Internal Use — Email Copy Tool

September 2026 Newsletter — Email Version

Click the button below to copy the formatted newsletter, then paste into Gmail, Outlook, or your email client.

IT Insights & News
September 2026

Welcome to the September 2026 edition of IT Insights & News — our monthly roundup of what is happening in IT and cybersecurity that matters to Central Florida businesses. If a colleague forwarded this to you, you can subscribe here.


This Month at a Glance

  • AI-Assisted Phishing: The threat has matured — here is what it looks like now
  • Microsoft 365 Security Defaults: What changed and what you need to do
  • Q4 Disaster Recovery Review: Why now is the right time to test your plan
  • Quick Tip: One setting that stops most account takeovers
  • From the Team: What we are seeing in the field this month

AI-Assisted Phishing: The Threat Has Matured

A year ago, we were warning clients that AI tools were making phishing emails harder to spot. In September 2026, that warning has become the new normal — and the tactics have evolved further than most businesses realize.

The latest generation of AI-assisted phishing attacks does not just produce grammatically correct emails. It produces contextually accurate ones. Attackers are now pulling data from LinkedIn, company websites, press releases, and social media to craft messages that reference real projects, real colleagues, and real business relationships.

We reviewed three phishing attempts that hit Central Florida businesses this month. All three:

  • Referenced the recipient by name and job title
  • Mentioned a real vendor or partner relationship
  • Used formatting and signature styles that matched the impersonated sender
  • Were sent from domains registered within the past 30 days — too new to appear on most blocklists

The practical implication: employee training that focuses on "does this email look suspicious?" is no longer sufficient. The emails do not look suspicious. The focus needs to shift to process — specifically, verifying any request involving credentials, payments, or sensitive data through a second channel before acting on it.

What to do: Review your security awareness training program. If it has not been updated in the past 12 months, it is not addressing the current threat landscape. Simulated phishing campaigns that use AI-generated content are now available and worth running. Call us if you want help setting one up.


Microsoft 365 Security Defaults: What Changed in September

Microsoft rolled out updated security defaults for Microsoft 365 tenants this month, with changes that affect how multi-factor authentication is enforced and which legacy authentication protocols are blocked.

Here is what changed and what it means for your business:

Legacy Authentication Blocking Is Now Broader

Microsoft has expanded the list of legacy authentication protocols that are blocked by default. This includes older versions of ActiveSync, POP3, and IMAP configurations that bypass MFA entirely. If any of your users or applications rely on these protocols, they may have stopped working.

Who is affected: Businesses using older email clients (Outlook 2013 or earlier), shared mailboxes accessed via legacy protocols, or third-party applications that authenticate directly to Exchange using basic authentication.

What to do: Check your Microsoft 365 admin center for sign-in activity reports filtered to legacy authentication. Any active legacy auth connections need to be migrated to modern authentication before they become a support issue.

MFA Registration Is Now Required for New Accounts

New Microsoft 365 accounts created in tenants with security defaults enabled will now be required to register for MFA during their first sign-in. This is a positive change — it closes the window between account creation and MFA enrollment that attackers sometimes exploit.

What to do: Update your onboarding process to account for the MFA registration step. New employees should complete MFA setup before they need to access any business-critical systems.

Conditional Access Policy Interaction

If your tenant uses Conditional Access policies (available in Microsoft 365 Business Premium), the new security defaults may conflict with existing policies. Microsoft disables security defaults when Conditional Access is active, but it is worth reviewing your policies to confirm they cover the same ground.

What to do: If you are on Business Premium, review your Conditional Access policies against the new default requirements. If you are on Business Standard or Basic, verify that security defaults are enabled in your tenant.

If you are not sure where your Microsoft 365 tenant stands on any of these items, we are glad to do a quick review. Call us at 352-432-4200.


Q4 Is the Right Time to Test Your Disaster Recovery Plan

We say this every year, and every year it is still true: Q4 is the best time to test your disaster recovery plan. Here is why the timing matters.

Hurricane season ends November 30. If you have not tested your recovery procedures since last hurricane season, you do not actually know whether your plan works. Testing now — before the season ends — closes that gap while the lessons from any storm events are still fresh.

Year-end audits surface compliance gaps. Many businesses discover backup and recovery deficiencies during year-end IT audits. Finding them in October gives you time to address them before they become a finding on a client security questionnaire or a compliance review.

Holiday staffing creates risk. Reduced staffing in November and December means IT incidents are more likely to go undetected longer. A tested and documented recovery plan means your team can execute a recovery even without your most experienced IT person available.

What a Meaningful DR Test Looks Like

  • Restore test: Actually restore a server or a significant data set from backup and measure how long it takes. Compare that to your Recovery Time Objective. If you do not have a defined RTO, this is a good time to establish one.
  • Tabletop exercise: Walk through a specific scenario — ransomware attack, server room flooding, extended power outage — with the people who would be responsible for responding. Identify gaps in your plan before they become gaps in an actual recovery.
  • Remote work validation: Confirm that your team can actually work from home if your office is inaccessible. Test VPN access, remote desktop connections, and access to critical applications from outside the office network.
  • Contact list review: Verify that your emergency contact list is current. Phone numbers change. People leave. The middle of an incident is not the time to discover that your primary IT contact's number is out of date.

If you have not done a formal DR test this year, we can help you run one. We work with businesses across Central Florida to design and execute tabletop exercises and restore tests that give you real confidence in your recovery capabilities — not just a checkbox on a compliance form.


Quick Tip: The One Setting That Stops Most Account Takeovers

If you do nothing else this month, do this: confirm that multi-factor authentication is enabled for every user in your Microsoft 365 tenant — including shared mailboxes and service accounts.

MFA stops more than 99 percent of automated credential-stuffing attacks. It is the single highest-impact security control available to small businesses, it is included in every Microsoft 365 plan at no additional cost, and it takes less than an hour to enable for an entire organization.

To check your current MFA status: log into the Microsoft 365 admin center, go to Users > Active Users, and look for the "Multi-factor authentication" column. Any account showing "Disabled" is a risk.

If you find accounts with MFA disabled and are not sure how to enable it without disrupting your team, call us. We can walk you through it or handle it for you.


From the Team: What We Are Seeing in the Field

A few patterns we have noticed across client environments this month that are worth sharing:

Backup jobs running but not completing. We have seen several cases this month where backup jobs were showing as "running" in the management console but had not actually completed a successful backup in weeks. The jobs were stuck, not failing — so no alert was triggered. If you are relying on automated alerts to know when backups fail, add a manual check to your routine: confirm that the last completed backup timestamp is recent, not just that a job is running.

Outdated firmware on network equipment. Several businesses we onboarded this quarter had network switches and wireless access points running firmware that was two or three years out of date. Firmware updates for network equipment are easy to overlook because the equipment "just works" — until a vulnerability is published and attackers start scanning for it. Add network equipment firmware to your quarterly maintenance checklist.

Microsoft 365 licenses assigned to departed employees. We found active Microsoft 365 licenses assigned to former employees at three separate clients this month. In two cases, the accounts were still accessible — the passwords had never been changed and MFA had never been enabled. Offboarding procedures need to include immediate license revocation and account disabling, not just removing the person from the org chart.


Coming Up in October

Next month we will be covering:

  • Cybersecurity Awareness Month: what it means for your security training program
  • Windows 10 end-of-life planning: what businesses still running Windows 10 need to do before October 2025
  • Network segmentation basics: why separating your guest Wi-Fi from your business network matters more than you think

Talk to Our Team

If anything in this newsletter raised a question about your own environment, we are glad to help. BlueStream Consulting serves small and mid-sized businesses across Central Florida — Clermont, Kissimmee, Lakeland, Winter Garden, Tavares, and the greater Orlando area.

Call us at 352-432-4200 or reach out through our contact page to schedule a complimentary IT review.

— The BlueStream Consulting Team

BlueStream Consulting
Central Florida IT & Cybersecurity
352-432-4200 | teambluestream.com

You are receiving this newsletter because you are a client or contact of BlueStream Consulting. To unsubscribe, reply to this email with "Unsubscribe" in the subject line.