X
Back to the top

Right Sidebar

Right Sidebar

Right Sidebar

A Risk Assessment Is Not a Document. NYSDFS Just Said So.

On September 10, the New York State Department of Financial Services published guidance on how regulated entities should conduct and use risk assessments under Part 500. The first sentence of the guidance says: “This Guidance does not create new obligations.” That’s technically accurate, and also a reason to read more carefully, not less. What the...

Continue reading

AI Close Encounters of a First Kind: What Rogue AI Means for Smaller Businesses

A thousand days since ChatGPT launched, the coverage hasn’t slowed down. What has changed is the quality of the question being asked. Early on, the question was whether AI was real. Then it was whether AI would take everyone’s jobs. Now — at least in the places that are thinking about it seriously — the...

Continue reading

10 Incident Response Scenarios Every Smaller Business Should Test

10 Incident Response Scenarios Every Small Business Should Test Before 2027

Most smaller businesses have some version of an incident response plan: a document on a shared drive, a general understanding of who calls whom if something goes wrong, or just the IT vendor’s number saved in someone’s phone. None of that is the same as having worked through what actually happens when an incident unfolds,...

Continue reading

Ransomware in 2027. Why the Metric Everyone's watching is the wrong one.

Ransomware in 2027: Why the Metric Everyone’s Watching Is the Wrong One

Last year’s ransomware data looked, briefly, like good news. Ransom payments fell roughly 35% in 2024, then another 8% in 2025, and some outlets called it a turning point, which is a reasonable thing to say about data that trends the right direction. The problem is that the payment number and the underlying threat are...

Continue reading

What the CMMC Pause Actually Changed, and What It Didn’t

If you’ve been waiting to sort out your cybersecurity compliance because CMMC is on hold, this is the article worth reading before 2027. The pause is real. Phase II requirements, the third-party assessments by certified C3PAO organizations, are now suspended by binding acquisition regulation, not just an administrative memo. A class deviation signed September 3,...

Continue reading

The problem with MFA

The Problem with MFA (And Why You Can’t Ditch It)

For most of the last decade, “add MFA” was the closest thing to a silver bullet that cybersecurity had. Multi-factor authentication (the text message, the authenticator app push, the numerical code) gave organizations something passwords alone couldn’t: a second barrier that made account compromises significantly harder. New Q2 2026 Research from LevelBlue suggests attackers have...

Continue reading

OrbitalFire Cybersecurity delivers fully managed, affordable, cybersecurity services to small businesses.

We are the small business cybersecurity experts

certifications

Find Us

(844) ORB-FIRE (672-3473)

Troy, NY
Rochester, NY

OrbitalFire Cybersecurity  BBB Business Review

(R) All Rights Reserved 2025  |  OrbitalFire Cybersecurity  |  Privacy Policy