Cyber attack readiness is not a document. It is a set of decisions you make before a cyber attack. A few months ago, I sat in a county office with a clerk who had a binder on her shelf labeled “Emergency Plan.” She pulled it down and blew the dust off the cover. Inside was […]
Cyber Security Weekly Roundup: Top 5 for the Week of July 27 to August 2, 2026
1. Coordinated Cyberattack Hits More Than 30 Minnesota Water Systems Minnesota IT Services confirmed that a coordinated cyberattack struck over 30 community water systems across roughly 48 hours beginning July 26. Braham’s treatment plant went offline entirely, while Plymouth, South St. Paul, and Maple Plain reported failures in cellular communications and automated utility controls, with […]
vCISO: The Acronym That Cuts Your Security Budget
In a field drowning in initials, vCISO is the one that can save a small organization real money At a charity lunch this spring, a woman who runs a twelve-person insurance agency slid a vendor proposal across the table to me. She had circled seven acronyms on the first page alone. MFA. EDR. SIEM. SOC. […]
Cyber Security Weekly Roundup: Top 5 for the Week of July 20-26, 2026
This week the threat landscape sharpened around two themes: the weaponization of AI agents and the exploitation of trusted access. A single link could forge a rogue AI insider, extortion crews leaned on the phone rather than the exploit, and a fired employee’s credentials became a live breach. Here is what mattered, and what to […]
The Small Health Care Practice Is Cyber Crime’s New Target
A small health care practice in a Kentucky county seat lost access to its patient records on a Monday morning last winter. The front desk could not pull up a single chart. Appointments backed up into the parking lot. The office manager told me later that she had always assumed criminals went after the big […]
Cyber Security Weekly Roundup: The Week of July 13-19, 2026
1. SharePoint zero-day under active attack forces federal patch deadline. CISA added CVE-2026-58644, a critical (CVSS 9.8) deserialization flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, giving Federal Civilian Executive Branch agencies until July 19 to remediate. The bug allows unauthenticated remote code execution and was weaponized as […]






