Prairie Information Technology Services Corp.
Your primary work email is on every business card, contract, and website. It's also the first thing attackers look for when they're targeting your business.
Phishing crews scrape your company website and LinkedIn for the format and patterns of your email addresses. Once they have one address, they can guess the rest of your team's emails in seconds. That gives them targets for credential phishing, fake invoice scams, and CEO impersonation.
Email aliases reduce that exposure. An alias is an extra email address that delivers to the same inbox without exposing the real one. Microsoft 365 supports up to 400 aliases per mailbox. Google Workspace supports up to 30 per user. Both are free and built in.
A simple pattern that works for most small businesses:
- Use a public-facing alias for any address that lives on your website, business cards, and signup forms (info@, hello@, sales@). Keep your real email off public pages.
- Create vendor-specific aliases for major suppliers ([email protected], [email protected]). If one vendor leaks and you start seeing phishing on that alias, you know exactly which one.
- Use one tightly held internal email for sensitive operations like banking and payroll. That one stays off everything public.
If a phishing campaign hits one of your aliases tomorrow, you'll know which list you ended up on. You can shut that alias off without changing your main address.
If someone asks whether your business has backups, you probably say yes. Disaster recovery is a different question.
A backup is a copy of your data. Disaster recovery is the plan that brings your business back to running condition after something goes wrong. The two get confused all the time, and the confusion costs real money when ransomware or a hardware failure hits.
A good backup setup follows the 3-2-1-1-0 rule: three copies of every important file, on two different types of storage, with one copy stored offsite, one copy that's immutable so ransomware can't encrypt it, and zero errors in your last test restore.
That last one is what most businesses skip. Untested backups are not backups.
They're an unverified promise.
Pick a normal file, an email, and a full server volume, then try to restore each one to a different location.
If the restore works, you have backups. If it doesn't, you have a problem you can fix today instead of during an attack.
Disaster recovery goes one layer further. It's the playbook for what your business does when it can't function. Things like which systems come back first, which people make decisions, which vendors get called, and how long each step is supposed to take. Without that playbook, even a working backup leaves you guessing during the worst week of your year.
07/12/2026
In April 2026, ransomware hit Adaptavist, an Atlassian platinum partner that builds and supports tools for thousands of business customers.
Adaptavist makes ScriptRunner and similar add-ons that plug into Atlassian products like Jira and Confluence. When attackers got into Adaptavist's systems, every customer connected to those tools was suddenly downstream of a breach they didn't cause.
This is the supply chain attack pattern. Your business doesn't have to be the target. It just has to share a vendor with the target.
Three things worth doing this month:
-Make a one-page list of every SaaS vendor your business depends on. Email, accounting, payroll, CRM, helpdesk, file storage, project management. The list is usually longer than you'd expect.
-For each vendor, find their security and breach notification page online. If you can't find it in five minutes, that's information worth knowing.
-For the top five vendors by data sensitivity, ask three questions in writing: do you have a current SOC 2 Type II report, what's your breach notification SLA, and how do you handle credentials inside your support tooling.
You can't control every vendor's security. Pick the ones that take it seriously.
Adaptavist Group breach: Ransomware crew claims mega-haul : Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole
Your incident response plan needs to live on paper, because the second you need it, your computers and email are the thing that's broken.
A one-page version beats nothing. The most important piece is the contact list, because those are the phone numbers you can't get to once your systems are down. Print this list and keep one copy at the office and one at home.
Six contacts to have on paper:
1. Your cyber insurance broker. They open the door to every other resource your policy covers. Save the after-hours line, not just the main number.
2. Your breach attorney. Not your business attorney. A specialist in cyber incidents. Their first job is to create legal privilege over the response.
3. Your incident response firm. If your insurance assigns one, save the IR firm's name and 24/7 line on this same page.
4. Your IT provider or MSP. Direct line for the senior engineer, not the front desk.
5. Law enforcement. FBI IC3 (1-800-CALL-FBI / ic3.gov) and your state cyber unit if you have one.
6. Two business lifelines. Your bank's fraud line and your payroll provider's emergency line. Both can freeze transactions if an attack is in progress.
Once ransomware locks your email and laptops, the only contact list you can reach is the one you printed.
Click here to claim your Sponsored Listing.