North Bay Computer

North Bay Computer

Share

North Bay Computer - Santa Rosa managed IT Technical Services, managed Cloud backup, networking & server design, installation & managed maintenance.

08/21/2026

If your team is juggling a different password for every app they use, there's a simpler setup, and you might already be paying for it.

It's called single sign-on. Everyone logs in once, through one secure account, and that gets them into all their work apps without a separate password for each.

It's also safer. Everything runs through one account, so when someone leaves, you switch off that one login and they're locked out of everything at once. No more trying to remember every app they ever touched. You also turn on MFA once, in that one place, instead of hoping it's switched on in every app separately.

Microsoft 365 and Google Workspace both come with single sign-on built in, so there's a good chance you already own it. Most of the apps your team uses can hook into it.

Ask your IT provider what it'd take to get your main apps running through it. Fewer passwords floating around means fewer chances for one to leak.

08/20/2026

Those little add-ons in your web browser, the ad blockers, the coupon finders, the thing that changes your new tab page, can read pretty much everything you do online. That includes passwords and customer info. Most people install one and forget it's even there.

A lot of them are fine. But some are built to grab your data, and others start out useful, get sold to a new owner, then push out a sketchy update to everyone who already has them.

Check what's installed:
In Chrome or Edge, type chrome://extensions into the address bar.
Delete anything you don't recognize or haven't used in ages.
For the ones you keep, click "Details" and see what they're allowed to do. A simple tool shouldn't need access to everything on every site.

Going forward, make it a team habit: if someone wants a new extension, IT takes a quick look first. Most people can't tell a safe one from a bad one, so take that guess off their plate.

08/19/2026

Microsoft put out its June updates and fixed around 200 security holes. A few of them were already being used by attackers before the patch even landed.
One let someone holding your laptop get past BitLocker, the encryption that's supposed to keep a stolen laptop locked. Another could knock a server offline. The fixes are out.

Most businesses don't install these updates for weeks, and that delay is exactly when attackers strike.

Do this:
▶️ Check that your computers install Windows updates on their own, instead of waiting for someone to keep clicking "later."
▶️ Ask whoever handles your IT how fast they roll these monthly updates out. And don't forget the machines nobody thinks about: the spare laptop, the front desk PC, the server in the closet.

One machine left behind is all it takes.


https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws

08/18/2026

Microsoft 365 and Google Workspace come with security settings switched off by default, and most small businesses never turn them on.

These are already included in what you pay for, and they close some of the most common ways attackers get in. Ask your IT provider to confirm each of these is in place:
✅ Legacy authentication is blocked. Old sign-in methods skip MFA entirely, and attackers rely on them. Turning legacy auth off forces every login through modern, MFA-protected sign-in.
✅ Audit logging is on. This is the record of who did what and when. Without it, you have no way to see what happened after something goes wrong.
✅ External sharing and forwarding are controlled. Limit who can share files outside the company, and block automatic email forwarding to outside addresses.
✅ MFA is enforced for everyone, not just admins. A single account without it is the gap an attacker needs.

You don't have to change these yourself. Just ask your IT provider and get a clear answer on each one. "I think so" isn't the same as "yes, confirmed."

08/17/2026

The once-a-year security training most businesses run does almost nothing, because people forget it within weeks and the threats keep changing.

Training works when it's small, frequent, and tied to real examples. A 5-minute reminder once a month sticks far better than a 60-minute session once a year. And it lands harder when it uses the scams hitting businesses, like the fake "paste this command" prompts or the AI voice calls impersonating the boss.

Good training also makes it safe to report mistakes. If an employee clicks something and worries they'll get in trouble, they'll keep it to themselves, and that silence is how a small problem becomes a breach. Tell your team plainly that reporting a click the moment it happens means no blame. That's how you catch most attacks early.

You don't have to build this yourself. Ask your IT provider what ongoing awareness training they offer, and whether it includes short, regular refreshers and simulated phishing tests. If your current setup is one slideshow a year, that's the thing to fix.

08/16/2026

Two members of the hacking group Scattered Spider pleaded guilty in the UK.
They’re behind some of the largest corporate breaches of recent years.

The pair, aged 18 and 20, admitted to the 2024 cyberattack that disrupted Transport for London. Sentencing is scheduled for mid-July 2026
They get in the low-tech way, by calling employees and IT help desks, sounding convincing, and talking their way past security.

That approach works just as well on a 30-person company as it does on a global one.

Train your team to verify who they're talking to before acting on any request. Anyone asking for a password reset, system access, or an urgent payment should be confirmed through a known, separate channel first.


https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial

08/15/2026

Your team connects to wifi at hotels, airports, and cafes without thinking about it. When that network has no password, or a password posted on the wall for everyone, the traffic between their laptop and the network isn't private.

Someone else on the same network can potentially capture what's being sent, or set up a fake "Airport Free WiFi" hotspot that routes everything through their own machine.

Do this:
▶️ Use a VPN on any device that connects to public wifi. It scrambles the connection so anyone snooping sees gibberish. Most password managers and security suites include one, or your IT provider can set it up.
▶️ Better yet, skip public wifi for anything sensitive and use your phone's hotspot instead. A mobile connection is much harder to tamper with.
▶️ Turn off "auto-connect to open networks" on company phones and laptops, so devices don't join random hotspots on their own.

Most websites encrypt their own traffic now, so this is less risky than it used to be. But a VPN protects everything on the device, so it's worth setting up for anyone who travels for work.

08/14/2026

Think about everyone outside your company who has a login to your systems: the web developer from two years ago, the marketing freelancer, the bookkeeper who left in March. A lot of those accounts are probably still active.
These accounts are easy to forget because the people aren't your employees. But each one is a way into your business, and you have no idea how well that person guards their password.

Do this:
1. List every outside person and company with a login to your email, files, website, accounting, or any business system.
2. For each one, decide whether they still need it and when they last used it.
3. Turn off anything that's no longer needed, and ask your IT provider to set a reminder to review this again in six months.

For the access you keep, give each outside party their own named login, never a shared one. If something goes wrong, you'll want to know exactly whose account it was.

08/13/2026

A company called Klue got breached in June 2026, and dozens of other businesses lost customer data because of it, including LastPass and BeyondTrust.

Klue makes a tool that connects to Salesforce. To use it, businesses gave Klue a digital access pass (called an OAuth token) that lets it reach their Salesforce data without a password. A group calling itself Icarus got into Klue, stole those access passes, and used them to pull customer records out of every connected Salesforce account.

This is the risk with every app you connect to your email, CRM, or file storage. You're handing it a key to your data, and if that app gets breached, your data goes with it.

What to do:
▶️ In your Salesforce, Microsoft 365, and Google accounts, review the list of connected apps and third-party integrations.
▶️ Remove anything you don't recognize or no longer use.
▶️ For the apps you keep, check what access each one needs. Many ask for far more than they use.

The accounts that hold your customer list are worth this 20-minute review. A forgotten app connection is exactly how this kind of breach starts.

08/12/2026

Someone calls your IT support and says they're an employee who's locked out of their account. They sound friendly, a bit rushed, and they know a few details about the company, so the request seems legit. But it's an attacker, and this is how some of the biggest breaches of the last few years began.

They act like a stressed-out colleague and talk your IT person into resetting a password or MFA. Now they're in.

Add one verification step before any reset, every time:
▶️ Call the employee back on the number already in your records, not a number the caller gives you.
▶️ Or have a manager confirm the request through a separate channel.
▶️ Or use a pre-agreed code or question that only a real employee would know.

Make it a hard rule for whoever runs your IT: no password or MFA reset on a phone call alone. Verifying takes 30 seconds and stops the attack.

Want your business to be the top-listed Computer & Electronics Service in Santa Rosa?
Click here to claim your Sponsored Listing.

Telephone

Address


2444 San Pedro Drive
Santa Rosa, CA
95401

Opening Hours

Monday 9am - 6pm
Tuesday 9am - 6pm
Wednesday 9am - 6pm
Thursday 9am - 6pm
Friday 9am - 6pm