Logo Net At Work

Identity Attacks Are the New Cyber Threat: Why Zero Trust Matters for SMBs

Over 600 million identity attacks occur daily, with more than 99% targeting passwords through breach replay, password spray, and phishing tactics, according to the 2024 Microsoft Digital Defense Report. Yet despite this staggering reality, most organizations remain focused on traditional perimeter defenses while attackers simply log in with stolen credentials.  

“The most common misconception is that there is one product or one solution to buy and you are protected,” says Brian Kingsley, Director of Managed Services at Net at Work. “Many leaders think of security as a point in time protection—I bought this and thus I’m good. But this is an ongoing, living and breathing concept that requires constant attention and evaluation, much like a business needs to continually update its forecast and budget.”  

Breaches do not start with hackers smashing through firewalls anymore; they start with logins that look completely legitimate. This is what makes identity attacks so dangerous, so common, and so difficult to detect. 

In this article, you will learn:

  • Why identity attacks have become the primary threat vector for modern breaches 
  • How small and mid-sized businesses have become prime targets for cybercriminals 
  • Why traditional MSP security models are no longer sufficient 
  • What Zero Trust really means for SMBs (without enterprise complexity) 
  • Practical steps you can take now to improve your organization’s security posture 

What Is an Identity Attack? 

Identity attacks do not break in; they blend in. Unlike traditional cyberattacks that exploit network vulnerabilities, identity-based attacks use legitimate credentials to gain access.  

For small and mid-sized businesses (SMBs), identity attacks often look like everyday activities: phishing emails that appear legitimate, multi-factor identification (MFA) prompts employees approve by mistake, former employees who still have access, and admin accounts used for convenience. 

One identity-related issue that repeatedly surprises SMB leadership is also one of the oldest scenarios. “A user gets compromised through social engineering or a phishing email,” Kingsley explains. “Effectively, the user has a strong password and may even have multi-factor authentication; however, they accidentally give their credentials away. Multi-factor authentication is an important part, but there are ways to get around it that are becoming more common.” This means users are unknowingly giving their credentials away rather than being hacked in the traditional sense. 

In fact, many identity-related attacks are not even attacks in the technical sense. The threat actor simply logs in with the credentials they were given or found. This is one of the hardest methods to detect with traditional security solutions because there is no error message and no attack signature, just a login. 

Why do attackers prefer identities? There is no firewall to break through, and once inside, they look like legitimate users. The Identity Theft Resource Center 2024 report revealed that stolen credentials were the leading attack vector among 133 cyberattacks against publicly traded companies. Better cyber practices, including MFA and passkeys, could have prevented at least 196 compromises and more than 860 million victim notices. 

Why SMBs Are a Prime Target (Not an Afterthought) 

“We are too small to be a target” is one of the most dangerous assumptions in cybersecurity. Small and medium-sized businesses are attractive precisely because they are small. According to recent research, 43% of cyber incidents are directed at SMBs, who are attractive to attackers because they often have fewer security layers, smaller IT teams, more trust with less verification, and the same tools as enterprises, but with fewer controls. 

Common SMB realities that create vulnerabilities include: 

  • Tool sprawl without integration 
  • Shared admin accounts used for convenience 
  • Over-permissioned users with excessive access 
  • Cloud apps added without security review 
  • Cyber insurance pressure without clarity 

Most SMBs did not design insecure systems. Instead, they grew into them as technology needs evolved faster than security practices could adapt. 

Why Traditional MSP Security Models Fall Short 

Managed Service Providers (MSPs) have traditionally focused on uptime, ticket response times, and patch management. These are important, but they address infrastructure availability, not modern security threats. Net at Work explains the fundamental shift: “We focus on how modern attacks actually happen – through identities, access, cloud misconfigurations, and human behavior.” 

Gartner 2024 cybersecurity trends emphasize that as organizations move to an identity-first approach to security, the focus shifts from network security and traditional controls to Identity and Access Management (IAM), making it critical to cybersecurity and business outcomes. 

“Protection no longer has a defined edge as in the past traditional perimeter security solutions,” Kingsley explains. “In the past it was like defending a castle: get good walls in place and gate keep what comes in and out for the best defense. Today, there are software and online tools, remote employees, ‘bring your own device’ computers and phones, and multiple vendors that need access into systems. These situations are quite common and make the environment fully distributed.” 

Combined with software and devices synchronizing to other systems, your weakest link across your entire estate becomes a potential door into your environment. Having a handle on who has access to what and ensuring you protect that access is one of the best defensive methods today.  

Consider a user who reuses the same password across multiple systems. While the internal environment may be fully protected, a compromised user identity on a personal website could use the same credentials that user uses to access sensitive company information. A threat actor who obtains those credentials from the personal account—such as a social media breach—could simply log into the company environment without triggering traditional alarms. 

You can have healthy infrastructure and still be wide open to identity abuse. Security must be built into how access is granted, monitored, and removed. 

What Zero Trust Actually Means for SMBs 

Zero Trust is a security strategy built on a simple principle: trust nothing by default. Every user, device, and request must be verified before gaining access to resources, regardless of whether they are inside or outside your network. 

Kingsley offers a practical way to understand the difference: “The traditional method is trust everything behind the perimeter—once it gets in it is okay. Think of this like a traditional office building: you get past the turnstiles and the front desk, and you can choose any floor on the elevator and technically access any office once you are inside. Or you get a physical universal key that opens any door in the office.” 

“Zero Trust environments assume everything and everyone is unprotected and a potential risk, requiring more rigorous checks along the entire path,” Kingsley continues. “Think of this like some of the more modern or secure offices that make you check in at the desk and give you a keycard that only allows you to go to the floor it’s programmed for. Even though you are in the building, you have no access to the other offices or floors. Some of these even have individual locks on doors that only allow you to open certain doors, not all.” 

The core principles of Zero Trust include:  

  • Verify explicitly based on all available data points 
  • Use least-privilege access with just-in-time and just-enough-access policies 
  • Assume breach by minimizing blast radius and using analytics to detect threats 

For SMBs, this translates into practical implementations without enterprise complexity:  

  • Identity-first security making identity the primary control point,  
  • MFA plus conditional access based on risk signals,  
  • Least-privilege access giving users only what they need 
  • Continuous monitoring for abnormal behavior patterns. 

Zero Trust means no user, device, or request is trusted automatically, even if it is already inside your environment. It is a fundamental shift from asking “Are you on our network?” to asking “Can you prove who you are, that your device is secure, and that you need access to this specific resource right now?” 

Why Zero Trust Is the Direction the Industry Is Taking 

Gartner predicts the Zero Trust Network Access (ZTNA) market will soar from $575.7 million in 2021 to $3.99 billion in 2027, representing a compound annual growth rate of 31.6%. Similarly, Identity Access Management (IAM) is predicted to grow from $4 billion in 2021 to $11.1 billion in 2027. 

This rapid growth reflects fundamental shifts: NIST and CISA have published Zero Trust frameworks, major technology vendors are building Zero Trust capabilities directly into their platforms, cyber insurers increasingly require MFA and privileged access management for coverage, and emerging data protection laws align with Zero Trust principles. 

What This Looks Like in Practice for SMBs 

Zero Trust does not require a complete technology overhaul. For most SMBs, it starts with strategic use of tools you likely already have, combined with better processes and visibility. 

  1. Securing Microsoft 365 Identities
    Many SMBs already use Microsoft 365, which includes powerful identity security features that often go unused. Implementation includes enabling MFA for all users, configuring conditional access policies based on risk signals, implementing privileged access management for administrative accounts, and monitoring sign-in logs for suspicious activity. 
  2. Shared Admin Accounts
    Shared accounts represent one of the biggest identity risks. Zero Trust requires individual accountability through unique credentials for every administrator, time-limited elevation of privileges only when needed, and comprehensive audit trails. 
  3. Continuous Monitoring and Incident Response
    Continuous monitoring is essential for detecting compromise. This includes establishing baselines for normal behavior, setting alerts for anomalies, and regularly reviewing access logs. Zero Trust assumes breach will happen, so being prepared means having documented procedures for common scenarios. 

Security Is About People, Not Just Technology 

Identity attacks will continue to rise because they work. But here is the empowering reality: SMBs do not need enterprise-scale tools or massive security budgets to protect themselves. They need clarity, strategy, and managed execution. 

The shift to Zero Trust represents a fundamental change in how we think about security. Instead of building higher walls around a defined perimeter, we verify every interaction. Instead of trusting by default, we validate continuously. Instead of reacting to incidents, we assume compromise and minimize its impact. 

Net at Work represents this new approach to managed IT services. By focusing on how modern attacks actually happen—through identities, access, cloud misconfigurations, and human behavior—they deliver cybersecurity services built on an identity-first, Zero Trust strategy aligned with NIST, CISA, and Microsoft frameworks. This ensures security is proactive, measurable, and continuously validated. 

The question is not whether your organization will face identity-based attacks. The question is whether you will be ready when they come. With the right strategy, partnerships, and commitment, SMBs can build security postures that rival much larger organizations through smart implementation of Zero Trust principles that put identity at the center of everything. 

Key Takeaways: Action Items for IT Managers and Executives

Based on the research and best practices outlined in this article, here are the most critical steps you can take now to improve your organization’s cybersecurity posture: 

  1. Conduct an Identity Security Assessment. Audit who has access to what in your organization. Identify shared accounts, overly permissioned users, and former employees who still have active credentials. Many breaches exploit access that should have been revoked months or years earlier. 
  2. Implement MFA Everywhere with Conditional Access. Enable multi-factor authentication for all users, especially for administrative accounts and any systems containing sensitive data. If you are already using Microsoft 365, configure conditional access policies that consider risk signals like location, device compliance, and sign-in behavior. 
  3. Eliminate Shared Administrative Accounts. Create unique credentials for every administrator. Implement privileged access management that provides time-limited, audited elevation of permissions only when needed. This creates accountability and reduces your blast radius if credentials are compromised. 
  4. Deploy Security Awareness Training. Since 88% of breaches involve human error, regular training on phishing recognition, password security, and suspicious behavior is essential. Use simulated phishing campaigns to test and reinforce learning. 
  5. Start Your Zero Trust Journey with an Assessment. You do not need to implement everything at once. Begin with a Zero Trust readiness assessment to understand your current state and prioritize improvements. Evaluate your MSP relationship to ensure they focus on identity security, Zero Trust implementation, and continuous monitoring – not just traditional uptime metrics. 

Remember: Security is a journey, not a destination. The organizations that succeed are those that make continuous improvements in their security an integral part of their culture. 

Secure Your 3 Free Months of Net at Work Security

MongoDB “MongoBleed” Vulnerability Mitigation for Sage X3

by Joe Harris, Sage X3 Technical Team Lead, Net at Work

A recently disclosed MongoDB vulnerability (CVE-2025-14847), informally known as “MongoBleed,” impacts nearly all Sage X3 environments. The issue involves a specific MongoDB compression method that may allow an unauthorized client to access memory, and it has been actively exploited in the wild. While the risk is reduced for deployments where MongoDB is protected behind an internal firewall, it is not fully eliminated.  

To address this vulnerability, MongoDB recommends using alternative compression protocols or disabling compression entirely as a workaround. Sage has released hotfix update editions of MongoDB for versions 4, 7, and 8, covering multiple patch levels of Sage X3 V12. For customers who choose not to apply the hotfix—or for earlier Sage X3 versions where no hotfix will be released—Sage recommends updating the MongoDB configuration to disable the affected compression method. Net at Work has tested and validated this mitigation when implemented using the procedures outlined below. 

Please note that applying this configuration change requires restarting both the Syracuse and MongoDB components of Sage X3. This work should only be performed during a planned maintenance window when all users are logged out of the system. 

Part 1: Changes to the mongodb.conf file 

  1. Locate the file named “mongodb.conf” with your X3 instance’s MongoDB installation folder. It will be located in a subfolder named “config” 
    1. Example: Sage\MongoDBComponent\config 
    2. Different releases of the MongoDB component over the years have had different default naming conventions for the component folder. “MongoDBComponent” is the current standard and has been used consistently for the last several years and is the most common variant. If your X3 instance is older, your MongoDB folder may be named something like “MongoDB” or “SafeX3MongoDB” but it should still have a subfolder named “config” and a file named “mongodb.conf”.
      Mognobleed 1
  2.  Copy the file, naming the copy something like “mongodb_original.conf” to save as a backup in case you need to revert to the unmodified version
    Mognobleed 2

    1.  It is imperative that this backup be made before any alterations to the file take place. Any issue with the syntax and layout of the config file will cause MongoDB to not restart successfully. If you are unable to restart the MongoDB service and no solution to the issue can be found, rename this backup as “mongodb.conf” to bring the MongoDB service back online. 
  3. A successful update of this file will require an advanced text editor such as Notepad++. Sage and Net At Work recommend Notepad++ for its wide-ranging utility and typically install it on every X3 server as part of a standard deployment. If you do not have it installed on your MongoDB server, it can be downloaded for free from the publisher here. 
    1. Any other text editor that can display space, tab, and end of line symbols can be used instead if that is preferred, though the rest of these instructions assume use of Notepad++. It is NOT recommended to use standard Microsoft Notepad for this change, as it lacks functionality to validate space and tab formatting. 
  4. Open the “mongodb.conf” file in Notepad++ 
    1. It should look similar to this, with file paths and folder names specific to your instance:
      Mognobleed 3
  5.  On the upper tool bar, select View – Show Symbol – Show Space and Tab and View – Show Symbol – Show End of Line
    Mognobleed 4
  6.  Once these two views have been selected, your file should appear like the following:
    Mognobleed 5

    1.  You should see yellow dots denoting spaces, and the “LF” symbol at the end of each line 
      1. Some older versions of Notepad++ only allow you to select one additional symbol view or the other. If your version only allows this, download and install the latest version of Notepad++ and use it. Both character views need to be seen simultaneously 
  7. Within the section of the file headed as “net:” and below the line containing “ipv6: false” and above the line containing “tls:” add an additional line.
    Mognobleed 6
     

    1.  NOTE: The new line has been added with a TAB rather than spaces. That’s what the yellow arrow symbol in the screenshot above indicates. The tab now needs to be removed, and spaces added in its place:
      Mognobleed 7
  8.  Add the following on this line, without the quotation marks, but with the colon: 
    1. “Compression:”  
      1. The beginning of this entry should align precisely with the lines above and below it:
        Mognobleed 8
  9.  Add another line below “compression:” and above “tls:” 
    1. Repeat step 7 to remove the tab character and replace with spaces. This line should contain additional spaces so that it aligns with the lines below “tls:” such as “mode:” and “CAFile:”
      Mognobleed 9
  10.   Add the following text, without the quotation marks but including the colon 
    1. “Compressors:”
      Mognobleed 10
  11. Add the following text, depending on preference and situation, following “compressors:” and a single space (without quotation marks) 
    1. “Disabled” 
      1. Use this to disable all compression by MongoDB. This is Sage’s suggestion for all instances, and Net At Work’s recommendation if your MongoDB instance is on the same server as your Syracuse webhost component, and no other Syracuse webhosts are part of the solutionMognobleed 11
         
      2. “snappy,zstd” 
        1. Use this to allow MongoDB to continue to use the Snappy and ZSTD compression methods, while disabling the ZLIB compression method, which is the one affected by the security vulnerability 
        2. This allows MongoDB to continue using data compression, which it typically uses when communicating across the local network to remote Syracuse instances. Use this method if you wish to continue allowing MongoDB to use compression methods unaffected by the announced vulnerability 
      3. “snappy” 
        1. Some older versions of MongoDB and X3, such as X3 V11, do not include the ZSTD compression method and can only use the Snappy method. Use this and omit the “,zstd” if you are on X3 V11 or older and wish to continue to use data compression in MongoDB
          Mognobleed 12
  12.   Verify that the correct spacing, alignment, and line returns are in place so that it matches the example screenshots exactly. Misaligned spacing, incorrect positioning, or the presence of tabs instead of spaces will prevent MongoDB from running 
  13. Save the updated file 
    1. Note that the updated configuration will only go into effect once the MongoDB service has been restarted. It does not go into effect immediately. 

Part 2: Shutdown of X3 and Components

  1. The following procedure is for how to perform a clean shutdown of X3. This should be done prior to restarting MongoDB to pick up the modifications to the config file to mitigate the vulnerability. If you are already familiar with this process, you can skip to section three. 
  2. Log into X3 and access your Production folder. 
  3. Use the compass icon above to get to the X3 Menu 
  4. Navigate to Usage>Batch Server > Accounting tasks
    Mognobleed 13
  5. Click the Deactivate button
    Mognobleed 14
     

    1.  Use “X”  the  button to back out of the Accounting task screen 
  6. Navigate to Administration > Endpoints > Batch server
    Mognobleed 15
  7.  Click on the 3 vertical dots and select “Stop All” to stop the batch server
    Mognobleed 16
  8.  Stop WEB Pool Services
    Mognobleed 17
     

    1.  X3 -> Administration -> Administration -> Web services -> Classic SOAP pools Configuration 
    2. Select the triple dots on each of the listed pools that have the \/ icon (indicating that they are running) next to Alias and click StopMognobleed 18
       

      1.  Click the Trashcan icon on each of the notification windows once each has confirmed stopped to clear the message from your screen. 
  9. Connect to the Windows desktop of your Syracuse server (or servers) 
  10. Open Services.msc 
  11. Stop the Syracuse service 
    1. For versions of X3 prior to V12 P36, there are two services, one named “Safe X3 Agent Syracuse Server NODEx” and one named “Safe X3 Syracuse Server NODEx” 
      1. The “x” in the names above represent a number, usually 0 but sometimes 1, 2, 3, 4, etc.
        Mognobleed 19
    2.  Stop the service named “Safe X3 Agent Syracuse Server NODEx” 
    3. This service controls the “Safe X3 Syracuse Server NODEx” service as well – stopping the Agent service will also stop the NODEx service. 
    4. If this service hangs up during the stop procedure, open Task Manager, go to the Details tab, select each instance of the “node.exe” process, and click End Task
      Mognobleed 20

      1.  ONLY perform step 2 above if the two Syracuse services do not successfully stop on their own 
    5. For versions of X3 after V12 P36, there is only one service named “Safe X3 Syracuse Server NODEx” 
      1. The same procedure as above can be performed while stopping only this service 
  12. If you have multiple Syracuse host instances in your X3 solution, repeat step 23 on all servers prior to proceeding with shutdown of MongoDB 
    1. If you also have a “Sage X3 Services” instance, stop this as well before proceeding 

Part 3: Stop and Restart of MongoDB Service

  1. Once all Syracuse and associated processes have been stopped on all servers, it is safe to restart MongoDB. 
    1. Stop the service named “Safe X3 MongoDB MONGOxx”
      Mognobleed 21
  2.  Start the Safe X3 MongoDB MONGOxx service 
    1. If you get an error when attempting to restart this service, it is likely that there is a configuration, layout, or bad character in your revised “mongodb.conf” file 
    2. Re-verify the changes made in section I above 
    3. If you are still unable to restart MongoDB, change the name of your revised “mongodb.conf” to something like “mongodb_new1.conf” and rename the backup copy created in step 1 as “mongodb.conf” 
      1. This will rollback the config change made and will not mitigate the vulnerability, but it will make X3 functional again. 
  3. Once the Safe X3 MongoDB MONGOxx service is running again, you can restart all Syracuse services on all servers 
    1. Also restart Sage X3 Services if present after all Syracuse services have been restarted 
  4. Once Syracuse has restarted successfully, log back into X3. 
    1. Check that the batch server and all SOAP pools that are set on Auto Start have started running again. They are supposed to after a Syracuse restart. 
    2. If they did not, click the three dots as in section II above next to their names and click “Start”
      Mognobleed 25 Mognobleed 24 Mognobleed 23 Mognobleed 22
    3.  Go back into Usage > Batch Server > Accounting tasks  
    4. Click the Accounting task button
      Mognobleed 26
    5. Click the Activate button
      Mognobleed 27
    6.  Use “X” the  button to back out of the Accounting task screen 

Upon completion of these steps, your Sage X3 environment should be successfully mitigated against the MongoBleed vulnerability. If you encounter any issues, we recommend reviewing each step carefully to confirm configuration accuracy. Should you require assistance at any point, the Net at Work Sage X3 technical team is available to support you. 

 

A Stronger Network Behind Cabrini Green Legal Aid’s Mission

Cabrini Green Legal Aid (CGLA) has always been close to the people it serves. The organization’s roots trace back to Chicago’s Cabrini Green neighborhood, where founder Chuck Hogren and other attorneys listened to people talk about the charges, records, registries, and legal barriers that followed them long after a case was over. What began in a church and in conversations with people from the neighborhood grew into a legal aid organization with a clear purpose: help people move forward when the legal system has made that harder than it should be.

Today, CGLA continues that work across Chicago and Illinois, serving people impacted by the criminal legal system through legal services, social support, advocacy, and policy work. Its attorneys and staff help with issues tied to criminal records, housing, family stability, and other matters that can affect a person’s ability to work, live safely, care for family, and rebuild.

THE WORK BEHIND THE WORK

For Rocky Harder, Operations and IT Manager at CGLA, that mission is personal. “Working here, you’re part of something bigger,” Rocky says. “We’re helping people whose lives are being impacted in real ways.”

Carrying that mission forward is a team of about 50 employees, including roughly 30 attorneys. The organization receives dozens of calls each day from people seeking help. Each call represents someone navigating a stressful moment, often with legal, personal, and financial stakes attached.

When an attorney needs a file, it has to be accessible. When a new employee joins, they need a laptop, accounts, and permissions ready to go. When staff communicate with clients, partners, courts, donors, and community members, those systems need to be secure and reliable. And when the organization handles sensitive legal and personal information, the right access controls and security practices matter deeply.

That is why CGLA turned to Net at Work Managed IT Services for support that could be responsive, secure, and steady enough for the work behind the mission.

For Rocky, the goal boils down to making sure technology supports the work rather than slowing it down. “Our lawyers and staff rely on technology,” he says. “They need to access information, they need to communicate, they just need things to work.”

WHEN SUPPORT BECOMES ANOTHER BURDEN

CGLA had worked with another managed services provider for years, but the relationship had become increasingly difficult. Support was slow and communications were inconsistent. Then, a major move from physical servers to SharePoint and OneDrive became far more complicated than expected.

CGLA’s move to the cloud was supposed to take about five months. Instead, it stretched to 18 months and was still not fully resolved.

For CGLA, the problem was not simply the delay. The organization needed to preserve folder permissions and access controls as files moved into the cloud. Instead, Rocky says permissions became messy and unreliable. Some staff could not access what they needed, while others could see information they should not.

For any organization, that kind of confusion creates frustration. For a legal aid nonprofit handling sensitive client information, it also creates risk.

Rocky found himself doing more and more internally because he did not fully trust the provider to handle it. He created onboarding sheets. He walked new employees through setup steps. He managed access questions. He fielded staff support issues that should have gone elsewhere.

The whole point of working with a managed services partner was to reduce that burden. Instead, CGLA was spending too much time managing the partner. “We really wanted a managed services provider and a strong operations presence,” Rocky says. “We needed people to be able to get what they need and keep moving.”

NO GAP IN SUPPORT

CGLA’s leadership was already familiar with Net at Work, and the organization began to take a more serious look at making a change. The timing was delicate. CGLA was still associated with its previous provider, and moving from one managed services provider to another can feel risky even in the best circumstances.

Net at Work understood that CGLA was coming from a difficult experience. They reviewed what CGLA had, mapped the services it needed, and helped create a clear path forward. Just as important, Net at Work provided support from day one.

CGLA could not afford a service gap while contracts, tools, systems, and responsibilities changed hands. Staff still needed help and new employees still needed to be onboarded. Meanwhile, security still had to be monitored. The organization’s work could not pause while the technology relationship caught up.

Net at Work brought a dedicated team and a practical approach: help CGLA get through the transition, stabilize the environment, and rebuild confidence. “They said, ‘We’ve got you,’” Rocky says. “That was huge.”

A DIFFERENCE STAFF COULD FEEL

The difference showed up quickly. Onboarding is one example. CGLA uses Rippling heavily for HR and operations, and Net at Work helped make the technology side of onboarding far smoother. Instead of Rocky building step-by-step instructions and walking employees through each part of the process, Net at Work coordinates device setup, shipping, tracking, and account readiness.

Now, new employees can receive laptops already configured and ready to use. Staff notice. Rocky does, too. “People love that new devices are ready to go,” he says. “I get fewer of those calls now.”
The change also gave employees a trusted support option. Instead of every IT question landing on Rocky’s desk, staff can contact Net at Work directly and expect a responsive, human answer.

That is especially valuable in an organization where internal roles carry significant weight. CGLA’s attorneys and staff are working with people in stressful situations. They need technology support that feels calm, competent, and quick.Rocky describes it as “white glove” service for the attorneys and staff. “They know they can call Net at Work,” he says. “There’s a team of humans on call.”

HOURS INSTEAD OF WEEKS

One of the clearest early tests came during CGLA’s spring fundraiser, Lights, Camera, Legal Aid!, an event that brings the community together in support of the organization’s work.

The year before, CGLA had needed technology support for a similar event, including laptops, MiFi, and credit card machines for registration and merchandise sales. The previous provider took about three weeks to prepare the setup. But when the team arrived at the event, the configuration failed because the work had been done on a nonlocal drive, leaving staff unable to sign in.

It was exactly the kind of preventable problem that makes an event team anxious. With Net at Work, Rocky asked for a similar setup: three computers and an iPad ready for event use. This time, the work took about three hours. Everything was ready to go.

For Rocky, the contrast was hard to miss. This was still early in the transition, and he admits he was hopeful the event setup would work the way it should. It did. That moment gave him confidence that CGLA had made the right move.

STRONGER PROTECTION, LESS GUESSWORK

Security was another important factor in the decision to work with Net at Work. CGLA had seen increasingly sophisticated email scams and other attempts that made cybersecurity feel immediate rather than theoretical.

The organization needed stronger protection, but it also needed security support that employees could understand and use. Rocky knows that technology tools matter, but user awareness matters too.

Net at Work helped CGLA improve its phishing reporting and security training. When employees use the phishing button, Rocky receives alerts and can see how staff are responding. Net at Work also brings current cybersecurity knowledge to the relationship, including awareness of how AI is making scams more convincing and harder to spot. “I know they’ve improved our security,” Rocky says. “People are getting smarting about what to look for.”

He appreciates that Net at Work treats security as an ongoing practice rather than a one-time setup. The cybersecurity team is available, engaged, and up to date on emerging threats. “I’ve seen it working,” he says. “They trained our staff too, because so much of it is on the user.”

MORE VALUE, MORE TRUST

CGLA chose Net at Work’s Managed IT Services offering with cost in mind, but the decision was never only about price. Rocky wanted value, responsiveness, better protection, and a partner he could trust enough to stop holding every piece of IT himself.

“Net at Work gives us exactly what we need: responsive support, stronger protection, and a team our staff can trust,” Rocky says. “They’ve taken a lot off my plate, and that gives us more time and confidence to focus on the work we’re here to do.”

Net at Work delivers stronger support at a more cost-effective rate than CGLA had before. But the larger value is the trust the organization is rebuilding around technology.

A NETWORK FOR THE WORK AHEAD

CGLA’s work has always been about helping people move through systems that can feel overwhelming, confusing, and unforgiving. The organization brings legal knowledge, social support, advocacy, and persistence to people who need a way forward.

Net at Work plays a quieter role in that mission, but an important one. It helps keep the systems behind CGLA’s work stable, secure, and responsive. It gives Rocky and his team more confidence. It gives staff a better experience. And it helps make sure technology does not become one more obstacle in the path of the work.

Rocky describes CGLA’s spirit with a little humor and a lot of pride. “We’re kind of fighting against the machine,” he says. “So it’s nice to have a network that can help with our network.”

You Passed the Audit. Are You Actually Secure?

Healthcare Cybersecurity: Practical Steps to Stay Secure

Your healthcare organization may have passed its audit, but that does not automatically mean your environment is secure, resilient, or prepared for what comes next. Many providers and healthcare organizations meet compliance requirements while still carrying hidden infrastructure and security gaps across identity, remote access, email, endpoints, segmentation, backup, and legacy systems.

Join Paul Edwards from SonicWall and Chad Copeland from Net at Work for this recorded web event and candid discussion on healthcare cybersecurity, infrastructure blind spots, and the controls that actually improve resilience.

Topics Include:

  • Breaking down the most common risks that remain after audit season ends
  • Explaining why “compliant” and “secure” are not the same thing
  • Exploring where healthcare IT teams are still exposed
  • How gaps show up in day-to-day operations
  • What practical steps leaders can take to reduce risk without overwhelming already stretched teams

What Modern Managed IT Should Actually Deliver in 2026

Managed IT expectations have evolved, but many service models have no Traditional MSP engagements built around ticket resolution and reactive troubleshooting are no longer enough to support today’s mid-market organizations. As businesses face increasing complexity, distributed workforces, AI adoption, and heightened risk exposure, managed IT must move beyond maintenance and into strategic enablement.

In this session, we’ll introduce the MSP 2.0 model, a modern approach to managed IT that prioritizes security-first architecture, proactive visibility, infrastructure resilience, identity governance, automation, and long-term technology alignment.

Attendees will gain practical tools to evaluate their current managed IT model and determine whether it is simply maintaining uptime or actively driving operational maturity and business value.

By the end of this session, participants will be able to:

  • Differentiate between traditional MSP service models and modern MSP 2.0 frameworks.
  • Identify critical gaps in reactive, ticket-based IT support structures.
  • Evaluate how security, automation, and identity governance should integrate into managed IT delivery.
  • Assess whether their current IT partnership aligns with strategic business objectives.
  • Outline the next steps needed their organization can take to modernize its managed IT approach.

The Cyber Emergency Survival Kit: The Small Business Owner’s Step-by-Step Guide to Responding to Cyber Attacks

Cyber incidents rarely stay contained for long.

That is why we created the Cyber Emergency Survival Kit — a practical resource for SMB and mid-market organizations that want to be better prepared before an incident happens.

Inside, you will find guidance on:

  • what to do in the earliest stages of a cyber incident
  • common response mistakes that can make things worse
  • how to coordinate internal response efforts more effectively
  • and how to assess whether your business is truly prepared

Whether you are building your response plan for the first time or looking to strengthen what you already have, this guide is designed to help you respond with more clarity and less chaos.

Zero Trust for the Real World: How SMBs Can Reduce Risk Without Adding Complexity

Cybersecurity has become more complex, especially for small and mid-sized organizations. Identity-based attacks now outpace traditional network breaches. Email remains a primary entry point. Cyber insurance requirements are getting stricter. And many organizations are overwhelmed by security tools that don’t always translate into better outcomes.

In this session, we’ll break down what Zero Trust actually means in practice… without vendor buzzwords or enterprise-only complexity. Attendees will learn how a pragmatic, identity-first approach can help organizations improve visibility, strengthen incident readiness, and reduce risk without overhauling their entire environment.

This webinar is designed for IT leaders, executives, and security stakeholders who want clarity, not another list of products.