Lewis IT, LLC
If someone asks whether your business has backups, you probably say yes. Disaster recovery is a different question.
A backup is a copy of your data. Disaster recovery is the plan that brings your business back to running condition after something goes wrong. The two get confused all the time, and the confusion costs real money when ransomware or a hardware failure hits.
A good backup setup follows the 3-2-1-1-0 rule: three copies of every important file, on two different types of storage, with one copy stored offsite, one copy that's immutable so ransomware can't encrypt it, and zero errors in your last test restore.
That last one is what most businesses skip. Untested backups are not backups.
They're an unverified promise.
Pick a normal file, an email, and a full server volume, then try to restore each one to a different location.
If the restore works, you have backups. If it doesn't, you have a problem you can fix today instead of during an attack.
Disaster recovery goes one layer further. It's the playbook for what your business does when it can't function. Things like which systems come back first, which people make decisions, which vendors get called, and how long each step is supposed to take. Without that playbook, even a working backup leaves you guessing during the worst week of your year.
Your incident response plan needs to live on paper, because the second you need it, your computers and email are the thing that's broken.
A one-page version beats nothing. The most important piece is the contact list, because those are the phone numbers you can't get to once your systems are down. Print this list and keep one copy at the office and one at home.
Six contacts to have on paper:
1. Your cyber insurance broker. They open the door to every other resource your policy covers. Save the after-hours line, not just the main number.
2. Your breach attorney. Not your business attorney. A specialist in cyber incidents. Their first job is to create legal privilege over the response.
3. Your incident response firm. If your insurance assigns one, save the IR firm's name and 24/7 line on this same page.
4. Your IT provider or MSP. Direct line for the senior engineer, not the front desk.
5. Law enforcement. FBI IC3 (1-800-CALL-FBI / ic3.gov) and your state cyber unit if you have one.
6. Two business lifelines. Your bank's fraud line and your payroll provider's emergency line. Both can freeze transactions if an attack is in progress.
Once ransomware locks your email and laptops, the only contact list you can reach is the one you printed.
07/09/2026
In May 2026, the US government's cybersecurity agency added a top-severity Cisco vulnerability to its "fix this now" list.
The flaw lives in Cisco SD-WAN controllers. These are the devices many businesses use to connect remote offices, branch locations, or remote workers to their main network. The vulnerability scored a 10.0 out of 10 on the standard severity scale, which means an attacker who reaches the device over the internet can take it over completely. Once they're in, they have the keys to the network the device sits on.
CISA's "fix it now" list, formally called the Known Exploited Vulnerabilities catalog, is the list of bugs that hackers are already actively using. Federal agencies have a hard deadline to patch anything on it. Your business should be just as fast.
If you use Cisco SD-WAN, your IT team or MSP should already be on this. If you're not sure, ask them today: "Do we have any Cisco SD-WAN devices anywhere in our network?" The answer is yes, no, or "let me check." Only the third one needs follow-up.
The CISA KEV catalog is free, public, and updated weekly. It's the closest thing to a "what to patch first" list for businesses without a full security team.
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits CISA added CVE-2026-20182, a CVSS 10.0 Cisco Catalyst SD-WAN Controller authentication bypass flaw, to its KEV catalog.
MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.
The attacker already has the password (bought from a leak or stolen from another site). They log in. The MFA push hits your employee's phone. They tap "Deny." The attacker tries again 10 seconds later. Then again at 2am. Then during lunch. Eventually someone taps "Approve" just to make it stop. The attacker is in.
Uber got hit this way in 2022. Cisco too. It still works on small businesses every week because passwords keep leaking and the push prompt looks identical to a real login.
Three things close the gap, and none of them are expensive. Switch your team from "tap to approve" to number matching, which both Microsoft Authenticator and Duo support out of the box and takes about 10 minutes to enable in your tenant. Then turn on geo-blocking or impossible-travel rules in your identity platform so logins from countries you don't operate in get blocked before the push ever fires. Last, give your team one rule: if you get an MFA prompt you didn't ask for, deny it AND report it. The report is what catches the attacker mid-attempt.
The attacker doesn't need a fancy hack. They just need someone tired enough to tap "Approve."
Click here to claim your Sponsored Listing.