• Link to Instagram
  • Link to LinkedIn
  • Link to Facebook
  • Support
  • Resource Center
  • News & Events
  • Blog
  • Pay Online
Cumulus Global
  • What We Do
    • Managed Cloud Services Provided by Cumulus Global
    • Cloud Computing Security, Privacy, Compliance, & Continuity
    • Collaboration, Productivity, & Transformation
    • Managed Infrastructure & Platforms
  • How We Do It
    • Understand & Assess
    • Cloud Computing Strategy & Planning
    • Cloud Migration & Deployment
    • Cloud Managed Services
    • Service & Support for Cloud and IT Solutions
    • Global Strategic Services
    • Guide, Educate, & Train
  • What We Offer
    • Managed Cloud Services
    • IT Admin, Service, and Support
    • Security CPR® Managed Security
    • Google Cloud Workspace / Education / Chrome / Voice
    • Google Cloud Platform Computing Services
    • Microsoft 365 and Office 365 Managed Services
    • Microsoft Azure
  • Who We Are
    • Our Mission
    • Our Team and Opportunities
    • Our Cloud Computing Partners
    • Our Reviews and Testimonials
    • Our Community
    • Our Sustainability
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Archive for category: General

The Cloud, Shared Responsibility, and You

February 24, 2023/in Blog, General

The vast majority of small and midsize businesses (SMBs) understand — or have learned the hard way — that the ability to recover lost or damaged data is critical to your IT services and business resiliency.  You need to be able to recover and restore files, databases, servers, and workstations from loss due to disasters, hardware failures, software errors, or human action. In the cloud, it is your shared responsibility to protect your data.

The Cloud

As we move data, services, and servers, we rely on infrastructure and security built into the services.  Google and Microsoft operate industry-leading, sophisticated services designed for security as well as performance, features, and functions.  The capabilities do three things:

  1. Continuity: Ensure the clouds run with little or no disruption
  2. Recovery: Enable the restoration of services without loss of failure do to hardware, network, or other issues
  3. Capability: Provide us with the ability to secure and protect our data based on our usage

Microsoft, Google, and other cloud services do not, however, protect us from how we use their services.

You

Microsoft and Google do not control how we use Microsoft 365 or Google Workspace services.  We, as subscribers, control how we manage and protect our data, including:

  • Who can access the services
  • Which applications can connect and integrate
  • Which other applications and services will share user identities
  • Which users can manage, edit, suggest, or view files and folders
  • Which users can access various services within each of the productivity suites

With these controls comes great responsibility.  You are responsible for how your data is stored and used.  You are responsible if that use causes data loss or damage.

Shared Responsibility

Microsoft and Google  both use a “Shared Responsibility” model for security and data protection. The model defines which aspects of the cloud service security and data protection are your responsibility and which are the responsibility of the service provider.

Microsoft

Microsoft Shared Responsibility ModelMicrosoft discusses Shared Responsibility as a component of its terms of service.  A recent Microsoft Learning article notes the following:

“In an on-premises datacenter, you own the whole stack. As you move to the cloud some responsibilities transfer to Microsoft. The following diagram illustrates the areas of responsibility between you and Microsoft, according to the type of deployment of your stack.”

For Microsoft 365, a “Software as a Service” (SaaS) offering, Microsoft expects you to take responsibility for protecting and recovery of your information and data; devices; accounts and identities; and portions of your identity and directory infrastructure. Microsoft has a detailed white paper covering shared responsibility for Azure services.

Google

Google Shared Responsibility ModelThe Google Workspace Data Protection Guide includes a section dedicated to the Shared Responsibility model. Google states:

“Data protection is not only the responsibility of the business using Google Workspace services; nor is it only that of Google in providing those services. Data protection on the cloud is instead a shared responsibility; a collaboration between the customer and the Cloud service provider (CSP).”

“As a Google Workspace customer, you are responsible for the security of components that you provide or control, such as the content you put in Google Workspace services, and establishing access control for your users.”

As a SaaS offering, Google warns that you are responsible for the access control, security, and protection of any and all content you place in the Google Workspace service. The Google Cloud Platform: Shared Responsibility Matrix provides a detailed overview of shared responsibility for Google Cloud Platform.

Back to You

Understanding your shared responsibility, you can meet your data security and protection obligations.

First and foremost, configure and use the security and data protection features included within your Microsoft 365 or Google Workspace subscription. These services range from multi-factor authentication to secure user identities and access to advanced data loss prevention services in enterprise level subscriptions.

Your next step is to add additional services to cover aspects of data protection not provided with your Microsoft 365 or Google Workspace subscriptions.  These services may include:

  • Advanced threat protection for inbound email
  • Backup/recovery of all user content in Google Workspace (including shared drives) and Microsoft 365 (including Teams)
  • Archive/eDiscovery services to meet internal data policy, industry guidelines, or regulatory requirements
  • Backup/recovery for data located on end user devices and on-premise or hosted servers
  • Continuity services for mission-critical servers and end user device
  • Message-level and file-level encryption for compliance with industry or regulatory requirements

Your business may or may not need all of the services listed.  Which services you deploy should be part of a larger assessment of your cyber security and data protection needs.

Call To Action

Contact us or schedule time with one of our Cloud Advisors to discuss how you are meeting your shared responsibility and/or your broader security needs, priorities, and solutions.

For a broader look at your cyber security, complete our Rapid Security Assessment (free through June 2023) for a review of your basic security measures.

About the Author

Chris CaldwellChristopher Caldwell is the COO and a co-founder of Cumulus Global.  Chris is a successful Information Services executive with 40 years experience in information services operations, application development, management, and leadership. His expertise includes corporate information technology and service management; program and project management; strategic and project-specific business requirements analysis; system requirements analysis and specification; system, application, and database design; software engineering and development, data center management, network and systems administration, network and system security, and end-user technical support.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2023-02-24 09:00:342026-05-11 21:24:50The Cloud, Shared Responsibility, and You

Understanding a Third Party Data Breach & How to Prevent One

February 22, 2023/in Blog, General

Understanding Third Party Breach AlertsWhat is a Third Party Data Breach?

A third party data breach occurs when an individual’s login identity and/or personally identifiable information (PII) has been disclosed by a third party system or service. A third party system or service is one that is unrelated to your business.

Third party data breaches are a security risk to your business and your employees. To understand this risk, we look at human behavior and the nature of modern cyber attacks. Knowing the risks, we look at ways to identify and respond. We discuss methods to ensure you are properly protecting your employees and your business.

The Risks of Third Party Data Breaches

The Risk of Human Nature

Multiple studies show that between 65% and 70% of humans will use identical or similar passwords across systems. The practices of “patterning” and “mimicking” passwords is more common across accounts using the email address or username as the account identity, whether or not the login is for a business system or some other system or service.

Think about employees using their work email for business-related services, such as video conferencing services, LinkedIn, or file sharing services. Some employees may have accounts to online stores for purchasing materials or supplies.  A breach in any of these systems, which are out of your control, poses a risk to your business.

A second aspect of human nature that works against us: humans are social creatures.  People, at different levels, want and need to interact with others.  In general, humans are trusting and we want to be helpful.  We will share information if and when it fits within typical interactions and when we think we are helping ourselves or others.

The Risk of Cyber Attack Methods

Currently, sophisticated criminal organizations (sometimes backed by hostile nation-states or terrorist groups) execute the vast majority of cyber attacks. They often sell and trade methods, malware, and data on the dark web, as different organizations build specialized expertise. Modern cyber attacks reflect the sophistication and expertise of the cyber criminals. Most cyber attacks involve indirect and direct methods.

Indirect Attacks

We define indirect attacks as those intending to gather information. Cyber criminals collect useful information in order to conduct direct attacks and to sell to other criminals. Phishing, social media “clickbait”, and third party data breaches are three common examples of indirect attacks that provide personal information for further attacks.

Direct Attacks

We define direct attacks as those intending to gain access to your systems and information. These include compromised user identities or credentials, ransomware, activity/keystroke monitoring, business email compromise attacks, and other attacks where your data is exposed or altered.

Direct attacks are more successful if they use data gathered from previous, indirect attacks.  And while cyber attackers may manage the complete attack, it is more common for those interested in direct attacks to buy data from those that specialize in conducting indirect attacks.  Your answers to quizzes and games on Facebook are being sold to cyber criminals that will use that information against you in a future attack. Indirect attacks also gather information that allow the attackers to impersonate you, organizations, or those around you.

Maybe the information lets them craft a surprisingly real-looking email asking you to log into a fake website, or to transfer money to a vendor using incorrect banking information.  Or, you are asked to share the MFA code you received by text. And with enough information, the attackers pretend to be you and ask your customers to make a payment by wire or ACH transfer using their banking information, not yours.

Tracking Third Party Data Breaches

The best method of tracking third party data breaches is subscribing to a monitoring and alert service.  Use the service to scan and monitor the dark web for data breaches related to any email address from your business domain(s).  The service should send you alerts that include:

  • Email address of the breached account
  • Origin of the breach, if known and disclosed
  • The Source of the breached data (where was the data posted/visible)
  • The type of the compromise
  • When the data was found
  • If a password was compromised, and if the password is visible or encrypted
  • Any PII disclosed in the breach

Using this information, you can assess the risk and take appropriate actions in response.

At Cumulus Global, we partner with DarkWeb ID for third party data breach monitoring and alerts.  Our eBook, Understanding Third Party Breach Alerts, covers how to analyze alerts, assess risks, and respond accordingly.

Protecting Your Business From a Third Party Data Breach

To fully protect your business from a third party data breach, your security strategy needs to ensure you have three things in place:

  1. You and your team should understand your security risks and how your behaviors can help or prevent an attack.
  2. Have procedures and technologies in place to protect you from successful attacks
  3. Have security services in place to prevent the disclosure or loss of data and/or system access.
  4. Capabilities and services in place to respond should an attack be successful, and to help your business recover.

We developed our Security CPR® managed security services specifically to help small and midsize businesses create, deploy, and manage an appropriate security strategy. If you follow this model in addition to other cyber security best practices, you’ll be well positioned to prevent a third party data breach.

Communicate & Educate

    • Communicate with your team that Cyber Security is a priority and educate them on cyber security risks, the need for everybody to be vigilant, and the behaviors/actions they can use to help prevent successful attacks.
    • Develop policies and procedures to establish clear expectations for how your organization will maintain cyber security and how your team will use security technologies and services

Protect & Prevent

      • Select, deploy, and maintain security technologies and services that match and support your cyber protection needs and priorities.
      • You can simplify your security services by focusing on the most likely threats and those that would have the greatest impact if successful (see: How Can SMBs Streamline IT Security?)

Respond & Recover

    • Put systems in place to recover lost or damaged data and systems; consider business continuity solutions that enable you to continue operating your business while restoring your primary systems.
    • Pre-arrange resources to help you respond to the technical, regulatory, legal, reputation, and customer service impacts of a successful cyber attack

You can learn cyber security tips and key information about third party data breach prevention by viewing Security CPR®, our 3T@3 Webcast from January 2023.

Call To Action

Complete our Rapid Security Assessment (free through June 2023) for a review of your basic security measures.

Or, contact us or schedule time with one of our Cloud Advisors to discuss your security needs, priorities, and solutions.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America. Starting his first business at age 12, Allen is a serial entrepreneur. He has launched strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.

 

 

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2023-02-22 10:00:062025-09-30 16:26:48Understanding a Third Party Data Breach & How to Prevent One

Cumulus Global Recognized on the 2022 CRN® MSP 500 List

February 20, 2023/in General, News

2022 CRN MSP 500Company Celebrates 5th Consecutive Year of Recognition as an Industry Leader

For the fifth consecutive year, Cumulus Global proudly shares that CRN®, a brand of The Channel Company®, has named Cumulus Global to its Managed Service Provider (MSP) 500 list in the Pioneer 250 category for 2022. CRN’s annual MSP 500 list identifies leading North American service providers with forward-thinking approaches to managed services. Cumulus Global’s inclusion on the 2022 MSP 500 recognizes the company’s through leadership on managed cloud services and the company’s ability to help its customers increase productivity, simplify IT solutions, secure their business, and maximize their return on investment.

“The continued recognition by CRN as a Pioneer on the 2022 MSP 500 List is an incredible honor,” stated Cumulus Global CEO Allen Falcon. “We appreciate CRN recognizing the differentiation we bring to the market, and our clients, with our managed cloud services offerings.”

Cumulus Global innovates in ways that help small and midsize businesses (SMBs) adapt to changing business conditions. Many SMBs continue recovering from, and adjusting to, the impact of the COVID-19 pandemic. Cumulus Global leverages cloud services that more effectively and efficiently support remote and hybrid work environments. The company’s Security CPR® managed security services provides SMBs with an understandable method of assessing security risks, prioritizing needs, and deploying effective, budget-friendly solutions.

“In addition to having to adjust their own business operations to account for the changed conditions during the pandemic, MSPs have also seen increased demand for their managed communications, collaboration and security services,” said Blaine Raddon, CEO of The Channel Company. “The solution providers on our 2022 MSP 500 list deserve credit for their innovative and game-changing approaches to managed services in these unpredictable times, as well as their ability to optimize operational efficiencies and systems without straining IT budgets.”

The economy, markets, supply chains, expectations for work environments, and other business factors remain in flux post-pandemic.  Cumulus Global managed cloud services blend the best aspects of traditional MSP services with a “cloud first” perspective. Leveraging the economies of cloud computing, Cumulus Global offers these robust, secure services at costs below traditional IT services for small and midsize businesses.

The MSP 500 list is featured in the February 2022 issue of CRN and online at www.crn.com/msp500.

About Cumulus Global

Cumulus Global is an industry-leading managed cloud service provider with a mission to deliver solutions with tangible value.

  • What We Do: We translate your business goals and objectives into solutions and services.
  • How We Do It: We start with your business needs and priorities. Planning and migration includes guidance to help your team adopt and utilize new services. Your team benefits from co-managed services, on-going support, and client success services that help you adapt as your business changes and grows.
  • What We Offer: Managed cloud solutions featuring Google, Microsoft, and more than three dozen providers.
About The Channel Company

The Channel Company enables breakthrough IT channel performance with our dominant media, engaging events, expert consulting and education, and innovative marketing services and platforms. As the channel catalyst, we connect and empower technology suppliers, solution providers, and end-users. Backed by more than 30 years of unequaled channel experience, we draw from our deep knowledge to envision innovative new solutions for ever-evolving challenges in the technology marketplace. www.thechannelcompany.com  

Follow The Channel Company: Twitter, LinkedIn, and Facebook.

The Channel Company Contact:

  • Jennifer Hogan
  • The Channel Company
  • jhogan@thechannelcompany.com
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2023-02-20 09:00:332025-09-30 16:27:55Cumulus Global Recognized on the 2022 CRN® MSP 500 List

Google Workspace Fee Increase Effective April 11, 2023

February 16, 2023/in General, News

Google WorkspaceOn February 11, 2023, Google provided sixty (60) days notice of a Google Workspace fee increase across most licenses.  For many customers, this increase is coming immediately after increased fees related to the transition from G Suite to Google Workspace.

The Google Workspace Fee Increase in Summary

The Google Workspace fee increase primarily impacts subscriptions on the “Flex Plan”, or month to month service.  Flex Plan fees will increase by 20%. This includes all Google Workspace Business, Enterprise, Front Line Worker, Archived User, and Appsheet licenses. The 20% increase also impacts Google Cloud Identity Premium licenses.

Additionally, the underlying annual commitment plan fees for Google Workspace Enterprise Standard is increasing by 15%.  Enterprise Standard Flex Plan licenses will be charged the 20% increase on top of the 15% increase.

Google Workspace Fee Increase Details

For all Google Workspace Business plans, the per-user fees for Flex Plan subscriptions are increasing by 20%. The per user monthly fees will change as follows:

  • Business Starter: from $6 to $7.20 per user per month
  • Business Standard: from $12 to $14.40 per user per month
  • Business Plus: from $18 to $21.60 per user per month

For all Google Workspace Enterprise plans, the per-user fees for Flex Plan subscriptions are increasing by 20%. There is also an increase in the underlying Annual Commit pricing for Google Workspace Enterprise Standard. The per user monthly fees will change as follows:

  • Enterprise Essentials – Flex Plan: from $10 to $12 per user per month
  • Enterprise Starter – Flex Plan: from $10 to $12 per user per month
  • Enterprise Standard – Annual Commit Plan: from $20 to $23 per user per month
  • Enterprise Standard – Flex Plan: from $20 to $27.60 per user per month
  • Enterprise Plus – Flex Plan: from $30 to $36 per user per month

Similar 20% increases will impact Flex Plan pricing across the following licenses:

  • Google Vault
  • Google Workspace Front Line Worker
  • Google Workspace Archived User (all Business and Enterprise licenses)
  • Cloud Identity Premium
  • Google Workspace Appsheet (all Business and Premium licenses)

Impact on G Suite to Google Workspace Transition

If you are still using G Suite licensing, these changes will be in effect as of April 11, 2023 or as of your transition date if your transition occurs after this date. If you are using G Suite on an Annual Commitment Plan, Google will automatically move you to Google Workspace on your annual (or contract) renewal date.  If you are using G suite on a Flex Plan, Google should provide your with 60 days notice of your automatic transition. Google began automatic (forced) transitions earlier this month and will continue until all customers are moved to Google Workspace.

As a reminder: When Google automatically transitions your service from G Suite to Google Workspace, Google will select the licensing that maintains your current feature set even if the transition will double or triple your monthly per user fees. Cumulus Global can manage your transition can discuss options to avoid or mitigate these increases. 

Avoid the Fee Increase

You can avoid this fee increase by converting your service from the Flex Plan to an Annual Commitment Plan.

Flex Plan subscriptions are month-to-month. As such, you can adjust the number of licenses up or down, as needed, each month. Your invoices are in arrears and reflect any changes.

Annual Commitment Plan subscriptions, as the name implies, commit you to one year (or multiple years) of service.  During your Commitment Plan term, you may added licenses at a prorated fee through the end of your term.  Any added licenses increase your commitment. You cannot reduce the number licenses (you can reuse them as employees leave and new employees join your business) and you cannot cancel service until your contract renewal date.

Given the fee increase on Flex Plan subscriptions, most small businesses will NOT save money by remaining on the Flex Plan, even if your license count fluctuates over the year.

  • For the Flex Plan to be less expensive, you would need to reduce your license count by more than the equivalent of 20% of your users for a full 12 months.
  • Example 1:
    • A seasonal business that reduces its staff for 6 months each year would need to reduce their license count by more than 40% to save money on the Flex Plan.
  • Example 2:
    • A business that reduces staffing for the 3 primary winter months would need to reduce their number of licenses by more than 70% to save money on the Flex Plan.

Most small businesses do not have staffing changes this large. Please evaluate your projected costs and consider switching to an Annual Commitment Plan.

Call To Action

Contact us or schedule time with one of our Cloud Advisors to discuss your options. We are here to assist you and to ensure you are getting the best value from your Google Workspace services.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Founded in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions, Allen has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.  Having started his first business at age 12, Allen is a serial entrepreneur having started strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.

 

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2023-02-16 12:00:562023-02-22 14:27:16Google Workspace Fee Increase Effective April 11, 2023

3 Questions – About Cyber Security

January 12, 2023/in General

Data Protection & SecurityShare your answers to our 3 Questions and, in exchange, we will

  • Schedule time (no cost / no obligation) with one of our Cloud Advisors to discuss why the questions are important and to review your answers
  • Provide our Rapid Security Assessment at no cost to you.
3 Questions about Cyber Security:

1) How do you protect your user devices?

  • Anti-virus, next-gen endpoint protection, managed event detection and response, other …

2) Do you require that employees multi-factor authentication (MFA) when connecting to online services?

  • For all services, some services, other …

3) Do you perform backups of critical systems and data?

  • weekly, daily, hourly, other …
Why and How:

These 3 Questions about Cyber Security indicate how well you may be protected, and your ability to recover, from the most common and most costly types of Cyber Attacks on small businesses.

  • To learn more about you risk and protections, Schedule a chat with one of our Cloud Advisors.
  • Share Your Answers to access three no-cost security assessments. 
Related Resources
  • State of Security for Small and Midsize Businesses (eBook)
  • Debunking 5 Cyber Security Myths for SMBs (Blog Post)
  • How Can SMBs Streamline IT Security? (Blog Post)

About 3 Questions:

3 Questions is a new program we are launching to help small business owners and IT leaders think about the issues facing their businesses in new ways.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Founded in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions, Allen has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.  Having started his first business at age 12, Allen is a serial entrepreneur having started strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.

 

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2023-01-12 15:00:472023-02-03 16:42:483 Questions – About Cyber Security

Lessons from the Rackspace Attack

December 13, 2022/in Cybersecurity, General
ransomware

Cyber Security Ransomware Email Phishing Encrypted Technology, Digital Information Protected Secured

On December 2, 2022, a ransomware attack on Rackspace disrupted email services for thousands of businesses.  The attack encrypted files throughout Rackspace’s Hosted Exchange environment, one of the largest in the world.  The outage impacts mostly small and midsize businesses (SMBs).  While Hosted Exchange is only 1% of Rackspace revenue, the incident was large enough to warrant a filing with the Securities and Exchange Commission. We can all learn lessons from the Rackspace attack with respect to cybersecurity and response.

Lessons from the Rackspace Attack

1 Incident Response Must Be Quick

In their SEC filing, Rackspace noted that their “… information security team had strong incident response protocols in place that led to the quick containment of the ransomware attack.”  They were able to limit the damage to the Hosted Exchange service, protecting other aspects of the company’s operations and other services.

For SMBs like ours, speed is also necessary. Quickly identifying an attack and isolating effected devices is critical. An infected laptop can spread the infection to servers and through files sync’d into cloud storage (ie, OneDrive, Google Drive, Dropbox). From there, every connected device is vulnerable.

2 Recovery is Not a Sure Thing

Rackspace is NOT recovering customers’ Hosted Exchange service. The company is moving these customers to Microsoft 365.

Paying the ransom is not always possible. Paying a ransom does not guarantee that your get your data back.

3 Recovery is Difficult

As of December 12, 2022 — a full 10 days after the attack, Rackspace disclosed that about two thirds of its customers have been transitioned to Microsoft 365. Nearly one third of customers remain without email service. Rackspace is effectively abandoning its Hosted Exchange service.

The logistics of identifying recoverable data and understanding interdependencies is complex. Managing data restoration across multiple devices, systems, and data sets is challenging. Some data will be lost. Understanding which data, and how much data, has been lost is challenging.

4 Recovery is Big and Slow

Rackspace has hired staff and contracted with many Microsoft Fast Track service providers.  Even so, call wait times are still averaging about 30 minutes.  Rackspace is setting expectations, repeatedly telling customers that data recover will “necessarily take significant time”.

Starting with a clean system gets your systems up and running. How effectively can your run your business without your data?  Data recovery takes time, even from backups. While emails may be relatively easy to live without, what is the impact if your accounting system is unavailable for days or weeks?

5 Recovery needs Expertise

While Rackspace is a leading technology firm, they have hired outside firms to investigate the attack and remediate the incident.

Most IT firms servicing SMBs do not have the expertise or staff to respond to a cyber attack. Expertise and resources will be needed for investigations and forensics, data recovery, systems restoration, communications, regulatory reporting and compliance, and customer service.

6 Recovery is Expensive

Rackspace is actively promoting that it maintains sufficient cybersecurity insurance to cover the costs of the incident. Their SEC filing, however, does not indicate if or how they plan to compensate customer for their losses.

You will spend money … lots of money … beyond the cost of getting your data back, your systems restores, and your business back up and running. Regulatory filings, communication, legal services, and litigation can be a crushing burden that threatens. More than half of SMBs fail within six months of a significant cyber attack.

Steps You Can Take

Looking at the lessons from the Rackspace Attack informs how we should think about protecting our businesses and ensuring we can return to normal operations quickly and efficiently. Here are resources for you to learn more.

Earlier this year, we blogged about how Streamlining Security for SMBs can protect you from the most common and the most expensive types of cyber attacks without breaking your budget.  We held a webinar on the same subject.

Our Security CPR® managed security service model outlines the three critical aspects of cyber security communication/education, protection/prevention, and recovery/response.  Our eBook, 15 Best Practices for Cyber Protection, dives into the model.

To discuss your security footprint, risks, and options, contact us by email, via our website, or by scheduling time directly with one of our Cloud Advisors.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2022-12-13 15:00:412025-10-09 13:56:17Lessons from the Rackspace Attack

Service Update: Microsoft 365 Fees Increase on January 1, 2023

December 5, 2022/in General, News

Cumulus Global 15 Years of ServiceService Update: Microsoft 365 Fees Increase on January 1, 2023.

As previously announced by Microsoft, Microsoft 365 Fees Increase on January 1, 2023.  In addition to increased fees for specific licenses, Microsoft is changing the structure of annual agreements and adding a 20% surcharge for month-to-month licensing.

Why Now?

Microsoft has been working towards these changes for more than a year. They company pushed back the deadline several times as the change coincided with major changes to Microsoft’s partner program. Microsoft has notified customers and partners that all subscriptions will be on the new pricing as of January 1, 2023.

For our customers, Cumulus Global has delayed the impact and fee increases for as long as possible.  We are communicating with our customers individually to address the final deadline.

New Terms and Conditions

With the pricing changes, Microsoft is also changing some of the terms and conditions for the services.  Historically, Microsoft has not enforced commitments on annual agreements; customer were free to change user counts and even cancel without penalty. Going forward, Microsoft will enforce annual subscriptions and terms as firm commitments. Customers may change or cancel within three (3) days of starting an annual term. Customer commit to the number of licenses for the full year. Microsoft is offering a three year commitment option as well, which secures pricing for that period.

If you need or want the flexibility of increasing and decreasing user counts at any time, you will need to opt for month-to-month licenses.  Monthly licensing lacks the commitment but includes a 20% surcharge over fees for an annual commitment.

License Pricing Changes

The following are the fee changes for annual licensing. All fees are listed as per user per month.

  • Microsoft 365 Business Basic
    • Annual: From $5 to $6
    • Monthly: $7.20
  • Microsoft 365 Business Premium
    • Annual: From $20 to $22
    • Monthly:  $26.40
  • Office 365 E1
    • Annual: From $8 to $10
    • Monthly: $12
  • Office 365 E3
    • Annual: From $20 to $23
    • Monthly: $27.6
  • Office 365 E5
    • Annual: From $35 to $38
    • Monthly: $45.60
  • Microsoft 365 E3
    • Annual: From $32 to $36
    • Monthly: $43.20

All other Microsoft 365 and Office 365 license fees remain this same with an annual commitment; monthly fees will reflect the 20% surcharge.

Next Steps

Our team is contacting each our customers impacted by the pricing to discuss their options and plan their services going forward.

As we are here to assist any small business with their cloud services, feel free to contact us by email, via our website, or by scheduling time directly with one of our Cloud Advisors to discuss your options and path forward.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2022-12-05 08:30:022022-12-04 21:05:35Service Update: Microsoft 365 Fees Increase on January 1, 2023

Service Update: Archived User License Fees Begin in January

December 2, 2022/in General, News

Cumulus Global 15 Years of ServiceService Update: Archived User License Fees Begin on January 23, 2023.

As previously announced by Google and covered in our blog, Google has discontinued the Vault Former Employee (VFE) service.  All Google Workspace customers had there VFE licenses converted to a trial of the Archived User License (AUL) service.

The free trial of the AUL service ends on January 15, 2023.  Archived User License fees begin on January 16, 2023.

Archived User License (AUL) Fees

All customers with active AUL accounts will be invoiced in accordance with their Google Workspace License:

  • $4/user/month – Google Workspace Business AUL
  • $5/user/month – Google Workspace Enterprise Standard AUL
  • $7/user/month – Google Workspace Enterprise Standard AUL

Available Options

In addition to keeping your AUL subscription and paying the above fees, you have the option to:

  • Discontinue the AUL subcription
    • Removing the service will permanently remove all archived data.
    • Deleted archived data cannot be restored or recovered.
  • Export the Data prior to discontinuing the AUL service
    • This provides you with a static copy of existing data in your AUL accounts.
    • Data in your AUL accounts are permanently deleted when you discontinue the subscription.
  • Migrate to a third party archive solution prior to discontinuing the AUL service
    • Your archive of past Google Workspace user accounts is preserved using a third party archive solutions, prior to ending your AUL subscription.
    • The annual fees to retain the archived accounts is significantly lower than AUL licensing.
    • You will incur migration fees to move your data.
    • Data in your AUL accounts are permanently deleted when you discontinue the subscription.

Next Steps

Organizations with Archived User Licenses should contact us as soon as possible by email, via our website, or by scheduling time directly with one of our Cloud Advisors to discuss your options and path forward.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2022-12-02 14:00:442022-12-21 21:13:14Service Update: Archived User License Fees Begin in January

Google Workspace Transition Update – 12/01/22

December 1, 2022/in General

Google WorkspaceMore than two years after announcing the change, the Google Workspace transition from G Suite continues.

  • For organizations running G Suite with an annual or term commitment, your transition is scheduled to occur on your next renewal date.
  • For organization on the Flex Plan (month to month), Google will automatically transition your account with 60 days advanced notice.
  • Organizations willing to transition with an annual commitment before Google transitions you automatically may be eligible for incentive discounts.

For many, if not most, organizations, this transition will result in higher subscription fees and/or loss of features.

This post identifies the restrictions and potential features impact for organizations currently running G Suite Basic and G Suite Business editions.

Current G Suite Basic Subscribers

  • Additional Storage
    • If you currently do not have additional storage assigned to at least one user:
      • You can no longer add this service.
      • You will not have the ability to add storage to your Google Workspace subscription.
      • As users reach the 30GB limit, you will need to upgrade to Google Workspace Business Standard or Business Plus editions at an additional cost.
    • If you currently have additional additional storage assigned to at least one user:
      • You may grandfather this service and you may be able to add more storage.
      • The duration for how long you can maintain your existing additional storage or add new additional storage has not be clearly defined by Google. At the end of the grandfather period, you will need to upgrade to a version of Google Workspace that meets your storage needs.
  • Vault
    • If you currently have Vault:
      • You may be able to grandfather this service.
      • The duration for how long you can maintain Vault as an add-on has not been defined by Google. At the end of the grace period, you will need to upgrade to Google Workspace Business Plus to maintain this service and data.
    • If you currently do not have Vault:
      • You should select and upgrade to Google Workspace Business Plus to add this service.
  • Advanced Endpoint Management
    • This feature is not available in Google Workspace Business Starter or Business Standard subscriptions. You will not be able to set up company-managed mobile devices or selectively distribute apps to mobile devices.
    • If you use this feature, you should select and upgrade to Google Workspace Business Plus.
  • Organizational Branding / Templates
    • This feature is not available in Google Workspace Business Starter. You will no longer be able to create or use custom templates for Google Docs, Sheets, Slides, Forms and Sites. Documents created from the templates remain.
    • If you use this feature, you should select and upgrade to Google Workspace Business Standard or Business Plus.
  • Advanced Chat Space Features / Spaces
    • This feature is not available in Google Workspace Business Starter. You will no longer be able create spaces that allow external users. Existing spaces remain and users can make changes to existing spaces, such as adding or removing members.
    • If you use this feature, you should select and upgrade to Google Workspace Business Standard or Business Plus.

Current G Suite Business Subscribers

  • Storage Capacity
    • Your storage capacity will be limited based on the Google Workspace Business tier subscription you select for you transition:
      • Business Starter: 30GB per user, fixed
      • Business Standard: 2TB per user, aggregated across all users
      • Business Plus: 5 TB per user, aggregated across all users
    • To maintain unlimited storage capacity, you should select and upgrade to Google Workspace Enterprise Standard or Enterprise Plus.
  • Google Vault
    • This service will not be available if you transition to Google Workspace Business Starter or Business Standard.  Additionally, holds and retention rules will stop protecting your organization’s messages and files. Google will immediately remove all data that users deleted more than 30 days ago from all Google systems. You cannot recover this data.
    • To keep the Vault service, you should select and upgrade to Google Workspace Business Plus or an Enterprise tier subscription.
  • Advanced Endpoint Management
    • This feature is not available in Google Workspace Business Starter or Business Standard subscriptions. You will not be able to set up company-managed mobile devices or selectively distribute apps to mobile devices.
    • If you use this feature, you should select and upgrade to Google Workspace Business Plus.
  • Organizational Branding / Templates
    • This feature is not available in Google Workspace Business Starter. You will no longer be able to create or use custom templates for Google Docs, Sheets, Slides, Forms and Sites. Documents created from the templates remain.
    • If you use this feature, you should select and upgrade to Google Workspace Business Standard or Business Plus.
  • Advanced Chat Space Features / Spaces
    • This feature is not available in Google Workspace Business Starter. You will no longer be able create spaces that allow external users. Existing spaces remain and users can make changes to existing spaces, such as adding or removing members.
    • If you use this feature, you should select and upgrade to Google Workspace Business Standard or Business Plus.
  • Shared drives
    • This feature is not available in Google Workspace Business Starter. You will no longer be able manage existing shared drives. In addition, users and owners will not be able access shared drive content or add or delete content to or from shared drives. Before switching editions, ask shared drive owners to review their content and move it to their My Drive to maintain access.
    • If you use this feature, you will should select Google Workspace Business Standard or Business Starter.
  • Organization-Specific Drive Settings
    • This feature is not available in Google Workspace Business Starter. All users in your organization will inherit the settings of your top-level organizational unit, but the organizational structure itself will not change.
    • To maintain this feature, you should select Google Workspace Business Standard or Business Plus.
  • Meets
    • If you transition to Google Workspace Business Starter, your Meets will be limited to 100 participants.
    • Select G Suite Business Standard or Business Plus to maintain you Meets capacity.
  • Calendar Advanced Controls
    • These controls will not be available if you transition to Google Workspace Business Starter or Business Standard.  Rooms aren’t automatically released when all attendees decline. Rooms that decline invitations aren’t replaced. You can’t set a default duration for events.
    • To maintain access to these controls you will should select Google Workspace Business Plus.
  • Data Regions
    • These controls will not be available if you transition to Google Workspace Business Starter or Business Standard.  You can no longer choose a geographic location for your data.
    • To maintain access to these controls you should select Google Workspace Business Plus.
  • Session Length for Google services
    • These controls will not be available if you transition to Google Workspace Business Starter or Business Standard.  You can no longer control how long users can access Google services without having to sign in again.
    • To maintain access to these controls you should select transition to Google Workspace Business Plus.
  • Predefined Content Detectors
    • This feature is not available in Google Workspace Business Starter. If you use any predefined content detectors data-loss prevention, Google will remove them from any settings that use them.
    • To maintain this feature, you should select Google Workspace Business Standard or Business Plus.
  • Automated User Provisioning Applications
    • Google limits the scope of this feature in Google Workspace Business Starter. If you have more than 3 automated user provisioning applications, you must first remove automated user provisioning from all but 3 applications before downgrading.
    • To maintain this feature, you should select Google Workspace Business Standard or Business Plus.
  • Target Audiences
    • This feature is not available in Google Workspace Business Starter. You can’t recommend specific groups of people, like departments or teams, for your users to share their items with. Important: Any target audiences currently in use aren’t automatically deleted when you switch to this edition. You might want to delete them before switching.
    • To maintain this feature, you should select Google Workspace Business Standard or Business Plus.

Call To Action

Contact us or schedule time with one of our Cloud Advisors to discuss your options to best manage your transition. By default, Google will transition your G Suite account to the version of Google Workspace based on your user account and your use of the services and features listed, above. Your subscription fees may double or triple.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2022-12-01 11:00:302022-12-01 12:47:18Google Workspace Transition Update – 12/01/22

Responding to Ransomware: Police, Pay, or Panic?

November 28, 2022/in Cybersecurity, General

ransomware response plan
In today’s digital landscape, the threat of ransomware looms large, posing a significant risk to businesses and organizations of all sizes. Ransomware, a malicious form of cyber attack, can swiftly encrypt critical data and hold it hostage until a ransom is paid. These attacks can disrupt operations, compromise sensitive information, and inflict financial losses. In the face of this evolving threat, having a robust ransomware response plan is imperative.

At Cumulus, we understand that responding to ransomware is complicated.  With the continuing increase of successful cyber attacks against small businesses, we hear a lot of debate on two aspects of your ransomware response to a successful attack.

  • Should you contact law enforcement?
  • Should you pay the ransom?

Both of these questions have pros and cons. How and when you answer these questions can have a long-lasting impact on you and your business. Read on to learn about top ransomware response plans, how to prevent a ransomware attack, and other vital information to keep you and your business safe.

Ransomware Incident Response Strategies

Involving Law Enforcement

The debate about if and when to contact law enforcement often centers around what happens after law enforcement gets involved.  Typically, you would contact your local police department which, in turn, would contact the cyber crimes unit of your state police (if your state has one) and/or the FBI. You can also report a ransomware attack directly to the FBI or the Cybersecurity and Infrastructure Security Agency (CISA).

The biggest risks to involving law enforcement are the effects of a criminal investigation. You may not be able to repair and rebuild your systems until a forensic investigation is complete. In some cases, your computers may be considered evidence as part of a criminal investigation. By delaying your access to your computers, these actions can disrupt your ability to recover those systems.

The biggest advantages to involving law enforcement is the assistance the cyber security agencies can provide during the investigation and recovery. The FBI Cyber Division, CISA, and the National Cyber Investigative Joint Task Force can help identify the specific attack. For known variants, they often have valid decryption keys.  If involved quickly enough, the FBI and other agencies have a history of recovering at least some ransoms and thefts (e.g. the Colonial Pipeline incident).

If you have cyber insurance, you may not have a choice about reporting the attack to law enforcement.  Your carrier may require you to involve law enforcement as a condition for processing your claim. Your insurer may also mandate a forensic analysis to fully understand the scope of the attack and the necessary steps to recovery.

Paying the Ransom

Responding to ransomware, you want to move quickly and correctly. Wiping and rebuilding systems, restoring your data from backups, and recreating missing or damaged data takes time and money. Decrypting the data can be faster and easier.  Paying the ransom is tempting. Your insurance carrier may also pressure you to pay the ransom to lower the cost of the claim.

Before you pay a ransom, consider the following:

  • As noted above, law enforcement may already have decryption key;
  • It is a funding mechanism for hackers to carry out future and repeated attacks;
  • Paying a ransom does not guarantee you will receive a decryption key;
  • Even with the decryption key, you may not be able to recover all of your data;
  • Attackers will often demand additional payments to prevent the release of stolen information; and
  • Paying the ransom is likely to be a federal crime as it may be funding hostile nations, terrorism, human tracking, or child exploitation.

To the latter point, paying ransom to an organization or government on a sanctions list, including those tied to terrorist activities, violates US law (18 USC 2339A, 2339B, 2339C). In October of 2020, the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) issued a warning that “Ransomware Payments with a Sanctions Nexus Threaten U.S. National Security Interests” and could result in civil and criminal actions.

Recommended Actions For a Ransomware Response

When responding to ransomware, you will need to work with your cyber insurance carrier. Contacting law enforcement early is more likely to help your recovery than hinder it.

  • Additional expertise
  • Simultaneous investigation/forensics with your insurer
  • The possibility of known decryption keys for your ransomware variant
  • The ability to cover lost or stolen funds
  • The potential identification of the source of the attack

These benefits can mitigate the damage and help speed recovery.

Paying the ransom should always be a last resort. To avoid violating US law and facing the risk of criminal charges or civil sanctions, paying a ransom should not be done without consulting law enforcement.

For more information about cyber security and protecting your business, visit our Resource Center, or schedule an introductory call with one of our Cloud Advisors.

 

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2022-11-28 10:00:062025-10-09 13:56:43Responding to Ransomware: Police, Pay, or Panic?
Page 13 of 69«‹1112131415›»

Recent Posts

  • Secure Gemini AI in Google Workspace
  • Your Path to Full Cloud Adoption
  • How We Use AI for Data Enrichment

Featured Blog Topics

  • Artificial Intelligence / AI
  • Managed Cloud Services
  • Cybersecurity

Read

  • Blog
  • Newsletter
  • Microsoft Cloud Monday
  • Google Workspace Wednesday

Watch

  • 3T@3 Series
  • Coffee and Clouds
  • Event Recordings
  • Cumulus Global Channel

Explore

  • Library
  • Events Calendar

Phone / Fax / Email

  • 866-356-1202
  • 508-948-4070
  • info@cumulusglobal.com

Headquarters / Boston

  • Street Address

    4 Bellows Rd / 2nd Floor
    Westborough, MA 01581

  • Mailing Address

    PO Box 1129
    Westborough, MA 01581-6129

Regional Offices

  • Southeast Office

    120 W Trinity Pl
    Decatur, GA 30030

Copyright © 2026 - Cumulus Global | Privacy Policy | Terms of Service | Disclaimer | Website by Cold Spring
Scroll to top Scroll to top Scroll to top