• Link to Instagram
  • Link to LinkedIn
  • Link to Facebook
  • Support
  • Resource Center
  • News & Events
  • Blog
  • Pay Online
Cumulus Global
  • What We Do
    • Managed Cloud Services Provided by Cumulus Global
    • Cloud Computing Security, Privacy, Compliance, & Continuity
    • Collaboration, Productivity, & Transformation
    • Managed Infrastructure & Platforms
  • How We Do It
    • Understand & Assess
    • Cloud Computing Strategy & Planning
    • Cloud Migration & Deployment
    • Cloud Managed Services
    • Service & Support for Cloud and IT Solutions
    • Global Strategic Services
    • Guide, Educate, & Train
  • What We Offer
    • Managed Cloud Services
    • IT Admin, Service, and Support
    • Security CPR® Managed Security
    • Google Cloud Workspace / Education / Chrome / Voice
    • Google Cloud Platform Computing Services
    • Microsoft 365 and Office 365 Managed Services
    • Microsoft Azure
  • Who We Are
    • Our Mission
    • Our Team and Opportunities
    • Our Cloud Computing Partners
    • Our Reviews and Testimonials
    • Our Community
    • Our Sustainability
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Archive for category: Cybersecurity

Secure Gemini AI in Google Workspace

July 31, 2026/in AI in Google Workspace, Blog, Cybersecurity, General

Three Ways to Protect Company Files When Your Team Uses Gemini AI

Written by Allen Falcon, Co-Founder & CEO, Cumulus Global

Artificial intelligence offers incredible potential for productivity. AI also creates new security challenges.

Follow these three steps to protect and secure information when using Gemini AI in Google Workspace.

Key Takeaways

    • ✓Gemini AI sees what your Workspace settings allow
    • ✓Cleaning up shared files prevents sensitive data leaks
    • ✓Automated onboarding and offboarding keeps permissions accurate
    • ✓Decommissioning inactive accounts closes security gaps and cuts costs

Leaking sensitive, proprietary, or confidential data via AI is easy. An employee may put confidential financial data into a public AI tool, a private AI model, like Gemini AI, might read files that were overshared within your organization, or you may accidentally externally share sensitive information embedded in an internal model.

Gemini AI relies on your existing Google Workspace permissions. If a document is shared too broadly, the AI engine will make that information visible to unauthorized users.

Fortunately, you can secure your sensitive files and establish clear guardrails with a few strategic updates.

Step 1 of 3

Audit Your File Sharing Settings

Unintended file sharing happens quietly in nearly all organizations. Over time, link sharing and external permissions create hidden security risks.

Pay close attention to these common sharing pitfalls that can inadvertently surface confidential data to AI tools:

    • Exposure via Links: “Anyone with the link” settings can expose internal documents to external search engines and public AI crawlers.
    • Sharing to your Domain: Giving permission to your entire domain gives everybody, and every attached service, access to the information.
    • Lingering Access: External sharing permissions granted to contractors often remain active long after their work is complete.
    • Group Over-Sharing: Public Google Groups may inadvertently grant broad access to internal shared drives.

Use an automated tool to scan file, folder, and shared drive permissions against defined policies and compliance guidelines. Put systems in place to monitor and mitigate risks in real-time.

Step 2 of 3

Streamline User Onboarding and Offboarding

Manual IT administration is prone to human error and inefficiency. When employees join or leave, updating access controls requires careful detail.

Establishing automated lifecycle policies helps maintain strict access boundaries at every stage of employment.

    • Automate Onboarding: Add new hires to the correct Google Groups, shared folders, and chat spaces using policy-based automation.
    • Secure Transfers: Transfer file ownership directly to managers or secure shared drives as part of your offboarding workflow.
    • Cleanup Calendars: Remove former staff from internal meetings without disrupting active client appointments.
    • Manage Contacts: Ensure mobile address books remain accurate by clearing out former employees and transferring key business contacts.

Automate these steps to ensure your access controls are up-to-date and Gemini AI only displays sensitive files to authorized team members.

Step 3 of 3

Manage Inactive Accounts and Licenses

Inactive accounts waste budget and create unnecessary entry points for bad actors. Staff members who left months ago should not remain in your user directory.

Put automated management rules in place to ensure that former accounts are properly monitored and decommissioned:

    • Suspension Rules: Establish automated account suspension policies to keep your user directory secure and up-to-date.
    • Inactivity Alerts: Utilize alerts to track and address accounts with no login activity over a 30-day period.
    • License Management: Minimize software expenses and satisfy legal data retention requirements by transitioning offboarded employees to archive licenses.
    • Data Preservation: Safely eliminate paid licenses by transferring essential data into alternate cloud storage options.

Manage user lifecycles to reduce your monthly costs while protecting your company data.

Take the Next Step for Workspace Security

Securing your workspace does not require a complete operational overhaul. Targeted, automated changes create a foundation for strong data governance and reduce operational overhead and risks.

As demonstrated in our recent 3T@3 Series session, automated solutions like Patronum give you the capability to actively monitor and manage permissions and access, streamline your onboarding and offboarding processes, and secure your Google Workspace environment.

Contact us or schedule time to connect with a Cloud Advisor at Cumulus Global to arrange your workspace security review and to explore your options.

Ready to Take the Next Step?

Whether you’re beginning your cloud migration or looking to improve an existing environment, our Cloud Advisors can help.

Schedule a conversation

Allen Falcon

Co-Founder & CEO, Cumulus Global

Allen Falcon co-founded Cumulus Global in 2006 to help small businesses implement enterprise-grade cloud, security, and compliance solutions. Under his leadership, Cumulus Global has grown into a managed cloud services provider supporting more than 1,000 organizations throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-07-31 11:31:542026-07-31 11:39:33Secure Gemini AI in Google Workspace

What to Do When It Happens

March 17, 2026/in 3T@3 Webcast Series, Cybersecurity

(03/17/26) – How you initially respond to a cybersecurity incident will affect your ability to recover, your cyber insurance coverage, your customer relationships, your legal and financial liability, and possibly your survival.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2026-03-17 15:00:382026-03-18 13:40:22What to Do When It Happens

Cyber Attack Recovery Starts Before the Breach

March 12, 2026/in Blog, Cybersecurity, General

No prevention is perfect. No protection is perfect. You are already a target for cyberattacks, and eventually, one will likely succeed. When that happens, you need to know what comes next.

Event or Incident? Know the Difference

Understanding the distinction between a cybersecurity event and an incident is critical because they carry different operational and legal implications.

A Cybersecurity Event is an observable change in the status of a network, system, application, or data. You should investigate these events to determine if they qualify as an incident. Not all events become incidents.

A Cybersecurity Incident is a confirmed event, or series of events, that jeopardizes the confidentiality, integrity, or availability of data or systems. It causes harm or disruption and requires an immediate, formal response. Incidents trigger legal, regulatory, and contractual obligations, such as reporting, that must be managed.

Connect with a Cloud AdvisorYour Next Steps

With this distinction in mind, follow these steps to manage the situation effectively.

1 Do NOT Panic

Stay calm.

Quick, smart action serves you better than panic.

2 Disconnect and Isolate

Notify your IT team and service providers immediately.

Enlist their assistance to secure every impacted or potentially impacted system:

  • Log out users on all devices.
  • Change passwords or disable accounts.
  • Disconnect systems from your network and the internet.
  • Document all actions and changes with a timestamp.

3 Document the Event

Take a few moments to document everything you know.

Create a clear timeline of the situation:

  • What did you notice and when?
  • What happened and when?
  • What actions did you take (e.g., links clicked, reports made to IT)?

4 Do NOT Start Fixing Things

Your cyber insurance carrier, legal counsel, or law enforcement may need to preserve your systems for forensics.

Restoring systems or recovering data prematurely could destroy evidence and impede criminal investigations. Furthermore, altering systems might provide a reason for your insurance carrier to deny or limit your claim.

5 Make These Calls

Connect with resources that can help you navigate your next steps.

Your Cyber Insurance Agent and/or Carrier

Advise your insurer that you are responding to a cybersecurity event that may be an incident. They will want to know the nature of the event and any actions you have taken. If they determine the event is an incident, they will initiate a response.

Your insurer may: (1) Require you to report the event to law enforcement (FBI or CISA.GOV); (2) Require you to hold systems for forensic analysis; (3) Hire a specialized firm to manage recovery efforts; and/or (4) Direct you to complete other specific actions.

Your insurer may also ask for validation that you follow your security policies and procedures. Depending on your coverage, they may also provide assistance with: (1) Required legal and/or regulatory reporting; (2) Client communications; (3) Client response services (e.g., credit monitoring); and (4) Other response-related services.

Your Legal Counsel

Work with counsel knowledgeable in cybersecurity response.

They will help you with: (1) Compliance with state and federal laws and industry regulations; (2) Stakeholder and customer notifications; (3) Contractual obligations; and (4) Interactions with law enforcement.

Law Enforcement

We recommend opening a report with law enforcement in coordination with your cyber insurance carrier and legal counsel.

  • If your local law enforcement agency lacks a dedicated cybercrime unit, they can still open a report and refer you to the cybercrime unit of your local FBI field office. You can also report directly to the FBI or CISA.GOV.
  • Please be aware that law enforcement may collect computers or other devices as evidence. While this can be disruptive to daily operations, the long-term benefits far outweigh the temporary inconvenience.
  • Reporting the crime provides you with an official record that often assists insurance claims, and law enforcement may also be able to assist with recovery. For example, federal agencies maintain a database of decryption keys for ransomware attacks which could help you recover data without paying a ransom.

The Event

Human action triggered all three of these recent events. While it is easy to claim that the individuals involved should have known better, the reality is that even knowledgeable people succumb to these tricks when they are tired or distracted.

How many times have you replied to or acted on an email that you skimmed or quickly read without focusing on the content? We are all busy, and an email often feels like just another task to check off.

When you combine a false sense of security with a momentary lack of attention, it is very easy to click the wrong link, enter credentials into a fake site, or share private information.

Technology is vital for protection, but your people must also understand the risks. They should be able to identify suspect interactions and know exactly what to do when faced with a suspicious email, text, call, or web page.

After The Event

In every recent event we have handled, the business and IT leaders were unsure how to proceed. Given the urgency and stress of the moment, none of them referred to an existing Information Security Plan because they did not have an incident response checklist or strategy in place.

We tend to focus on recovery, such as getting systems back online and restoring data. While this is an urgent and tangible response, it is only one part of the equation.

Your cyber insurance carrier may need to verify your security measures, conduct a forensics analysis, or direct your recovery efforts. You likely have legal, industry, or contractual reporting requirements, and you may even need law enforcement to investigate.

Response and recovery from a cyberattack requires having the technology in place to get your systems, apps, and data back in operation as well as having resources in place to get you through the legal, regulatory, contractual, marketing, and customer relationship challenges you will face.

Help is Here

Responding to an attack requires a plan before the attack occurs. Our Security CPR® model provides the framework your business needs:

  • Communicate and Educate: Ensuring your team stays knowledgeable, aware, and prepared through appropriate policies and procedures.
  • Prevent and Protect: The right mix of security solutions to prevent cyberattacks and protect against active and successful attacks.
  • Recover and Respond: The services needed for business continuity, resilience, and a quick return to operations, along with the resources to assist with the insurance, regulatory, legal, and communication aspects of a cyber incident response.
About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-Blog-Hero-Image.png 689 1215 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-12 08:30:382026-07-27 22:01:54Cyber Attack Recovery Starts Before the Breach

Cybersecurity Fatigue: Is Your Business at Risk?

March 4, 2026/in Blog, Cybersecurity, General

Security fatigue is real. You’ve felt it, and so have we. Cyber criminals know this, and they are waiting to capitalize on it. When we let security fatigue guide our decisions and allow our guard to drop, we become much more likely to fall victim to a cyberattack.

Over the past few weeks, we have assisted multiple companies that fell victim to such attacks. These events reflect a recent surge in cyberattacks, serving as a harsh reminder that we must remain vigilant.

Common Elements

Each of these recent cases shared three common elements:

  1. An employee clicked on a malicious link and shared account information.
  2. The company opted not to deploy recommended security measures.
  3. Neither the business or IT leaders had a plan for how to respond to an emergency.

These elements demonstrate critical failures at every phase of a cybersecurity event.

Prior to The Event

Even as small businesses, we are more vulnerable to cyberattacks than we may expect. A basic suite of cybersecurity services is no longer optional, it is essential for defending and protecting against attacks.

In each of the cases we recently handled, simple and effective baseline tools were not in place. Decisions made to avoid the incremental cost of added protections left these businesses exposed.

Consequently, each company is now paying a much larger price, ranging from several days of downtime and lost productivity to potential fines and litigation.Connect with a Cloud Advisor

The Event

Human action triggered all three of these recent events. While it is easy to claim that the individuals involved should have known better, the reality is that even knowledgeable people succumb to these tricks when they are tired or distracted.

How many times have you replied to or acted on an email that you skimmed or quickly read without focusing on the content? We are all busy, and an email often feels like just another task to check off.

When you combine a false sense of security with a momentary lack of attention, it is very easy to click the wrong link, enter credentials into a fake site, or share private information.

Technology is vital for protection, but your people must also understand the risks. They should be able to identify suspect interactions and know exactly what to do when faced with a suspicious email, text, call, or web page.

After The Event

In every recent event we have handled, the business and IT leaders were unsure how to proceed. Given the urgency and stress of the moment, none of them referred to an existing Information Security Plan because they did not have an incident response checklist or strategy in place.

We tend to focus on recovery, such as getting systems back online and restoring data. While this is an urgent and tangible response, it is only one part of the equation.

Your cyber insurance carrier may need to verify your security measures, conduct a forensics analysis, or direct your recovery efforts. You likely have legal, industry, or contractual reporting requirements, and you may even need law enforcement to investigate.

Response and recovery from a cyberattack requires having the technology in place to get your systems, apps, and data back in operation as well as having resources in place to get you through the legal, regulatory, contractual, marketing, and customer relationship challenges you will face.

How We Help: Security CPRⓇ

Your security profile should match your business. The nature of your company, its size, your industry and markets, and your locations should all dictate your security requirements. Your leadership team should guide your security strategy and spending.

Our Security CPRⓇ model and services provide the framework for creating the right security profile for your business:

  • Communicate and Educate: Ensure you and your team are knowledgeable, aware, and prepared, and that you have appropriate policies and procedures in place.
  • Prevent and Protect: Implement the right mix of security solutions to stop cyberattacks and defend against active threats.
  • Recover and Respond: Build the necessary services for business continuity, resilience, and a quick return to operations, including resources to assist with the insurance, regulatory, legal, and communication aspects of a response to an incident.
About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-02-Blog-Hero-Image.png 719 1080 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-04 09:30:292026-03-04 14:15:14Cybersecurity Fatigue: Is Your Business at Risk?

Cumulus Global Awarded Cybersecurity Trademark: Security CPR®

October 27, 2025/in Cybersecurity, General, News

The Security CPR® Model and Services Focus on Cybersecurity Needs of Small and Midsize Businesses

Westborough, MA, October 20, 2025 – Cumulus Global proudly shares that the our Security CPR® model and services received a Trademark (Registration Number 7,966,747) from the United States Patent and Trademark Office. The trademark recognizes our unique expertise and leadership. Security CPR® includes our cybersecurity risk management technical consulting; training and education; and services covering threat analysis, prevention and deterrence, remediation, and governance.

“We are excited and proud that our Security CPR® model and services received this recognition,” stated Cumulus Global CEO Allen Falcon. “Security CPR® defines and delivers cybersecurity solutions that small businesses can rely upon, understand, and afford.”

Most small businesses struggle to meet current cybersecurity demands. Without expertise or the resources of larger organizations, small businesses still need to follow state and federal laws, industry regulations and standards, and contractual obligations. Security CPR® encompasses three core components of an effective cybersecurity program.

  • Communication and Education
  • Prevention and Protection
  • Recovery and Response

“As a model and a set of services, Security CPR® adapts to your specific business needs,” notes Falcon. “We tune your cybersecurity services to match your requirements, risks, business operations, and budget.”

As part of our commitment to helping small businesses protect themselves from cybersecurity threats, we recently launched our Cybersecurity Landing Zone. The zone collates blog posts, web events, eBooks, and other resources to help small business owners navigate the ever-changing cybersecurity landscape.

To assess, plan, and improve your cybersecurity, book a free, no obligation meeting with one of our Cloud Advisors.

About Cumulus Global

Nationally recognized as a leader, Cumulus Global delivers productive, secure, and affordable managed cloud services to small and midsize businesses, governments, and K-12 schools. Translating business objectives into technology needs and priorities, we design, deploy, manage, and support services that help our clients thrive and grow.

https://www.cumulusglobal.com/wp-content/uploads/2024/05/Security-CPR-Model.png 1080 1080 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-10-27 20:09:202026-03-03 21:58:07Cumulus Global Awarded Cybersecurity Trademark: Security CPR®

{URGENT}: Windows 10 Support ENDS on Oct. 14th. Extended Security Updates Available

October 10, 2025/in Cybersecurity, General

Windows 11

ACT NOW!  Support for Windows 10 officially ends on October 14, 2025. After this date, Microsoft will no longer provide software updates and technical assistance. If you are not upgrading to Windows 11, you must purchase Windows 10 Extended Security Updates to continue receiving critical and important security updates.

Without these extended security updates, continuing to use Windows 10 dramatically increases your exposure to significant risks. Your systems become prime targets for cyberattacks, ransomware, and data breaches. You risk costly downtime, loss of sensitive information, and severe compliance issues. 

Proactive planning and action are not just recommended, they are critical for your business continuity and security.

Know Your Windows 10 Options

We agree with Microsoft’s recommendation to upgrade all eligible systems to Windows 11. We also understand you may have budget constraints or compatibility issues with older software.

You can check if your PCs will run Windows 11 using Microsoft’s PC Health Check app. If your PC will not run Windows 11, you have options other than buying new devices.

Windows 10 Extended Security Updates (ESU): 

Microsoft has release pricing for ESU licenses.  The license are available as a one-time purchase for each year. You do not need to commit to multiple years up-front, you can purchase the licenses annually if needed.  The pricing is as follows:

  • Year 1 – from October 2025 to October 2026 – $61 each
  • Year 2 – from October 2026 to October 2027 – $122 each
  • Year 3 – from October 2027 to October 2028 – $244 each

Important Notes:

  • Not all systems are eligible to install the updates. To be eligible to install updates from the ESU program, devices must be running Windows 10, version 22H2. For more information on prerequisites and enabling ESU in commercial environments, see Enable Extended Security Updates (ESU).
  • ESU Program updates do NOT include: New features; Customer-requested non-security updates; Design change requests; or General support.
  • The Windows 10 ESU only includes support for the license activation, installation, and possible regressions of the ESU itself for organizations with a support plan in place.

Keep in mind, the Windows 10 Extended Security Update program serves as a temporary bridge and does not address underlying hardware or software compatibility issues related to upgrading to Windows 11.

Virtual Desktop Services: 
  • Using virtual desktop services, such as Azure Virtual Desktop, allow you to use your existing PCs to access a robust and secure Windows 11 environment. Virtual desktops work well for hybrid team members and to mitigate the cost of upgrading multiple devices.
  • Connect with one of our Cloud Advisors to explore this option.

Windows 11 Upgrade HelpPlan for Your Windows 11 Transition

Regardless of the strategy you choose, proactive planning is crucial for a smooth and secure transition. Follow these steps to ensure you’re ready:

Assess Your Current IT Environment
  • Use Microsoft’s PC Health Check app to determine which devices can run Windows 11, which can be upgraded, and which require replacement. If you use Windows 10 in embedded systems, check with your vendor.
  • Confirm which of your business-critical applications and tools are compatible with Windows 11. Identify necessary software upgrades or migrations.
Prepare Your Budget
  • Accurately map the cost of upgrading and/or replacing devices. Keep in mind that older systems, even if upgraded now, may soon require replacement.
  • Identify any software upgrade costs.
  • Keep in mind any fees for tech support or professional services. You may need or want help transferring applications and data to new devices or setting up virtual desktops.
Develop Your Transition Plan & Data Strategy
  • Plan your timing and procedures for upgrades, purchases, and migrations. Focus on preventing data loss during migration and consider staging your rollout in phases to minimize disruption.
  • Crucially, ensure all critical data is securely backed up before upgrading or migrating systems. 
  • Remember to allow time to test critical software on Windows 11 before upgrading.
Train Your Team
  • Provide resources and help your team become familiar with the Windows 11 interface and new features.
  • If you are upgrading your business software for compatibility, you may want to provide additional training on new functionalities and capabilities.
  • Stay Informed: Monitor Microsoft’s official updates and announcements. Keep current with regarding Windows 10 end of life and Windows 11 developments.

Cumulus Global Will Help

Plan and Act Now.  As with any major upgrade, we expect demand for PCs, laptops, and technical services will increase as the deadline nears. Waiting may result in delays and missed deadlines. Losing Windows 10 support can result in costly business disruptions.

For assistance, schedule a brief, free call with one of our Cloud Advisors to discuss your assessment, plan, and upgrade needs, priorities, and budget.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2024/12/Win11-Background.jpg 533 800 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-10-10 20:09:202025-12-15 22:13:18{URGENT}: Windows 10 Support ENDS on Oct. 14th. Extended Security Updates Available

5 Cyber Threat Trends You Should Know

August 6, 2025/in AI in Google Workspace, Cybersecurity, General

5 Security Cyber Threats You Should Know

Earlier this week, we shared CrowdStrike’s 2025 Global Threat Report which identified five (5) cyber threat trends that you should know. While cyber-fatigue is real, understanding the threat landscape helps you assess your risks and security posture and make informed decisions on how to prioritize security-related spending and investment.

5 Cyber Threat Trends

Here are the 5 cyber threat trends you should know.

1 China on the Rise

Cyber attacks originating in China – both nation-state and organized crime – jumped 130% over the prior 12 months. At the enterprise-level, China-nexus attackers focus on telecommunication systems. For most businesses, the increase in attacks on unmanaged devices should be of concern. 

Unmanaged devices lack detection and response capabilities that allow attackers to lurk, monitor, and capture credentials for greater access to your systems, applications, and data.

2 Hands-On-Keyboard Attacks are Making a Comeback

The best way for cyber attackers to avoid modern malware protection, such next-gen endpoint protection and managed detection and response (MDR) services, is for the attacker or a surrogate to use the keyboard. These manual, interactive attacks are up 27% over the prior year.

We may imagine hands–on-keyboard attacks as movie-like scenarios of corporate spies posing as custodians sneaking onto computers while avoiding the security guards making their rounds. In reality, the hands-on-attack may be your employee responding to somebody they think is IT support or a vendor helping them solve a problem.

3 Rapid Ransomware Reach

The speed at which cyber attackers can launch ransomware attacks after an initial breach is accelerating. From breach to spread, attacks are up to 32% faster than previously known.

This speed gives cybersecurity systems less time to identify behaviors and patterns that identify the cyber attack, weakening the effectiveness of the protections.

4 AI for Evil

With the help of AI, certain types of cyber attacks have jumped 220% over the prior year. Cyber attackers are using generative artificial intelligence (Gen AI) technologies to power more-effective attacks.  

Using GenAI, attackers create more realistic fakes – emails, documents, phone calls, and videos – to trigger responses and reactions that enable and facilitate access and breaches.

At the same time, cyber attackers are using security vulnerabilities in the platforms and tools businesses use to build AI agents, just as they use vulnerabilities in web, application, and office productivity platforms.

5 Cloud Attacks Gain Altitude

Cloud intrusions – successful cyber attacks on cloud systems and services – jumped 136% during the first half of 2025 compared to all of 2024. These attacks vector through compromised identities, improper security configurations, API vulnerabilities, lax security and permissions governance.

Steps You Can Take

To ensure your security footprint protects your business appropriately:

  • Conduct IT and Security Assessments that benchmark your security posture.
  • Prioritize your risks based on the nature and size of your business, industry standards and expectations, and regulatory requirements.
  • Level our Security CPR® model and managed services to plan, prioritize, and implement appropriate security and business resilience solutions that:
    • Address your prioritized risks as your budget allows
    • Protect from the most common and the most damaging/costly types of attacks.

We Will Help

Plan Now; Act Soon. Our Cloud Advisors are here to assist. We will:

  • Review your current systems and services and prioritize your risks. 
  • Help you prioritize, plan, and budget for security changes and improvements that may be necessary or preferred
  • Deploy and co-manage your security solutions to keep you protected.

Schedule time with one of our Cloud Advisors now to begin your security review and improvements.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2025/08/5-Security-Cyber-Threat-Trends-You-Should-Know.ai_.jpg 2048 2048 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-08-06 20:09:202025-12-15 22:18:335 Cyber Threat Trends You Should Know

2025 CrowdStrike Global Threat Report

August 4, 2025/in Cybersecurity, White Paper

Whitepaper | Source: CrowdStrike — This report is a deep dive into cyber threat data an analyses for 2024. The report identifies emerging risks and overall trends to consider when evaluating and planning your cybersecurity posture, systems and services, and budget.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-08-04 13:26:482025-10-09 13:59:032025 CrowdStrike Global Threat Report

Cybersecurity for Sole Practitioners, Solopreneurs, and VSBs

June 27, 2025/in Coffee & Clouds Minicasts, Cybersecurity

If you are a sole practitioner, a solopreneur working to build a business, or leading a very small business (VSB) of less than 20 people, you face unique IT challenges.  You want and need your IT and productivity systems to be secure. At the same time you are “too small” for most IT service providers.

You can secure and protect your business, affordably, with the right tools and service partner.

In this Coffee & Clouds online event, Cumulus Global CEO Allen Falcon shares a strategy for securing your business without breaking your budget. Using our Security CPR® managed security model and services, Allen shares our approach for protecting against the most common and most damaging cybersecurity risks. He will also cover services you may need for industry and regulatory compliance and those you may want for better cyber insurance coverage.

Invest 15 minutes to understand the approach and how to evaluate your security needs and options.  Join us live or view the recording on-demand, and the Dunkin’ or Starbucks is on us.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-06-27 02:30:172025-10-09 14:20:51Cybersecurity for Sole Practitioners, Solopreneurs, and VSBs

Cybersecurity Essentials for Smaller Businesses

June 12, 2025/in Cybersecurity, eBook

eBook | Source: Cumulus Global — Cybercriminals target small businesses because we tend to have fewer resources and less robust cybersecurity practices. This eBook provides a strategy, model, & roadmap of affordable, effective cybersecurity essentials for sole practitioners, solopreneurs, & very small businesses.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-06-12 16:37:462025-10-09 13:59:03Cybersecurity Essentials for Smaller Businesses
Page 1 of 8123›»

Recent Posts

  • Secure Gemini AI in Google Workspace
  • Your Path to Full Cloud Adoption
  • How We Use AI for Data Enrichment

Featured Blog Topics

  • Artificial Intelligence / AI
  • Managed Cloud Services
  • Cybersecurity

Read

  • Blog
  • Newsletter
  • Microsoft Cloud Monday
  • Google Workspace Wednesday

Watch

  • 3T@3 Series
  • Coffee and Clouds
  • Event Recordings
  • Cumulus Global Channel

Explore

  • Library
  • Events Calendar

Phone / Fax / Email

  • 866-356-1202
  • 508-948-4070
  • info@cumulusglobal.com

Headquarters / Boston

  • Street Address

    4 Bellows Rd / 2nd Floor
    Westborough, MA 01581

  • Mailing Address

    PO Box 1129
    Westborough, MA 01581-6129

Regional Offices

  • Southeast Office

    120 W Trinity Pl
    Decatur, GA 30030

Copyright © 2026 - Cumulus Global | Privacy Policy | Terms of Service | Disclaimer | Website by Cold Spring
Scroll to top Scroll to top Scroll to top