Business leaders reviewing cyber risk trends

Cyber Risk Insights

Security Trends. Business Decisions. Practical Guidance.

Timely cybersecurity insights for growing businesses, government contractors, professional firms, and Microsoft 365 organizations.

MICROSOFT 365   |   CMMC   |   CYBER INSURANCE   |   HUMAN RISK

Latest Insights

Cyber Risk, Explained for Business Leaders.

Cyber Insurance Readiness Assessment

Cyber Insurance Claims Depend on What You Can Prove

JULY 2026

Cyber insurance is not simply a policy purchased and forgotten. Insurers increasingly ask whether businesses have MFA, secure backups, incident response plans, endpoint protection, and employee training.

In Travelers v. International Control Services, a ransomware incident led to a dispute over whether the company accurately represented its MFA implementation. The parties later agreed to void the policy. The business lesson is clear: application answers should match controls actually operating across the organization.

FTC CYBER INSURANCE GUIDANCE →
Microsoft 365 Security Assessment

One Microsoft 365 Identity Can Open the Entire Business

JULY 2026

In May 2026, Microsoft documented a Storm-2949 attack that began with social engineering and abuse of the password-reset process. Users were persuaded to approve fraudulent MFA prompts, allowing attackers to take control of their identities.

The attackers accessed Microsoft 365, downloaded thousands of files from OneDrive and SharePoint, and expanded into Azure resources. The incident demonstrates why security must include Conditional Access, privileged-role review, password-reset protection, application governance, and monitoring—not MFA alone.

MICROSOFT INCIDENT ANALYSIS →
CMMC Readiness Assessment Virginia

July 2026 CMMC Changes Do Not Eliminate Contractor Responsibility

JULY 2026

On July 13, 2026, the Department suspended CMMC Phase II implementation while reviewing the program. Phase I self-assessment requirements remain in place.

Contractors should not treat the suspension as permission to stop protecting federal information. Contract requirements, NIST SP 800-171 obligations, SPRS submissions, and affirmations may still apply. Organizations should confirm scope, requirements, implemented controls, and supporting evidence.

OFFICIAL CMMC UPDATE →
Deepfake Phishing Awareness Training

Deepfake Phishing Can Turn a Video Call Into Financial Fraud

JULY 2026

Deepfake attacks are no longer theoretical. Engineering firm Arup confirmed that an employee was deceived by AI-generated voices and images during a video meeting and transferred approximately $25 million.

In July 2026, the FBI warned that scammers were using AI-generated video, cloned voices, spoofed websites, and impersonation. Businesses need separate verification and approval procedures for payments, banking changes, password resets, and urgent executive requests.

FBI JULY 2026 WARNING →
Phishing-Resistant MFA for Microsoft 365

Attackers Are Learning How to Bypass Basic MFA

JULY 2026

In March 2026, Microsoft and international partners disrupted Tycoon 2FA, a phishing-as-a-service operation targeting Microsoft 365, Outlook, and Gmail accounts.

Microsoft reported that it supported tens of millions of fraudulent emails reaching more than 500,000 organizations each month. The lesson is not that MFA has failed; businesses need phishing-resistant MFA, properly configured Conditional Access, restricted administrator access, and employee verification procedures.

MICROSOFT DISRUPTION REPORT →

Turn Cyber Risk Into Clear Business Priorities.

Explore AST services or speak with a cybersecurity advisor.

Talk With an Advisor