MTRIT MTR IT is performance driven Company. Our passion is to be a IT partner of choice for all Medical and Dental Industries. MTR IT is your IT Security Partner.

We aim to help Medical and Dental with all aspects of their IT and Communication needs.

Your team is using AI right now, whether you have a policy on it or not.ChatGPT, Gemini, Copilot, Claude, and a dozen ni...
02/09/2026

Your team is using AI right now, whether you have a policy on it or not.
ChatGPT, Gemini, Copilot, Claude, and a dozen niche business tools are in the
workflow of someone in your business this week.
These tools learn from what you type, sometimes retain it for training, and live outside whatever data security setup
you've built for the rest of the business.
Without a written policy, you have no way to know what client data is being pasted
into prompts, which business decisions are being made with AI assistance, or how
your insurance views any of it if something goes wrong.
An AI Acceptable Use Policy doesn't have to be 30 pages.
A one-page version covers the essentials: which tools are approved, what data is forbidden as input, what
disclosure rules apply to AI-generated work, and who reviews AI output before it goes
to a client.
If you want a full AI Acceptable Use Policy template to implement in your business,
comment below with "AI Policy" and we'll send it to you.

Your bookkeeper picks up a call after hours. The voice on the other end sounds exactly like the founder, asking for a $4...
01/09/2026

Your bookkeeper picks up a call after hours.
The voice on the other end sounds exactly like the founder, asking for a $40,000 wire to a new vendor before the bank
closes.
That kind of call is happening more often in 2026.
Attackers can now clone a voice from just a few seconds of public audio, and the result is a phone-call-shaped scam
that almost no business owner has trained their team against.
Three seconds of LinkedIn video, a podcast clip, or a webinar recording.
Any of those is enough to feed an AI voice model.
Once the model has the voice, the attacker types whatever they want and your founder's voice says it back.
Banks and accounting teams don't catch this in the moment.
The voice is too good.
The fix is older than the technology.
Set up a verification code word inside your business this week.
Any wire transfer, vendor change, payroll change, or unusual money request requires the person making the call to say the code word first.
No code, no money.
Tell your team this rule out loud, write it down somewhere paperbased, and remind them every 90 days.
The attacker can clone your voice.
They can't clone your code word.

MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.The attac...
31/08/2026

MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.
The attacker already has the password (bought from a leak or stolen from another
site).
They log in. The MFA push hits your employee's phone.
They tap "Deny." The attacker tries again 10 seconds later.
Then again at 2am. Then during lunch.
Eventually someone taps "Approve" just to make it stop.
The attacker is in. Uber got hit this way in 2022. Cisco too.
It still works on small businesses every week because passwords keep leaking and the push prompt looks identical to a real login.
Three things close the gap, and none of them are expensive.
Switch your team from "tap to approve" to number matching, which both Microsoft Authenticator and Duo
support out of the box and takes about 10 minutes to enable in your tenant.
Then turn on geo-blocking or impossible-travel rules in your identity platform so logins
from countries you don't operate in get blocked before the push ever fires.
Last, give your team one rule: if you get an MFA prompt you didn't ask for, deny it AND report it.
The report is what catches the attacker mid-attempt.
The attacker doesn't need a fancy hack.
They just need someone tired enough to tap "Approve."

The ransom is usually the smallest cost of a ransomware attack on a small business.A 25-person company often takes 3 to ...
30/08/2026

The ransom is usually the smallest cost of a ransomware attack on a small business.
A 25-person company often takes 3 to 6 weeks to fully recover from one. Most of that
cost has nothing to do with the criminals.
What 3 to 6 weeks of downtime actually costs you:
1. Payroll. 25 people getting paid for a month or more with almost no productive
output. Easily $200K to $400K, depending on your industry.
2. Lost revenue. Whatever your business normally pulls in over that window, gone.
3. Lost customers. Public breaches drive customer churn, especially in industries built
on trust. Different studies put the rate anywhere from 5% to 30% in the year after.
4. Outside costs. Incident response firm fees, breach lawyers, state notification rules,
credit monitoring for affected customers.
5. Higher insurance. Cyber premiums often double or triple at your next renewal.
You might pay the ransom once. The downtime bills you for months.
Want a fair estimate of your real exposure? Take your monthly payroll, multiply by 1.5.
Add your monthly revenue times 1.5. Add 20% on top for everything else. That's the
kind of number to put in front of your leadership team the next time someone asks
why you're spending on security.

Saving passwords in Chrome is one of the riskiest habits you could have today.Chrome stores them in a way that's easy to...
27/08/2026

Saving passwords in Chrome is one of the riskiest habits you could have today.
Chrome stores them in a way that's easy to steal.
Anyone who gets onto your computer can pull every saved login in seconds.
Malware called infostealers (names like Redline, Lumma, and Vidar) does exactly that.
Once it's on a machine, it copies every saved password and sells them online within hours.
The fix takes about 10 minutes. Sign up for a real password manager. 1Password,
Bitwarden, and Dashlane all work, and Bitwarden has a free tier that's actually good.
Use the built-in import tool to bring in your saved Chrome passwords.
Then go into Chrome's settings (Settings > Autofill > Password Manager), delete every saved
password, and turn off "Offer to save passwords."
A real password manager costs around $3 a month per user. Chrome's free one could
cost you your business.

Your website is online all day, every day, and most owners never think about itssecurity. You don't need to be a securit...
26/08/2026

Your website is online all day, every day, and most owners never think about its
security.
You don't need to be a security expert. Here's what to check:
1. Make sure your site uses HTTPS, the padlock in the browser bar. It's standard now,
and visitors (and Google) treat sites without it as untrustworthy.
2. Keep the software behind your site updated. If you're on WordPress or similar,
outdated plugins are the number one way these sites get hacked. Set them to update
automatically or have someone check monthly.
3. Lock down the admin login. A strong password, MFA, and don't use "admin" as
the username. It's the door attackers try first.
4. If your site has contact or signup forms, make sure they're protected against spam
and abuse, and that anything customers enter is sent and stored securely.
If a web designer built your site and then disappeared, it's worth having someone do
a quick once-over. A hacked website can serve malware to your own customers
without you ever knowing.
26

You got ransomware and your files are locked. Now what? Do you pay or not? Before you send a cent, keep in mind that pay...
25/08/2026

You got ransomware and your files are locked.
Now what? Do you pay or not? Before you send a cent, keep in mind that paying the hackers doesn't guarantee you'll
get your files back.
And in some cases, paying them can even break the law.
So start with your backups.
Check that they're working and that you can restore your systems yourself.
If you can, you might not need to pay at all.
Sort this out with your IT provider before it ever happens, not in the middle of an
attack.

These devices have a limited shelf life. Once a certain point passes, they stop gettingsecurity updates.And no security ...
24/08/2026

These devices have a limited shelf life. Once a certain point passes, they stop getting
security updates.
And no security updates means a higher chance of getting hacked.
So do this:
1. Ask your IT provider for a list of your network gear, with the model and whether
it's still getting security updates. Anything past end of life should be on a replacement
plan.
2. Don't only think about the firewall. Old switches, access points, even that ancient
backup router count too.
3. When you buy new gear, check the support timeline, not just the price. Cheaper
hardware sometimes hits end of life years sooner.

Deepfakes have gotten good enough that the face on a video call might not be thereal person.There have already been case...
23/08/2026

Deepfakes have gotten good enough that the face on a video call might not be the
real person.
There have already been cases where an employee joined a video call with what
looked like their CFO and a few colleagues, all of them fake, and got talked into
wiring out a fortune.
Faking a familiar face and voice on a live call keeps getting cheaper and easier.
24
If someone on a call is pushing you to move money or hand over access fast, verify it
another way before you do anything.
Call them back on a number you already have, or ask them something only the real person would know.
It feels awkward to second-guess your own boss on a call.
But a good boss would much rather you check than get fooled. Make "always verify money requests" a
normal rule, so nobody feels weird doing it.

You're probably holding far more customer data than you need, and all of it issomething a hacker can take if they get in...
20/08/2026

You're probably holding far more customer data than you need, and all of it is
something a hacker can take if they get in.
You've got old spreadsheets of card numbers, customer files from people who left
years ago, exports you pulled once and forgot about.
It's all just sitting there, and if you don't need it, it's just something for a hacker to steal.
So keep less.
Go through where you store customer info and delete what you've got
no reason to keep, old payment details first.
Set a sensible limit on how long you hold
different records and stick to it.
Your accountant or lawyer can tell you the minimums you're legally required to keep.
And watch the copies, because the spreadsheet someone saved to their desktop is just as easy to steal as the main system.
You can't lose what you don't have.
Every file you clear out is one less thing to worry about if you're ever breached.

Address

Unit 1, 9 Dawson Street
Coburg North, VIC
3058

Alerts

Be the first to know and let us send you an email when MTRIT posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to MTRIT:

Shortcuts

Share