-tier account that disappears when they change roles.

Identity and access through Microsoft Entra ID. Authentication and access management are handled consistently across our applications, so we always know who can reach what – whether the app is internal-only or touches client data.

Code managed in Azure DevOps. Our repositories live there, and we push code from DevOps straight to the application in Azure. That gives us version control, a documented change history, and a clean, repeatable way to ship updates.

The payoff is that as more applications surface – and they will – we’re not reinventing the approach each time. We have a repeatable, supportable process that protects three things at once: operational efficiency (we ship and maintain without chaos), intellectual property (the code your team creates is a business asset, governed like one), and operational security (access, hosting, and change management are controlled by design, not by accident).

How Much Does AI App Hosting Cost? Azure Pricing Explained

One of the most reassuring parts of this conversation is that the costs are knowable and modest relative to the value.

A basic application can run on an Azure Static Web App for approximately $9 per month. A more robust application – one that needs to run in a Linux container, for example – typically lands in the $100 to $200 per month range. Either way, you’re working with predictable monthly recurring costs you can plan around.

That predictability makes return on investment easy to evaluate. It also opens the door to a new metric worth tracking: Return on Tokens – how much did you spend, in AI usage and supporting infrastructure, to build and run that app, and is the value it returns worth it? That’s the difference between ‘we think this AI thing is helping’ and ‘we know exactly what this costs and what it returns.’

Building an AI App Hosting Strategy That Scales

If deciding whether your business is AI-ready was the first step, this is the natural next one: giving the things your team builds a secure, permanent, well-managed home – and a strategy that scales as the next app, and the one after that, arrives.

This is the path we’ve walked ourselves, which is exactly why we can guide you down it. Go West IT can help you stand up a secure hosting and development foundation – Azure for hosting, Entra for identity, Azure DevOps for code, so the value your team is creating with AI becomes something lasting, protected, and supportable.

You’re already building. Let’s make sure what you build has somewhere solid to stand.

If you’d like to talk through a hosting and development strategy for your AI-built applications, we’re here.

Frequently Asked Questions About AI App Hosting

What is the cheapest way to host an AI-built application?

A basic application can run on an Azure Static Web App for approximately $9 per month. This is suitable for lighter tools; internal dashboards, simple agents, or workflow automations that don’t require a dedicated server. More complex applications, such as those that need to run in a Linux container, typically cost $100 to $200 per month. Both options offer predictable monthly costs and enterprise-grade reliability.

What security considerations apply to AI app hosting?

Key areas to address include identity and access management (Microsoft Entra ID handles authentication and controls who can reach each application), code version control (Azure DevOps ensures a documented, repeatable deployment process), and data governance (knowing whether client data or internal data flows through each application and how it is stored and protected). Hosting on a managed cloud platform like Azure also provides redundancy and backup capabilities that consumer-grade tools do not.

What is ‘Return on Tokens’ in AI app development?

Return on Tokens is a metric for evaluating the value of an AI-built application against its actual running costs – including AI model usage fees and hosting infrastructure. It helps businesses move from “we think this is helping” to “we know exactly what this costs and what it returns,” making it easier to prioritize which applications are worth developing and maintaining.

Is your business adopting AI strategically or are employees already using AI tools without clear policies, security controls, or oversight?

Artificial intelligence is no longer something businesses are “thinking about.”

It’s already here.

Employees are using AI tools to write emails, summarize meetings, analyze spreadsheets, generate marketing content, assist with coding, and automate repetitive work. In many organizations, AI adoption is happening faster than leadership realizes.

The challenge is not whether businesses should use AI.

The challenge is whether they are prepared to use it responsibly, securely, and strategically.

As we discussed in AI Conversations Are Accelerating Business Innovation But What Does That Mean for IT Security?, AI adoption is accelerating across nearly every industry. But moving quickly without clear guardrails can introduce operational, compliance, and cybersecurity risks businesses may not fully understand yet.

AI readiness is not about having all the answers.

It’s about asking the right questions early.

1. Who Owns AI Strategy Inside Your Organization?

One of the biggest mistakes businesses make with AI adoption is assuming it will “figure itself out.”

In reality, AI works best when someone is steering the process.  

That does not necessarily mean hiring a Chief AI Officer or building a dedicated AI department.

But businesses should identify:

  • Who evaluates AI tools
  • Who approves use cases
  • Who manages risk discussions
  • Who ensures policies are followed
  • Who measures business value

Without ownership, AI adoption often becomes fragmented.

Different teams begin using different tools independently, sensitive information may be exposed unintentionally, and businesses lose visibility into where AI is being used and why.

The goal is not to slow innovation down.

It’s to ensure adoption happens intentionally.

 

2. Do You Have an AI Use Policy?

Many businesses already have employees using AI tools without any formal guidance.

That creates significant risk.

According to Microsoft Work Trend Index1, employees are often adopting AI tools faster than organizations can establish governance around them.

An AI use policy helps define:

  • Which AI tools are approved
  • What types of data can be used
  • What information should never be entered into AI systems
  • Expectations around human review and accountability
  • Compliance considerations for regulated industries

As outlined in Go West IT’s AI Readiness guidance, organizations should explicitly prohibit employees from inputting confidential client data, financial information, personally identifiable information (PII), or protected health information into consumer-grade AI tools.  

This is especially important for industries like:

  • Financial services
  • Healthcare
  • Legal
  • Accounting
  • Professional services

A simple, readable policy is often more effective than a complicated one no one follows.

3. Are Your Existing Security Controls Ready for AI?

AI adoption introduces new types of security considerations.

Businesses often focus on productivity first and security second.

But AI tools interact with:

  • Cloud platforms
  • Internal documents
  • SaaS applications
  • Sensitive data
  • Identity systems
  • Business workflows

That means AI readiness is closely connected to cybersecurity readiness.

As we explored in Modern Security for the Distributed Workforce, businesses already operate across increasingly decentralized environments. AI expands that complexity further.

Organizations should evaluate whether they have:

  • Multifactor authentication (MFA)
  • Single sign-on (SSO)
  • Identity management controls
  • Data loss prevention policies
  • Endpoint visibility
  • Security monitoring
  • User access governance

Go West IT’s AI Readiness framework also recommends implementing technical guardrails such as SSO integration, input/output restrictions, and controlled AI access layers where appropriate.  

The question is not simply:
“Can employees use AI?”

The better question is:
“Can they use it safely?”

4. Is Your Team Trained to Use AI Responsibly?

AI literacy is quickly becoming a business necessity.

Many employees understand what AI tools can do.

Far fewer understand:

  • What AI should not be used for
  • How hallucinations occur
  • Why outputs require validation
  • How sensitive data may be exposed
  • What ethical concerns exist around AI-generated content

According to IBM AI Insights2, businesses are increasingly integrating AI into operational workflows, making employee understanding and oversight increasingly important.

Training helps close the gap between intention and behavior.

As outlined in Go West IT’s AI Readiness guidance, organizations should provide baseline AI literacy training and reinforce that AI is a productivity tool not an authority. Human review remains essential.  

This is not about fear.

It is about responsible adoption.

5. Are You Measuring Business Value or Just Experimenting?

AI adoption should ultimately support business outcomes.

That could include:

  • Improved efficiency
  • Faster response times
  • Reduced repetitive work
  • Better reporting
  • Operational automation
  • Improved customer experiences

But businesses should still ask:

  • What problem are we solving?
  • How will we measure value?
  • Is this tool improving productivity?
  • Are we reducing risk or introducing it?
  • Is adoption aligned with business goals?

As discussed in Will AI Agents Replace SaaS Applications?, AI is rapidly reshaping how businesses interact with software and workflows. But successful adoption requires intentional planning not random experimentation.

Go West IT’s own AI Readiness framework emphasizes revisiting AI initiatives regularly because the tools, risks, and opportunities evolve quickly.  

AI readiness is not a one-time project.

It’s an ongoing operational conversation.

AI Readiness Is Really About Operational Readiness

The businesses seeing the most success with AI are not necessarily the ones adopting tools the fastest.

They are the ones creating structure around adoption.

That includes:

  • Clear ownership
  • Practical policies
  • Security guardrails
  • Employee training
  • Strategic use-case evaluation

As we discussed in Why Small Businesses Need a Cybersecurity Framework, mature technology strategies are rarely built on isolated tools alone. They are built on structured processes, visibility, and governance.

AI is no different.

Final Thoughts

Most businesses are already exploring AI in some form.

The question is whether that adoption is happening intentionally.

AI readiness does not require perfection. It requires visibility, ownership, training, and thoughtful guardrails that align innovation with security and operational goals.

Because the businesses that benefit most from AI will not simply be the ones that adopt it first.

They will be the ones that adopt it responsibly.

If your organization is beginning to explore AI tools, workflows, or governance strategies, now is the time to start building the foundation for long-term success.

FAQs

1. What does it mean for a business to be AI-ready?

AI readiness means a business has the policies, ownership, security controls, and training needed to adopt AI tools responsibly and effectively.

2. Why do businesses need an AI use policy?

An AI use policy helps define approved tools, acceptable use, data handling expectations, and employee accountability to reduce operational and security risks.

3. What are the biggest AI risks for small businesses?

Common risks include data exposure, compliance issues, inaccurate outputs, shadow AI usage, identity security concerns, and lack of governance.

4. Should employees be trained on AI usage?

Yes. AI literacy training helps employees understand both the benefits and limitations of AI tools, including security, privacy, and ethical considerations.

5. Does AI readiness only apply to large companies?

No. Small and mid-sized businesses are rapidly adopting AI tools as well, making governance, security, and operational readiness important for organizations of all sizes

 

 

Sources:

https://www.ibm.com/think/topics/artificial-intelligence-business-use-cases

https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part

 

How often should businesses test their network security to stay ahead of modern cyber threats?

For many organizations, penetration testing has traditionally been a once-a-year checkbox exercise.

But in today’s environment, that approach is no longer enough.

Your network changes constantly – new users, new devices, new configurations and attackers only need one overlooked vulnerability to gain access.

Quarterly penetration testing shifts security from a point-in-time assessment to an ongoing, measurable strategy.

What Is Network Penetration Testing?

Penetration testing simulates real-world cyberattacks to evaluate how your network would hold up under pressure.

Unlike basic scans, it goes a step further by:

  • Attempting safe exploitation of vulnerabilities
  • Mapping how far an attacker could move within your environment
  • Identifying real-world impact, not just theoretical risk

Go West IT’s approach combines both internal and external testing, using automated tools to simulate attacks from inside your network and from outside your perimeter. 

The result is a comprehensive understanding of:

  • Where vulnerabilities exist
  • How they could be exploited
  • What needs to be prioritized


Why Annual Testing Falls Short

A yearly penetration test may tell you where you stood 12 months ago.

But it doesn’t account for:

  • New vulnerabilities discovered daily
  • Software updates and configuration changes
  • Expanding attack surfaces from remote work and cloud adoption

As we explored in Why Vulnerability Management Is a Must, Not a Maybe, attackers often rely on known, unpatched weaknesses not sophisticated zero-day exploits.

This is why continuous visibility matters.

According to the Verizon Data Breach Investigations Report1, a large percentage of breaches involve the exploitation of known vulnerabilities, reinforcing the importance of identifying and addressing risks early.

Internal vs External Testing: Why Both Matter

Effective penetration testing doesn’t stop at the perimeter.

It evaluates two critical perspectives:

Internal Testing

Simulates what happens if an attacker gets inside your network.

This helps identify:

  • Lateral movement opportunities
  • Privilege escalation risks
  • Access to sensitive systems and data

External Testing

Simulates attacks from outside your organization.

This focuses on:

  • Firewalls and gateway defenses
  • Public-facing systems
  • Exposure to internet-based threats

Together, they provide a complete picture of your security posture not just isolated snapshots.


From Findings to Action: Prioritized Remediation

One of the biggest advantages of modern penetration testing is not just identifying vulnerabilities but prioritizing them effectively.

Each assessment delivers:

  • Severity-ranked findings
  • Executive summaries for leadership
  • Technical reports for IT teams
  • Clear remediation roadmaps

This aligns closely with principles outlined in Cyber Frameworks for Small Business Risk Management, where structured, prioritized approaches help organizations focus on the most critical risks first.

Measuring Progress Over Time

Security isn’t static and neither are your risks.

Quarterly testing introduces something most businesses lack:

Trend visibility.

With consistent testing, organizations can:

  • Track improvements over time
  • Measure the impact of remediation efforts
  • Identify recurring root causes (e.g., patching gaps, misconfigurations)
  • Demonstrate progress to leadership and stakeholders

This transforms security from a reactive function into a measurable business initiative.


The Cost-Effective Advantage of Automation

Traditional penetration testing can be:

  • Expensive
  • Infrequent
  • Resource-intensive

Modern automated solutions change that by providing:

  • Consistent quarterly testing
  • Faster turnaround times
  • Reduced reliance on manual red-team efforts
  • Scalable coverage across environments

According to the CrowdStrike Global Threat Report2, attackers increasingly exploit known vulnerabilities and misconfigurations, reinforcing the importance of identifying and addressing risks early.

In other words:

Testing more frequently isn’t just better security, it’s better business.

The Bigger Picture: Testing as a Core Security Layer

Penetration testing is not a standalone solution.

It works alongside:

  • Vulnerability scanning (to identify risks)
  • Detection and response tools (to monitor threats)
  • Frameworks (to guide strategy and governance)

As highlighted in Update on SASE: Modern Security for the Distributed Workforce, modern security must adapt to environments where users, devices, and applications operate beyond traditional network boundaries.

Testing ensures those environments remain secure, no matter where they exist.

Final Thoughts

Cybersecurity isn’t about hoping your defenses work.

It’s about proving they do.

Quarterly penetration testing gives you that proof, turning assumptions into validated insights and helping you stay ahead of evolving threats.

Because in today’s landscape, attackers don’t wait a year to find your weaknesses.

And neither should you.

If you’re ready to move from reactive security to continuous validation, learn more about our Penetration Testing services here.

FAQs

1. What is network penetration testing?

It is a simulated cyberattack designed to identify and evaluate exploitable vulnerabilities in your network.

2. Why is quarterly testing important?

Because your environment and threats evolve constantly, quarterly testing provides up-to-date insights and measurable progress.

3. What’s the difference between internal and external testing?

Internal testing simulates threats inside your network, while external testing evaluates perimeter defenses from outside.

4. Is penetration testing automated or manual?

Modern solutions often use automated tools for consistency and efficiency, combined with expert analysis.

5. Does penetration testing fix vulnerabilities?

No, it identifies and prioritizes them. Remediation is carried out based on the findings.

Sources:

  1. https://www.verizon.com/business/resources/reports/dbir/
  2. https://www.crowdstrike.com/global-threat-report/

Managed Detection & Response vs. Antivirus: What’s the Difference?

Are your defenses preparing you for threats before they strike, or ready to respond effectively when they do?

For years, antivirus software was the go-to defense for business systems. It scanned files, flagged suspicious attachments, and blocked known malware. But in today’s fast-evolving cyber landscape, threats move quicker, target more broadly, and often slip through cracks that traditional antivirus (AV) can’t spot.

That’s where Managed Detection & Response (MDR) steps in as a critical layer of protection. MDR combines Endpoint Detection & Response (EDR) software with 24/7 monitoring by a Security Operations Center (SOC) team. It identifies unusual behavior that signals a breach in progress and enables rapid response to contain and mitigate the damage. While preventive tools aim to stop attacks before they happen, MDR focuses on detecting and responding during and after an incident, minimizing the fallout.

What Does “Left of Boom” Mean and Why It Matters

In cybersecurity, the terms “left of boom” and “right of boom” come from military strategy, adapted to describe the timeline of a cyber incident. “Left of boom” refers to everything that happens before a security breach occurs—proactive measures like prevention, hardening systems, and threat hunting to avoid incidents altogether. “Right of boom” covers everything after the initial compromise, including detection, containment, response, recovery, and learning from the event.

No business can stay entirely left of boom forever; breaches can and do happen despite the best prevention. That’s why a balanced approach is essential: strong left-of-boom protections to reduce risks, paired with robust right-of-boom capabilities to handle incidents when they occur. MDR excels on the right-of-boom side by providing real-time detection and expert response, helping businesses recover faster and with less damage.

“Luck is what happens when preparation meets opportunity.” – Seneca

This balanced mindset aligns with what we covered in Why EDR Is Essential for Cybersecurity in 2025, where detection and response bridge prevention and recovery. MDR elevates this by adding round-the-clock human expertise to manage those systems effectively.

Antivirus vs. EDR vs. MDR: Understanding the Evolution

Let’s break down these layers of defense and where they fit on the boom timeline:

Antivirus (AV): Primarily Left-of-Boom Protection

Traditional AV focuses on known signatures—viruses, malware, and trojans that have been identified and cataloged. It scans files, emails, and attachments against a database of threats. While it’s a solid preventive tool, it is not designed to stop new or evolving threats. AV is a left of boom prevention tool that blocks familiar dangers at the door.

Endpoint Detection & Response (EDR): Bridging Left and Right of Boom

EDR goes beyond signatures by analyzing system behavior to spot suspicious activity, like an unauthorized user escalating privileges or a process copying sensitive data. It provides visibility and alerts but often requires your team to investigate and respond. EDR supports left-of-boom efforts through ongoing monitoring and pairs with right-of-boom actions by enabling quicker detection during an attack.

Managed Detection & Response (MDR): Right-of-Boom Expertise

MDR builds on EDR by adding human intelligence from a dedicated team of cybersecurity professionals who monitor, investigate, and act in real time—24/7. If malicious behavior is detected, they can isolate devices, block threats, and contain the issue before it escalates. Unlike “set-and-forget” tools, MDR ensures your business has expert eyes on potential incidents around the clock, making it a powerhouse for right-of-boom response when attackers strike at any hour.

Why MDR Is Critical for Modern Businesses

The average breakout time for attackers—the window from initial compromise to spreading within your network—is now under 48 minutes, according to the CrowdStrike Global Threat Report. Relying only on left-of-boom tools like basic AV or periodic checks leaves small and medium-sized businesses vulnerable, especially without in-house IT teams available 24/7.

MDR addresses this by providing:

  • Detection of threats beyond known malware, including sophisticated attacks.
  • Response within minutes to contain and neutralize issues.
  • Access to seasoned analysts, bridging the skills gap for businesses without dedicated security staff.
  • Reduced downtime, data loss, and recovery costs through swift action.

MDR is an important control highlighted in frameworks like CIS Controls and NIST, which emphasize continuous monitoring, incident detection, and rapid response—key topics in our post Why Small Businesses Need the CIS Cybersecurity Framework.

Balancing Left and Right of Boom: A Comprehensive Defense

A complete cybersecurity strategy combines left-of-boom prevention (like AV and patching) with right-of-boom response (like MDR) to handle the full attack lifecycle:

  • Before (Left of Boom): Prevention through tools, policies, and awareness to stop threats from entering.
  • During and After (Right of Boom): Detection, containment, recovery, and forensics to limit damage and strengthen future defenses.

MDR doesn’t prevent every attack but ensures that when one occurs, the “blast radius” is minimized. It’s the difference between a quick recovery and a devastating breach.

Go West IT: Your Partner for Balanced Cyber Defense

At Go West IT, we help small and medium-sized businesses build layered protections that cover both left and right of boom. From preventive managed IT services to responsive MDR solutions tailored for industries like finance, law, and accounting, we scale security to fit your needs.

Ready to strengthen your defenses? Contact us for a free consultation or call 303-795-2200 (option 1).

FAQ

Does MDR replace antivirus? No—MDR complements AV by handling advanced threats and providing response capabilities that AV lacks. Together, they cover left and right of boom.

Is MDR expensive for small businesses? Not at all. Many providers, including us, offer scalable MDR options that deliver enterprise-level protection without breaking the bank.

How fast can MDR respond to a threat? Top MDR services respond within minutes of detection, isolating threats to prevent widespread damage.

What does “left of boom” mean? It refers to preventive actions before a cyber incident. “Right of boom” involves response and recovery after one starts.

How does MDR align with frameworks like CIS or NIST? MDR supports their recommendations for ongoing monitoring, threat detection, and quick incident response—core to right-of-boom effectiveness.

Sources

  • CrowdStrike Global Threat Report 2025

CISA – Managed Detection and Response

What happens when one unpatched system becomes your business’s weakest link?

In the world of cybersecurity, prevention starts long before an attack occurs. Threat actors don’t need to invent new exploits, they often take advantage of known vulnerabilities that haven’t been patched. This is where vulnerability management steps in: a continuous process of identifying, prioritizing, and remediating security weaknesses across your digital environment.

When done right, it transforms your IT operations from reactive firefighting to proactive protection.

What Is Vulnerability Management and Why It Matters More Than Ever

Vulnerability management is the ongoing process of scanning systems, assessing their exposure to threats, and applying fixes before attackers can exploit them. Unlike occasional patching, vulnerability management emphasizes continuous monitoring, criticality scoring (CVE prioritization), and structured remediation.

According to a 2025 study by IBM, 29% of breaches exploited unpatched vulnerabilities, a reminder that even well-intentioned IT teams can’t rely on manual patch cycles anymore [¹].

As we discussed in our earlier article, Software Patching Strategy for 2025: More Than Just Updates, patching is more than applying updates, it’s about staying one step ahead of evolving threats. Vulnerability management takes this further by ensuring that every component of your environment, from endpoints to edge devices, stays protected on an ongoing basis.

Three Areas You May Be Overlooking

1. Operating Systems

While Windows and macOS updates seem automatic, the reality is that failed or incomplete updates are common. Businesses should have a monitoring and remediation process to ensure patches actually apply. Missed OS patches can leave gaps for attackers to exploit within days of public disclosure.

2. Third-Party and Web Applications

Your browser extensions, PDF readers, and even accounting software can harbor vulnerabilities. As we noted in The Hidden Risks of Ignoring Firmware Updates, overlooked maintenance, whether in firmware or third-party tools, creates an open invitation for threat actors.

3. Network Edge Devices

Firewalls, routers, and switches often sit untouched after initial configuration. But these devices are prime targets for exploitation. Keeping network hardware firmware updated, combined with configuration audits, strengthens your perimeter defenses and supports compliance with frameworks like CIS and NIST, which we outlined in Why Small Businesses Need the CIS Cybersecurity Framework.

From Scheduled Patching to Continuous Management

The old way, quarterly patch windows, no longer cuts it. Today’s threat actors move faster than ever. In fact, CrowdStrike’s 2025 Global Threat Report found that the average breakout time for attackers dropped below 48 minutes [²].

That’s why continuous vulnerability management—supported by automation, CVE prioritization, and strong reporting—is essential. Businesses that adopt an ongoing approach significantly reduce their mean time to remediate (MTTR) and their overall exposure to known threats.

“An ounce of prevention is worth a pound of cure.”

— Benjamin Franklin

How Vulnerability Management Reduces Risk

  1. Identifies Hidden Weaknesses – Regular scans uncover risks across endpoints, servers, and cloud platforms.
  2. Prioritizes What Matters Most – CVE scoring and contextual threat intelligence focus efforts on the most critical vulnerabilities.
  3. Improves Patch Success Rates – Automated remediation reduces human error and downtime.
  4. Enhances Compliance – Demonstrates alignment with CIS, NIST, and other security frameworks.
  5. Builds Long-Term Resilience – Reduces the window of exposure, protecting your data, uptime, and reputation.


Go West IT: Your Partner in Risk Mitigation

At Go West IT, we help small and midsized businesses build structured, framework-aligned vulnerability management programs. From automated patching to CVE prioritization dashboards and managed monitoring, our team ensures that every “door” in your IT environment stays locked.

Learn how our vulnerability management and cybersecurity services can strengthen your defenses contact us for a free consultation or call 303-795-2200 (option 1).

FAQ

1. What’s the difference between patching and vulnerability management?

Patching is one action within a broader vulnerability management program, which also includes scanning, prioritizing, and validating remediation efforts.

2. What is CVE prioritization?

CVE (Common Vulnerabilities and Exposures) scoring helps rank vulnerabilities by severity, allowing IT teams to patch the most dangerous flaws first.

3. Does vulnerability management apply to small businesses?

Absolutely. Small businesses are frequent targets because they often lack the layered defenses that continuous vulnerability management provides.

4. What frameworks recommend vulnerability management?

Frameworks like CIS, NIST, and ISO 27001 all list vulnerability management as a core control for maintaining security and compliance.

Sources

  1. IBM Cost of a Data Breach Report 2025
  2. CrowdStrike Global Threat Report 2025
  3. CISA – Vulnerability Management Best Practices

March Madness isn’t just for basketball—it’s also the perfect metaphor for cybersecurity. In the world of college hoops, you can’t rely on last year’s strategies to win this year’s championship. Your competitors are constantly improving, analyzing past plays, and adjusting their tactics. The same applies to cybersecurity—especially for businesses handling sensitive financial data.

Unfortunately, one accounting firm learned this lesson the hard way last tax season. Before working with us, they believed their existing security measures were enough to protect them, but cybercriminals were playing a much more advanced game. Their lack of email security and data hygiene left them vulnerable, and when tax season rolled around, they suffered a devastating loss.

The Play-by-Play: A Costly Mistake

Everything seemed normal in early March. The firm’s accountants were busy filing returns and managing financial documents for their clients. Then, it happened—one of their employees received an urgent email that appeared to be from a longtime client requesting a tax return update. The email was well-crafted, used the client’s real name, and contained no obvious red flags. Without second-guessing, the employee responded, attaching sensitive financial documents.

A few days later, the real client called, confused. They hadn’t sent that email. It was a business email compromise (BEC) attack, and now, the cybercriminal had access to highly confidential tax documents, Social Security numbers, and financial records. By the time the firm realized what had happened, thousands of dollars were stolen in fraudulent tax refunds, and their reputation was on the line.

What Went Wrong?

Just like trying to rely on the same roster year after year in basketball, the firm was relying on outdated security strategies. Here’s where they fell short:

  • No DMARC Policy – Their email domain lacked proper authentication protections, allowing cybercriminals to spoof their email addresses and trick employees.
  • No Multi-Factor Authentication (MFA) – A hacker had previously compromised an employee’s email account, and without MFA, it was easy to use that access to gather more intelligence.
  • No Secure File Transfer Policy – Employees were sharing sensitive tax documents over email instead of using encrypted portals.
  • Lack of Employee Awareness – The firm had no regular cybersecurity training, so employees weren’t trained to spot sophisticated phishing scams.

Adjusting the Game Plan: How They Recovered

After the breach, they reached out to Go West IT for help, and we immediately stepped in to strengthen their cybersecurity, ensuring they never faced an upset like this again. We implemented:

DMARC, DKIM, and SPF Policies – To prevent email spoofing and ensure only legitimate emails were sent from their domain.

Multi-Factor Authentication (MFA) – Adding an extra layer of security for email logins and financial platforms.

Encrypted File Sharing – Transitioning the firm to a secure document-sharing platform rather than using email attachments.

Phishing Awareness Training – Conducting simulated phishing campaigns to test and train employees to recognize scams.

24/7 Email Monitoring – Installing advanced email security solutions to detect and block suspicious activity before it reaches employees.

Tax Season & Cybersecurity: Don’t Leave Your Business Vulnerable

Tax season is already stressful enough—don’t make it harder by leaving your business exposed to cyber threats. Cybercriminals are constantly evolving, just like the competition in March Madness. If your security strategy hasn’t been updated recently, you’re taking a gamble on your business.

Instead of guessing who might attack next, fortify your defenses. Let Go West IT help you develop a winning cybersecurity game plan that protects your business from tax fraud, email compromise, and financial theft.

Are your cybersecurity defenses ready for the next big game? Contact Go West IT today to ensure you’re prepared for whatever threats come your way.

Email security is undergoing a major shift, and if your business relies on email communication (as most do), it’s time to pay attention. You may start hearing more about DMARC (Domain-based Message Authentication, Reporting, and Conformance) and its impact on email deliverability. Large email providers like Google and Yahoo are now enforcing stricter DMARC policies, requiring organizations to adopt better authentication measures—or risk having their emails rejected outright.

Ignoring these changes could mean disrupted communication with clients, vendors, and partners, increased susceptibility to email fraud, and damage to your business’s reputation. Here’s what you need to know and how to ensure your organization stays protected.

What is DMARC and Why Does It Matter?

DMARC is an email authentication protocol designed to prevent email spoofing and phishing attacks. It works in conjunction with SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) to verify that the sender of an email is authorized to use a given domain.

With stricter DMARC enforcement policies now in place, emails that fail authentication may be rejected entirely or flagged as spam—significantly impacting your email communication and business operations.

How to Tell if an Email is DMARC Approved or Rejected

Understanding how DMARC policies impact email security is crucial. When an email is sent, email servers verify whether it passes authentication checks before allowing it into an inbox. If these checks fail, the email is either marked as spam or rejected altogether.

Here’s a quick comparison of what a DMARC-approved email looks like versus one that fails authentication:

DMARC Approved (Passes SPF, DKIM, and DMARC Checks)DMARC Failed (Rejected or Marked as Spam)
✅ From: support@yourcompany.com❌ From: support@yourc0mpany.com
✅ Sent via: yourcompany.com❌ Sent via: unknownserver.com
✅ SPF Alignment: Verified❌ SPF Alignment: Failed
✅ DKIM Signature: Valid❌ DKIM Signature: Missing or Mismatched
✅ DMARC Policy: Pass❌ DMARC Policy: None or Reject
✅ Lands in Inbox❌ Marked as Spam or Rejected

If your legitimate business emails are being marked as spam or failing to reach recipients, it may be time to review and implement a strong DMARC policy. Without it, your business could face email spoofing risks, phishing attacks impersonating your domain, and a loss of trust from customers.

The Business Risks of Ignoring DMARC Reject Policies

If your company’s domain lacks proper DMARC configurations, you could face:

  • Email Deliverability Issues: Emails sent from your domain may not reach clients, partners, or employees if they fail authentication checks.
  • Increased Cybersecurity Risks: Attackers frequently use domain spoofing to impersonate businesses in phishing scams. Without DMARC, your domain is vulnerable to misuse.
  • Regulatory and Compliance Challenges: Many industries, especially finance and legal sectors, are tightening email security requirements. Non-compliance could lead to fines or reputational damage.
  • Customer Trust Erosion: If fraudulent emails appear to come from your domain, your brand’s credibility takes a hit—leading to lost business and damaged relationships.

How Businesses Can Adapt and Secure Their Email Communication

The good news is that Go West IT has a solution. As a Managed IT and cybersecurity provider, we specialize in configuring and enforcing DMARC, SPF, and DKIM policies to secure business email communications. Here’s how we can help:

  • DMARC Policy Implementation: We assess your domain and establish an appropriate DMARC policy (Monitor, Quarantine, or Reject) to enhance security without disrupting legitimate emails.
  • Email Authentication Configuration: We properly configure SPF and DKIM records to align with your email-sending sources, ensuring all authorized emails pass authentication.
  • Ongoing Monitoring & Reporting: DMARC reports provide insights into who is sending emails on your behalf. We analyze these reports to detect unauthorized use and prevent future threats.
  • Strategic Rollout to Avoid Business Disruption: Enforcing DMARC too aggressively without monitoring can lead to unintended email rejections. We implement a phased approach, allowing you to monitor and adjust policies before moving to a full reject mode.

Stay Ahead of Email Security Threats

Email remains a primary attack vector for cybercriminals, and with the latest enforcement of DMARC policies by major providers, businesses must take action to protect their domains. Go West IT ensures your email security is up to modern standards—reducing your risk, maintaining email deliverability, and keeping your business communications secure.

Don’t wait until email failures or phishing attacks disrupt your business. Contact Go West IT today to ensure your email domain is secure and compliant with the latest DMARC policies.

As of October 2025, Microsoft will officially end support for Windows 10, signaling the end of an era. For small businesses, this means the clock is ticking to secure your systems and prepare for the transition. Without updates, patches, or support, your systems could be left vulnerable to cyber threats and operational disruptions.

If your business runs on limited resources or lacks an in-house IT team, this can feel overwhelming—but it doesn’t have to be. With the right plan and support, you can transition smoothly and position your team for greater efficiency and security.

Why Small Businesses Need to Act Now

When an operating system reaches its end of life (EOL), it no longer receives critical updates, leaving your business exposed to serious risks:

  • Increased Cybersecurity Threats: Outdated systems are a prime target for hackers.
  • Compliance Risks: Unsupported software could lead to non-compliance with regulations, especially for businesses handling sensitive data.
  • Disruptive Compatibility Issues: Legacy systems might not work with modern software or devices, causing interruptions to your workflow.

The good news? By planning early, you can avoid costly disruptions and ensure your business stays secure and operational.

Option 1: Upgrade to Windows 11

If your current hardware is up to the task, upgrading to Windows 11 can be the simplest and most cost-effective solution. Windows 11 brings improved security features, better performance, and a modern interface designed to support today’s business needs.

Steps for Small Teams to Upgrade:

  1. Check Compatibility: Use Microsoft’s PC Health Check Tool to see if your hardware supports Windows 11.
  2. Back Up Critical Files: Ensure all important business files are securely backed up before starting the upgrade.
  3. Prepare for the Upgrade: Work with Go West IT or a trusted provider to handle the upgrade process. We’ll manage the technical details, so you can stay focused on your business. If you prefer to manage internally, ensure your current system is fully updated before initiating the upgrade. Then follow Microsoft’s upgrade instructions.

Option 2: Replace Outdated Hardware

If your systems don’t meet Windows 11 requirements, replacing them with new devices is the best path forward. While this may feel like a bigger investment, it’s an opportunity to modernize your business technology for faster, more efficient operations.

How to Transition Securely

  • Assess Your Needs: Determine the specifications and features you need for your business or personal use.
  • Migrate Data Safely: Use secure tools or IT professionals to transfer data to your new system. Avoid using unencrypted external drives or unsafe online transfer methods.
  • Decommission Old Devices: Properly wipe data from your old system before recycling or disposing of it. Use certified destruction services for sensitive data.

How Go West IT Makes Replacement Simple:

  • Needs Assessment: We’ll help you determine the best devices for your specific business requirements.
  • Secure Data Migration: Let our team handle moving your data safely from old devices to new ones—no technical know-how required on your end.
  • Proper Disposal of Old Devices: We’ll ensure your sensitive data is securely wiped and your old devices are responsibly recycled.

Staying Secure During the Transition

Data security is a top concern for small businesses, especially during upgrades or replacements. Go West IT ensures your transition is secure with managed services like:

  • Encryption: Protect your data during transfer and storage.
  • Endpoint Protection: Set up modern antivirus and security tools on your new system.
  • Multi-Factor Authentication (MFA): Secure your accounts and systems with added layers of protection.
  • Backup Management: Create reliable backups stored securely in the cloud or offsite.

Why Start Now?

Small teams often wear many hats, so last-minute tech changes can disrupt your operations. Starting early gives you time to prepare and avoids unnecessary downtime or stress. This type of technology transition may also require a great partner.

Partnering with Go West IT means you’ll get:

  • Tailored Planning: Solutions designed specifically for your small business.
  • Hands-Free Implementation: We handle the technical work, so your team can focus on their priorities.
  • Peace of Mind: Your systems will be secure and compliant, with minimal disruption.

Ready to Future-Proof Your Business?

Don’t let the Windows 10 sunset catch you off guard. Whether you’re upgrading to Windows 11 or replacing old systems, Go West IT specializes in helping small businesses make the transition seamlessly and securely.

Contact us today to plan your upgrade and keep your business running smoothly. Your future starts now.

In the evolving landscape of cybersecurity, phishing remains one of the most persistent and damaging threats businesses face. To combat this, many organizations invest in software solutions to enhance their security posture. However, all too often, these tools are purchased as a “check-the-box” measure and left underutilized—or worse, completely unused. The result? Vulnerabilities persist, resources are wasted, and businesses remain exposed to the very risks they sought to mitigate.

The Problem with “Shelfware”

A common scenario: a company identifies phishing as a top concern and purchases an email filtering or endpoint detection and response (EDR) solution. Yet, the software is never fully set up, integrated into their systems, or managed effectively. It sits idle for years, offering no protection while silently draining budgets.

For example:

   • Phishing Prevention Tools: Businesses often invest in robust tools like email filtering solutions but fail to implement and monitor them correctly or run phishing campaigns to train employees.

   • Endpoint Detection and Response (EDR): Some companies run EDR software for years without proper configuration and more importantly monitoring, leaving systems vulnerable despite the illusion of security.

   • Incomplete IT Transitions: Organizations that start transitioning to new antivirus or other security platforms may abandon projects mid-way, leaving gaps in their defenses.

Why Managed Services Are the Solution

A managed service provider (MSP) like Go West IT solves this common issue by offering software, expertise, and execution in a single, comprehensive package. Here’s how partnering with an MSP delivers better outcomes:

  1. Cost Savings

MSPs often have access to enterprise-level pricing for software, meaning businesses can secure top-tier tools like Microsoft Defender, Azure Information Protection, CrowdStrike, Ironscales, and SaaSAlerts at lower costs. Consolidating software and services under one vendor eliminates the hidden costs of unused tools and duplicate solutions.

     2.    Full Integration

An MSP ensures that every tool—whether it’s an EDR platform or phishing prevention software—is fully set up, integrated with existing systems, and tailored to meet the organization’s unique security needs.  More importantly, it is aggressively monitored so important security events are dealt with in real time.

     3.    Ongoing Management

Cybersecurity is not a “set it and forget it” endeavor. MSPs provide continuous monitoring, updates, and management to ensure tools remain effective against evolving threats.

     4.    Improved Security Outcomes

With managed services, businesses benefit from expertly managed phishing campaigns, employee training, and proactive threat detection, ensuring comprehensive protection.

     5.    Streamlined Operations

Instead of juggling multiple vendors and tools, businesses work with one trusted partner who oversees every aspect of their security infrastructure.

Case Study: The Cost of Inaction

In one instance, a company purchased an EDR solution and ran it on their systems for five years without proper implementation. Not only were they paying for software that wasn’t protecting them, but their systems remained exposed to cyber threats during that entire period. A similar story is common with email filtering solutions like Mimecast—purchased but never leveraged to their full potential.

Had these businesses partnered with an MSP, they could have avoided wasted spend, mitigated risks, and achieved better results through a fully managed and optimized security solution.

Why Microsoft Solutions Matter

Microsoft offers a suite of security tools designed to address modern threats, particularly in email security. Solutions like Microsoft Defender for Office 365 provide advanced phishing protection, link detonation, and real-time monitoring, making them ideal for safeguarding against phishing attacks. When paired with MSP services, these tools can be fully leveraged to maximize both protection and value.

Make the Switch to Managed Services

Stop paying for unused or ineffective software. Partner with Go West IT to consolidate your cybersecurity tools, reduce costs, and ensure your defenses are always optimized. From phishing prevention to endpoint security, we bring the platform, expertise, and execution you need to stay ahead of threats.

Contact us today to learn more about managed services for your business!

The owner of this website has made a commitment to accessibility and inclusion, please report any problems that you encounter using the contact form on this website. This site uses the WP ADA Compliance Check plugin to enhance accessibility.