Coleman Technologies Blog

Blogs on IT Support and Cybersecurity for Small Business

Insights on cybersecurity, AI, and IT strategy to help business leaders reduce risk, improve performance, and make better technology decisions.

Web and DNS Filtering for Abbotsford Small Businesses Catches the Mistake Your Team Already Made

Untitled-design-4

Somebody on your team will click a bad link this year, and no amount of training changes that. Web and DNS filtering for Abbotsford small businesses exists for the half second after the click, when a browser asks where to go and something decides whether to answer.

The Lookup Nobody Sees

Every visit to a website starts with a request for directions. The Domain Name System translates a name people can read into an address a machine can use. The Canadian Centre for Cyber Security describes DNS as the address book for the internet, and notes that almost everything an organization does online depends on it.

That request is the moment of leverage. A filtering service checks the requested domain against threat intelligence before any connection opens. When the domain is known to host phishing pages or malware, no address comes back and the page never loads.

Your employee sees a block notice instead of a convincing fake login screen. Nothing downloads. No credentials get typed into a form built to harvest them.

The control is unglamorous, which is part of why it gets skipped. There is no dramatic alert and no story to tell afterward. The whole point is that nothing happened.

That also makes it hard to justify in a budget meeting. A firewall is a box somebody can point at. Filtering is a setting, a subscription, and a policy document, and its output is an absence of events.

Attackers Work Through the Address Book

The Cyber Centre reports that industry estimates place between 80 and 90 percent of cyber attacks as leveraging DNS in some way. That figure sounds inflated until you look at how ordinary the mechanism is.

A malicious email needs a destination. Malware needs to reach its operator. A fake login portal needs somewhere to live.

Each of those steps involves a name that has to be resolved into an address first. Interrupt the resolution and you interrupt the step.

This is also why filtering catches things that arrive by routes other than email. A link pasted into a chat message behaves the same way. So does a search result, a QR code on a printed invoice, and a bookmark saved months ago to a site that has since been taken over. Web and DNS filtering for Abbotsford small businesses sits below all of those channels rather than guarding any one of them.

The Canadian data supports the same logic from a different angle. Statistics Canada's most recent Survey of Cyber Security and Cybercrime found that about one in six businesses, or 16 percent, were impacted by cyber security incidents in 2023. What impacted them tells you more than the headline number.

  • Scams and fraud were the most common method, affecting 50 percent of impacted businesses, up six percentage points from 2021.
  • Identity theft climbed fastest, reaching 31 percent of impacted businesses after an eleven point jump.
  • Ransomware affected 13 percent of impacted businesses, up from 11 percent two years earlier.
  • Just 22 percent of businesses provided formal cyber security training to employees outside their IT function.

Read those together and a pattern surfaces. The dominant attack methods depend on persuading a person to do something, and most Canadian businesses are not training the people being persuaded.

Where Awareness Training Runs Out

Training is worth doing, and the businesses that skip it are worse off. It is also the control most dependent on one person staying alert at exactly the wrong moment.

People are tired at 4:30 on a Friday. A message arrives from a supplier you genuinely use, referencing an order you are genuinely expecting. The domain is off by a single character, and the logo is correct because it was copied from the real site an hour ago.

Asking someone to catch that while they are also doing their actual job is a thin margin to build a security posture on. It works most of the time. Most of the time is not the standard you want when the failure mode is a compromised mailbox.

Statistics Canada found that only 26 percent of businesses had written cyber security policies, and half reported having any cyber security employees, down from 61 percent in 2021. Most small organizations in the Fraser Valley are running on general awareness rather than a documented program, which puts a great deal of weight on individual judgment.

What a Filter Catches That People Miss

Web and DNS filtering for Abbotsford small businesses does not require anyone to notice anything. It applies the same judgment to every request, at every hour, on every device it covers.

  • Phishing pages hosted on domains registered days or even hours earlier
  • Malware attempting to reach its command and control server after landing on a machine
  • Legitimate sites that have been quietly compromised without the owner knowing
  • Typo domains that catch a mistyped bank, supplier, or software address
  • Unsanctioned file sharing and remote access tools staff install on their own initiative

The Cyber Centre's foundational guidance for small organizations lists protective DNS alongside antivirus software, VPNs, and firewalls. It sits in the baseline category rather than the advanced one, which is a useful signal for anyone deciding where to spend next.

The Laptop That Leaves the Building

Your office firewall protects traffic that passes through your office. That covers less of the working week than it did five years ago.

Staff take laptops home, out to job sites across the valley, and onto hotel Wi-Fi in another province. On those networks your firewall rules do not apply and your monitoring sees nothing at all. Statistics Canada found that 46 percent of businesses monitor their networks and business systems, making it the most common risk identification activity, but that monitoring stops at the edge of the network.

A filtering agent installed on the device travels with the device. The same policy applies in the boardroom, in a truck cab, and at a kitchen table in Clearbrook.

This is where filtering earns most of its value. Protective DNS also extends to phones and tablets, where conventional antivirus often cannot be installed at all. It holds up under a bring your own device arrangement, where the company does not control the hardware in the first place.

Why the Compliance Angle Is Not an Afterthought

Under PIPEDA, an organization that suffers a breach of security safeguards has to assess whether it creates a real risk of significant harm. If it does, the organization must report to the Privacy Commissioner and notify the individuals affected. Records of every breach have to be kept for two years regardless of that assessment, and the Privacy Commissioner is explicit that small businesses are covered.

A credential harvested through a fake login page is exactly that kind of event. Preventing the connection is considerably simpler than working through the assessment, the notification, and the client conversations that follow.

Insurers have noticed the same thing. Statistics Canada recorded cyber risk insurance uptake rising to 22 percent of businesses in 2023 from 16 percent in 2021, and applications increasingly ask what preventative controls are actually in place.

What Filtering Will Not Do

Honest limits are more useful than a feature list.

  • It does not inspect page contents, so a malicious file on a domain nobody has flagged will still resolve.
  • It does not stop traffic that avoids domain names entirely and connects straight to an address.
  • Browsers using encrypted DNS can route around a filter unless the deployment accounts for that.
  • It does not replace multi-factor authentication, patching, backups, or endpoint protection.

Filtering reduces how often a human mistake turns into an incident. It does not make mistakes impossible, and any provider claiming otherwise is selling something. Layers work precisely because each one fails differently.

Rolling It Out Without Breaking the Workday

Filtering earns a bad reputation when it is deployed as a blunt instrument. Block too much and staff find ways around it, usually on personal devices you cannot see. Block too little and it becomes decoration.

Category policy is where most of the internal debate happens. Newly registered domains, known malware hosts, and phishing infrastructure should be blocked without argument. Categories such as personal webmail, streaming, and file sharing depend entirely on how your business actually operates, and a distribution warehouse will land somewhere different from an accounting firm.

  • Start in monitoring mode and review real traffic for a week before enforcing anything.
  • Block security categories first, and treat productivity categories as a separate conversation.
  • Build an exception process staff can use in minutes rather than days.
  • Extend the agent to laptops and mobile devices instead of stopping at the office network.
  • Review block reports monthly, since they show what is being aimed at your people.

That final point gets overlooked most often. Block logs are a free source of intelligence about which staff are being targeted and what the current campaigns look like.

They also settle arguments. When somebody insists the filter is too aggressive, the report shows what was actually blocked and why, which turns a complaint into a five minute policy adjustment.

Fitting It Into a Layered Stack

Statistics Canada found that 47 percent of businesses without dedicated cyber security employees said they rely on consultants or contractors instead. For a great many small organizations in Abbotsford and the surrounding valley, that is simply the practical model, and filtering is among the easier layers to hand across.

The argument for adding it is not that it is impressive. It is that it does its work on an ordinary Tuesday, when somebody is distracted and the link looks entirely reasonable. Web and DNS filtering for Abbotsford small businesses is a quiet control, and the evidence it is working is a page that never loaded.

Sources:

  • Canadian Centre for Cyber Security, Protective Domain Name System (ITSAP.40.019)
  • Canadian Centre for Cyber Security, Foundational cyber security actions for small organizations (ITSAP.10.300)
  • Statistics Canada, The Daily: Impact of cybercrime on Canadian businesses, 2023 (Canadian Survey of Cyber Security and Cybercrime)
  • Office of the Privacy Commissioner of Canada, PIPEDA breach of security safeguards reporting requirements
Continue reading

Why Multi-Factor Authentication for Langley Small Businesses Beats Every Security Tool You've Bought

Untitled-design-4

Among Canadian businesses hit by cyber security incidents in 2023, 31% faced attacks involving identity theft, an eleven percentage point jump in only two years. That single trend is why multi-factor authentication for Langley small businesses now outperforms almost everything else on the security invoice.

The Gap Your Current Stack Was Never Built to Cover

Walk through the security spending of a typical 30-person firm and the list is familiar. Antivirus on every machine. A firewall at the edge.

Spam filtering on the mail server. Perhaps endpoint monitoring, added after a scare or an insurance questionnaire.

Each product does a legitimate job, and none of them is built to stop someone who signs in with a correct username and password.

That distinction matters more than most owners realize. A stolen credential triggers no malware alert, because no malware is involved anywhere in the sequence. The session looks ordinary from the inside, and by the time anyone notices, the intruder has been reading email for days.

How the Password Gets Out in the First Place

Attackers reach those credentials without much effort. Passwords leak in breaches at unrelated services, then get replayed against business accounts in bulk until something opens. The Canadian Centre for Cyber Security calls this credential stuffing, and it works whenever an employee has reused a password across two sites.

Notice what the attacker never had to do. No firewall was defeated, no software vulnerability was exploited, and no attachment was opened. Your perimeter behaved exactly as designed, and someone walked through the front door carrying a valid key.

What the Measured Evidence Shows

Security vendors make large claims, and very few of those claims arrive with published research attached. This particular control is the rare exception, which is worth pausing on before any purchase decision.

Microsoft studied account compromise across a large population of business accounts that were showing suspicious activity. The findings are unusually clear:

  • Risk of account compromise fell by 99.22% across the population studied.
  • Where credentials had already leaked, the risk still fell by 98.56%.
  • Microsoft's own platform guidance puts the block rate above 99.2% of account compromise attacks.
  • Dedicated authenticator apps outperformed text message codes, though both beat having no second factor at all.

No firewall, content filter, or endpoint agent publishes numbers anywhere in that range.

The Canadian Centre for Cyber Security arrives at the same conclusion from a different direction. Its baseline set contains 13 control categories written specifically for small and medium organizations, and it names four of them as the place to begin. Strong user authentication sits among those four, alongside patching, backups, and an incident response plan.

Where Langley Firms Sit in the National Picture

The Canadian numbers deserve a note about who they describe. Statistics Canada counts a small business as 10 to 49 employees and a medium one as 50 to 249. That band covers most of the professional services firms, contractors, and manufacturers operating around Langley and the wider Fraser Valley.

Roughly 170,000 small businesses fell inside that survey population. About 1 in 6 Canadian businesses reported being impacted by a cyber security incident during 2023, continuing a gradual decline from 21% in 2019.

That headline drop hides an uncomfortable detail. Scams and fraud remained the most common attack method at 50% of impacted businesses, and identity theft climbed faster than any other category. Overall incidents are down while the methods that target people and credentials are up.

Internal capacity moved the other way over the same period. Half of Canadian businesses reported having cyber security employees in 2023, down from 61% two years earlier, and 47% of those without such staff said they rely on consultants or contractors instead.

Two Accounts Deserve Your Attention First

Rolling out multi-factor authentication for Langley small businesses works best in deliberate stages. Switching it on everywhere in a single weekend tends to collapse under its own weight, and a stalled rollout protects nobody.

Business email comes first, without much room for debate. Password resets for nearly every other system land in that inbox, which quietly makes it the master key to everything else you own. An attacker holding email can redirect invoices, approve their own access requests, and reset credentials at leisure.

Moving On to Privileged Logins

Administrator accounts come second. These are the logins that create users, change permissions, and switch off logging, so compromising one turns a contained problem into an open-ended one.

The Cyber Centre also recommends that administrators maintain separate accounts for routine work and privileged tasks. Daily email and web browsing should never run under a login capable of rewriting your entire environment.

Remote access and finance systems belong in the third wave. Anything reachable from outside the office, and anything that can move money or client records, earns a second factor before the general staff rollout begins.

Picking a Second Factor Without the Jargon

Authentication factors fall into three plain categories, according to Cyber Centre guidance: something you know, something you have, and something you are. The whole idea is to require proof from more than one of those categories, so a stolen password on its own stops being enough.

Here is how the practical options compare for a small office:

  • Authenticator app: a code or approval prompt on a phone, free with most business platforms, and the sensible default for the majority of teams.
  • Hardware key: a physical device that plugs in or taps against a phone, the strongest of the group, and worth the cost for finance and administrator roles.
  • Biometrics: a fingerprint or face scan, already built into most modern laptops and phones, and easily the least disruptive for staff.
  • Text message codes: better than a password alone, but the weakest option on this list, and worth replacing wherever the platform supports something better.

Owners often assume the strongest available choice is the right choice everywhere. It rarely is, and forcing hardware keys on a reception desk usually buys resentment rather than security. The Cyber Centre notes that the best solution varies by organization, since staff still need to complete their work without constant friction.

The Gaps That Survive a Rollout

Plenty of businesses believe they have this handled, then discover on review that meaningful holes remain. Coverage tends to fail at the edges rather than in the middle.

Watch for these in particular:

  • Shared logins for a reception desk, warehouse terminal, or social media account, where nobody owns the second factor.
  • Individual users granted a permanent exemption during the original rollout and never revisited afterward.
  • Contractors, bookkeepers, and external IT staff who hold access but sat outside the internal project.
  • Older systems and legacy sign-in methods that quietly bypass the policy you thought applied everywhere.

Each of these represents a working credential that a second factor does not protect. Finding them takes an afternoon and a list of every account with access, which is a task most firms have never completed in full.

Why Rollouts Stall, and How to Keep Yours Moving

Technical setup is the easy part of this project. Most attempts at multi-factor authentication for Langley small businesses stall on human logistics rather than on configuration screens.

Someone leaves a phone at home on the morning of an important deadline. A long-tenured employee objects to installing a work application on a personal device. A prompt arrives at an awkward moment and gets dismissed without a thought.

Each of these is entirely predictable, and each has a straightforward answer if you plan for it before launch rather than during it.

  • Write down the recovery process for a lost or replaced phone before the first user enrols.
  • Keep spare hardware keys with whoever handles support, and replace any that get issued.
  • Turn on number matching, so approval requires typing a displayed number rather than tapping yes.
  • Enrol leadership first, so nobody reads the policy as a set of rules for everyone else.
  • Show people where the setting lives, since it often sits buried under advanced menus.

Communication carries more weight here than any of the technical choices. Staff accept the extra step readily once they understand what it protects and how they get back in when something goes wrong.

Only 22% of Canadian businesses provided formal cyber security training to their non-technical employees in 2023. That gap explains a great deal about why sensible security projects meet resistance on the floor.

The Compliance Picture Running in the Background

Canadian privacy law reinforces all of this without naming a single product. PIPEDA requires that personal information be protected by safeguards appropriate to its sensitivity, which is a standard rather than a shopping list.

The Office of the Privacy Commissioner is explicit that the legislation prescribes no particular technology, and that organizations must keep pace as risks and tools evolve. For a firm holding client files, payroll records, or health information, an unprotected login has become difficult to defend as appropriate.

That same reasoning shows up in the insurance market. Cyber risk coverage among Canadian businesses reached 22% in 2023, up six percentage points from 2021.

Written cyber security policies, meanwhile, stayed flat at 26% across both survey years. Documentation lags adoption, which becomes a problem the moment anyone has to demonstrate what was in place and when.

Where This Leaves the Security Budget

Spending more is the instinctive response to feeling exposed, and the measured evidence points somewhere considerably cheaper. Multi-factor authentication for Langley small businesses costs very little, comes bundled with most business software already in use, and addresses the attack pattern that grew fastest in Canada's most recent national figures.

The Cyber Centre puts the trade-off plainly. Implementing this control can take significant cost and effort, and recovering from a compromise could cost more still.

None of that argues for tearing anything out. Firewalls, patching, and tested backups all continue to earn their place in the budget.

It argues instead for fixing the order of operations, and putting the highest-return control fully in place before adding one more product to the pile.

Sources:

  • Statistics Canada, Impact of Cybercrime on Canadian Businesses, 2023 (Canadian Survey of Cyber Security and Cybercrime)
  • Microsoft Research, How Effective Is Multifactor Authentication at Deterring Cyberattacks?
  • Microsoft Learn, Plan for Mandatory Microsoft Entra Multifactor Authentication
  • Canadian Centre for Cyber Security, Top Measures to Enhance Cyber Security for Small and Medium Organizations (ITSAP.10.035)
  • Canadian Centre for Cyber Security, Secure Your Accounts and Devices With Multi-Factor Authentication (ITSAP.30.030)
  • Office of the Privacy Commissioner of Canada, PIPEDA Fair Information Principle 7: Safeguards
Continue reading

AI Meeting Assistant Risks for Surrey Businesses: Who's Really in Your Meeting?

Untitled-design-8

Three out of four professionals now use an AI note-taker in their meetings, often without a second thought. That quiet shift has made AI meeting assistant risks for Surrey businesses worth understanding before the next call begins.

The Silent Guest at the Table

An AI meeting assistant is a bot that joins a video call to listen, record, and write up what was said. These tools transcribe the conversation, summarize decisions, and pull out action items on their own. The pitch is simple. Let the software take notes so people can focus on the discussion.

Adoption has been swift. A 2025 survey found that 75 percent of professionals now use one in their work meetings. Many were invited by a single employee who liked the convenience, not by any company decision.

These bots often arrive through a calendar link. Connect one to a work calendar, and it can join every meeting automatically from then on. No one presses record, and no one is asked. The assistant simply shows up, call after call, doing what it was set up to do.

Hybrid work is fuel for the trend. As more meetings moved online, note-takers became the easy way to keep everyone in the loop. The habit grew faster than any policy meant to guide it.

What the bot captures and keeps

That is where the trouble starts. The bot does not just sit quietly in the corner. It captures the full conversation and sends it to a third-party server for processing, often one the business has never vetted.

Consider what a normal meeting actually contains. The record these tools create is far richer than most people pause to think about.

  • Client names, account details, and private circumstances
  • Pricing, proposals, and competitive strategy
  • Personnel matters, salaries, and performance concerns
  • Legal questions and early views on a dispute
  • Passwords or system details mentioned in passing

Once that transcript exists on an outside server, your control over it fades. Who can read it, how long it is kept, and what it trains later become decisions the vendor makes, not you.

Not the same as a colleague with a notepad

It is tempting to treat this like a co-worker jotting things down. The difference is scale and permanence. A person forgets, paraphrases, and keeps notes in one place.

A bot captures every word, stores it indefinitely, and makes it searchable by anyone with access. A careless line a human would overlook becomes a permanent, retrievable record. That shift changes the stakes entirely.

When Convenience Becomes Exposure

The gap between intent and reality is wide. In the same 2025 research, 47 percent of active users said a note-taker had recorded or shared something they never meant to capture. Nearly half. That is not a rare glitch.

People also behave differently once they notice a bot. Around 84 percent of users say they change how they speak when an assistant is listening. Candour drops, and the honest back-and-forth that good meetings depend on quietly fades.

This is the core of AI meeting assistant risks for Surrey businesses. The tool that promised better records can chill the very conversation it was meant to capture, while stockpiling sensitive material somewhere you cannot see.

Stored, then shared without you

Storage is the part few owners examine. Many of these tools retain transcripts by default, sometimes with no clear end date. Some reserve the right to use recordings to improve their models unless you find and change a setting.

There is also the question of who else receives the summary. Many tools share notes automatically with everyone they judge to be a participant. An assistant invited by one attendee can quietly send a full transcript to people who were never in the room. Distribution, not just capture, is where control slips.

Picture a quarterly review at a Surrey accounting firm. A partner talks through client tax positions aloud while a note-taker, invited weeks earlier, captures all of it. The summary lands in an inbox, then a shared folder, then the vendor's servers. No breach occurred, yet confidential client data now sits in three places the firm never intended.

The scenario is not unusual. It is the default behaviour of these tools working exactly as designed. Nothing looks broken, because nothing is. The exposure comes from the ordinary operation of a helpful tool, which is precisely why it slips past busy teams.

The Consent Problem No One Mentions

Did everyone on the call agree to be recorded?

Under PIPEDA, businesses are responsible for how they collect personal information, and a recorded voice qualifies. When a bot captures a client, a candidate, or a partner who never consented, the business that invited it carries the exposure. The vendor rarely shoulders that burden.

In 2025, a widely reported class action in the United States drew attention to exactly these risks. The suit alleged that a popular AI assistant joined meetings on its own, sent conversations to outside servers, and recorded people who were not account holders. It further claimed the recordings were kept and used to train the tool.

Higher stakes for professional firms

For professional service firms, the stakes climb higher. Legal experts have warned that letting a note-taker vendor access transcripts could weaken attorney-client privilege. For accountants and consultants across Surrey, a leaked transcript can breach the confidentiality clients simply assume.

Regulated fields carry extra weight. A recorded discussion of someone's health, finances, or employment can pull a business into duties it never signed up for. The more sensitive the meeting, the higher the cost of an uninvited listener.

Trust is the currency of a referral market. Clients in the Fraser Valley share advisors the way they share contractors, on reputation. One story about a recorded meeting gone astray can cost far more than any single engagement.

Signs the Problem Is Already in Your Office

Most owners have never approved a single one of these tools. That does not mean the tools are absent. It usually means no one has looked.

  • Meeting invites show an unfamiliar bot or note-taker as an attendee
  • Summaries arrive by email from a service IT never set up
  • Staff forward AI-generated notes without knowing where they were stored
  • No one can say which meetings are being recorded, or by whom
  • Clients have asked, half-joking, who else is on the call

If these feel familiar, uninvited assistants are already sitting in on your conversations. The only unknown is how much they have gathered.

The pattern is familiar from other technologies. Adoption runs ahead of oversight, and the gap closes only once someone goes looking. The sooner that look happens, the smaller the cleanup.

Building a Sensible Policy Around Recording Bots

The answer is not to fear the technology. Used deliberately, these tools genuinely save time and sharpen follow-up. The goal is to decide when they join, which ones you trust, and where the data lands. Sound management of AI meeting assistant risks for Surrey businesses rests on a few clear moves.

  • Set a plain policy stating which tools are approved and who may enable them
  • Turn on host and admin controls that block uninvited bots from joining calls
  • Require clear notice and consent whenever a meeting will be recorded
  • Vet each tool's retention and training terms before it touches a real conversation
  • Keep recordings of sensitive meetings inside systems you manage

Order helps here. A policy sets the rule, platform settings enforce it, and consent practice keeps you onside of privacy law. Each layer covers a gap the others miss.

Start with your meeting platform

Most video platforms already let an administrator control who and what can join. A short configuration session can stop unknown bots at the door. That single step closes the most common opening without slowing anyone down.

From there, choose one or two vetted tools for the teams that need them. A small approved set is far easier to govern than a free-for-all. Review it each quarter, since terms and features shift often.

Make consent routine

Consent does not need to feel awkward. A short line at the start of a call, plus a note on the invite, is usually enough. State that the meeting may be recorded, name the tool, and give people room to object. Most will not mind, and the few who do will be glad you asked.

Training rounds it out. When staff understand why a bot in a client call is a problem, they stop inviting them by reflex. The rule sticks because it makes sense, not because it was ordered.

It also pays to read the fine print once. Look for how long a tool keeps transcripts, whether it trains on your data, and who counts as a participant for sharing. A vendor that answers those plainly is usually the safer bet. Vague terms are a signal to keep looking.

A Clearer Path Forward

None of this calls for banning note-takers or policing every call. It calls for the same judgement you already apply to any vendor that handles client information. Ask where the data goes, who can see it, and how long it stays.

Handled with that care, AI meeting assistant risks for Surrey businesses become manageable rather than alarming. You keep the productivity, protect the confidence clients place in you, and stay on the right side of privacy rules.

The bots are already joining meetings across the region, invited or not. Knowing which ones belong there, and on what terms, is what turns a hidden liability into a tool you actually control.

Sources:

  • Fellow.ai, "The State of AI Meeting Notetakers 2025" (2025): fellow.ai
  • Laxis, "The State of Meeting Note-Taking 2026" (2026): laxis.com
  • Meetily, "Are AI Meeting Assistants Safe? 2026 Privacy Risks" (2026): meetily.ai
  • Littler, "AI Transcription and Note-Taking Technologies: Seven Points for Employers" (2026): littler.com
  • Pittsburgh Technology Council, "Hidden Risks of AI Note-Takers" (2026): pghtech.org
  • Office of the Privacy Commissioner of Canada, PIPEDA overview: priv.gc.ca
Continue reading

Six of the Worst Data Breaches of 2023

Six of the Worst Data Breaches of 2023

In this blog, we do our best to give people the knowledge they need to protect themselves and their organizations while operating online. With all the digital tools that we all have come to rely on, it’s important to understand the result of a data breach on organizations and their customers. In today’s blog, we go through six of the most devastating data breaches that happened in 2023. 

Continue reading

Prioritize Your Cybersecurity Hygiene in 2024

Prioritize Your Cybersecurity Hygiene in 2024

A New Year can be about self-improvement. Most of us make lofty goals to spend more time at the gym, or to stop sneaking spoonfuls of uncooked Pillsbury Cookie Dough right out of the tube from the back of the fridge at four in the morning. Some of us accomplish our goals, and some of us have gotten really good at hiding that Pillsbury Cookie Dough wrapper in the bottom of the trash so nobody realizes it’s gone. All joking aside, it feels good to make accomplishments, and I truly hope that anything you set your mind to is able to happen for you.

If you are looking for an easy resolution that will help you sleep better at night and is extremely easy to maintain, I’d highly suggest that you prioritize your own personal cybersecurity in 2024.

It will take a little effort, but trust me, it will save you a lot of headache down the road.

Continue reading

Cyberthreats Can Threaten Your Business in Several Ways

Cyberthreats Can Threaten Your Business in Several Ways

Every organization has a lot of things that could go wrong in the course of doing business. They can run into supply chain issues, employee turnover and poor performance, natural disasters interrupting your “business as usual”, but one of the most unassuming, yet worrisome threats to your business is the cyberattack. This month, we go into a few ways cyberattacks threaten your business and how they play out to give you an idea of how to prepare.

Continue reading

Are You Being Phished? 4 Things to Look Out For

Are You Being Phished? 4 Things to Look Out For

Your business’ computing infrastructure is a pretty resilient system. It has all types of tools added on to keep malicious code, bad actors, and even sabotage from ruining the good thing you have. This reliability has led to hackers changing the way that they go about their business. Nowadays, most of the attacks that affect businesses are phishing attacks. In today’s blog we will go through the elements of a phishing attack and how you can protect your business from them.

Continue reading

How to Secure Your IoT Devices at Home

How to Secure Your IoT Devices at Home

The Internet of Things is everywhere and that means that it’s important to understand how much of a potential security risk these devices can be. From smart speakers to smartphones, it's important that you understand how these devices can create problematic situations. In this week’s blog we will discuss how you can protect yourself against IoT vulnerabilities at home.

Continue reading

The Less Intrusive Your Cybersecurity Plan Is, the More Effective It Will Be

The Less Intrusive Your Cybersecurity Plan Is, the More Effective It Will Be

Threats are everywhere in business today. You can quite literally be sitting at your desk actively working in your email and be exposed to multiple scams. With this revelation, it is essential that every organization takes the steps necessary to secure themselves against the immense amount of threats that could put their network and infrastructure at risk, and do so without making it difficult on their staff. Let’s dig into what that takes in this month’s newsletter.

Continue reading

Cybersecurity is a Constantly Evolving Industry

Cybersecurity is a Constantly Evolving Industry

Security is extremely important for every single organization that uses IT. Like any other part of a business where practices and demands change frequently, there is bound to be significant innovation involved with the strategies built to protect users and the business as a whole. Let’s look at why it is important to continuously innovate your organization’s cybersecurity policies and procedures.

Continue reading

One Employee Can Put Your Business in the Red (By Mistake)

One Employee Can Put Your Business in the Red (By Mistake)

You know the old phrase, “A chain is no stronger than its weakest link?”

It’s a pretty good idiom, but when it comes to cybersecurity, I think the idea is worth revisiting. It’s not that you aren’t as strong as your weakest link, or in terms of cybersecurity, it’s not that you aren’t as secure as your most vulnerable endpoint…

You are less secure the more users you have.

Continue reading

You Need to Take Your Cybersecurity Seriously

You Need to Take Your Cybersecurity Seriously

Small businesses have a lot to worry about in terms of technology, but one of the things that often gets overlooked is network security. Some small businesses feel that they are too small to be considered a viable target for hackers, but they are wrong; all businesses have data valuable for hackers in some form.

Continue reading

What’s the Line Between a Security Breach, and a Data Breach?

What’s the Line Between a Security Breach, and a Data Breach?

When security breaches and data breaches are mentioned in the same breath so often, it’s easy to look at them as one and the same. However, we want to take a moment to explain the differentiating factors between the two, as it could be all the most important for protecting your business in the future.

Continue reading

What Every Business Owner Needs to Know About Security Training

What Every Business Owner Needs to Know About Security Training

The effectiveness of your business’ IT security is largely contingent on how your IT operates. As a result, it is extremely important to ensure that your staff understands the role they play in protecting your business’ assets. This month, we discuss what you should prioritize when putting together a security training platform; an essential part of any business’ attempts to keep their IT secure. 

Continue reading

Your Business Is Currently At Risk: What You Should Know

Your Business Is Currently At Risk: What You Should Know

Do you know those horror stories you catch every so often where a huge business has their network hacked and millions of their customers and employees have their personal and financial information leaked onto the Dark Web? Your organization isn't likely as big as theirs, but regardless of how much money, people, and diverse revenue streams an organization has, having its network breached and its customers’, or its employees’, information strewn about over the Dark Web is not an ideal scenario. 

Continue reading

Luck Isn’t a Cybersecurity Strategy

Data Backup and Recovery

Data backup is a critical process that every business that depends on their IT needs to have. If data is the lifeblood of your business, then you need to protect it. Your business most assuredly has data that, if lost, would put you back. Why risk it when a solution for this problem is a simple fix? You need data backup.

Continue reading

Include Your Staff in Your Security Strategies

Tesla’s Near-Sabotage

In August 2020, a Russian businessman was indicted on charges of conspiracy to intentionally cause damage to a protected computer after he attempted to recruit a current Tesla employee to install malicious software on the automaker’s Gigafactory network. 

Continue reading

Why You Need to Keep an Eye on Your Data

How a Company Acquires Your Data

For a company to get your data, all they really have to do is ask you for it. Think about what happens each time you make a purchase online, or even create an account—you’re handing over your contact information, and usually pairing it to one of your financial resources.

Obviously, you’re subconsciously entrusting them with this information, assuming that they will keep it sufficiently protected and secure.

Continue reading

A Brief Review of Various Cybercrime Statistics

Ransomware

Imagine trying to access your computer (or your network as a whole), only to find yourself locked out and presented with a demand for payment in exchange for your files to be decrypted. This is precisely the scenario that ransomware puts its victims into, usually with a deadline to pay up under threat of the destruction of the encrypted files. If you’ve heard about Cryptolocker, WannaCry, or Petya, they are what we are referring to.

In 2019, a business was infected with ransomware once every 15 seconds, racking up a total of $11.5 million in total losses. Spam and phishing attacks were responsible for infecting 66 percent of affected companies, and in 2017, almost half of companies surveyed were affected by ransomware.

Denial of Service

Denial of Service (DoS) attacks, and their more-popular offshoot, Distributed Denial of Service attacks are the most common form of cyberattack. Using automation, an attacker has resources batter a target with the aim of taking it down. The rise in Internet of Things-enabled devices now allows an attacker to take over these devices and turn them against a single webpage. Naturally, this takes the website down.

The biggest DDoS attack on record happened on March 5, 2018, but was fortunately unsuccessful in taking down the targeted ISP… despite clocking in at 1.7 TB/s. On average, one of these attacks costs somewhere between $20K-to-$40K each hour, or in other terms, just under the average American worker’s annual salary. In the UK, businesses lost £1 billion to cybercrime in 2019.

Man-in-the-Middle

A Man-in-the-Middle attack compromises any communications between a business and their contact. Any and all data can be interfered with, allowing cybercriminals to have their way with personal data, business correspondence, or financial data that is transmitted. It can be intercepted, altered, or redirected, potentially causing more problems than can be counted. The worst part: because Man-in-the-Middle attacks are relatively easy to carry out, they are rising in popularity on a daily basis. They are most commonly used to extract information, whether personal or professional, that otherwise wouldn’t be available. This includes things like login credentials, banking information, or payment card data.

Okay, that wasn’t the worst part. The worst part is that the majority of servers are still vulnerable. As in, 2016 saw 95 percent of HTTPS servers still at risk.

Phishing

Believe it or not, phishing attacks are ranked as the biggest threat to businesses out there today. Phishing is a kind of social engineering where an attacker will reach out to the victim through some format, from email to instant messaging and beyond, in order to gain access to a secure system by fooling their victim into erroneously trusting them. While phishing emails have been around the block a few times, today’s attacks have grown to be quite sophisticated.

Many statistics surrounding phishing emails demonstrate how effective this relatively simple attack has proved to be. Phishing is involved in 93 percent of all social engineering attacks, and was directly responsible for 70 percent of government network breaches. In the last 12 months, 64 percent of organizations had first-hand experience with phishing, notably, 82 percent of manufacturers. The aforementioned ransomware relies on phishing for 21 percent of its delivery. As recently as 2016, 30 percent of phishing messages were opened.

SQL Injection

Abbreviating a structure query language injection, an SQL injection attack does what it says on the box - it injects malicious code into a target’s SQL servers and feeds the database information back to the attackers. While this is another “golden oldie” of an attack, web-based applications that call for database access have given new life to SQL injection attacks and allowed attackers to extract very valuable info.

It should then come as no surprise that 65 percent of all web application attacks are performed through SQL injections. So, if your organization draws information from a database for an application, you could easily be victimized to a significant degree. Even gamers need to be concerned, as 12 billion out of 55 billion detected SQL attacks that Akamai security experts found were leveled at the gaming community.

Malware

If only these other attacks meant that attackers didn’t have time to try anything else, but unfortunately, that isn’t the case. Malware attacks still rank among both the worst, and most common, attacks against businesses. Of course, there are many types to consider, including:

  • Trojan horses - Malicious code will be concealed within other files and applications and allow an attacker a point of access to a computing system or network.
  • Worms - Malicious and self-replicating applications that travel along and infect networks and individual devices.
  • Viruses - Samples of malicious code that infect applications for a variety of motives, including sabotage and theft of data and other resources.
  • Spyware - Code that, while it seems harmless, piggybacks to software and gathers information about how a device or network is used.

There are many ways for malware to be introduced into a system. Again, phishing messages can be responsible, but many attackers will use something called “droppers.” Droppers are specialized programs that will install a virus after bypassing cybersecurity solutions. Since there is nothing inherently malicious about the dropper, protections usually don’t flag them.

Fortunately, there are ways to protect your business’ resources, network, and infrastructure from the millions of different versions of these attacks - and you need them, as your business is actively targeted by these attacks. To learn more about putting these protections into place, reach out to the professionals at Coleman Technologies by calling (604) 513-9428.

Continue reading

Why It’s Paramount to Keep Security in Mind

The past few years have seen some of history’s greatest data breaches. For instance, the most notorious of these attacks, the Equifax breach, Yahoo, and Marriott-Starwood, resulted in a combined total of 3.5 billion accounts breached.

This means, statistically speaking, you would have a pretty good chance of picking a data breach victim of the past few years by randomly selecting two human beings from the entirety of planet Earth’s population.

Crunching the numbers, there has been an increase of security breaches of 67 percent since 2014.

What Does this Mean? Is Anything Secure Anymore?

Interestingly, there is a plus side to these enormous data breaches happening in the public eye, thanks to a few key points:

  • It brings attention to these kinds of crimes - Thanks to disasters like the Equifax breach, more Canadians are aware of the impact of cybercrime. This kind of awareness is crucial to encouraging improved security.
  • There is too much data for cybercriminals to practically use. This one can be chalked up to statistics… the more data that a given cache has, the less of a chance that your data is pulled up in an attack.

To clarify, we aren’t trying to sugarcoat the severity of a data breach, but having said that, the past few years’ cybersecurity threats have really given us all an example to consider. With new compliances, regulations, and other mandates being put into play, businesses are certainly considering these threats.

What About Small Businesses?

There is a tendency to overlook small businesses when discussing data breaches. After all, the ones that have struck large targets (like Yahoo, Target, eBay, Sony, and many others) almost always get a headline, along with the attacks that focus on municipalities, like the ones that targeted Wasaga Beach, Ontario and Midland, Ontario with ransomware.

What aren’t heard about so much, unfortunately, are the attacks that lead to much smaller companies shutting their doors for good… a side effect of the limited number of victims per attack, and the relatively casual approach that many have towards security. Unfortunately, a Verizon survey shows just how misguided the assumption that a smaller business size will protect it from threats, when 43 percent of businesses breached would be classified as small.

Security Needs to Be a Priority

Fortunately, there are ways that you can reinforce your business’ cybersecurity, especially with the help of Coleman Technologies and our experienced cybersecurity professionals. Call (604) 513-9428 to get in touch with us, so we can help evaluate and fulfill your business’ needs.

Continue reading

About Coleman Technologies

Coleman Technologies is a managed IT and cybersecurity partner for growing businesses that can’t afford downtime, breaches, or guesswork. For over 25 years, we’ve helped organizations across British Columbia run stable, secure, and scalable technology environments—backed by 24/7 support, enterprise-grade security, and clear accountability. We don’t just fix IT problems. We take ownership of them.

get a free quote

Understanding IT

Get the Knowledge You Need to Make IT Decisions

Technology is constantly evolving, and keeping up can feel overwhelming. Whether you want to understand cybersecurity threats, explore automation, or learn how regulations like PCI DSS impact your business, we’ve made it easy to access clear, straightforward insights on key IT topics.

Insights to Understanding IT

Contact Us

20178 96 Ave C400
Langley, British Columbia V1M 0B2

Mon to Fri 7:00am–5:00pm

[email protected]

(604) 513-9428

Coleman Technologies Awards & Memberships

Image
Image
Image