Blog

Our views on technology, security, marketing & design

/

September 12, 2026

A business owner called me because her website felt slow and wasn’t bringing her calls. Within a few minutes I was looking at her invoices — sitting in online storage with no password on it. And they weren’t the only thing there. Signed contracts. Tax documents. Scans of identification. Then I realized not all of it was hers: the person who built her site had been using the same storage for EVERY client and never turned the lock. She had no idea — of course she didn’t. She hired someone to build a website. She was never going to know to ask, and nobody told her. That call isn’t unusual anymore. Here’s what I keep finding when I get called in: the security problems nobody can see, the ‘handcrafted’ claims that aren’t true, the sites that don’t work while charging premium rates — plus why your website is the first conversation you have with almost every customer you’ll ever get, what it actually means to own the whole thing instead of one piece, and the fourteen questions every business owner should ask before hiring anyone. This isn’t an anti-AI article. I use AI every day. It’s about what happens when a powerful tool lands in unaccountable hands.

/

August 27, 2026

For months, officials warned it was coming — and now it appears to have happened: a cyberattack knocked a small British power generator offline for four days this summer, on the heels of attacks that struck 30+ community water systems in the US. British security officials attribute the power-plant incident to hackers linked to Iran; US authorities connected the water attacks to the same source. Here’s the thread that ties them together: the targets weren’t massive national grids. They were SMALL. A generator a UK minister called ‘tiny.’ Community water systems. These attacks succeeded not by overpowering the strongest defenses but by finding the weakest — the small, under-resourced, lightly-defended facilities everyone assumed were too minor to bother with. If that sounds like most small businesses, it should. Being small isn’t camouflage — it’s what put these facilities in the crosshairs. Here’s why, and the achievable steps that turn you from a soft target into one attackers skip past.

/

August 27, 2026

The headlines this week grabbed everyone: US officials announced a state-sponsored hacking operation linked to China had targeted NASA, the Federal Reserve, the US Senate, the Department of Justice, and other agencies. It sounds like a spy thriller — but buried in it is a detail that matters enormously to ordinary small businesses, and it has nothing to do with being a government agency. The attackers didn’t launch from their own computers. They hijacked THOUSANDS of everyday internet-connected devices — ordinary routers and network gear belonging to regular people and businesses — and used them as disposable stepping stones to carry out and disguise their attacks. The equipment used to go after NASA may well have included hacked devices sitting in small offices that had no idea. To a global attacker, your under-secured router isn’t valuable for its data — it’s valuable as a weapon. Here’s why ‘we’re too small to be targeted’ misses the point entirely, and the ordinary fixes that keep your equipment from being conscripted.

/

August 23, 2026

The backpacks are packed and a new school year starts tomorrow — so here’s a thought to go with it: your business website is a lot like a student. And most small-business websites are the kind that aced one test years ago and have been coasting on that grade ever since, quietly falling behind while the rest of the class keeps moving. A website that was BUILT ONCE is very different from one that KEEPS SHOWING UP to learn. In honor of the first day of school, here’s what it means to have a website that behaves like a straight-A student instead of a forgotten one: it shows up every day (we don’t disappear after launch), it does its own real work (no AI slop — hand-built by a real engineer), it keeps learning all year (we continuously improve it), and it brings home results (leads and booked clients). Plus a quick report card you can run on your own website today.

/

August 20, 2026

Here’s a story that should permanently retire the most dangerous idea in small business security: ‘we’re too small to be a target.’ A company whose components sit inside Patriot and THAAD missile-defense systems, fighter jets, satellites, and torpedoes was just breached — not by a foreign intelligence service defeating military-grade defenses, but because ONE employee clicked ONE link. A fake ‘shared document’ from a supposed business contact, a counterfeit Microsoft login page, one password typed in, and an attacker was inside the mailbox of a company that arms the US military. We know the details precisely because they were disclosed in an SEC filing. The exact technique used here is the identical one aimed at accounting firms, medical practices, and contractors every day — and here’s what it means for you, including the one habit that would have stopped it cold.

/

August 20, 2026

Early on December 29, a steam turbine at a Polish power plant serving 50,000 people stopped — along with the system treating its water. When investigators spent three months piecing it together, they found something never documented before in a real attack. The hackers didn’t break into the plant directly. They broke into a separate WIND FARM miles away, then walked from one to the other through a shared network that NEITHER facility controlled. It’s the first known case of attackers reaching industrial controls this way — and the lesson isn’t about power plants. It’s about the trusted connections hiding in every business: the vendor with remote access, the managed device in the closet, the link between your two locations. Your security is only as strong as the things you’re connected to — including the ones you don’t control and can’t see.

/

August 20, 2026

There’s a comforting belief a lot of business owners hold: ‘if my files ever get locked up, I’ll just restore from backup and tell them to get lost.’ It’s a good instinct — and it’s exactly the plan a ransomware operation called Gunra is built to defeat. Gunra doesn’t just lock your files. It steals a copy first, then goes hunting for your backups to destroy them. When your safety net is gone, ‘I’ll just restore’ stops being an option. It’s serious enough that CISA, the FBI, and South Korean authorities issued a joint advisory. Here’s how it gets in (through unpatched firewalls and VPNs — a door you can close), the three-part squeeze it puts on victims, and the backup and patching habits that actually defeat it. Every part of its playbook has a specific, achievable counter.