• Skip to main content
  • Skip to primary sidebar
  • Home
TechTidBit – Tips and advice for small business computing – Tech Experts™ – Monroe Michigan

TechTidBit - Tips and advice for small business computing - Tech Experts™ - Monroe Michigan

Brought to you by Tech Experts™

The First Question I Ask Every New Client

September 21, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

When I sit down with a new client for the first time, I don’t start by asking what software they use or what their network looks like.

I ask one simple question: When was the last time you actually tested your backup?

Not “do you have a backup.” Almost everyone says yes to that. I mean REALLY tested, like we do at Tech Experts. Restore a file, open it, and make sure the contents are really there.

The answer tells me more about a business’s real risk than almost anything else I could ask. Most of the time, people pause.

They know backups are running and they’ve seen the “green checkmark” or the automated email confirming success. What they haven’t done is actually try to get their data back.

The action of making sure the backups are restorable matters more than people realize. A backup that runs every night but has never been tested is really just a hope, not a plan.

I’ve seen businesses discover their backups were incomplete, corrupted, or hadn’t run properly in months, and they only found out when they needed the files most, or when disaster struck.

By then, it’s too late to fix quietly. It becomes a crisis instead of a non-event.

The second question I ask

Once we’ve talked about backups, I ask something else: who can see what on your network?

This one usually gets a longer pause. Most business owners can tell me who has a login. Most can’t tell me what each of those logins can actually access. In a busy office, permissions pile up over time. That employee who got access to the accounting share for a one-time project keeps it long after the project ends. Even worse (and we see this all the time) is when a former employee’s account gets disabled but never fully removed.

By themselves, none of these seem like an urgent problem. Together, they add up to a business that doesn’t really know who can touch its data. That’s a hard position to defend from, whether the threat is a hacker or just an honest mistake.

Why I ask these two first

Neither question is technical. I’m not asking about firewalls or encryption or anything like that. I’m asking whether you actually know what would happen if something went wrong today. This helps me understand a client’s risk tolerance, and how much importance they place on their IT systems.

Most businesses I meet have invested in tools. They have antivirus and a firewall, and some kind of backup system. What they often haven’t done is confirm that any of it actually works the way they think it does.

Untested backups and unmanaged access are two of the most common ways I’ve seen businesses get hurt. These companies aren’t careless, they just didn’t know they should be checking these things.

That’s really what these two questions are getting at. It’s not about whether you have the right tools. It’s about whether you actually know your own risk. Most business owners are surprised by how much clarity comes from just asking.

Are Your AI Problems Business Problems In Disguise?

September 21, 2026

By now, you’ve probably experimented with AI in some form.

Maybe it’s helping write documents, summarize meetings, analyze spreadsheets, or speed up customer service.

You see the potential very quickly…

But then the excitement fades.

A handful of people keep using it every day, a few others stop using it altogether, and before long, you’re left wondering why the big AI transformation never fully arrived.

It’s tempting to blame the technology, but the problem is often much more human.

Businesses struggle because they haven’t changed the way work happens around AI tools.

Imagine introducing a new piece of machinery into a factory but keeping the same production process around it. You’d never see the full benefit.

AI works in the same way.

If employees are expected to experiment but still judged entirely on speed, consistency, and avoiding mistakes, most will stick with the methods they already know.

If nobody takes ownership of how AI fits into the business, good ideas can stay trapped inside individual departments instead of becoming part of everyday work.

The same challenge appears when there isn’t a clear approach to how AI should be used across the business.

Employees want to know what they’re allowed to use, what information can be shared, and where the boundaries are.

Without clear guidance, many people become cautious. Others simply make up their own rules.

Getting the best results from AI usually means changing the way work gets done, not only adding new software.

Give people permission to experiment, create clear ownership, and build AI into existing processes rather than leaving it as an optional extra.

AI is moving into workplaces quickly.

Giving people the skills, confidence, and guidance to use it well may turn out to be as important as the technology itself.

If you’d like help putting the right foundations in place, give us a call at (734) 457-5000, or email us at info@mytechexperts.com.

Why Hackers Don’t Need Ransomware Anymore

September 21, 2026

Is your business ready for an attack that doesn’t lock your files but steals them instead?

Cybercriminals are changing their approach, and it’s worth understanding what that shift means for you.

For years, ransomware was the story. Hackers broke in, encrypted your files, and demanded payment to get them back.

That threat hasn’t gone away, but a quieter and in some ways more dangerous tactic is catching on: stealing your data first and threatening to publish it if you don’t pay.

That data might be financial records, customer information, contracts, intellectual property, or internal documents you’d never want made public.

Between privacy regulations and the damage to your reputation, having sensitive information exposed can hurt just as much as losing access to your systems, sometimes more.

This shift matters because it changes the calculation for business owners. With traditional ransomware, restoring from a good backup often took the leverage away from the attacker. Data theft works differently.

Once your information is copied, having a backup doesn’t undo the exposure. The only real protection is keeping attackers from getting their hands on the data in the first place.

Attackers are looking for the easiest way in

One of the biggest openings hackers exploit is outdated software.

Any device or application that hasn’t been updated is a potential doorway, and that includes file sharing platforms, remote access tools, internet-facing devices, and other systems your business depends on every day.

A single unpatched vulnerability has been enough, in some cases, for attackers to compromise dozens of organizations before anyone noticed something was wrong.

Hackers actively scan the internet for these gaps, so a system that’s been overlooked for even a few weeks can become an easy target.

That’s why keeping your systems patched and current remains one of the most effective things a business can do to protect itself.

It’s not flashy, and it doesn’t make headlines, but it closes off the doors attackers rely on most.

Modern attacks are harder to catch

Hackers are also getting better at hiding in plain sight. Rather than using obviously malicious software that antivirus tools are built to catch, many now rely on legitimate tools already built into Windows and other operating systems.

Because these tools are normally used for everyday administration, it becomes much harder for security software to tell the difference between an IT technician doing routine work and an attacker moving through your network.

Virtual servers have become a favorite target for this reason. These are the systems that host multiple applications and services at once, which means a single compromised server can give an attacker access to far more than they’d get from a single computer.

Once an attacker gets into one, they can move through your systems quickly and cause widespread damage before anyone realizes there’s a problem.

The best defense is still the basics

Attacks keep evolving, but the fundamentals of good cybersecurity haven’t changed much at all. The businesses that hold up best under these newer, sneakier attacks tend to do a few things consistently well:

  • Keep operating systems and applications fully patched
  • Monitor for unusual activity across every device on the network
  • Maintain visibility into who is accessing systems and what they’re doing

Have a tested incident response plan in place before trouble hits

None of this is new advice. But businesses that stick to these basics put themselves in a much stronger position, both to avoid an attack and to recover quickly if one happens anyway.

Cyber threats aren’t going to stop getting more sophisticated. The encouraging part is that your defenses don’t have to fall behind. A little consistency with the fundamentals goes a long way.

If you’d like help understanding where your business stands or strengthening your defenses, give us a call at (734) 457-5000.

Could This Be The Future Of Cybersecurity?

September 21, 2026

Most cybersecurity tools work reactively.

Something suspicious happens, the system spots it, and then tries to stop the damage before it spreads.

That’s incredibly important.

But Microsoft is working on something that pushes much further: using AI to find weaknesses before attackers discover them.

The new system is called MDASH, and the idea behind it is genuinely interesting.

Microsoft has built a platform that uses more than 100 specialized AI agents working together to search for hidden security flaws inside Windows.

These agents are designed to inspect different parts of the system, test for weaknesses, and flag potential vulnerabilities automatically.

Simply put, Microsoft is using AI to hunt for security holes at a scale humans simply couldn’t manage alone.

And it appears to be working.

During testing, the system reportedly uncovered multiple previously unknown vulnerabilities inside important parts of Microsoft Windows.

This included flaws that attackers could potentially have exploited remotely over the internet.

Some of those vulnerabilities were considered critical.

These are the kinds of weaknesses that, in the wrong hands, could allow attackers to take control of systems or run malicious code.

What makes this more impressive is the accuracy.

One of the biggest problems with AI-driven security tools has always been false alarms.

Systems that flag hundreds of “possible issues” which turn out to be nothing. That creates noise, wastes time, and makes security teams less effective.

Microsoft claims MDASH has been unusually good at avoiding that problem while still finding genuine risks.

Now, before anyone assumes AI is about to solve cybersecurity completely, it’s important to keep this in perspective.

This technology is mainly being used internally by Microsoft engineers now.

It’s still early days, and even if these systems become more widely available, they won’t suddenly replace the fundamentals that keep businesses safe.

Because most cyberattacks still succeed through ordinary gaps:

  • Weak passwords
  • Unpatched systems
  • People clicking the wrong link
  • Poor access controls
  • Missing backups

Those remain the biggest risks for most businesses today.

AI-driven security tools may eventually become a powerful extra layer of protection, especially for large organizations managing huge and complex systems.

The idea of intelligent agents constantly scanning for hidden weaknesses before criminals find them is a very promising direction for the future.

But the basics are more important right now.

A fully patched system with strong passwords, multi-factor authentication, good backups, and sensible user awareness training will protect most businesses far better than chasing the latest AI security trend without solid foundations underneath it.

The future of cybersecurity probably will involve more AI working behind the scenes, both defending systems and, unfortunately, helping attackers too.

But while the technology evolves, the core principles of staying safe haven’t changed.

Good security still comes down to reducing risk, limiting opportunities for attackers, and making sure the simple things are consistently done well.

If you want to make sure your business security is up to scratch, we’d be happy to help. Get in touch. You can call (734) 457-5000 or email info@mytechexperts.com.

The Threats Hiding In The Tools You Use Every Day

August 17, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

How do you imagine a cyberattack? A sophisticated hacker breaking through layers of security? Using advanced tools that no regular business could possibly defend against?

The reality is usually way less glamorous.

Many breaches start with something small. A forgotten account that was never removed. A laptop that missed an update. A security setting that was switched off and never switched back on.

These are the kinds of gaps attackers actively search for because they’re far easier to exploit than forcing their way through a heavily protected system.

In other words, the danger often comes from the things nobody realized were a problem.
One of the biggest changes in cybersecurity right now is the growing focus on identities.

Instead of attacking systems directly, criminals increasingly target usernames and passwords.

Once they gain access to a legitimate account, they can move through a business much more easily because, from the outside, it looks like a normal user logging in.

That can happen surprisingly quickly. In some cases, ransomware attacks have escalated within hours of the initial breach.

The challenge is that modern businesses are complicated. Staff work remotely. Devices move between home and office.

New software gets introduced. Small gaps appear naturally, unless someone is constantly monitoring them.

Even security tools themselves can become blind spots.

You may have protection installed, but if it is misconfigured, outdated, or partially disabled, it creates a false sense of security. Attackers also rely heavily on something known as “living off the land” techniques.

This means using legitimate tools already built into Windows and Microsoft 365 to carry out malicious activity.

Because those tools are commonly used by IT teams every day, suspicious behavior can blend into normal activity more easily.

Artificial intelligence is likely to accelerate this problem.

AI tools can help criminals identify weaknesses faster, automate attacks, and adapt techniques more quickly than before.

But many of the most effective protections are the basics done well.

Strong passwords, multi-factor authentication, regular updates, controlled access permissions, and ongoing staff awareness training remain some of the strongest defenses available.

If you’d like help spotting and closing small security gaps before somebody else finds them, get in touch.

It’s Happening, Whether You Like It Or Not

August 17, 2026

AI tools are becoming a normal part of the working day.

Someone uses one to tidy up a report. Someone else asks a chatbot to summarize meeting notes. A team member installs an AI browser extension because it helps them work faster.

Most of this happens with good intentions.

But some businesses have no visibility of it at all.

This is known as “shadow AI”.

It describes employees using AI tools that haven’t been approved, reviewed, or properly managed by the business.

In many ways, it’s like shadow IT, where staff adopt their own software without involving the IT team.

The difference is that AI tools can interact with company information in deeper ways.

Employees may paste confidential documents into public chatbots, connect AI assistants to email accounts, or allow AI tools to access files and calendars without fully understanding what happens to that data afterwards.

The motivation is easy to understand. These tools save time, reduce admin, help people get through work more efficiently.

So, banning AI outright rarely works.

If employees feel the tools genuinely help them, they often continue using them secretly. At that point, the business loses even more visibility and control.

The better approach is usually to accept that AI is now part of modern work, then guide people towards safer, approved options.

Newer AI systems are becoming more capable very quickly. Tools are no longer limited to generating text or summaries.

They can search files, access systems, organize information, trigger workflows… and even carry out actions automatically.

Without proper oversight, that creates obvious security and compliance concerns.

For businesses using Microsoft 365, approved tools like Copilot offer a safer route because they sit inside existing permissions and security controls.

That doesn’t remove risk completely, but it does give businesses much better visibility over how AI is being used.

Whatever tools you’re using, the important thing is not to ignore the issue.

If you need better oversight on how your team is using AI tools, we can help. Get in touch.

SIM Swapping: How Hackers Steal Your Phone Number

August 17, 2026

One morning, your phone drops to “No Service” and stops receiving calls and texts. You assume it’s a network glitch and you get on with your day.

But across town, someone has just convinced your mobile carrier that they’re you.

They’ve moved your number onto a SIM card sitting in their own phone.

Every call and text meant for you now goes to them, including the security codes that protect your email and your bank logins.

This is a SIM swap. The attacker never touches your password or breaks into a single system. They take over your phone number, then use it to reset everything attached to it.

They start by gathering a few details about you, often pulled from an old data breach or your social media.

Then they call your carrier, claim your phone was lost or damaged, and ask to activate your number on a new SIM. If the agent believes the story, your number is theirs in minutes.

From there, the SMS codes you rely on become their codes (SMS is the text message system most accounts use to send those one-time login codes). Password reset links and login verifications all land on their device instead of yours.

Researchers at Princeton University tested five major US carriers by posing as customers and trying to move numbers they didn’t own. They succeeded on 80% of their first attempts, mostly because the carriers were leaning on security questions a motivated attacker could answer.

The losses reported to the FBI run into the tens of millions of dollars a year, and the true figure is almost certainly higher, because most victims report the end result, like a drained account, rather than the phone takeover that caused it.

Your personal mobile number is probably the recovery method for nearly everything you log into, from your Microsoft 365 account to your business bank.

If that one number falls into the wrong hands, a lot can fall with it.

Don’t panic though. This is very fixable, and the setup is quick and free:

Lock your number with your carrier

Every major provider now offers a free toggle that blocks anyone from moving your SIM or porting your number without your say-so.

Move your important logins off text-message codes

For your email, banking, and admin accounts, switch from SMS codes to an authenticator app or a passkey.
Both keep working even if someone steals your number because the approval happens on your device, not through your phone signal.

Add a separate passcode to your carrier account.

Most carriers let you set a PIN or passcode that’s required before any change is made to your account. It’s one more wall between an attacker and your number.

Many carriers now send a text or email alert when someone requests a SIM change on your account. If that alert shows up and it wasn’t you, call your carrier right away.

If you’d like a hand checking which of your accounts still rely on text-message codes, or help locking down your team’s numbers, just reply and we’ll walk you through it.

The Employee Who Left Six Months Ago Still Has Access

August 17, 2026

When someone leaves your company, you probably collect their keys, take back the laptop, and shut off their email. Job done, right?

Not quite.

Over the years, most employees pick up access to more systems than anyone tracks. There’s Microsoft 365, your accounting software, your CRM, cloud storage, payroll, vendor portals, remote access tools, and shared mailboxes.

Then there are the accounts nobody remembers: a Canva login someone set up for marketing, a Facebook page a former employee managed, a Dropbox folder shared with a manager years ago, an app someone connected to their Microsoft 365 account and forgot about.

The employee leaves, their email gets disabled, and everyone assumes their access went with it. It often doesn’t.

What is access creep

Access creep happens when employees pick up new permissions as they change roles, but the old ones never get removed.

Someone starts in customer service, moves to sales, and eventually becomes a manager. Each job change adds new access. Rarely does anyone go back and take the old access away.

After five years, that employee may be able to reach far more of your business than their current job requires. When they leave, all of that access leaves the building with them, at least on paper. In reality, it usually stays right where it was.

Offboarding needs to be a process, not a checklist item

Turning off someone’s email is a start, but it only closes one door. What about the cloud app they logged into with a separate password? The vendor site where their account is still active? The shared password they know? The company social media account they had the keys to?

Offboarding works best when it starts before the employee’s last day.

Someone should know which systems they can reach, which devices they hold, which passwords or codes they know, and whether they have access to any shared accounts.

From there, equipment gets returned, individual accounts get disabled, shared passwords get changed, remote access gets pulled, and email forwarding or delegation gets reviewed.

Don’t forget the accounts your IT provider doesn’t manage directly. Your bookkeeper may have logins for banking or payroll.

A salesperson might hold customer portal credentials. Whoever runs your marketing may control social media accounts, your website, ad platforms, or your email marketing tool. Those accounts need the same attention.

The account nobody is watching is the one that gets hacked

Most former employees have no interest in logging back into your systems. That’s not the real risk. The real risk is that their old account is still sitting there, active and unused. If that account gets compromised months or years later, an attacker may find it still opens the door to your business. Nobody notices, because nobody remembers the account exists. That makes forgotten accounts an easy target.

Don’t wait until someone leaves

Access should match the job. When someone’s role changes, their access should change with it.

A periodic review of who can reach what often turns up old accounts, admin permissions nobody needs anymore, forgotten vendor logins, and software nobody uses. You might be surprised by what’s still active.

Ask yourself this: if you made a list today of everyone who can access your company’s systems and data, could you say for certain that everyone on that list still belongs there?

If your honest answer is “I think so,” it’s worth a closer look.

Give us a call for a no-charge, no-obligation review of your user accounts and access, and we’ll help you build a process that covers employees joining, changing roles, and leaving for good.

The Inbox Hiding Place You Don’t Think To Check

July 21, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

If a hacker got into your email account, you would probably do the obvious thing and change your password right away. That is a good instinct. But it does not always solve the problem.

There is a small feature buried in your inbox settings that attackers use to stay hidden long after you have locked them out. It is called an inbox rule, and most business owners have no idea it exists.

What is an inbox rule?

An inbox rule is a setting that automatically moves emails into folders, flags certain messages, or forwards them to another address. You may already use rules to keep your inbox organized, sorting invoices into one folder and newsletters into another.

That same feature is exactly what makes it so useful to a criminal.

How attackers use inbox rules against you

When someone breaks into an email account, one of the first things they often do is create a hidden rule of their own. These rules can quietly forward copies of your emails to an outside address, move important messages out of your main inbox, or mark them as read so you never notice them arrive.

This happens fast. In many cases, attackers set up these rules within seconds of gaining access, before you even know anything is wrong.

That speed gives them a real advantage. With a hidden rule in place, an attacker can read your conversations, pull out sensitive information, and hide the security alerts that would normally tip you off. If they are after your finance team or leadership, they can also sit back and watch for the right moment to reroute a payment.

Here is the part that catches most people off guard: changing your password does not remove these rules. If you reset your password but skip this step, the attacker may still be reading everything that comes into your inbox.

How to check for hidden inbox rules

The good news is that this is easy to check once you know where to look. Every inbox rule has a name, and one that looks strange, generic, or unfamiliar is worth a closer look. Take a few minutes to review your rules periodically, and always check them right after any suspected security issue.

You do not need advanced technical skills to do this. Most email platforms list all active rules in one settings screen – anything you did not create yourself should raise a flag.

The takeaway

Modern cyberattacks do not always rely on complicated hacking techniques. Sometimes they simply use a feature that is already sitting inside your inbox, working exactly as it was designed to, just for the wrong person’s benefit. A quick habit of checking your inbox rules can close a gap that a password reset alone will not. If you would like a hand making sure your business email is locked down the right way, give us a call.

Those Little Jobs Add Up… Delegate Them To AI

July 21, 2026

When people think about AI at work, they often imagine things like writing reports, analyzing data, or answering emails.

That’s useful, of course. But it’s not where most of your time goes.

In a typical working day, it’s the smaller jobs that really slow things down. Following up after meetings, tidying documents, fixing spreadsheets, chasing information.

They’re not difficult, but combined, they eat into hours you’d rather spend elsewhere.

This is where tools like Microsoft Copilot are becoming genuinely helpful.

Take meetings as an example. The real time cost usually comes afterwards. Notes need checking, actions need confirming, and anyone who missed the call needs catching up.

Copilot in Teams can summarize discussions in a more practical way, pulling out decisions, highlighting what still needs doing, and helping people get straight to the important points.

It’s a similar story with writing.

Most people aren’t staring at a blank page. They’re trying to improve something that already exists. A draft might be too long, unclear, or not quite right for the audience.

Copilot can reshape that content, tighten it up, and adjust the tone without you having to rewrite everything from scratch.

Spreadsheets are another common frustration.

You know what you want the outcome to be but remembering how to get there isn’t always straightforward.

Instead of searching for formulas or watching tutorials, you can describe what you need in plain language and let Copilot handle much of the process.

Microsoft has also started bringing everything together more effectively.

Shared pages and notebooks mean ideas, notes, and files don’t end up scattered across different tools.

It becomes easier to keep projects moving without constantly switching between apps.

And for those repetitive tasks that crop up every day, simple workflows can now be created just by describing the process.

Routine updates, reminders, and approvals can run in the background without needing manual input each time.

As a reassurance, this isn’t to replace people. It’s to remove the small points of friction that build up during the day.

When those start to disappear, work feels smoother, and your team can focus more on the things that move the business forward.

If that sounds like something you’d like to learn more about, we can help. Get in touch.

Next Page »

Primary Sidebar

Browse past issues

  • 2026 Issues
  • 2025 Issues
  • 2024 Issues
  • 2023 issues
  • 2022 Issues
  • 2021 Issues
  • 2020 Issues
  • 2019 Issues
  • 2018 Issues
  • 2017 Issues
  • 2016 Issues
  • 2015 Issues
  • 2014 Issues
  • 2013 Issues
  • 2012 Issues
  • 2011 Issues
  • 2010 Issues
  • 2009 Issues
  • 2008 Issues
  • 2007 Issues
  • 2006 Issues

More to See

Are Your AI Problems Business Problems In Disguise?

September 21, 2026

Why Hackers Don’t Need Ransomware Anymore

September 21, 2026

Could This Be The Future Of Cybersecurity?

September 21, 2026

The Threats Hiding In The Tools You Use Every Day

August 17, 2026

Tags

AI Antivirus backups Cloud Computing Cloud Storage COVID-19 cyberattacks cybersecurity Data Management Disaster Planning Disaster Recovery E-Mail Facebook Firewalls Hard Drives Internet Laptops Maintenance Malware Managed Services Marketing Microsoft Network online security Passwords password security Phishing planning Productivity Ransomware remote work Security Servers smart phones Social Media Tech Tips Upgrading Viruses vulnerabilities Websites Windows Windows 7 Windows 10 Windows Updates work from home

Copyright © 2026 Tech Experts™ · Tech Experts™ is a registered trademark of Tech Support Inc.