Threat Intel & Security Guides
Breach breakdowns, practical advice, and actionable security tips for small business.
HIPAA Right of Access Requirements: OCR Just Fined an Eye Clinic $50,000 for One Patient's Records
On August 27, 2026, HHS OCR settled with Azul Vision for $50,000 after a patient waited about two years for records that 45 CFR 164.524 says must arrive in 30 days. What the rule actually requires, what you can charge, what you cannot refuse, and the five-column log OCR now makes violators keep.
The AI Cyber Defense Letter: What 155 Companies Just Asked Your 20-Person Firm to Do
On August 27, 2026, OpenAI published an open letter, co-signed by Anthropic, Google, Microsoft, Visa, Mastercard, Zurich Insurance and Marsh, warning that AI-enabled attacks get far more widespread within months. It never mentions small business. Here is what its 'every organization' paragraph actually asks, and where each instruction already lives in HIPAA, the FTC Safeguards Rule and NIST 800-171.
Unmarked CUI: Are You Still on the Hook If DoD Never Labeled It?
DoD's own Inspector General says DoD components routinely fail to mark CUI. Industry told the CMMC Reform Task Force the same thing. Here is what DFARS 252.204-7012 actually says about unmarked information, why the answer differs for data DoD gives you versus data you create, and how to sort it before it lands in your CMMC scope.
AI Browser Agent Security Risks: What the Zenity Attacks Mean for a Firm That Handles Client Data
Zenity Labs published working zero-click attack chains against Claude in Chrome and ChatGPT Atlas on August 5, 2026. One email or one planted comment led to inbox exfiltration, permanent Google Drive access, and account takeover. Neither vendor has a patch, because there is no bug to fix. What that means for a small regulated firm, and the five controls to put in place this week.
AI Vendor Outage Business Continuity: What HIPAA Already Requires, What CMMC Does Not, and What a 30-Person Firm Does This Week
An export-control order took Anthropic's newest models offline for 18 days. August added seven status-page incidents. Where an AI vendor outage sits in a HIPAA contingency plan, a Safeguards incident response plan, and a CMMC self-assessment.
CMMC Specialized Assets Just Got Tested: What CISA's Siemens PLC Advisory Means for a Small Defense Manufacturer
On August 19, 2026, NSA, CISA, FBI, DOE and EPA confirmed threat actors are using AI-generated scripts against internet-exposed Siemens S7 PLCs. Under 32 CFR 170.19 those PLCs are CMMC Specialized Assets, managed under risk-based policy rather than the 110 controls. The advisory is the first federal statement of what that policy has to cover.
AI-Powered Attacks on Small Businesses: What Five Weeks of AI Agent Incidents Mean for Your Firm
Between July 16 and August 23, 2026, AI agents hacked Hugging Face, went off script in UK government cyber tests, and pushed OpenAI to pause its own frontier training. The NCSC has issued interim guidance. What the escalation means for a small firm already running AI tools, and the controls to put in place this week.
CMMC Affirmation and the False Claims Act: The Pause Left One Signature Holding All the Risk
The July 13 suspension removed C3PAO assessments, not the annual affirmation under 32 CFR 170.22. With DOJ recovering $52M across nine cyber FCA settlements in FY2025 and whistleblowers driving the cases, the affirmation is now the entire compliance statement DoD receives from most contractors. What that concentration of risk means for the person who signs.
Shadow AI Breach Cost 2026: The Number Doubled and the Controls Went Backwards
IBM's 2026 Cost of a Data Breach Report found shadow AI in 43% of breaches, up from 20% a year earlier, at an average cost of $5.39 million. Meanwhile the share of organizations requiring IT approval before AI deployment fell from 45% to 38%. What that scissors pattern means for a 20 to 50 person firm in a regulated industry.
AI Meeting Assistant Security Risks: What the Fireflies and Otter.ai Lawsuits Mean for a Small Business
On August 12 an AI note-taker's transcript became the core of a discrimination suit against Marathon Engineering. On August 13 a federal judge let wiretap and biometric claims against Otter.ai proceed. What HIPAA, DFARS 252.204-7012, CIPA and BIPA require before the next bot joins your call.
AI Vendor Due Diligence: What to Ask When Software You Already Approved Adds AI
A vendor audit of 2,400 software providers found 63.6% never name the third-party AI subprocessor touching customer data. What 16 CFR 314.4(f), 45 CFR 164.308(b), and NIST AI RMF require when a vendor changes its data flow, plus the 12 questions to send.
HIPAA Breach Notification Requirements: The 60-Day Limit Is a Ceiling, Not a Deadline
OCR settled with a health system for $552,250 on July 29, 2026, and two of the four cited violations were timing failures. What 45 CFR 164.400 through 164.414 actually requires, including the two different 500 thresholds.
CMMC Level 1 Requirements: The 15 Controls, the Annual Affirmation, and Who Actually Needs It
CMMC Level 1 covers FCI, not CUI. The 15 requirements from FAR 52.204-21, why no POA&M is permitted, what the annual SPRS affirmation obligates, and what the Phase 2 suspension left untouched.
Can You Use ChatGPT With CUI? What DFARS and CMMC Actually Require in 2026
The CMMC Phase 2 suspension did not touch DFARS 252.204-7012. What the cloud clause requires of AI tools, which services qualify, and what to do when CUI lands in a chatbot.
AI Content Labeling Requirements: The Two Rules That Went Live on August 2, 2026
EU AI Act Article 50 and California's AI Transparency Act both became enforceable on August 2, 2026. What each one requires, and the third role that catches small firms.
CMMC Reform Task Force RFI: How a Small Contractor Files a Response Before August 14
The DoW RFI on CMMC reform closes at noon Eastern on August 14, 2026. The seven questions in plain English, what belongs in each answer, and how a small sub submits.
HIPAA Security Rule Changes in 2026: What Actually Changed, and What Slipped to 2027
The HIPAA Security Rule overhaul is still a proposed rule, now targeted for July 2027. The 2026 deadline that did bind was February 16, and most coverage never mentioned it.
AI Chatbot Disclosure Requirements: What US Companies Must Do by August 2, 2026
EU AI Act Article 50 applies August 2, 2026. The four-condition test that decides whether your chatbot needs an AI disclosure, and why US companies are in scope.
FAR CUI Rule Requirements: What the June 2026 Revision Actually Changed
The FAR CUI proposed rule was rewritten in June 2026. Reporting moved to 72 hours, the training mandate came out, and unmarked CUI stopped being an incident. Verified against 91 FR 37550.
When to Update Your HIPAA Risk Assessment: The Triggers OCR Actually Names
The HIPAA Security Rule sets no interval for risk analysis. It sets a trigger standard. Here is what actually forces an update, straight from 45 CFR 164 and OCR guidance.
How to Prepare for a DIBCAC Assessment: The Government Audit the CMMC Pause Did Not Touch
CMMC Phase 2 is suspended, but DIBCAC assessments are not. What DFARS 252.240-7997 obligates you to provide, what Medium and High assessments involve, and how to prepare.
Is ChatGPT HIPAA Compliant? What Changed in January 2026, and What Your Practice Does Now
Is ChatGPT HIPAA compliant? Consumer tiers are not and cannot be. Which OpenAI products can sign a BAA, what changed in January 2026, and the four steps for a practice whose staff is already using AI.
NIST 800-171 Self-Assessment Evidence: What Backs Your Score Now That No Assessor Is Coming
The CMMC pause made your self-assessment the only assessment DoD has. What evidence backs each of the 110 requirements, and what a defensible SPRS score requires.
Deepfake Fraud: How to Protect Your Small Business When You Can No Longer Trust a Voice
Deepfake fraud cost businesses $893M in 2025 per the FBI. The three process controls that stop voice cloning and CEO impersonation scams at a small firm.
Why Your CMMC Timeline Is a Scoping Decision, Not a Controls Problem
Every defense contractor faces the same 110 CMMC Level 2 controls. How you draw your CUI boundary under 32 CFR 170.19 decides whether prep takes a few months or most of a year. Here is how scoping works, and where it goes wrong.
Is CMMC Still Required? What the Phase 2 Suspension Did and Did Not Change
DoD suspended CMMC Phase 2 on July 13, 2026. Self-assessments, SPRS scores, and DFARS 7012 remain fully in force. What a small defense contractor should do now.
HIPAA Fines for Small Practices: What OCR Enforcement Actually Looks Like in 2026
Can a small practice get fined for HIPAA violations? Yes. Real OCR settlements from $10,000 up, the 2026 penalty tiers, and the one control regulators check first.
CMMC External Service Provider Requirements: Does Your MSP Need to Be Certified?
Your MSP does not need its own CMMC certification, but its services get assessed inside your assessment. What 32 CFR 170 requires of ESPs, CSPs, and the contractors who hire them.
NIST 800-171 Implementation Cost: The Itemized Breakdown for Small Defense Contractors
DoD's CMMC cost estimates put implementation at zero because the rule treats NIST 800-171 as already done. Here is the itemized bill for the readiness work, and which line items a small contractor can build in-house.
NIST 800-171 Rev 2 or Rev 3 for CMMC? What the July 2026 Interim Rule Changes
DoD's regulatory agenda shows an interim final rule this month setting the NIST 800-171 Rev 3 transition deadline. Here is what changes for CMMC Level 2, and why your assessment baseline is still Rev 2.
AI Acceptable Use Policy: What a Small Business Actually Needs in 2026
What an AI acceptable use policy must cover for a small business: approved tools, four data classes, incident reporting, and a one-session rollout plan.
CMMC Level 2 Self-Assessment: Requirements, Who Qualifies, and What Changes on November 10
CMMC Level 2 (Self) is appearing in live DoD solicitations right now, but you do not get to choose it. What 32 CFR 170.16 actually requires, how DFARS 252.204-7025 assigns your path, and why the window narrows after November 10, 2026.
Real Estate Wire Fraud: The $275 Million Problem Hitting Closings in 2026
FBI IC3 data shows real estate wire fraud cost $275.1M in 2025. How the scam works at closing, who is liable, and the call-back protocol that stops it.
CMMC Annual Affirmation Requirements: How Often, How to Submit, and What Happens If You Skip It
CMMC affirmations are due after every assessment, at POA&M closeout, and annually in SPRS. The full cycle under 32 CFR 170.22, the submission mechanics, and the award consequences under DFARS 252.204-7021.
AI Agent Security Risks: What Small Firms Must Check Before Agents Touch Client Data
AI agents inherit every permission of the account that runs them. What a small law firm, clinic, or CPA practice needs to check before connecting an agent to email, files, and client data, plus what belongs in an AI acceptable use policy.
HIPAA Risk Analysis Requirements in 2026: The Scope Gaps OCR Is Fining
What a HIPAA risk analysis has to cover in 2026, what OCR is actually fining, and why the AI and SaaS tools your staff already use belong in scope.
NIST 800-171 Rev 2 vs Rev 3: Which One CMMC Uses
CMMC Level 2 is still graded against NIST 800-171 Rev 2, not Rev 3. Which revision to build your SSP to in 2026, and why switching early can fail your assessment.
HIPAA Risk Analysis vs Risk Management: Why the Analysis Alone Will Not Save You
HIPAA risk analysis and risk management are two separate Security Rule requirements at 45 CFR 164.308(a)(1)(ii)(A) and (B). Here is the difference and why OCR enforces both.
HIPAA Security Risk Assessment: What the Rule Requires and Why OCR Keeps Citing It
A HIPAA security risk assessment is a required Security Rule specification at 45 CFR 164.308(a)(1)(ii)(A). Here is what it must cover and why OCR enforces it most.
CMMC Level 2 Cost for Small Business: What the Proposed Grant Pays For (and What It Doesn't)
A breakdown of what CMMC Level 2 actually costs a small defense contractor, what the Senate's proposed $100,000 grant would cover, and the much larger bill it leaves on your desk.
The CMMC Affirming Official: Who Signs, and What Their Name Is Actually On
Who is the affirming official for CMMC, what the annual affirmation under 32 CFR 170.22 attests to, and why that one signature carries personal False Claims Act liability every year.
CMMC Level 2 Certification Timeline: How Long It Really Takes, and Why June 2026 Is Late
How long does CMMC Level 2 certification take? Usually 6 to 12 months. With Phase 2 starting November 10, 2026, here is why mid-2026 is already late.
How Your NIST 800-171 SPRS Score Is Calculated (and What It Legally Commits You To)
How the DoD calculates a NIST 800-171 SPRS score, why it ranges from 110 down to minus 203, and what certifying that number legally commits a defense contractor to.
Who Signs Your CMMC Affirmation Is Personally on the Hook
The CMMC affirmation in SPRS is a legal certification a named senior official signs, not an IT task. What 32 CFR 170.22 requires and the False Claims Act exposure it creates for small defense contractors.
Which CMMC Gaps You Can POA&M (and the 63 You Can't)
CMMC POA&M eligibility under 32 CFR 170.21, explained: which controls you can defer to Conditional status, the 88-point floor, the six controls named out, and the 180-day clock.
DFARS 7019 Is Gone. Do You Still Need an SPRS Score?
DFARS 252.204-7019 was eliminated and 7020 renumbered on Feb 1, 2026. Here is what changed for your SPRS score and what every CUI contractor still has to do.
What Can Actually Go on a CMMC POA&M (and What Can't)
Under 32 CFR 170.21, only 1-point controls can sit on a CMMC Level 2 POA&M, and six of those are barred by name. Here is exactly what you can defer, what you can't, and the 180-day clock that starts the day you get conditional status.
What a C3PAO Actually Examines, Interviews, and Tests in a CMMC Level 2 Assessment
A CMMC Level 2 assessment grades 320 evidence objectives, not 110 controls. Here is what a C3PAO examines, interviews, and tests, and the evidence each method needs.
CMMC Evidence Checklist: What a C3PAO Examines, Interviews, and Tests
A C3PAO scores 320 NIST 800-171A objectives, not 110 controls. What assessors examine, interview, and test, and the evidence file that passes.
NIST 800-171 SPRS Score: How It's Calculated and Why It Now Carries Legal Weight
DoD now reviews your SPRS score at contract award. How NIST 800-171 scoring works, what the MORSECORP FCA settlement reveals, and how to check yours.
CMMC SSP Template: What NIST 800-171 Control 3.12.4 Requires (and What a C3PAO Actually Reads)
What NIST 800-171 control 3.12.4 requires in a CMMC Level 2 System Security Plan, what a C3PAO reads first, and the gaps that fail assessments.
What Your Prime Is Actually Accepting When They Say 'Be CMMC Certified by November 10'
A prime contractor's CMMC demand letter rarely means a full C3PAO audit by the deadline. Here is what a subcontractor actually has to show, and the three questions that decide it.
Shadow AI's Hidden OAuth Problem: How to Find Which AI Tools Can Reach Your Google Workspace
The April 2026 Vercel breach started with one employee clicking 'Allow All' on an AI tool. Here's the OAuth attack surface most small businesses can't see, and a step-by-step way to find and close it.
CMMC Phase 2 Explained: What November 10, 2026 Actually Means for a Small Defense Contractor
November 10, 2026 starts CMMC Phase 2, but it isn't a universal deadline. Here's what it actually means for small defense contractors, and what to do now.
You Can Be CMMC-Ready and Still Lose the Contract: The C3PAO Scheduling Wall Facing Defense Contractors in 2026
Readiness is only half the CMMC Phase 2 deadline. With ~759 assessors for tens of thousands of contractors and booking 6 to 9 months out, the assessor's calendar is the deadline that decides your eligibility.
The CMMC Phase 2 Readiness Checklist: What Defense Contractors Need to Do Before November 10, 2026
Phase 2 of CMMC begins November 10, 2026, when DoD contracting officers can require Level 2 C3PAO certifications as a condition of award. The DOJ recovered $51.8M across eight cyber-related False Claims Act settlements in FY 2025 — a 233% increase. Here is the six-step readiness checklist defense contractors need to complete before the deadline.
The $2M Lesson From Vercel: How One AI Chrome Extension Became a Supply Chain Breach
On April 19, 2026, a single OAuth grant to an AI Chrome extension cost Vercel a $2M stolen database. Here's the shadow AI playbook every SMB needs to run this week.
What AI Is Actually Doing Inside Your Business — And Why It's a Security Problem
98% of organizations have employees using unauthorized AI tools. Shadow AI creates compliance risks for healthcare, legal, and accounting firms that most small businesses don't see coming.
Tax Season Is Cyberattack Season. Your CPA Firm Is the Target.
Microsoft tracked 29,000 phishing emails targeting accountants in a single day in February 2026. The IRS just flagged phishing as the #1 threat on their 2026 Dirty Dozen list. Here's what's happening and how to protect your firm right now.
Your AWS Bucket Is Probably Leaking. Here's How to Check in 10 Minutes.
IBM's 2026 X-Force report found misconfigured access controls are the #1 cloud attack entry point — up 44% year over year. AI tools now find your misconfigs faster than your team can patch them. Here's a quick audit checklist.
Ransomware Is Shutting Down Job Sites. Why Construction Is Now a Top Cyber Target.
Project files, payroll data, subcontractor records, bid documents — everything ransomware operators want is sitting on your network right now. IBM's 2026 report shows manufacturing and construction at the top of the target list for the fifth straight year.
Scammers Are Cloning Your Kid's Voice With 3 Seconds of Audio. Here's How to Protect Your Family.
AI voice cloning now requires just 3 seconds of audio — enough to clone a voice from a single TikTok or Instagram clip. Scammers are using it to fake kidnappings and extort families. Here's what parents need to know.
Ransomware Shut Down Mississippi's Biggest Hospital for 9 Days. Here's What Clinics Need to Do Now.
The Medusa ransomware gang took out UMMC — 10,000 employees, Mississippi's only Level I trauma center, gone dark for 9 days. Here's the breakdown and what every clinic needs in place before it happens to them.
LexisNexis Breached. 3.9 Million Records Exposed. Law Firm Credentials Leaked.
A threat actor stole 3.9 million records from LexisNexis — including law firm credentials, government user data, and plaintext passwords. If your firm uses LexisNexis, here's exactly what to check right now.
AI Is Now Attacking Your SaaS. Here's What Changed.
IBM's 2026 X-Force report shows a 44% surge in AI-assisted attacks on SaaS apps. Here's what's actually different now — and what a small team can do about it today.
5.8 Million SSNs Exposed — The 700Credit Breach Every Dealership Needs to Know About
The 700Credit data breach exposed 5.8 million Social Security numbers through auto dealership credit applications. Here's what happened, what it means for your dealership, and what to do now.
Wire Fraud Is Crushing Real Estate — Here's How Agents Can Fight Back
Real estate wire fraud is up 300% in three years. Learn how agents, brokers, and title companies can protect closings from BEC scams.
// 67 POSTS PUBLISHED