• Link to Instagram
  • Link to LinkedIn
  • Link to Facebook
  • Support
  • Resource Center
  • News & Events
  • Blog
  • Pay Online
Cumulus Global
  • What We Do
    • Managed Cloud Services Provided by Cumulus Global
    • Cloud Computing Security, Privacy, Compliance, & Continuity
    • Collaboration, Productivity, & Transformation
    • Managed Infrastructure & Platforms
  • How We Do It
    • Understand & Assess
    • Cloud Computing Strategy & Planning
    • Cloud Migration & Deployment
    • Cloud Managed Services
    • Service & Support for Cloud and IT Solutions
    • Global Strategic Services
    • Guide, Educate, & Train
  • What We Offer
    • Managed Cloud Services
    • IT Admin, Service, and Support
    • Security CPR® Managed Security
    • Google Cloud Workspace / Education / Chrome / Voice
    • Google Cloud Platform Computing Services
    • Microsoft 365 and Office 365 Managed Services
    • Microsoft Azure
  • Who We Are
    • Our Mission
    • Our Team and Opportunities
    • Our Cloud Computing Partners
    • Our Reviews and Testimonials
    • Our Community
    • Our Sustainability
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Archive for category: Topic Series

Secure Gemini AI in Google Workspace

July 31, 2026/in AI in Google Workspace, Blog, Cybersecurity, General

Three Ways to Protect Company Files When Your Team Uses Gemini AI

Written by Allen Falcon, Co-Founder & CEO, Cumulus Global

Artificial intelligence offers incredible potential for productivity. AI also creates new security challenges.

Follow these three steps to protect and secure information when using Gemini AI in Google Workspace.

Key Takeaways

    • ✓Gemini AI sees what your Workspace settings allow
    • ✓Cleaning up shared files prevents sensitive data leaks
    • ✓Automated onboarding and offboarding keeps permissions accurate
    • ✓Decommissioning inactive accounts closes security gaps and cuts costs

Leaking sensitive, proprietary, or confidential data via AI is easy. An employee may put confidential financial data into a public AI tool, a private AI model, like Gemini AI, might read files that were overshared within your organization, or you may accidentally externally share sensitive information embedded in an internal model.

Gemini AI relies on your existing Google Workspace permissions. If a document is shared too broadly, the AI engine will make that information visible to unauthorized users.

Fortunately, you can secure your sensitive files and establish clear guardrails with a few strategic updates.

Step 1 of 3

Audit Your File Sharing Settings

Unintended file sharing happens quietly in nearly all organizations. Over time, link sharing and external permissions create hidden security risks.

Pay close attention to these common sharing pitfalls that can inadvertently surface confidential data to AI tools:

    • Exposure via Links: “Anyone with the link” settings can expose internal documents to external search engines and public AI crawlers.
    • Sharing to your Domain: Giving permission to your entire domain gives everybody, and every attached service, access to the information.
    • Lingering Access: External sharing permissions granted to contractors often remain active long after their work is complete.
    • Group Over-Sharing: Public Google Groups may inadvertently grant broad access to internal shared drives.

Use an automated tool to scan file, folder, and shared drive permissions against defined policies and compliance guidelines. Put systems in place to monitor and mitigate risks in real-time.

Step 2 of 3

Streamline User Onboarding and Offboarding

Manual IT administration is prone to human error and inefficiency. When employees join or leave, updating access controls requires careful detail.

Establishing automated lifecycle policies helps maintain strict access boundaries at every stage of employment.

    • Automate Onboarding: Add new hires to the correct Google Groups, shared folders, and chat spaces using policy-based automation.
    • Secure Transfers: Transfer file ownership directly to managers or secure shared drives as part of your offboarding workflow.
    • Cleanup Calendars: Remove former staff from internal meetings without disrupting active client appointments.
    • Manage Contacts: Ensure mobile address books remain accurate by clearing out former employees and transferring key business contacts.

Automate these steps to ensure your access controls are up-to-date and Gemini AI only displays sensitive files to authorized team members.

Step 3 of 3

Manage Inactive Accounts and Licenses

Inactive accounts waste budget and create unnecessary entry points for bad actors. Staff members who left months ago should not remain in your user directory.

Put automated management rules in place to ensure that former accounts are properly monitored and decommissioned:

    • Suspension Rules: Establish automated account suspension policies to keep your user directory secure and up-to-date.
    • Inactivity Alerts: Utilize alerts to track and address accounts with no login activity over a 30-day period.
    • License Management: Minimize software expenses and satisfy legal data retention requirements by transitioning offboarded employees to archive licenses.
    • Data Preservation: Safely eliminate paid licenses by transferring essential data into alternate cloud storage options.

Manage user lifecycles to reduce your monthly costs while protecting your company data.

Take the Next Step for Workspace Security

Securing your workspace does not require a complete operational overhaul. Targeted, automated changes create a foundation for strong data governance and reduce operational overhead and risks.

As demonstrated in our recent 3T@3 Series session, automated solutions like Patronum give you the capability to actively monitor and manage permissions and access, streamline your onboarding and offboarding processes, and secure your Google Workspace environment.

Contact us or schedule time to connect with a Cloud Advisor at Cumulus Global to arrange your workspace security review and to explore your options.

Ready to Take the Next Step?

Whether you’re beginning your cloud migration or looking to improve an existing environment, our Cloud Advisors can help.

Schedule a conversation

Allen Falcon

Co-Founder & CEO, Cumulus Global

Allen Falcon co-founded Cumulus Global in 2006 to help small businesses implement enterprise-grade cloud, security, and compliance solutions. Under his leadership, Cumulus Global has grown into a managed cloud services provider supporting more than 1,000 organizations throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-07-31 11:31:542026-07-31 11:39:33Secure Gemini AI in Google Workspace

How We Use AI for Data Enrichment

June 29, 2026/in AI in Google Workspace, Blog, General, News

If you receive our newsletter or follow our blog, you’ve likely seen our recent posts and resources regarding proper AI usage. Our use of AI needs to be more than compliant with laws, regulations, and contractual obligations. We must be responsible and accountable for ensuring that our use of AI is both ethical and respectful to the individuals and organizations with whom we interact.

Our Commitment Includes Transparency and Security

At Cumulus Global, our commitment to ethical and appropriate use of AI includes transparency in why, when, and how we use AI services.

Any data we process through these AI tools is protected under our strict internal security protocols, ensuring your information remains secure, confidential, and never sold to outside parties.

Where We Use AI for Data Enrichment

As with most businesses, accurate information about clients, vendors, and partners is essential for managing services and communications. Data enrichment is a vital part of this process.

By definition, data enrichment is the process of updating information by filling in missing data or collecting new, relevant details.

We are currently piloting AI-powered tools to help us enrich the data we store about individuals and organizations. Doing so will give us better context for managing client relationships and for focusing our marketing and sales communications to those most likely to be interested.

Cumulus Global runs much of our operations using HubSpot, including our marketing, sales, and service functions. HubSpot features several tools (some of which use AI) to verify and update data elements in contact and company records.

Connect with a Cloud AdvisorHubSpot Breeze AI

Breeze AI is a service within HubSpot that offers data enrichment services by using the HubSpot Commercial Dataset to fill in missing fields.

Similar to commercial products like ZoomInfo, Cleanlist, Apollo, the HubSpot Commercial Dataset gathers publicly available information directly from individuals, as well as from third parties where a legal basis exists to process the information. However, unlike these other services, we cannot use HubSpot to identify new potential customers. We can only use the service to fill in missing information within our existing customer or company contact records.

Much of what the service provides involves common missing information, such as countries for addresses, country prefixes for phone numbers, and job titles. The AI component analyzes this information alongside the data we already have to provide further context, such as job function and authority. For example, a record may be updated to reflect a contact’s role as a senior manager in an operations department. The AI service also cross-references opt-outs and other verifications to help ensure we do not send you unwanted messages.

LinkedIn Integration

When a person or an organization is added to our database, HubSpot will, if possible, match the information to the person’s public LinkedIn profile or a company’s public page. HubSpot scans these public profiles and pages to fill in basic information, such as job titles, website domains, and employee counts.

You Are in Control

You are always able to manage how much of your information is shared.

LinkedIn

LinkedIn has several settings that allow you to extensively limit what the platform shares. You can review and manage these settings through your LinkedIn account.

HubSpot Commercial Dataset

HubSpot, like ZoomInfo and other data aggregators, provides the ability on its website to delete your data from the HubSpot Commercial Dataset. Doing so serves as an opt-out of the “sale” of data under relevant laws. Cumulus Global is immediately notified, and any data used to enrich our records is removed.

Cumulus Global

We do not share information other than as needed to provide our services to you and your company. You can manage which types of communications you receive from us by using the “Manage Preferences” link at the bottom of all of our automated emails.

We Are Here to Help

If at any time, you have questions or concerns, please send us an email or use the chat box or contact form on our website.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/06/2026-06-25-How-We-Use-AI-for-Data-Enrichment.HERO_.png 1350 2400 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-06-29 10:00:182026-07-28 10:52:18How We Use AI for Data Enrichment

Avoid Unrealistic AI Expectations

May 26, 2026/in AI in Google Workspace, Blog, General

Connect with a Cloud Advisor

The initial AI hype is wearing off, and a growing backlash is setting in. Now, your plans and investments need to reflect what’s actually happening.

As recently reported in Inc., a Boston Consulting Group (BCG) study found significant gaps between AI expectations and reality.

Leadership expectations for AI do not match the messy reality of rolling the technology out to frontline workers and managers. And while the study focused on larger enterprises, these challenges apply directly to small and midsize organizations.

The AI Gap

Gaps between expectations and reality manifest in three key areas:

1Expected ROI

Many businesses are investing heavily in AI but aren’t seeing the promised returns yet. The BCG study shows only 20% of leaders feel their adoption rate is correct. The other 80% feel they’re moving too slowly or inconsistently.

The study attributes this to the AI hype cycle and a limited understanding of AI among non-technical business leaders. Fear of missing out (FOMO) is driving urgency rather than clear strategic goals.

2Trust

Business leaders trust AI more than frontline workers and managers. While leadership sees pure potential, the employees using the tools are highly skeptical. Many worry that working with AI tools is just training their eventual replacements.

3Training

Executives and upper management want quick AI adoption, but their staff commonly struggle with when and how to use these new tools. The study notes that AI leadership is often unclear, leading to conflicting expectations and priorities. Your team needs hands-on training to integrate AI into their workflows, along with an easy way to provide feedback.

Steps You Should Take

Given the gaps and their potential to slow or halt AI efforts, we recommend you take the following five steps for your AI projects and efforts.

1)Create an AI
Appropriate Use Policy

A robust AI Appropriate Use Policy creates a foundation for why, when, and how your team uses AI. It also sets solid expectations for data security, privacy, and governance.

2)Define and Share your
AI Goals and Strategy

Communication builds trust. When you share your AI goals and strategies, your team will understand how AI supports their daily work. This sets healthy boundaries and removes the fear of the unknown.

3)Clearly Establish AI
Leadership and Governance

Consistent direction, priorities, and expectations reduce friction while creating predictable results. Top-down leadership provides a uniform approach that demonstrates your commitment to responsible AI usage.

4)Identify and Focus on
Specific Use Cases

AI for the sake of AI will fail. Look closely at your daily workflows, especially repetitive or data-intensive tasks, and define clear use cases. Pinpoint your desired outcomes so that you can easily review and refine the rollout.

5)Setup and Follow a
Change Management Process 

Don’t just let AI happen. Instead, make it happen. Treat your transition to AI like any other mission-critical project. Regular updates, feedback loops, and clear timelines will help you stay ahead of issues. Your team will be able to spot and fix problems before they stall your progress. 

Help is Here

We are here to help you succeed.  If you want to learn more, check out our AI Landing Zone, send us a message, or book a meeting with our Cloud Advisors.

About the Author

Bill Seybolt bio pictureBill is a Senior Cloud Advisor responsible for helping small and midsize organizations with productive, security, and secure managed cloud services. Bill works with executives, leaders, and team members to understand workflows, identify strategic goals and tactical requirements, and design solutions and implementation phases. Having helped hundreds of organizations successfully adopt cloud solutions, his expertise and working style ensure a comfortable experience and effective change management.

https://www.cumulusglobal.com/wp-content/uploads/2026/05/5-26-26-Blog-Hero-Image.png 1080 1920 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-05-26 14:00:572026-05-26 16:39:57Avoid Unrealistic AI Expectations

7 Reasons to Upgrade Your Google Workspace Business Starter Plan

May 8, 2026/in AI in Google Workspace, Blog, General

Google Workspace Business Starter is a robust, affordable productivity suite that handles the essentials of secure email, calendar, and document sharing services. But as your business grows, those entry-level features can start to feel like a constraint.

If you are outgrowing the limits of Business Starter, here are seven reasons to consider upgrading to a Business Standard or Business Plus subscription.

1 Massive Storage Increases:

Business Starter caps you at 30GB per user. This fills up fast when you consider high-resolution images, video files, and years of email history. Upgrading to Business Standard or Plus bumps your capacity to 2TB or 5TB per user, respectively. Furthermore, this storage is pooled across your entire organization, which gives your heavy users the flexibility they need.

2 Shared Drives:

Shared drives provide a centralized way to manage your folders and permissions. Ownership resides with the system instead of individuals, so access remains consistent even as your team changes. You also benefit from more precise access controls and a streamlined process for sharing files externally.

3 Appointment Scheduling:

This feature allows you to eliminate the cost of third-party tools like Calendly. By upgrading, you can create professional booking pages directly within Google Calendar. Simply set your availability and share a link to let clients book time with you, which removes the friction of back and forth scheduling emails.

4 Professional Meeting Tools:

Don’t rely on third-party AI extensions to capture your meetings. With a Business Starter or Business Plus Subscription, you unlock the ability to record Google Meet sessions and use built-in AI note-taking. These features are secure and fully integrated, ensuring your team never misses a follow-up item or a key decision.

5 Gemini AI Assistance:

Gemini AI is now built directly into Gmail, Drive, Docs, Sheets, Slides, Chat, and Meet. Whether you need a first draft of a proposal, a summary of a long email thread, or a custom image for a slide deck, Gemini acts as a force multiplier for your daily tasks. It helps your team move from a blank page to a finished product faster.

6 The Gemini App and Custom Gems:

Beyond the side panel in your documents, an upgrade provides secure access to the full Gemini LLM at gemini.google.com. You can create Gems, which are custom AI personas tailored to your specific brand voice or workflows. They allow you to schedule automated actions to keep your business moving efficiently.

7 NotebookLM:

This tool is a significant advantage for data-driven teams. NotebookLM allows you to create private and secure learning models using only your specific data. It functions like a research assistant that has read your internal documents and can synthesize information or answer complex questions instantly.

Connect with a Cloud AdvisorWhat About the Cost?

While upgrading comes with marginal increases in your per user licensing fees, the vast majority of small and midsize organizations can offset the increase.

With the expanded capabilities of Google Workspace Business Standard and Business Plus subscriptions, you can eliminate fees for:

  • Calendaring and appointment scheduling tools
  • Online meeting services
  • Standalone Gen AI subscriptions
  • External AI note-taking services
  • Additional cloud storage providers

Help is Here

We are here to ensure you have the right tools for your specific goals. If you want to learn more, check out the blog posts and eBooks in our AI Landing Zone, send us a message, or book a meeting with our Cloud Advisors.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/05/5-8-26-Blog-Hero-Image.png 718 1080 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-05-08 14:00:152026-05-08 12:22:267 Reasons to Upgrade Your Google Workspace Business Starter Plan

The AI Agent Handbook

May 4, 2026/in AI in Google Workspace, eBook

eBook | Source: Google– AI Agents are a major leap from traditional automation or chatbots. Properly deployed, They can help your employees and teams get more done. Use this guide to explore 10 ways to you and your team can use AI Agents today.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2026-05-04 13:04:212026-05-05 14:43:36The AI Agent Handbook

Gemini, Copilot, or ChatGPT? What You Want to Know

March 31, 2026/in AI in Google Workspace, Blog, General

Earlier this month, we surveyed our clients about the AI services they use regularly. The results show that a majority of respondents prioritize the AI services included within their existing productivity suites.

Of more than 50 respondents:

  • 57% use Gemini for Google Workspace (including the Gemini App, Gems, and NotebookLM)
  • 55% use Microsoft Copilot
  • 51% use stand-alone AI services, such as ChatGPT, Claude, and/or Grok
  • 12% use Gemini Enterprise

While stand-alone service adoption is slightly lower, many companies officially use more than one solution:

  • 33% use Gemini AI and at least one stand-alone service.
  • 33% use Microsoft Copilot and at least one stand-alone service.

As you evaluate your AI needs, consider these strategic factors:

Secure Your Baseline

Maintain control and security over your data before you begin your AI journey. You need to ensure that individuals using AI cannot access information beyond their specific responsibilities. Additionally, you also want to confirm that your data is not used to train or populate learning models beyond your internal systems.

This data governance is critical for maintaining compliance with regulatory, industry, and contractual requirements for data protection.

Understanding how each AI tool or service integrates with your identity, access, and security services helps you select solutions that will protect your business.

Start Simple

Before diving into multiple new solutions, explore and take advantage of the AI services embedded in your current IT systems and applications.

Microsoft Copilot and Gemini for Google Workspace each offer a robust suite of services. You may not need to make additional investments in other tools. Additionally, both platforms integrate directly with your email, documents, spreadsheets, and meetings, as well as other applications within your suite.

Leveraging these services lets you avoid the cost and complexity of third party integrations. For example, both Gemini and Copilot provide excellent transcription and note-taking services for Google Meet and Microsoft Teams meetings, respectively.

Dive DeepConnect with a Cloud Advisor

Before adding third party AI services and tools, make sure to explore and pilot the capabilities already at your fingertips.

For instance, Gemini AI for Google Workspace includes:

  • The Gemini App (gemini.google.com): Provides prompt response using public information and secure access to your content in Google Workspace. It also supports advanced image creation and manipulation, Deep Research tools, and short video creation.
  • Gems: Customized Gen AI chat agents with defined personas and objectives
  • Scheduled Actions: Automation for repetitive AI actions
  • NotebookLM: creates private, secure learning models using your data and select public information.

Define Use Cases

As part of your exploration, identify use cases where AI integration provides tangible benefits.

For each use case, define the opportunity, workflows, process changes, and desired outcomes.

These use cases provide you with a framework to test AI services and solutions, and they will help you identify the individuals and teams that will be impacted by AI adoption. These people will require training and should participate in your AI pilot projects.

Be Selective

If you cannot address use cases with your integrated and embedded AI services, focus your search on AI tools and services appropriate for your use cases.

Before selecting a tool, vet its ability to integrate with your existing applications, systems, and security. Keep in mind that every additional application introduces administrative overhead and security constraints.

Balance the added effort and costs against the potential outcomes to ensure that the tool delivers true value to your business.

Help is Here

Visit our AI Landing Zone for a range of resources to help you plan, manage, and secure your AI services.

Our Cloud Advisors can also provide the guidance and assistance you need to plan and execute your AI strategy. Send us an email or book a brief introductory call. We are here to help.

About the Author

Bill Seybolt bio pictureBill is a Senior Cloud Advisor responsible for helping small and midsize organizations with productive, security, and secure managed cloud services. Bill works with executives, leaders, and team members to understand workflows, identify strategic goals and tactical requirements, and design solutions and implementation phases. Having helped hundreds of organizations successfully adopt cloud solutions, his expertise and working style ensure a comfortable experience and effective change management.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-31.-Blog-Hero-Image.png 598 1080 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-31 10:00:162026-03-31 09:44:03Gemini, Copilot, or ChatGPT? What You Want to Know

What to Do When It Happens

March 17, 2026/in 3T@3 Webcast Series, Cybersecurity

(03/17/26) – How you initially respond to a cybersecurity incident will affect your ability to recover, your cyber insurance coverage, your customer relationships, your legal and financial liability, and possibly your survival.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2026-03-17 15:00:382026-03-18 13:40:22What to Do When It Happens

Cyber Attack Recovery Starts Before the Breach

March 12, 2026/in Blog, Cybersecurity, General

No prevention is perfect. No protection is perfect. You are already a target for cyberattacks, and eventually, one will likely succeed. When that happens, you need to know what comes next.

Event or Incident? Know the Difference

Understanding the distinction between a cybersecurity event and an incident is critical because they carry different operational and legal implications.

A Cybersecurity Event is an observable change in the status of a network, system, application, or data. You should investigate these events to determine if they qualify as an incident. Not all events become incidents.

A Cybersecurity Incident is a confirmed event, or series of events, that jeopardizes the confidentiality, integrity, or availability of data or systems. It causes harm or disruption and requires an immediate, formal response. Incidents trigger legal, regulatory, and contractual obligations, such as reporting, that must be managed.

Connect with a Cloud AdvisorYour Next Steps

With this distinction in mind, follow these steps to manage the situation effectively.

1 Do NOT Panic

Stay calm.

Quick, smart action serves you better than panic.

2 Disconnect and Isolate

Notify your IT team and service providers immediately.

Enlist their assistance to secure every impacted or potentially impacted system:

  • Log out users on all devices.
  • Change passwords or disable accounts.
  • Disconnect systems from your network and the internet.
  • Document all actions and changes with a timestamp.

3 Document the Event

Take a few moments to document everything you know.

Create a clear timeline of the situation:

  • What did you notice and when?
  • What happened and when?
  • What actions did you take (e.g., links clicked, reports made to IT)?

4 Do NOT Start Fixing Things

Your cyber insurance carrier, legal counsel, or law enforcement may need to preserve your systems for forensics.

Restoring systems or recovering data prematurely could destroy evidence and impede criminal investigations. Furthermore, altering systems might provide a reason for your insurance carrier to deny or limit your claim.

5 Make These Calls

Connect with resources that can help you navigate your next steps.

Your Cyber Insurance Agent and/or Carrier

Advise your insurer that you are responding to a cybersecurity event that may be an incident. They will want to know the nature of the event and any actions you have taken. If they determine the event is an incident, they will initiate a response.

Your insurer may: (1) Require you to report the event to law enforcement (FBI or CISA.GOV); (2) Require you to hold systems for forensic analysis; (3) Hire a specialized firm to manage recovery efforts; and/or (4) Direct you to complete other specific actions.

Your insurer may also ask for validation that you follow your security policies and procedures. Depending on your coverage, they may also provide assistance with: (1) Required legal and/or regulatory reporting; (2) Client communications; (3) Client response services (e.g., credit monitoring); and (4) Other response-related services.

Your Legal Counsel

Work with counsel knowledgeable in cybersecurity response.

They will help you with: (1) Compliance with state and federal laws and industry regulations; (2) Stakeholder and customer notifications; (3) Contractual obligations; and (4) Interactions with law enforcement.

Law Enforcement

We recommend opening a report with law enforcement in coordination with your cyber insurance carrier and legal counsel.

  • If your local law enforcement agency lacks a dedicated cybercrime unit, they can still open a report and refer you to the cybercrime unit of your local FBI field office. You can also report directly to the FBI or CISA.GOV.
  • Please be aware that law enforcement may collect computers or other devices as evidence. While this can be disruptive to daily operations, the long-term benefits far outweigh the temporary inconvenience.
  • Reporting the crime provides you with an official record that often assists insurance claims, and law enforcement may also be able to assist with recovery. For example, federal agencies maintain a database of decryption keys for ransomware attacks which could help you recover data without paying a ransom.

The Event

Human action triggered all three of these recent events. While it is easy to claim that the individuals involved should have known better, the reality is that even knowledgeable people succumb to these tricks when they are tired or distracted.

How many times have you replied to or acted on an email that you skimmed or quickly read without focusing on the content? We are all busy, and an email often feels like just another task to check off.

When you combine a false sense of security with a momentary lack of attention, it is very easy to click the wrong link, enter credentials into a fake site, or share private information.

Technology is vital for protection, but your people must also understand the risks. They should be able to identify suspect interactions and know exactly what to do when faced with a suspicious email, text, call, or web page.

After The Event

In every recent event we have handled, the business and IT leaders were unsure how to proceed. Given the urgency and stress of the moment, none of them referred to an existing Information Security Plan because they did not have an incident response checklist or strategy in place.

We tend to focus on recovery, such as getting systems back online and restoring data. While this is an urgent and tangible response, it is only one part of the equation.

Your cyber insurance carrier may need to verify your security measures, conduct a forensics analysis, or direct your recovery efforts. You likely have legal, industry, or contractual reporting requirements, and you may even need law enforcement to investigate.

Response and recovery from a cyberattack requires having the technology in place to get your systems, apps, and data back in operation as well as having resources in place to get you through the legal, regulatory, contractual, marketing, and customer relationship challenges you will face.

Help is Here

Responding to an attack requires a plan before the attack occurs. Our Security CPR® model provides the framework your business needs:

  • Communicate and Educate: Ensuring your team stays knowledgeable, aware, and prepared through appropriate policies and procedures.
  • Prevent and Protect: The right mix of security solutions to prevent cyberattacks and protect against active and successful attacks.
  • Recover and Respond: The services needed for business continuity, resilience, and a quick return to operations, along with the resources to assist with the insurance, regulatory, legal, and communication aspects of a cyber incident response.
About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-Blog-Hero-Image.png 689 1215 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-12 08:30:382026-07-27 22:01:54Cyber Attack Recovery Starts Before the Breach

Cybersecurity Fatigue: Is Your Business at Risk?

March 4, 2026/in Blog, Cybersecurity, General

Security fatigue is real. You’ve felt it, and so have we. Cyber criminals know this, and they are waiting to capitalize on it. When we let security fatigue guide our decisions and allow our guard to drop, we become much more likely to fall victim to a cyberattack.

Over the past few weeks, we have assisted multiple companies that fell victim to such attacks. These events reflect a recent surge in cyberattacks, serving as a harsh reminder that we must remain vigilant.

Common Elements

Each of these recent cases shared three common elements:

  1. An employee clicked on a malicious link and shared account information.
  2. The company opted not to deploy recommended security measures.
  3. Neither the business or IT leaders had a plan for how to respond to an emergency.

These elements demonstrate critical failures at every phase of a cybersecurity event.

Prior to The Event

Even as small businesses, we are more vulnerable to cyberattacks than we may expect. A basic suite of cybersecurity services is no longer optional, it is essential for defending and protecting against attacks.

In each of the cases we recently handled, simple and effective baseline tools were not in place. Decisions made to avoid the incremental cost of added protections left these businesses exposed.

Consequently, each company is now paying a much larger price, ranging from several days of downtime and lost productivity to potential fines and litigation.Connect with a Cloud Advisor

The Event

Human action triggered all three of these recent events. While it is easy to claim that the individuals involved should have known better, the reality is that even knowledgeable people succumb to these tricks when they are tired or distracted.

How many times have you replied to or acted on an email that you skimmed or quickly read without focusing on the content? We are all busy, and an email often feels like just another task to check off.

When you combine a false sense of security with a momentary lack of attention, it is very easy to click the wrong link, enter credentials into a fake site, or share private information.

Technology is vital for protection, but your people must also understand the risks. They should be able to identify suspect interactions and know exactly what to do when faced with a suspicious email, text, call, or web page.

After The Event

In every recent event we have handled, the business and IT leaders were unsure how to proceed. Given the urgency and stress of the moment, none of them referred to an existing Information Security Plan because they did not have an incident response checklist or strategy in place.

We tend to focus on recovery, such as getting systems back online and restoring data. While this is an urgent and tangible response, it is only one part of the equation.

Your cyber insurance carrier may need to verify your security measures, conduct a forensics analysis, or direct your recovery efforts. You likely have legal, industry, or contractual reporting requirements, and you may even need law enforcement to investigate.

Response and recovery from a cyberattack requires having the technology in place to get your systems, apps, and data back in operation as well as having resources in place to get you through the legal, regulatory, contractual, marketing, and customer relationship challenges you will face.

How We Help: Security CPRⓇ

Your security profile should match your business. The nature of your company, its size, your industry and markets, and your locations should all dictate your security requirements. Your leadership team should guide your security strategy and spending.

Our Security CPRⓇ model and services provide the framework for creating the right security profile for your business:

  • Communicate and Educate: Ensure you and your team are knowledgeable, aware, and prepared, and that you have appropriate policies and procedures in place.
  • Prevent and Protect: Implement the right mix of security solutions to stop cyberattacks and defend against active threats.
  • Recover and Respond: Build the necessary services for business continuity, resilience, and a quick return to operations, including resources to assist with the insurance, regulatory, legal, and communication aspects of a response to an incident.
About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-02-Blog-Hero-Image.png 719 1080 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-04 09:30:292026-03-04 14:15:14Cybersecurity Fatigue: Is Your Business at Risk?

6 Decisions for Productive, Secure, Affordable AI

February 17, 2026/in 3T@3 Webcast Series, AI in Google Workspace

(02/17/26) – Allowing AI to happen through individual experimentation and unstructured projects creates security risks, leads to unpredictable costs, and increases your chance of failure. If you want AI to be an effective tool for your business, you need to actively lead and manage your AI efforts.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2026-02-17 15:00:442026-02-17 17:27:166 Decisions for Productive, Secure, Affordable AI
Page 1 of 12123›»

Recent Posts

  • Secure Gemini AI in Google Workspace
  • Your Path to Full Cloud Adoption
  • How We Use AI for Data Enrichment

Featured Blog Topics

  • Artificial Intelligence / AI
  • Managed Cloud Services
  • Cybersecurity

Read

  • Blog
  • Newsletter
  • Microsoft Cloud Monday
  • Google Workspace Wednesday

Watch

  • 3T@3 Series
  • Coffee and Clouds
  • Event Recordings
  • Cumulus Global Channel

Explore

  • Library
  • Events Calendar

Phone / Fax / Email

  • 866-356-1202
  • 508-948-4070
  • info@cumulusglobal.com

Headquarters / Boston

  • Street Address

    4 Bellows Rd / 2nd Floor
    Westborough, MA 01581

  • Mailing Address

    PO Box 1129
    Westborough, MA 01581-6129

Regional Offices

  • Southeast Office

    120 W Trinity Pl
    Decatur, GA 30030

Copyright © 2026 - Cumulus Global | Privacy Policy | Terms of Service | Disclaimer | Website by Cold Spring
Scroll to top Scroll to top Scroll to top