Newsletter Review Page
For Mr. Jason's review before publishing. This page is not indexed by search engines.
Newsletter Status
Approval Checklist
- 1Mr. Jason reviews this page
- 2Mr. Jason approves — replies or calls 352-432-4200
- 3Set published: true in campaignBlogPosts.ts
- 4Publish site — blog post goes live
- 5Send email campaign to leads list
Welcome to the September 2026 edition of IT Insights & News — our monthly roundup of what is happening in IT and cybersecurity that matters to Central Florida businesses.
This Month at a Glance
- •AI-Assisted Phishing: The threat has matured — here is what it looks like now
- •Microsoft 365 Security Defaults: What changed and what you need to do
- •Q4 Disaster Recovery Review: Why now is the right time to test your plan
- •Quick Tip: One setting that stops most account takeovers
- •From the Team: What we are seeing in the field this month
AI-Assisted Phishing: The Threat Has Matured
A year ago, we were warning clients that AI tools were making phishing emails harder to spot. In September 2026, that warning has become the new normal — and the tactics have evolved further than most businesses realize.
The latest generation of AI-assisted phishing attacks does not just produce grammatically correct emails. It produces contextually accurate ones. Attackers are now pulling data from LinkedIn, company websites, press releases, and social media to craft messages that reference real projects, real colleagues, and real business relationships.
We reviewed three phishing attempts that hit Central Florida businesses this month. All three referenced the recipient by name and job title, mentioned a real vendor or partner relationship, used formatting and signature styles that matched the impersonated sender, and were sent from domains registered within the past 30 days — too new to appear on most blocklists.
The practical implication: employee training that focuses on "does this email look suspicious?" is no longer sufficient. The emails do not look suspicious. The focus needs to shift to process — specifically, verifying any request involving credentials, payments, or sensitive data through a second channel before acting on it.
What to do: Review your security awareness training program. If it has not been updated in the past 12 months, it is not addressing the current threat landscape. Simulated phishing campaigns that use AI-generated content are now available and worth running. Call us if you want help setting one up.
Microsoft 365 Security Defaults: What Changed in September
Microsoft rolled out updated security defaults for Microsoft 365 tenants this month, with changes that affect how multi-factor authentication is enforced and which legacy authentication protocols are blocked.
Legacy Authentication Blocking Is Now Broader — Microsoft has expanded the list of legacy authentication protocols that are blocked by default. This includes older versions of ActiveSync, POP3, and IMAP configurations that bypass MFA entirely. If any of your users or applications rely on these protocols, they may have stopped working. Check your Microsoft 365 admin center for sign-in activity reports filtered to legacy authentication.
MFA Registration Is Now Required for New Accounts — New Microsoft 365 accounts created in tenants with security defaults enabled will now be required to register for MFA during their first sign-in. Update your onboarding process to account for the MFA registration step.
Conditional Access Policy Interaction — If your tenant uses Conditional Access policies (available in Microsoft 365 Business Premium), the new security defaults may conflict with existing policies. Review your Conditional Access policies against the new default requirements.
If you are not sure where your Microsoft 365 tenant stands on any of these items, we are glad to do a quick review. Call us at 352-432-4200.
Q4 Is the Right Time to Test Your Disaster Recovery Plan
We say this every year, and every year it is still true: Q4 is the best time to test your disaster recovery plan.
Hurricane season ends November 30. If you have not tested your recovery procedures since last hurricane season, you do not actually know whether your plan works. Year-end audits surface compliance gaps — finding them in October gives you time to address them before they become a finding on a client security questionnaire. Reduced staffing in November and December means IT incidents are more likely to go undetected longer.
A meaningful DR test includes: actually restoring a server or significant data set from backup and measuring how long it takes; a tabletop exercise walking through a specific scenario (ransomware, flooding, extended power outage); remote work validation confirming your team can work from home if the office is inaccessible; and a contact list review to verify emergency contacts are current.
If you have not done a formal DR test this year, we can help you run one.
Quick Tip: The One Setting That Stops Most Account Takeovers
If you do nothing else this month, do this: confirm that multi-factor authentication is enabled for every user in your Microsoft 365 tenant — including shared mailboxes and service accounts.
MFA stops more than 99 percent of automated credential-stuffing attacks. It is the single highest-impact security control available to small businesses, it is included in every Microsoft 365 plan at no additional cost, and it takes less than an hour to enable for an entire organization.
To check your current MFA status: log into the Microsoft 365 admin center, go to Users > Active Users, and look for the "Multi-factor authentication" column. Any account showing "Disabled" is a risk. Call us if you need help enabling it without disrupting your team.
From the Team: What We Are Seeing in the Field
Backup jobs running but not completing — We have seen several cases this month where backup jobs were showing as "running" in the management console but had not actually completed a successful backup in weeks. The jobs were stuck, not failing — so no alert was triggered. Add a manual check to your routine: confirm that the last completed backup timestamp is recent, not just that a job is running.
Outdated firmware on network equipment — Several businesses we onboarded this quarter had network switches and wireless access points running firmware that was two or three years out of date. Add network equipment firmware to your quarterly maintenance checklist.
Microsoft 365 licenses assigned to departed employees — We found active Microsoft 365 licenses assigned to former employees at three separate clients this month. In two cases, the accounts were still accessible. Offboarding procedures need to include immediate license revocation and account disabling.
Coming Up in October
- •Cybersecurity Awareness Month: what it means for your security training program
- •Windows 10 end-of-life planning: what businesses still running Windows 10 need to do
- •Network segmentation basics: why separating your guest Wi-Fi from your business network matters
Questions? Ready to schedule a complimentary IT review?
352-432-4200— The Team BlueStream Consulting Team
This page is for internal review only. It is marked noindex and will not appear in search results. After approval, the newsletter will be published at teambluestream.com/blog/it-cybersecurity-newsletter-september-2026
