CyberISolve

Security Notes & Case Studies

Write-ups from real engagements, and practical guidance on the threats actually hitting small and mid-sized businesses right now.

All Posts

Network Security

Secure Remote Access: What to Actually Set Up Instead of Forwarding RDP to the Internet

August 5, 2026 · 6 min read

Needing to reach a machine remotely is normal. Forwarding RDP straight through your router so anyone on the internet can try to reach it isn’t — here’s what to do instead.

Incident Response

Case Study: Recovering a Business After a Publicly Exposed RDP Server Was Taken Over and Wiped

August 3, 2026 · 8 min read

A publicly forwarded RDP port, no other way in needed, and the client’s only backup living on the exact machine that got wiped. Here’s how the recovery actually went.

Incident Response

Case Study: Removing a ClickFix Malware Infection From a Compromised WordPress Site

July 14, 2026 · 9 min read

A walkthrough of a real WordPress clean-up: ClickFix-style fake-verification malware, multiple malicious plugins, hidden backdoors, a rogue admin account, and the hardening that stopped it from coming back.

WordPress Security

9 Signs Your WordPress Site Has Been Hacked (and What to Do First)

June 2, 2026 · 6 min read

From unfamiliar admin accounts to sudden search-engine warnings, here are the signs that mean your WordPress site needs an incident response, not just a quick fix.

Managed Security

Why Small Businesses Are Prime Ransomware Targets — Not Just Big Enterprises

May 18, 2026 · 5 min read

The "we’re too small to be a target" assumption is exactly what makes small businesses an efficient target for ransomware operators.

Penetration Testing

Penetration Testing vs. Vulnerability Scanning: What’s Actually the Difference

April 22, 2026 · 5 min read

A scanner tells you what might be exploitable. A penetration test tells you what actually is — and the difference matters for budget and compliance decisions.

Incident Response

Incident Response: What Should Actually Happen in the First 24 Hours

March 10, 2026 · 6 min read

The first 24 hours after discovering a breach determine most of what happens next — here’s the order that actually reduces damage.

Email Security

SPF, DKIM, and DMARC: What They Actually Do and Why Half of Small Business Email Is Still Unprotected

February 24, 2026 · 6 min read

Three records that decide whether an attacker can send email that looks like it came from you — and why so many small businesses have them missing or misconfigured.

Identity Security

Multi-Factor Authentication: Why SMS Codes Are the Weakest Option, Not the Safe Default

February 10, 2026 · 5 min read

MFA dramatically cuts account-takeover risk, but not all MFA is equal — SMS codes are the version most vulnerable to interception and SIM-swap attacks.

Vulnerability Management

Patch Management: Why "We Update on Patch Tuesday" Isn’t a Full Strategy

January 28, 2026 · 5 min read

Patch Tuesday covers Windows and Microsoft products. It says nothing about your third-party software, network devices, or the servers running your business.

Network Security

VPN vs. Zero Trust Network Access: What Actually Changes for a Small Business

January 15, 2026 · 5 min read

Zero Trust is genuinely useful, but it’s not automatically the right move for every business still running a traditional VPN.

WordPress Security

A WooCommerce Security Checklist That Goes Beyond "Install a Security Plugin"

December 18, 2025 · 6 min read

WooCommerce security is WordPress security plus payment data, checkout flow, and PCI scope — a single security plugin doesn’t cover all of that.

Penetration Testing

What a Phishing Simulation Actually Tests (and What It Doesn’t)

December 2, 2025 · 5 min read

Click-rate is the number every phishing simulation report leads with, and it’s also the least useful metric in it.

Cloud Security

The Cloud Misconfigurations We Find Most Often in AWS and Azure Audits

November 19, 2025 · 6 min read

Most cloud breaches aren’t sophisticated exploits — they’re a handful of recurring configuration mistakes we see across almost every audit.

Threat Detection

EDR vs. Traditional Antivirus: What the Upgrade Actually Buys You

November 5, 2025 · 5 min read

Antivirus asks "is this file known-bad?" EDR asks "is this behavior suspicious?" — and that distinction is why modern attacks slip past antivirus alone.

Incident Response

Why We Run Tabletop Exercises Before a Business Ever Needs Incident Response for Real

October 22, 2025 · 5 min read

A written incident response plan and a team that’s actually rehearsed it are two very different levels of preparedness.

Network Security

DNS Security: The Infrastructure Layer Most Businesses Never Monitor

October 8, 2025 · 5 min read

DNS decides where your traffic actually goes, and it’s one of the least monitored pieces of infrastructure in a typical small business setup.

Incident Response

Case Study: How a Business Email Compromise Almost Redirected a $40,000 Wire Transfer

September 24, 2025 · 6 min read

A convincing email, a legitimate-looking invoice, and one habit that stopped a $40,000 wire transfer from going to the wrong account.

Data Protection

The 3-2-1 Backup Rule, and Why "We Have Backups" Still Isn’t Enough

September 10, 2025 · 5 min read

Having backups and having a backup strategy that actually survives ransomware are two different things.

Compliance

PCI-DSS Basics for Small Retailers: What Actually Applies to You

August 27, 2025 · 6 min read

PCI-DSS applies differently depending on how your business actually handles card data — and reducing scope is often more practical than trying to secure everything.

Penetration Testing

Social Engineering Beyond Phishing: Pretexting, Vishing, and Physical Tailgating

August 13, 2025 · 5 min read

Phishing is the social engineering technique everyone trains for. It’s not the only one, and the others don’t show up in an email inbox at all.

Incident Response

Ransomware: Should You Ever Pay? What We Tell Clients Facing That Decision

July 30, 2025 · 6 min read

There’s no universally correct answer to "should we pay the ransom" — but there are specific factors that should actually drive the decision, and a few myths worth clearing up first.

Dealing with something right now?

If this is an active incident, don't wait on a blog post — our response team is on call 24/7.