Redefine Logic
Redefine Logic Media
Free reference · No signup · Nothing to buy

Must-see common situations
and a starting point for each one

“What do I do if…” — real situations, and where we would begin. The first step, the reasoning underneath, and an honest read on how worried you should be.

Written to teach

Not to frighten you into a call. Where a risk is overblown, we say so plainly.

Both halves

Growing something and protecting it are the same job. Both are here.

It grows

Built from situations people actually bring us. Send us yours and it gets added.

If something is happening right now and money is moving or systems are locked — filter to “Happening now” below, then call someone. Not deciding alone is the most underrated control there is.

⚠

Read this before you act on anything below

This page is general education, written from our own experience and from published research. It is not advice about your specific situation, your systems, your contracts or your legal obligations — and it cannot be, because we cannot see any of those.

Treat every scenario as a starting point for your own research, not an instruction. Verify anything consequential independently, and where money, data, staff or regulators are involved, get qualified professional help before you act. You proceed at your own risk, and responsibility for the outcome stays with you.

Situations differ in ways that change the right answer completely. Something that is correct for a sole trader can be wrong for a regulated practice with an insurance policy and a notification duty.

⚲
Show Urgency
Nothing matched that. Try fewer words, or describe it differently. If it is a situation we have not covered, tell us — that is how this page grows.
Protect

When something has already happened

Ordered roughly by how fast you need to move. The red ones are where minutes matter.

!

We came in this morning and everything is locked. There is a screen demanding cryptocurrency. What do we do?

Right now — in this order

1. Disconnect, do not power off. Unplug the network cable, switch off Wi-Fi. Leave the machines running — shutting down destroys evidence that investigators need, and some variants do further damage on reboot.

2. Photograph the ransom screen with your phone. The note, any ID or reference on it, the file extensions. You will need this.

3. Call your cyber-insurance provider before you call anyone else. Most policies require you to use their approved incident responders. Bringing in your own IT firm first can void the claim entirely.

4. Do not pay, and do not decide alone. Not yet, and not in the first hour.

What happens next, and what people get wrong
Then
  1. Assume the data was stolen as well as encrypted. Modern ransomware copies data out before locking it, precisely so paying for a decryption key does not end the problem. That changes this from an IT outage into a probable privacy breach.
  2. Work out your notification duties early. In Canada, a breach posing real risk of significant harm must be reported to the Privacy Commissioner and to the people affected. If you hold health information in Ontario, PHIPA obligations apply on top. These have clocks attached.
  3. Report it. The Canadian Anti-Fraud Centre and your local police. It rarely recovers anything directly, and it is how the case data that eventually stops these groups gets built.
  4. Check whether a free decryptor exists. The No More Ransom project, run by Europol with industry partners, publishes free tools for many strains. Worth ten minutes before any payment conversation.
  5. Do not restore from backup yet. If you rebuild before anyone knows how they got in, you restore straight back into a compromised environment — often with the attacker still holding valid credentials.
Why

The instinct is to fix it fast and quietly. Almost every expensive mistake in a ransomware incident comes from that instinct — powering machines off, wiping and rebuilding, paying early, or calling a responder your insurer has not approved.

The insurance point is the one that surprises people most. Cyber policies typically name a panel of firms you must use. Organisations regularly do the sensible-seeming thing, call their usual IT support, and discover weeks later that the claim will not pay.

About paying

We are not going to tell you never to pay, because that decision belongs to you and your counsel, and sometimes an organisation genuinely has no other route to survival. We will tell you what paying does not do: it does not un-steal the data, it does not remove your notification obligations, and decryption tools supplied by attackers are frequently slow and incomplete.

How worried should you be?This is the worst day, and it is survivable — but only with preparation you make beforehand. Tested, immutable backups and a printed incident plan are the difference between a bad fortnight and closing. If you are reading this before it happens: that is the work.
!

My boss just called. It sounded exactly like him — but he wants a large payment, urgently, and it is completely out of character. What do I do?

Right now

1. Do not act on the call. Not even partially. Not “just start the paperwork so we are ready.”

2. Hang up and call back on the number you already have. Not a number given during the call. Not one in the email that follows. The one that was in your phone yesterday.

3. If you cannot reach him, tell one other person. The point is not permission — a second human breaks the spell. Every version of this attack depends on you being alone with the decision.

Why it sounded exactly like him — and how to make this impossible next time
Why it sounded right

Voice cloning now needs only seconds of source audio — a podcast, a conference talk, a voicemail greeting, a video on your own website. It is cheap, fast, and no longer reliably distinguishable by ear. Recognising a voice has stopped being a control.

Notice what the attack actually runs on, because it is not the audio. It is urgency, authority and secrecy. The request is always time-critical, always from someone you would not push back on, and almost always framed as confidential — a deal not yet announced, something the team must not hear about. That framing exists for one reason: to stop you checking.

Then
  • If any money moved, call your bank immediately and use the word “fraud”. Recovery chances fall away by the hour.
  • Report it to the Canadian Anti-Fraud Centre, and to police if funds left.
  • Preserve everything — call time, number, any follow-up email, the exact wording.
  • Tell your team the same day. Someone being targeted usually means several people are.
How to make it not work

Agree a verification habit now, while nothing is happening. Two things, both free:

  1. A call-back rule. Any payment request arriving by phone, text or email gets verified on a channel the requester did not choose. No exceptions for senior people — especially not for senior people.
  2. A spoken code word, agreed in person, known to whoever can move money. It sounds ridiculous until the day it saves you six figures. Do the same with your family; the parent-and-grandchild version of this scam is rampant.

And say this out loud to your staff: nobody will ever be disciplined for slowing down a payment to check. If your culture punishes hesitation, you have built the vulnerability yourself.

How worried should you be?Genuinely worried — this one is live, growing, and no longer needs technical skill to run. But it is also almost entirely defeated by one habit that costs nothing. Of everything on this page, agreeing a call-back rule this week is the highest return on the least effort.
!

An invoice came in from a supplier we genuinely use. Everything looks right — but the email address is slightly off, and the bank details have changed.

Right now

1. Do not pay it. Do not reply to it. Replying tells them a human is reading, and the reply goes to them, not your supplier.

2. Phone your supplier on the number you had before this email arrived. From your records, a previous invoice, or their website you navigated to yourself. Never the number on the new invoice.

3. Ask one specific question: “Have your banking details changed?” Almost always, the answer is no and they have no idea this is happening.

What is actually going on, and why the details are perfect
Why it looks so right

Because it probably is right — it is often a real invoice. Either your supplier’s mailbox has been compromised and someone is watching the thread, or a genuine invoice was intercepted, the bank details swapped, and the whole thing resent from a lookalike address.

That is why the usual advice fails here. The logo is correct, the amount is correct, the reference matches a real job, and the tone is right because earlier messages were there to copy. The only wrong detail is the one that moves the money.

The address trick

Look hard at the domain. A letter swapped, a hyphen added, .co instead of .ca, or rn where an m should be. On a phone, in a hurry, these are effectively invisible — which is the entire point.

Then
  • Warn your supplier properly. If their mailbox is compromised, every one of their customers is receiving this. You may be the first person to tell them.
  • Check your own outbox and rules. This runs both directions. Look for forwarding rules you did not create — a classic move is a rule that quietly hides the attacker’s replies from you.
  • If it was paid, call the bank within the hour and say “fraud”. Then the Canadian Anti-Fraud Centre.
The rule that ends this category

Any change to bank details gets verified by voice, on a known number, every single time. No exceptions for regular suppliers, urgency, or a plausible explanation about switching banks. Write it down, tell whoever pays invoices, and make it boring.

How worried should you be?This is the one that actually empties small business accounts — higher frequency and higher loss than anything glamorous. If you only fix one process this year, fix the one where bank details change.
?

I got an invoice from a company I have never heard of. Do I just ignore it?

Right now

Do not open the attachment, and do not click anything in it. The invoice may not be the point — the attachment often is.

Check whether anyone in your organisation ordered anything before assuming it is fake. Then delete it, or report it to your IT provider if you have one.

Two different scams wear this costume
Which one is it

Malware delivery. The attachment is the payload and the invoice is just a reason to open it. Anything that asks you to “enable content” or “enable macros” is this, every time, with no exceptions worth considering.

Or simple opportunism. Plausible invoices for modest amounts sent in volume, betting that a busy finance person pays without checking. Domain renewals, directory listings and office supplies are the classics, and the amounts are deliberately small enough not to trigger scrutiny.

Then

If someone already opened the attachment, treat it as a possible infection rather than a nuisance: disconnect that machine from the network, and get it looked at before it goes back on.

How worried should you be?Low, if nobody opened it. The real risk is volume — send enough of these to a busy office and eventually one gets paid or opened. Well-configured email filtering removes most of them before a human ever decides.
!

I got an email telling me to reset my password — but I never asked for a reset. What should I do?

Right now

1. Do not click the link. Not to check it, not to “cancel the request”. That button is the whole attack if the email is fake.

2. Go to the service directly — type the address yourself or use your own bookmark — and sign in normally. If there is a genuine problem, you will see it there.

3. While you are in there, change the password and check what devices are signed in. If this is a real reset request, someone knows your address and is actively trying.

Both possibilities are worth taking seriously — for different reasons
It is fake

The commonest case. The email is a lure, the link goes to a convincing copy of the login page, and typing your password there hands it straight over. Read the domain after the @ rather than the display name, and remember the padlock on the fake site means nothing — certificates are free.

It is real

This one gets dismissed as spam far too easily. A genuine reset email you did not request means somebody typed your address into that login page and clicked “forgot password”. It is not an attack that succeeded — it is an attack in progress, and you are being told about it.

If it keeps happening, treat it as targeting rather than noise.

Then
  • Turn on proper two-factor if it is not already — passkey or authenticator app rather than SMS.
  • Check mail forwarding rules and filters. A rule you did not create, quietly copying or hiding messages, is a classic sign someone already has access.
  • Check that account’s recovery email and phone number. Changing these is usually the first thing an attacker does once inside.
  • If it is your primary email, act with urgency. That one account can reset most of your others — it is the master key, and it should carry your strongest protection.
How worried should you be?Mildly, but do not ignore it. Ninety-nine times it is phishing you can delete. The hundredth is early warning, and it costs you five minutes to tell the difference by going to the site yourself.
!

My AI assistant has started asking for personal information and behaving oddly. Is something wrong?

Right now

1. Give it nothing. No passwords, no card numbers, no verification codes. A legitimate assistant never needs any of these — not to “confirm your identity”, not to “continue”.

2. Do not follow links it produces, and do not run commands or scripts it tells you to run.

3. Start a completely new conversation. Do not carry the old one on. Whatever is steering it lives in that thread.

What is probably happening — and why it is not the AI “going rogue”
The likely cause

This is usually prompt injection. Instructions get hidden inside content the assistant reads on your behalf — a web page it browsed, a document you uploaded, an email it summarised. The assistant cannot reliably tell the difference between your instructions and instructions buried in the material, so it follows both.

That is why the behaviour change is often sudden and tied to a moment: right after it opened a link, read a file, or processed a message. The text may be invisible to you — white on white, or tucked in metadata.

The tells
  • A sudden shift in tone or persona mid-conversation
  • Asking for credentials, codes or payment details
  • Urging you toward a specific link or download
  • Claiming a rule change, an account problem, or a deadline
  • Being evasive about what it was just asked to do
Then — and this is the part that matters

Work out what that assistant was connected to. If it has access to your email, files or calendar through an integration, the exposure is far larger than a strange conversation. Review connected apps and revoke anything you do not actively need.

Look back at what you pasted earlier in that thread. If client data, credentials or anything confidential went in before the behaviour changed, treat it as potentially disclosed and handle it accordingly.

Then report it to the vendor. These get fixed when people report them.

How worried should you be?More than most people currently are, and this is genuinely early days. Prompt injection has no complete fix yet — it is an open research problem, not a bug awaiting a patch. The practical defence is simple: never give an assistant a secret, and be deliberate about what you connect it to.
?

I found a USB stick in the car park — or there is a charging cable in the office nobody recognises. What do I do?

Right now

Bin it. Both of them. Do not plug it in “just to see whose it is”, not even on an old laptop, not even one you think does not matter.

If it turned up somewhere it should not have — inside a locked office, on a reception desk, in a bag — tell someone before you throw it away. That is a different conversation.

The stick is documented. The cable is the sneakier one.
The stick

Researchers have repeatedly scattered USB drives in car parks and measured how many get plugged into work machines. It keeps working, because curiosity is the exploit. Wanting to find the owner is a perfectly decent instinct, and it is the instinct being used.

Worse, a hostile drive need not behave like a drive at all. Devices exist that are physically identical to a memory stick but announce themselves to the computer as a keyboard, then type commands faster than you can read. Nothing warns you, because as far as the machine knows, somebody is typing.

The cable

Malicious cables are real and sold openly as penetration-testing tools, with the electronics hidden inside the moulded connector. They are indistinguishable from an ordinary cable by eye or by weight.

We will be straight with you though: we are not aware of documented cases of these being used against ordinary consumers. They are a professional tool, and the likelihood that the mystery cable in your drawer is one of them is low.

So why bin it anyway

Because of a principle worth carrying beyond this page:

When doing the safe thing costs you nothing, you do not need strong evidence to justify it. When it costs you money or attention, you do.

Binning a cable you never owned costs nothing. That is why this advice is easy, and why we give it confidently despite thin evidence — whereas we tell you not to worry about airport charging points, because avoiding those costs you something real for a threat nobody has documented.

How worried should you be?Barely at all — provided you do not plug it in. This is a near-zero-cost precaution against a low-probability event, which is the easiest kind of decision there is. Save your worry for the invoice scenarios above.
Grow

When you are trying to get something moving

The other half. Same format — what to do first, the reasoning underneath, and an honest read on how hard it actually is.

?

We are a nonprofit. We tried to sign up for the Google Ad Grant and were told our website is not up to spec. What now?

Right now

1. Check you went through Goodstack. Google’s validation partner is Goodstack (formerly Percent) — not TechSoup, despite a lot of advice online still saying so. If you started somewhere else, that alone can stall the whole application.

2. Get the actual rejection reason in writing rather than working from a summary. “Not to spec” covers several very different problems with very different fixes.

What they are usually objecting to, and the order to fix it in
The usual causes, most common first
  • No HTTPS. The site must be secure. This is the most common and the easiest to fix — most hosts now include a certificate free.
  • Thin or unclear content. The site has to make plain what the organisation does and who it serves. A one-page holding site with a donate button generally will not pass.
  • Broken or dead links, pages under construction, placeholder text still in place.
  • Commercial activity that reads wrong — ads on your own site, or affiliate links, can raise questions about the nature of the organisation.
  • Domain mismatch. The domain should be the organisation’s own, not a free subdomain on somebody else’s platform.
Then

Fix HTTPS first, because nothing else is assessable without it. Then make the homepage answer three questions plainly: who you are, who you help, and what happens next. Then reapply.

What nobody tells you

Getting approved is the easy half. Keeping it is where charities lose the grant — a 5% click-through minimum, active conversion tracking, no single-word keywords, and an account that has to actually be managed. A meaningful share of approved organisations lose it within a year to rules nobody walked them through.

So before you celebrate approval, decide who is going to run it. An unmanaged Ad Grant does not sit idle; it gets suspended.

How hard is this actually?The website fixes are usually a day of work, not a rebuild. The compliance side is the real commitment. Ten thousand US dollars a month is worth the effort — just go in knowing it is an ongoing job rather than a form you fill in once.
?

Everyone keeps telling me to add conversion tracking or “snippets” to my site. Where do I even start?

Right now

Before touching any code, write down what counts as a win. A booked call? A form sent? A phone number tapped? A donation? You cannot measure a conversion you have not defined, and most tracking setups fail here rather than technically.

Then install one container, not five separate snippets. Google Tag Manager gives you a single piece of code on the site and everything else configured inside it.

What these things actually are, and the order to do them in
Plain meaning

A snippet or tag is a small piece of code a platform gives you to paste into your site so it can see what visitors do. A conversion is you telling that platform which action was worth something. A container holds all of them so you are not pasting code every time.

The order
  1. Define the actions that matter. Two or three. Not fifteen.
  2. Install a tag container once, sitewide.
  3. Connect analytics so you can see traffic and behaviour at all.
  4. Mark those actions as conversions, then test each one by actually doing it yourself and confirming it registered.
  5. Only then spend money on ads. Advertising without working conversion tracking is buying clicks and hoping.
Two things that will bite you

Cookie consent. If you serve visitors in regions with consent requirements, tags must respect the choice made. Bolting consent on afterwards is far more painful than planning for it.

Untested tracking. Broken conversion tracking is the most common root cause we find behind “our marketing does not work”. It is worse than none, because it produces confident numbers that are wrong.

How hard is this actually?A competent afternoon for a simple site, if the goals are clear. The technical part is genuinely not the hard bit — deciding what counts as success, and then testing that it registers, is where the value and the failures both live.
?

What is affiliate marketing, and could I sell my products through it for the holiday season?

Right now

Plainly: you pay other people commission for sales they send you. They promote, you pay only when something actually sells, and tracking links tell you who sent what.

The honest answer on timing: if the holiday season is weeks away, this is not your lever. Affiliate programmes take months to recruit and build trust. Set it up now for next season and use something faster for this one.

What it takes, what it costs, and when it is the wrong idea
What you actually need
  • Margin to share. Typical commission runs 5–20%. If your margin cannot carry that on top of payment fees and shipping, the programme loses money on every sale it makes.
  • Tracking that works — a platform or plugin that attributes a sale to the right partner and handles payouts. This is the part people underestimate.
  • Clear terms. What partners may and may not say, whether they can bid on your brand name in ads, cookie window, when you pay.
  • Someone to recruit and manage partners. A programme nobody tends attracts coupon sites that cannibalise sales you would have made anyway.
The disclosure part, which is not optional

Affiliates must clearly disclose that links are paid. In Canada this sits under the Competition Act’s rules on misleading representations, and the Competition Bureau has been increasingly active on undisclosed influencer and affiliate promotion. Enforcement can land on the brand, not only the affiliate — put disclosure requirements in your terms and actually check compliance.

When it works, and when it does not

Works well for products with healthy margin, clear appeal and an existing audience of reviewers or creators in the category. Works badly for services, anything with a long or consultative sales cycle, or thin-margin goods.

If you want revenue this holiday season, the faster levers are your existing email list, your Google Business Profile, and making sure the checkout actually works on a phone. Unglamorous, and they pay this month.

How hard is this actually?Setting it up is a few weeks. Making it produce meaningful revenue is a quarter or more of recruiting and relationship work. Treat it as a channel you are building, not a campaign you are running — and do the margin arithmetic before anything else.
?

My Google Ad Grant got suspended. What do I do next?

Right now

1. Do not open a second Google Ads account. This is the single most damaging instinct, and it is the one almost everybody has. Creating a new account to get around a suspension is itself a policy violation and can turn a fixable problem into a permanent one.

2. Find out which kind of suspension this is. Sign in and read the notice at the top of the account. A policy suspension names the rule. An inactivity or programme-compliance pause is a different animal with a different fix.

3. Do not reapply or appeal until you have actually fixed something. A rejected appeal is a worse position than an unfiled one.

What usually causes it, and how each one gets fixed
The common causes
  • Click-through rate under 5% for two consecutive months. The most frequent cause by a wide margin, and almost always a symptom of keywords that are too broad.
  • Single-word keywords, or overly generic ones. Both are prohibited outright under the programme policy, and both quietly destroy your click-through rate on the way to getting you suspended.
  • No conversion tracking, or tracking that has broken. The programme expects at least one meaningful conversion action to be tracked and firing.
  • Missing geographic targeting, or targeting set to the whole world.
  • Account inactivity — no sign-in for an extended period, or the annual programme survey left uncompleted.
  • Site or ad problems — a domain that no longer resolves, a site that is not substantially the organisation’s own, deceptive claims, or a mismatch between the ad and the landing page.
Then

Fix the cause before you touch the appeal. Remove the offending keywords, rebuild the ad groups around specific intent phrases, get conversion tracking verified and firing, set your geography properly. Then submit the reactivation request and say plainly what was wrong and what you changed.

Expect it to take time. Reviews are not instant and chasing does not speed them up.

Then fix the reason it happened. A suspension is nearly always the account telling you it was never set up to the programme’s rules in the first place. Reinstating it without changing how it is run buys you a few months.

How worried should you be?Not very — most suspensions are recoverable, and the grant is not gone. The real risk is the panic move: a duplicate account, or an appeal filed before anything was actually fixed. Slow down and this is an administrative problem, not a lost programme.
?

We have run this business for 20+ years with no website and done fine. How could one possibly help us now?

The honest answer first

You are right that you did not need one. Twenty years of business on reputation and word of mouth is a genuine asset, and most companies with beautiful websites would trade them for it. Nobody should tell you otherwise, and anyone who opens by suggesting you have been doing it wrong is selling, not advising.

What changed is not websites. It is what people do before they call you. They look you up first — to check you are real, still trading, and the same business somebody just recommended. When there is nothing to find, some of them stop there. You never hear about those, which is exactly why the gap is invisible.

What it actually buys you — and what you probably do not need
What a modest site does
  • It confirms the referral. Word of mouth still does the selling. A page simply stops the handoff failing at the last step.
  • You own it. A social page or a directory listing is rented — the platform sets the rules, the reach, and whether your page stays up. Your own domain and email cannot be suspended by someone else’s policy change.
  • It answers the same questions you answer by phone all day. Hours, service area, what you do and do not take on, what a job typically costs. That is time back.
  • It is where AI assistants and search now read from. Increasingly people ask a chatbot for a local recommendation. Those answers are assembled from sources that can be found. If nothing about you exists, you are not in the running — not because you lost, but because you were never a candidate.
  • It matters when you sell or hand over. A business with no findable presence is harder to value and harder to transfer.
What you probably do not need

Not a big build. Not a monthly retainer for content nobody reads. For a great many established businesses, a properly completed Google Business Profile plus one honest page — who you are, what you do, where, how to reach you, a few real photos, a handful of real reviews — captures most of the value. Anyone quoting a large project before asking what you actually want more of is guessing.

And a bad site is worse than none. A neglected page with a dead phone number, 2019 prices, or a contact form that goes nowhere actively costs you work. If you are not going to keep it current, keep it small enough that it stays true.

One thing worth doing either way

Register your own domain name and put your email on it, even if the site can wait. It is a small annual cost, it is yours, and it prevents somebody else registering your business name later.

So is this urgent?No. You have earned the right not to be rushed. But the cost of the gap compounds quietly — it is made of enquiries that never reach you, so it never shows up as a problem you can point at. Treat it as overdue maintenance on an otherwise healthy business, not an emergency.
The Problem Pool

From what needs attention right now, to what keeps you up at night

Real things people have said to us, close to word for word. Some are emergencies. Most are the quieter kind — a question someone carried around for a year because nobody gave them a straight answer, or one they are living with this week and have not said out loud yet.

Several of these sit across both halves of the job at once, and are labelled Grow + Protect. Those show up under either filter, because the problem genuinely does.

Hit a term you do not know? The glossary explains every word on this site in plain English — written on the assumption that nobody is born knowing this.

“

We never marketed, and we never needed security beyond what Windows gave us. We have been fine so far.

What is usually going on underneath

Start with what is true here, because most of it is. “Fine so far” is real evidence and it deserves respect — you have run a business for years without an incident, which plenty of far better-resourced organisations cannot claim. And Windows Defender is genuinely good now. Anyone who tells you it is worthless is selling something.

The gap is not that you were wrong. It is that “nothing has happened” and “we are not exposed” feel like the same sentence, and they are not. One is a record. The other is a forecast.

What actually changed — and what you probably do not need to do about it
On the security half

What changed is not that threats got cleverer. It is that they got automated and indiscriminate. Most attacks on small organisations are not aimed at you — nobody chose you. Scanners sweep the whole internet for a known weakness and take whatever answers. Being small used to mean being uninteresting. Automation removed that protection, because the cost of trying you fell to nearly nothing.

Defender handles the file-on-the-disk problem well. It does not cover the three things that actually cause bad weeks: someone signing in as you with a working password, a backup nobody tested, and an account you forgot to switch off. Those are not virus problems, so no antivirus was ever going to catch them.

On the marketing half

Word of mouth built this. Keep it — but notice that it is a single channel you do not control, and its capacity is capped by how many people happen to know you. That is concentration risk in commercial clothing. It is the same shape of exposure as one customer being 60% of revenue, and it is fine right up until the week a key referrer retires.

Where we would start — and it is smaller than you expect
  • Multi-factor authentication on email and anything financial. Free, an afternoon, and it removes the single most common way small organisations get hurt.
  • Restore one file from your backup this week. Not review the backup — restore from it. If that fails, nothing else on this list matters yet.
  • List who still has access to what. Former staff, the old bookkeeper, the web person from 2019.
  • Own your domain and your email on it. The commercial equivalent: stop renting your identity.

That is most of the risk, and none of it is a project. If someone is quoting you a monthly retainer before they have asked whether your backup restores, they are selling a product rather than answering your question.

How worried should you be?Not frightened. But “fine so far” stops being evidence the day something happens, and the four items above cost almost nothing against what they cover. Do those and you are ahead of most organisations your size — genuinely, not as a sales line.
“

Our competitors seem to be using new AI tools. We do not want to change. Is it actually necessary?

What is usually going on underneath

Mostly, no — and a great deal of what you are seeing is theatre. Plenty of businesses announce AI adoption and change almost nothing about how they work. Some are worse off, having added a tool nobody governs.

But two real things hide inside the question, and they pull in opposite directions: a genuine efficiency gain on repetitive work, and a visibility shift that is happening whether or not you adopt anything. Those deserve separate answers.

The honest split: what is real, what is hype, and the one risk of standing still
Where it is genuinely useful

Narrow, boring, repetitive text work. First drafts, summarising a long document, turning notes into something sendable, rewriting the same reply for the hundredth time. The gain is real but unglamorous, and it is measured in hours rather than transformation.

Where it is oversold

Anything promising strategy, judgement, or replacing a person who knows your customers. And anything sold as an “AI platform” that is a normal product with a new label on the pricing page.

The one thing standing still does cost you

This is the part that has nothing to do with whether you adopt a tool. People increasingly ask an assistant for a recommendation instead of scrolling a results page, and those answers are assembled from sources the model can find, read and quote. If your business is thinly documented online, you are not losing that comparison — you were never a candidate in it.

So the defensive move is not buying AI. It is making sure clear, accurate, specific information about what you do exists somewhere machine-readable. That is closer to writing a good page than to adopting a platform.

If you do adopt something, the one rule

Decide what must never be pasted in, and say so out loud, before anyone starts. Client records, anything covered by a confidentiality clause, payroll, credentials. The most common AI incident in small organisations is not a rogue model — it is a well-meaning employee pasting something sensitive into a personal account nobody knew existed.

How worried should you be?Not about falling behind on tools — that fear is mostly manufactured, and late adopters of this will be fine. Mildly about being invisible to a question your best customer asks an assistant next year. Those are different problems, and only the second one has a deadline.
“

Someone got into our email — or emails went out pretending to be us.

Right now, in this order

1. Change the password and sign out every session. Changing the password alone is not enough — an attacker with an active session stays in. Look for “sign out everywhere” or “revoke sessions”.

2. Check for mail rules and forwarding you did not create. This is the step people skip, and it is the one that matters most. A rule quietly copying your mail outward, or filing anything containing “invoice” into a folder you never open, means they intended to stay. Remove them and note what they were.

3. Read the Sent and Deleted folders. What went out, and to whom? If anything asked a customer or supplier to change bank details, phone those people now — do not email them.

4. Check the recovery email and phone number on the account. Changing these is usually the first thing done once inside.

Why this one is expensive, and what stops it happening again
What this is called, and why that matters

This is business email compromise, and it costs organisations more than ransomware does. There is no malware to find and nothing looks broken — someone simply signed in as you and read your mail until they understood how your money moves. Then they sent one message, from a real address, at a plausible moment.

That is why it defeats staff training. The email is genuine. It comes from the right person, continues a real thread, and uses the right vocabulary.

Then
  • Turn on multi-factor authentication on every mailbox, not just the owner's. Attackers go for whoever handles invoices, which is rarely the person with the biggest title.
  • Prefer an authenticator app or passkey over text messages. A code by SMS can be defeated by someone taking over your phone number.
  • Set up SPF, DKIM and DMARC on your domain. These are the records that make it hard for anyone to send mail that appears to come from you. Most small businesses have either none or a half-finished set, which is why the spoofing half of this works at all.
  • Agree one out-of-band rule and write it down: no change to bank details is ever actioned on an email alone, no matter who it appears to be from. A phone call to a number you already had defeats nearly every version of this attack.
Also worth doing

Assume anything in that mailbox was read. If it held client records, contracts, or personal information, you may have a notification obligation — that is a question for your lawyer and, if you carry it, your insurer. Tell the insurer early; policies often require prompt notice, and a delay can matter more than the incident.

How worried should you be?Properly worried, and act today. Not because of what was taken, but because access was the goal — the payoff usually comes days or weeks later, in an invoice that looks completely normal. Closing the door is the urgent part; warning the people who transact with you is the close second.
“

We have backups… but we do not actually know if they work.

Right now

Restore something this week. Not check the dashboard, not confirm the green tick — take one real file, or better a database, and bring it back. Time how long it takes and write the number down.

Until you have done that, you do not have a backup. You have a hypothesis. That is not a slogan — a meaningful share of the failed recoveries we hear about involve a backup that had been running, and reporting success, for months.

The four ways backups fail quietly — and what to fix first
How they fail while looking healthy
  • Incomplete scope. It backs up the file server but not the accounting system, the mailboxes, or the line-of-business database that actually runs the company. Very common, and only discovered at the worst moment.
  • Reachable from the network. Ransomware hunts backups first and encrypts them before touching anything you would notice. A backup the attacker can reach is a backup you do not have.
  • Never restored. Corruption accumulates silently. Jobs succeed, files are unreadable.
  • Recovery takes longer than the business can survive. A restore that technically works but needs nine days is a different kind of failure, and it is the one nobody measures until they need it.
Then

Get one copy out of reach. Offline, or immutable — meaning it cannot be altered or deleted for a set period even by someone holding valid credentials. This single property is what makes the difference between a bad week and an existential event.

Answer two questions in plain numbers. How much work can we afford to lose — an hour, a day? And how long can we be down before this becomes serious? Those two answers drive every other decision, and most organisations have never been asked them.

Then test on a schedule and keep the evidence. Quarterly is reasonable for most small organisations. Note what you restored, how long it took, and what broke. That record is also what an insurer or a board will ask for.

One thing people get wrong

Cloud file sync is not a backup. It is a mirror, and it faithfully mirrors encryption and deletion. Versioning and recycle bins help, but they have limits and attackers know exactly what they are.

How worried should you be?This is the single highest-value item on the whole page, and the cheapest to check. An untested backup is the one gap that turns a recoverable incident into a closed business — and you can move it from unknown to known in an afternoon. If you only act on one thing here, make it this.
“

Our employees are using ChatGPT and other AI tools. What are they putting into it?

What is usually going on underneath

The honest answer is that most organisations do not know, and the number using these tools is higher than leadership thinks. This is called shadow AI, and the pattern is consistent: capable people solving real problems with a tool nobody told them not to use.

The exposure is rarely malice. It is a personal account — outside your tenant, outside your logging, with settings and retention you do not control and cannot audit.

What actually gets pasted in, and the fix that does not involve banning it
What tends to go in

Whatever someone was already struggling to write. Contracts being summarised. Client emails being softened. Spreadsheets pasted wholesale to ask what a pattern means. Source code. Draft board papers. Almost always the thing that was hardest to do, which is usually the thing that was most sensitive.

Why banning it fails

A ban moves the activity onto phones and personal laptops, where you have no visibility at all. You trade a manageable problem for an invisible one, and you lose the ability to help people do it safely.

Where we would start
  • Name two or three approved tools. Not a policy document — a short list people can actually remember. Ambiguity is what pushes people to personal accounts.
  • Provide business accounts for those tools. The paid or tenant-linked versions generally give you administrative control and clearer data handling than a personal sign-up. This is the highest-value single step, and it is a purchase rather than a project.
  • Write down what must never be pasted in. Client or patient records, anything under a confidentiality clause, credentials, payroll, unreleased financials. One page. Specific, not abstract.
  • Say what output must be checked before it leaves the building. Anything going to a customer, a regulator or a board.
  • Ask, without blame, what people are already using. You will learn more in one honest conversation than from any technical control, and you cannot govern what you have not been told about.
The part that catches people out

AI features are arriving switched on inside tools you already pay for — note-takers joining meetings, assistants summarising mailboxes, features added in an update nobody read. So “we do not use AI” is frequently untrue by the time it is said. Worth checking what is enabled by default across your existing subscriptions.

How worried should you be?Concerned enough to act this quarter, not alarmed. Nothing here is catastrophic on its own, and the fix is unusually cheap — an approved list and one page of rules removes most of the exposure. The genuine risk is leaving it unaddressed long enough that something confidential ends up somewhere you cannot account for to a client who asks.
“

We are paying for marketing, but I have no idea what is actually working.

What is usually going on underneath

This is almost never a marketing problem. It is a measurement problem, and it is the single most common thing we are asked about on the Grow side.

In most cases one of three things is true: conversion tracking was never installed correctly, enquiries arrive by routes nobody counts — phone calls, walk-ins, replies to a personal inbox — or the numbers exist but sit in four dashboards that disagree with each other. You are not failing to read the data. There is no single version of it to read.

How to get to an answer you can trust, in about three weeks
Start at the end, not the beginning

Define one thing that counts as a win — a booked call, a submitted form, a completed sale. Then check it is actually being recorded. Broken or missing conversion tracking is so common that we treat it as the default assumption until proven otherwise, and until it is fixed every other number on this list is decoration.

Then close the counting gaps
  • Ask every new enquiry how they found you and write it down for eight weeks. Crude, unfashionable, and frequently more accurate than the analytics.
  • Tag your links so email, social and ads stop collecting in a bucket labelled “direct”.
  • Route enquiries to one place. If some arrive in a personal inbox, they are invisible by definition.
  • Accept that attribution is approximate. Every model is a simplification and they disagree. Pick one, learn its bias, and stop switching — comparing across models is how people conclude that nothing works.
What good looks like

Not a dashboard with forty numbers. Three numbers you trust: how many enquiries arrived, where they came from, and what a customer costs you to acquire. Most organisations we meet cannot answer the third, which is the one that decides whether any of the spending is sensible.

An honest warning

Once this is measured properly, you will probably discover that something you have been paying for monthly is producing very little. That is the point, and it is usually uncomfortable — often the thing that looks busiest is the thing contributing least.

How urgent is this?Not an emergency, but every month unmeasured is a month of spending on faith. The fix is small and mostly one-off — and it is the prerequisite for every other Grow decision, so doing it first makes everything after it cheaper.
“

Our board, our insurer or a client is asking what cybersecurity measures we have. What do we say?

What is usually going on underneath

The question is almost never really about technology. It is about whether anyone is accountable. A board asking this is asking whether someone owns the risk. An insurer is asking whether you qualify for the price they quoted. A client is asking whether you are a safe link in their own supply chain.

Those three want different evidence, and the most common mistake is answering with a list of products. “We have antivirus and a firewall” reads, to all three audiences, as though nobody is in charge.

What to put in writing — and the one answer that is worse than "we do not know"
Answer in four parts, on one page
  • Who is accountable. A named person, even if the work is outsourced. Outsourcing the work does not outsource the accountability, and every one of these audiences knows that.
  • What you actually have in place. Multi-factor authentication and where it is enforced; how devices are patched; what is backed up and when it was last restored; who has administrative rights; how leavers are removed.
  • What happens when something goes wrong. Who is called, in what order, and who can authorise spending at 11pm on a Saturday. This is the part that most distinguishes a serious answer from a nervous one.
  • What you know you have not done yet, and when you will. Counter-intuitive, but a short honest gap list with dates reads as competence. A flawless claim invites someone to go looking.
Insurers specifically

Treat the application as a technical questionnaire with contractual weight, because that is what it is. Questions about multi-factor authentication, backups, endpoint protection and patching are conditions, not curiosity. Answering optimistically is the genuinely dangerous move — a claim can be challenged on the basis of what you attested to. If you are not certain, verify before you tick.

Clients and procurement

Expect a questionnaire that was written for a company twenty times your size. It is reasonable to answer “not applicable at our scale, and here is what we do instead”. Do not invent a policy to fill a box. If you claim one, you may be asked to produce it and to show it is followed.

Where we would start if you have nothing written down

One page covering the four points above. That page is worth more than any tool purchase, because it is what turns scattered good practice into something you can show. Being able to evidence what you do is now part of doing it.

How worried should you be?Not worried, but do not stall — silence reads badly to all three audiences, and to a board it reads as nobody being in charge. This is a writing task more than a technical one, and most organisations discover they are doing more than they could prove. Just never overstate it in a document that could be tested later.

What happened to you?

This page grows from real situations, not from a list we invented. If something happened to you and it is not here, tell us — anonymised, no detail we would ever publish, and we will write it up so the next person finds an answer instead of a panic.

Already in the middle of it?

If money is moving right now, stop reading and phone your bank — use the word fraud. Then report it to the Canadian Anti-Fraud Centre. Speed matters more than getting the sequence perfect.

If something here resonated

Several of these are questions people carried around for months without getting a straight answer. If one of them is yours, book a free conversation or just email the question. No pitch, no obligation.

And we will tell you if you do not need us. Some of what is on this page you can do yourself in an afternoon, and we would rather say so than sell you something.

Educational only. Everything on this page reflects our own experience and published research, offered as a starting point for your own independent research — not as advice about your circumstances, your systems, your contracts or your legal obligations. Verify anything consequential, seek qualified professional help where money, data, staff or regulators are involved, and proceed at your own risk. Responsibility for what you do with this stays with you.

Our full methodology and limitations statement explains how we reach the positions we take, including where we are relying on judgement rather than evidence.