• Link to Instagram
  • Link to LinkedIn
  • Link to Facebook
  • Support
  • Resource Center
  • News & Events
  • Blog
  • Pay Online
Cumulus Global
  • What We Do
    • Managed Cloud Services Provided by Cumulus Global
    • Cloud Computing Security, Privacy, Compliance, & Continuity
    • Collaboration, Productivity, & Transformation
    • Managed Infrastructure & Platforms
  • How We Do It
    • Understand & Assess
    • Cloud Computing Strategy & Planning
    • Cloud Migration & Deployment
    • Cloud Managed Services
    • Service & Support for Cloud and IT Solutions
    • Global Strategic Services
    • Guide, Educate, & Train
  • What We Offer
    • Managed Cloud Services
    • IT Admin, Service, and Support
    • Security CPR® Managed Security
    • Google Cloud Workspace / Education / Chrome / Voice
    • Google Cloud Platform Computing Services
    • Microsoft 365 and Office 365 Managed Services
    • Microsoft Azure
  • Who We Are
    • Our Mission
    • Our Team and Opportunities
    • Our Cloud Computing Partners
    • Our Reviews and Testimonials
    • Our Community
    • Our Sustainability
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Tag Archive for: Cybersecurity

Posts

Secure Gemini AI in Google Workspace

July 31, 2026/in AI in Google Workspace, Blog, Cybersecurity, General

Three Ways to Protect Company Files When Your Team Uses Gemini AI

Written by Allen Falcon, Co-Founder & CEO, Cumulus Global

Artificial intelligence offers incredible potential for productivity. AI also creates new security challenges.

Follow these three steps to protect and secure information when using Gemini AI in Google Workspace.

Key Takeaways

    • ✓Gemini AI sees what your Workspace settings allow
    • ✓Cleaning up shared files prevents sensitive data leaks
    • ✓Automated onboarding and offboarding keeps permissions accurate
    • ✓Decommissioning inactive accounts closes security gaps and cuts costs

Leaking sensitive, proprietary, or confidential data via AI is easy. An employee may put confidential financial data into a public AI tool, a private AI model, like Gemini AI, might read files that were overshared within your organization, or you may accidentally externally share sensitive information embedded in an internal model.

Gemini AI relies on your existing Google Workspace permissions. If a document is shared too broadly, the AI engine will make that information visible to unauthorized users.

Fortunately, you can secure your sensitive files and establish clear guardrails with a few strategic updates.

Step 1 of 3

Audit Your File Sharing Settings

Unintended file sharing happens quietly in nearly all organizations. Over time, link sharing and external permissions create hidden security risks.

Pay close attention to these common sharing pitfalls that can inadvertently surface confidential data to AI tools:

    • Exposure via Links: “Anyone with the link” settings can expose internal documents to external search engines and public AI crawlers.
    • Sharing to your Domain: Giving permission to your entire domain gives everybody, and every attached service, access to the information.
    • Lingering Access: External sharing permissions granted to contractors often remain active long after their work is complete.
    • Group Over-Sharing: Public Google Groups may inadvertently grant broad access to internal shared drives.

Use an automated tool to scan file, folder, and shared drive permissions against defined policies and compliance guidelines. Put systems in place to monitor and mitigate risks in real-time.

Step 2 of 3

Streamline User Onboarding and Offboarding

Manual IT administration is prone to human error and inefficiency. When employees join or leave, updating access controls requires careful detail.

Establishing automated lifecycle policies helps maintain strict access boundaries at every stage of employment.

    • Automate Onboarding: Add new hires to the correct Google Groups, shared folders, and chat spaces using policy-based automation.
    • Secure Transfers: Transfer file ownership directly to managers or secure shared drives as part of your offboarding workflow.
    • Cleanup Calendars: Remove former staff from internal meetings without disrupting active client appointments.
    • Manage Contacts: Ensure mobile address books remain accurate by clearing out former employees and transferring key business contacts.

Automate these steps to ensure your access controls are up-to-date and Gemini AI only displays sensitive files to authorized team members.

Step 3 of 3

Manage Inactive Accounts and Licenses

Inactive accounts waste budget and create unnecessary entry points for bad actors. Staff members who left months ago should not remain in your user directory.

Put automated management rules in place to ensure that former accounts are properly monitored and decommissioned:

    • Suspension Rules: Establish automated account suspension policies to keep your user directory secure and up-to-date.
    • Inactivity Alerts: Utilize alerts to track and address accounts with no login activity over a 30-day period.
    • License Management: Minimize software expenses and satisfy legal data retention requirements by transitioning offboarded employees to archive licenses.
    • Data Preservation: Safely eliminate paid licenses by transferring essential data into alternate cloud storage options.

Manage user lifecycles to reduce your monthly costs while protecting your company data.

Take the Next Step for Workspace Security

Securing your workspace does not require a complete operational overhaul. Targeted, automated changes create a foundation for strong data governance and reduce operational overhead and risks.

As demonstrated in our recent 3T@3 Series session, automated solutions like Patronum give you the capability to actively monitor and manage permissions and access, streamline your onboarding and offboarding processes, and secure your Google Workspace environment.

Contact us or schedule time to connect with a Cloud Advisor at Cumulus Global to arrange your workspace security review and to explore your options.

Ready to Take the Next Step?

Whether you’re beginning your cloud migration or looking to improve an existing environment, our Cloud Advisors can help.

Schedule a conversation

Allen Falcon

Co-Founder & CEO, Cumulus Global

Allen Falcon co-founded Cumulus Global in 2006 to help small businesses implement enterprise-grade cloud, security, and compliance solutions. Under his leadership, Cumulus Global has grown into a managed cloud services provider supporting more than 1,000 organizations throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-07-31 11:31:542026-07-31 11:39:33Secure Gemini AI in Google Workspace

Cyber Attack Recovery Starts Before the Breach

March 12, 2026/in Blog, Cybersecurity, General

No prevention is perfect. No protection is perfect. You are already a target for cyberattacks, and eventually, one will likely succeed. When that happens, you need to know what comes next.

Event or Incident? Know the Difference

Understanding the distinction between a cybersecurity event and an incident is critical because they carry different operational and legal implications.

A Cybersecurity Event is an observable change in the status of a network, system, application, or data. You should investigate these events to determine if they qualify as an incident. Not all events become incidents.

A Cybersecurity Incident is a confirmed event, or series of events, that jeopardizes the confidentiality, integrity, or availability of data or systems. It causes harm or disruption and requires an immediate, formal response. Incidents trigger legal, regulatory, and contractual obligations, such as reporting, that must be managed.

Connect with a Cloud AdvisorYour Next Steps

With this distinction in mind, follow these steps to manage the situation effectively.

1 Do NOT Panic

Stay calm.

Quick, smart action serves you better than panic.

2 Disconnect and Isolate

Notify your IT team and service providers immediately.

Enlist their assistance to secure every impacted or potentially impacted system:

  • Log out users on all devices.
  • Change passwords or disable accounts.
  • Disconnect systems from your network and the internet.
  • Document all actions and changes with a timestamp.

3 Document the Event

Take a few moments to document everything you know.

Create a clear timeline of the situation:

  • What did you notice and when?
  • What happened and when?
  • What actions did you take (e.g., links clicked, reports made to IT)?

4 Do NOT Start Fixing Things

Your cyber insurance carrier, legal counsel, or law enforcement may need to preserve your systems for forensics.

Restoring systems or recovering data prematurely could destroy evidence and impede criminal investigations. Furthermore, altering systems might provide a reason for your insurance carrier to deny or limit your claim.

5 Make These Calls

Connect with resources that can help you navigate your next steps.

Your Cyber Insurance Agent and/or Carrier

Advise your insurer that you are responding to a cybersecurity event that may be an incident. They will want to know the nature of the event and any actions you have taken. If they determine the event is an incident, they will initiate a response.

Your insurer may: (1) Require you to report the event to law enforcement (FBI or CISA.GOV); (2) Require you to hold systems for forensic analysis; (3) Hire a specialized firm to manage recovery efforts; and/or (4) Direct you to complete other specific actions.

Your insurer may also ask for validation that you follow your security policies and procedures. Depending on your coverage, they may also provide assistance with: (1) Required legal and/or regulatory reporting; (2) Client communications; (3) Client response services (e.g., credit monitoring); and (4) Other response-related services.

Your Legal Counsel

Work with counsel knowledgeable in cybersecurity response.

They will help you with: (1) Compliance with state and federal laws and industry regulations; (2) Stakeholder and customer notifications; (3) Contractual obligations; and (4) Interactions with law enforcement.

Law Enforcement

We recommend opening a report with law enforcement in coordination with your cyber insurance carrier and legal counsel.

  • If your local law enforcement agency lacks a dedicated cybercrime unit, they can still open a report and refer you to the cybercrime unit of your local FBI field office. You can also report directly to the FBI or CISA.GOV.
  • Please be aware that law enforcement may collect computers or other devices as evidence. While this can be disruptive to daily operations, the long-term benefits far outweigh the temporary inconvenience.
  • Reporting the crime provides you with an official record that often assists insurance claims, and law enforcement may also be able to assist with recovery. For example, federal agencies maintain a database of decryption keys for ransomware attacks which could help you recover data without paying a ransom.

The Event

Human action triggered all three of these recent events. While it is easy to claim that the individuals involved should have known better, the reality is that even knowledgeable people succumb to these tricks when they are tired or distracted.

How many times have you replied to or acted on an email that you skimmed or quickly read without focusing on the content? We are all busy, and an email often feels like just another task to check off.

When you combine a false sense of security with a momentary lack of attention, it is very easy to click the wrong link, enter credentials into a fake site, or share private information.

Technology is vital for protection, but your people must also understand the risks. They should be able to identify suspect interactions and know exactly what to do when faced with a suspicious email, text, call, or web page.

After The Event

In every recent event we have handled, the business and IT leaders were unsure how to proceed. Given the urgency and stress of the moment, none of them referred to an existing Information Security Plan because they did not have an incident response checklist or strategy in place.

We tend to focus on recovery, such as getting systems back online and restoring data. While this is an urgent and tangible response, it is only one part of the equation.

Your cyber insurance carrier may need to verify your security measures, conduct a forensics analysis, or direct your recovery efforts. You likely have legal, industry, or contractual reporting requirements, and you may even need law enforcement to investigate.

Response and recovery from a cyberattack requires having the technology in place to get your systems, apps, and data back in operation as well as having resources in place to get you through the legal, regulatory, contractual, marketing, and customer relationship challenges you will face.

Help is Here

Responding to an attack requires a plan before the attack occurs. Our Security CPR® model provides the framework your business needs:

  • Communicate and Educate: Ensuring your team stays knowledgeable, aware, and prepared through appropriate policies and procedures.
  • Prevent and Protect: The right mix of security solutions to prevent cyberattacks and protect against active and successful attacks.
  • Recover and Respond: The services needed for business continuity, resilience, and a quick return to operations, along with the resources to assist with the insurance, regulatory, legal, and communication aspects of a cyber incident response.
About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-Blog-Hero-Image.png 689 1215 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-12 08:30:382026-07-27 22:01:54Cyber Attack Recovery Starts Before the Breach

Cybersecurity Fatigue: Is Your Business at Risk?

March 4, 2026/in Blog, Cybersecurity, General

Security fatigue is real. You’ve felt it, and so have we. Cyber criminals know this, and they are waiting to capitalize on it. When we let security fatigue guide our decisions and allow our guard to drop, we become much more likely to fall victim to a cyberattack.

Over the past few weeks, we have assisted multiple companies that fell victim to such attacks. These events reflect a recent surge in cyberattacks, serving as a harsh reminder that we must remain vigilant.

Common Elements

Each of these recent cases shared three common elements:

  1. An employee clicked on a malicious link and shared account information.
  2. The company opted not to deploy recommended security measures.
  3. Neither the business or IT leaders had a plan for how to respond to an emergency.

These elements demonstrate critical failures at every phase of a cybersecurity event.

Prior to The Event

Even as small businesses, we are more vulnerable to cyberattacks than we may expect. A basic suite of cybersecurity services is no longer optional, it is essential for defending and protecting against attacks.

In each of the cases we recently handled, simple and effective baseline tools were not in place. Decisions made to avoid the incremental cost of added protections left these businesses exposed.

Consequently, each company is now paying a much larger price, ranging from several days of downtime and lost productivity to potential fines and litigation.Connect with a Cloud Advisor

The Event

Human action triggered all three of these recent events. While it is easy to claim that the individuals involved should have known better, the reality is that even knowledgeable people succumb to these tricks when they are tired or distracted.

How many times have you replied to or acted on an email that you skimmed or quickly read without focusing on the content? We are all busy, and an email often feels like just another task to check off.

When you combine a false sense of security with a momentary lack of attention, it is very easy to click the wrong link, enter credentials into a fake site, or share private information.

Technology is vital for protection, but your people must also understand the risks. They should be able to identify suspect interactions and know exactly what to do when faced with a suspicious email, text, call, or web page.

After The Event

In every recent event we have handled, the business and IT leaders were unsure how to proceed. Given the urgency and stress of the moment, none of them referred to an existing Information Security Plan because they did not have an incident response checklist or strategy in place.

We tend to focus on recovery, such as getting systems back online and restoring data. While this is an urgent and tangible response, it is only one part of the equation.

Your cyber insurance carrier may need to verify your security measures, conduct a forensics analysis, or direct your recovery efforts. You likely have legal, industry, or contractual reporting requirements, and you may even need law enforcement to investigate.

Response and recovery from a cyberattack requires having the technology in place to get your systems, apps, and data back in operation as well as having resources in place to get you through the legal, regulatory, contractual, marketing, and customer relationship challenges you will face.

How We Help: Security CPRⓇ

Your security profile should match your business. The nature of your company, its size, your industry and markets, and your locations should all dictate your security requirements. Your leadership team should guide your security strategy and spending.

Our Security CPRⓇ model and services provide the framework for creating the right security profile for your business:

  • Communicate and Educate: Ensure you and your team are knowledgeable, aware, and prepared, and that you have appropriate policies and procedures in place.
  • Prevent and Protect: Implement the right mix of security solutions to stop cyberattacks and defend against active threats.
  • Recover and Respond: Build the necessary services for business continuity, resilience, and a quick return to operations, including resources to assist with the insurance, regulatory, legal, and communication aspects of a response to an incident.
About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2026/03/2026-03-02-Blog-Hero-Image.png 719 1080 Jordyn Seybolt https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Jordyn Seybolt2026-03-04 09:30:292026-03-04 14:15:14Cybersecurity Fatigue: Is Your Business at Risk?

Your Strategy for Business Resilience

February 4, 2026/in Blog, General

Cyber incidents, system failures, and unexpected disruptions are no longer rare events. For small and mid-size businesses (SMBs), even a short outage or minor breach can interrupt operations, expose sensitive data, and damage customer trust.

Business resilience means preparing your organization to absorb disruptions and keep moving forward. You cannot, however, achieve resilience with a single tool or policy. 

Business Resilience requires a layered security strategy that reduces risk, limits impact, and supports fast recovery. 

Why Business Resilience is Your Priority

Technology plays a critical role in nearly every part of your business. When systems are disrupted, the impact extends beyond IT to revenue, reputation, and customer confidence. 

A resilient security strategy helps you maintain operations even when things do not go as planned. 

Connect with a Cloud Advisor4 Strategic Pillars for Resilient Cybersecurity

An effective approach to security addresses risk across four key areas:

  1. Awareness: Your employees recognize common threats, follow security best practices, and understand their role in protecting the organization.
  2. Prevention: Updates, controls, and monitoring reduce exposure by closing common attack paths.
  3. Protection: Safeguards such as encryption, access controls, and multi-factor authentication limit damage when incidents occur.
  4. Recovery: Backups and response plans enable you to restore systems, data, and workflows quickly.

These pillars help you defend against both cyber threats and everyday mistakes and align with our Security CPR™ managed security model. 

Plan for Impact, Not Just Prevention

No environment is immune to risk. 

Even with strong preventive measures, incidents will still happen. Ongoing training, layered defenses, and clearly defined response plans will help you manage disruptions efficiently and reduce downtime. 

Preparation ensures that a security event becomes a manageable incident rather than a prolonged crisis.

Resilient cybersecurity is the foundation for business resilience. 

Resilience is a Strategic Commitment

Building resilience is an ongoing effort that evolves as threats, technologies, and business needs change. With the right strategy and experienced partners, you can stay prepared, protect critical systems, and maintain stability when disruptions occur.

Managed Cloud Services Support Business Resilience

Managed cloud and managed security services play a critical role in helping you improve security and business resilience without overwhelming internal teams. At Cumulus Global, we support resilience through:

  • Comprehensive IT and security management
  • Secure collaboration and productivity solutions
  • Cloud infrastructure monitoring, optimization, and protection

By aligning cloud technology with your business objectives, our managed cloud services and our Security CPR™ Managed Security Services improve reliability, reduce risk, and support long-term continuity.

About the Author

Bill Seybolt bio pictureBill is a Senior Cloud Advisor responsible for helping small and midsize organizations with productive, security, and secure managed cloud services. Bill works with executives, leaders, and team members to understand workflows, identify strategic goals and tactical requirements, and design solutions and implementation phases. Having helped hundreds of organizations successfully adopt cloud solutions, his expertise and working style ensure a comfortable experience and effective change management.

https://www.cumulusglobal.com/wp-content/uploads/2026/02/02-04-26-Blog-Hero-Image.png 890 1350 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2026-02-04 11:00:282026-02-04 13:59:18Your Strategy for Business Resilience

Avoid MFA Pitfalls and Lockouts

September 23, 2025/in General

MFA PitfallsMaybe you have seen the meme about spending 6 hours per day entering multi-factor authentication (MFA) codes. While inconvenience is one pitfall of MFA, improper configuration and management of MFA can lead to more damaging pitfalls and lockouts. Your ability to work can take days to recover.

The MFA Pitfalls 

Most of us are not using a separate security key; we authenticate using our smartphones. Whether by Authenticator app, SMS text, one-time passwords/codes, or local app login, we need our smartphone to access our apps and services.

Imagine this scenario:

  • Your iPhone is lost, stolen, or damaged.
  • On your laptop, you need to login to check email and the authentication goes to the Authenticator app on your phone.
  • You could opt to have a one-time password emailed to you, but you cannot access your email.
  • You could send it to your recovery email, which you rarely use, is logged out and the MFA also goes to your phone.

You get the picture. You are stuck, but you still have other means of access. Depending on your configuration, restoring access may be complex and take too much time.

And while this scenario may seem unlikely to happen, we see online forums where over 80% of help requests relate to account lockout and recovery. Almost all of the problems were avoidable with proper configuration and management.

Tips to Avoid MFA Pitfalls

To help you avoid MFA pitfalls and lockouts, we created a list of things to consider when configuring management of your MFA services.

  • Use a Sustainable Phone Number for MFA and for Recovery: MFA texts and messages should only go to a phone number that can remain in use if you switch phones or phone systems. Whether to a physical phone or a VoIP service, make sure that you will not lose your number if things change in the future.
  • Have a Separate Recovery Phone Number: If your phone is not available for MFA calls or texts, it is not going to work for recovery codes, calls, or texts. If at all possible, use different phone numbers for MFA and recovery. If your MFA phone number is your smartphone, your recovery phone number could be your business’ VoIP phone number, or the number of a trusted coworker or spouse.
  • Use a Separate Recovery Email: If the email account that receives MFA messages is inaccessible, you will not be able to use it for recovery. Use an alternate email address. This could be a personal (@gmail.com) account or a one belonging to somebody you trust. When setting up your recovery email account, make sure that account is not reliant on the same methods and devices.
  • Stop Before You Drop: Before you give up, abandon, or change a phone number or email address, review the MFA setup across all of your apps and systems. Make sure you move them to your new number and/or email address before you give up the old ones.
  • Backup Your Authenticator Apps: Both Microsoft Authenticator and Google Authenticator let you backup your Authenticator App data. This lets you reinstall and recover your Authenticator settings and accounts on a new or different device. Make sure, however, that the backup location does not require the Authenticator App for access.
  • Create, Print, and Save Recovery Codes: Many systems, apps, and security tools let you create emergency recovery codes. If available, create the codes, print them, and keep them in a safe location (“Put it with your Passport”). Having these codes can reduce account recovery time by hours or days.
  • Use a Password Manager: Password managers provide a single, secure login to allow access to complex passwords and validation for the connected apps. Using a password manager reduces the risk of account lockout.
  • Do Not Buy Direct: Buy your cloud apps and services through authorized partners. For most SaaS and cloud solutions, your partner has administrative access to your account. They can reset passwords and recover accounts. If needed to expedite access or recovery, your partner can change MFA configuration and/or temporarily remove MFA from an account.

These steps require some planning. As MFA settings and preference can often be set individually, you will need to communicate and coordinate with your employees. 

We Will Help

Our Cloud Advisors are here to assist. We can:

  • Review your current MFA services and configurations
  • Identify risks and recommend changes
  • Assist your team members with settings and recovery codes
  • Provide your with Password Manager services
  • Provide license and account co-management for your cloud services

Schedule time with one of our Cloud Advisors now to discuss your next steps.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2025/09/MFA-Pitfalls.ai_.png 469 640 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-09-23 20:09:202025-12-15 22:13:54Avoid MFA Pitfalls and Lockouts

Don’t Fall for the Call

August 29, 2025/in Blog, General

Don't Fall for the Call

IT support scams are back and on the rise. Over the past few weeks, the reports of vendor phone calls and emails claiming to contact people about suspicious activity in their accounts have skyrocketed.  

Do Not Fall for the Scam

Google, and Microsoft, will NEVER call your or email you to start a service or support call.  Let me repeat that, but this time in bold. Google, and Microsoft, will NEVER call your or email you to start a service or support call.

Some of these calls and emails attempt to get you to enter your username and password into a fake web page. 

Many of these attacks request the multi-factor authentication (MFA) code. The attackers initiate a password reset. If given the MFA code, they access the account and can change credentials, access other services, and exfiltrate information.

It is more difficult to spot fake landing and sign in pages

While historically easy to spot, attackers use generative AI to create sophisticated fake login pages. 

Attackers are also using legitimate landing page, marketing, or document tools. The link in the email may open a validly hosted page or document with instructions and another link that, in turn, takes you to the fake login page. 

As the hackers take you through a legitimate service, as a pass-through, you may be less likely to notice that the page asking for your credentials is fake. This method is also more difficult to combat since the pass-through may require valid credentials for access.

Steps You Can Take

You can take a few simple steps to prevent these types of attacks from successfully damaging your business.

  • Education – Inform and educate your team about current and emerging cyber attack methods, what to look for, and how to handle suspicious activity.  Cyber Awareness Training, if well managed, is an affordable means to keep security top of mind.
  • Advanced Email Threat Protection – Email threat protection focused on sender domains, links, and attachments is not enough. Attackers use masking, images, and QR codes beyond the capabilities of many email protection services. Upgrading to a more robust service will provide better protections. Solutions that provide banners and “one-click response” better empower users to flag and manage suspect messages.

We Will Help

Our Cloud Advisors are here to assist. We will:

  • Assess your current security profile and protections
  • Prioritize options and recommendations for security improvements
  • Help you plan and budget for any changes
  • Deploy and co-manage your security solutions to keep you protected.

Schedule time with one of our Cloud Advisors now to begin your security review and improvements.

About the Author

Bill Seybolt bio pictureBill is a Senior Cloud Advisor responsible for helping small and midsize organizations with cloud forward solutions that meet their business needs, priorities, and budgets. Bill works with executives, leaders, and team members to understand workflows, identify strategic goals and tactical requirements, and design solutions and implementation phases. Having helped over 200 organizations successfully adopt cloud solutions, his expertise and working style ensure a comfortable experience effective change management.

https://www.cumulusglobal.com/wp-content/uploads/2025/08/Dont-Fall-for-the-Call.ai_.512.png 512 512 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-08-29 20:09:202025-12-15 22:15:18Don’t Fall for the Call

5 Cyber Threat Trends You Should Know

August 6, 2025/in AI in Google Workspace, Cybersecurity, General

5 Security Cyber Threats You Should Know

Earlier this week, we shared CrowdStrike’s 2025 Global Threat Report which identified five (5) cyber threat trends that you should know. While cyber-fatigue is real, understanding the threat landscape helps you assess your risks and security posture and make informed decisions on how to prioritize security-related spending and investment.

5 Cyber Threat Trends

Here are the 5 cyber threat trends you should know.

1 China on the Rise

Cyber attacks originating in China – both nation-state and organized crime – jumped 130% over the prior 12 months. At the enterprise-level, China-nexus attackers focus on telecommunication systems. For most businesses, the increase in attacks on unmanaged devices should be of concern. 

Unmanaged devices lack detection and response capabilities that allow attackers to lurk, monitor, and capture credentials for greater access to your systems, applications, and data.

2 Hands-On-Keyboard Attacks are Making a Comeback

The best way for cyber attackers to avoid modern malware protection, such next-gen endpoint protection and managed detection and response (MDR) services, is for the attacker or a surrogate to use the keyboard. These manual, interactive attacks are up 27% over the prior year.

We may imagine hands–on-keyboard attacks as movie-like scenarios of corporate spies posing as custodians sneaking onto computers while avoiding the security guards making their rounds. In reality, the hands-on-attack may be your employee responding to somebody they think is IT support or a vendor helping them solve a problem.

3 Rapid Ransomware Reach

The speed at which cyber attackers can launch ransomware attacks after an initial breach is accelerating. From breach to spread, attacks are up to 32% faster than previously known.

This speed gives cybersecurity systems less time to identify behaviors and patterns that identify the cyber attack, weakening the effectiveness of the protections.

4 AI for Evil

With the help of AI, certain types of cyber attacks have jumped 220% over the prior year. Cyber attackers are using generative artificial intelligence (Gen AI) technologies to power more-effective attacks.  

Using GenAI, attackers create more realistic fakes – emails, documents, phone calls, and videos – to trigger responses and reactions that enable and facilitate access and breaches.

At the same time, cyber attackers are using security vulnerabilities in the platforms and tools businesses use to build AI agents, just as they use vulnerabilities in web, application, and office productivity platforms.

5 Cloud Attacks Gain Altitude

Cloud intrusions – successful cyber attacks on cloud systems and services – jumped 136% during the first half of 2025 compared to all of 2024. These attacks vector through compromised identities, improper security configurations, API vulnerabilities, lax security and permissions governance.

Steps You Can Take

To ensure your security footprint protects your business appropriately:

  • Conduct IT and Security Assessments that benchmark your security posture.
  • Prioritize your risks based on the nature and size of your business, industry standards and expectations, and regulatory requirements.
  • Level our Security CPR® model and managed services to plan, prioritize, and implement appropriate security and business resilience solutions that:
    • Address your prioritized risks as your budget allows
    • Protect from the most common and the most damaging/costly types of attacks.

We Will Help

Plan Now; Act Soon. Our Cloud Advisors are here to assist. We will:

  • Review your current systems and services and prioritize your risks. 
  • Help you prioritize, plan, and budget for security changes and improvements that may be necessary or preferred
  • Deploy and co-manage your security solutions to keep you protected.

Schedule time with one of our Cloud Advisors now to begin your security review and improvements.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America.

https://www.cumulusglobal.com/wp-content/uploads/2025/08/5-Security-Cyber-Threat-Trends-You-Should-Know.ai_.jpg 2048 2048 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-08-06 20:09:202025-12-15 22:18:335 Cyber Threat Trends You Should Know

The 3 Most Common Cloud Admin Oversights

March 21, 2025/in General

Cloud AdminIf you use Google Workspace or Microsoft 365, managing your services requires time and effort. Failing to do so can lead to wasted money and security risks. Here are the three most common cloud admin oversights we encounter.

1 – Data and Account Retention Policies

Every business has some degree of employee turnover. Whether you are hiring replacements, reducing staff, or growing, having data and account retention policies will guide how you handle user accounts and data when an employee leaves. Without such policies, we tend to keep accounts active “in case we need some of their files or emails,” long after the need has passed. 

Data and account retention policies can be both effective and simple. Here are some key elements for simple data and account retention policies: 

  • Determine how long you need to keep an employee’s data accessible for legal or regulatory reasons. The length will depend on your business and the user’s job function.

Outside of legal and regulatory requirements, think about:

  • When should you transfer emails, files, or other content to another person.
  • How long to keep an account active in the system.
  • How long to keep an archive or the user’s account in the system.
  • How long to keep a copy of the user’s data in your backup/recovery system.
  • If you choose to export the data, how long to keep the export.
  • When to delete the account after it becomes inactive, allowing you to reuse the license.

Since archive and backup/recovery solutions allow you to restore data to a different user, they offer a more cost-effective option than keeping an account active and licensed. They also help meet your legal retention requirements without the expense of an active user license.

2 – License Management

Sometimes we overlook simple actions that can save us time and money. Both Microsoft and Google allow you to add users at any time during your annual contract term. These additions become part of your contracted commitment, which you cannot reduce until renewal.

Too often, when a new employee or contractor joins the team, we immediately add a license and set them up to work. By not checking for available licenses or user accounts that can be deleted, we miss opportunities to reuse existing licenses. Consequently, we end up paying more without any added benefit.

If you have data and account retention policies, you can safely determine if and when to remove a former employee’s account. This allows you to reuse licenses and avoid incremental costs.

While the process may take a few minutes, it is simple and effective in saving money. We have seen businesses with seasonal employee turnover accumulate 25% to 50% more licenses than they actually need.

3 – On-Boarding / Off-Boarding

Small and midsize businesses may not see the need for formal on/off-boarding processes. However, not having them in place can lead to wasted time and potential security risks. Simple, efficient checklists can save you time, effort, and money

On-Boarding

The key to efficient on-boarding is knowing which applications, tools, and data the new employee should be able to access and use.

Create a simple checklist of applications, tools, and file shares. When on-boarding a new employee, determine what access is needed and check off each item as it is provided. This ensures new staff members only gain access to the resources they need.

Creating standard checklists for specific departments and jobs ensures consistent access and permissions across teams.

As a best practice, create security groups for departments and/or job functions to which you assign permissions are access rights. When on-boarding, adding new employees to the appropriate groups streamlines the process and saves time.

Off-Boarding

One of the most common mistakes made during employee departures is leaving accounts active with continued access to systems and data. This poses a security risk and can create confusion for remaining staff.

Having data and account retention policies helps ensure that past employee accounts, also known as “ghost accounts,” are removed from your systems. Creating off-boarding checklists helps ensure that application and data access gets transferred, as appropriate, to other users. Using security groups further simplifies the off-boarding process.

Your Next Step

With time-saving best practice, cloud admin services, Cumulus Global co-manages and remotely administers your IT services to save you time and money, improve productivity, enhance security, and protect your business.

Contact us about our Managed Cloud Services or schedule a no-obligation meeting with a Cloud Advisor today.

Contact us or schedule a no-obligation meeting with a Cloud Advisor today.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America. Starting his first business at age 12, Allen is a serial entrepreneur. He has launched strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.

https://www.cumulusglobal.com/wp-content/uploads/2025/03/Cloud-Admin.png 512 512 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-03-21 11:00:112025-03-20 17:44:56The 3 Most Common Cloud Admin Oversights

US Cybersecurity Policy Shift Increases Risk of Successful Cyber Attacks

March 4, 2025/in Cybersecurity, General

Data Protection & SecurityThe current United States administration continues to issue and execute dramatic changes in US policies and programs. For businesses, tariffs and their potential impact on the economy and various business sectors gets most of the media attention. Getting less attention, US Cybersecurity Policy changes will have an immediate and potentially devastating impact on many businesses and individuals.  

Multiple reputable news and information sources are reporting that on March 2nd, the current administration ordered the Cybersecurity and Infrastructure Security Agency (CISA) to cease tracking and reporting on Russian threats. This is a tectonic shift in policy as Russia is generally understood to be the largest nation-state sponsor of cyber attacks. This change in focus for CISA will dramatically reduce the availability, reliability, and timeliness of cybersecurity threat intelligence. 

Here is what you need to know, what to expect, and what to do.

What to Know

Here are three things to know about cyber threats, CISA, and nation-state cyber attacks.

1Threat Intelligence

Threat intelligence is the invisible backbone of your cybersecurity protections. As the name implies, threat intelligence is the collection of sharing of information about cybersecurity risks, threats, methods, actors, sources, and sponsors. It also encompasses knowledge of how to prevent, block, and stop attacks; fix hardware and software to close exploits.

Every legitimate cybersecurity product or service relies on threat intelligence to build, maintain, and improve their product or service. Larger and better-funded cybersecurity companies conduct their own research and share their findings.

2CISA: Cybersecurity & Infrastructure Security Agency

CISA is the US federal government agency responsible for collecting, evaluating, and sharing threat intelligence across government and private sectors. The agency also partners with core infrastructure companies, such as Internet Service Providers, to actively prevent, block, and respond to potential and active cyber attacks.

3Nation-State Cyber Attacks

Industry experts estimate that over 40% of cyber attacks originate from, or are sponsored by, hostile nation-states. The Microsoft Digital Defense Report Report 2024 notes that in 2024, 58% of nation-state attacks originated in Russia. These attacks account for up to 25% of all cyber attacks globally.

What to Expect

Expect more cyber attacks and greater challenged to your cyber security profile.

1More Cyber Attacks

Expect an increase in cyber attacks and, more importantly, successful cyber attacks.

With CISA no longer tracking Russian-sourced cyber attacks, expect Russia, Russian-sponsored, and Russian organized crime to increase the frequency, intensity, and scope of the cyber attacks. Knowing that CISA is no longer watching signals a huge opportunity to attack US government entities, businesses, and non-profits with fear of early detection or responsiveness.

2More Successful Attacks

Without fast and accurate threat intelligence, cybersecurity systems and services will take longer to identify threats and attacks.Their response to zero-day (new, immediate) and other cyberattacks will take longer.

Unprotected and under-protected systems will be more vulnerable to successful attacks as the frequency and scope of cyber attacks increase.

3More Challenging Recovery

In addition to sharing information to help block and stop cyber attacks, CISA shares information on how to repair and recover. Without this information, obtaining decrypt keys and other help to undo the damage will be more difficult and will take more time.

What to Do

Use our Security CPR® model to guide your next steps:

Communicate and Educate:

Inform your team to expect an increase in cyber attacks and ask for additional vigilance. Have security awareness training in place to reinforce the message and to occasionally test if your team can recognize phishing and other email-based cyber attacks.

Protect and Prevent:

More than 80% of cyber attacks originate, directly or indirectly, by email. Make sure you have next-generation email threat protection services in place. Beyond header validation and basic sandboxing, your solution now should analyze character sets and fonts, images, QR codes, graymail, and email delivery patterns.

Microsoft estimates that more than 90% of cyber attacks on small and midsize businesses can be stopped with multi-factor authentication (MFA). If you do not have MFA in place for critical systems (preferably ALL systems), do so now.

Restore and Recover:

As the risk of successful attacks increases, ensure that you have the ability to restore damaged and lost data and systems. Verify that you can recover – return to operations – quickly, even as you continue to restore systems and data.  Continuity solutions for critical systems and software will save you time and money.

Your Next Steps

Assess your immediate needs and take appropriate action. Our Cloud Advisors can help you assess your cybersecurity needs and priorities, and can offer budget-friendly, effective solutions.

Contact us or schedule a no-obligation meeting with a Cloud Advisor today.

About the Author

Allen Falcon is the co-founder and CEO of Cumulus Global.  Allen co-founded Cumulus Global in 2006 to offer small businesses enterprise-grade email security and compliance using emerging cloud solutions. He has led the company’s growth into a managed cloud service provider with over 1,000 customers throughout North America. Starting his first business at age 12, Allen is a serial entrepreneur. He has launched strategic IT consulting, software, and service companies. An advocate for small and midsize businesses, Allen served on the board of the former Smaller Business Association of New England, local economic development committees, and industry advisory boards.

https://www.cumulusglobal.com/wp-content/uploads/2020/02/Data-Protection-Security-1.png 564 800 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-03-04 08:30:432025-10-09 13:56:14US Cybersecurity Policy Shift Increases Risk of Successful Cyber Attacks

Debunking Cyber Insurance Myths

February 24, 2025/in Cybersecurity, General

Cyber Insurance Risk Assessment

Your business faces an ever-increasing array of cyber threats. Beyond protections, cyber insurance is an essential component of a robust risk management strategy. Therefore, understanding cyber insurance realities is necessary for you to make sound security and business decisions. In this post, we focus on debunking common cyber insurance myths.

1MYTH: Cyber Insurance Policies Offer the Same Level of Protection

In reality, policies vary significantly with respect to coverages and services. Opting for bundled policies generally results in coverage gaps, as most general liability policies treat cyber coverage as an add-on.These gaps leave your businesses vulnerable to liabilities and losses.

Standalone cyber insurance policies, provided by financially strong carriers, offer comprehensive protection tailored to the specific needs of your business. They address unique risks associated with cyber threats given your industry, business size, and other risk factors. Standalone policies also often include coverage of forensics, temporary resources, and other recovery needs. Dedicated coverage helps you respond more effectively to a cyber incident.

2MYTH: Your IT Security Measures Dictate Your Premiums.

While robust security practices can positively impact premiums, broader industry trends and company-specific factors play a more significant role in determining pricing.

Industry-wide loss ratios have a substantial impact on insurance costs. Peer group averages impact premiums as well. Insurers assess the risk profile of businesses within sectors. As insurers issue more policies and analyze claims, insurers refine actuarial, incorporating additional factors and risks.

3MYTH: Cyber Insurance Policies do Not Pay Out

Many businesses hesitate to buy standalone cyber insurance policies out of fear that their policy will not pay out in the event of a claim. Reputable cyber insurers with strong financials rarely deny claims with a valid cause..

Inaccurate, or fraudulent, applications are the most frequent reasons for claim denials or reductions. 

Your application must accurately reflect your cyber insurance risk profile. The information you provide on your cyber insurance application should reflect a thorough review process. Cybersecurity tools offer verification of your security profile.

4MYTH: Cyber Insurance is All You Need

Many businesses, including yours, may need additional layers of protection for specific cyber risks. These additional coverages may not be available within a traditional cyberinsurance policy.

Cyber warranties offer additional layers of protection by covering these specific elements of cyber risk. Combining cyber warranties with cyber insurance creates a more comprehensive safety net. This approach bolsters your overall security strategy and ensures appropriate coverage.

5MYTH: Robust Cybersecurity Measures Eliminate the Need for Cyber Insurance

Investing in strong cybersecurity defenses provides crucial protection for your business. No security profile or system, however, will stop every cyber attack, data breach, or data loss incident. Cyber threats continually evolve. Even the most secure systems fall victim to sophisticated attacks.

Cyber insurance serves as your financial safety net. Beyond covering direct financial losses, better policies help you recover from incidents that slip through the cracks of your security measures. These resources include forensics, data recovery, customer relations, legal expenses, and more. Cyber insurance protects you financially if and when a cyber attack gets past your defenses.

6MYTH: Obtaining Cyber Insurance is Complicated and Time-Consuming

The thought of obtaining cyber insurance deters many businesses from seeking the coverage they need. Horror stories of complex applications, surveys, and audits create anxiety and fear of the process. 

Unfortunately, this myth can come true. Businesses that apply through general insurance agents and fail to leverage knowledgeable IT resources often run into issues during the underwriting process.

Cumulus Global partners with cyber insurance specialists that offer streamlined application processes and non-committal quotes. Our partners work with more than two dozen carriers, ensuring you have options to choose the policies that meet your business needs and budget. Non-biased policy reviews help you understand your coverages and make informed decisions.

Related Information

Cyber Security Requirements for Cyber Insurance (eBook)

5 Questions for Lower SMB Cyber Insurance Premiums (Coffee & Clouds)

Security CPR® (Cloud Burst)

Security CPR® Managed Security Services (Service Overview)

Your Next Step 

Avoid falling prey to cyber insurance myths. Contact us and let us introduce you to our cyber insurance partners.

We can provide you with a Cyber Insurance Risk Assessment and help you assess your cybersecurity profile.

About the Author

Bill Seybolt bio pictureBill is a Senior Cloud Advisor responsible for helping small and midsize organizations with cloud forward solutions that meet their business needs, priorities, and budgets. Bill works with executives, leaders, and team members to understand workflows, identify strategic goals and tactical requirements, and design solutions and implementation phases. Having helped over 200 organizations successfully adopt cloud solutions, his expertise and working style ensure a comfortable experience effective change management.

https://www.cumulusglobal.com/wp-content/uploads/2022/06/Cyber-Insurance.jpg 432 767 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-02-24 13:00:512025-10-09 13:56:16Debunking Cyber Insurance Myths
Page 1 of 212

Webcasts

What to Do When It Happens

March 17, 2026/in 3T@3 Webcast Series, Cybersecurity

(03/17/26) – How you initially respond to a cybersecurity incident will affect your ability to recover, your cyber insurance coverage, your customer relationships, your legal and financial liability, and possibly your survival.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2026-03-17 15:00:382026-03-18 13:40:22What to Do When It Happens

Pen Testing: What and Why (CloudBurst Ep. 01.07)

February 6, 2025/in Cloud Burst Series, Cybersecurity

Feb 6, 2025

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-02-06 17:52:482026-04-10 17:55:17Pen Testing: What and Why (CloudBurst Ep. 01.07)

Protecting Your Laptop Protects Your Business (Cloud Burst Ep. 01.05)

November 6, 2024/in Cloud Burst Series, Cybersecurity

Nov 6, 2024

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2024-11-06 17:41:382026-04-10 17:44:15Protecting Your Laptop Protects Your Business (Cloud Burst Ep. 01.05)

Security CPR (Cloud Burst Ep. 01.03)

September 16, 2024/in Cloud Burst Series, Cybersecurity

Sept. 16, 2024

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2024-09-16 17:37:382026-06-22 22:37:29Security CPR (Cloud Burst Ep. 01.03)

ALERT: Dramatic Increase in Threatening Cyber Attacks (Cloud Burst Ep SP.01)

September 9, 2024/in Cloud Burst Series, Cybersecurity

Sept. 9, 2024

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2024-09-09 12:00:012026-04-10 17:35:01ALERT: Dramatic Increase in Threatening Cyber Attacks (Cloud Burst Ep SP.01)

Business Email Compromise Attacks (Cloud Burst Ep. 01.01)

July 16, 2024/in Cloud Burst Series, Cybersecurity

July 16, 2024

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2024-07-16 12:00:172026-04-10 17:36:21Business Email Compromise Attacks (Cloud Burst Ep. 01.01)

library

Decision Tree: Windows 10 End of Life

July 2, 2025/in eBook

eBook | Source: Cumulus Global — Windows 10 End of Life is October 14, 2025. Proactive planning and action are not just recommended, they are critical for your business continuity and security. This eBook provides a decision tree and walks you through your Windows 10 upgrade options.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-07-02 15:47:502025-07-02 18:25:57Decision Tree: Windows 10 End of Life

Cybersecurity Essentials for Smaller Businesses

June 12, 2025/in Cybersecurity, eBook

eBook | Source: Cumulus Global — Cybercriminals target small businesses because we tend to have fewer resources and less robust cybersecurity practices. This eBook provides a strategy, model, & roadmap of affordable, effective cybersecurity essentials for sole practitioners, solopreneurs, & very small businesses.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-06-12 16:37:462025-10-09 13:59:03Cybersecurity Essentials for Smaller Businesses

Google Workspace: A Guide for Using AI at Work

April 24, 2025/in AI in Google Workspace, eBook

eBook | Source: Google — With Google Workspace, powerful AI is included – not bolted on. Gemini AI is the AI that makes everyday work easier. This eBook provides an app by app overview of ways to use AI in Google Workspace

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-04-24 10:56:012025-08-01 18:12:40Google Workspace: A Guide for Using AI at Work

Verizon 2024 Data Breach Investigations Report

April 10, 2025/in White Paper

Whitepaper | Source: Verizon — The Verizon 2024 Data Breach Investigations Report, the 17th annual edition, highlights evolving threat scenarios world-wide. From year to year, we see new and innovative attacks as well as variations on tried and-true attacks. The past year has been a busy one for cybercrime.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-04-10 08:30:162025-04-10 10:32:08Verizon 2024 Data Breach Investigations Report

Microsoft Digital Defense Report 2024

March 5, 2025/in Cybersecurity, White Paper

Whitepaper | Source: Microsoft — In the last year, the cyber threat landscape continued to become more dangerous and complex. Improved defenses will not be enough. However, improved defense will not be enough. The data, insights, and events in this report represent July 2023 through June 2024 (Microsoft fiscal year 2024), unless otherwise noted.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-03-05 14:13:222025-10-09 13:59:03Microsoft Digital Defense Report 2024

Google Workspace Security Feature Matrix

January 22, 2025/in Cybersecurity, eBook

eBook | Source: Cumulus Global — This eBook provides a summary of the security features across Google Workspace subscriptions. Using the included matrices, you can select the subscription that best meets your needs and compare the detailed capabilities of security features against third party options.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2025-01-22 16:40:412025-10-09 14:00:15Google Workspace Security Feature Matrix

Pen Test Primer: Security for Small Businesses

December 20, 2024/in Cybersecurity, eBook

eBook | Source: Cumulus Global — This eBook presents an introduction to Penetration Testing and discusses how small and midsize businesses can use Pen Testing effectively and affordably as part of a robust cybersecurity program.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2024-12-20 14:13:592025-10-09 13:59:03Pen Test Primer: Security for Small Businesses

2023 OpenText Cybersecurity Email Threat Report

June 15, 2023/in Cybersecurity, eBook

eBook | Source: OpenText Security — Attackers persistently adapted their email-based techniques throughout 2022, introducing more nuances into their methods. This eBook shares current information about Phishing, Business Email Compromise, Cryptocurrency Scams; and the Top Malware Threats. The report provides examples of attacks as a learning tool for understanding attacks, how to prevent them, and how to respond.

Read more
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2023-06-15 10:00:292025-10-09 13:59:022023 OpenText Cybersecurity Email Threat Report

Recent Posts

  • Secure Gemini AI in Google Workspace
  • Your Path to Full Cloud Adoption
  • How We Use AI for Data Enrichment

Featured Blog Topics

  • Artificial Intelligence / AI
  • Managed Cloud Services
  • Cybersecurity

Read

  • Blog
  • Newsletter
  • Microsoft Cloud Monday
  • Google Workspace Wednesday

Watch

  • 3T@3 Series
  • Coffee and Clouds
  • Event Recordings
  • Cumulus Global Channel

Explore

  • Library
  • Events Calendar

Phone / Fax / Email

  • 866-356-1202
  • 508-948-4070
  • info@cumulusglobal.com

Headquarters / Boston

  • Street Address

    4 Bellows Rd / 2nd Floor
    Westborough, MA 01581

  • Mailing Address

    PO Box 1129
    Westborough, MA 01581-6129

Regional Offices

  • Southeast Office

    120 W Trinity Pl
    Decatur, GA 30030

Copyright © 2026 - Cumulus Global | Privacy Policy | Terms of Service | Disclaimer | Website by Cold Spring
Scroll to top Scroll to top Scroll to top