Click the button below to copy the formatted newsletter, then paste into Gmail, Outlook, or your email client.
Welcome to the September 2026 edition of IT Insights & News — our monthly roundup of what is happening in IT and cybersecurity that matters to Central Florida businesses. If a colleague forwarded this to you, you can subscribe here.
A year ago, we were warning clients that AI tools were making phishing emails harder to spot. In September 2026, that warning has become the new normal — and the tactics have evolved further than most businesses realize.
The latest generation of AI-assisted phishing attacks does not just produce grammatically correct emails. It produces contextually accurate ones. Attackers are now pulling data from LinkedIn, company websites, press releases, and social media to craft messages that reference real projects, real colleagues, and real business relationships.
We reviewed three phishing attempts that hit Central Florida businesses this month. All three:
The practical implication: employee training that focuses on "does this email look suspicious?" is no longer sufficient. The emails do not look suspicious. The focus needs to shift to process — specifically, verifying any request involving credentials, payments, or sensitive data through a second channel before acting on it.
What to do: Review your security awareness training program. If it has not been updated in the past 12 months, it is not addressing the current threat landscape. Simulated phishing campaigns that use AI-generated content are now available and worth running. Call us if you want help setting one up.
Microsoft rolled out updated security defaults for Microsoft 365 tenants this month, with changes that affect how multi-factor authentication is enforced and which legacy authentication protocols are blocked.
Here is what changed and what it means for your business:
Microsoft has expanded the list of legacy authentication protocols that are blocked by default. This includes older versions of ActiveSync, POP3, and IMAP configurations that bypass MFA entirely. If any of your users or applications rely on these protocols, they may have stopped working.
Who is affected: Businesses using older email clients (Outlook 2013 or earlier), shared mailboxes accessed via legacy protocols, or third-party applications that authenticate directly to Exchange using basic authentication.
What to do: Check your Microsoft 365 admin center for sign-in activity reports filtered to legacy authentication. Any active legacy auth connections need to be migrated to modern authentication before they become a support issue.
New Microsoft 365 accounts created in tenants with security defaults enabled will now be required to register for MFA during their first sign-in. This is a positive change — it closes the window between account creation and MFA enrollment that attackers sometimes exploit.
What to do: Update your onboarding process to account for the MFA registration step. New employees should complete MFA setup before they need to access any business-critical systems.
If your tenant uses Conditional Access policies (available in Microsoft 365 Business Premium), the new security defaults may conflict with existing policies. Microsoft disables security defaults when Conditional Access is active, but it is worth reviewing your policies to confirm they cover the same ground.
What to do: If you are on Business Premium, review your Conditional Access policies against the new default requirements. If you are on Business Standard or Basic, verify that security defaults are enabled in your tenant.
If you are not sure where your Microsoft 365 tenant stands on any of these items, we are glad to do a quick review. Call us at 352-432-4200.
We say this every year, and every year it is still true: Q4 is the best time to test your disaster recovery plan. Here is why the timing matters.
Hurricane season ends November 30. If you have not tested your recovery procedures since last hurricane season, you do not actually know whether your plan works. Testing now — before the season ends — closes that gap while the lessons from any storm events are still fresh.
Year-end audits surface compliance gaps. Many businesses discover backup and recovery deficiencies during year-end IT audits. Finding them in October gives you time to address them before they become a finding on a client security questionnaire or a compliance review.
Holiday staffing creates risk. Reduced staffing in November and December means IT incidents are more likely to go undetected longer. A tested and documented recovery plan means your team can execute a recovery even without your most experienced IT person available.
If you have not done a formal DR test this year, we can help you run one. We work with businesses across Central Florida to design and execute tabletop exercises and restore tests that give you real confidence in your recovery capabilities — not just a checkbox on a compliance form.
If you do nothing else this month, do this: confirm that multi-factor authentication is enabled for every user in your Microsoft 365 tenant — including shared mailboxes and service accounts.
MFA stops more than 99 percent of automated credential-stuffing attacks. It is the single highest-impact security control available to small businesses, it is included in every Microsoft 365 plan at no additional cost, and it takes less than an hour to enable for an entire organization.
To check your current MFA status: log into the Microsoft 365 admin center, go to Users > Active Users, and look for the "Multi-factor authentication" column. Any account showing "Disabled" is a risk.
If you find accounts with MFA disabled and are not sure how to enable it without disrupting your team, call us. We can walk you through it or handle it for you.
A few patterns we have noticed across client environments this month that are worth sharing:
Backup jobs running but not completing. We have seen several cases this month where backup jobs were showing as "running" in the management console but had not actually completed a successful backup in weeks. The jobs were stuck, not failing — so no alert was triggered. If you are relying on automated alerts to know when backups fail, add a manual check to your routine: confirm that the last completed backup timestamp is recent, not just that a job is running.
Outdated firmware on network equipment. Several businesses we onboarded this quarter had network switches and wireless access points running firmware that was two or three years out of date. Firmware updates for network equipment are easy to overlook because the equipment "just works" — until a vulnerability is published and attackers start scanning for it. Add network equipment firmware to your quarterly maintenance checklist.
Microsoft 365 licenses assigned to departed employees. We found active Microsoft 365 licenses assigned to former employees at three separate clients this month. In two cases, the accounts were still accessible — the passwords had never been changed and MFA had never been enabled. Offboarding procedures need to include immediate license revocation and account disabling, not just removing the person from the org chart.
Next month we will be covering:
If anything in this newsletter raised a question about your own environment, we are glad to help. BlueStream Consulting serves small and mid-sized businesses across Central Florida — Clermont, Kissimmee, Lakeland, Winter Garden, Tavares, and the greater Orlando area.
Call us at 352-432-4200 or reach out through our contact page to schedule a complimentary IT review.
— The BlueStream Consulting Team
BlueStream Consulting
Central Florida IT & Cybersecurity
352-432-4200 | teambluestream.com
You are receiving this newsletter because you are a client or contact of BlueStream Consulting. To unsubscribe, reply to this email with "Unsubscribe" in the subject line.