Ransomware in 2026: backups first, the rest – later

For years, the standard ransomware advice was "make sure you have backups." But for ransomware in 2026, that advice is now incomplete in a way that's costing manufacturers weeks of downtime and, in some cases, the ransom payment they were trying to avoid.

The reason is: ransomware operators have updated their playbook. Before they encrypt anything, they find your backups. Then they encrypt or destroy those first.

According to Veeam's 2025 Data Protection Trends Report, over 93% of ransomware attacks now specifically target backup repositories as part of the attack sequence. The logic is straightforward: if the victim can restore quickly, they don't pay. So the attackers remove that option before they reveal themselves. While this trend isn't new, ransomware threats in 2026 follow the same playbook.

The IBM X-Force Threat Intelligence Index 2026 documents this as a deliberate strategic shift, which the report calls "recovery denial." Attackers are systematically targeting backup infrastructure, identity services, and virtualization management layers specifically to eliminate the victim's ability to recover without paying.

What "recovery denial" looks like in practice

The attacker gains initial access typically through a phishing email, a compromised VPN credential, or an unpatched network appliance. Then they spend days or weeks moving laterally and mapping the environment. They're not looking for the crown jewels yet. They're looking for the backup server.

If your backup server is on the same network as your production environment and uses the same or similar credentials, they find it. They encrypt it first, or they delete the backup catalog, or they compromise the backup software console with admin access. By the time the ransomware payload executes across your production systems, your recovery option is already gone.

The three questions that determine your exposure

Whether your backups survive a ransomware attack comes down to three things. As ransomware by the end of 2026 is expected to become more sophisticated, these questions take on a critical new importance.

1. Are they reachable from the production environment?

Backups stored on a network-attached share accessible from the same domain, or a backup server that uses the same admin credentials as your production servers, sit inside the blast radius. An attacker who has compromised your production environment has a path to them.

The standard that carriers and auditors now require is immutable backups (data that cannot be modified or deleted for a defined retention period, enforced at the storage level) or air-gapped backups (physically or logically disconnected from the production network), and preferably both.

2. Do backup admin accounts share credentials with production accounts?

This is the most common gap. The backup software console is protected by a local admin account using the same password rotation schedule (or lack thereof) as everything else. An attacker with domain admin on your production environment has a short path to the backup console.

Backup infrastructure should be managed through dedicated accounts that exist nowhere else: separate credentials, separate MFA, separate access paths. If compromising your production admin account also means compromising your backup admin account, you have one layer where you need two.

3. Has a restore actually been tested?

This is distinct from the first two, but it matters for a different reason. Even backups that are properly isolated can fail to restore if the process has never been rehearsed. The most common scenario: backups have been running nightly for two years, nobody has performed an actual restore test, and when ransomware hits, the restore process fails or takes five times longer than expected because the team is running it for the first time under pressure.

Carriers now require documented restore tests, timestamped, with screenshots, completed within the last 90 days, not a backup job completion log.

How to find out where you stand

We built a short self-assessment (eight questions, two minutes) that scores your backup architecture against the criteria that ransomware operators are specifically targeting and that cyber insurance carriers are specifically requiring.

It doesn't ask for any system access or sensitive information. It asks about your architecture decisions. At the end, you get a score (Protected, At Risk, or Exposed) with a breakdown of which specific gaps your setup has.

If you'd rather talk through it directly, we can do a free 20-minute backup architecture review for manufacturers in the area. No pitch. Just a clear picture of where you stand before it matters as ransomware strategies in 2026 continue to shift.

Free 2-Minute Assessment
Is Your Backup in the Blast Radius?

Over 90% of ransomware operators target backup infrastructure first. Score your architecture against the exact criteria they exploit — and find out where you stand.

Take the Assessment

8 questions · 2 minutes · Instant score

Wisconsin Manufacturers Under Attack: What the Cyber Threat Data Is Telling Us

The cybersecurity threats Wisconsin manufacturers face are no longer limited to stolen files or suspicious emails. When ransomware hits a production environment, it can escalate fast: CNC machines stop receiving job files, shipping slows down, ERP data becomes unavailable, supervisors lose visibility into work orders, and the plant floor starts making decisions with incomplete information.

That is why manufacturing has become such an attractive target. Attackers know many manufacturers run lean IT teams, older production systems, remote vendor connections, and tight delivery schedules. A bank can freeze transactions. A manufacturer may have to stop a line.

National threat data now backs up what many Wisconsin IT directors already feel: manufacturing is under heavier pressure than most industries. IBM reported that manufacturing was the most attacked industry for the fourth consecutive year in 2024, with the highest number of ransomware cases among industries it tracked.

 

The Numbers: What the Threat Data Means for Wisconsin Manufacturers

 

The clearest takeaway from the 2023–2025 data is this: ransomware is now an operations problem, not just an IT problem.

 

Dragos documented 1,693 ransomware attacks against industrial organizations in 2024, an 87% increase over the prior year, and found that 75% of ransomware incidents it responded to caused a partial OT shutdown while 25% caused a full OT shutdown.

Dragos 8th Annual OT Cybersecurity Year in Review

For a Wisconsin manufacturer, that can mean delayed shipments, overtime recovery, missed contract obligations, and customer confidence problems.

Verizon’s 2025 manufacturing breach data also shows why mid-sized manufacturers are exposed. In manufacturing breaches, ransomware appeared in 47% of cases, stolen credentials in 34%, exploited vulnerabilities in 23%, and phishing in 19%. Verizon also found that more than 90% of breached manufacturing organizations in its sample were SMBs with fewer than 1,000 employees.

That matters because many Wisconsin manufacturers operate exactly in that range: large enough to be valuable, but not large enough to run a 24/7 security operations center. Zscaler’s 2025 ransomware research found manufacturing was the most frequently hit sector in its data, with 1,063 attacks over the prior year, while U.S. victims accounted for 50% of ransomware attacks globally.

Locally, the 2023 ransomware attack involving Fincantieri Marinette Marine showed what that risk looks like on the shop floor. USNI News reported that the attack affected servers used to feed instructions to CNC manufacturing machines and knocked some systems offline for several days.

 

How Attackers Get In

 

 

Most manufacturing ransomware attacks do not start with movie-style hacking. They start with access that should have been harder to use, easier to monitor, or closed months ago.

 

1. Phishing and Credential Theft

A phishing email in a manufacturing business rarely looks like a generic scam. It may look like a supplier invoice, a freight update, a customer drawing, a quote request, or a Microsoft 365 login prompt sent to a plant manager rushing between meetings.

Once attackers capture a password, they try to log in like a real employee. IBM reported that stolen credentials surged 71% year over year and represented 30% of incidents it responded to in 2023, tied with phishing as the top infection vector.

In a plant environment, that one login can lead to email access, file shares, ERP systems, CAD files, or maintenance documentation. If multi-factor authentication is missing from VPN, admin accounts, or email, the attacker’s job gets much easier.

 

2. Unpatched VPN and Remote Access

Manufacturers rely on remote access for good reasons. Engineers connect after hours. Vendors support equipment. IT teams troubleshoot without driving to the plant. The problem is that VPNs, firewalls, and remote access portals are some of the first doors attackers check.

Verizon’s 2025 SMB snapshot noted that exploitation of vulnerabilities has become the most common initial access vector in ransomware breaches, driven heavily by attacks on perimeter devices.

For manufacturers, the risk is not just “someone got into the network.” The risk is that an old VPN account, unpatched firewall, or shared vendor login gives an attacker a path toward the systems production depends on.

 

3. Vendor Access

Manufacturing runs on outside access: machine vendors, ERP consultants, managed software providers, maintenance contractors, logistics platforms, and sometimes customers with portal access. Each relationship may be necessary. Each one also creates a door.

The issue is usually not that vendors are careless. It is that access is often granted once and reviewed rarely. A vendor account may stay active after a project ends. A shared login may exist because “that’s how the machine vendor set it up.” A remote support tool may be installed on a workstation nobody has inventoried.

When attackers find those paths, they do not need to break down the front door. They walk in through a service entrance.

 

4. IT/OT Convergence

The phrase OT IT security manufacturing sounds technical, but the business issue is simple: the office network and production network are now more connected than they used to be.

ERP talks to scheduling. Scheduling talks to production. Engineers push files to machines. Supervisors pull reports from plant-floor systems. Remote monitoring tools collect equipment data.

That connectivity helps manufacturers move faster, but it also gives attackers more ways to turn an IT incident into an operations event. The Fincantieri Marinette Marine incident is a practical example: the impact was not limited to email or back-office disruption; it touched networked operations tied to CNC workflows.

 

The 5 Gaps Showing Up Again and Again

 

 

The pattern in the data is not that manufacturers are being beaten by exotic attacks. The pattern is that attackers keep finding the same gaps: access, patching, documentation, segmentation, and recovery.

“The future of the Industrial Heartland depends on its ability to defend the digital code that now governs its physical machines.”

Here are the five gaps Wisconsin manufacturers should pay attention to first.

1. Incomplete asset inventory.

You cannot protect what you cannot see. Many manufacturers know their servers and laptops, but not every vendor tool, engineering workstation, old switch, remote access appliance, or production-connected PC.

2. Weak identity controls.

Shared accounts, stale users, missing MFA, and standing admin rights give attackers room to move. This is especially risky for executives, IT admins, engineers, and vendor accounts.

3. Unclear patch ownership.

IT may patch Windows systems, but who owns firmware, firewalls, VPNs, HMIs, PLC support stations, and vendor-managed equipment? When nobody owns the patching calendar, attackers benefit.

4. Flat networks between IT and OT.

If ransomware can spread from a compromised office workstation into production-adjacent systems, the business has a segmentation problem. Segmentation is not about making the plant harder to use. It is about making a bad day smaller.

5. Untested recovery plans.

Backups are helpful only if they restore quickly and completely. Cyber insurers and customers increasingly expect evidence: restore tests, logs, incident response plans, and documented roles. Current cyber insurance renewal guidance, for example, focuses on MFA, EDR, backup restore testing, and evidence gathering as practical readiness steps.

For defense suppliers, this also connects to compliance. The Department of Defense CMMC program rule became effective December 16, 2024, and phased CMMC implementation began November 10, 2025. For a CMMC Wisconsin manufacturer, cybersecurity documentation is no longer just a best practice. It can affect contract eligibility.

 

What IT Directors Are Doing About It

 

Many Wisconsin manufacturers do not need to replace their IT teams. They need to stop asking a small internal team to do every job at once.

That is where the co-managed IT model is gaining traction. Internal IT keeps ownership of the business: users, systems, plant priorities, ERP projects, production needs, and leadership communication. A co-managed cybersecurity partner adds the pieces that are hard to staff internally, such as continuous monitoring, patch compliance tracking, endpoint detection, log review, incident response planning, backup validation, and security documentation.

This model works well for manufacturers because it respects how plants operate. Production cannot wait for a generic enterprise security program. IT needs help that fits maintenance windows, vendor realities, older systems, and uptime requirements.

The best co-managed relationships also produce evidence. That matters for cyber insurance, customer audits, CMMC readiness, and executive reporting. Your co-managed IT partner can provide you with help and documentation around MFA, role-based access, incident response plans, backup testing, vendor controls, and any other cybersecurity policy controls are needed. Here you can find an Ultimate Compliance Checklist we put together for Milwaukee businesses.

 

The Warning Is Clear, but So Is the Path Forward

 

The 2023–2025 threat data tells a clear story: manufacturers are high-value ransomware targets because downtime hurts immediately. For Wisconsin manufacturers, this is not a distant national trend. The local and sector-level evidence shows attackers are already focused on production-heavy environments, remote access, stolen credentials, vendors, and IT/OT weak spots.

The good news is that the biggest improvements are practical. Start with visibility. Lock down identity. Patch the systems attackers actually use to get in. Segment production from office IT where it matters. Test recovery before a crisis. Document the work so leadership, insurers, auditors, and customers can see progress.

 

 

Book a cybersecurity gap analysis consultation here

AI Is Already in Your Manufacturing Operation. Here’s the Security and Compliance Risk Most IT Teams Haven’t Addressed.

AI governance for manufacturing security is not a future planning topic anymore. It is already showing up in the daily habits of engineers, estimators, production managers, buyers, HR teams, and customer service staff.

The warning sign came early. In 2023, Samsung reportedly discovered that employees had entered sensitive company information into ChatGPT, including source code used to debug semiconductor systems and internal meeting content. Cyberhaven’s analysis later cited that incident as an example of what happens when helpful employees use public AI tools before policy catches up.

For a manufacturer, the equivalent is not hard to picture.

An engineer pastes a customer drawing into ChatGPT and asks it to summarize the tolerances. A project manager uploads contract language to generate a supplier checklist. A defense subcontractor copies Controlled Unclassified Information into an AI tool to rewrite a status update. A maintenance technician uses an AI browser extension to troubleshoot a recurring equipment fault and accidentally exposes production data.

Workers are not out to cause a breach, they are just trying to move faster.

That is the problem. AI is already in the workflow, but many IT policies still treat it like an optional tool instead of a new data path.

The AI Tools Already in Your Environment

Most manufacturers do not have one AI problem. They have three.

1) Sanctioned AI (IT knows about it)

This is usually Microsoft Copilot (or “Copilot Chat”) because it’s bundled into daily work: Teams, Outlook, Word, Excel.

The good news: Microsoft positions Microsoft 365 Copilot as operating within the Microsoft 365 service boundary, and states prompts/responses and Microsoft Graph data aren’t used to train the underlying foundation models.


The catch: “inside the boundary” doesn’t automatically mean “safe for your business.” If you’ve got overshared SharePoint libraries, messy permissions, weak labeling, or no retention plan for Copilot interactions, Copilot can still surface things to people who shouldn’t see them (because they already had access somewhere).

Translation: Copilot can amplify whatever content hygiene you currently have—good or bad.

2) Unsanctioned AI (IT doesn’t know about it)

This is where things get spicy:

  • ChatGPT / Claude / Gemini accounts created with personal emails
  • “Just one quick question” to a public AI website
  • AI browser extensions that read pages, emails, or clipboard content
  • Consumer “meeting notes” tools used for Teams/Zoom recaps

And it’s not a rare edge case. Cyberhaven found that sensitive data made up 11% of what employees pasted into ChatGPT in their analysis.

In manufacturing terms, 11% isn’t “a few mistakes.” It’s a steady drip of drawings, supplier details, quotes, quality issues, and customer conversations—leaving your environment one paste at a time.

3) Embedded AI (it shows up inside other tools)

Even if you block public chatbots, AI can still be “baked into” tools you already run:

  • ERP “AI insights” features
  • Maintenance diagnostics that use AI to predict failures
  • AI-assisted design features in engineering software
  • Vendor portals that now include “smart assistants”
  • Security tools using AI to summarize alerts

This category is easy to miss because it doesn’t look like “someone using AI.” It looks like a feature update.

The first step most teams skip: an AI usage audit

Before you write policy, you need visibility. A practical starter audit looks like:

  • Review M365 usage: where Copilot is enabled, for whom, and which apps
  • Look for “shadow AI” patterns in web proxy/DNS/firewall logs
  • Inventory browser extensions (managed endpoints)
  • Identify which SaaS/ERP/engineering tools have embedded AI features turned on
  • Ask department leads one blunt question: “Which AI tools are people using to do their jobs faster?”

If you don’t know what’s in use, you can’t govern it.

For a manufacturing IT director, the lesson is direct: before you can govern AI, you need to know where it is. That means approved tools, unapproved tools, browser extensions, SaaS features, vendor portals, and operational platforms.

The Compliance Angle: CMMC, CUI, Copilot, and Insurance

AI governance becomes more serious when the manufacturer handles regulated data.

For defense suppliers, the issue is not just “Should employees use AI?” The sharper question is: Can we prove that CUI is not entering AI systems that are outside our authorized environment?

If you’re a manufacturer, compliance risk from AI usually shows up in one of four places: CUI handling, tenant boundaries, insurance renewal, and frameworks you can point to when leadership asks “what good looks like.”

CUI spillage risk for DoD suppliers (CMMC reality)

If you handle CUI, you’re already living inside a rule set that expects discipline around where that information is stored, processed, and transmitted.

  • NIST SP 800-171 is the baseline “protect CUI in nonfederal systems” playbook many DoD contractors align to.
  • DoD’s CMMC Level 2 assessment guidance ties certification to regulatory requirements and assessments for those environments.

So here’s the practical problem with generative AI:

If an employee pastes CUI into an unsanctioned AI tool or uploads a controlled drawing into a consumer “AI helper”, you’ve got CUI leaving the controlled environment. Whether that becomes a reportable incident depends on your contracts and incident response requirements, but it’s never a good day.

This is why “CMMC AI tools” is becoming a real discussion internally: not because AI is banned, but because CUI boundaries are non-negotiable.

Microsoft Copilot: commercial vs. GCC / GCC High / DoD

A lot of manufacturers are in a mixed reality:

  • Corporate runs a commercial Microsoft 365 tenant
  • Defense work requires tighter controls, sometimes government cloud alignment

That does not mean Copilot is automatically unsafe. It means Microsoft Copilot manufacturing security depends on tenant type, data type, configuration, permissions, labels, logging, and user behavior.

Microsoft’s guidance on government cloud environments explicitly calls out that GCC High is intended for organizations handling CUI and that Copilot in government clouds operates within the government tenant, with prompts/responses remaining in that environment.

Also important: Microsoft states Microsoft 365 Copilot prompts/responses aren’t used to train foundation models and that Copilot only surfaces data users have permission to access.

But here’s the compliance gotcha:
Even if Copilot is “secure,” your environment choice still matters. If your contract requires CUI to live in a specific enclave (and your security plan is built around that), you don’t want CUI “handled casually” in the wrong tenant just because it’s convenient.

A framework you can actually cite: NIST AI RMF

When leadership asks, “What are we aligning to?”, the NIST AI Risk Management Framework (AI RMF 1.0) gives you a credible backbone with four core functions: Govern, Map, Measure, Manage.

You don’t have to implement a big enterprise program on day one. But referencing NIST AI RMF helps you:

  • justify why governance is necessary,
  • prioritize what to tackle first,
  • and document decisions in a way auditors and insurers understand.

Cyber insurance: AI is starting to show up at renewal

Cyber insurance is shifting from “do you have MFA?” to “prove you can manage modern risk.” HUB International notes that cyber insurers will ask how an insured uses AI, what types of data AI tools are trained on or regularly handle, whether the company complies with AI laws and regulations, and what first- and third-party liabilities may apply.

We’re seeing more discussion of AI exclusions and “AI-connected” claim language in policies and renewals.

What does that mean for an IT Director at a manufacturer?

At renewal, don’t be surprised by questions like:

  • Do employees use generative AI tools for business work? Which ones?
  • Do you have an AI acceptable use policy your workforce is trained on?
  • Can you show controls for data loss prevention (DLP) and logging around AI use?
  • Do you review third-party AI features in SaaS tools (vendor risk)?

For many manufacturers, the honest answer is still “not yet.”

NIST gives teams a useful starting point. The NIST AI Risk Management Framework is designed to help organizations that design, develop, deploy, or use AI systems manage AI risk and support trustworthy AI use. For a small IT team, that does not have to become a 200-page governance project. It can start with inventory, classification, acceptable use, monitoring, training, and incident response.

Four Risk Scenarios That Should Feel Familiar

The risk is easier to manage when it sounds like real work instead of abstract compliance language.

1. The engineer using public AI to speed up a drawing review

An engineer receives a customer print with tight tolerances and special handling notes. The job is urgent. Instead of manually summarizing the requirements, they paste sections into a public AI tool and ask for a checklist.

The output is useful. The exposure is the problem.

That prompt may include customer IP, controlled technical data, export-sensitive information, or contract-specific requirements. If the company later needs to prove that customer data stayed inside approved systems, there may be no clean audit trail.

2. The production manager using AI to clean up a customer update

A production manager wants to write a clearer explanation for a delayed shipment. They paste the customer’s email thread, internal notes, part numbers, job status, and quality issue into an AI tool and ask it to “make this sound professional.”

The issue here is not the polished response. It is everything that went into the prompt: customer identity, production timing, defect details, order status, and potentially sensitive commercial terms.

The X-Force Threat Intelligence Index 2026 reinforces why identity and data exposure matter. X-Force found credential harvesting and data leaks were leading impacts in 2025, and attackers continued to rely on stolen credentials, misconfigured access, and weak authentication to blend into normal business activity.

3. The CMMC supplier using AI to simplify CUI-heavy language

A defense supplier receives documentation from a prime contractor. An employee copies several paragraphs into an AI assistant and asks, “Can you explain this in plain English?”

That single prompt could create a CUI handling issue. The employee did not download malware. They did not click a phishing link. They simply used a convenient tool to understand a difficult document.

This is why an AI acceptable use policy manufacturer teams can actually follow is so important. Employees need clear rules for what is allowed, what is prohibited, and what to do when they are unsure.

4. The vendor AI feature no one vetted

A maintenance platform adds an AI troubleshooting feature. A technician enters machine symptoms, downtime history, error codes, and notes from prior service calls. The vendor’s AI model returns helpful recommendations.

But was that feature reviewed? Where is the data processed? Is it used for model training? Can the vendor’s subcontractors access it? Does it create a new system where production data is stored?

X-Force warned that AI adoption broadens the attack surface and that attackers are using generative AI to speed up social engineering, reconnaissance, and attack-path iteration. The same report also found manufacturing was the most-targeted industry for the fifth consecutive year, accounting for 27.7% of incidents in 2025.

Manufacturers already have enough exposure through vendors, remote access, cloud systems, and production networks. AI adds another layer unless it is governed.

Building the Policy: Six Elements of a Minimum Viable AI Governance Program

An AI governance policy does not need to start as a legal binder. For most small and mid-sized manufacturers, the better first move is a one-page policy your team can understand and use.

Here are the six sections that belong in a practical first version.

1. Approved tools

List which AI tools employees may use. Include Copilot, approved chatbots, AI features inside business applications, and any department-specific tools. If a tool is not on the list, employees should know how to request review.

2. Prohibited data

Be specific. Do not say “do not enter sensitive data.” Say what that means: CUI, customer drawings, engineering files, source code, pricing, contracts, employee records, financials, credentials, production data, regulated personal information, and nonpublic customer communications.

3. Allowed use cases

Give employees safe examples. Drafting a generic email from non-sensitive notes may be acceptable. Summarizing public information may be acceptable. Brainstorming a maintenance checklist without machine-specific or customer-specific data may be acceptable.

4. Review process for new AI tools

Define who reviews new tools before use. IT should look at security, data retention, authentication, logging, vendor terms, integrations, and whether the tool touches regulated data. For CMMC-regulated environments, the review should also consider whether the tool is inside the right cloud boundary.

5. Monitoring and nonconformity handling

The uploaded AI governance protocol recommends treating AI policy deviations as nonconformities: contain the issue, identify root cause, remediate the system weakness, and prevent recurrence. It also warns that blaming “human error” is usually the wrong answer; the deeper issue may be lack of training, lack of approved tools, or a stalled security review.

That is the right mindset. The goal is not to punish employees for using AI. The goal is to learn where policy, tools, and training are not keeping up.

6. Training and onboarding

Add AI rules to onboarding, annual security training, engineering team briefings, and manager checklists. Keep it plain. Employees should leave training knowing three things: what they can use, what they cannot paste, and whom to ask before using a new AI tool.

The protocol also recommends tracking AI issues through a lifecycle: identified, contained, root cause in progress, action planned, implementing, awaiting verification, and closed. That gives IT and leadership evidence that AI governance is being managed, not improvised.

The Point Is Not to Stop AI

Manufacturers should not treat AI like a problem to ban. The productivity benefits are real. AI can help teams summarize information, draft communications, analyze data, improve maintenance workflows, and reduce administrative drag.

The point is to build guardrails before the first serious exposure.

For manufacturers, AI governance is now part of security, compliance, cyber insurance readiness, and customer trust. If employees are already using AI, the business needs visibility. If Copilot is being considered, permissions and tenant architecture matter. If CUI is involved, AI use needs to be treated as a compliance boundary, not just a productivity choice.

Start small: inventory the tools, write the one-page policy, train employees, monitor for shadow AI, and create a simple process for exceptions and incidents.

Cybersecurity for Milwaukee Businesses: What You Need to Know

Milwaukee businesses are no longer asking whether cybersecurity is necessary. They are asking what level of protection is actually enough. Local manufacturers, accounting firms, clinics, contractors, real estate offices, and professional services are all being targeted. Not because they are large, but because they are accessible.

This article gives you a clear picture of today’s threat landscape, the most common risks faced by Wisconsin businesses, what protection really looks like, and how the right IT partner helps you do more than just “install antivirus.”

1. The Reality: Cyber Threats Are Rising Fast

Here are a few numbers that tell the story clearly:

  • Wisconsin contributed to over 8,000 cybercrime complaints in 2024, resulting in more than 36 million dollars in reported losses, according to the FBI’s Internet Crime Report.
  • Nationally, cyberattacks against small and mid-sized businesses rose 22 percent in 2024, with ransomware being the number one driver.
  • Nearly 60 percent of SMBs that suffer a major cybersecurity incident fail within six months, according to the National Cybersecurity Alliance.
  • The average ransomware payment for U.S. businesses in 2025 climbed to $122,000, not including recovery and downtime costs.

Cyberattacks are no longer isolated IT issues. They affect operations, insurance eligibility, reputation, client retention, and regulatory compliance. In today’s climate, cybersecurity is risk management.

2. The Most Common Cybersecurity Threats Affecting Milwaukee Businesses

While national news covers massive data breaches, local businesses experience a different set of threats. Here are the most common in Wisconsin:

Local ThreatHow It Impacts Businesses
RansomwareLocks systems, halts production, demands payment to regain access
Phishing and Business Email CompromiseFake invoices, CEO impersonation, payroll diversion, vendor fraud
Cloud account takeoverStolen Microsoft 365 credentials used to access email, SharePoint, or OneDrive
Outdated servers, firewalls, or Windows 10 machinesUnsupported systems with no security patches, often uninsured
“Shadow IT” tools used by staffUnapproved apps create security holes and violate insurance policy requirements
Data breaches from vendorsThird-party tools or contractors exposing sensitive information

Two trends are clear: attackers are using familiar methods, and human behavior is often the entry point. That is why cybersecurity is not just technology. It is monitoring, policy, training, and preparedness.

3. Essential Security Measures Every Milwaukee SMB Should Have

Not every business needs enterprise-level cybersecurity, but every business needs protection that aligns with their size, risk-level, insurance requirements, and client expectations.

Here are the foundational layers that should be in place:

Identity Protection (Who gets in)

  • Multi-factor authentication (MFA) on email, VPN, servers, and apps
  • Conditional access or least-privilege controls
  • Password management policies and enforcement

Endpoint Protection (What runs on your devices)

  • AI-driven endpoint detection and response (EDR) like SentinelOne or Huntress
  • Remote isolation for compromised machines
  • Automated rollback for ransomware events

Data Protection

  • Regularly tested backups, both local and off-site
  • Immutable backups that cannot be altered or encrypted
  • Clear recovery time and recovery point objectives (RTO/RPO)

Email and Cloud Security

  • Advanced threat scanning, impersonation detection, and quarantine
  • Domain-level protection through DMARC, DKIM, and SPF
  • Logs and analytics for Microsoft 365 and Google Workspace

Network Security

  • Business-grade firewalls with threat detection and monitoring
  • Zero Trust or network segmentation where applicable
  • Encrypted remote access with identity verification

Human Awareness

  • Ongoing phishing simulations and staff training
  • Executive awareness and policy enforcement
  • Cyber insurance alignment so protections match policy requirements

Cybersecurity is no longer one layer at a time. Real protection means these controls work together.

4. How MSPs Actually Help with Cybersecurity

A mature MSP is not just “the IT help desk.” It functions as a cybersecurity partner.

Here is where that becomes tangible:

  • They monitor threats in real time across endpoints, servers, cloud apps, firewalls, backups, and logs.
  • They help you meet cyber insurance, HIPAA, NIST, or other compliance requirements.
  • They provide documentation, risk scoring, and security posture reports.
  • They lead disaster recovery and coordinate with insurance, legal, and technology vendors during incidents.
  • They test backups and recovery rather than hoping they work.
  • They update security tools and policies before attackers exploit them.

The real value is not only the tools they deploy. It is the way they help you understand your risk, reduce it, and prepare for it.

5. Why Centurion’s Security Approach Stands Out

Most MSPs offer basic cybersecurity. Centurion builds structured protection around these specific goals:

ChallengeCenturion’s Approach
“We do not know our real risk.”Documented Security Posture Assessment and Risk Score
“I worry backups might not actually work.”Scheduled recovery tests, not just backup reports
“How would we explain this to insurance or regulators?”Compliance-ready policies, logging, and reporting
“We do not want tools with no visibility.”Monthly risk dashboards with event logs and insight
“We need real human response, not just alerts.”Milwaukee-based response team with defined escalation paths

We use advanced tools like Huntress, SentinelOne, Proofpoint, ThreatLocker, Datto, and Microsoft Defender for Business, layered with monitoring, documentation, and people who know your business.

That combination is what matters. Technology alone does not protect. Strategy does.

Get a Security Posture Review

Cybersecurity does not have to be overwhelming. You do not need to solve everything at once. You need to start with clarity.

That is why we offer a Cybersecurity Assessment (Security Posture Review) for Milwaukee businesses that includes:

✔ Assessment of your current security controls and gaps
✔ Practical risk score with no technical jargon
✔ Review of insurance requirements and readiness
✔ Written roadmap of your most cost-effective upgrades
✔ No obligation and no disruption to your systems

You will receive a plain-language report your leadership team can actually understand and use.

👉 Request your Security Posture Review and see where you really stand.

Inside the Shadow AI Economy: Why Your Employees Are Already Ahead of You

When MIT released its Project NANDA report this summer, headlines fixated on a startling figure: 95% of enterprise AI projects fail to deliver meaningful results. For Wall Street, it was a warning flare about overhyped technology. For business leaders in Milwaukee and beyond, it raises a sharper question: if companies are spending millions on AI but getting nothing back, who actually is making AI work?

The answer might not be who you think.

AI in the Shadows

The MIT researchers discovered a parallel economy thriving just below the radar of CIOs and CFOs: the Shadow AI economy. While multimillion-dollar deployments stall in pilot purgatory, employees across industries are quietly turning to consumer-grade tools like ChatGPT, Claude, and Midjourney to speed up their work.

They’re writing proposals faster, automating spreadsheets, drafting reports, and even brainstorming new product ideas, often without approval, and sometimes against policy. According to the study, more than 90% of employees already use AI in some form. Most never reported it to IT.

The irony? Workers are realizing measurable productivity gains while corporate projects crumble under the weight of bureaucracy and over-engineering.

Why Big Projects Fail—And Small Ones Win

Official AI rollouts often collapse under familiar pressures: governance slowdowns, tool sprawl, integration nightmares. By the time a solution gets to the frontline worker, it’s clunky, fragmented, and outdated.

Employees, on the other hand, gravitate toward what works. Consumer tools are fast, flexible, and relentlessly improved. For the people doing the work, the choice is obvious.

This tension is driving the quiet divide: companies that ban AI risk losing ground to competitors who learn to govern it instead.

The Hidden Business Case

Buried in the MIT report was another overlooked insight: the biggest payoffs aren’t in flashy front-end pilots but in back-office operations. Document processing, compliance reporting, customer service workflows, and other areas that were once considered too mundane to innovate are now prime targets for AI automation.

Organizations embracing AI in these areas are already seeing annual savings in the millions, without cutting staff. For small and mid-sized businesses, that translates into efficiency gains that can reshape margins and free up teams to focus on growth.

So What Should Leaders Do?

The message is clear: pretending Shadow AI doesn’t exist is a losing strategy. Employees are already bringing these tools into the workplace. The real question is whether leadership chooses to get ahead of it—or wait for compliance violations, data leaks, or client trust issues to force the conversation.

That’s where a structured Shadow AI Audit comes in. It’s a way to bring daylight to what’s already happening inside your business: mapping usage, uncovering risks, and, critically, pinpointing the hidden wins you can scale safely.

Bringing AI Into the Light

At Centurion Data Systems, we’ve seen this pattern unfold across Greater Milwaukee’s SMB landscape: manufacturers, healthcare groups, financial firms. Employees lean on AI because it helps them do their jobs better. Leadership hesitates and worries about risk. The companies that bridge that divide by governing Shadow AI without crushing it are the ones unlocking real value.

That’s why we launched our Shadow AI Audit. It’s designed to help local businesses turn Shadow AI from a liability into an advantage: safely, securely, and with measurable ROI.

Because AI isn’t failing. It’s the way enterprises are trying to use it that’s broken. The workers have already proven it works. Now it’s time to meet them halfway.

Your ChatGPT Chats Might Be on Google: Why This Is a Problem for Your Business and How to Fix It

Recent reports from Tom’s Guide and Fast Company confirm that private ChatGPT conversations are appearing in Google search results. For individuals, that’s alarming. For business owners, it’s potentially catastrophic.

Imagine an employee using ChatGPT to draft a financial forecast, troubleshoot a security issue, or brainstorm a client project - and that conversation becomes publicly accessible online. That’s not just an embarrassing privacy slip. It’s a potential data breach, a compliance violation, and a reputational risk rolled into one.

If you think it’s only tech-savvy employees using AI, think again. These tools have quietly made their way into marketing, finance, HR, and customer support. Many business owners don’t realize how much company data is already passing through AI tools—sometimes without any oversight.

How Did This Happen?

ChatGPT conversations don’t automatically appear on Google. The issue comes from shared conversation links in ChatGPT. Users can create shareable URLs for their chats, often to collaborate with coworkers, or between personal and work accounts, or during document work. If those links aren’t locked down or get posted publicly (e.g., on blogs, forums, or shared documents that are indexed), Google and other search engines can crawl and index them.

This means what was intended as a simple collaboration step can quickly turn into a public data leak. Employees often don’t realize this risk because they assume that since they've signed into an account, especially if the account is paid, that their conversations are always private, even if they opted to make the conversation link "discoverable by anyone." Random people out there don't know that the link exists, right? Correct. But search engines do. They can now crawl and index it. The result: internal conversations—sometimes containing sensitive client or operational information—can show up in a basic web search.

Since the issue was reported by Fast Company, there have already been updates that Google and OpenAI are working together on solving this issue. OpenAI CISO Dane Stuckey announced that the feature to share chats in web searches would be removed from the ChatGPT app. The cached chats may still be showing up in search while they're working with Google to remove it.

However, there are currently no guarantees released that some chat that ended up is search engine's caches, may not show up, ever. And, more importantly, there is always a risk of things like that happening in the future. Not this exact issue, perhaps, but something completely unforeseen.

Business Impact: Why Owners Should Be Concerned

This isn’t just an IT issue. It’s a business risk with multiple layers:

  • Client Trust: If client information appears in a public ChatGPT chat, you risk losing accounts and damaging relationships.
  • Compliance Violations: For industries under HIPAA, GDPR, or financial regulations, exposing data via AI tools can trigger audits and fines.
  • Competitive Exposure: AI chats often include details about pricing models, sales strategies, or product roadmaps. That’s exactly the kind of intelligence competitors love to find.
  • Reputation Damage: Even if content is removed later, archived pages and screenshots can live on. Prospects, partners, and investors doing due diligence may find them long after you’ve taken action.

What makes this problem unique is that it often happens without malicious intent. Employees are just trying to be efficient. But unmonitored AI use can turn into an expensive problem for your business.

Shadow AI – The Hidden Risk

Private COmpany Info in ChatGPT

“Shadow IT”—when employees use unapproved software—has been a known security risk for years. AI has now amplified it, giving rise to shadow AI. Employees sign up for free AI accounts, often with personal email addresses, and use them for work tasks. These accounts bypass IT controls, data policies, and compliance standards.

Why do employees do this? Because AI makes their work easier and faster. The problem is that these AI chats may contain proprietary data, customer details, or internal processes. Since no one is monitoring these tools, sensitive information can end up outside company oversight—sometimes even indexed publicly.

If your business doesn’t have a defined AI usage policy, chances are you already have shadow AI operating within your organization.

What’s Already Out There About You or Your Team?

Before assuming your company is safe, take a moment to check what’s public. Try searching Google for your company name, product names, or unique phrases you know exist only in internal documentation.

If you see unexpected results, that’s your first red flag. Set up Google Alerts with your brand name plus terms like “ChatGPT” or “ShareGPT” to monitor future exposures.

Finding indexed ChatGPT conversations tied to your business isn’t just a technical issue—it’s a leadership issue. These conversations may already have been archived or scraped by third parties, making removal more complicated. That’s why understanding and controlling your team’s AI usage is critical.

How to Secure Your Personal ChatGPT Conversations

If you’ve ever shared or saved ChatGPT conversations, start by making sure they’re not indexed publicly. Tom’s Guide outlined how to check and delete them, but here’s a simplified version:

1. Check if your conversations are indexed:
Search Google for your name or unique phrases you remember using in a ChatGPT conversation. If you see your ChatGPT link (often starting with https://sharegpt.com/), it’s public.

2. Delete shared chats you no longer need:
Open your ChatGPT account, go to “Shared Links,” and delete any you don’t want public. This instantly removes access to those chats.

3. Turn off conversation history:
Inside ChatGPT settings, toggle “Chat History & Training” off. This prevents your chats from being stored and used for AI training and keeps them more private.

4. Avoid sharing sensitive data in any AI chat:
Treat AI conversations like email: once it’s shared, you lose control.

How to Secure Your Business From AI Data Leaks

Personal cleanup is only half the solution. For business owners, the bigger issue is controlling how employees use AI. Here’s what to do:

1. Create an AI usage policy immediately
Even a basic one is better than none. Define what kind of company information is acceptable to use in AI tools and what is strictly prohibited.

2. Restrict public sharing of AI chats
Disable or discourage the use of “shareable links” for AI-generated content unless approved by IT or leadership.

3. Centralize AI use with company-approved accounts
Provide employees with secure, company-controlled AI accounts instead of allowing personal logins. This lets you monitor access and enforce policies.

4. Conduct a shadow AI audit
Find out what tools employees are already using. This is often an eye-opener for leadership because unofficial AI use is more common than expected.

5. Train your team on AI security risks
Don’t assume employees know. Provide short, practical training on what’s safe to input into AI and what could put the company at risk.

6. Implement AI governance and monitoring tools
Use platforms designed to track AI usage, enforce policies, and flag risky behavior. This is especially critical if you handle regulated or sensitive data.

Why You Can’t Just Ignore This

The problem is bigger than a few public chats. AI tools are now embedded in how people work, often without guidance or oversight. Ignoring it increases your risk of:

  • Data breaches from unintended AI leaks
  • Compliance violations that trigger fines and legal issues
  • Loss of competitive advantage when sensitive strategy or product data leaks out
  • Reputation damage that erodes customer trust

And this isn’t a one-time event. The number of indexed AI conversations is growing, and malicious actors are actively scraping and analyzing AI-generated content for useful information. If your business doesn’t have a plan, you’re relying on luck.

How We Help

We work with business owners to remove luck from the equation. Our services include:

  • AI Policy Creation: We create clear, practical policies tailored to your business needs.
  • Shadow AI Audits: We identify which AI tools your team is using—official or not—and assess risks.
  • AI Governance & Compliance Frameworks: We implement monitoring tools and processes to keep AI use secure and compliant.
  • Secure AI Adoption Strategies: We help you leverage AI safely so it becomes a business advantage rather than a liability.

If you want to know exactly what AI risks exist in your business right now, we can help.

Want to know what’s out there about your company? Let’s start with a shadow AI risk assessment and discuss how to secure your business.

Contact us today to schedule a conversation and take control of AI before it becomes your next security or compliance problem.