<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Kryptek Insights</title>
    <link>https://www.kryptek.ai/blog</link>
    <description>Practical cybersecurity guidance for small and midsized businesses — ransomware, phishing, managed security, and compliance, explained in plain terms.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 09 Sep 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://www.kryptek.ai/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Who Is Allowed to Reset a Password? The Help Desk Rule Most Companies Never Wrote Down</title>
      <link>https://www.kryptek.ai/blog/help-desk-identity-verification-account-recovery-vishing</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/help-desk-identity-verification-account-recovery-vishing</guid>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <description>Voice phishing is now one of the most common ways attackers get into business environments, and the target is not your login screen. It is the account recovery call, where authentication is suspended by design and a person decides whether to believe the caller.</description>
    </item>
    <item>
      <title>The Wire Is Already Gone: Why BEC Losses Are Decided by Your Approval Rules, Not Your Email Filter</title>
      <link>https://www.kryptek.ai/blog/bec-payment-approval-controls-first-hour-response</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/bec-payment-approval-controls-first-hour-response</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <description>Business email compromise now accounts for more successful attacks than ransomware, and the average loss has nearly doubled since 2019. The controls that actually stop the money are a payment approval rule and a plan for the first hour.</description>
    </item>
    <item>
      <title>The Firewall Nobody Has Logged Into Since Install Is Now the Most Likely Way In</title>
      <link>https://www.kryptek.ai/blog/vulnerability-exploitation-overtakes-credentials-patch-ownership</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/vulnerability-exploitation-overtakes-credentials-patch-ownership</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <description>Verizon's 2026 breach report found that exploiting unpatched internet-facing equipment has passed stolen credentials as the top way attackers get in. Here is how a company with no security team decides who owns patching and how fast it happens.</description>
    </item>
    <item>
      <title>Not All MFA Counts Anymore, and Your Insurer Knows the Difference</title>
      <link>https://www.kryptek.ai/blog/phishing-resistant-mfa-admin-vpn-accounts</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/phishing-resistant-mfa-admin-vpn-accounts</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>The text-message codes and push prompts you rolled out still work fine for most staff logins, but carriers and attackers now treat admin, VPN, and email-administration accounts differently. Here is how to upgrade the handful of logins that matter.</description>
    </item>
    <item>
      <title>The Cyber Insurance Questionnaire You Signed Is a Promise, Not a Survey</title>
      <link>https://www.kryptek.ai/blog/cyber-insurance-attestation-patching-evidence</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/cyber-insurance-attestation-patching-evidence</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description>Carriers now verify what you attested to, and unpatched internet-facing equipment is the easiest way to break a promise you did not realize you made. Here is how to answer the renewal questionnaire from evidence instead of memory.</description>
    </item>
    <item>
      <title>Ransomware Crews Do Not Stumble Onto Your Company. They Shop For It.</title>
      <link>https://www.kryptek.ai/blog/how-ransomware-crews-pick-mid-sized-targets</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/how-ransomware-crews-pick-mid-sized-targets</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>New research found that mid-sized companies account for 73 percent of publicly disclosed ransomware and extortion incidents, and more than half of those victims earn under 50 million dollars a year. Here is what your company is broadcasting to the people doing the shopping.</description>
    </item>
    <item>
      <title>The Riskiest Email Your Business Will Get This Year Comes From Your Vendor's Real Mailbox</title>
      <link>https://www.kryptek.ai/blog/vendor-payment-change-fraud-callback-rule</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/vendor-payment-change-fraud-callback-rule</guid>
      <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
      <description>Business email compromise and funds transfer fraud now make up the majority of cyber insurance claims. The two controls that actually work are a callback rule owned by finance and a rehearsed 24 to 72 hour recovery drill.</description>
    </item>
    <item>
      <title>The Two Things That Decide Whether Ransomware Is a Bad Week or the End of Your Company</title>
      <link>https://www.kryptek.ai/blog/edge-appliance-patching-immutable-backups-ransomware</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/edge-appliance-patching-immutable-backups-ransomware</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Attackers have shifted from stolen passwords to unpatched internet-facing appliances, and they now delete backups before they encrypt anything. Here is what that changes for a company without a security team.</description>
    </item>
    <item>
      <title>You Turned On MFA and Attackers Are Still Logging In as Your Staff</title>
      <link>https://www.kryptek.ai/blog/mfa-bypass-session-hijacking-account-takeover</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/mfa-bypass-session-hijacking-account-takeover</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <description>Multi-factor authentication has become table stakes rather than protection, because attackers now steal the session after a legitimate login succeeds. Here is what a company without a security team should change first.</description>
    </item>
    <item>
      <title>The Apps Your Employees Connected to Microsoft 365 and Nobody Ever Reviewed</title>
      <link>https://www.kryptek.ai/blog/connected-apps-microsoft-365-google-workspace-audit</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/connected-apps-microsoft-365-google-workspace-audit</guid>
      <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
      <description>Over the years, your staff has quietly granted dozens of third-party apps standing access to company email and files. Here is how to pull that list yourself and clean it up in about thirty minutes.</description>
    </item>
    <item>
      <title>What a Managed Security Service Actually Does All Day</title>
      <link>https://www.kryptek.ai/blog/what-a-managed-security-service-actually-does</link>
      <guid isPermaLink="true">https://www.kryptek.ai/blog/what-a-managed-security-service-actually-does</guid>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <description>Most small and midsized businesses buy security tools before they have anyone to run them. Here's what the day-to-day work of managed security looks like, and why the monitoring matters more than the software.</description>
    </item>
  </channel>
</rss>
