• Skip to main content
  • Skip to primary sidebar
  • Home
TechTidBit – Tips and advice for small business computing – Tech Experts™ – Monroe Michigan

TechTidBit - Tips and advice for small business computing - Tech Experts™ - Monroe Michigan

Brought to you by Tech Experts™

The Inbox Hiding Place You Don’t Think To Check

July 21, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

If a hacker got into your email account, you would probably do the obvious thing and change your password right away. That is a good instinct. But it does not always solve the problem.

There is a small feature buried in your inbox settings that attackers use to stay hidden long after you have locked them out. It is called an inbox rule, and most business owners have no idea it exists.

What is an inbox rule?

An inbox rule is a setting that automatically moves emails into folders, flags certain messages, or forwards them to another address. You may already use rules to keep your inbox organized, sorting invoices into one folder and newsletters into another.

That same feature is exactly what makes it so useful to a criminal.

How attackers use inbox rules against you

When someone breaks into an email account, one of the first things they often do is create a hidden rule of their own. These rules can quietly forward copies of your emails to an outside address, move important messages out of your main inbox, or mark them as read so you never notice them arrive.

This happens fast. In many cases, attackers set up these rules within seconds of gaining access, before you even know anything is wrong.

That speed gives them a real advantage. With a hidden rule in place, an attacker can read your conversations, pull out sensitive information, and hide the security alerts that would normally tip you off. If they are after your finance team or leadership, they can also sit back and watch for the right moment to reroute a payment.

Here is the part that catches most people off guard: changing your password does not remove these rules. If you reset your password but skip this step, the attacker may still be reading everything that comes into your inbox.

How to check for hidden inbox rules

The good news is that this is easy to check once you know where to look. Every inbox rule has a name, and one that looks strange, generic, or unfamiliar is worth a closer look. Take a few minutes to review your rules periodically, and always check them right after any suspected security issue.

You do not need advanced technical skills to do this. Most email platforms list all active rules in one settings screen – anything you did not create yourself should raise a flag.

The takeaway

Modern cyberattacks do not always rely on complicated hacking techniques. Sometimes they simply use a feature that is already sitting inside your inbox, working exactly as it was designed to, just for the wrong person’s benefit. A quick habit of checking your inbox rules can close a gap that a password reset alone will not. If you would like a hand making sure your business email is locked down the right way, give us a call.

Those Little Jobs Add Up… Delegate Them To AI

July 21, 2026

When people think about AI at work, they often imagine things like writing reports, analyzing data, or answering emails.

That’s useful, of course. But it’s not where most of your time goes.

In a typical working day, it’s the smaller jobs that really slow things down. Following up after meetings, tidying documents, fixing spreadsheets, chasing information.

They’re not difficult, but combined, they eat into hours you’d rather spend elsewhere.

This is where tools like Microsoft Copilot are becoming genuinely helpful.

Take meetings as an example. The real time cost usually comes afterwards. Notes need checking, actions need confirming, and anyone who missed the call needs catching up.

Copilot in Teams can summarize discussions in a more practical way, pulling out decisions, highlighting what still needs doing, and helping people get straight to the important points.

It’s a similar story with writing.

Most people aren’t staring at a blank page. They’re trying to improve something that already exists. A draft might be too long, unclear, or not quite right for the audience.

Copilot can reshape that content, tighten it up, and adjust the tone without you having to rewrite everything from scratch.

Spreadsheets are another common frustration.

You know what you want the outcome to be but remembering how to get there isn’t always straightforward.

Instead of searching for formulas or watching tutorials, you can describe what you need in plain language and let Copilot handle much of the process.

Microsoft has also started bringing everything together more effectively.

Shared pages and notebooks mean ideas, notes, and files don’t end up scattered across different tools.

It becomes easier to keep projects moving without constantly switching between apps.

And for those repetitive tasks that crop up every day, simple workflows can now be created just by describing the process.

Routine updates, reminders, and approvals can run in the background without needing manual input each time.

As a reassurance, this isn’t to replace people. It’s to remove the small points of friction that build up during the day.

When those start to disappear, work feels smoother, and your team can focus more on the things that move the business forward.

If that sounds like something you’d like to learn more about, we can help. Get in touch.

The 4-Step Legacy IT Debt Audit Your Business Needs

July 21, 2026

Legacy systems and outdated technology create hidden costs that drain your budget and slow your business down.

If you’re running software that hasn’t been updated in years, relying on hardware past its prime, or patching together workarounds to keep things running, you’re carrying technical debt.

According to TechTarget, “A technical debt audit involves systematically identifying, assessing, and prioritizing areas of technical debt within an organization’s IT landscape. This process helps organizations understand the scope and impact of their debt, enabling them to create a strategic plan for remediation.”

Here’s how to conduct a practical audit of your legacy IT systems.

Inventory your current IT assets

Start by creating a complete list of every system, application, and piece of hardware your business uses. Include the age of each asset, its current version, the vendor’s support status, and who depends on it daily.

This isn’t just about servers and computers – document your software licenses, cloud subscriptions, and any custom applications built years ago that still run critical processes.

Assess business impact and risk

For each item in your inventory, evaluate how it affects your operations. Ask: What happens if this system fails tomorrow? Does it handle sensitive customer data? Is it connected to other critical systems?

CIO.com emphasizes that “assessing the impact of technical debt on business operations” and “prioritizing remediation efforts based on risk and value” are essential steps in managing technical debt effectively.

Systems that pose security risks or could halt business operations should rise to the top of your priority list.

Calculate the true cost of keeping it

Legacy systems cost more than their maintenance contracts. Factor in the staff time spent on workarounds, the productivity lost to slow performance, the security vulnerabilities that put you at risk, and the opportunities you’re missing because your systems can’t support new capabilities.

Compare these ongoing costs against the investment required to modernize or replace the system.

Create a prioritized remediation roadmap

Based on your risk assessment and cost analysis, build a realistic plan for addressing your technical debt. Some systems may need immediate replacement while others can be phased out gradually.

Budget for both quick wins that deliver immediate value and longer-term projects that address foundational issues.

Set clear timelines, assign ownership, and establish metrics to track your progress.

If you’d like help conducting a thorough legacy IT audit or developing a modernization strategy that fits your budget and timeline, contact us to discuss your specific situation. You can give us a call at (734) 457-5000, or email us at info@mytechexperts.com.

The Hidden Cost Of “Just This One Time”

July 21, 2026

Most technology problems do not begin with a major failure. They start with a small shortcut.

An employee needs to send a large file, so they upload it to a personal cloud storage account. Someone forgets their laptop charger and borrows a family computer to finish a proposal. A manager shares a password with a coworker because it is quicker than creating a new login.

Each decision seems harmless on its own. After all, everyone is just trying to get their job done.

The trouble is that these “just this once” moments have a habit of becoming everyday habits.

Over time, businesses end up with important files scattered across personal accounts, passwords shared between multiple employees, and sensitive information stored in places that were never meant for business use. Nobody intended to create a security risk. It simply happened one shortcut at a time.

This is one of the biggest challenges we see when working with small businesses.

Most owners invest in firewalls, antivirus software, and secure backups. Those are all important. But even the best technology cannot protect information that has quietly drifted outside of your managed systems.

Imagine an employee leaves your company. If company files are stored in their personal cloud account, do you still have access?

If customer contacts are saved on a personal phone, can you retrieve them? If passwords were shared through text messages or sticky notes, how many accounts need to be changed?

These situations create unnecessary stress during what is already a busy time.

The same problem appears when businesses begin to grow.

What works for five employees often breaks down at fifteen or twenty. New staff members need access to files. Teams need to collaborate. Managers need confidence that information is protected without slowing everyone down.

That is why consistency matters. Instead of asking employees to figure out the best way to share files or store documents, give them one approved method and encourage everyone to use it. Instead of sharing passwords, use a password manager that allows secure access without exposing the actual password. Instead of allowing business information to spread across personal devices and accounts, keep it inside systems that your business owns and controls.

The goal is not to make work more complicated. It is to remove uncertainty.

Employees generally want to do the right thing. If the secure option is also the easiest option, people will naturally follow it.

This is also a good reminder to review your business processes every so often. Ask yourself a few simple questions. Where are our important files stored? Who has access to them? Are we relying on personal accounts for business work? Would someone else be able to find what they need if a key employee was away for a week?

You might be surprised by the answers.

Small improvements made today can prevent much larger problems later. Better organization, clearer processes, and a few sensible security practices can save hours of frustration while reducing your risk at the same time.

Technology should make running your business easier, not leave you wondering where your information is or who can access it.

If you are not sure whether your business has developed a few “just this once” habits over the years, we would be happy to help you take a closer look. Sometimes the biggest improvements come from fixing the small things before they become expensive problems.

Can Someone Hack Your Email Without The Password?

June 22, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

Most people assume an email hack starts with a stolen password. That’s not always true.

Yes, weak and reused passwords are still a major problem. But many modern email attacks work around the password entirely. Hackers are not always sitting in a dark room trying to guess your login. More often, they are tricking someone or slipping into the account through a connected app.

That is why email security cannot stop at “we have strong passwords.”

Your email is one of the most valuable keys to your business. Think about how many systems connect back to it: banking alerts, payroll, Microsoft 365, and cloud storage.

If a criminal gets into your inbox, they may be able to reset passwords for other accounts, read private conversations, and watch how money moves through your company.

One common trick is phishing. An employee receives what looks like a normal Microsoft login. They click the link, enter their information, and the attacker captures what they need.

Another method is account recovery abuse. If recovery options are weak, outdated, or tied to a personal phone number or email account, criminals may use that path to regain access. They do not need the current password if they can convince the system to issue a new one.

One we see far too often is email forwarding rules. A hacker gets access briefly, creates a hidden rule that forwards copies of messages to an outside address, then quietly leaves. From that point on, they can study invoices, customer emails, and payment patterns.

They may wait weeks before making their move. That is how business email compromise happens. A criminal watches a real conversation, then jumps in at the right time with fake banking instructions, a changed invoice, or an urgent request from someone who appears to be the owner or manager.

By the time anyone notices, the money may already be gone. So what should you do?

First, use multi-factor authentication on every email account. Not just the owner. Not just the office manager. Everyone. Email is the front door to your business, and one unprotected account is enough to create a serious problem.

Second, use strong, unique passwords and a password manager. Reusing the same password across personal and business accounts is asking for trouble.

Third, review email forwarding rules and login activity regularly. Strange logins, unexpected reset messages, missing emails, or messages in the sent folder that no one remembers sending are all warning signs.

Fourth, train your staff to slow down. Criminals rely on rushing people. A payment change, password alert, or “urgent” document should always be verified through a second channel.

Finally, ask your IT provider for proof. Are all users protected by MFA? Are suspicious logins monitored? Are old accounts removed quickly when employees leave? Are email rules being checked?

Email attacks do not always require a stolen password. Sometimes they only require one missed setting, one rushed click, or one account no one is watching.

The good news is that most of this risk can be reduced with practical, proven controls. Not scare tactics. Just the basics done consistently. And in cybersecurity, the basics done well still matter.

Where Are Your Cloud Files Really Going?

June 22, 2026

When people talk about “moving to the cloud,” it can sound like a single decision. But there are a few different ways to do it. The right choice depends on how your business works.

At its simplest, cloud storage means your data isn’t stored on a single computer or server in your office.

Instead, it’s stored in secure data centers run by providers (like Microsoft) and accessed over the Internet.

That’s what allows you to open files from anywhere, share them instantly, and collaborate in real time.

But not all cloud setups are the same. The most common approach is what’s known as the public cloud.

This is where your data is stored on shared infrastructure managed by a provider. Tools like Microsoft 365 and OneDrive fall into this category.

You’re effectively renting space in a highly secure, always-available environment without needing to maintain any hardware yourself.

At the other end of the spectrum is private cloud. This is where the infrastructure is dedicated to your business, either hosted on-site or in a data center.

It offers more control and can be useful for organizations with specific security or compliance requirements. But it also comes with more responsibility and cost.

Some businesses sit somewhere in the middle with a hybrid setup.

That might mean everyday files and collaboration tools live in the public cloud while more sensitive systems or data are kept in a private environment. It gives you flexibility to balance accessibility, control, and risk.

Whichever route you take, the benefits tend to be similar:

  • Your team can access what they need from anywhere
  • You can scale storage up or down without buying new equipment
  • And your data is protected by enterprise-grade security, including encryption and multiple backups across different locations

The important thing is that “the cloud” isn’t a one-size-fits-all solution.

The way it’s set up should reflect how your business operates, what data you handle, and how your team works day to day.

If you’re not sure whether your current setup is right, or you’d like a clearer picture of the options available, we can help. Get in touch.

Everyone’s Talking About AI, But What Are The Risks?

June 22, 2026

Do you ever get the sense that AI is showing up everywhere these days? It feels like every email, every meeting, and every industry headline is pushing the same message: adopt it now or get left behind.

Business owners and team leaders see it clearly. New tools pop up weekly, each one promising to cut hours off routine tasks, streamline operations, and free up people for more important work.

And in many cases, they deliver on those promises. Simple things like drafting reports, analyzing spreadsheets, or handling customer queries suddenly take a fraction of the time they used to.

But alongside the enthusiasm, a quieter conversation keeps surfacing in boardrooms and break rooms alike. What are we actually risking here?

Most leaders already recognize that rushing in without thinking carries real downsides. Still, the fear of watching competitors pull ahead often wins out. No one wants to be the cautious one who falls behind.

This pressure creates a tricky spot. AI systems are growing more capable by the month, and some are starting to act with surprising independence.

You have probably come across the term AI agent by now. These are not just chatbots that answer questions. They can perform real actions: pulling files, sending emails, updating records, or connecting with other programs on your behalf.

That kind of access is exactly where things get complicated. Once an AI tool is inside your systems, it sees the same information your employees do. Customer details, financial records, strategic plans.

Without tight boundaries in place, there is a genuine chance that sensitive data slips out in ways no one intended. The tool might follow instructions too closely, or it might get fooled by a carefully worded request from someone outside the company.

These deceptive inputs, often called malicious prompts, can be as straightforward as a phishing-style message that tricks the AI into revealing information or taking unwanted actions. It does not require sophisticated hacking – just someone who knows how to phrase things cleverly.

Then there is the growing problem of visibility. Different departments often test out their own AI solutions. Some get official approval.

Many do not. Over time, this patchwork of usage turns into what people call shadow AI. No central record exists of which tools are active, what data they are handling, or where that data ends up. It becomes almost impossible to track.

On top of everything else, the technology moves faster than most companies can update their policies or security practices.

What seemed safe six months ago might carry new vulnerabilities today. Organizations find themselves trying to hit a moving target.

None of this means businesses should step away from AI altogether. The potential gains are too significant to ignore. The smarter path is to bring some order to the process.

Start by selecting a few approved platforms that meet your security standards. Create straightforward guidelines about what data can and cannot be entered into these tools.

Assign clear responsibility to someone – whether it is a dedicated team or an existing manager – to keep an eye on AI usage across the organization.

Regular check-ins and simple training sessions can go a long way toward keeping everyone on the same page. The goal is not to slow things down unnecessarily, but to move forward without unnecessary exposure.

If your company is navigating these decisions and you would like a straightforward conversation about what makes sense for your situation, feel free to reach out.

We have helped plenty of businesses find a balanced approach that captures the benefits while keeping risks in check.

Why Human Habits Are Your Biggest Security Risk

June 22, 2026

Most cyberattacks do not start with a sophisticated intrusion. They start with a click on a personal email, a reused password, or a file uploaded to a familiar cloud service because the approved option felt slower.

The Verizon Data Breach Investigations Report found that 68% of breaches involve the human element.

Not a zero-day exploit or a brute-force attack on a hardened system. Human behavior, in the course of an ordinary working day.

For businesses running cloud-based workflows across multiple devices, the personal and professional overlap is now the rule. Understanding where that overlap creates risk is no longer optional. It is a core part of modern security strategy.

How personal web habits create business exposure

Personal channels are phishing’s preferred territory. Personal inboxes, messaging platforms, and social media feeds are where phishing thrives.

These environments are harder to filter, easier to spoof, and loaded with the emotional triggers that make people act before they think.

When those channels share a device or browser with business systems, a single click can cross the boundary instantly.

Phishing is the most common entry method for attackers precisely because it exploits distraction rather than technical weakness. The target does not need to be careless. They just need to be busy.

Password reuse is one of the most direct connections between personal and professional exposure.

When credentials from a personal account are compromised, attackers run them against business systems automatically. This technique, credential stuffing, is low-effort and highly effective because so many people use the same password across multiple accounts.

Unique credentials for every account, combined with multi-factor authentication, break that chain.

A personal breach has nowhere to go when the work account requires a second factor that the attacker cannot relay.

Why blocking behavior doesn’t work

The instinct is to lock things down: block personal apps, restrict browsing, enforce strict device policies.

In practice, blanket restrictions rarely stop the behavior. They relocate it. Users find workarounds.

Unapproved tools move to personal devices. IT teams lose visibility into exactly the activity they were trying to manage.

The risk does not disappear. It moves somewhere harder to see. Security strategies that assume perfect compliance perform poorly in real workplaces.

The goal is not eliminating the overlap between personal and professional digital activity. It is managing it without breaking how people work.

What actually reduces risk

The controls that work are the ones that match how people actually operate.

Separate contexts, not people

The simplest way to reduce crossover risk is to reduce crossover.

Separate browser profiles for work and personal activity, provide clear guidance on where business accounts should be accessed, and identified boundaries that prevent accidental mixing all reduce exposure without restricting what people do with their time.

Design for credential failure

Assume passwords will eventually be exposed somewhere. Design for that outcome rather than hoping to prevent it. CISA reports that enabling multi-factor authentication makes accounts 99% less likely to be compromised, even when the underlying password has already been stolen.

Make secure behavior easier than unsafe behavior. Contact us or schedule a consultation to review current controls and identify where the most important gaps are.

Your Next Best Employee Probably Won’t Be Human

May 26, 2026

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

What would happen if your competitor could suddenly get twice as much work done… without hiring anyone new?

No extra desks, recruitment fees, or bigger payroll. Just more output.

That’s the shift we’re moving into.

You’ve probably heard people talk about AI and wondered what that means for a normal business like yours.

An AI worker isn’t a robot. It’s software that can think through tasks in a surprisingly human way.

It can read documents, write emails, summarize meetings, analyze numbers, draft proposals, create job descriptions, and even help write computer code.

If you’re using Microsoft 365, you’re already seeing early versions of this built into tools like Word, Outlook and Teams.

Right now, many SMBs are dabbling. Someone asks AI to tidy up an email. Someone else uses it to help write a report.

But the real advantage comes when a business is properly set up to use AI across the organization.

And this is where some companies are going to struggle.

AI tools work best when your data is organized and accessible. If your files are scattered across personal laptops, old servers, and mystery cloud apps no one remembers signing up for, AI can’t safely “see” the information it needs.

If your security is weak, giving AI deeper access could create risk.

Being ready for AI doesn’t mean being technical. It means having tidy systems, clear permissions (who can access what), strong security, and leadership that’s willing to adapt processes.

Because this isn’t a small improvement.

The people building these tools are predicting dramatic leaps forward very quickly. Tasks that currently take hours could shrink to minutes.

Research that once required days might happen in seconds.

When that becomes normal, businesses that can plug in AI workers smoothly will accelerate. Those that can’t will feel slower, more expensive, and less responsive.

And this isn’t about replacing your team. It’s about giving them superpowers.

And in the next few years, the businesses that win won’t necessarily be the biggest or the oldest. They’ll be the ones that were ready.

If you’d like to discuss how AI could benefit your business, get in touch.

Beware The Next Generation Of Phishing Attacks

May 26, 2026

If phishing scams are supposed to trick people, why do so many of them still feel clumsy?

For years, the answer was simple: Most scams were mass-produced.

The same email, the same fake website, sent to thousands of people and hoping a few would fall for it.

That approach is still around, but it’s starting to evolve.

When generative AI first appeared, there was a lot of talk about “dynamic websites.”

Instead of one fixed site for everyone, pages would be generated on the spot, shaped by who you are, where you are, and what device you’re using.

That future never really arrived for everyday businesses. It was complex and rarely worth the effort.

Cybercriminals, however, don’t need perfect systems.

They need something convincing.

Security researchers have shown how this idea could be used for phishing. While it’s still largely experimental, it gives a clear picture of the next generation of scams.

A victim clicks a link and lands on a webpage that looks harmless. There’s no obvious malicious code sitting on the page.

Once it loads, the page asks a legitimate AI service to help generate content.

That content is then assembled and run directly in the person’s browser.

The result is a phishing page that’s created especially for that visitor.

The wording, layout, and code can all be different every time. There’s no single fake website for security systems to spot and block – because the scam doesn’t fully exist until someone opens it.

Before you panic, this method isn’t widespread yet. But the building blocks are in use.

AI is being used to write malicious code, malware is increasingly assembled as it runs, and AI-assisted scams are becoming more common.

For you, this changes the rules slightly.

Phishing is no longer just about spotting bad spelling or sloppy design.

Future scams may look even more polished, personalized, and completely legitimate. Some will appear to come from legitimate senders.

That’s why modern protection focuses less on “don’t ever click the wrong thing” and more on limiting the damage if someone does.

Tools like multi-factor authentication, secure browsers, and email filtering still work, even when a fake page looks convincing.

Remember this: phishing isn’t going away.

To stay protected now, you must assume the next scam will look professional and make sure your defenses don’t rely on people spotting obvious mistakes.

Next Page »

Primary Sidebar

Browse past issues

  • 2026 Issues
  • 2025 Issues
  • 2024 Issues
  • 2023 issues
  • 2022 Issues
  • 2021 Issues
  • 2020 Issues
  • 2019 Issues
  • 2018 Issues
  • 2017 Issues
  • 2016 Issues
  • 2015 Issues
  • 2014 Issues
  • 2013 Issues
  • 2012 Issues
  • 2011 Issues
  • 2010 Issues
  • 2009 Issues
  • 2008 Issues
  • 2007 Issues
  • 2006 Issues

More to See

Those Little Jobs Add Up… Delegate Them To AI

July 21, 2026

The 4-Step Legacy IT Debt Audit Your Business Needs

July 21, 2026

The Hidden Cost Of “Just This One Time”

July 21, 2026

Can Someone Hack Your Email Without The Password?

June 22, 2026

Tags

AI Antivirus backups Cloud Computing Cloud Storage COVID-19 cyberattacks cybersecurity Data Management Disaster Planning Disaster Recovery E-Mail Facebook Firewalls Hard Drives Internet Laptops Maintenance Malware Managed Services Marketing Microsoft Network online security Passwords password security Phishing planning Productivity Ransomware remote work Security Servers smart phones Social Media Tech Tips Upgrading Viruses vulnerabilities Websites Windows Windows 7 Windows 10 Windows Updates work from home

Copyright © 2026 Tech Experts™ · Tech Experts™ is a registered trademark of Tech Support Inc.