Cloud-hosted security vendors upgrade on their own schedule — your configuration doesn’t always survive the transition. A Fortinet EMS incident this week shows what proactive managed security monitoring looks like when it matters most.
Risk Management
Who Is Checking the AI’s Work?
AI can write code faster than any developer. The question is whether anyone is checking what it actually produced — and whether it is secure, not just functional. Si Futures ran penetration tests against their own services to find out.
The 6am Call: Why Verification Is Your Most Important Security Control
What happens when the 6am standby call sounds completely legitimate — but something still feels wrong? Nicholas Broderick on the verification process that protects MSP engineers and clients when AI voice cloning makes impersonation almost indistinguishable from the real thing.
The Microsoft Change That Will Break Your Office 365 Backups
Microsoft is retiring Exchange Web Services in October 2026 — a backend change that will silently break backup tools, archiving solutions, and integrations still relying on EWS. Find out if your Microsoft 365 backup is at risk and what to do before the deadline.
Your Business Domain: Who Actually Owns It?
Domain security sits in a gap most businesses have never audited. If a contractor registered your domain years ago and the relationship has since ended, you may not control one of the most critical pieces of your infrastructure — including all your business email. This piece explains what that exposure looks like and what to check before it becomes a crisis.
When a Personal Device Becomes a Business Risk
A personal device signs into a work email account. That device is already compromised. Before the morning is out, spoofed payment requests have gone to suppliers with changed banking details. This piece examines how personal device security sits outside the perimeter most SMEs actively protect — and what rapid account compromise detection looks like when it works.
Why VPN and MFA Are No Longer Enough
VPN and MFA are good controls — but attackers have adapted their techniques to work around both. Si Futures explains adversary-in-the-middle attacks, MFA fatigue, and why managed threat detection is the next essential layer for any serious security posture.
When the Carrier Has Problems: The Client Conversation That Can’t Wait
When an IT partner spots early signs that a connectivity carrier is under financial stress, what should they do with that information? Geordie Hogarth argues that the instinct to wait is both understandable and wrong — and that the obligation to raise difficult supply chain conversations before clients are forced to react is one of the clearest tests of whether an IT partnership is genuinely embedded.
Who Owns Compliance When You Leave Microsoft’s Umbrella?
Cloud compliance doesn’t transfer automatically when you move data off Microsoft 365. Si Futures’ Security and Compliance Specialist Sean Rogers examines who owns accountability when you self-host — and the seven questions every business should ask their IT provider.
