A blocked malware site in DefensX becomes a SuperOps ticket within five minutes, with no technician watching a dashboard.
As our business continues to grow our focus is on providing white labeled Tier 3 IT support services, RMM as a service, and co-managed IT services. This blog will be highlighting tips for using an n8n workflow to watch a DefensX global URL group and open a SuperOps ticket whenever a client machine tries to reach a site on it. We keep a global malware list in DefensX that applies to every customer. A block on that list is not routine web filtering. It means something on that machine tried to reach a known bad destination, and we want a technician looking at it in minutes, not at the next report review.
Research
DefensX has a Partner API with log endpoints for every customer, and SuperOps has a GraphQL API that can create tickets. The plan was simple: poll DefensX, find blocks from our list, create a ticket for the right client. Getting there took more discovery than expected. Here is what we ran into:
There is no webhook, and the logs don’t say which group caused the block. The URL log gives you the URL, the action and a category, but not the URL group that matched. The workflow has to pull the group’s entries itself and do the matching. That means handling all three entry styles DefensX allows: exact hostnames, *.domain.com wildcards, and full URLs with a path.
Browser logs are only half the picture. Our first test was a curl from a command prompt, and it never appeared in the URL logs. The browser extension only sees browser traffic. Anything else, including scripts and processes running as SYSTEM, is caught by the agent and written to the DNS logs. Since malware rarely uses the browser, the workflow checks both endpoints for every customer.
DNS logs are large. One customer returned more than 5,700 DNS rows in a 20-minute window, which is over the 5,000-row page limit. Pagination is not optional.
SuperOps required a field the schema calls optional. Our first ticket failed with mandatory_validation_failed on requestType, even though introspection shows it as a plain optional string. The tenant enforces it.
The next error named a field we never sent. After adding requestType: "Incident", SuperOps answered with referred_value_does_not_exist on ticketType. The field was renamed at some point and the error still uses the old name. The real problem was the value: ticket types are customizable per tenant, and ours has no type called “Incident”. It has “Incident – Security”.
Our API token could not look up the answer. We tried reading the type from existing tickets. The list query returned a total count of 429 and zero rows, and single-ticket lookups returned forbidden. The token could create tickets but not read them. What finally explained everything was asking the schema for field descriptions, not just field types. The description for requestType states that it replaced ticketType and tells you which query lists the valid options.
Repeat hits would flood the board. A machine retrying a blocked connection every few seconds would create a ticket on every run. The workflow remembers each user and site pair for 24 hours and tickets it once. It also keeps a separate time cursor per customer, so a failed API call for one customer is retried from where it left off without holding up the others.
Variables
Everything you need to change lives in one Set node at the top of the workflow:
urlGroupName – the exact name of the DefensX URL group to watch, for example Global Malware List
groupOwnerCustomerId – leave blank if the group lives on your partner account; otherwise the ID of the customer that owns it
suppressHours – how long to stay quiet about the same user and site after a ticket is created (default 24)
overlapMinutes – how far each run reaches back past the last one, to catch logs that arrive late (default 5)
includeConsented – whether to report blocks the user clicked through (default true)
defangUrls – writes sites as example[.]com in the ticket so nobody clicks one by accident (default true)
superopsSubdomain – your SuperOps subdomain, sent as the CustomerSubDomain header
ticketRequestType – one of your own ticket type names, spelled exactly as it appears in SuperOps
fallbackSuperOpsAccountId – the client that receives the ticket when a DefensX customer name has no match in SuperOps
customerNameMap – optional JSON for customers whose names differ between the two systems
API keys go in n8n credentials, never in the workflow itself.
Script Snippet
The matching logic runs in a Code node. Wildcard entries match the domain and every subdomain, and path entries are only checked against URL logs because a DNS lookup has no path:
function findEntry(target, hasPath) {
for (const e of ctx.entries) {
const hostOk = e.wildcard
? (target.host === e.host || target.host.endsWith('.' + e.host))
: target.host === e.host;
if (!hostOk) continue;
if (!e.path) return e;
if (hasPath && (target.path === e.path || target.path.startsWith(e.path + '/'))) return e;
}
return null;
}
Both log endpoints use the same pagination settings on the HTTP Request node:
Each ticket lands on the matching SuperOps client with a table showing the time, user, device, site, number of blocks and whether it came from the browser or the agent. Query strings are stripped from URLs before they are written, so session tokens never end up in a ticket.
The complete workflow, with the customer loop, DNS and URL log handling, SuperOps client matching and duplicate suppression, is free on our GitHub: [GITHUB LINK]
If your company is a MSP or wants to become one and automation just seems out of reach, then contact us to run your RMM for you.
Why “nobody wants our data” is one of the most expensive sentences a small business owner can say
Automated cyber attacks don’t check your company size. They look for the easiest open door.
Welcome to How to Get Breached, our weekly guide for business owners who want to make a cybercriminal’s job as easy as possible. Step one is a classic, and it costs nothing to adopt. Just decide that hackers only go after banks, big retailers, and national brands. Not a 20-person company with a modest office and a coffee maker that leaks. Once you believe that, you can skip the security budget, the complaints about multi-factor authentication, and the backup testing. Attackers appreciate the cooperation.
For everyone who would rather not get breached, here’s why this advice backfires.
Attackers Don’t Check Your Size First
Most cyberattacks are automated. Bots scan the internet around the clock for exposed remote access, unpatched firewalls, and email accounts with weak or reused passwords. They don’t look up your revenue before they knock. They look for an open door.
We see this firsthand. The security monitoring we run for our clients records automated login attempts and scans every day against organizations of every size, including small offices most people would assume nobody cares about.
Small Means Easier, Not Safer
Small businesses often have fewer defenses: no dedicated security staff, older equipment, and shared passwords that never get changed. Attackers know this. Verizon’s 2025 Data Breach Investigations Report found ransomware in 88% of breaches at small and mid-sized businesses, compared with 39% at large organizations.
Your business is also a doorway to other people. Your email account can be used to send fake invoices to your customers. Your vendor relationships and bank accounts are worth something to a criminal even if your customer list isn’t.
A Hypothetical Scenario
Picture a fictional 15-person distribution company. The office manager uses the same password for work email as for a shopping site that was breached years ago. There’s no multi-factor authentication. An attacker logs in quietly, watches email for two weeks, then sends a few customers a polite note with “updated” bank details. Nobody notices until payments stop arriving. No advanced hacking was needed. The door was simply unlocked.
Practical Action Steps for Owners and IT
Turn on multi-factor authentication (MFA) for email, remote access, banking, and every cloud app, starting with email.
Patch operating systems, firewalls, and VPNs on a schedule, and replace equipment that no longer receives security updates.
Close exposed remote access. Remote desktop should never face the open internet.
Keep backups with at least one copy offline or immutable, and test a full restore at least quarterly.
Put security monitoring in place so someone reviews suspicious activity around the clock, not just during business hours.
Train staff to spot phishing, and require a phone call to a known number before changing any payment details.
Write a one-page incident response plan listing who to call first: your IT provider, your cyber insurer, and legal counsel.
Review your cyber insurance requirements. Many carriers now require MFA and tested backups before they’ll pay a claim.
Questions Your Customers May Ask You
Is my information safe with you? A strong answer explains what you actually do: MFA, monitored systems, tested backups, and staff training.
Why do you call me to confirm payment changes? Because fake invoice emails are one of the most common scams, and a quick call stops them.
What happens if you get hit by ransomware? You should be able to say that you have tested backups and a plan to restore operations quickly.
Would you tell me if my data were exposed? Yes. Explain that you have a response plan that includes timely notification.
How Farmhouse Networking Can Help
Farmhouse Networking helps small and mid-sized businesses close the gaps attackers count on. We provide 24/7 security monitoring, manage MFA, patching, and backups so they stay current, run staff security awareness training, and support compliance requirements specific to your industry. Our team is 100% U.S.-based, and when you call, a real person answers.
Find Out Where You Stand
You don’t need to guess whether your business is an easy target. Email support@farmhousenetworking.com to schedule a free breach-readiness review. We’ll show you where your gaps are and what to fix first, in plain language.
Next week: How to Get Breached, Step 2: Use the Same Password Everywhere.
Duo authentication and admin activity logs flowing into a self-hosted Wazuh SIEM, ready for MFA monitoring and CMMC audit evidence.
As our business continues to grow our focus is on providing white labeled Tier 3 IT support services, RMM as a service, and co-managed IT services. This blog will be highlighting tips for using a Bash script to forward Cisco Duo MFA logs into a self-hosted Wazuh SIEM.
We recently connected Duo to the onsite Wazuh server of a client working toward CMMC Level 2. Logging every MFA event and every admin change is part of the evidence an assessor wants to see (NIST 800-171 controls 3.3.1 and 3.5.3). Duo ships an official tool for exactly this. Getting it to produce real Wazuh alerts took some work, so we turned everything we learned into one script that you can run by hand or from SuperOps RMM.
Research
Duo publishes DuoLogSync (github.com/duosecurity/duo_log_sync), a small Python service that pulls logs from the Duo Admin API and sends them as JSON over TCP. The plan was simple: run DuoLogSync on the Wazuh manager, send its output to a syslog listener that only accepts local connections, and let Wazuh’s built-in JSON decoder do the rest. No agent, no public port, no custom decoder.
In practice, five things got in the way. They aren’t obvious from the documentation:
Stock Wazuh rule 86600 (Suricata) matches any JSON event that has both “timestamp” and “event_type” fields. Duo auth logs have both, so every event was captured by a level 0 rule and silently thrown away. Our rules now hang under 86600 as child rules.
Wazuh loads every rule file, stock and custom together, in alphabetical order. Naming the file 9999_duo_rules.xml makes sure it loads after the stock rules it depends on.
“action” is a reserved Wazuh field name, so a field match on it stops the whole ruleset from loading. Use the <action> tag or a dotted field like action.name instead.
DuoLogSync 2.4 retired the “adminaction” endpoint. Admin events now come from the “activity” log, which has a completely different JSON layout.
DuoLogSync opens one TCP connection and never reconnects. Every Wazuh manager restart quietly lost the next batch of logs. The fix is a systemd unit tied to the manager with PartOf=wazuh-manager.service.
The payoff showed up right away. The 180-day history pull surfaced twelve failed Active Directory syncs, all caused by a Duo Authentication Proxy outage. If an AD sync fails, a user you just disabled in AD can still pass Duo, so that’s a finding worth knowing about.
Variables
DuoIntegrationKey = The integration key of a Duo Admin API application with only “Grant read log” permission – i.e. DIXXXXXXXXXXXXXXXXXX DuoSecretKey = The secret key for that application (mark this as a secure variable in SuperOps) DuoApiHost = The API hostname from the same application – i.e. api-xxxxxxxx.duosecurity.com DuoEndpoints = Optional. Which Duo logs to pull – default auth,telephony,activity DuoOffsetDays = Optional. How many days of history to pull on the first run, maximum 180 DuoAction = Optional. install, status, resend or uninstall
Script Snippet
The full script handles prerequisite checks, backups, validation, automatic rollback, and a final check with wazuh-logtest. These are the core pieces:
# DuoLogSync config - single quotes are required by DLS
cat > /opt/duologsync/config.yml <<EOF
version: '1.0.0'
dls_settings:
log_format: 'JSON'
api:
offset: $DLS_OFFSET_DAYS
checkpointing:
enabled: True
directory: '/opt/duologsync/checkpoints'
servers:
- id: 'wazuh'
hostname: '127.0.0.1'
port: 5140
protocol: 'TCP'
account:
ikey: '$DUO_IKEY'
skey: '$DUO_SKEY'
hostname: '$DUO_API_HOST'
endpoint_server_mappings:
- endpoints: ['auth', 'telephony', 'activity']
server: 'wazuh'
EOF
# Local-only listener added to ossec.conf
<remote>
<connection>syslog</connection>
<port>5140</port>
<protocol>tcp</protocol>
<local_ip>127.0.0.1</local_ip>
<allowed-ips>127.0.0.1</allowed-ips>
</remote>
# Duo auth events are claimed by Suricata rule 86600 - attach under it
<rule id="120000" level="0">
<if_sid>86600</if_sid>
<field name="txid">\.+</field>
<field name="factor">\.+</field>
<description>Duo: authentication event</description>
</rule>
# systemd: restart with the manager, wait for the listener first
[Unit]
After=wazuh-manager.service
PartOf=wazuh-manager.service
[Service]
ExecStartPre=/bin/bash -c 'until ss -ltn | grep -q "127.0.0.1:5140 "; do sleep 2; done'
ExecStart=/opt/duologsync/venv/bin/duologsync /opt/duologsync/config.yml
Restart=always
The complete script, the SuperOps edition, and the full ruleset (with alerts for MFA fraud reports, MFA fatigue, admin panel brute force, Duo configuration changes and AD sync failures, all tagged for NIST 800-171) are free on our GitHub: https://github.com/FarmhouseNetworking/Duo-Wazuh-LogSync
If your company is a MSP or wants to become one and automation just seems out of reach, then contact us to run your RMM for you.
AI usage limits are now part of every business plan. Here is what happens when your team hits one, and how to keep company data from walking out the door with them.
When AI usage limits stop work, employees often switch to free AI tools. That is how shadow AI puts company data at risk.
It’s 3:40 on a Thursday. Your office manager is halfway through a customer proposal when the company AI assistant stops responding: usage limit reached, try again later. The deadline is 5:00. So she opens a free AI chatbot on her phone, pastes in the customer’s details, and finishes the job. The proposal goes out on time. The customer’s information now sits on a server you have never vetted, under terms nobody at your company has read.
That is the real risk behind AI token limits. The interruption is annoying. What your people do next can be expensive.
What Are AI Tokens and Why Do They Run Out?
Tokens are how AI tools measure work. A token is a small piece of text, often part of a word, and everything counts: the question, any file you attach, the running conversation history, and the answer. Business AI plans come with an allowance, whether the vendor calls it tokens, credits, or messages.
In 2026 those allowances are tighter and more closely metered. Vendors are moving away from flat, unlimited-feeling plans toward usage-based billing. Microsoft, for example, now bills some Copilot features in Copilot Credits with admin spending limits. At the same time, teams are using AI harder. AI agents that handle multi-step tasks, long chat threads, and large uploaded documents burn through tokens far faster than a quick question does.
What Happens When You Hit the Limit
Depending on the tool and plan, one of three things usually happens:
Work stops. New requests are blocked until the allowance resets or an admin raises it. One source reported one consultant waiting 13 hours for tokens to refresh.
The bill grows. Overage billing keeps things running, then shows up as a surprise on next month’s invoice.
People improvise. Employees switch to whatever AI tool they can reach, usually a free personal account.
That third outcome is called shadow AI: AI tools used for work without the company’s approval or oversight. Free consumer tools may retain what you paste in and, depending on settings, may use it to improve their models. IBM’s 2025 Cost of a Data Breach Report found that 63% of the breached organizations it studied had no AI governance policy, and that high levels of shadow AI added about $670,000 to the average cost of a breach.
Action Steps for Business Owners and IT
Inventory every AI tool in use. Ask staff what they use, including free and browser-based tools. IT should confirm with web traffic and application reports.
Standardize on business-grade plans. Choose approved tools with admin controls and contract terms that keep your data out of model training.
Right-size the allowance. Review usage reports monthly. Set spending caps and threshold alerts so IT hears about a limit before employees hit it.
Write an AI acceptable use policy. Spell out approved tools, data that must never be entered, and exactly what to do when a limit is reached.
Build a fast escalation path. If requesting more capacity takes a day, people will go around it. Make the safe option the easy option.
Restrict unapproved AI sites on company devices. Use web filtering and data loss prevention tools to block or flag sensitive data headed to unknown AI services.
Teach token-smart habits. Start a new chat for each new task, attach only the pages you need, and use lighter models for simple work.
Add AI to your continuity plan. List the workflows that depend on AI and document the manual fallback if the tool is unavailable.
Questions Your Customers May Ask
Do you put my information into AI tools? Only into tools we have approved and configured for business use, under agreements that keep your data out of model training. Our policy prohibits entering customer information into personal or free AI accounts.
What happens if an employee uses an unapproved AI app? Our systems restrict unapproved AI services on company devices, and our policy treats it as a security issue. We would investigate and respond just as we would to any other data concern.
If your AI tool goes down or hits a limit, will my project be delayed? No. AI helps our team work faster, but every AI-assisted process has a documented manual fallback.
Does a person check AI-generated work? Yes. A member of our team reviews anything AI helps produce before it reaches you.
How Farmhouse Networking Can Help
Most small businesses adopted AI one employee at a time, which means few owners know which tools are in use, what they cost, or where the data goes. Farmhouse Networking helps you take control without slowing your team down.
We start by identifying every AI tool touching your network, approved or not. From there we help you choose and configure business-grade accounts, set up usage alerts and spending controls, apply web filtering and data loss prevention to stop shadow AI, and write an acceptable use policy your staff will actually follow. We also train your team on efficient, secure AI habits and add AI dependencies to your continuity plan.
Our 100% U.S.-based team answers the phone live, and most issues are resolved in about 15 minutes, so a blocked tool never becomes an all-afternoon problem.
Get Your Free AI Acceptable Use Policy Template
Your employees are going to hit an AI limit. The only question is whether they have a safe path forward when it happens. Email support@farmhousenetworking.com with AI Policy in the subject line and we will send you our free AI Acceptable Use Policy template, ready to customize for your business.
What the growing patchwork of state laws means for your business, and how to track activity responsibly without eroding staff trust.
A clear, written policy is the starting point for legal, trust-friendly employee monitoring
More states are passing laws that require you to tell employees, in writing, when and how you’re monitoring their electronic activity. At the same time, insider incidents, whether malicious or just careless, remain one of the more expensive risks a small business can face. Those two facts point the same direction: employee activity monitoring is worth doing, but only if it’s built on a clear policy rather than software quietly running in the background. Handled well, it protects your business and your staff know exactly where they stand. Handled poorly, it’s a legal risk and a trust problem rolled into one.
Practical Steps to Take
Put a written monitoring and acceptable use policy in place before you turn on any tracking tool. Define what’s monitored, why, and who sees the reports.
Check your state’s specific requirements, and confirm with an employment attorney if you operate in more than one state. New York, Delaware, Connecticut, Illinois, and Colorado already require written notice or signed acknowledgment before monitoring electronic activity, and more states are following.
If you’re in Oregon, note that state law separately requires notifying everyone in a conversation before it’s recorded, which matters for call and video monitoring specifically. If you have employees or customers in California, remember that state privacy law now covers employee data too, so you need clear notice about what you collect and why.
Scope monitoring to company-owned devices and accounts. Personal phones and personal email should stay out of it unless your BYOD policy explicitly says otherwise.
Get signed acknowledgment from every employee, and update it when the policy changes.
Give your IT provider clear rules for who can see monitoring data, and keep that group small.
Set a schedule for reviewing logs and for deleting them. Don’t let data pile up indefinitely just because storage is cheap.
Revisit the whole policy at least once a year. Both the laws and the tools are changing quickly.
Questions Customers May Ask You
“Is it a red flag that your employees are being monitored? Should I trust this business less?” No, it’s the opposite. It means access to your information is tracked and controlled, not left to chance.
“How do you know an employee hasn’t misused my information?” Access to customer data is logged, and unusual activity, like someone accessing records outside their normal role, gets flagged rather than discovered later.
“Do your employees know they’re being monitored?” Yes. Every employee is given written notice and signs an acknowledgment. Transparency with staff is part of what makes the whole system work.
How Farmhouse Networking Can Help
Farmhouse Networking helps small and mid-sized businesses put together a written employee monitoring and acceptable use policy that matches what your state actually requires, then configures the access controls, activity logging, and secure retention to back it up. It’s part of our managed IT services, so you’re not left guessing whether your policy and your technology actually match, or whether either one would hold up if it were ever questioned.
Let’s Take a Look
If you don’t have a written employee monitoring policy, or you’re not sure your current one matches what your state requires, let’s fix that now. Email support@farmhousenetworking.com and we’ll review what you have and tell you plainly what’s missing.
Audit logs won’t stop an incident from happening. They’re what tells you exactly what happened, how bad it is, and how to move forward with confidence instead of guesswork.
Reviewing audit logs regularly helps small business owners catch problems early and respond with confidence.
An employee’s laptop gets stolen from their car. A phishing email lands and someone clicks it. A contractor’s access is never fully removed after the project ends. Any of these can turn into a genuine crisis, or a contained, well-understood incident, and the difference usually comes down to one unglamorous thing: whether your systems were keeping a record of who did what before anyone knew there was a problem.
Audit logs are the timestamped trail of activity across your network, systems, and accounts. Most small business owners never think about them until an incident forces the question: what actually happened here, and how far did it go? Without logs, that question gets answered with guesswork, which means overreacting, locking down everything and alarming customers unnecessarily, or underreacting, missing that the problem is worse than it looks. With logs, you get a fast, factual answer.
Action steps for you and your IT team:
Enable logging on your core systems: email, file storage, remote access tools such as VPN or RDP, and any line-of-business software holding customer or financial data.
Log both successful and failed logins. Repeated failures followed by success is one of the clearest signs of a compromised account.
Set a retention period of at least a year for critical systems, and confirm logs aren’t being quietly overwritten by default settings.
Remove access immediately when an employee or contractor leaves, and confirm the removal itself is logged.
Store logs somewhere separate from the systems they’re monitoring, so an attacker who compromises one system can’t also erase the evidence.
Review logs on a regular schedule, not only when something feels wrong. Most warning signs show up as patterns over time.
Know who on your team, or which vendor, is actually responsible for watching this. If the answer is no one, that’s the gap to close first.
Questions clients ask us about this:
Q: We’re a small business. Do we really need this level of tracking? A: Attackers don’t skip small businesses because they’re small. Many target them specifically because defenses tend to be lighter. Basic logging is inexpensive and often the deciding factor in how quickly you recover from an incident.
Q: We have antivirus and a firewall. Isn’t that enough? A: Those tools help prevent and detect threats, but they don’t give you a full history of user activity across your systems. Logs answer the who and when that other tools weren’t built to track.
Q: If nothing bad has ever happened to us, why start now? A: Most businesses that suffer an incident didn’t see it coming either. Logging is cheap insurance you set up before you need it, because you can’t go back and turn it on after the fact.
How Farmhouse Networking helps: We help small and mid-sized businesses put practical monitoring and logging in place without overcomplicating your environment or your budget. That means configuring logging across your key systems, setting retention that actually covers you, and reviewing activity on a regular schedule so small issues get caught before they become expensive ones. If something does happen, you get a fast, clear answer from a U.S.-based team who already knows your setup, instead of starting from zero during a crisis.
Why how your staff uses AI matters more than whether they use it
Experienced staff use AI to work faster. New hires should watch and learn from it, not let it do the job for them.
Why how your staff uses AI matters more than whether they use it
Somewhere in your business right now, an employee is probably using AI to draft an email, summarize a document, or answer a customer question. Whether you approved it or not, AI has already found its way into your workday. The real question for your business isn’t whether to allow AI. It’s whether the people using it know the difference between a tool that makes them better and a shortcut that replaces their judgment.
Here’s a useful way to think about it: AI should act as a tool in the hands of a master and a mentor in the hands of a novice. Your most experienced employees already know what good work looks like in your business, whether that’s a client proposal, a service call, or a piece of finished work. For them, AI is a force multiplier that speeds up the parts of the job they already understand. For your newest hires, the ones still learning how your business actually operates, AI shouldn’t hand them a finished answer to pass along. It should be something they watch work through a problem and learn from, the way they’d learn by shadowing an experienced coworker.
Get that balance backward and the risk is real. Gartner predicts that by 2030, 30 percent of organizations will see worse decision-making tied directly to overreliance on AI, a risk concentrated among less experienced employees in roles that depend on judgment. In practice, that looks like a new hire who never develops real expertise because AI has always supplied the answer. There’s also a more immediate problem: recent workplace surveys found a majority of employees already use AI tools their employer never approved or reviewed, often entering business or customer information into them without a second thought. For any business that handles customer data, that’s a real exposure, not a hypothetical one.
What This Means for Your Business
The goal isn’t to slow down AI adoption. It’s to make sure your best people are using it to work faster, while your newest employees are actually building skill, not just prompting their way through the job.
Action Steps for You as the Business Owner
Put a simple written AI use policy in place: which tools are approved, what business or customer data can go into them, and who signs off on new tools.
Separate low-risk uses, like drafting internal notes, from anything touching customer data, financial information, or work that goes out under your name.
Require experienced staff to review AI-assisted work until you’ve established confidence in the results, not just approved it once and moved on.
Treat AI as a training tool for new hires: have them explain how the AI arrived at an answer to a supervisor, rather than submitting the output directly.
Revisit the policy every few months. AI tools and the risks around them change faster than most small business policies do.
Action Steps for Your IT Department or Provider
Take inventory of the AI tools already touching your network, including ones employees adopted on their own without telling anyone.
Confirm which tools meet your data security and privacy standards, and restrict or block the ones that don’t.
Set up monitoring that flags new or unapproved AI tool use before it becomes a habit across the team.
Check whether AI features built into your existing software, like your CRM or accounting platform, meet the same security bar as the rest of your systems.
Put technical controls behind the written policy, such as access restrictions and activity logs, so it’s more than a memo employees forget.
Questions Your Customers Might Ask You
“Are you using AI to handle my information or my order?” Be direct about where AI helps, such as drafting a first response, and reassure them a staff member reviews anything that matters before it reaches them.
“Is my information safe if you’re using these tools?” Point to your policy: only vetted, secure tools are used, and customer information never goes into a tool that hasn’t been reviewed.
“Will AI replace the people I usually work with at your business?” Explain that AI supports your team’s work, it doesn’t make the final call, and every decision that affects a customer still comes from a person.
“How do I know your newer staff aren’t just letting AI do their job?” Explain that your business uses AI as a supervised training tool for newer employees, always reviewed by an experienced coworker, not a substitute for learning the job.
How Farmhouse Networking Can Help
Setting the right guardrails takes more than good intentions. Farmhouse Networking helps small and mid-sized businesses build AI usage policies that match how their teams actually work, put practical safeguards behind those policies, and monitor the network for AI tools employees may have adopted without approval. We help you see clearly what’s already running on your systems, close the security gaps, and put a structure in place so your experienced staff can work faster with AI while your newest employees are actually learning the job.
If you’re not sure what AI tools are already touching your business data, or you want a policy that actually holds up, we can help you find out and fix it.
Email us at support@farmhousenetworking.com and let’s talk about what a safe, practical AI approach looks like for your business.
Voice phishing scams are getting harder to spot, and they’re not just an enterprise problem anymore. Here’s what business owners need to do now.
One convincing phone call is often all it takes. Verification before action is the strongest defense against vishing.
A hedge fund employee gets a phone call. The voice sounds exactly like a colleague, tone and pacing included. Within minutes, the caller has talked their way into a password reset. That scenario played out at several major investment firms in August 2026, when AI-generated voice cloning was used to target Point72, Citadel, and Millennium Management. Two Sigma caught the attempt before any damage was done, according to Bloomberg’s reporting.
Most small and mid-sized businesses don’t have that level of security scrutiny watching over them. This is vishing: voice phishing, where a scammer uses a phone call instead of an email to trick someone into handing over credentials, approving a wire transfer, or granting system access. It’s not a future threat. It’s active right now, and AI voice tools are making it more convincing every month.
Why Vishing Works So Well
People trust a human voice more than a written message, and criminals know it. According to Verizon’s 2026 Data Breach Investigations Report, phone-based social engineering succeeds roughly 40% more often per attempt than email phishing. Gartner research found that 35% of organizations have already experienced at least one deepfake-related incident, yet only 10% of security leaders prioritize training staff to recognize a cloned voice, compared to 73% who focus on email phishing alone.
The financial risk is real. In 2023, a vishing call to an IT help desk was the entry point for a breach that cost MGM Resorts an estimated $100 million.
Action Steps for Owners and IT
For the business owner:
Set a rule that no wire transfer, password reset, or system access is approved based on a phone call alone. Require a callback to a known, independently verified number first.
Build a culture where staff can pause and question an “urgent” request without fear of looking difficult.
Schedule recurring, not one-time, staff training on phone-based scams.
For your IT team or provider:
Enforce multi-factor authentication on every account that supports it, and never let it be disabled based on a phone request.
Require independent identity verification before any help desk password reset.
Document and block known scam and spoofed numbers where possible.
Run periodic simulated vishing tests to find gaps before criminals do.
Questions Clients Are Asking
“How do I know if a call is legitimate?” Hang up and call the company or person back using a number you already have on file, not one the caller gives you.
“What should my team do if they’re unsure?” Stop, verify, then act. No legitimate request will penalize someone for double-checking.
“Can this really happen to a business our size?” Yes. Smaller businesses are often targeted precisely because attackers assume less security is in place.
“What’s the first thing we should change?” Put a callback verification policy in place this week. It costs nothing and closes the biggest gap immediately.
How Farmhouse Networking Can Help
Farmhouse Networking builds vishing and social-engineering awareness training around how your team actually works, not a generic slideshow. We run realistic simulated call scenarios, show you exactly where the gaps are, and help you put clear verification procedures in place your staff will actually follow. As a locally based, USA-only provider, we invest heavily in our own team’s ongoing security training, and we bring that same standard to yours.
Protect Your Business Before the Call Comes In
Vishing attacks succeed because they catch people off guard. A short, honest conversation now is a lot less costly than the one you’d have after a breach. Email us at support@farmhousenetworking.com for a free risk assessment. We’ll give you a clear picture of where your business stands, not just against vishing, but across your full security posture.
A practical guide to cutting costs by moving your business off traditional fax
Modern businesses are replacing the fax machine with secure, cloud-based digital fax.
Most businesses that still fax do it because a client, vendor, or government agency expects it, not because anyone actually prefers the machine. But keeping that machine running means paying for a dedicated phone line, equipment, toner, and paper, plus the staff time spent checking on it. A digital fax service lets you keep sending and receiving faxes exactly as your partners expect, without any of the overhead.
What Changes When You Switch
You keep your existing fax number, but instead of documents printing out of a machine, they arrive as PDFs in a secure email or online inbox. Sending works the same way, in reverse: attach a file and send it like an email.
Action Steps for Your Business and IT Team
Calculate your current fax costs. Add up the phone line, any equipment lease, paper, and toner. Compare that total to a monthly digital fax subscription.
Port your existing number. This keeps continuity for clients, vendors, and any government or financial contacts who already have your fax number.
Route incoming faxes to a group inbox. Setting delivery to a Google Group or Microsoft 365 Group means multiple team members see new documents right away instead of one person checking a machine.
Automate document storage. Configure faxes to save directly into a Google Drive or OneDrive folder, cutting down on manual scanning and lost paperwork.
Pilot before a full cutover. Run the new system alongside your current setup for a short period to confirm delivery and receipts are working as expected.
Check vendor security practices. If your business handles sensitive client or financial information, confirm encryption and access control standards before switching.
Questions Your Team or Clients Might Ask
“Will our fax number change?” No, it transfers to the new service and works exactly as before.
“Is this actually cheaper?“ In most cases, yes. You eliminate the dedicated phone line and hardware costs and pay only for the service.
“What if we’re not very technical?” Sending and receiving through email or a simple app is generally easier to learn than operating a physical machine, and most staff pick it up quickly.
“Do we still need to fax at all in [current year]?” Many industries still rely on fax for certain transactions, so keeping a working number matters even as the technology behind it modernizes.
How Farmhouse Networking Can Help
Farmhouse Networking manages RingCentral fax deployments for businesses across our service area, handling the number port, setting up group-based inbox routing so the right people see documents the moment they arrive, and configuring automatic filing into your Google Drive or OneDrive. We work with other fax platforms if you already have a preference, but RingCentral is the service we support directly and recommend for its reliability and flexible notification options.
Ready to Stop Paying for a Machine You Barely Use?
If your business is ready to cut an unnecessary cost and simplify how documents move through your office, email support@farmhousenetworking.com and we’ll help you figure out what the switch looks like for you.
The American Chiropractic Association just endorsed adjustable standing desks and monitor arms
A well-planned ergonomic workstation supports both employee comfort and IT reliability.
This is a small industry story that’s really about a bigger issue: how well your workplace supports the people who keep your business running.
The American Chiropractic Association announced its endorsement of adjustable standing desks and monitor arms, pointing to their ergonomic design and role in reducing strain during long work sessions. For small and mid-sized business owners, it’s a useful prompt to take stock of your own office. Most workplace injuries aren’t dramatic, they’re cumulative, showing up as chronic discomfort, missed days, and slow-building turnover risk among the staff who spend the most hours at a desk.
Ergonomics isn’t just a wellness perk. It’s a practical, low-cost way to reduce absenteeism and protect the productivity of your team.
Action Steps for Business Owners and IT Staff
Identify which employees spend the most consecutive hours at a workstation, and start there.
Try low-cost fixes first: monitor height, chair adjustment, and keyboard positioning, before investing in new equipment.
If you’re upgrading desks or adding monitor arms, involve your IT provider early. Cable management, power access, and hardware compatibility all need to be part of the plan.
Build ergonomic upgrades into your regular equipment refresh cycle instead of treating them as a separate, one-time project.
Ask employees directly what’s uncomfortable, the fix is sometimes simpler and cheaper than a full desk replacement.
Reassess your office setup annually, especially after any staffing or equipment changes.
Questions Employees or Managers Might Ask
“Do we need to replace every desk in the office?” No. Most businesses phase upgrades in by role, starting with the highest-strain positions.
“Will new equipment interfere with our existing setup?” It shouldn’t — as long as the physical changes are planned alongside your network and hardware configuration, not as an afterthought.
“Is this really an IT issue?” More than people expect. Monitor arms, docking stations, and desk power all intersect with your network and device setup, which is why it’s worth coordinating both at once.
How Farmhouse Networking Can Help
Workplace equipment changes almost always touch your IT environment more than expected: cabling, power, docking stations, and device compatibility all need to work together. Farmhouse Networking helps small and mid-sized businesses plan equipment upgrades that support both staff wellbeing and system reliability, so a simple desk swap doesn’t turn into a network headache.
Ready to Take a Closer Look at Your Office Setup?
If you’re considering ergonomic upgrades for your team, let’s make sure the technical side is handled right. Email us at support@farmhousenetworking.com for a free workplace and IT equipment consultation.
And God will generously provide all you need. Then you will always have everything you need and plenty left over to share with others. As the Scriptures say, “They share freely and give generously to the poor. Their good deeds will be remembered forever.” For God is the one who provides seed for the farmer and then bread to eat. In the same way, he will provide and increase your resources and then produce a great harvest of generosity in you. - 2 Corinthians 9:8-10
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.