• Skip to main content
  • Skip to primary sidebar
  • Home
TechTidBit – Tips and advice for small business computing – Tech Experts™ – Monroe Michigan

TechTidBit - Tips and advice for small business computing - Tech Experts™ - Monroe Michigan

Brought to you by Tech Experts™

The Threats Hiding In The Tools You Use Every Day

August 17, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

How do you imagine a cyberattack? A sophisticated hacker breaking through layers of security? Using advanced tools that no regular business could possibly defend against?

The reality is usually way less glamorous.

Many breaches start with something small. A forgotten account that was never removed. A laptop that missed an update. A security setting that was switched off and never switched back on.

These are the kinds of gaps attackers actively search for because they’re far easier to exploit than forcing their way through a heavily protected system.

In other words, the danger often comes from the things nobody realized were a problem.
One of the biggest changes in cybersecurity right now is the growing focus on identities.

Instead of attacking systems directly, criminals increasingly target usernames and passwords.

Once they gain access to a legitimate account, they can move through a business much more easily because, from the outside, it looks like a normal user logging in.

That can happen surprisingly quickly. In some cases, ransomware attacks have escalated within hours of the initial breach.

The challenge is that modern businesses are complicated. Staff work remotely. Devices move between home and office.

New software gets introduced. Small gaps appear naturally, unless someone is constantly monitoring them.

Even security tools themselves can become blind spots.

You may have protection installed, but if it is misconfigured, outdated, or partially disabled, it creates a false sense of security. Attackers also rely heavily on something known as “living off the land” techniques.

This means using legitimate tools already built into Windows and Microsoft 365 to carry out malicious activity.

Because those tools are commonly used by IT teams every day, suspicious behavior can blend into normal activity more easily.

Artificial intelligence is likely to accelerate this problem.

AI tools can help criminals identify weaknesses faster, automate attacks, and adapt techniques more quickly than before.

But many of the most effective protections are the basics done well.

Strong passwords, multi-factor authentication, regular updates, controlled access permissions, and ongoing staff awareness training remain some of the strongest defenses available.

If you’d like help spotting and closing small security gaps before somebody else finds them, get in touch.

It’s Happening, Whether You Like It Or Not

August 17, 2026

AI tools are becoming a normal part of the working day.

Someone uses one to tidy up a report. Someone else asks a chatbot to summarize meeting notes. A team member installs an AI browser extension because it helps them work faster.

Most of this happens with good intentions.

But some businesses have no visibility of it at all.

This is known as “shadow AI”.

It describes employees using AI tools that haven’t been approved, reviewed, or properly managed by the business.

In many ways, it’s like shadow IT, where staff adopt their own software without involving the IT team.

The difference is that AI tools can interact with company information in deeper ways.

Employees may paste confidential documents into public chatbots, connect AI assistants to email accounts, or allow AI tools to access files and calendars without fully understanding what happens to that data afterwards.

The motivation is easy to understand. These tools save time, reduce admin, help people get through work more efficiently.

So, banning AI outright rarely works.

If employees feel the tools genuinely help them, they often continue using them secretly. At that point, the business loses even more visibility and control.

The better approach is usually to accept that AI is now part of modern work, then guide people towards safer, approved options.

Newer AI systems are becoming more capable very quickly. Tools are no longer limited to generating text or summaries.

They can search files, access systems, organize information, trigger workflows… and even carry out actions automatically.

Without proper oversight, that creates obvious security and compliance concerns.

For businesses using Microsoft 365, approved tools like Copilot offer a safer route because they sit inside existing permissions and security controls.

That doesn’t remove risk completely, but it does give businesses much better visibility over how AI is being used.

Whatever tools you’re using, the important thing is not to ignore the issue.

If you need better oversight on how your team is using AI tools, we can help. Get in touch.

SIM Swapping: How Hackers Steal Your Phone Number

August 17, 2026

One morning, your phone drops to “No Service” and stops receiving calls and texts. You assume it’s a network glitch and you get on with your day.

But across town, someone has just convinced your mobile carrier that they’re you.

They’ve moved your number onto a SIM card sitting in their own phone.

Every call and text meant for you now goes to them, including the security codes that protect your email and your bank logins.

This is a SIM swap. The attacker never touches your password or breaks into a single system. They take over your phone number, then use it to reset everything attached to it.

They start by gathering a few details about you, often pulled from an old data breach or your social media.

Then they call your carrier, claim your phone was lost or damaged, and ask to activate your number on a new SIM. If the agent believes the story, your number is theirs in minutes.

From there, the SMS codes you rely on become their codes (SMS is the text message system most accounts use to send those one-time login codes). Password reset links and login verifications all land on their device instead of yours.

Researchers at Princeton University tested five major US carriers by posing as customers and trying to move numbers they didn’t own. They succeeded on 80% of their first attempts, mostly because the carriers were leaning on security questions a motivated attacker could answer.

The losses reported to the FBI run into the tens of millions of dollars a year, and the true figure is almost certainly higher, because most victims report the end result, like a drained account, rather than the phone takeover that caused it.

Your personal mobile number is probably the recovery method for nearly everything you log into, from your Microsoft 365 account to your business bank.

If that one number falls into the wrong hands, a lot can fall with it.

Don’t panic though. This is very fixable, and the setup is quick and free:

Lock your number with your carrier

Every major provider now offers a free toggle that blocks anyone from moving your SIM or porting your number without your say-so.

Move your important logins off text-message codes

For your email, banking, and admin accounts, switch from SMS codes to an authenticator app or a passkey.
Both keep working even if someone steals your number because the approval happens on your device, not through your phone signal.

Add a separate passcode to your carrier account.

Most carriers let you set a PIN or passcode that’s required before any change is made to your account. It’s one more wall between an attacker and your number.

Many carriers now send a text or email alert when someone requests a SIM change on your account. If that alert shows up and it wasn’t you, call your carrier right away.

If you’d like a hand checking which of your accounts still rely on text-message codes, or help locking down your team’s numbers, just reply and we’ll walk you through it.

The Employee Who Left Six Months Ago Still Has Access

August 17, 2026

When someone leaves your company, you probably collect their keys, take back the laptop, and shut off their email. Job done, right?

Not quite.

Over the years, most employees pick up access to more systems than anyone tracks. There’s Microsoft 365, your accounting software, your CRM, cloud storage, payroll, vendor portals, remote access tools, and shared mailboxes.

Then there are the accounts nobody remembers: a Canva login someone set up for marketing, a Facebook page a former employee managed, a Dropbox folder shared with a manager years ago, an app someone connected to their Microsoft 365 account and forgot about.

The employee leaves, their email gets disabled, and everyone assumes their access went with it. It often doesn’t.

What is access creep

Access creep happens when employees pick up new permissions as they change roles, but the old ones never get removed.

Someone starts in customer service, moves to sales, and eventually becomes a manager. Each job change adds new access. Rarely does anyone go back and take the old access away.

After five years, that employee may be able to reach far more of your business than their current job requires. When they leave, all of that access leaves the building with them, at least on paper. In reality, it usually stays right where it was.

Offboarding needs to be a process, not a checklist item

Turning off someone’s email is a start, but it only closes one door. What about the cloud app they logged into with a separate password? The vendor site where their account is still active? The shared password they know? The company social media account they had the keys to?

Offboarding works best when it starts before the employee’s last day.

Someone should know which systems they can reach, which devices they hold, which passwords or codes they know, and whether they have access to any shared accounts.

From there, equipment gets returned, individual accounts get disabled, shared passwords get changed, remote access gets pulled, and email forwarding or delegation gets reviewed.

Don’t forget the accounts your IT provider doesn’t manage directly. Your bookkeeper may have logins for banking or payroll.

A salesperson might hold customer portal credentials. Whoever runs your marketing may control social media accounts, your website, ad platforms, or your email marketing tool. Those accounts need the same attention.

The account nobody is watching is the one that gets hacked

Most former employees have no interest in logging back into your systems. That’s not the real risk. The real risk is that their old account is still sitting there, active and unused. If that account gets compromised months or years later, an attacker may find it still opens the door to your business. Nobody notices, because nobody remembers the account exists. That makes forgotten accounts an easy target.

Don’t wait until someone leaves

Access should match the job. When someone’s role changes, their access should change with it.

A periodic review of who can reach what often turns up old accounts, admin permissions nobody needs anymore, forgotten vendor logins, and software nobody uses. You might be surprised by what’s still active.

Ask yourself this: if you made a list today of everyone who can access your company’s systems and data, could you say for certain that everyone on that list still belongs there?

If your honest answer is “I think so,” it’s worth a closer look.

Give us a call for a no-charge, no-obligation review of your user accounts and access, and we’ll help you build a process that covers employees joining, changing roles, and leaving for good.

The Inbox Hiding Place You Don’t Think To Check

July 21, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

If a hacker got into your email account, you would probably do the obvious thing and change your password right away. That is a good instinct. But it does not always solve the problem.

There is a small feature buried in your inbox settings that attackers use to stay hidden long after you have locked them out. It is called an inbox rule, and most business owners have no idea it exists.

What is an inbox rule?

An inbox rule is a setting that automatically moves emails into folders, flags certain messages, or forwards them to another address. You may already use rules to keep your inbox organized, sorting invoices into one folder and newsletters into another.

That same feature is exactly what makes it so useful to a criminal.

How attackers use inbox rules against you

When someone breaks into an email account, one of the first things they often do is create a hidden rule of their own. These rules can quietly forward copies of your emails to an outside address, move important messages out of your main inbox, or mark them as read so you never notice them arrive.

This happens fast. In many cases, attackers set up these rules within seconds of gaining access, before you even know anything is wrong.

That speed gives them a real advantage. With a hidden rule in place, an attacker can read your conversations, pull out sensitive information, and hide the security alerts that would normally tip you off. If they are after your finance team or leadership, they can also sit back and watch for the right moment to reroute a payment.

Here is the part that catches most people off guard: changing your password does not remove these rules. If you reset your password but skip this step, the attacker may still be reading everything that comes into your inbox.

How to check for hidden inbox rules

The good news is that this is easy to check once you know where to look. Every inbox rule has a name, and one that looks strange, generic, or unfamiliar is worth a closer look. Take a few minutes to review your rules periodically, and always check them right after any suspected security issue.

You do not need advanced technical skills to do this. Most email platforms list all active rules in one settings screen – anything you did not create yourself should raise a flag.

The takeaway

Modern cyberattacks do not always rely on complicated hacking techniques. Sometimes they simply use a feature that is already sitting inside your inbox, working exactly as it was designed to, just for the wrong person’s benefit. A quick habit of checking your inbox rules can close a gap that a password reset alone will not. If you would like a hand making sure your business email is locked down the right way, give us a call.

Those Little Jobs Add Up… Delegate Them To AI

July 21, 2026

When people think about AI at work, they often imagine things like writing reports, analyzing data, or answering emails.

That’s useful, of course. But it’s not where most of your time goes.

In a typical working day, it’s the smaller jobs that really slow things down. Following up after meetings, tidying documents, fixing spreadsheets, chasing information.

They’re not difficult, but combined, they eat into hours you’d rather spend elsewhere.

This is where tools like Microsoft Copilot are becoming genuinely helpful.

Take meetings as an example. The real time cost usually comes afterwards. Notes need checking, actions need confirming, and anyone who missed the call needs catching up.

Copilot in Teams can summarize discussions in a more practical way, pulling out decisions, highlighting what still needs doing, and helping people get straight to the important points.

It’s a similar story with writing.

Most people aren’t staring at a blank page. They’re trying to improve something that already exists. A draft might be too long, unclear, or not quite right for the audience.

Copilot can reshape that content, tighten it up, and adjust the tone without you having to rewrite everything from scratch.

Spreadsheets are another common frustration.

You know what you want the outcome to be but remembering how to get there isn’t always straightforward.

Instead of searching for formulas or watching tutorials, you can describe what you need in plain language and let Copilot handle much of the process.

Microsoft has also started bringing everything together more effectively.

Shared pages and notebooks mean ideas, notes, and files don’t end up scattered across different tools.

It becomes easier to keep projects moving without constantly switching between apps.

And for those repetitive tasks that crop up every day, simple workflows can now be created just by describing the process.

Routine updates, reminders, and approvals can run in the background without needing manual input each time.

As a reassurance, this isn’t to replace people. It’s to remove the small points of friction that build up during the day.

When those start to disappear, work feels smoother, and your team can focus more on the things that move the business forward.

If that sounds like something you’d like to learn more about, we can help. Get in touch.

The 4-Step Legacy IT Debt Audit Your Business Needs

July 21, 2026

Legacy systems and outdated technology create hidden costs that drain your budget and slow your business down.

If you’re running software that hasn’t been updated in years, relying on hardware past its prime, or patching together workarounds to keep things running, you’re carrying technical debt.

According to TechTarget, “A technical debt audit involves systematically identifying, assessing, and prioritizing areas of technical debt within an organization’s IT landscape. This process helps organizations understand the scope and impact of their debt, enabling them to create a strategic plan for remediation.”

Here’s how to conduct a practical audit of your legacy IT systems.

Inventory your current IT assets

Start by creating a complete list of every system, application, and piece of hardware your business uses. Include the age of each asset, its current version, the vendor’s support status, and who depends on it daily.

This isn’t just about servers and computers – document your software licenses, cloud subscriptions, and any custom applications built years ago that still run critical processes.

Assess business impact and risk

For each item in your inventory, evaluate how it affects your operations. Ask: What happens if this system fails tomorrow? Does it handle sensitive customer data? Is it connected to other critical systems?

CIO.com emphasizes that “assessing the impact of technical debt on business operations” and “prioritizing remediation efforts based on risk and value” are essential steps in managing technical debt effectively.

Systems that pose security risks or could halt business operations should rise to the top of your priority list.

Calculate the true cost of keeping it

Legacy systems cost more than their maintenance contracts. Factor in the staff time spent on workarounds, the productivity lost to slow performance, the security vulnerabilities that put you at risk, and the opportunities you’re missing because your systems can’t support new capabilities.

Compare these ongoing costs against the investment required to modernize or replace the system.

Create a prioritized remediation roadmap

Based on your risk assessment and cost analysis, build a realistic plan for addressing your technical debt. Some systems may need immediate replacement while others can be phased out gradually.

Budget for both quick wins that deliver immediate value and longer-term projects that address foundational issues.

Set clear timelines, assign ownership, and establish metrics to track your progress.

If you’d like help conducting a thorough legacy IT audit or developing a modernization strategy that fits your budget and timeline, contact us to discuss your specific situation. You can give us a call at (734) 457-5000, or email us at info@mytechexperts.com.

The Hidden Cost Of “Just This One Time”

July 21, 2026

Most technology problems do not begin with a major failure. They start with a small shortcut.

An employee needs to send a large file, so they upload it to a personal cloud storage account. Someone forgets their laptop charger and borrows a family computer to finish a proposal. A manager shares a password with a coworker because it is quicker than creating a new login.

Each decision seems harmless on its own. After all, everyone is just trying to get their job done.

The trouble is that these “just this once” moments have a habit of becoming everyday habits.

Over time, businesses end up with important files scattered across personal accounts, passwords shared between multiple employees, and sensitive information stored in places that were never meant for business use. Nobody intended to create a security risk. It simply happened one shortcut at a time.

This is one of the biggest challenges we see when working with small businesses.

Most owners invest in firewalls, antivirus software, and secure backups. Those are all important. But even the best technology cannot protect information that has quietly drifted outside of your managed systems.

Imagine an employee leaves your company. If company files are stored in their personal cloud account, do you still have access?

If customer contacts are saved on a personal phone, can you retrieve them? If passwords were shared through text messages or sticky notes, how many accounts need to be changed?

These situations create unnecessary stress during what is already a busy time.

The same problem appears when businesses begin to grow.

What works for five employees often breaks down at fifteen or twenty. New staff members need access to files. Teams need to collaborate. Managers need confidence that information is protected without slowing everyone down.

That is why consistency matters. Instead of asking employees to figure out the best way to share files or store documents, give them one approved method and encourage everyone to use it. Instead of sharing passwords, use a password manager that allows secure access without exposing the actual password. Instead of allowing business information to spread across personal devices and accounts, keep it inside systems that your business owns and controls.

The goal is not to make work more complicated. It is to remove uncertainty.

Employees generally want to do the right thing. If the secure option is also the easiest option, people will naturally follow it.

This is also a good reminder to review your business processes every so often. Ask yourself a few simple questions. Where are our important files stored? Who has access to them? Are we relying on personal accounts for business work? Would someone else be able to find what they need if a key employee was away for a week?

You might be surprised by the answers.

Small improvements made today can prevent much larger problems later. Better organization, clearer processes, and a few sensible security practices can save hours of frustration while reducing your risk at the same time.

Technology should make running your business easier, not leave you wondering where your information is or who can access it.

If you are not sure whether your business has developed a few “just this once” habits over the years, we would be happy to help you take a closer look. Sometimes the biggest improvements come from fixing the small things before they become expensive problems.

Can Someone Hack Your Email Without The Password?

June 22, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

Most people assume an email hack starts with a stolen password. That’s not always true.

Yes, weak and reused passwords are still a major problem. But many modern email attacks work around the password entirely. Hackers are not always sitting in a dark room trying to guess your login. More often, they are tricking someone or slipping into the account through a connected app.

That is why email security cannot stop at “we have strong passwords.”

Your email is one of the most valuable keys to your business. Think about how many systems connect back to it: banking alerts, payroll, Microsoft 365, and cloud storage.

If a criminal gets into your inbox, they may be able to reset passwords for other accounts, read private conversations, and watch how money moves through your company.

One common trick is phishing. An employee receives what looks like a normal Microsoft login. They click the link, enter their information, and the attacker captures what they need.

Another method is account recovery abuse. If recovery options are weak, outdated, or tied to a personal phone number or email account, criminals may use that path to regain access. They do not need the current password if they can convince the system to issue a new one.

One we see far too often is email forwarding rules. A hacker gets access briefly, creates a hidden rule that forwards copies of messages to an outside address, then quietly leaves. From that point on, they can study invoices, customer emails, and payment patterns.

They may wait weeks before making their move. That is how business email compromise happens. A criminal watches a real conversation, then jumps in at the right time with fake banking instructions, a changed invoice, or an urgent request from someone who appears to be the owner or manager.

By the time anyone notices, the money may already be gone. So what should you do?

First, use multi-factor authentication on every email account. Not just the owner. Not just the office manager. Everyone. Email is the front door to your business, and one unprotected account is enough to create a serious problem.

Second, use strong, unique passwords and a password manager. Reusing the same password across personal and business accounts is asking for trouble.

Third, review email forwarding rules and login activity regularly. Strange logins, unexpected reset messages, missing emails, or messages in the sent folder that no one remembers sending are all warning signs.

Fourth, train your staff to slow down. Criminals rely on rushing people. A payment change, password alert, or “urgent” document should always be verified through a second channel.

Finally, ask your IT provider for proof. Are all users protected by MFA? Are suspicious logins monitored? Are old accounts removed quickly when employees leave? Are email rules being checked?

Email attacks do not always require a stolen password. Sometimes they only require one missed setting, one rushed click, or one account no one is watching.

The good news is that most of this risk can be reduced with practical, proven controls. Not scare tactics. Just the basics done consistently. And in cybersecurity, the basics done well still matter.

Where Are Your Cloud Files Really Going?

June 22, 2026

When people talk about “moving to the cloud,” it can sound like a single decision. But there are a few different ways to do it. The right choice depends on how your business works.

At its simplest, cloud storage means your data isn’t stored on a single computer or server in your office.

Instead, it’s stored in secure data centers run by providers (like Microsoft) and accessed over the Internet.

That’s what allows you to open files from anywhere, share them instantly, and collaborate in real time.

But not all cloud setups are the same. The most common approach is what’s known as the public cloud.

This is where your data is stored on shared infrastructure managed by a provider. Tools like Microsoft 365 and OneDrive fall into this category.

You’re effectively renting space in a highly secure, always-available environment without needing to maintain any hardware yourself.

At the other end of the spectrum is private cloud. This is where the infrastructure is dedicated to your business, either hosted on-site or in a data center.

It offers more control and can be useful for organizations with specific security or compliance requirements. But it also comes with more responsibility and cost.

Some businesses sit somewhere in the middle with a hybrid setup.

That might mean everyday files and collaboration tools live in the public cloud while more sensitive systems or data are kept in a private environment. It gives you flexibility to balance accessibility, control, and risk.

Whichever route you take, the benefits tend to be similar:

  • Your team can access what they need from anywhere
  • You can scale storage up or down without buying new equipment
  • And your data is protected by enterprise-grade security, including encryption and multiple backups across different locations

The important thing is that “the cloud” isn’t a one-size-fits-all solution.

The way it’s set up should reflect how your business operates, what data you handle, and how your team works day to day.

If you’re not sure whether your current setup is right, or you’d like a clearer picture of the options available, we can help. Get in touch.

Next Page »

Primary Sidebar

Browse past issues

  • 2026 Issues
  • 2025 Issues
  • 2024 Issues
  • 2023 issues
  • 2022 Issues
  • 2021 Issues
  • 2020 Issues
  • 2019 Issues
  • 2018 Issues
  • 2017 Issues
  • 2016 Issues
  • 2015 Issues
  • 2014 Issues
  • 2013 Issues
  • 2012 Issues
  • 2011 Issues
  • 2010 Issues
  • 2009 Issues
  • 2008 Issues
  • 2007 Issues
  • 2006 Issues

More to See

It’s Happening, Whether You Like It Or Not

August 17, 2026

SIM Swapping: How Hackers Steal Your Phone Number

August 17, 2026

The Employee Who Left Six Months Ago Still Has Access

August 17, 2026

The Inbox Hiding Place You Don’t Think To Check

July 21, 2026

Tags

AI Antivirus backups Cloud Computing Cloud Storage COVID-19 cyberattacks cybersecurity Data Management Disaster Planning Disaster Recovery E-Mail Facebook Firewalls Hard Drives Internet Laptops Maintenance Malware Managed Services Marketing Microsoft Network online security Passwords password security Phishing planning Productivity Ransomware remote work Security Servers smart phones Social Media Tech Tips Upgrading Viruses vulnerabilities Websites Windows Windows 7 Windows 10 Windows Updates work from home

Copyright © 2026 Tech Experts™ · Tech Experts™ is a registered trademark of Tech Support Inc.