Practical security writing for small and mid-sized businesses — passkeys, MFA, endpoint hygiene, and the controls that matter when you can't afford a CISO.
Multi-factor authentication is not all the same. SMS-based MFA is the most common form, and it's been routinely defeated for the better part of a decade.
Thirty years of "longer, more complex, rotated more often" produced sticky notes and password reuse. The actual move in 2026 is to stop typing passwords altogether.
Most small businesses won't have a dedicated incident response team. The playbook still works — it's just shorter.
Forcing people to change their password every 90 days makes them write it down. NIST quietly dropped the recommendation eight years ago.
Security at a 50-person company doesn't need to be exotic. It needs to be present. Here's the short list, in order of leverage.