<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Starfish Computer Corporation]]></title><description><![CDATA[Plain-English cybersecurity for small and mid-sized businesses: what's changed, what it costs, and what to do next.]]></description><link>https://newsletter.starfishcomputer.com</link><image><url>https://substackcdn.com/image/fetch/$s_!EHLH!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff5ce3bd-20ae-4e96-a6a8-83ca36501641_1024x1024.png</url><title>Starfish Computer Corporation</title><link>https://newsletter.starfishcomputer.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 08 Oct 2026 00:27:14 GMT</lastBuildDate><atom:link href="https://newsletter.starfishcomputer.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Starfish Computer Corporation]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[starfishcomputer@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[starfishcomputer@substack.com]]></itunes:email><itunes:name><![CDATA[Starfish Computer Corporation]]></itunes:name></itunes:owner><itunes:author><![CDATA[Starfish Computer Corporation]]></itunes:author><googleplay:owner><![CDATA[starfishcomputer@substack.com]]></googleplay:owner><googleplay:email><![CDATA[starfishcomputer@substack.com]]></googleplay:email><googleplay:author><![CDATA[Starfish Computer Corporation]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Enhancing Cybersecurity for Ohio Businesses]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/ohio-cybersecurity</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/ohio-cybersecurity</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:20:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/mbua3n_-zsg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-mbua3n_-zsg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;mbua3n_-zsg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/mbua3n_-zsg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=mbua3n_-zsg">Watch the video on YouTube</a></p><p>Every Ohio business, whatever its size or industry, now runs on IT systems, and the attacks against those systems are landing closer to home. In May 2025, Dayton-area Kettering Health was hit by the Interlock ransomware group, forcing a system-wide outage across its 14 medical centers and more than 120 outpatient facilities (<a href="https://www.paubox.com/blog/kettering-health-ransomware-hit-1.7m-confirmed-year-after-interlock-breach">Paubox</a>). Strong cybersecurity is what keeps Ohio businesses competitive, compliant and open for business.</p><h2>Why cybersecurity matters for Ohio businesses</h2><p>High-profile incidents show what&#8217;s at stake when systems go down:</p><ul><li><p><strong>Ransomware can stop operations for weeks.</strong> At Kettering Health, attackers were inside the network for 41 days, from April 9 to May 20, 2025, before deploying ransomware, and the breach ultimately affected nearly 1.7 million people (<a href="https://www.paubox.com/blog/kettering-health-ransomware-hit-1.7m-confirmed-year-after-interlock-breach">Paubox</a>). The health system canceled elective procedures, diverted ambulances until May 28, and wasn&#8217;t fully operational until June 10 (<a href="https://www.classactionlawyers.com/blog/ketteringhealth">Schubert Jonckheer &amp; Kolbe</a>).</p></li><li><p><strong>Even global brands go dark.</strong> In July 2020, WastedLocker ransomware took down Garmin&#8217;s website, apps, customer support and call centers (<a href="https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/">BleepingComputer</a>).</p></li><li><p><strong>Outages don&#8217;t have to be attacks to hurt.</strong> AT&amp;T&#8217;s February 22, 2024 nationwide wireless outage was caused by a single misconfigured network change; the FCC found it blocked more than 92 million calls, including over 25,000 calls to 911 (<a href="https://www.androidauthority.com/fcc-report-att-outage-3464036/">Android Authority</a>; <a href="https://www.fierce-network.com/wireless/fcc-reports-atts-nationwide-outage-february">Fierce Network</a>).</p></li></ul><p>The numbers behind those headlines keep climbing. IBM&#8217;s 2026 research puts the average U.S. data breach at $11.5 million (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson</a>), and Verizon counted 7,152 confirmed breaches at small and mid-sized businesses in its 2026 report (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p><p>Every business needs to understand its own dependence on IT. If your operations rely on staying connected around the clock, you need a plan to keep running, or recover quickly, when a breach or outage hits.</p><h2>Ohio&#8217;s legal incentive to act</h2><p>Ohio offers something most states don&#8217;t: a legal reward for doing security well. Under the Ohio Data Protection Act (R.C. 1354), a business that creates, maintains and follows a written cybersecurity program reasonably conforming to a recognized framework, such as the NIST Cybersecurity Framework, can use it as an affirmative defense against tort claims after a data breach (<a href="https://codes.ohio.gov/ohio-revised-code/section-1354.02">Ohio Revised Code &#167; 1354.02</a>; <a href="https://www.dinsmore.com/publications/ohio-enacts-first-of-its-kind-data-protection-act">Dinsmore</a>). A written, followed plan is both good security and good legal protection.</p><h2>A strategic approach to cybersecurity</h2><p>Starfish Computer recommends four building blocks:</p><ul><li><p><strong>Risk assessment and strategy.</strong> Identify which parts of your business depend most on IT and which are most vulnerable. Unpatched software is now the most common way in, at 31% of breaches (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon</a>), so start with what&#8217;s exposed to the internet.</p></li><li><p><strong>Right-sized protection.</strong> Tailor security to the business, whether that&#8217;s protecting a small email-only operation or a full 24/7 environment.</p></li><li><p><strong>Written plans and policies.</strong> Make sure your team knows exactly what to do in a crisis, including how to work remotely and connect securely. Use multifactor authentication on every remote connection; CISA recommends phishing-resistant MFA such as passkeys and security keys where possible (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p></li><li><p><strong>Proactive monitoring and testing.</strong> Like a medical check-up, regular stress tests confirm that networks, backups and defenses work before an attacker tests them for you. Kettering&#8217;s 41-day dwell time shows why continuous monitoring matters.</p></li></ul><h2>Protect your Ohio business</h2><p>If your business is ready to strengthen its cybersecurity, Starfish Computer can help. Our team focuses on proactive strategies that stay ahead of evolving threats, with protection tailored to your operations. Contact us for a consultation and take the first step toward a written, defensible cybersecurity program.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.paubox.com/blog/kettering-health-ransomware-hit-1.7m-confirmed-year-after-interlock-breach">Paubox, &#8220;Kettering Health ransomware hit 1.7M, confirmed year after Interlock breach&#8221;</a></p></li><li><p><a href="https://www.classactionlawyers.com/blog/ketteringhealth">Schubert Jonckheer &amp; Kolbe, &#8220;Kettering Health Under Investigation for Data Breach of Patient Records&#8221;</a></p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/">BleepingComputer, &#8220;Garmin outage caused by confirmed WastedLocker ransomware attack&#8221;</a></p></li><li><p><a href="https://www.fierce-network.com/wireless/fcc-reports-atts-nationwide-outage-february">Fierce Network, &#8220;FCC says this is what caused AT&amp;T&#8217;s big outage in February&#8221;</a></p></li><li><p><a href="https://www.androidauthority.com/fcc-report-att-outage-3464036/">Android Authority, &#8220;AT&amp;T&#8217;s February outage blocked over 25,000 calls to 911&#8221;</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://codes.ohio.gov/ohio-revised-code/section-1354.02">Ohio Revised Code &#167; 1354.02</a></p></li><li><p><a href="https://www.dinsmore.com/publications/ohio-enacts-first-of-its-kind-data-protection-act">Dinsmore, &#8220;Ohio Enacts First of its Kind Data Protection Act&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[The Future of Remote Work and IT: Navigating the New Landscape]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/remote-work</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/remote-work</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:19:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/40DausapK_Y" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-40DausapK_Y" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;40DausapK_Y&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/40DausapK_Y?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=40DausapK_Y">Watch the video on YouTube</a></p><p>Remote and hybrid work have settled into a permanent part of how businesses operate, and the IT behind them now matters as much as the office. In March 2026, 22.6% of U.S. workers teleworked or worked from home for pay, a rate that has held between 21.5% and 23% for a year (<a href="https://www.bls.gov/opub/ted/2026/22-6-percent-of-workers-teleworked-in-march-2026.htm">BLS</a>). In financial services the share is far higher: 52.5% of workers in financial activities teleworked in June 2026 (<a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">BLS</a>).</p><h2>Finding the right balance</h2><p>Remote work is no longer a trend to watch; it&#8217;s an operating decision. The key is deciding how much remote work fits your business. Some roles need people on site, handling physical products or hands-on tasks. Many others can be done well from anywhere, which widens the talent pool you can hire from.</p><h2>What a remote-ready business needs</h2><ul><li><p><strong>Cloud services and IT management.</strong> Moving from on-premises systems to cloud services adds flexibility, but it requires well-managed infrastructure. Remember that in the cloud you still own the security of your data, user accounts and devices (<a href="https://learn.microsoft.com/en-ca/Azure/security/fundamentals/shared-responsibility">Microsoft Learn</a>).</p></li><li><p><strong>Secure remote access.</strong> Remote access is now a top target. Verizon found edge devices and VPNs rose from 3% to 22% of the systems attackers exploited in a single year (<a href="https://www.securityweek.com/verizon-dbir-flags-major-patch-delays-on-vpns-edge-appliances/">SecurityWeek</a>). Patch VPNs and firewalls quickly, require MFA on every remote login, and consider zero-trust tools that connect users only to the applications they need.</p></li><li><p><strong>Phishing-resistant sign-ins.</strong> Remote workers can&#8217;t walk down the hall to check whether a request is real. CISA calls phishing-resistant MFA, such as passkeys and security keys, the &#8220;gold standard&#8221; (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p></li><li><p><strong>Hybrid work policies.</strong> Clear policies on devices, home networks, data handling and approved AI tools protect the business and give employees clarity. Verizon found 45% of employees now regularly use AI on corporate devices, and many reach those tools through personal accounts (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>IT aligned with business goals.</strong> Technology choices should follow your strategy. At Starfish Computer, we look not just at the tools but at how they move your business forward, planning for both immediate needs and long-term growth.</p></li></ul><p>Businesses that plan for distributed work now will be better positioned than those that keep patching together short-term fixes.</p><h2>Plan your remote work strategy with Starfish Computer</h2><p>Whether you&#8217;re considering a hybrid model or tightening the security of an existing one, Starfish Computer can help you build the right foundation. Contact us to discuss how secure, well-planned IT can support a connected and adaptable workplace.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.bls.gov/opub/ted/2026/22-6-percent-of-workers-teleworked-in-march-2026.htm">U.S. Bureau of Labor Statistics, &#8220;22.6 percent of workers teleworked in March 2026&#8221;</a></p></li><li><p><a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">U.S. Bureau of Labor Statistics, &#8220;52.5 percent of workers in financial activities teleworked in June 2026&#8221;</a></p></li><li><p><a href="https://learn.microsoft.com/en-ca/Azure/security/fundamentals/shared-responsibility">Microsoft Learn, &#8220;Shared responsibility in the cloud&#8221;</a></p></li><li><p><a href="https://www.securityweek.com/verizon-dbir-flags-major-patch-delays-on-vpns-edge-appliances/">SecurityWeek, &#8220;Verizon DBIR Flags Major Patch Delays on VPNs, Edge Appliances&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Why Outsourcing Your IT Matters]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/outsourcing-it</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/outsourcing-it</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:18:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/MRNgJqDD65g" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-MRNgJqDD65g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;MRNgJqDD65g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/MRNgJqDD65g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=MRNgJqDD65g">Watch the video on YouTube</a></p><p>Most small and mid-sized businesses can&#8217;t afford, or can&#8217;t find, all the IT and security skills they need in-house, which is why outsourcing has become a strategy rather than a shortcut. A single network and computer systems administrator earned a median of $96,800 in 2024 (<a href="https://www.bls.gov/ooh/computer-and-information-technology/network-and-computer-systems-administrators.htm">BLS</a>), and one person can&#8217;t cover servers, cloud, security and help desk around the clock. Outsourcing gives you that range of expertise without the overhead of building a full department.</p><h2>The skills gap is real</h2><p>Finding the right people is getting harder, not easier. In ISC2&#8217;s 2025 Cybersecurity Workforce Study of more than 16,000 professionals, 95% reported at least one skills gap on their teams, and 59% called those gaps critical or significant, up from 44% in 2024 (<a href="https://www.securityinfowatch.com/cybersecurity/article/55338497/cybersecurity-skills-gaps-now-outpace-headcount-shortages-isc2-workforce-study-finds">SecurityInfoWatch</a>). The most-needed skills were AI (41%) and cloud security (36%) (<a href="https://www.csoonline.com/article/4108270/cybersecurity-skills-matter-more-than-headcount-in-the-ai-era.html">CSO Online</a>). Outsourcing is one of the three main ways security leaders are closing those gaps (<a href="https://meritalk.com/articles/isc2-report-cyber-experts-say-they-need-skills-more-than-headcount/">MeriTalk</a>).</p><h2>IT solutions tailored to your needs</h2><p>Starfish Computer isn&#8217;t just an outsourcing option; we&#8217;re a partner focused on helping your business grow. Our flexible approach fits the way you work today:</p><ul><li><p><strong>Full IT department.</strong> For businesses without IT staff, Starfish Computer can serve as your complete IT department, so technology supports your goals without the burden of managing it in-house.</p></li><li><p><strong>IT staff augmentation.</strong> Already have a team? We add specialized expertise in areas like firewalls, storage, cloud and security, without the cost of a full-time hire.</p></li><li><p><strong>Project-based support.</strong> For one-time needs such as a migration or a Windows 11 refresh, we provide scalable support on your timeline, so you don&#8217;t hire permanent staff for temporary work.</p></li></ul><h2>The benefits you can expect</h2><ul><li><p><strong>Predictable costs.</strong> Avoid the expense of hiring, training and retaining an internal IT team, with costs that scale as you grow.</p></li><li><p><strong>Access to expertise.</strong> Tap a team with current knowledge across networking, cloud, security and AI, instead of relying on one generalist.</p></li><li><p><strong>Focus on your core business.</strong> With IT handled, your leaders can spend their time on customers and growth.</p></li><li><p><strong>Scalability and flexibility.</strong> Adjust your IT capabilities as your business changes, without internal restructuring.</p></li><li><p><strong>Stronger security coverage.</strong> An outside team can provide monitoring, patching and incident response that most small businesses can&#8217;t staff on their own.</p></li></ul><h2>Get started with Starfish Computer</h2><p>Outsourcing your IT with Starfish Computer means more than filling gaps; it&#8217;s a partnership that helps your technology drive your business forward. Whether you need complete IT management or supplemental support, contact us to design a solution that fits your goals.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.bls.gov/ooh/computer-and-information-technology/network-and-computer-systems-administrators.htm">U.S. Bureau of Labor Statistics, Occupational Outlook Handbook: Network and Computer Systems Administrators</a></p></li><li><p><a href="https://www.securityinfowatch.com/cybersecurity/article/55338497/cybersecurity-skills-gaps-now-outpace-headcount-shortages-isc2-workforce-study-finds">SecurityInfoWatch, &#8220;Cybersecurity Skills Gaps Now Outpace Headcount Shortages, ISC2 Workforce Study Finds&#8221;</a></p></li><li><p><a href="https://www.csoonline.com/article/4108270/cybersecurity-skills-matter-more-than-headcount-in-the-ai-era.html">CSO Online, &#8220;Cybersecurity skills matter more than headcount in the AI era&#8221;</a></p></li><li><p><a href="https://meritalk.com/articles/isc2-report-cyber-experts-say-they-need-skills-more-than-headcount/">MeriTalk, &#8220;ISC2 Report: Cyber Experts Say They Need Skills More Than Headcount&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[How IT Planning Is Business Strategy]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/it-planning</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/it-planning</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:17:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/1oOWc9lqu3I" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-1oOWc9lqu3I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;1oOWc9lqu3I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/1oOWc9lqu3I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=1oOWc9lqu3I">Watch the video on YouTube</a></p><p>IT planning is no longer a back-office support task; it&#8217;s part of how a business sets and reaches its goals. Businesses worldwide are expected to spend $6.37 trillion on IT in 2026, up 14.2% from 2025, according to Gartner (<a href="https://www.telecomtv.com/content/digital-platforms-services/gartner-forecasts-worldwide-it-spending-to-grow-14-2-in-2026-totalling-6-37tn-55964/">TelecomTV</a>). The businesses that get value from that spending are the ones that plan it around their strategy.</p><h2>Integrating IT with business strategy</h2><p>Take customer communications as an example. Every company has some kind of customer contact center, whether it&#8217;s one front-desk employee or a dedicated team. Good IT planning keeps that operation running smoothly even when call volume spikes or staff are short, using tools such as overflow and rollover groups, call queues and auxiliary answering services.</p><p>Modern cloud phone and contact-center systems also provide detailed metrics: call volumes by hour, wait times, abandoned calls and agent workload. Reviewing those numbers helps you make informed staffing decisions and spot when your team is stretched too thin, giving employees room to perform well and improving profitability.</p><p>The same thinking applies across the business. If your field sales team loses time to unreliable hotel Wi-Fi, an IT plan might provide 5G hotspots or cellular-enabled laptops, along with secure remote access, so they stay productive and protected on the road.</p><h2>Security belongs in the plan</h2><p>IT planning now has to include cybersecurity from the start. The NIST Cybersecurity Framework 2.0 added a &#8220;Govern&#8221; function that makes leadership responsible for cybersecurity strategy, policy and oversight, alongside the business&#8217;s other risks (<a href="https://www.nist.gov/node/1539696">NIST</a>). In Ohio, a written cybersecurity program that follows a recognized framework can also serve as a legal defense after a breach (<a href="https://codes.ohio.gov/ohio-revised-code/section-1354.02">Ohio Revised Code &#167; 1354.02</a>).</p><p>Planning also means keeping technology current. Windows 10 reached end of support on October 14, 2025, and businesses still running it now pay rising fees for extended security updates (<a href="https://learn.microsoft.com/en-us/answers/questions/5704668/prize-for-windows10-extension-license">Microsoft Q&amp;A</a>). Hardware refreshes, software upgrades and license renewals should be on a multi-year roadmap, not handled as emergencies.</p><h2>IT as a strategic partner</h2><p>Many business leaders now see IT planning as a window into future growth. Working with IT experts, owners can map how the company should evolve over the next three to four years and align technology with those goals, including where AI tools can help and how to adopt them safely.</p><p>Starfish Computer provides that strategic view along with day-to-day support, so the technology you implement matches your business objectives.</p><h2>Why choose Starfish Computer?</h2><p>The right IT partner understands your business, not just your equipment. Our team identifies pain points and delivers practical solutions, whether that&#8217;s analyzing customer-interaction data, improving connectivity for remote staff or building a security roadmap.</p><h2>Contact us today</h2><p>If you&#8217;re ready to make IT planning part of your business strategy, contact Starfish Computer. We&#8217;ll assess your current infrastructure and build a plan that aligns technology with your goals, from contact-center operations to field connectivity to a multi-year IT roadmap.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.telecomtv.com/content/digital-platforms-services/gartner-forecasts-worldwide-it-spending-to-grow-14-2-in-2026-totalling-6-37tn-55964/">TelecomTV, &#8220;Gartner forecasts worldwide IT spending to grow 14.2% in 2026, totalling $6.37tn&#8221;</a></p></li><li><p><a href="https://www.nist.gov/node/1539696">NIST, Cybersecurity Framework 2.0 for Small Business</a></p></li><li><p><a href="https://codes.ohio.gov/ohio-revised-code/section-1354.02">Ohio Revised Code &#167; 1354.02</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/answers/questions/5704668/prize-for-windows10-extension-license">Microsoft Q&amp;A, Windows 10 ESU pricing</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Assessing Your IT Security]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/assessing-it-security</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/assessing-it-security</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:16:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/kKgGUiTN0hk" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-kKgGUiTN0hk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;kKgGUiTN0hk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/kKgGUiTN0hk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=kKgGUiTN0hk">Watch the video on YouTube</a></p><p>You can&#8217;t protect what you haven&#8217;t measured. Exploiting vulnerabilities is now the most common way attackers get into a business, at 31% of breaches, overtaking stolen credentials (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). Assessing your IT security on a regular schedule is how you find those openings before someone else does. Having security tools in place is only the start; you also have to keep checking that they work and keep strengthening them.</p><h2>Why a security assessment matters now</h2><p>Most organizations are falling behind on the fixes that matter most. Only 26% of the critical vulnerabilities in CISA&#8217;s Known Exploited Vulnerabilities catalog were fully remediated in 2025, down from 38% the year before, and the median time to fix them grew to 43 days (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). CISA recommends using that catalog to decide what to patch first (<a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA</a>). Aging systems add to the problem: Windows 10 stopped receiving free security updates on October 14, 2025, so any PC still running it without extended updates is falling further behind every month (<a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft</a>).</p><h2>How Starfish Computer assesses your environment</h2><p>Starfish Computer starts by learning how your business works and which technology it depends on. Then we evaluate your network systematically with our assessment tool, looking for weaknesses an attacker could exploit.</p><ul><li><p><strong>Detailed equipment analysis.</strong> We review every device on your network, from firewalls and switches to servers and workstations, looking for weak configurations, unsupported software and outdated hardware that create risk.</p></li><li><p><strong>Identifying security gaps.</strong> We look for common oversights such as missing multifactor authentication and open ports. CISA notes that some forms of MFA can still be phished or bypassed and calls phishing-resistant MFA the gold standard (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>), so we check which kind you use, too.</p></li><li><p><strong>Custom solution design.</strong> We turn the findings into a plan built for your company: the policy changes needed to tighten security, user training that helps staff spot and report threats, and any additional tools that would strengthen your defenses.</p></li></ul><h2>A structured process for immediate and long-term protection</h2><p>Findings only help if they get fixed in the right order. We roll out improvements in phases so the most serious risks are handled first and the cost and workload stay manageable.</p><ul><li><p><strong>Immediate actions.</strong> Critical changes, such as resetting compromised passwords or closing an exposed port, happen right away. Simple policy changes can sharply reduce risk in days.</p></li><li><p><strong>Priority-based execution.</strong> We lay out the order in which the remaining issues should be addressed, so your budget goes to the most severe threats first.</p></li><li><p><strong>Ongoing partnership.</strong> Security isn&#8217;t a one-time project. We reassess as your business and the threats change, and we align the plan with the NIST Cybersecurity Framework 2.0, which NIST designed for organizations of every size, including small businesses (<a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST</a>).</p></li></ul><p>For Ohio businesses there is a legal reason to document this work. Under Ohio law, a business that maintains a written cybersecurity program reasonably conforming to an industry-recognized framework can use it as an affirmative defense against certain tort claims after a data breach (<a href="https://codes.ohio.gov/ohio-revised-code/section-1354.02">Ohio Revised Code</a>).</p><h2>Schedule your IT security assessment</h2><p>Don&#8217;t leave your IT security to chance. Rather than waiting for a real attack to show you where the gaps are, let Starfish Computer stress test your environment first. Contact us to schedule an assessment. Our team, including experts like Adam, will work with you to build a security plan that fits your business and keeps your data and operations safe.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA, &#8220;Known Exploited Vulnerabilities Catalog&#8221;</a></p></li><li><p><a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft, &#8220;Windows 10 support has ended on October 14, 2025&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li><li><p><a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST, &#8220;NIST Releases Version 2.0 of Landmark Cybersecurity Framework&#8221;</a></p></li><li><p><a href="https://codes.ohio.gov/ohio-revised-code/section-1354.02">Ohio Revised Code &#167; 1354.02</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Effortless Cloud Migration: Revolutionizing Business Efficiency]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/cloud-migration</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/cloud-migration</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:15:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/7muUr7pdkVQ" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-7muUr7pdkVQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;7muUr7pdkVQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/7muUr7pdkVQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=7muUr7pdkVQ">Watch the video on YouTube</a></p><p>Many businesses still run file sharing, email or a key business application on a server in a back closet. If that server runs Windows Server 2016, Microsoft's extended support ends in January 2027 (<a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2016">Microsoft</a>), after which it stops receiving regular security updates. That deadline makes this a good time to decide what belongs in the cloud.</p><h2>Why businesses move to the cloud</h2><p>A business-class server can cost around $20,000 and typically lasts about five years before it needs to be replaced. Moving to the cloud trades that recurring purchase, and the hardware failures and renewals that come with it, for a service you pay for as you use it.</p><ul><li><p><strong>Lower costs.</strong> Eliminating server hardware and its maintenance frees up money for other priorities.</p></li><li><p><strong>Flexibility and accessibility.</strong> Employees can work from home, the office or the road with the same tools, which keeps work moving through sick days, bad weather and travel. Remote work is a fixture in many industries: in June 2026, 52.5% of workers in financial activities and 41.8% in professional and business services teleworked (<a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">BLS</a>).</p></li><li><p><strong>Better connectivity.</strong> Fiber, faster broadband and 5G wireless make reliable remote access practical in more places than ever.</p></li><li><p><strong>Scalability.</strong> Cloud resources grow or shrink with your needs, so you are not buying hardware for capacity you might use years from now.</p></li></ul><p>The productivity gain is real. A technical problem with one office server no longer means hours of downtime for everyone, and tasks that once required a trip to the office can be handled in minutes from wherever you are.</p><h2>How to plan a smooth migration</h2><p>Moving to the cloud should be planned like any other major project. Microsoft's Cloud Adoption Framework recommends several practices we follow (<a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/migrate/plan-migration">Microsoft</a>):</p><ul><li><p><strong>Assess readiness first.</strong> Review your team's skills and bring in outside expertise when you lack migration experience, which reduces risk and speeds up the project (<a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/migrate/plan-migration">Microsoft</a>).</p></li><li><p><strong>Map dependencies.</strong> Identify which systems depend on each other so connected pieces move together and nothing breaks during the cutover (<a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/migrate/plan-migration">Microsoft</a>).</p></li><li><p><strong>Start simple.</strong> Move less complex, lower-risk workloads first, and schedule critical systems once the process is proven (<a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/migrate/plan-migration">Microsoft</a>).</p></li><li><p><strong>Plan for rollback.</strong> Define what counts as a failed migration and test a plan to return to a known-good state before you begin (<a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/migrate/plan-migration">Microsoft</a>).</p></li><li><p><strong>Secure it from day one.</strong> Third parties were involved in 48% of breaches in Verizon's 2026 report, and only 23% of third-party organizations fully fixed missing or weak multifactor authentication on their cloud accounts (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). Turn on MFA and review access settings as part of the move, not afterward.</p></li><li><p><strong>Watch the bill.</strong> Flexera estimates 29% of cloud spend is wasted (<a href="https://www.flexera.com/about-us/press-center/flexera-finds-cloud-value-is-rising-while-ai-waste-grows">Flexera</a>). Right-size services after migration and review costs regularly.</p></li></ul><h2>Start your cloud migration with Starfish Computer</h2><p>Starfish Computer helps businesses move to the cloud with a plan built around their specific needs, so they can simplify operations, reduce costs and improve productivity. Moving to the cloud can seem daunting, but with personalized guidance and support, the transition can be smooth and predictable. Whether you are replacing an aging server or looking for more flexible ways to work, contact Starfish Computer to plan your move to the cloud.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2016">Microsoft Learn, &#8220;Windows Server 2016 lifecycle&#8221;</a></p></li><li><p><a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">U.S. Bureau of Labor Statistics, &#8220;52.5 percent of workers in financial activities teleworked in June 2026&#8221;</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/migrate/plan-migration">Microsoft Learn, Cloud Adoption Framework, &#8220;Plan your migration&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, &#8220;2026 Data Breach Investigations Report, Executive Summary&#8221;</a></p></li><li><p><a href="https://www.flexera.com/about-us/press-center/flexera-finds-cloud-value-is-rising-while-ai-waste-grows">Flexera, &#8220;Flexera Finds Cloud Value is Rising While AI Waste Grows&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Discover the 9 Advantages of VoIP Technology]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/voip-advantages</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/voip-advantages</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:14:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/8qf-cLPQ5qY" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-8qf-cLPQ5qY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;8qf-cLPQ5qY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/8qf-cLPQ5qY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=8qf-cLPQ5qY">Watch the video on YouTube</a></p><p>Traditional copper phone lines are on their way out. AT&amp;T plans to essentially retire its copper network by 2029 (<a href="https://www.telecompetitor.com/att-plans-copper-retirement-by-2029-heres-how/">Telecompetitor</a>), and in March 2026 the FCC moved to simplify the rules that govern retiring copper networks (<a href="https://fiberbroadband.org/advocacy/fcc-copper-retirement-march-23-2026/">Fiber Broadband Association</a>). For businesses still relying on traditional lines, Voice over Internet Protocol (VoIP) is the practical path forward, and it brings real advantages beyond simply replacing a dial tone.</p><h2>Nine advantages of VoIP</h2><ul><li><p><strong>Lower costs.</strong> Traditional phone systems carry setup and maintenance costs for on-site hardware and separate phone lines. VoIP runs over your internet connection, which typically lowers those costs, along with long-distance and international calling charges.</p></li><li><p><strong>Agility and mobility.</strong> Staff can make and take business calls from a desk phone, laptop or mobile app anywhere they have a reliable connection. That matters in the industries we serve: in June 2026, 52.5% of workers in financial activities and 41.8% in professional and business services teleworked (<a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">BLS</a>).</p></li><li><p><strong>Disaster recovery.</strong> If an office loses power or connectivity, calls can be rerouted to another location, to mobile apps or to voicemail, keeping your business reachable with minimal downtime.</p></li><li><p><strong>High-quality audio.</strong> On a properly configured network with adequate bandwidth, VoIP delivers clear, high-definition audio that matches or exceeds traditional lines.</p></li><li><p><strong>Less hardware.</strong> A hosted VoIP system replaces the on-premises phone system in the back closet. Phones simply plug into the network, which reduces hardware costs and clutter.</p></li><li><p><strong>Scalability.</strong> Adding or removing lines takes minutes, not a service call. Whether you are opening a branch or downsizing, the system adjusts with you.</p></li><li><p><strong>Integrated features.</strong> Voicemail-to-email, call forwarding, auto attendants, call recording and integrations with customer relationship management (CRM) and collaboration tools come standard in most modern platforms.</p></li><li><p><strong>Environmental impact.</strong> Fewer on-site systems mean less equipment to manufacture, power and cool, which supports more sustainable operations.</p></li><li><p><strong>The new standard.</strong> With carriers retiring copper and regulators moving to ease the transition (<a href="https://fiberbroadband.org/advocacy/fcc-copper-retirement-march-23-2026/">Fiber Broadband Association</a>), internet-based voice is becoming the standard for business phone service. Moving now lets you plan the change on your schedule instead of a carrier's.</p></li></ul><h2>What to plan for before you switch</h2><ul><li><p><strong>911 compliance.</strong> Under Kari's Law, multi-line telephone systems must allow users to dial 911 directly, without a prefix, and must notify a central point such as a front desk. RAY BAUM'S Act rules require a dispatchable location, such as a street address plus floor or room, to be sent with 911 calls from these systems and from interconnected VoIP services (<a href="https://www.kelleydrye.com/viewpoints/blogs/commlaw-monitor/fcc-orders-implementation-of-direct-911-dialing-and-dispatchable-location-for-multi-line-telephone-systems-extends-location-obligations-of-interconnected-voip-and-trs-providers">Kelley Drye</a>).</p></li><li><p><strong>Network readiness.</strong> Voice quality depends on your network. Plan for sufficient bandwidth, quality of service settings, a backup internet connection and battery backup for network equipment.</p></li><li><p><strong>Security.</strong> Protect admin portals with multifactor authentication, restrict international calling you do not need, and monitor for toll fraud. Criminals increasingly use the phone: in phishing simulations, voice and text lures succeeded at a median rate 40% higher than email (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>Legacy lines.</strong> Alarm panels, elevators and fax machines often still depend on copper lines. Identify them early so they are not left behind.</p></li></ul><h2>Make the move to VoIP with Starfish Computer</h2><p>Starfish Computer helps businesses move to VoIP smoothly and effectively. We know new technology can feel daunting, so we provide support through every step, from initial assessment to full implementation and ongoing maintenance, tailored to your business. If you are ready to replace aging phone lines, contact Starfish Computer to discuss how VoIP can support your business's communication.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.telecompetitor.com/att-plans-copper-retirement-by-2029-heres-how/">Telecompetitor, &#8220;AT&amp;T Plans Copper Retirement by 2029: Here&#8217;s How&#8221;</a></p></li><li><p><a href="https://fiberbroadband.org/advocacy/fcc-copper-retirement-march-23-2026/">Fiber Broadband Association, &#8220;FCC Copper Retirement, March 23, 2026&#8221;</a></p></li><li><p><a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">U.S. Bureau of Labor Statistics, &#8220;52.5 percent of workers in financial activities teleworked in June 2026&#8221;</a></p></li><li><p><a href="https://www.kelleydrye.com/viewpoints/blogs/commlaw-monitor/fcc-orders-implementation-of-direct-911-dialing-and-dispatchable-location-for-multi-line-telephone-systems-extends-location-obligations-of-interconnected-voip-and-trs-providers">Kelley Drye, &#8220;FCC Orders Implementation of Direct 911 Dialing and Dispatchable Location for Multi-Line Telephone Systems&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, &#8220;2026 Data Breach Investigations Report, Executive Summary&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Six Essential Tips for Better Cybersecurity]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/cybersecurity-tips</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/cybersecurity-tips</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:13:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/l9h9-CWe1iw" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-l9h9-CWe1iw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;l9h9-CWe1iw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/l9h9-CWe1iw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=l9h9-CWe1iw">Watch the video on YouTube</a></p><p>Most breaches still start with the basics: an unpatched system, a stolen password or a convincing message. Verizon&#8217;s 2026 report found that exploiting vulnerabilities is now the most common way attackers get in, at 31% of breaches, with credential abuse at 13% (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). The six tips below, drawn from our video conversation with Adam from Starfish Computer, cover the controls that close those doors for most businesses.</p><h2>Six tips that stop most attacks</h2><ul><li><p><strong>Turn on multifactor authentication everywhere.</strong> With MFA, a stolen password alone isn&#8217;t enough to get in. Use it on email, remote access, banking and every cloud app. CISA calls phishing-resistant MFA, such as FIDO security keys, the gold standard; app-based codes or push notifications with number matching are the next best option for smaller businesses, and text-message codes should be a last resort (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p></li><li><p><strong>Use long passphrases, not complicated rules.</strong> Password advice has changed. NIST&#8217;s current guidelines require at least 15 characters for a password used on its own, drop forced complexity rules and scheduled password changes, and call for checking new passwords against lists of known compromised ones. A password should be changed when there&#8217;s evidence it was compromised (<a href="https://pages.nist.gov/800-63-4/sp800-63b.html">NIST</a>). A password manager makes a unique passphrase for every account practical.</p></li><li><p><strong>Move from basic antivirus to managed detection and response.</strong> Built-in tools like Microsoft Defender are a starting point, but a centrally managed endpoint detection and response (EDR or XDR) platform watches for suspicious behavior, can isolate an infected computer, and gives your IT team one view of every device. That matters when ransomware is involved in 48% of breaches (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>Filter email and train people to spot what gets through.</strong> Business email compromise cost U.S. victims more than $3 billion in 2025, out of $20.9 billion in total reported cybercrime losses (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>). Good filtering removes most spam and malicious attachments before anyone sees them. Attackers are also shifting to phone calls and text messages, where simulated attacks succeed more often than email does (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>), so training should cover those channels too.</p></li><li><p><strong>Keep backups offline and test them.</strong> CISA recommends offline, encrypted backups of critical data and regular testing to confirm they can actually be restored, because many ransomware strains hunt for connected backups and destroy them (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>). A backup you&#8217;ve never restored from is a hope, not a plan.</p></li><li><p><strong>Assess, scan and patch on a schedule.</strong> Regular IT assessments and network vulnerability scans, by your own team or a third party, find weaknesses before attackers do. Speed matters: only 26% of the most critical known-exploited vulnerabilities were fully fixed in 2025, and the median time to fix them grew to 43 days (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li></ul><h2>Layers, not a single product</h2><p>No single control stops everything, which is why these tips work best together. MFA protects you when a password leaks. Detection and response catches the phishing email that slipped past the filter. Backups bring you back when everything else fails. Review each layer at least once a year, and whenever your business changes: new employees, new cloud apps, new locations or new vendors.</p><h2>Strengthen your security with Starfish Computer</h2><p>Whether you&#8217;re revisiting your defenses or putting them in place for the first time, Starfish Computer can help you implement all six of these practices and keep them working. Contact our team to review where you stand today and build a plan to close the gaps.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li><li><p><a href="https://pages.nist.gov/800-63-4/sp800-63b.html">NIST, SP 800-63B-4, &#8220;Digital Identity Guidelines: Authentication and Authenticator Management&#8221;</a></p></li><li><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI Internet Crime Complaint Center, 2025 IC3 Annual Report</a></p></li><li><p><a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA and MS-ISAC, &#8220;#StopRansomware Guide&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[How to Be Proactive with Your IT Infrastructure: A Strategic Approach]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/proactive-it</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/proactive-it</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:12:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/5NL_Djvkd3Y" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-5NL_Djvkd3Y" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5NL_Djvkd3Y&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5NL_Djvkd3Y?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=5NL_Djvkd3Y">Watch the video on YouTube</a></p><p>Being proactive with your IT infrastructure is a necessity, not a slogan. Exploiting unpatched vulnerabilities is now the most common way attackers get in, at 31% of breaches, and organizations fully fixed only 26% of the most critical known-exploited flaws in 2025, taking a median of 43 days (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). A proactive strategy protects continuity, strengthens security and replaces surprise expenses with planned ones.</p><h2>Regular assessments and lifecycle planning</h2><p>At Starfish Computer, proactive IT starts with regular assessments of your network: monthly, quarterly or yearly, depending on the complexity of your operations. Assessments identify outdated equipment and predict when replacements will be needed:</p><ul><li><p><strong>Flag devices by alerts and age.</strong> Aging hardware and unsupported software are where failures and breaches start. Windows 10 reached end of support on October 14, 2025, and PCs still running it no longer receive security updates unless enrolled in Extended Security Updates (<a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft</a>).</p></li><li><p><strong>Plan rolling replacements.</strong> Replacing a share of computers each year, for example on a three-year cycle, avoids replacing everything at once.</p></li><li><p><strong>Budget ahead.</strong> Building future replacements and upgrades into the budget lets you modernize systematically, without sudden financial burdens.</p></li></ul><h2>Patch what attackers are actually exploiting</h2><p>Not every vulnerability carries the same risk. CISA maintains the Known Exploited Vulnerabilities catalog, a list of flaws attackers are using in the wild, and recommends using it as an input to how you prioritize patching (<a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA</a>). A proactive patching program closes those flaws first, on a schedule, rather than waiting for an incident to force the issue.</p><h2>Modernize your security posture</h2><p>Ten years ago, a Security Information and Event Management (SIEM) system or Extended Detection and Response (XDR) platform was realistic only for large organizations. Today these tools are within reach for small and mid-sized businesses, and they matter because detection speed drives cost. The average breach now takes 247 days to identify and contain, and breaches that run longer than 200 days cost an average of $5.65 million, compared with $4.32 million for those contained sooner (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson</a>).</p><p>Every business has to weigh costs against risks, and proactive planning makes those trade-offs deliberate:</p><ul><li><p><strong>Tools or policies.</strong> Decide whether to invest in comprehensive security tools or to manage cost with more restrictive policies on devices and access.</p></li><li><p><strong>Buy for the full lifecycle.</strong> When purchasing servers, choose specifications and warranty terms, such as seven years instead of five, that match how long you plan to run them.</p></li><li><p><strong>Tie IT to business risk.</strong> NIST&#8217;s Cybersecurity Framework 2.0 added a Govern function so cybersecurity becomes part of overall enterprise risk management, not a separate technical project (<a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">NIST CSF 2.0</a>).</p></li></ul><p>Being proactive with IT is really being proactive with your business: thinking ahead about budgets, timelines and growth so technology supports where you are going.</p><h2>Partner with Starfish Computer for proactive IT</h2><p>Starfish Computer helps businesses build a proactive IT plan, from network assessments and lifecycle budgets to patching programs and modern detection tools. Contact us to schedule an assessment and turn your IT from a source of surprises into a planned, strategic advantage.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft, &#8220;Windows 10 support has ended on October 14, 2025&#8221;</a></p></li><li><p><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA, &#8220;Known Exploited Vulnerabilities Catalog&#8221;</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">NIST, &#8220;The NIST Cybersecurity Framework (CSF) 2.0&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[The Flaw in Your Disaster Recovery Strategy: Unveiled]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/disaster-recovery</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/disaster-recovery</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:11:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/Zc1aZfj9ebg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-Zc1aZfj9ebg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Zc1aZfj9ebg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Zc1aZfj9ebg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=Zc1aZfj9ebg">Watch the video on YouTube</a></p><p>Many businesses believe that because they back up their data, they have a disaster recovery plan. They don&#8217;t. A backup protects your data; a recovery plan gets your business running again, and the gap between the two is measured in days of lost work and revenue. In Uptime Institute&#8217;s 2026 outage analysis, 57% of respondents said their most recent major outage cost more than $100,000, and one in five said it cost more than $1 million (<a href="https://www.itweb.co.za/article/uptime-announces-annual-outage-analysis-report-2026/o1Jr5MxPNOwMKdWL">Uptime Institute</a>).</p><h2>Why a backup alone isn&#8217;t a recovery plan</h2><p>The traditional approach, copying files to an external hard drive or a cloud folder, answers only one question: is the data somewhere safe? It doesn&#8217;t answer how quickly you can use it. When a server fails, you can&#8217;t walk into the nearest store and buy a replacement off the shelf. The new hardware has to be compatible, ordered, delivered and configured with the operating system, applications and settings your business runs on, all before the data can be restored. That can take days or weeks, especially when an entire environment is affected rather than a single computer.</p><p>Ransomware makes the gap worse. Ransomware was involved in 48% of breaches in Verizon&#8217;s 2026 report (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>), and many variants specifically look for connected backups to delete or encrypt them (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>). If your only backup is plugged into the network, it may be the first thing you lose.</p><h2>What a real recovery plan includes</h2><ul><li><p><strong>Backups that can run your systems, not just store them.</strong> Starfish Computer uses backup hardware that can virtualize your critical servers and run them directly from the backup while failed equipment is repaired or replaced, so your staff can get back to work without waiting on a shipment.</p></li><li><p><strong>Offline, encrypted copies.</strong> Keep offline, encrypted backups of critical data so ransomware can&#8217;t reach them (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p></li><li><p><strong>Rebuild-ready system images.</strong> Maintain &#8220;golden images,&#8221; preconfigured templates of the operating system and applications that can be deployed quickly to rebuild a server or virtual machine (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p></li><li><p><strong>Regular restore tests.</strong> Test the availability and integrity of your backups in a realistic disaster scenario (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>), and time how long a full recovery takes. That number is your real recovery time.</p></li></ul><h2>Build an incident response team</h2><p>Technology is only half of recovery. A disaster, especially a cyberattack, affects every department. Starfish Computer helps organizations form an incident response team that brings together key people from across the business: operations decides how work continues, marketing handles communication with customers and the public, and legal manages regulatory and notification requirements. CISA advises organizations to create, maintain and regularly exercise an incident response plan, with a communications plan and notification procedures (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p><p>The clock matters. Federally insured credit unions must report a reportable cyber incident to the NCUA no later than 72 hours after they reasonably believe it occurred (<a href="https://ncua.gov/regulation-supervision/regulatory-compliance-resources/cybersecurity-resources/cyber-incident-reporting">NCUA</a>). And IBM&#8217;s 2026 research found that breaches taking more than 200 days to identify and contain cost an average of $5.65 million, compared with $4.32 million for those contained sooner (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>). Starfish Computer can lead these planning conversations or support your team when the impact reaches beyond IT.</p><h2>Find the flaw before a disaster does</h2><p>Recovering quickly from an unexpected event takes the right tools and the right conversations. Contact Starfish Computer to review your current disaster recovery strategy, test a real restore, and build the incident response team and virtualization capability that will keep your business running when something goes wrong.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.itweb.co.za/article/uptime-announces-annual-outage-analysis-report-2026/o1Jr5MxPNOwMKdWL">Uptime Institute via ITWeb, &#8220;Uptime Announces Annual Outage Analysis Report 2026&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA and MS-ISAC, &#8220;#StopRansomware Guide&#8221;</a></p></li><li><p><a href="https://ncua.gov/regulation-supervision/regulatory-compliance-resources/cybersecurity-resources/cyber-incident-reporting">NCUA, &#8220;Cyber Incident Notification Requirements&#8221;</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Discover the Key Advantages of Cloud Computing]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/cloud-computing-advantages</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/cloud-computing-advantages</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:10:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/htVqYR6r5zg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-htVqYR6r5zg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;htVqYR6r5zg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/htVqYR6r5zg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=htVqYR6r5zg">Watch the video on YouTube</a></p><p>Moving from traditional, on-premises IT to cloud computing has become a strategic decision for businesses of every size. In Flexera's 2026 State of the Cloud survey of more than 750 cloud decision-makers and users, 73% of organizations reported operating hybrid environments that combine cloud and on-premises systems (<a href="https://www.flexera.com/about-us/press-center/flexera-finds-cloud-value-is-rising-while-ai-waste-grows">Flexera</a>). The advantages are real, and getting them depends on understanding what the cloud does and does not take off your plate.</p><h2>The core benefits of cloud computing</h2><ul><li><p><strong>Cost efficiency.</strong> The cloud removes the need to buy and maintain servers, along with the space, cooling, electricity and periodic upgrades they require. NIST defines cloud computing by characteristics including rapid elasticity and measured service (<a href="https://csrc.nist.gov/pubs/sp/800/145/final">NIST</a>), which means you pay for what you use. Savings do take oversight: 85% of organizations call managing cloud spend a top challenge, and Flexera found wasted cloud spend rising to 29% (<a href="https://www.flexera.com/about-us/press-center/flexera-finds-cloud-value-is-rising-while-ai-waste-grows">Flexera</a>).</p></li><li><p><strong>Stronger security, shared responsibility.</strong> Major providers secure the physical datacenters, networks and host servers, and for software-as-a-service they also manage the operating systems. You always keep responsibility for your data, devices, user accounts and access controls (<a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility">Microsoft</a>). CISA publishes free secure configuration baselines for Microsoft 365 and Google Workspace to help organizations set those controls correctly (<a href="https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project">CISA</a>).</p></li><li><p><strong>Better disaster recovery.</strong> Data stored in a provider's datacenters is protected from local events such as fire, flooding or storm damage that can take down a business relying only on an on-site server. Because your data remains your responsibility (<a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility">Microsoft</a>), a separate backup of cloud data is still wise.</p></li><li><p><strong>Flexibility and accessibility.</strong> When a tornado warning or a snowstorm keeps people home, staff can keep working from anywhere with an internet connection. Remote work is now routine: in June 2026, 52.5% of workers in financial activities teleworked (<a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">BLS</a>).</p></li><li><p><strong>Scalability.</strong> Add users, storage or computing power when demand grows, and scale back when it falls, without buying hardware.</p></li></ul><h2>Transition challenges and solutions</h2><p>Moving mail servers and file systems to the cloud is not as simple as buying a license and clicking a button. It takes careful planning to move data accurately and on schedule, set permissions correctly, and keep the business running during the cutover. Users also need training on the new way of working, from opening shared files to managing who can access them. Starfish Computer understands these details and guides you through them.</p><h2>Cloud solutions built for your business</h2><p>Every business has different needs. Starfish Computer starts by assessing your current systems to determine which are ready for the cloud and which are better suited to a hybrid approach. For systems that are not cloud-ready yet, we build a roadmap so each step makes sense for your operations and budget.</p><h2>Partner with Starfish Computer for your cloud transition</h2><p>Starfish Computer guides businesses through the move to cloud computing so they can take full advantage of it. A personal consultation lets us understand your needs and design a plan that fits your goals. Contact Starfish Computer to schedule an appointment and start planning your move to the cloud.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.flexera.com/about-us/press-center/flexera-finds-cloud-value-is-rising-while-ai-waste-grows">Flexera, &#8220;Flexera Finds Cloud Value is Rising While AI Waste Grows&#8221;</a></p></li><li><p><a href="https://csrc.nist.gov/pubs/sp/800/145/final">NIST, &#8220;SP 800-145: The NIST Definition of Cloud Computing&#8221;</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility">Microsoft Learn, &#8220;Shared responsibility in the cloud&#8221;</a></p></li><li><p><a href="https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project">CISA, &#8220;Secure Cloud Business Applications (SCuBA) Project&#8221;</a></p></li><li><p><a href="https://www.bls.gov/opub/ted/2026/52-5-percent-of-workers-in-financial-activities-teleworked-in-june-2026.htm">U.S. Bureau of Labor Statistics, &#8220;52.5 percent of workers in financial activities teleworked in June 2026&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Understanding the Essentials of IT Strategy]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/it-strategy</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/it-strategy</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:09:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/vKOXxUnupAg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-vKOXxUnupAg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;vKOXxUnupAg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/vKOXxUnupAg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=vKOXxUnupAg">Watch the video on YouTube</a></p><p>An IT strategy is a plan that ties your technology to your business goals: what you run, what it costs, how it&#8217;s protected and where it needs to go next. It matters more as costs rise. Gartner notes technology budgets are being strained by inflation, supply shortages and rising hardware and memory costs (<a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion">Gartner</a>). A clear strategy turns those pressures into planned decisions instead of surprises.</p><h2>Strategy starts with leadership</h2><p>The NIST Cybersecurity Framework 2.0 added a new Govern function that treats cybersecurity as a major enterprise risk, alongside financial and reputational risk, and the framework is written for organizations of every size (<a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST</a>). The same idea applies to IT as a whole: technology decisions should flow from business priorities set by leadership. At Starfish Computer, we cut through the buzzwords to help you build a strategy that fits your operations today and anticipates where you&#8217;re heading.</p><h2>The core components of an effective IT strategy</h2><ul><li><p><strong>Client-centered discovery.</strong> We start with conversations about your core goals, the software you depend on, how you operate today and where you want to be. That understanding is the foundation for a strategy that reflects your business, not a generic template.</p></li><li><p><strong>Scalable solutions.</strong> We design systems that can grow and change with your business, so adding people, locations or services doesn&#8217;t mean starting over.</p></li><li><p><strong>Layered security.</strong> Security combines endpoint protection, firewalls and advanced email filtering, including AI-assisted spam detection, with fast patching. Speed matters: only 26% of the most critical known-exploited vulnerabilities were fully fixed in 2025, and the median time to fix them rose to 43 days (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). Equipment lifecycles belong in the plan too; Windows 10 stopped receiving security updates when support ended on October 14, 2025 (<a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft</a>).</p></li><li><p><strong>An actionable plan.</strong> You get a written plan tailored to your network that separates what we can do now, what needs a joint decision, and what needs buy-in from your team. It includes regular user training, from quarterly to monthly sessions, because the human element was present in 62% of breaches in Verizon&#8217;s 2026 report (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>Continuous partnership.</strong> Implementation isn&#8217;t the end. We stay involved so you always know why each step is being taken and how it strengthens your business.</p></li></ul><h2>Review it, don&#8217;t file it</h2><p>An IT strategy isn&#8217;t a document to file away. Review it at least once a year and whenever the business changes. Ongoing monitoring is part of the plan for a reason: IBM&#8217;s 2026 research found that breaches taking more than 200 days to identify and contain cost an average of $5.65 million, compared with $4.32 million for those contained sooner (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>).</p><h2>Build your IT strategy with Starfish Computer</h2><p>Your technology is the backbone of your business operations, and it shouldn&#8217;t be left to chance. Contact Starfish Computer to schedule a consultation, and we&#8217;ll help you define and carry out an IT strategy that delivers efficiency, room to grow and strong protection.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion">Gartner, &#8220;Gartner Forecasts Worldwide IT Spending to Grow 14.2% in 2026, Totaling $6.37 Trillion&#8221;</a></p></li><li><p><a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST, &#8220;NIST Releases Version 2.0 of Landmark Cybersecurity Framework&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft, &#8220;Windows 10 support has ended on October 14, 2025&#8221;</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Enhance Your Cybersecurity with AI: The Future Begins Now]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/ai-cybersecurity</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/ai-cybersecurity</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:08:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/pwDsGG4YsLw" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-pwDsGG4YsLw" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pwDsGG4YsLw&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pwDsGG4YsLw?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=pwDsGG4YsLw">Watch the video on YouTube</a></p><p>Artificial intelligence is no longer a future concern for cybersecurity; attackers are using it today. Verizon&#8217;s 2026 report found threat actors using generative AI at every stage of an attack, from choosing targets and gaining access to building malware (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). In 2025 the FBI received 22,364 complaints involving AI, with adjusted losses of more than $893 million (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>). Businesses need defenses that can keep up.</p><h2>How attackers are using AI</h2><p>AI makes old scams faster, cheaper and more convincing:</p><ul><li><p><strong>Phishing and business email compromise.</strong> Chat tools can write official-sounding emails that mimic a CEO or other leader and ask for a wire transfer. Businesses reported more than $30 million in losses to AI-involved business email compromise in 2025 (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>).</p></li><li><p><strong>Voice cloning and deepfakes.</strong> Criminals use cloned voices to request wire payments, and voice spoofing, possibly using deepfakes, has appeared in online job interviews (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>). In phishing simulations, click rates on voice and text message lures run 40% higher than email (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>Faster attack development.</strong> The median threat actor used AI assistance across 15 documented attack techniques, and some used it for 40 or more (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li></ul><p>People remain the main target: the human element was present in 62% of breaches (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p><h2>Where AI helps defenders</h2><p>As Adam from Starfish Computer explains in the video, partnerships with security leaders like Barracuda let us put AI to work on the defensive side:</p><ul><li><p><strong>Smarter email filtering.</strong> Traditional spam filters look for known markers, so a plain, friendly message from what appears to be a real contact can slip through. AI-based filtering evaluates the content and the normal conversation patterns between people, and it can stop social engineering emails before they reach the inbox.</p></li><li><p><strong>Network monitoring.</strong> AI learns what normal traffic looks like and flags or blocks unusual data transfers. Speed matters: the average breach now takes 247 days to identify and contain, and breaches lasting more than 200 days cost an average of $5.65 million (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson</a>).</p></li><li><p><strong>Behavior-based endpoint protection.</strong> Signature-based antivirus only recognizes threats it has seen before. AI-driven tools watch for suspicious behavior, which helps catch new and modified malware.</p></li></ul><h2>Govern your own use of AI</h2><p>Your employees are adopting AI too, approved or not. Verizon found 45% of employees now use AI regularly on corporate devices, up from 15% a year earlier, and 67% of users reach AI services through non-corporate accounts (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). IBM&#8217;s 2026 research found incidents involving employee shadow AI more than doubled, to 43% (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson</a>).</p><ul><li><p><strong>Set an AI use policy.</strong> Decide which tools are approved and what data may never be pasted into them, such as client records or source code.</p></li><li><p><strong>Use a recognized framework.</strong> The NIST AI Risk Management Framework, with its Govern, Map, Measure and Manage functions and a Generative AI Profile, gives businesses a voluntary structure for managing AI risk (<a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST</a>).</p></li><li><p><strong>Back up AI with strong authentication.</strong> No filter catches everything. CISA calls phishing-resistant MFA the gold standard and urges organizations to make it a high priority (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p></li></ul><h2>Put AI to work with Starfish Computer</h2><p>AI gives defenders a real advantage when it is chosen carefully, configured well and paired with sound policies. Starfish Computer combines AI-driven email protection, monitoring and endpoint security from proven partners with practical guidance on how your team uses AI. Contact us to review your current defenses and see where AI can close the gaps.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI Internet Crime Complaint Center, 2025 IC3 Annual Report</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST, &#8220;AI Risk Management Framework&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[The Future of IT Services: Navigating the Next Wave]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/future-of-it-services</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/future-of-it-services</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Thu, 30 Jan 2025 14:07:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/RERi7CfCrkM" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published January 30, 2025.</em></p><div id="youtube2-RERi7CfCrkM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;RERi7CfCrkM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/RERi7CfCrkM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=RERi7CfCrkM">Watch the video on YouTube</a></p><p>IT is changing faster than most budgets. Gartner expects worldwide IT spending to reach $6.37 trillion in 2026, up 14.2% from 2025, with the fastest growth in AI infrastructure, cloud services and software (<a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion">Gartner</a>). For small and mid-sized businesses, the question isn&#8217;t whether these changes arrive but how to adopt them without adding risk. In our video, Adam from Starfish Computer highlights three forces shaping IT services: compliance, artificial intelligence and the cloud.</p><h2>Cybersecurity and compliance keep tightening</h2><p>As threats grow more complex, regulators expect more, and their requirements are often buried in long, dense documents. Federally insured credit unions, for example, must report a reportable cyber incident to the NCUA within 72 hours (<a href="https://ncua.gov/regulation-supervision/regulatory-compliance-resources/cybersecurity-resources/cyber-incident-reporting">NCUA</a>). Banks and credit unions also lost a familiar yardstick when the FFIEC retired its Cybersecurity Assessment Tool on August 31, 2025, with NIST CSF 2.0 and CISA&#8217;s Cybersecurity Performance Goals among the recommended alternatives (<a href="https://www.communitybankingconnections.org/articles/2025/third-release-2025/cybersecurity-risks-and-resources">Federal Reserve</a>).</p><p>Starfish Computer specializes in translating these requirements into plain terms: what applies to you, where your gaps are, and a practical plan to close them.</p><h2>AI cuts both ways</h2><p>AI already helps defenders. Modern email filters use it to flag messages that don&#8217;t match a sender&#8217;s normal patterns. Attackers use it too: Verizon found threat actors using generative AI for targeting, initial access and malware development (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>), and the FBI received reports of more than $30 million in 2025 losses from business email compromise scams involving AI (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>).</p><p>Inside your own walls, unmanaged AI creates new risk. Some 45% of employees now regularly use AI on their corporate devices (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). IBM&#8217;s 2026 research found that incidents involving employees&#8217; unapproved &#8220;shadow AI&#8221; more than doubled, to 43%, and 68% of organizations that had an AI-related incident lacked AI governance policies (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>). AI tools can also produce convincing but wrong output. Starfish Computer helps businesses capture the benefits of AI with approved tools, clear policies and human review.</p><h2>The cloud makes flexible work practical</h2><p>Cloud services have become affordable enough that small businesses can use the same platforms as large enterprises, and spending on cloud infrastructure services is forecast to grow 29.3% in 2026 (<a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion">Gartner</a>). Cloud applications let employees work securely from anywhere, so bad weather or flu season doesn&#8217;t have to stop the business, and a sick employee can stay home without spreading illness around the office or falling behind. That flexibility depends on security: multifactor authentication, managed devices and monitored access.</p><h2>Planning ties it together</h2><p>Starfish Computer looks beyond the technology itself to how it fits your business strategy, operational planning and budget. That planning matters now. Gartner notes technology budgets are being strained by inflation, supply shortages and rising hardware and memory costs (<a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion">Gartner</a>), and any PCs still running Windows 10 stopped receiving security updates when support ended on October 14, 2025 (<a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft</a>). Building upgrades and new services into a multi-year plan avoids surprises.</p><h2>Plan your next step with Starfish Computer</h2><p>Whether you need help closing a compliance gap, setting rules for AI, moving to the cloud or building a technology budget, Starfish Computer can help. Contact our team to talk through where your business is heading and how your IT should get it there.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-07-27-gartner-forecasts-worldwide-it-spending-to-grow-14-point-2-percent-in-2026-totaling-6-point-37-trillion">Gartner, &#8220;Gartner Forecasts Worldwide IT Spending to Grow 14.2% in 2026, Totaling $6.37 Trillion&#8221;</a></p></li><li><p><a href="https://ncua.gov/regulation-supervision/regulatory-compliance-resources/cybersecurity-resources/cyber-incident-reporting">NCUA, &#8220;Cyber Incident Notification Requirements&#8221;</a></p></li><li><p><a href="https://www.communitybankingconnections.org/articles/2025/third-release-2025/cybersecurity-risks-and-resources">Federal Reserve, Community Banking Connections, &#8220;Cybersecurity Risks and Resources&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI Internet Crime Complaint Center, 2025 IC3 Annual Report</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft, &#8220;Windows 10 support has ended on October 14, 2025&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Secure Your Data with Starfish Computer’s Backup Solutions]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/data-backup</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/data-backup</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Wed, 03 Apr 2024 14:06:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/VIqIK8_n3PA" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published April 3, 2024.</em></p><div id="youtube2-VIqIK8_n3PA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;VIqIK8_n3PA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/VIqIK8_n3PA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=VIqIK8_n3PA">Watch the video on YouTube</a></p><p>A reliable backup and recovery plan is what lets a business come back from ransomware, hardware failure or disaster. Ransomware was involved in 48% of all breaches in Verizon&#8217;s 2026 report, and small organizations are disproportionately affected (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). CISA&#8217;s first recommendation for ransomware readiness is to maintain offline, encrypted backups of critical data and regularly test them (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p><h2>Why rethink your backup strategy</h2><ul><li><p><strong>Outdated methods fall short.</strong> Tape drives and USB drives are slow to restore, easy to forget and often fail when you need them. A drive left connected to the network can also be encrypted along with everything else.</p></li><li><p><strong>Follow the 3-2-1 rule.</strong> Keep three copies of important data, on two different types of media, with one copy stored offsite (<a href="https://www.cisa.gov/sites/default/files/publications/data_backup_options.pdf">CISA</a>). A hybrid approach, with fast on-premises backups plus a cloud copy, meets this standard and covers both local outages and site-wide disasters.</p></li><li><p><strong>Make at least one copy immutable or offline.</strong> Many ransomware variants hunt for accessible backups, so CISA recommends keeping backups offline, and notes that some cloud providers offer immutable storage that protects data from being changed or deleted (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p></li><li><p><strong>Encrypt everything.</strong> Modern backups should be encrypted in transit and at rest, so a stolen backup does not become a data breach of its own.</p></li></ul><h2>A backup is only as good as the restore</h2><p>Having backups is not the same as being able to recover. Sophos found that recovery through backups fell to its lowest rate in six years, and 49% of victims paid the ransom to get their data back (<a href="https://www.sophos.com/en-us/blog/the-state-of-ransomware-2025">Sophos</a>). Verizon&#8217;s data shows the alternative is possible: 69% of ransomware victims did not pay, and the median payment still reached $139,875 (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p><ul><li><p><strong>Test restores on a schedule.</strong> CISA advises regularly testing the availability and integrity of backups in a disaster recovery scenario (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p></li><li><p><strong>Keep golden images.</strong> Maintain up-to-date templates of critical systems, with the operating system and key applications preconfigured, so servers can be rebuilt quickly (<a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA</a>).</p></li><li><p><strong>Know your recovery targets.</strong> Decide how much data you can afford to lose and how long you can be down, then design backups to meet those numbers.</p></li></ul><h2>Weighing cost against value</h2><p>A professional backup and recovery solution costs more up front than an external drive. The value is in business continuity: minimal downtime, intact data and the option to refuse a ransom demand. Starfish Computer combines on-premises hardware with cloud infrastructure so you can recover quickly from a single failed server or a complete site loss.</p><h2>Protect your data with Starfish Computer</h2><p>Do not wait for a disaster to find out whether your backups work. Contact Starfish Computer to review your current backup strategy, test a real restore and build a hybrid, encrypted and immutable plan that keeps your business recoverable.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.cisa.gov/stopransomware/ransomware-guide">CISA, &#8220;#StopRansomware Guide&#8221;</a></p></li><li><p><a href="https://www.cisa.gov/sites/default/files/publications/data_backup_options.pdf">CISA (US-CERT), &#8220;Data Backup Options&#8221;</a></p></li><li><p><a href="https://www.sophos.com/en-us/blog/the-state-of-ransomware-2025">Sophos, &#8220;The State of Ransomware 2025&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Cybersecurity Defense Strategies for Businesses]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/cybersecurity-defense</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/cybersecurity-defense</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Wed, 03 Apr 2024 14:05:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/b3ZFD2-r6gc" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published April 3, 2024.</em></p><div id="youtube2-b3ZFD2-r6gc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;b3ZFD2-r6gc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/b3ZFD2-r6gc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=b3ZFD2-r6gc">Watch the video on YouTube</a></p><p>Cyber threats against businesses keep getting more convincing. At the engineering firm Arup, a finance employee joined a video call with people he believed were the company's CFO and other colleagues. All of them were deepfakes, and he went on to transfer $25.6 million to the fraudsters over 15 transactions (<a href="https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo">Fortune</a>). Attacks like this show why every business needs a defense plan built for how criminals operate today.</p><h2>The threat picture in 2026</h2><p>The latest data shows attackers gaining ground on several fronts:</p><ul><li><p><strong>Losses keep rising.</strong> Americans reported $20.877 billion in internet crime losses to the FBI in 2025, a 26% increase over 2024. Business email compromise alone accounted for more than $3 billion of that total (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>).</p></li><li><p><strong>AI is now part of the playbook.</strong> For the first time, the FBI reported AI-related fraud on its own: 22,364 complaints and more than $893 million in losses in 2025 (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>).</p></li><li><p><strong>Unpatched systems are the top way in.</strong> Exploitation of vulnerabilities is now the most common initial access vector, at 31% of breaches, and ransomware appeared in 48% of all breaches (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>People are still the target.</strong> The human element was present in 62% of breaches, and in phishing simulations, voice and text lures succeeded at a median rate 40% higher than email (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li></ul><h2>Four strategies to combat cybersecurity threats</h2><p>At Starfish Computer Corporation, our approach focuses on educating and equipping businesses with the right tools and knowledge to protect their operations. We build defenses around four strategies:</p><ul><li><p><strong>Awareness and vigilance.</strong> Train your team to recognize phishing, deepfake voice and video, and urgent requests for money or credentials. Set a firm rule that any request to send funds or change banking details is verified through a second, known channel, such as a call to a number already on file, no matter who appears to be asking.</p></li><li><p><strong>Strong security tools, well managed.</strong> Patch internet-facing systems first, run endpoint detection and response on every device, and require multifactor authentication for email, remote access and financial accounts. CISA calls phishing-resistant MFA, such as FIDO security keys, the &#8220;gold standard&#8221; and urges organizations to make it a high priority (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p></li><li><p><strong>Comprehensive disaster recovery plans.</strong> Keep backups that attackers cannot reach or alter, test your restores, and write down who does what during an incident. In Verizon's 2026 data, 69% of ransomware victims did not pay a ransom (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>); reliable, tested backups are what make that choice possible.</p></li><li><p><strong>Regular assessments and updates.</strong> Threats change every year, and your defenses should too. The NIST Cybersecurity Framework 2.0 gives businesses a common structure built on six functions: govern, identify, protect, detect, respond and recover. NIST also publishes quick-start guides written for small businesses (<a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST</a>).</p></li></ul><h2>Strengthen your defenses with Starfish Computer</h2><p>Starfish Computer Corporation offers a full range of services to strengthen your cybersecurity posture, from an initial assessment of your current security measures to implementing layered defenses and building a disaster recovery plan you have actually tested. Contact Starfish Computer to review your defenses against today's threats, including deepfakes and payment fraud, and to build a plan that keeps your business protected.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo">Fortune, &#8220;A deepfake &#8216;CFO&#8217; tricked British design firm Arup in $25 million fraud&#8221;</a></p></li><li><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI Internet Crime Complaint Center, &#8220;2025 Internet Crime Report&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, &#8220;2026 Data Breach Investigations Report, Executive Summary&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li><li><p><a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST, &#8220;NIST Releases Version 2.0 of Landmark Cybersecurity Framework&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Custom Cloud Solutions for Business Efficiency]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/custom-cloud-solutions</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/custom-cloud-solutions</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Wed, 03 Apr 2024 14:04:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/CLdtP3FE1qM" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published April 3, 2024.</em></p><div id="youtube2-CLdtP3FE1qM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;CLdtP3FE1qM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/CLdtP3FE1qM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=CLdtP3FE1qM">Watch the video on YouTube</a></p><p>Cloud services let your team work from anywhere, scale up as you grow and reach the same data from the office or the road. But the cloud also changes where your risk lives. Breaches involving a third party, such as a software or service provider, reached 48% of all breaches in Verizon&#8217;s 2026 report, up 60% from the year before (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). Starfish Computer Corporation builds custom cloud solutions that match your business goals and are configured securely from the start.</p><h2>Key considerations for your cloud strategy</h2><ul><li><p><strong>Define your goals.</strong> Start with what you want the cloud to do for you. Whether it&#8217;s speed, connectivity, collaboration or remote access, your goals should guide every platform and software decision.</p></li><li><p><strong>Flexibility and agility.</strong> Your team should be able to work effectively in the office or remotely without giving up speed or access. A good cloud design supports both from day one.</p></li><li><p><strong>Customized solutions.</strong> Avoid one-size-fits-all approaches. Your business is unique, and your cloud environment should be built around your specific applications, users and requirements.</p></li><li><p><strong>Security built in.</strong> Cloud platforms are only as secure as their settings. CISA and NSA guidance for cloud customers covers identity and access management, key management, network segmentation and encryption, securing data and managing the risks of service providers (<a href="https://cisa.gov/news-events/alerts/2024/03/07/cisa-and-nsa-release-cybersecurity-information-sheets-cloud-security-best-practices">CISA</a>).</p></li></ul><h2>Configuration is where cloud security succeeds or fails</h2><p>Many cloud problems come from settings nobody revisited. When Verizon tracked cloud exposures at third-party organizations, only 23% fully fixed missing or poorly configured multifactor authentication on their cloud accounts, and resolving half of the weak password and permission findings took almost eight months (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). IBM&#8217;s 2026 research found that 53% of breached organizations lacked encryption (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>).</p><p>Free government tools help close those gaps. CISA&#8217;s Secure Cloud Business Applications (SCuBA) project publishes secure configuration baselines for Microsoft 365 and Google Workspace, and its ScubaGear tool checks a Microsoft 365 tenant against them (<a href="https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project">CISA</a>). Strong sign-in protection matters just as much: CISA calls phishing-resistant MFA the gold standard and urges organizations to make moving to it a high priority (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p><h2>A consultative approach</h2><p>At Starfish Computer Corporation, we start by understanding your objectives. With that in hand, we recommend and implement the cloud platforms and software that fit your infrastructure, migrate your data carefully, and set up the security controls, backups and monitoring to protect it. The goal is a solution that improves how your business runs while staying scalable and secure.</p><h2>Build your cloud strategy with Starfish Computer</h2><p>Whether you are moving to the cloud for the first time or untangling a setup that grew without a plan, we can help. Contact Starfish Computer Corporation to schedule a consultation and build a cloud strategy that moves your business forward.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://cisa.gov/news-events/alerts/2024/03/07/cisa-and-nsa-release-cybersecurity-information-sheets-cloud-security-best-practices">CISA, &#8220;CISA and NSA Release Cybersecurity Information Sheets on Cloud Security Best Practices&#8221;</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project">CISA, &#8220;Secure Cloud Business Applications (SCuBA) Project&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Find Your Ideal IT Partner]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/ideal-it-partner</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/ideal-it-partner</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Wed, 03 Apr 2024 14:03:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/lo5QDfvUZtI" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published April 3, 2024.</em></p><div id="youtube2-lo5QDfvUZtI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;lo5QDfvUZtI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/lo5QDfvUZtI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=lo5QDfvUZtI">Watch the video on YouTube</a></p><p>For a growing business, choosing an IT partner shapes how efficiently you operate and how well you are protected. It is also a security decision: breaches involving a third party reached 48% of all breaches in Verizon&#8217;s 2026 report, up 60% from the year before, and 55% of breaches at small and mid-sized businesses (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). The right partner fits your goals and strengthens your defenses rather than adding risk.</p><h2>What to look for in an IT partner</h2><p>Starfish Computer recommends starting with four qualities:</p><ul><li><p><strong>Vendor agnosticism.</strong> Look for a partner that is impartial to brands and recommends the technology that suits your business, not the one with the best reseller margin.</p></li><li><p><strong>Solution flexibility.</strong> Whether you prefer on-premises, cloud or a hybrid approach, a good partner adapts to what works best for you.</p></li><li><p><strong>A client-centric approach.</strong> Your partner should put your interests first, with solutions that are efficient, cost-effective and sized to your needs.</p></li><li><p><strong>Open dialogue.</strong> You should be able to have honest conversations about your technology strategy and whether it fits your current and future goals.</p></li></ul><h2>Security questions to ask any provider</h2><p>CISA is clear that outsourcing IT to a managed service provider does not remove your own responsibility for managing risk (<a href="https://www.cisa.gov/sites/default/files/publications/cisa-insights_risk-considerations-for-msp-customers_508.pdf">CISA</a>). Before you sign, ask:</p><ul><li><p><strong>Who is responsible for what?</strong> Agree in writing on who applies patches, maintains hardware and trains employees, using a shared responsibility model (<a href="https://www.cisa.gov/sites/default/files/publications/cisa-insights_risk-considerations-for-msp-customers_508.pdf">CISA</a>). NIST&#8217;s Cybersecurity Framework 2.0 calls for cybersecurity roles and responsibilities with suppliers and partners to be established and communicated (<a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">NIST CSF 2.0</a>).</p></li><li><p><strong>What are our most critical assets?</strong> A good partner helps you build an inventory of systems and data and prioritize protection by importance to the business (<a href="https://www.cisa.gov/sites/default/files/publications/cisa-insights_risk-considerations-for-msp-customers_508.pdf">CISA</a>).</p></li><li><p><strong>How is access secured?</strong> Every administrative login should use multifactor authentication, and CISA calls phishing-resistant MFA the gold standard (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>). Third parties are slow to fix this: only 23% fully remediated missing or weak MFA on their cloud accounts (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>).</p></li><li><p><strong>Will this provider be around?</strong> CISA notes that a vendor&#8217;s financial health can signal future service disruptions (<a href="https://www.cisa.gov/sites/default/files/publications/cisa-insights_risk-considerations-for-msp-customers_508.pdf">CISA</a>). Ask how long the company has been in business and who will actually support you.</p></li></ul><h2>How Starfish Computer works with clients</h2><p>Since 1994, Starfish Computer has put client needs at the front of everything we do. We start with real conversations to understand your business and the &#8220;why&#8221; behind each request. That way, the technology we recommend is not just installed, it is aligned with your objectives and makes financial and operational sense for your situation.</p><h2>Find your IT partner with Starfish Computer</h2><p>If you are looking for an IT partner that understands your business goals and takes security seriously, contact Starfish Computer. We will walk through your current environment, answer the questions above and show you how we would tailor IT support to your business.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.cisa.gov/sites/default/files/publications/cisa-insights_risk-considerations-for-msp-customers_508.pdf">CISA, &#8220;Risk Considerations for Managed Service Provider Customers&#8221;</a></p></li><li><p><a href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf">NIST, &#8220;The NIST Cybersecurity Framework (CSF) 2.0&#8221;</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Advanced Cybersecurity Solutions for Your Business]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/advanced-cybersecurity</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/advanced-cybersecurity</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Wed, 03 Apr 2024 14:02:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/H44I47WRjyE" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published April 3, 2024.</em></p><div id="youtube2-H44I47WRjyE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;H44I47WRjyE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/H44I47WRjyE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=H44I47WRjyE">Watch the video on YouTube</a></p><p>Attackers keep getting faster, and the cost of falling behind keeps rising. Ransomware was present in 48% of breaches in Verizon&#8217;s 2026 report, up from 44% a year earlier (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>), and the average U.S. data breach now costs $11.5 million (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>). Antivirus and a firewall alone no longer cover the risk. Starfish Computer Corporation implements modern security technology and pairs it with people who watch over it, so your business stays secure and resilient.</p><h2>Why the old defenses aren&#8217;t enough</h2><p>Most breaches still involve a person: the human element was present in 62% of them, and attackers increasingly use voice calls and text messages to catch employees off guard during the workday (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>). Fraud that targets businesses is just as costly. The FBI received more than one million complaints in 2025 with reported losses of nearly $20.9 billion, including more than $3 billion lost to business email compromise (<a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI IC3</a>). And when attackers get in, they often stay hidden: the average breach takes 247 days to identify and contain (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>).</p><h2>Three technologies every business should have</h2><ul><li><p><strong>Multifactor authentication (MFA).</strong> Once a nice-to-have, MFA is now a necessity for verifying who is logging in. CISA urges organizations to use MFA for all users and all services, and to move toward phishing-resistant methods such as FIDO security keys, because some text-message and push-based methods can be phished or bypassed (<a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA</a>).</p></li><li><p><strong>Security information and event management (SIEM).</strong> A SIEM collects and correlates logs from across your network, both internal and external activity, so actions are documented and suspicious behavior stands out. CISA, the FBI, NSA and international partners warn that attackers increasingly &#8220;live off the land&#8221; using built-in tools, which makes good event logging essential for detection (<a href="https://cisa.gov/news-events/alerts/2024/08/21/asds-acsc-cisa-fbi-and-nsa-support-international-partners-release-best-practices-event-logging-and">CISA</a>).</p></li><li><p><strong>Extended detection and response (XDR).</strong> XDR watches endpoints, email, identities and the network together in real time. With live security professionals behind it, threats can be contained quickly, often before your staff knows anything happened. Faster detection matters: breaches contained in under 200 days cost about $1.3 million less on average than those that take longer (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>).</p></li></ul><h2>Real time, real people</h2><p>Technology alone doesn&#8217;t stop attackers. Alerts need someone to read them, judge them and act. Starfish Computer&#8217;s focus is not just on deploying these tools but on putting experienced people behind them. Our team works around the clock to respond to emerging threats in real time, which gives our clients both stronger protection and peace of mind.</p><p>That approach also keeps the basics in view. Exploited vulnerabilities are now the most common way attackers get in (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>), so patching, configuration reviews and user training remain part of every security plan we build.</p><h2>Strengthen your defenses with Starfish Computer</h2><p>If your business is relying on yesterday&#8217;s tools, now is the time to close the gap. Contact Starfish Computer Corporation to learn how MFA, SIEM and XDR, backed by real people working in real time, can protect your business and keep it running.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI Internet Crime Complaint Center, 2025 IC3 Annual Report</a></p></li><li><p><a href="https://cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">CISA, &#8220;Implementing Phishing-Resistant MFA&#8221;</a></p></li><li><p><a href="https://cisa.gov/news-events/alerts/2024/08/21/asds-acsc-cisa-fbi-and-nsa-support-international-partners-release-best-practices-event-logging-and">CISA, &#8220;ASD&#8217;s ACSC, CISA, FBI, and NSA, with the Support of International Partners Release Best Practices for Event Logging and Threat Detection&#8221;</a></p></li></ol>]]></content:encoded></item><item><title><![CDATA[Boost Your Business with a Virtual CTO]]></title><description><![CDATA[Updated October 2026.]]></description><link>https://newsletter.starfishcomputer.com/p/virtual-cto</link><guid isPermaLink="false">https://newsletter.starfishcomputer.com/p/virtual-cto</guid><dc:creator><![CDATA[Starfish Computer Corporation]]></dc:creator><pubDate>Wed, 03 Apr 2024 14:01:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/1u0lSKvsRMA" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Updated October 2026. Originally published April 3, 2024.</em></p><div id="youtube2-1u0lSKvsRMA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;1u0lSKvsRMA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/1u0lSKvsRMA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><a href="https://www.youtube.com/watch?v=1u0lSKvsRMA">Watch the video on YouTube</a></p><p>As a business grows, its technology gets more complex and the decisions get more expensive. Yet hiring a full-time technology executive is out of reach for many small and mid-sized companies: the median pay for computer and information systems managers was $175,140 in 2025 (<a href="https://www.bls.gov/ooh/management/computer-and-information-systems-managers.htm">BLS</a>). A virtual Chief Technology Officer (vCTO) from Starfish Computer Corporation gives you that level of leadership for technology strategy, cybersecurity and operations, on a schedule and budget that fit your business.</p><h2>Why technology leadership matters more in 2026</h2><p>Cybersecurity is now a leadership responsibility, not just a technical one. The NIST Cybersecurity Framework 2.0 added a new &#8220;Govern&#8221; function that treats cybersecurity as a business risk alongside finance and reputation (<a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST</a>). At the same time, artificial intelligence is spreading through offices faster than policies can keep up. Verizon found that 45% of employees now use AI regularly on their work devices, up from 15% a year earlier (<a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon DBIR</a>), and IBM&#8217;s 2026 research found that 68% of organizations still lack AI governance policies (<a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">IBM via Baker Donelson</a>). Someone needs to own these decisions.</p><p>Talent is also hard to find. Employment of information security analysts is projected to grow 21% from 2025 to 2035, much faster than average (<a href="https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm">BLS</a>), which means competition for experienced people will stay intense.</p><h2>What a vCTO brings to your business</h2><ul><li><p><strong>Expert guidance.</strong> A vCTO brings specialized knowledge to your organization and helps you sort through technology options and opportunities, so you invest in what actually supports your goals.</p></li><li><p><strong>Cybersecurity leadership.</strong> Your vCTO is a dedicated professional focused on protecting your data, systems and people, from security policies and user training to incident response planning.</p></li><li><p><strong>Strategic oversight.</strong> Beyond day-to-day IT, a vCTO contributes to long-term planning, building a technology roadmap and budget that line up with where the business is headed.</p></li><li><p><strong>Lifecycle and risk planning.</strong> A vCTO tracks what needs replacing before it becomes a problem. For example, Windows 10 stopped receiving free security updates on October 14, 2025 (<a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft</a>), and every business needed a plan for those PCs.</p></li></ul><h2>vCTO services built for growing businesses</h2><p>Starfish Computer Corporation offers vCTO services tailored to the needs of growing businesses. Our experience in technology and cybersecurity strategy helps keep your operations both efficient and secure. Whether you are supporting remote and hybrid work, considering a move to the cloud, adopting AI tools responsibly or strengthening your cybersecurity, our vCTO services provide the leadership and planning needed to get it right. A vCTO also translates technical issues into plain business terms, so owners and managers can make informed decisions with confidence.</p><h2>Talk to Starfish Computer about a virtual CTO</h2><p>Let us help you manage the complexity of modern technology and lead your business toward a more secure future. Contact Starfish Computer Corporation to explore how a virtual Chief Technology Officer can strengthen your operations.</p><h2>Protect your business: start with an assessment</h2><p>The question isn&#8217;t whether your business will face a cyber threat, but whether you&#8217;ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:</p><ul><li><p><strong>Assess</strong> current security posture and risk</p></li><li><p><strong>Plan</strong> a cybersecurity roadmap aligned to NIST CSF 2.0</p></li><li><p><strong>Implement</strong> the right tools and processes for your size and budget</p></li><li><p><strong>Train</strong> your team on today&#8217;s threats, including AI-driven scams</p></li><li><p><strong>Support</strong> and improve your security over time</p></li></ul><p><strong>Call (440) 808-0468 or visit <a href="https://starfishcomputer.com/contact">starfishcomputer.com</a> to schedule a security assessment.</strong></p><h2>About the author</h2><p><strong>R.J. Arhar</strong> is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of <em>Attack or Defend &#8211; When is Enough Cybersecurity Enough?</em></p><p><em>This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.</em></p><h3>Sources</h3><ol><li><p><a href="https://www.bls.gov/ooh/management/computer-and-information-systems-managers.htm">U.S. Bureau of Labor Statistics, &#8220;Computer and Information Systems Managers,&#8221; Occupational Outlook Handbook</a></p></li><li><p><a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">NIST, &#8220;NIST Releases Version 2.0 of Landmark Cybersecurity Framework&#8221;</a></p></li><li><p><a href="https://www.verizon.com/business/resources/executivebriefs/dbir-2026-executive-summary.pdf">Verizon, 2026 Data Breach Investigations Report, Executive Summary</a></p></li><li><p><a href="https://www.bakerdonelson.com/ten-takeaways-from-ibms-2026-cost-of-a-data-breach-report">Baker Donelson, &#8220;Ten Takeaways from IBM&#8217;s 2026 Cost of a Data Breach Report&#8221;</a></p></li><li><p><a href="https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm">U.S. Bureau of Labor Statistics, &#8220;Information Security Analysts,&#8221; Occupational Outlook Handbook</a></p></li><li><p><a href="https://support.microsoft.com/en-us/windows/windows-10-support-has-ended-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281">Microsoft, &#8220;Windows 10 support has ended on October 14, 2025&#8221;</a></p></li></ol>]]></content:encoded></item></channel></rss>