Cyclone 365

Dependable Service. Consistent Results.

With over 25 years of industry experience, we provide a wide range of IT services for small and medium-sized businesses on the Gulf Coast.

Open weekdays from 9am to 5pm.

In-person office meetings by appointment only.

Why Your Cyber Insurance Renewal Application Got Longer

If you have a cyber insurance renewal coming up, the application in front of you is longer and far more specific than the one you filled out last time. That is not busywork. Every new question maps to a control that, when missing, allowed a major 2023 or 2024 claim to escalate into a very expensive loss.

Three events reshaped the forms. The MOVEit supply chain breach in 2023 eventually touched more than 2,650 organizations and over 66 million individuals, which changed how underwriters ask about third party software. The Change Healthcare ransomware incident in February 2024 froze claims processing nationwide, with reporting pointing to a missing multifactor authentication control on a key entry point and industry estimates placing insured losses above $250 million. The Arup deepfake wire fraud saw a finance employee send $25.6 million across 15 transfers after a video call with AI generated executives. Out of band callback verification is now on every underwriter's checklist because of it.

The backup question tightened first. What used to be a single yes or no now asks whether backups are immutable or air gapped, when they were last tested, and whether your domain administrator credentials could delete them. Native Microsoft 365 retention is no longer a passing answer. The strongest response references object lock or write once storage, an immutability window of at least 14 days with 30 preferred, credentials separated from production admin accounts, and a documented restore test.

MFA is no longer one checkbox. Carriers want it enforced on email, VPN, remote desktop, all administrator accounts, and privileged service accounts. SMS codes are now treated as the weakest factor available, so admin accounts should move to an authenticator app or hardware token. Many forms also ask about privileged access management, meaning a vaulting tool that rotates admin credentials on use and logs every session.

Wire verification gets its own section now. Expect to confirm that transfers above a stated threshold require a callback to a previously verified phone number, not the number on the request email, along with dual approval and annual social engineering training that covers deepfake awareness. Accounting firms, law firms holding trust accounts, and real estate brokerages handling escrow will see this section scrutinized hardest.

Antivirus alone no longer answers the endpoint question. Applications ask whether EDR is deployed across 100 percent of endpoints including servers, and whether a 24/7 security operations center watches the alerts. If MDR is on your roadmap but not yet live, give a real timeline. Underwriters can work with a scheduled deployment. They cannot work with vague intentions.

Vendor risk became a full section. You will likely be asked to list your top five software vendors with access to sensitive data and confirm whether each provides a SOC 2 Type II report. You are not expected to audit them, only to know who holds your data and to have asked the question.

The most expensive mistake on these forms is overstating what you have. Cyber applications are warranty documents, and if a forensic investigation after a claim finds your environment did not match your answers, the carrier can rescind the policy, which means coverage is treated as if it never existed and prior payouts can be clawed back. A declared gap with a remediation date costs you a premium adjustment. A misrepresentation costs you the entire claim.

Thirty days is usually enough to close the worst gaps. Start by confirming MFA coverage everywhere and moving admin accounts off SMS. Verify backup immutability and run a documented test restore. Write a one page wire transfer policy and have your authorizers sign it. Confirm EDR on every endpoint. Request SOC 2 reports from your top vendors. Then update your incident response plan and run a 60 minute tabletop exercise so you have evidence of testing within the past 12 months.

For businesses along the Gulf Coast, where hurricane season already forces hard conversations about continuity and recovery, cyber resilience belongs in the same plan. Cyclone 365 helps regional organizations close these exact gaps before renewal, from immutable backup and MFA enforcement to managed detection and response, so the answers on your application hold up under scrutiny. Call or Email us today!

Five Microsoft 365 Settings Worth Checking in Older Tenants

Microsoft has tightened several Microsoft 365 default settings over the past few years, but those changes rarely apply retroactively. If your tenant was created before 2022, configured by a previous IT provider, or simply left alone for a while, legacy settings are almost certainly still in place. Here are five worth verifying.

Default sharing links in SharePoint and OneDrive. Older tenants often default to "Anyone with the link," meaning any recipient can open a file without signing in, with no expiration and no record of who the URL was forwarded to. Newer Teams-created sites default to "Only people in your organization," but the tenant-level setting frequently still allows Anyone links. Switching the default to "Specific people" in the SharePoint admin center under Policies > Sharing forces authentication on every new link. Setting a maximum expiration for remaining Anyone links is a smart companion step. Roughly 15 minutes, with no impact on existing links until they are regenerated.

External email forwarding rules. Microsoft now blocks automatic forwarding to external addresses at the tenant level through the outbound spam policy. Rules created before that change can still be active, so a user who set up forwarding to a personal Gmail account years ago may still be exporting your data. In the Microsoft Defender portal, confirm the "Automatic forwarding rules" setting under your anti-spam outbound policy is set to Off or System-controlled, then audit existing inbox rules across your mailboxes. The Microsoft Purview audit log can surface inbox rule creation events.

Historical third-party app consents. A Microsoft-managed user consent policy arrived in July 2025, routing most third-party app requests to an admin for review. That change applies going forward only. Apps approved before the policy still hold whatever permissions they were granted, including access to mail, calendars, and files. Review them under Microsoft Entra ID > Enterprise Applications > All applications, sort by user consent, and revoke anything unrecognized or unused. Budget 30 to 60 minutes depending on how long the list is.

Audit log retention. As of October 2023, Audit (Standard) logs are retained for 180 days, up from 90. E5 licensing or the Purview Audit (Premium) add-on extends that to one year for Exchange, SharePoint, OneDrive, and Entra ID records. For Gulf Coast businesses in healthcare, financial services, or legal work, 180 days may fall well short of what HIPAA, the FTC Safeguards Rule, or state bar requirements assume you can produce. Retention policies live in the Microsoft Purview compliance portal under Audit > Audit retention policies.

MFA enforcement and Security Defaults. This is where older tenants are most often inconsistent. Tenants created before Security Defaults rolled out in late 2019 may have no baseline enforcement at all. There is also a common trap: when an admin enables a Conditional Access policy, Microsoft expects that policy to take over MFA enforcement and may switch Security Defaults off. A rushed transition can leave you with Security Defaults disabled and a Conditional Access policy that misses users. Check Security Defaults under Entra ID Properties, confirm a Conditional Access policy actively enforces MFA for all users including administrators, and pay close attention to break-glass accounts that may have been excluded and left unprotected.

A sensible order matters. Audit retention and the app consent review are silent to users, so start there. Verifying external forwarding comes next. The sharing default will generate questions from anyone used to clicking share and pasting a link, so communicate before you flip it. Save MFA and Conditional Access for last, since it carries the highest risk of locking people out.

A few caveats: some of these settings require Business Premium, E3, or E5 licensing, so a grayed-out toggle usually points to your license tier. None of them need to be changed all at once.

If you are not sure when your tenant was last reviewed, that is reason enough to look. Cyclone 365 works with businesses across the Gulf Coast to audit Microsoft 365 configurations, close the gaps that legacy settings leave behind, and keep tenants aligned with current security standards. Reach out and we will walk your environment with you. Call or Email us today!

Audit Your Permissions Before You Turn On Microsoft 365 Copilot

Microsoft 365 Copilot does not create new access to your data. It uses the access each user already has. That sounds reassuring until you look closely at what those permissions actually cover, because in most tenants access has been accumulating quietly for years.

Copilot retrieves information through Microsoft Graph, pulling from emails, calendar items, SharePoint documents, OneDrive files, Teams messages, and meeting transcripts that the signed-in user is authorized to see. Microsoft's own documentation is clear that Copilot can only summarize or reference content the user can already reach. That statement is accurate, and it is also exactly where the risk lives. The real question is whether each person's permission set still matches what you think it covers.

Why permissions drift

For a manufacturer or a trades business, most of what sits in Microsoft 365 is operational. Inventory records, production schedules, supplier contracts. Some of it is sensitive, but the fallout is usually contained if the wrong employee opens a file.

At a professional services firm, the files are the product. Client matters, settlement figures, fee arrangements, deal terms, and employment records are the deliverable, and confidentiality is the business model. Yet those files often live in environments that were never properly scoped.

The pattern is familiar. Someone gets access for a single matter, the matter closes, and the access is never removed. Multiply that across five years of staff changes, project onboarding, ad-hoc Teams channels, and external sharing links that never expired. If the permission exists, Copilot can use it, regardless of whether it was appropriate in the first place.

What that looks like in practice

A question as simple as "what deals are we working on" can pull together data room content that was never closed, pipeline trackers shared once for a partner meeting, and prospect lists in a Teams channel that outgrew its original membership. A search for a former employee's name can surface the termination memo, the severance calculation, and the performance review that preceded the exit. A question about compensation can return a spreadsheet HR shared with a hiring manager two years ago.

Nobody has to go looking with bad intent. Copilot simply answers the question with everything it is permitted to reach.

Small pilots are rarely as contained as they look

A limited trial feels like the safe middle ground, but most firms staff pilots with senior people, and senior people have the broadest access in the organization. That produces the highest-risk version of the test, not the lowest. Licenses also drift, getting reassigned to whoever asked most recently rather than whoever has the most appropriate access profile. Audit logs will tell you what was asked afterward, but a Copilot summary cannot be recalled once it has been returned.

The work that comes first

Microsoft publishes a deployment blueprint built around three pillars, and remediating oversharing sits first for a reason. The practical cleanup involves a SharePoint sharing audit to surface oversharing patterns and inactive sites, a review of OneDrive files still shared externally, a Teams membership review to confirm channels still reflect who belongs in them, and Microsoft Purview sensitivity labels applied to confidential material. Without labels, Copilot has no way to distinguish a client settlement document from a catering invoice.

For a firm in the 25 to 100 person range, this typically takes four to eight weeks. Much of it your IT partner can handle. The judgment calls, like which document categories deserve which label, are best made with input from the owners and partners who understand the material.

One question worth sending today

Ask whoever manages your Microsoft 365 environment for a report of every file accessible to more than ten people, flagged for client names, salary figures, or financial data. A useful answer within a few days means your tenant has been actively managed. An answer that starts with "we would need to enable some things first" tells you the sharing reports have never been run, and that is your real Copilot readiness assessment.

Cyclone 365 works with professional services firms across the Gulf Coast to audit tenant permissions, remediate oversharing, and apply the labeling and Data Loss Prevention policies that make Copilot safe to deploy. Get the environment right first, and the AI investment actually pays off. Call or Email us today!

Why Your Cyber Insurance Renewal Asks About Immutable Backups

Somewhere on your cyber insurance renewal application is a question that stops a lot of business owners cold: do you maintain immutable, air-gapped, or offline backups of your critical business data?

Carriers added that question because ransomware operators figured out that the fastest way to force a payout is to destroy the backups first and encrypt everything else afterward. CISA, the FBI, and the Internet Crime Complaint Center have all documented this as one of the most common moves in current ransomware playbooks. If an attacker can delete your backups with the same admin credentials they just stole, your only recovery path is paying the ransom.

What immutable actually means

An immutable backup cannot be changed or deleted for a fixed period of time, not by you, not by your IT provider, and not by anyone holding stolen admin credentials. The lock is enforced at the storage layer, so no level of privilege can override it during the retention window. Vendors call it object lock, WORM, or write-once-read-many. The label changes, but the control is the same.

Three setups that do not qualify

A NAS or external drive in your office is reachable from your network by design, which means ransomware can reach it too. These devices have a place in a broader strategy, but on their own they do not answer the question on the form.

Microsoft 365 retention is not a backup in the sense the application means. A global admin, or anyone who steals one, can delete data and purge retention holds. Microsoft's shared responsibility model places backup of your data squarely on you.

A cloud backup with immutability switched off is the most common gap we find in businesses along the Gulf Coast. The feature exists on most reputable platforms, but it is not always enabled by default, and you cannot tell from the outside without checking.

Three questions to send your IT provider

Send these before you check the box.

First, are our backups immutable, and how long is the immutability window? Most insurers now treat 14 days as a floor and 30 days as the preferred minimum, because attackers often sit inside a network for weeks before triggering encryption.

Second, if our domain admin or Microsoft 365 global admin account were stolen tomorrow, could that account be used to delete our backups? The correct answer is no.

Third, can you send documentation showing that immutability is enabled on our account? Verbal reassurance with nothing to show should be treated as a no.

What a qualifying setup looks like

Immutability has to be turned on, not merely available. Veeam, Datto, Rubrik, Acronis, and most S3-compatible storage providers support it, but a vendor name on the invoice does not answer the question by itself. Backup credentials need to sit outside your everyday administrative accounts so that one compromised login cannot reach both. The retention window needs to be long enough to give you a clean restore point from before the intruder arrived. And restores need to be tested, because most carriers now ask for the date of your last successful restore test.

If your honest answer is no

Declare what you actually have, then use the renewal date as your deadline to fix the gap. In many cases immutability is already supported on the platform you own, and switching it on is a configuration change rather than a new purchase.

Do not check yes to dodge a premium increase. Cyber insurance applications function as warranty documents. If a forensic investigation after a claim finds that your backups did not match what you declared, the carrier can rescind the policy and claw back prior payouts under the same term. Checking no will likely cost you something at renewal, and that cost is known and manageable. Misrepresentation is neither.

Cyclone 365 helps Gulf Coast businesses enable immutable backups, isolate backup credentials, verify restores, and produce the documentation carriers want to see. If you would rather answer that question with confidence at your next renewal, reach out to Cyclone 365 before the form is due. Call or Email us today!

How a Small Business Gets Ransomed in a Single Week

Most owners assume ransomware crews are chasing hospitals, banks, and national retailers. The incident numbers say otherwise. Small businesses are the most common ransomware target by volume, and the preferred range sits between 10 and 50 staff. A company that size has payroll, a customer database, project files, and an owner who will pay to get all of it back. What it usually does not have is a dedicated security team.

Here is how the week unfolds, written from the attacker's side. The company is composite, but the methods match current threat intelligence.

Monday, target selection. No breach and no inside tip. Public records do the work. State business registries, federal contract awards, and county licensing databases publish company names, registered agents, contract values, and named contacts. For a 22-person commercial services firm with a recent municipal job on file, a single search produces enough to begin. A clean incident history is a selling point to an attacker, because it suggests credentials are still valid and staff have never been trained to question anything.

Tuesday, the free org chart. Forty minutes in a browser is enough. LinkedIn supplies employee names and titles, including an office manager who lists accounts payable, payroll, and supplier invoicing in her profile. An old team photo post fills in the rest. Job listings mentioning QuickBooks or Sage reveal the accounting stack. The person who can approve a payment without a second signature becomes the primary target, not the owner.

Wednesday, fourteen dollars. Stealer logs are credential bundles harvested by malware from personal devices, then sold and searchable by company email domain. Two hits come back for this business. The office manager's password matches a pattern of a name plus a year plus a punctuation mark, and it already appeared in a retail breach three years ago. It was never changed. Password reuse across personal and business accounts is what turns a $14 purchase into full access.

Thursday, around the MFA. Push fatigue attacks largely stopped working once Microsoft enabled number matching by default for Authenticator notifications in May 2023. What still works is adversary-in-the-middle phishing. A convincing password reset email leads to a proxy page mirroring the real Microsoft sign-in screen. The victim enters her password, approves the prompt, and Microsoft issues a valid session token straight into the attacker's browser. The MFA challenge succeeds, and the attacker is signed in anyway. An inbox forwarding rule goes in quietly, and then the waiting starts.

Friday at 2:47pm. Thirty six hours of reading email is how the ransom gets priced. The cyber insurance policy shows a $250,000 sub limit. A bank reconciliation shows roughly $180,000 in the operating account. A message thread reveals a project with a hard deadline three weeks out. The demand lands at $65,000, deliberately low enough to be paid without a fight. The payload deploys on Friday afternoon, after the bookkeeper leaves and while the owner is on a job site. Total attacker spend, $14 and about six hours.

Five ordinary controls would have ended this. Enforcing unique passwords through a password manager and Microsoft Entra password protection makes purchased credentials worthless. Phishing-resistant MFA using FIDO2 keys, passkeys, or Windows Hello for Business defeats the session token capture, as do Conditional Access policies requiring a compliant device. Blocking external email forwarding at the tenant level removes the attacker's window into your inbox. Microsoft Defender for Business generates an alert the moment a forwarding rule is created, which means the detection existed and simply went unread. Finally, a practical conversation with your team about how much job detail belongs in a public profile removes the easy targeting.

Four of those five come bundled with licenses that most businesses in this size range already hold. The gap is rarely a missing product. It is configuration and attention.

If you want a straight answer on where you stand, ask your IT provider three things. Are we using phishing-resistant MFA for finance, admin, and executive logins? Is external email forwarding blocked at the tenant level? Are our security alerts going somewhere, and is somebody actually reviewing them?

Cyclone 365 works with contractors, professional services firms, and family owned businesses across the Gulf Coast to answer those questions properly, tighten Microsoft 365 configurations, and make sure the alerts your tools generate reach a human being. Reach out and we will walk your environment with you. Call or Email us today!

We provide IT support and services in and around these areas:

Mobile, AL Pensacola, FL Pascagoula, MS
Daphne, AL Fort Walton Beach, FL Gautier, MS
Fairhope, AL Destin, FL Ocean Springs, MS
Foley, AL Panama City, FL Biloxi, MS
Gulf Shores, AL Tallahassee, FL Gulfport, MS
Orange Beach, AL Lake City, FL Pass Christian, MS

★ Copyright © MMXXI. All rights reserved. ★