Cyclone 365

Dependable Service. Consistent Results.

With over 25 years of industry experience, we provide a wide range of IT services for small and medium-sized businesses on the Gulf Coast.

Open weekdays from 9am to 5pm.

In-person office meetings by appointment only.

Audit Your Permissions Before You Turn On Microsoft 365 Copilot

Microsoft 365 Copilot does not create new access to your data. It uses the access each user already has. That sounds reassuring until you look closely at what those permissions actually cover, because in most tenants access has been accumulating quietly for years.

Copilot retrieves information through Microsoft Graph, pulling from emails, calendar items, SharePoint documents, OneDrive files, Teams messages, and meeting transcripts that the signed-in user is authorized to see. Microsoft's own documentation is clear that Copilot can only summarize or reference content the user can already reach. That statement is accurate, and it is also exactly where the risk lives. The real question is whether each person's permission set still matches what you think it covers.

Why permissions drift

For a manufacturer or a trades business, most of what sits in Microsoft 365 is operational. Inventory records, production schedules, supplier contracts. Some of it is sensitive, but the fallout is usually contained if the wrong employee opens a file.

At a professional services firm, the files are the product. Client matters, settlement figures, fee arrangements, deal terms, and employment records are the deliverable, and confidentiality is the business model. Yet those files often live in environments that were never properly scoped.

The pattern is familiar. Someone gets access for a single matter, the matter closes, and the access is never removed. Multiply that across five years of staff changes, project onboarding, ad-hoc Teams channels, and external sharing links that never expired. If the permission exists, Copilot can use it, regardless of whether it was appropriate in the first place.

What that looks like in practice

A question as simple as "what deals are we working on" can pull together data room content that was never closed, pipeline trackers shared once for a partner meeting, and prospect lists in a Teams channel that outgrew its original membership. A search for a former employee's name can surface the termination memo, the severance calculation, and the performance review that preceded the exit. A question about compensation can return a spreadsheet HR shared with a hiring manager two years ago.

Nobody has to go looking with bad intent. Copilot simply answers the question with everything it is permitted to reach.

Small pilots are rarely as contained as they look

A limited trial feels like the safe middle ground, but most firms staff pilots with senior people, and senior people have the broadest access in the organization. That produces the highest-risk version of the test, not the lowest. Licenses also drift, getting reassigned to whoever asked most recently rather than whoever has the most appropriate access profile. Audit logs will tell you what was asked afterward, but a Copilot summary cannot be recalled once it has been returned.

The work that comes first

Microsoft publishes a deployment blueprint built around three pillars, and remediating oversharing sits first for a reason. The practical cleanup involves a SharePoint sharing audit to surface oversharing patterns and inactive sites, a review of OneDrive files still shared externally, a Teams membership review to confirm channels still reflect who belongs in them, and Microsoft Purview sensitivity labels applied to confidential material. Without labels, Copilot has no way to distinguish a client settlement document from a catering invoice.

For a firm in the 25 to 100 person range, this typically takes four to eight weeks. Much of it your IT partner can handle. The judgment calls, like which document categories deserve which label, are best made with input from the owners and partners who understand the material.

One question worth sending today

Ask whoever manages your Microsoft 365 environment for a report of every file accessible to more than ten people, flagged for client names, salary figures, or financial data. A useful answer within a few days means your tenant has been actively managed. An answer that starts with "we would need to enable some things first" tells you the sharing reports have never been run, and that is your real Copilot readiness assessment.

Cyclone 365 works with professional services firms across the Gulf Coast to audit tenant permissions, remediate oversharing, and apply the labeling and Data Loss Prevention policies that make Copilot safe to deploy. Get the environment right first, and the AI investment actually pays off. Call or Email us today!

Why Your Cyber Insurance Renewal Asks About Immutable Backups

Somewhere on your cyber insurance renewal application is a question that stops a lot of business owners cold: do you maintain immutable, air-gapped, or offline backups of your critical business data?

Carriers added that question because ransomware operators figured out that the fastest way to force a payout is to destroy the backups first and encrypt everything else afterward. CISA, the FBI, and the Internet Crime Complaint Center have all documented this as one of the most common moves in current ransomware playbooks. If an attacker can delete your backups with the same admin credentials they just stole, your only recovery path is paying the ransom.

What immutable actually means

An immutable backup cannot be changed or deleted for a fixed period of time, not by you, not by your IT provider, and not by anyone holding stolen admin credentials. The lock is enforced at the storage layer, so no level of privilege can override it during the retention window. Vendors call it object lock, WORM, or write-once-read-many. The label changes, but the control is the same.

Three setups that do not qualify

A NAS or external drive in your office is reachable from your network by design, which means ransomware can reach it too. These devices have a place in a broader strategy, but on their own they do not answer the question on the form.

Microsoft 365 retention is not a backup in the sense the application means. A global admin, or anyone who steals one, can delete data and purge retention holds. Microsoft's shared responsibility model places backup of your data squarely on you.

A cloud backup with immutability switched off is the most common gap we find in businesses along the Gulf Coast. The feature exists on most reputable platforms, but it is not always enabled by default, and you cannot tell from the outside without checking.

Three questions to send your IT provider

Send these before you check the box.

First, are our backups immutable, and how long is the immutability window? Most insurers now treat 14 days as a floor and 30 days as the preferred minimum, because attackers often sit inside a network for weeks before triggering encryption.

Second, if our domain admin or Microsoft 365 global admin account were stolen tomorrow, could that account be used to delete our backups? The correct answer is no.

Third, can you send documentation showing that immutability is enabled on our account? Verbal reassurance with nothing to show should be treated as a no.

What a qualifying setup looks like

Immutability has to be turned on, not merely available. Veeam, Datto, Rubrik, Acronis, and most S3-compatible storage providers support it, but a vendor name on the invoice does not answer the question by itself. Backup credentials need to sit outside your everyday administrative accounts so that one compromised login cannot reach both. The retention window needs to be long enough to give you a clean restore point from before the intruder arrived. And restores need to be tested, because most carriers now ask for the date of your last successful restore test.

If your honest answer is no

Declare what you actually have, then use the renewal date as your deadline to fix the gap. In many cases immutability is already supported on the platform you own, and switching it on is a configuration change rather than a new purchase.

Do not check yes to dodge a premium increase. Cyber insurance applications function as warranty documents. If a forensic investigation after a claim finds that your backups did not match what you declared, the carrier can rescind the policy and claw back prior payouts under the same term. Checking no will likely cost you something at renewal, and that cost is known and manageable. Misrepresentation is neither.

Cyclone 365 helps Gulf Coast businesses enable immutable backups, isolate backup credentials, verify restores, and produce the documentation carriers want to see. If you would rather answer that question with confidence at your next renewal, reach out to Cyclone 365 before the form is due. Call or Email us today!

How a Small Business Gets Ransomed in a Single Week

Most owners assume ransomware crews are chasing hospitals, banks, and national retailers. The incident numbers say otherwise. Small businesses are the most common ransomware target by volume, and the preferred range sits between 10 and 50 staff. A company that size has payroll, a customer database, project files, and an owner who will pay to get all of it back. What it usually does not have is a dedicated security team.

Here is how the week unfolds, written from the attacker's side. The company is composite, but the methods match current threat intelligence.

Monday, target selection. No breach and no inside tip. Public records do the work. State business registries, federal contract awards, and county licensing databases publish company names, registered agents, contract values, and named contacts. For a 22-person commercial services firm with a recent municipal job on file, a single search produces enough to begin. A clean incident history is a selling point to an attacker, because it suggests credentials are still valid and staff have never been trained to question anything.

Tuesday, the free org chart. Forty minutes in a browser is enough. LinkedIn supplies employee names and titles, including an office manager who lists accounts payable, payroll, and supplier invoicing in her profile. An old team photo post fills in the rest. Job listings mentioning QuickBooks or Sage reveal the accounting stack. The person who can approve a payment without a second signature becomes the primary target, not the owner.

Wednesday, fourteen dollars. Stealer logs are credential bundles harvested by malware from personal devices, then sold and searchable by company email domain. Two hits come back for this business. The office manager's password matches a pattern of a name plus a year plus a punctuation mark, and it already appeared in a retail breach three years ago. It was never changed. Password reuse across personal and business accounts is what turns a $14 purchase into full access.

Thursday, around the MFA. Push fatigue attacks largely stopped working once Microsoft enabled number matching by default for Authenticator notifications in May 2023. What still works is adversary-in-the-middle phishing. A convincing password reset email leads to a proxy page mirroring the real Microsoft sign-in screen. The victim enters her password, approves the prompt, and Microsoft issues a valid session token straight into the attacker's browser. The MFA challenge succeeds, and the attacker is signed in anyway. An inbox forwarding rule goes in quietly, and then the waiting starts.

Friday at 2:47pm. Thirty six hours of reading email is how the ransom gets priced. The cyber insurance policy shows a $250,000 sub limit. A bank reconciliation shows roughly $180,000 in the operating account. A message thread reveals a project with a hard deadline three weeks out. The demand lands at $65,000, deliberately low enough to be paid without a fight. The payload deploys on Friday afternoon, after the bookkeeper leaves and while the owner is on a job site. Total attacker spend, $14 and about six hours.

Five ordinary controls would have ended this. Enforcing unique passwords through a password manager and Microsoft Entra password protection makes purchased credentials worthless. Phishing-resistant MFA using FIDO2 keys, passkeys, or Windows Hello for Business defeats the session token capture, as do Conditional Access policies requiring a compliant device. Blocking external email forwarding at the tenant level removes the attacker's window into your inbox. Microsoft Defender for Business generates an alert the moment a forwarding rule is created, which means the detection existed and simply went unread. Finally, a practical conversation with your team about how much job detail belongs in a public profile removes the easy targeting.

Four of those five come bundled with licenses that most businesses in this size range already hold. The gap is rarely a missing product. It is configuration and attention.

If you want a straight answer on where you stand, ask your IT provider three things. Are we using phishing-resistant MFA for finance, admin, and executive logins? Is external email forwarding blocked at the tenant level? Are our security alerts going somewhere, and is somebody actually reviewing them?

Cyclone 365 works with contractors, professional services firms, and family owned businesses across the Gulf Coast to answer those questions properly, tighten Microsoft 365 configurations, and make sure the alerts your tools generate reach a human being. Reach out and we will walk your environment with you. Call or Email us today!

Clean Offboarding Starts on Day One

When an employee hands in their notice, the decisions that determine whether their departure is smooth or painful have already been made. They were made months earlier, during the new hire's first few weeks, when everyone was busy and a few shortcuts seemed harmless. A shared login here, a quick SaaS sign-up there, a personal laptop used until company hardware arrived. By month six, those shortcuts stop feeling like decisions and start feeling like standard practice.

A clean offboarding takes about 90 minutes. An account is disabled in your identity provider, which cascades access revocation across every connected tool. The device is wiped. Email is forwarded or converted to a shared mailbox. CRM and project accounts are reassigned. A handover note that was templated at onboarding gets filled in and filed.

The messy version takes three weeks. It begins with asking the departing employee to help reconstruct a list of tools nobody fully remembers. You uncover a Figma account, a Loom workspace, a Notion instance, all with passwords sitting in a personal password manager. The laptop is at their house. A client emails to say they received something strange from a personal address. Six weeks later, a vendor charges your card for a seat you thought was cancelled.

Four onboarding shortcuts that guarantee a painful exit

Letting new hires sign up for their own SaaS tools. An account created with a work email and a password only one person knows is functionally theirs. Provision every tool through a central identity system instead, connecting new applications to single sign-on before the first login.

Tolerating personal devices "just for now." Temporary never stays temporary. Once someone leaves, you cannot wipe company data from a device you never enrolled in a management system. Issue company hardware on day one and enroll it properly.

Sharing logins to avoid per-seat pricing. When five people share one credential, removing one person means changing the password for everyone. The savings reappear later as wasted hours and exposed access.

Letting client relationships live in one inbox. For Gulf Coast agencies and professional services firms, this is the expensive one. When the account manager leaves, the history and context leave too. A shared mailbox or CRM keeps the relationship with the business.

Retrofitting the team you already have

You cannot re-onboard existing staff, but you can close the gaps before the next departure. Pull three months of card statements and list every recurring SaaS charge, noting who set it up and who else could access it tomorrow. Build a device register covering who has what, when it was issued, and whether it is managed. Then move client communication into shared inboxes and CRM records so continuity belongs to the company.

None of this is a technology project. A spreadsheet, some honest conversations, and a few hours of your IT provider's time will cover most of it.

What your IT provider should be doing

Most providers get called when someone resigns. That is the wrong end of the lifecycle. The model that works puts your IT provider at onboarding, setting up identity accounts, enrolling devices, provisioning access through single sign-on, and maintaining a living handover document for every staff member.

Ask your provider what they do at onboarding. If the answer is "we usually just get called when someone leaves," that is worth a conversation.

Cyclone 365 works with businesses across the Gulf Coast to build onboarding processes that make every future departure a checklist instead of an excavation. Reach out to talk through what your next hire, and your next resignation, should look like. Call or Email us today!

Zombie Accounts Are Hiding in Your SaaS Stack

Someone leaves the company on a Friday. By Monday, their email is disabled and their laptop is back in the pile. What nobody checks is the project management tool they signed up for last quarter, the cloud storage folder they shared with a contractor, or the CRM login left over from a previous role. Three months later, those sessions are still active.

These are zombie accounts, and they form through an offboarding process built around corporate assets rather than how people actually use software. The average business now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three.

What makes a zombie account so dangerous is that it uses valid credentials. There is nothing suspicious to detect. The access was granted intentionally, and the system has no reason to question it. Industry research has found that half of all organizations have discovered former employees still reaching into SaaS applications months after their departure date, and for most of them, the discovery was accidental.

Three categories account for the majority of leftover access. Cloud storage and collaboration platforms like Google Drive, OneDrive, and Dropbox top the list, where guest permissions, personal-account shares, and open link settings survive long after the license is removed. Project management and CRM tools such as Asana, Notion, Jira, HubSpot, and Salesforce come next, since they are often provisioned by team leads rather than IT. The riskiest group is the shadow tools nobody registered at all, signed up for with a work email and never formally revoked.

The fix starts with a SaaS inventory. Pull every application connected to Microsoft Entra ID, Google Workspace Admin, or Okta, then cross-reference billing records, browser extensions, and login notification emails. One 2025 industry report analyzing 29 million user accounts identified nearly 24,000 distinct SaaS applications across its customer base, with 90 percent sitting outside IT management. For smaller teams, a focused 30-minute review of active subscriptions will surface most of the high-risk tools.

Next, take the last twelve months of departures and check each name against that inventory. Any access that belongs to someone who has left is a zombie. Revoke it, document what you found, and use those findings as the baseline for a stronger checklist. From there, enforce multi-factor authentication on every remaining account and schedule a SaaS access review each quarter so a one-time cleanup becomes a repeatable control.

Zombie accounts cannot be closed if nobody is looking for them. Cyclone 365 helps Gulf Coast businesses run a full zombie SaaS audit and build an offboarding process that holds up on every exit. Contact us to schedule a consultation. Call or Email us today!

We provide IT support and services in and around these areas:

Mobile, AL Pensacola, FL Pascagoula, MS
Daphne, AL Fort Walton Beach, FL Gautier, MS
Fairhope, AL Destin, FL Ocean Springs, MS
Foley, AL Panama City, FL Biloxi, MS
Gulf Shores, AL Tallahassee, FL Gulfport, MS
Orange Beach, AL Lake City, FL Pass Christian, MS

★ Copyright © MMXXI. All rights reserved. ★