Find partners
SMB Tech & Cyber Newsletter | CPF Coaching

SMB Tech & Cyber Newsletter | CPF Coaching

Hosted by CPF Coaching | Christophe Foulon

Episodes

127

Latest episode

Aug 2026

Language

EN

About the show

I empower Chief Information Security Officers (CISOs) and Small to Medium-sized Businesses (SMBs) to elevate their cybersecurity strategies, guiding them past stagnation to achieve tangible outcomes. substack.cpf-coaching.com

Listen to episodes

60 recent
August 14, 20265 min

This Week's SMB Risk Signals: Patch the VPN Edge, Audit Broker Data, and Tier AI Work

A free CPF Coaching audio briefing on Gunra's edge-driven ransomware tactics, California's first Delete Act enforcement action, and why premium AI seats now need real ownership. Built for SMB leaders who need a fast risk read before the premium implementation pack. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

August 7, 202611 min

The Top 3 Unmanaged Risks Threatening Your SMB Right Now

Discover this week's top SMB risk signals. Learn why leaders must immediately secure MSP control planes, manage data broker deletion rules, and govern AI workflows. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

July 24, 20269 min

SMB Risk Briefing: Lock the Controllers, Unify the Evidence, and Modernize AI with Real Ownership

A free CPF Coaching briefing for SMB leaders on SharePoint exploitation, recurring-subscription compliance, and the control boundaries AI agents need before they scale. This episode covers only the free strategic guidance. This week's SMB Risk Signals briefing is about the workflows your business already trusts. CISA's SharePoint alert shows how fast an old collaboration server can become an execution surface. New York's settlement with 1-800-Flowers shows that recurring billing becomes a legal control problem when disclosure, acknowledgment, and reminder logic drift. OpenAI's Presence launch makes the AI lesson even clearer: agent systems need approved actions, escalation rules, and visible policy boundaries before they scale. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

July 17, 20268 min

This Week's SMB Risk Signals: Router Hygiene, Genetic Data, and Agentic AI

On July 13, 2026, CISA and a broad coalition of U.S. and allied agencies warned that Russian state-sponsored actors continue to exploit poorly configured routers across six critical sectors, often by abusing legacy SNMP settings and exposed management paths. On July 14, 2026, a 42-state coalition secured an $18 million settlement from 23andMe after a breach that affected 6.9 million consumers and exposed how weak multifactor authentication, weak monitoring, and vague deletion controls fail under pressure. Also on July 14, 2026, OpenAI argued that agentic AI investments should be measured by useful work per dollar and governed before advanced workflows scale. These are not three unrelated headlines. They are one operating problem. The systems you trust most now need explicit credentials, evidence, and approval paths. If a router can quietly hand over configuration data, if a sensitive-data platform cannot prove its basic safeguards were reasonable, or if an AI workflow scales before you can define who approves risky actions, the business is still running on trust it has not recently re-earned 1. Router Hygiene Still Decides Whether an Adversary Gets a Shortcut The July 13 advisory matters because it is not about exotic zero-days. It is about weak operational hygiene on devices that sit close to identity, routing, and network control. CISA said the actors primarily scan for poorly configured networking devices, especially routers, and use SNMP weaknesses, Cisco Smart Install, and exposed management portals to get what they need. Why You Should Be Concerned: * Six sectors were named: Communications, defense industrial base, energy, financial services, government services, and healthcare were identified as the highest-risk sectors, which is a reminder that routers stay business-critical even when they feel invisible. * Legacy settings are still the entry point: The advisory says the actors look for SNMP agents that accept common or default community strings, then use those settings to copy device configurations and send them off-network. * Credential quality is part of network defense: The mitigation guidance specifically calls for strong, unique passwords, secure storage, and local accounts used only for emergencies. Strategic Action: Treat routers, firewalls, and network-device management paths as privileged systems, not background plumbing. If you cannot name who owns their credentials, firmware cadence, and emergency access path, you do not yet control the trust boundary they create. This Week’s Leadership Move: * Confirm which routers, switches, and firewalls still allow SNMPv1, SNMPv2, or broad management access from outside your management network. * Require a named owner for every privileged network-device credential and rotate any password that is shared in tickets, notes, or chat history. * Ask your MSP or network partner to show whether Cisco Smart Install is disabled and which management ports remain externally reachable by exception. To prevent router and infrastructure credentials from quietly becoming shared liabilities, 1Password helps teams keep privileged access unique, auditable, and easier to rotate without passing secrets via email, notes, or tickets. Affiliate sponsor 2. The 23andMe Settlement Raises the Floor for Sensitive-Data Discipline The legal lesson from July 14 is not limited to genetic testing. It is about what regulators and attorneys general may now treat as the minimum reasonable standard when a company stores highly sensitive customer data. The 23andMe case turned a breach into a broad indictment of basic control failures. Why You Should Be Concerned: * The numbers are large and specific: The settlement announcement says the breach affected 6.9 million consumers, with some customer data later offered for sale on the dark web. * Basic safeguards were part of the case: New York’s attorney general said investigators found failures around breached-password blocklists, multifactor authentication, rate limiting, logging, monitoring, unusual-login review, and known-vulnerability remediation. * Deletion rights stayed on the table: The settlement also preserved consumer deletion rights and added new security expectations for the successor organization handling the data. Strategic Action: If your business stores health, payroll, identity, or customer-record data, assume a future regulator, insurer, or board member will ask whether your basic safeguards were visible, enforced, and tested before the incident. I know many SMB teams inherit sensitive-data platforms without a clean map of who owns account protections, retention settings, or breach detection. That is exactly why the control story has to be explicit now, before an incident writes it for you. This Week’s Leadership Move: * Enforce multifactor authentication on every admin and customer-support role that can view or export sensitive records. * Check whether your identity stack blocks known breached passwords and alerts on repeated login spikes, not just outright lockouts. * Test your delete, export, and incident-review workflow on one real system this week so you know who approves, who documents, and who confirms completion. SENSITIVE DATA FAILURES ARE ALSO OPERATING FAILURES The 23andMe settlement shows how quickly missing logs, weak credential controls, and unclear deletion rights become part of the legal record. If your controls exist only as assumptions, they will not hold up under investigation. Noted.Solutions is a stronger fit when your team needs to explain compliance controls, evidence expectations, and risk outcomes in language buyers and stakeholders actually understand instead of repeating generic trust claims. Sharpen the compliance narrative. Explore Noted.Solutions Affiliate sponsor 3. Agentic AI Should Be Measured by Accepted Work, Not Excitement OpenAI’s July 14 guidance is useful because it frames AI modernization as an operating-model decision rather than a model-shopping exercise. It says leaders should judge AI by useful work per dollar: tasks completed, time saved, decisions improved, and workflows ready to scale. Why You Should Be Concerned: * Model economics are moving fast: OpenAI says the price per million tokens fell 97% from GPT-4 to GPT-5.4, while GPT-5.6 delivered 54% fewer output tokens and 57% less time per task in the cited coding-agent index. * Cheap is not the same as effective: The guidance warns that the lowest token price can still lead to the highest total cost if the workflow fails, retries, or requires extensive correction. * Governance is the operating layer: OpenAI says leaders need to define what context AI can use, which tools it can access, what actions it can take, and who approves higher-risk steps before advanced workflows scale. Strategic Action: Do not scale agentic AI because it looks impressive in a demo. Scale the workflows where you can define the quality bar, the approval boundary, the evidence trail, and the cost of an accepted outcome. This Week’s Leadership Move: * Choose one workflow where AI can draft or review, but cannot complete the action without named human approval. * Measure the cost per accepted outcome rather than the raw token cost or time spent in the tool. * Document which data the workflow can access, who can raise limits, and which event triggers manual review. Final Thoughts for Leaders Router hygiene, sensitive-data liability, and agentic AI governance all point to the same truth: the systems with the most leverage deserve the clearest ownership. The question is not whether these tools are useful. The question is whether you can prove who controls the credentials, who preserves the evidence, and who approves the action when the stakes rise. Put one item on next week’s agenda: list the systems in your business that can quietly change access, expose sensitive data, or automate work across tools, and assign a credential owner, an evidence owner, and an approval owner to each one. If another operator on your team needs this framing, use the share and referral tools below before the premium section. Help Other Leaders Secure Their Future The Network Effect of SMB Security The most effective way to strengthen our SMB community is by sharing the strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone’s business. Why Share This Subscription? When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team: * Zero-fluff technical execution: No high-level theory, just the steps to implement. * Cost-saving vendor analysis: An honest look at which tools are worth the SMB budget. * Direct coaching frameworks: Access to the same logic I use with private coaching clients. Pay It Forward. Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace. You’ve seen the "Why" behind this [Cyber/Tech Issue]—but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan. The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock: * The “How-To” Framework: A step-by-step breakdown of the [Process/Tool] mentioned above. * Resource Toolkit: Downloadable templates and checklists I use with my private coaching clients. * The Bottom Line: Direct analysis of the ROI and cost-savings associated with this strategy Subscribe to Unlock the Full Strategy Join a community of SMB leaders who stop reacting to tech shifts and start leading them. Premium Intelligence: The Trusted Systems Control Pack Welcome, premium subscribers. This section turns the three public signals into an implementation pack you can use with a lean team, an MSP, or a cross-functional leadership group. The goal is not more commentary. It is better to control ownership, better evidence, and faster decisions under pressure. 1. Router Hygiene Deep Dive: Privileged Network Paths Technical Detail: The July 13 joint advisory says the actors primarily scan for routers with active SNMP agents that accept common or default community strings, then instruct those devices to copy configurations and send them to actor-controlled infrastructure. The mitigation section calls for disabling Cisco Smart Install, using SNMPv3 with authPriv , replacing legacy SNMP versions, restricting management protocols, and limiting local accounts to emergency use. Specific controls to check this week: Disable Cisco Smart Install; move from SNMPv1 and SNMPv2 to SNMPv3 where supported; confirm management traffic is restricted to management devices or an out-of-band network. Port review: Unless business-critical, review external exposure on UDP 69, TCP 4786, UDP 161 and 162, and TCP or UDP 10161 and 10162. Credential practice: Use strong, unique local credentials and confirm whether any network passwords are still recoverable from notes, config exports, or ticket history. Monitoring question: Ask what alert fires if a device begins sending configuration-copy activity or unusual SNMP set requests. 2. Sensitive-Data Liability Deep Dive: 23andMe as a Minimum-Control Case Technical Detail: The July 14 settlement says investigators found failures to use breached-password blocklists or require multifactor authentication, failures in rate limiting and intrusion prevention, failures in logging and monitoring, failures to address unusual login spikes, and failures to remediate known vulnerabilities. Those findings make the case useful as a minimum-control benchmark for any SMB that stores sensitive personal data. Authentication baseline: Admin and customer-support roles touching sensitive data should require phishing-resistant MFA where feasible and should block known breached passwords. Detection baseline: Logins, password-reset attempts, suspicious export behavior, and sudden bursts of failed authentication should be visible in one place and reviewed by a named owner. Data-rights baseline: Test consumer or employee deletion, correction, and export flows like incident-response controls, not like documentation footnotes. Board-ready framing: If asked what “reasonable safeguards” looked like before an incident, can you show evidence for MFA enforcement, password hygiene, rate limiting, monitoring, and vulnerability remediation? 3. Agentic AI ROI Deep Dive: Cost Per Accepted Outcome Technical Detail: OpenAI’s July 14 guidance says leaders should evaluate AI by useful work per dollar, not token price alone. It recommends visibility into usage and spend, evaluation against real tasks, cost per accepted outcome, governance before advanced workflows scale, and funding that follows workflow maturity instead of hype. Useful-work metric: Define one accepted outcome. Examples: a support case fully resolved, a change request approved, a vendor review completed, or a customer draft accepted without rework. Workflow boundary: Separate workflows into advisory-only, draft-and-review, and permissioned execution. Do not let one approval rule cover all three. Governance layer: Record what context the workflow can see, which tools it can call, what approvals it needs, and what retention posture applies. Expansion rule: Raise limits only after the workflow meets the quality bar, shows stable demand, and has a clear business owner. AGENTS ARE ONLY AS SAFE AS THE CONTROLS AROUND THEM Agentic AI becomes useful when it can see context, use tools, and move work forward. It becomes risky when approvals, tool boundaries, and data access stay implicit. Airia is built for organizations that need governed AI orchestration, explicit controls, and clearer boundaries around where agents can and cannot act. Put guardrails around agentic work. Explore Airia Affiliate sponsor Premium Template: Privileged System Control Register Use this register for any system that can grant access, expose sensitive records, or automate work across business tools. System or workflow name: The exact platform, service, or automation. Why it is trusted: What access, data, or decisions it can influence. Credential owner: Who controls privileged authentication and rotation? Evidence owner: Who preserves logs, approval records, or export history. Approval owner: Who can authorize risky changes or emergency overrides? Control cadence: Patch review, access review, deletion review, or workflow evaluation frequency. Rollback path: What stops the action, and how do you recover if the trusted system fails? Premium Checklist: Sensitive-Data Minimum Safeguards * Require MFA for every admin or support role that can view, export, or modify sensitive records. * Block known breached passwords and review how the blocklist is enforced. * Confirm that rate limiting, suspicious-login review, and export monitoring are actually enabled. * Name the owner for delete, export, and correction requests on sensitive-data platforms. * Test one deletion or export workflow this week and save the evidence. * Review which vendors or MSPs still retain privileged access to the platform. Premium Guide: Seven-Day Trusted Systems Sprint Day 1: Inventory the high-leverage systems List every router, identity platform, sensitive-data system, and AI workflow that can materially change access, privacy, or operations. Day 2: Assign the three owners For each item, name the credential owner, evidence owner, and approval owner. If a system has no answer, flag it as a business risk immediately. Day 3: Verify the control baseline Check legacy protocols, MFA coverage, password-policy enforcement, logging, and rate limiting. Write down what is confirmed versus assumed. Day 4: Review vendor and MSP access Document who outside the business can still log in, rotate credentials, approve changes, or export records. Day 5: Pilot one AI workflow with limits Choose one bounded workflow, define the accepted outcome, and keep the workflow in draft-or-review mode only. Day 6: Run the tabletop Ask what happens if the trusted system fails quietly: the router leaks configuration, the customer data platform misses unusual logins, or the AI workflow acts beyond its intended scope. Day 7: Report the gaps Deliver a one-page summary showing the systems reviewed, the named owners, the unresolved gaps, and the next remediation date. Premium Exercise: Tabletop for the System You Trust Too Easily Tabletop Exercise: The Quiet Failure Premise: A network-device partner confirms that a remote-management setting was left broader than intended. On the same day, your customer-data platform shows repeated login spikes, but no one knows who owns the alert review. Meanwhile, an AI workflow has started drafting customer responses, with access to internal notes, and it wants broader tool permissions. Exercise Goal: Test whether your team can identify the credential owner, evidence owner, approval owner, and stop condition for each system before the issue becomes a public incident. Use this exercise to expose where ownership is assumed, where logs are not preserved, and where AI convenience is outrunning governance. Sources * CISA, “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,” July 13, 2026 * New York Attorney General, “Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data,” July 14, 2026 * OpenAI, “How to manage AI investments in the agentic era,” July 14, 2026Join a community of SMB leaders who stop reacting to tech shifts and start leading them. This post has bonus content for paid subscribers. Upgrade to get full access. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

July 10, 20268 min

Can Your Security Tools, Cameras, and Agents Prove Their Work?

A free CPF Coaching audio briefing on Cisco ISE trust risk, retail privacy controls, and AI-assisted hardening that still requires human approval. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

July 3, 202611 min

SMB Cyber Risk: Securing the Control Plane and Agentic AI

This week on SMB Risk, Chris Foulon breaks down control-plane risk for SMB leaders: CISA KEV activity, exploited SharePoint and remote-support tools, automated-decision compliance, and agentic AI governance. Learn how to spot systems that can act across your business, set a 72-hour response rule, build an automated-decision register, and define where AI can advise, draft, or execute. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

June 26, 20264 min

Stolen Logins, AI Agents, and $450K Regulatory Fines

What inside your business can act before a human verifies it? This week, we dive into the convergence of three major tech shifts: the modular infostealer economy, costly regulatory enforcement after ransomware, and the mainstream arrival of computer-using AI agents like Gemini 3.5 Flash. If you lead tech or cybersecurity for an SMB, this episode provides a localized execution plan to bridge the gap between risk awareness and actual protection. We cover: Cyber Threats: Why treating browsers, endpoints, and admin sessions as a single identity risk surface is critical to stopping credential theft. Compliance: How to build an evidence trail that satisfies regulators (like HHS OCR) before a ransomware incident occurs. AI Governance: Setting up "advise, draft, and act" lanes for AI to prevent unverified execution. Listen in for the 3 steps you need to take this week to secure your unverified workflows. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

January 31, 20266 min

5 Critical Security Alerts from Last Week: Copilot Bugs, Bluetooth Hacks, and New Privacy Laws

January 2026 Alert: Critical Microsoft Copilot vulnerability (Reprompt), Bluetooth "WhisperPair" exploit affecting Sony/Google devices, and new privacy laws in IN, KY, & RI. Get the executive summary and 30-day mitigation plan for SMBs. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

January 9, 20266 min

AI, Identity, and Breaking Into Cyber: CEO Jasson Casey’s Blueprint for Success

From building software to defending it: Jason Casey (CEO, Beyond Identity) shares his journey from Software Engineer to Cybersecurity Expert. Discover why mastering network protocols and engineering fundamentals is the secret to a successful cyber career. Listen now on Breaking into Cybersecurity. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

January 9, 202611 min

The Glass House: Why 2026 is the Year We Must Audit Our "Agents" and "Avatars"

CES 2026 changed the threat landscape. From "Superuser" AI agents to "cute" surveillance robots like Mirumi, we outline the top 4 trends SMB tech leaders must address immediately to secure their organizations. This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit substack.cpf-coaching.com/subscribe

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Business podcasts