SMB Tech & Cyber Newsletter | CPF Coaching

CPF Coaching | Christophe Foulon

I empower Chief Information Security Officers (CISOs) and Small to Medium-sized Businesses (SMBs) to elevate their cybersecurity strategies, guiding them past stagnation to achieve tangible outcomes. substack.cpf-coaching.com

  1. 3d ago

    Four Exploited Flaws and One Persistent Agent Problem

    Between September 27 and September 30, CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog. The affected products include Citrix NetScaler, Apple operating systems, and Cisco Catalyst SD-WAN Manager. Each entry received a three-day remediation deadline, and each requires forensic triage. During the same week, the United Kingdom’s privacy regulator moved to a board-led governance model, and Microsoft introduced Autopilot, a persistent agent designed to keep working when the user is not present. These developments are not the same problem. They do expose the same management gap. Technology can gain reach, authority, and urgency faster than a small business can assign an owner, preserve evidence, or stop the system. The answer is a 72-hour control plane: one short operating loop for urgent security work, regulatory evidence, and persistent AI actions . Secure your business with actionable insights tailored for IT and cyber executives. The SMB Tech & Cybersecurity Leadership Newsletter delivers practical risk management strategies straight to your inbox. Subscribe for free to stay ahead of the latest threats, or upgrade to a paid plan to unlock exclusive implementation frameworks and support our community. 1. Four Exploited Vulnerabilities Now Require Patch Evidence and Forensic Triage CISA added two Citrix NetScaler vulnerabilities on September 27. One can allow an unauthenticated attacker to execute arbitrary commands. The other can lead to remote code execution or denial of service. On September 29, CISA added an Apple CoreGraphics vulnerability that may allow arbitrary code execution. On September 30, it added a Cisco Catalyst SD-WAN Manager flaw that may let an unauthenticated attacker access the system with administrator privileges. The remediation windows were three days. CISA also marked forensic triage as required for all four entries. The job is not complete when the patch ticket closes. The business needs evidence that the affected system was identified, exposure was assessed, compromise checks were completed, and the owner accepted any remaining uncertainty. What SMB leaders should do now 1. Compare the four entries with internal assets and vendor-managed systems. 2. Record the owner, product version, internet exposure, remediation time, and evidence source for each match. 3. Preserve logs before changes remove useful evidence. 4. Require a compromise decision, not only a patch confirmation. 5. Escalate any missed deadline as accepted business risk. When a small team needs to reduce credential exposure during urgent response, 1Password can help separate privileged access and make credential rotation easier to verify: https://1password.partnerlinks.io/j7vr9u77t29s Affiliate sponsor 2. Privacy Governance Is Becoming More Explicit About Oversight and Accountability On September 30, the United Kingdom’s Information Commissioner’s Office formally transitioned to the Information Commission. The Data (Use and Access) Act 2025 changed the regulator from a corporation sole to a board-led governance structure. The regulator said its daily responsibilities will continue, while its future strategy will focus on AI, cyber resilience, children’s privacy, and public services. This change does not create a new checklist for every US-based SMB. It does show where regulatory oversight is moving. Privacy, cyber resilience, and AI are being managed as connected governance issues, with more explicit challenge and accountability at the top. An SMB does not need a regulator-sized board. It does need a record that can survive outside review. For each high-risk use of personal data, the business should be able to show the purpose, owner, data boundary, retention rule, approval, incident path, and latest control test. ### What SMB leaders should do now 1. Choose the three processing activities that could create the largest customer or employee impact. 2. Confirm that each activity has a named business owner and an independent reviewer. 3. Keep the decision record with the data map, vendor evidence, and test results. 4. Put unresolved privacy and cyber risk on a leadership agenda with a due date. When a team needs broader detection and response evidence across endpoints and identities, CrowdStrike can help make investigation and containment work more visible: https://crowdstrike2001.partnerlinks.io/crao4gjpq9ga Affiliate sponsor 3. Persistent AI Agents Need a Tested Stop Condition On September 25, Microsoft introduced a new Copilot experience that includes Autopilot, a persistent, proactive agent that can keep working when the user is not present. Microsoft also described wider access to business context through Fabric, Dynamics 365, and Power Platform. The productivity case is clear. A persistent agent can keep work moving across systems and reduce delays. The control question is also clear. An agent that keeps working without the user can repeat an error, use an outdated rule, or act on excessive permissions before a person notices. The right control is not a general statement that a human remains accountable. The business needs an operating record: approved purpose, allowed systems, maximum authority, review interval, spending or publishing limits, evidence retained, and a stop condition that another authorized person can use. What SMB leaders should do now 1. Start with one low-risk, reversible workflow and one measurable outcome. 2. Restrict the agent to the minimum systems and actions required. 3. Define events that pause the workflow automatically. 4. Review logs and exceptions before expanding authority. 5. Test the kill switch while the primary owner is unavailable. When AI workflows need policy, permission, approval, and monitoring boundaries, Airia can help govern the workflow before the agent gains broader authority: https://try.airia.com/hanp3sdhtshf-az7nx Affiliate sponsor The Leadership Decision This week’s three signals support one operating rule: authority must not move faster than evidence. Use a 72-hour control plane for high-authority technology. Name one owner. Limit access. Preserve evidence. Decide within the deadline. Test the stop condition. If the business cannot do those five things, it should not expand the system’s authority. Assess Drata With an Advisor Who Knows Your Environment CPF Coaching is a Drata channel partner. Drata brings GRC, Trust Centers, and Agentic Third-Party Risk Management into one platform. If you are comparing compliance, assurance, or vendor-risk options, contact me for a practical fit review. I will qualify your needs and submit the referral to Drata if the platform fits. Partner disclosure: CPF Coaching is a Drata channel partner. Request a Drata consultation Help Other Leaders Secure Their Future The Network Effect of SMB Security The most effective way to strengthen our SMB community is to share strategies that work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone’s business. Why Share This Subscription? When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team: * Zero-fluff technical execution: No high-level theory, just the steps to implement. * Cost-saving vendor analysis: An honest look at which tools are worth the SMB budget. * Direct coaching frameworks: Access to the same logic I use with private coaching clients. Pay It Forward: Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace. You’ve seen the "Why" behind this [Cyber/Tech Issue], but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan. The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock: * The “How-To” Framework: A step-by-step breakdown of the [Process/Tool] mentioned above. * Resource Toolkit: Downloadable templates and checklists I use with my private coaching clients. * The Bottom Line: Direct analysis of the ROI and cost-savings associated with this strategy Subscribe to Unlock the Full Strategy Join a community of SMB leaders who stop reacting to tech shifts and start leading them. Premium Implementation Package: The 72-Hour Control Plane Kit The free section explains the decision. This package gives the owner the records, procedure, and exercise needed to run it. Asset 1: 72-Hour High-Authority System Assessment Purpose: Decide whether a system may continue, must be restricted, or must stop during an urgent security, privacy, or AI event. Owner: Business system owner, supported by IT, privacy, legal, or the managed service provider. Inputs: Asset record, permissions, integrations, vendor notice, logs, data map, current controls, and incident history. Score ownership, authority, exposure, detection, decision window, containment, recovery, and independent review from 0 to 2. Zero means no usable evidence. One means partial or untested evidence. Two means current evidence exists and another person can review it. Decision criteria: - 13 to 16: Continue with routine monitoring. Fix any zero before authority expands. - 8 to 12: Restrict authority and close the largest gaps within seven days. - 0 to 7: Pause new use or external actions until an executive accepts the risk. Expected evidence: Completed assessment, named owner, permission export, remediation record, reviewer approval, and stop-test result. Next action: Score the three systems with the broadest authority before the next leadership meeting. Asset 2: Urgent Patch and Forensic Triage Proced

  2. Jul 17

    This Week's SMB Risk Signals: Router Hygiene, Genetic Data, and Agentic AI

    On July 13, 2026, CISA and a broad coalition of U.S. and allied agencies warned that Russian state-sponsored actors continue to exploit poorly configured routers across six critical sectors, often by abusing legacy SNMP settings and exposed management paths. On July 14, 2026, a 42-state coalition secured an $18 million settlement from 23andMe after a breach that affected 6.9 million consumers and exposed how weak multifactor authentication, weak monitoring, and vague deletion controls fail under pressure. Also on July 14, 2026, OpenAI argued that agentic AI investments should be measured by useful work per dollar and governed before advanced workflows scale. These are not three unrelated headlines. They are one operating problem. The systems you trust most now need explicit credentials, evidence, and approval paths. If a router can quietly hand over configuration data, if a sensitive-data platform cannot prove its basic safeguards were reasonable, or if an AI workflow scales before you can define who approves risky actions, the business is still running on trust it has not recently re-earned 1. Router Hygiene Still Decides Whether an Adversary Gets a Shortcut The July 13 advisory matters because it is not about exotic zero-days. It is about weak operational hygiene on devices that sit close to identity, routing, and network control. CISA said the actors primarily scan for poorly configured networking devices, especially routers, and use SNMP weaknesses, Cisco Smart Install, and exposed management portals to get what they need. Why You Should Be Concerned: * Six sectors were named: Communications, defense industrial base, energy, financial services, government services, and healthcare were identified as the highest-risk sectors, which is a reminder that routers stay business-critical even when they feel invisible. * Legacy settings are still the entry point: The advisory says the actors look for SNMP agents that accept common or default community strings, then use those settings to copy device configurations and send them off-network. * Credential quality is part of network defense: The mitigation guidance specifically calls for strong, unique passwords, secure storage, and local accounts used only for emergencies. Strategic Action: Treat routers, firewalls, and network-device management paths as privileged systems, not background plumbing. If you cannot name who owns their credentials, firmware cadence, and emergency access path, you do not yet control the trust boundary they create. This Week’s Leadership Move: * Confirm which routers, switches, and firewalls still allow SNMPv1, SNMPv2, or broad management access from outside your management network. * Require a named owner for every privileged network-device credential and rotate any password that is shared in tickets, notes, or chat history. * Ask your MSP or network partner to show whether Cisco Smart Install is disabled and which management ports remain externally reachable by exception. To prevent router and infrastructure credentials from quietly becoming shared liabilities, 1Password helps teams keep privileged access unique, auditable, and easier to rotate without passing secrets via email, notes, or tickets. Affiliate sponsor 2. The 23andMe Settlement Raises the Floor for Sensitive-Data Discipline The legal lesson from July 14 is not limited to genetic testing. It is about what regulators and attorneys general may now treat as the minimum reasonable standard when a company stores highly sensitive customer data. The 23andMe case turned a breach into a broad indictment of basic control failures. Why You Should Be Concerned: * The numbers are large and specific: The settlement announcement says the breach affected 6.9 million consumers, with some customer data later offered for sale on the dark web. * Basic safeguards were part of the case: New York’s attorney general said investigators found failures around breached-password blocklists, multifactor authentication, rate limiting, logging, monitoring, unusual-login review, and known-vulnerability remediation. * Deletion rights stayed on the table: The settlement also preserved consumer deletion rights and added new security expectations for the successor organization handling the data. Strategic Action: If your business stores health, payroll, identity, or customer-record data, assume a future regulator, insurer, or board member will ask whether your basic safeguards were visible, enforced, and tested before the incident. I know many SMB teams inherit sensitive-data platforms without a clean map of who owns account protections, retention settings, or breach detection. That is exactly why the control story has to be explicit now, before an incident writes it for you. This Week’s Leadership Move: * Enforce multifactor authentication on every admin and customer-support role that can view or export sensitive records. * Check whether your identity stack blocks known breached passwords and alerts on repeated login spikes, not just outright lockouts. * Test your delete, export, and incident-review workflow on one real system this week so you know who approves, who documents, and who confirms completion. SENSITIVE DATA FAILURES ARE ALSO OPERATING FAILURES The 23andMe settlement shows how quickly missing logs, weak credential controls, and unclear deletion rights become part of the legal record. If your controls exist only as assumptions, they will not hold up under investigation. Noted.Solutions is a stronger fit when your team needs to explain compliance controls, evidence expectations, and risk outcomes in language buyers and stakeholders actually understand instead of repeating generic trust claims. Sharpen the compliance narrative. Explore Noted.Solutions Affiliate sponsor 3. Agentic AI Should Be Measured by Accepted Work, Not Excitement OpenAI’s July 14 guidance is useful because it frames AI modernization as an operating-model decision rather than a model-shopping exercise. It says leaders should judge AI by useful work per dollar: tasks completed, time saved, decisions improved, and workflows ready to scale. Why You Should Be Concerned: * Model economics are moving fast: OpenAI says the price per million tokens fell 97% from GPT-4 to GPT-5.4, while GPT-5.6 delivered 54% fewer output tokens and 57% less time per task in the cited coding-agent index. * Cheap is not the same as effective: The guidance warns that the lowest token price can still lead to the highest total cost if the workflow fails, retries, or requires extensive correction. * Governance is the operating layer: OpenAI says leaders need to define what context AI can use, which tools it can access, what actions it can take, and who approves higher-risk steps before advanced workflows scale. Strategic Action: Do not scale agentic AI because it looks impressive in a demo. Scale the workflows where you can define the quality bar, the approval boundary, the evidence trail, and the cost of an accepted outcome. This Week’s Leadership Move: * Choose one workflow where AI can draft or review, but cannot complete the action without named human approval. * Measure the cost per accepted outcome rather than the raw token cost or time spent in the tool. * Document which data the workflow can access, who can raise limits, and which event triggers manual review. Final Thoughts for Leaders Router hygiene, sensitive-data liability, and agentic AI governance all point to the same truth: the systems with the most leverage deserve the clearest ownership. The question is not whether these tools are useful. The question is whether you can prove who controls the credentials, who preserves the evidence, and who approves the action when the stakes rise. Put one item on next week’s agenda: list the systems in your business that can quietly change access, expose sensitive data, or automate work across tools, and assign a credential owner, an evidence owner, and an approval owner to each one. If another operator on your team needs this framing, use the share and referral tools below before the premium section. Help Other Leaders Secure Their Future The Network Effect of SMB Security The most effective way to strengthen our SMB community is by sharing the strategies that actually work in the field. If you find value in these technical deep dives, helping a fellow leader bridge their tech gap makes the entire ecosystem more resilient. Cybersecurity is a collective effort, and more informed peers lead to a safer environment for everyone’s business. Why Share This Subscription? When you refer a colleague to this newsletter, you are giving them access to the same specialized insights you use to lead your team: * Zero-fluff technical execution: No high-level theory, just the steps to implement. * Cost-saving vendor analysis: An honest look at which tools are worth the SMB budget. * Direct coaching frameworks: Access to the same logic I use with private coaching clients. Pay It Forward. Use the button below to share this post or your unique referral link. When your peers join our community, we all benefit from a more secure and tech-forward marketplace. You’ve seen the "Why" behind this [Cyber/Tech Issue]—but knowing the risk is only half the battle. To move from awareness to actual protection, you need a localized execution plan. The remainder of this deep dive is designed specifically for the SMB leader who needs to move fast without a massive enterprise budget. By upgrading to a paid subscription, you unlock: * The “How-To” Framework: A step-by-step breakdown of the [Process/Tool] mentioned above. * Resource Toolkit: Downloadable templates and checklists I use with my private coaching clients. * The Bottom Line: Direct analysis of the ROI and cost-savings associated with this strategy Subscribe to Unlock the Full Strategy Join a community of SMB leaders who stop reacting to tech shifts and start leading them. Premium Intelligence: The Trusted S

About

I empower Chief Information Security Officers (CISOs) and Small to Medium-sized Businesses (SMBs) to elevate their cybersecurity strategies, guiding them past stagnation to achieve tangible outcomes. substack.cpf-coaching.com