TechOnPurpose Logo

Welcome To Our New Vlog Series: Who’s In Your Cloud?

by | Sep 17, 2021

Who's In Your Cloud Blog Header Image
In today’s “online” world, it’s nearly impossible to run a business without relying on the cloud. From peers to patrons, providers to perps – do you really know who’s in your cloud?

Introducing Who’s In Your Cloud – a new Vlog series that focuses the TechOnPurpose (“TOP”) 21 recommended best security practices – the #TOPcyber21!

The #TOPcyber21 utilizes 21 vital tools and best security practices, purpose-built to help select clients globally establish end-to-end cybersecurity from the office to the cloud and beyond.

“Constant threats from malicious actors intent on stealing our intellectual property, finances and livelihoods could not be more present, ubiquitous and real,” states Matt Tankersley, Founder & CEO.  “While certain industries are targeted more than others, no one is exempt and size does not matter. Like never before, the failure to plan is an inevitable plan to fail.”

Consider (carefully) these alarming Small Business Cyber Security Statistics (2021) by Fundera.com

  • 43% of cyber attacks target small businesses.
  • 60% of small businesses that are victims of a cyber attack go out of business within six months.
  • Cybercrime costs small and medium businesses more than $2.2 million a year.
  • There was a 424% increase in new small business cyber breaches last year.
  • Healthcare is the industry that’s most at-risk for cyber attacks.
  • 66% of small businesses are concerned or extremely concerned about cyber security risk.
  • 14% of small businesses rate their ability to mitigate cyber risks and attacks as highly effective.
  • 47% of small businesses they have no understanding of how to protect themselves against cyber attacks.
  • 66% of small businesses are most concerned about compromising customer data.
  • 3 out of 4 small businesses say they don’t have the personnel to address IT security.
  • 22% of small businesses encrypt their databases.
  • Human error and system failure account for 52% of data security breaches.
  • 63% of confirmed data breaches leverage a weak, default, or stolen password.
  • Cyber attacks caused by compromised employee passwords cost $383,365 on average.
  • 1 in 323 emails sent to small businesses are malicious.
  • The median small business received 94% of its detected malware by email.
  • 54% of small businesses think they’re too small for a cyber attack.
  • 25% of small businesses didn’t realize cyber attacks would cost them money.
  • 83% of small businesses haven’t put cash aside for dealing with a cyber attack.
  • 54% of small businesses don’t have a plan in place for reacting to cyber attacks.
  • 65% of small businesses have failed to act following a cyber security incident.
  • 50% of small and mid-sized businesses reported suffering at least one cyber attack in the last year.
  • Small businesses spend an average of $955,429 to restore normal business in the wake of successful attacks.
  • Just figuring out how a cyber attack happened could cost $15,000.
  • 40% of small businesses experienced eight or more hours of downtime due to a cyber breach.
  • This downtime accounts for an average of $1.56 million in losses.
  • Cyber attacks are projected to cause $6 trillion in damages by 2021.
  • Industry experts say a small business’s cyber security budget should be at least 3% of a company’s total spending.
  • 91% of small businesses don’t have cyber liability insurance.
  • This biggest cyber attack to date happened to Yahoo! In August 2013 when 3 billion accounts were hacked.

How TOP is Helping Small Businesses with Cybersecurity

“We care deeply for our customers, their business and success,” states Lauren Lev, Marketing Manager. “We’ve spent months developing our suite of services to protect our growing client family from these cyber atrocities. With the launch of our “Who’s in Your Cloud” campaign we’re extending the opportunity for current and new customers to also receive a FREE cybersecurity survey in the month of October.”

With this clear mission in mind, the #TOPcyber21 best security practice matrix includes all that’s needed to confidently identify, protect, detect, respond and recover to emerging cybersecurity risks for organizations of any type or size.

Sound familiar?  It should.

TOP has very intentionally built a service portfolio that meets or exceeds this proven cybersecurity framework developed by NIST (“National Institute of Standards and Technology”).

Organizations seeking to strengthen their cybersecurity, compliance and risk management posture can simply sign-up for a free cybersecurity survey to assess where risk is obvious or possible. Results are fast and the #TOPcyber21 matrix will help to chart a clear course of prioritized actions, products or services to secure gaps.

The #TOPcyber21 provides three unique solution sets for each of the (21) best security practices, offering your team a comprehensive total of (63) different security solutions, starting with Security Awareness Training.

Security awareness training is the tip of the #TOPcyber21 matrix – an operational imperative for teams of any size, especially considering that “user error” is the cause of 95% of cybersecurity compromises.

The TechOnPurpose 21 Recommended Best Security Practices for Businesses and Non Profits

“As we finalize plans to get underway in early October, viewers can anticipate a fiery lineup of sass and savvy from our industry experts who’ll be joining us for each segment,” states Lauren Lev.  “I encourage business owners, IT professionals and cyber enthusiasts to subscribe and follow along as we endeavor to unwrap the complexity of cybersecurity in today’s online marketplace.”

No matter the industry or size of your organization, TOP’s cybersecurity portfolio has all that’s needed to confidently tackle the unavoidable reality of today’s cyber threats.

Are you ready to discover why so many small businesses trust TechOnPurpose with their security needs?

We encourage you to take our free cybersecurity survey online today to discover what potential vulnerabilities your business should be aware of. Want to talk to a rep instead? Contact us anytime to chat about your IT and security needs.

And, be sure to subscribe to our blog to catch all the episodes of “Who’s In Your Cloud?” from TechOnPurpose and our expert partners.

Claim Your Free Cybersecurity Sruvey
#CYBERinsanity – Habit #2: No MFA!

#CYBERinsanity – Habit #2: No MFA!

NOT using MFA is not only unwise – it’s insane! A simple (poor) choice that daily robs individuals and organizations of potentially EVERYTHING. So what’s your excuse?

View Next

Diagram showing how Texas cybersecurity law applies to every business, with two outcome paths — documented before a breach leads to safe harbor, documented after leads to full legal exposure

Texas Cybersecurity Law: What Every Business Must Know

⏱ 6 min readKey Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
CVE dashboard showing NIST's "Not Scheduled" status replacing CVSS scores — patch prioritization without a score

NIST Just Derailed Patch Prioritization — Here’s Your Fix

⏱ 3 min readKey Takeaways NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently. Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive...
AI-Enabled Device Code Phishing — TechOnPurpose Identity & Access Management MFA Bypass Prevention

AI-Enabled Device Code Phishing Is Bypassing MFA — What Your Microsoft 365 Users Are Up Against

⏱ 4 min readKey Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won't catch...
Chrome Zero-Day Patch — TechOnPurpose TC21-05 Endpoint Patch Management Urgency

Chrome Zero Day Patch: Update Now

⏱ 4 min readKey Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
Russian CTRL Toolkit remote desktop hijacking — TechOnPurpose TC21-15 secure remote access defense

Russian Malware CTRL: Remote Desktop Hijacking Undetected

⏱ 4 min readKey Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
Old vulnerabilities cyber risk — TechOnPurpose patch management defense-in-depth

#CYBERinsanity: The Vulnerabilities Attacking You Today Were Published a Decade Ago

⏱ 5 min readKey Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they're just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying anything...
Defense in depth strategy — TechOnPurpose TOPCYBER21 cybersecurity framework protects your organization from vulnerability exploits

Why Patching Alone Won’t Stop 40% of Cyberattacks

⏱ 4 min readKey Takeaways A defense in depth strategy is no longer optional — it's the only architecture that holds when patching alone fails. Nearly 40% of all intrusions in Q4 2025 were caused by exploited vulnerabilities — not phishing, not credential theft. Some...
2026 National Cyber Strategy Blog Post image

2026 National Cybersecurity Strategy: What It Means for You

⏱ 5 min readKey Takeaways The White House's 2026 national cybersecurity strategy introduces six strategic pillars — the clearest federal signal yet that passive cyber defense is no longer acceptable. All six pillars align directly to the TOPCYBER21™ framework — if...
TechOnPurpose achieves MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally—a significant jump of 32 positions from last year's #191.

TechOnPurpose Named to MSSP Alert’s 2025 List of Top 250 MSSPs – Climbs 32 Spots Year-Over-Year

TechOnPurpose is proud to announce its inclusion in MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally - a significant jump of 32 positions from last year's #191. This marks the second consecutive year...
#STOPtheCYBERinsanity image - Is Pen Testing a Dollars-Before-Defense Mistake

#CYBERinsanity: When Pen Testing Becomes a Dollars-Before-Defense Mistake

The Fallacy of Pen Testing as a Priority in Cybersecurity If you’ve been following our STOP the #CYBERinsanity series, you already know this uncomfortable truth: Most cybersecurity failures aren’t caused by brilliant hackers or exotic zero-day exploits. They’re caused...
en_US