Most Canadian SMBs rely on Microsoft 365 daily, but few understand where their responsibility begins. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
View in browser
contegoheader

Practical cybersecurity insights for Canadian small and mid-sized businesses.

This Month’s Focus: Microsoft 365 & Cloud Security Blind Spots

 

Most Canadian small businesses rely on Microsoft 365 to run their operations, from email and file storage, to collaboration, and increasingly, identity.

 

Most businesses assume it’s secure by default. It isn’t.

 

Microsoft secures the platform. You are responsible for how it’s configured, monitored, and protected. Misconfigured permissions, weak authentication policies, and lack of visibility are some of the most common entry points for attackers targeting SMBs.

 

This month, we’re looking at where Microsoft 365 environments typically fall short, and what business leaders should be reviewing before those gaps become incidents.

 

 

From the Contego Blog: Implementing MFA in Small Business Accounts

qtq80-wuj8UM-1110x550

In today’s digital era, security has become a cornerstone for any business, big or small. For small businesses especially, the need for robust security measures like Multi-Factor Authentication (MFA) is paramount. In this comprehensive guide, we will walk you through the steps to implement MFA in your small business effectively.

 

Read More

What's Happening in Canada

NS RCMP

NS RCMP Warns of Increasing Business Email Scams

 

Nova Scotia RCMP is warning people of an increasing scam technique that has been seen across the province between March and October.

 

Police say they have seen an increase in business email compromise (BEC) scams where scammers impersonate legitimate businesses using a fake email to deceive clients into sending payments to fraudulent accounts.

 

“Scammers create a fake but convincing email address that looks very similar to a legitimate business email,” said Const. Karren Jensen in the Tuesday news release.

 

“The cyberattacker then sends an email to the businesses’ clients, indicating that the company’s banking information has changed. When the clients then go to pay their bills, they unknowingly deposit cash into the attacker’s bank account instead of the business’s.”

 

Read More

House of Commons

Hackers Expose Microsoft Flaw to Breach Canada's House of Commons

 

Threat actors reportedly breached Canada’s House of Commons by exploiting a recently disclosed Microsoft vulnerability.

 

“The House of Commons and Canada’s cybersecurity agency are investigating a significant data breach caused by an unknown “threat actor” targeting employee information.” reported CBC News.

 

“According to an internal email obtained by CBC News, the House of Commons alerted staff on Monday that there was an information breach. It said a malicious actor was able to exploit a recent Microsoft vulnerability to gain unauthorized access to a database containing information used to manage computers and mobile devices.”

 

The intruders gained access to a House of Commons database, compromised information includes employees’ names, job titles, office locations and email addresses, as well as information regarding their House of Commons-managed computers and mobile devices.

 

Read More

What to Review This Month:

 

Is Multi-Factor Authentication (MFA) enforced for all users (especially admins)? Not optional. Not partial. Fully enforced.

 

Do you know who has administrative access to your environment? Review and reduce privileges to only what’s necessary.

 

Are inactive or former employee accounts still active? These are easy entry points for attackers.

 

Do you have visibility into login activity and anomalies? Without monitoring, suspicious access often goes undetected.

 

Are email security policies configured to prevent spoofing and phishing? Basic protections like SPF, DKIM, and DMARC should be in place. 

Book a Security Review

 

If you’re unsure how your Microsoft 365 environment is configured (or whether it would withstand a targeted attack) we can help you assess and secure it.

Book a consultation with Contego to get clarity on your current exposure and next steps.

 

Arrange My Consultation

Follow Us

Facebook
LinkedIn
X
YouTube
Website

Share This Content

Share on Facebook Share on Facebook
Share on LinkedIn Share on LinkedIn
Share on X Share on X

Contego Inc., 2115 South Service Road West, Unit #5, Oakville, Ontario L6L 5W2, Canada, (866) 331-3393

Unsubscribe Manage preferences