CPU Managed IT Solutions

CPU Managed IT Solutions CPU is a long-standing IT Management company out of Greenville, NC. Why Partner with CPU? We treat your IT as an asset and fortify it with advanced protection.
(1)

We specialize in long-term, meaningful business relationships where we take a proactive approach to be your turn-key IT solution. CPU Managed IT Solutions
Serving Eastern NC since 1999

Since 1999, CPU Managed IT Solutions has proudly supported Eastern North Carolina’s businesses with a team holding over 100 years of combined experience in information technology. Our services cover a wide spectrum

, from computer and laptop repairs to complex multi-site VPN setups, secure off-site data backups, wireless coverage solutions, cyber security and more. With a focus on business networks, we also provide tailored support agreements for clients requiring high-caliber service. Our Mission: Trusted Partnerships, Proactive IT Management, and Uncompromising Cybersecurity
At CPU Managed IT Solutions, we do more than manage IT; we build long-term partnerships. Through proactive management, we ensure your technology remains efficient, secure, and resilient, helping you avoid costly downtime. Our cybersecurity services are central to this mission, with robust solutions that safeguard your business against ever-evolving digital threats. We work to remove the IT and security burdens so you can focus on your business’s growth and success. An Investment in Protection and Growth: IT is not just an expense; it’s a strategic investment that protects your assets and fuels your business’s growth. Cybersecurity as an Essential Asset: With today’s complex threat landscape, cybersecurity is indispensable. Complete Security and Continuity Solutions: From data protection to cybersecurity and recovery services, we help you secure your business's future with confidence. Our turnkey solutions serve small to medium-sized businesses across the Triangle to the Coast, specializing in the financial, medical, and legal sectors. CPU Managed IT Solutions is your trusted partner for comprehensive IT and cybersecurity support. Take the IT and Security Headache Away

Leave the challenges of IT and cybersecurity management to us so you can stay focused on what matters most: your business’s success. Invest in your technology. Invest in CPU Managed IT Solutions.

07/31/2026

Your team is using AI right now, whether you have a policy on it or not.

ChatGPT, Gemini, Copilot, Claude, and a dozen niche business tools are in the workflow of someone in your business this week. These tools learn from what you type, sometimes retain it for training, and live outside whatever data security setup you've built for the rest of the business.

Without a written policy, you have no way to know what client data is being pasted into prompts, which business decisions are being made with AI assistance, or how your insurance views any of it if something goes wrong.

An AI Acceptable Use Policy doesn't have to be 30 pages. A one-page version covers the essentials: which tools are approved, what data is forbidden as input, what disclosure rules apply to AI-generated work, and who reviews AI output before it goes to a client.

If you want a full AI Acceptable Use Policy template to implement in your business, comment below with "AI Policy" and we'll send it to you.

07/30/2026

Smishing is text message phishing, and it's now more effective at reaching people than email phishing.

The reason is mechanical. Most businesses spent the last decade hardening their email gateways and training people on suspicious links. Almost nobody applied the same effort to text messages. The result is a channel where employees still tap first and think later.

The patterns repeat: a "delivery failed" message with a link asking for login credentials, a "this is your CEO" text from a number nobody recognizes asking for gift cards or a wire, a fake account-lockout message that looks identical to a real bank alert, and a "hey, I'm in a meeting, can you help me with something quick?" text impersonating a senior person.

These work because texts feel personal in a way email doesn't. They land on the same screen where your spouse, your kids, and your coworkers reach you, which makes the brain default to trusting them. That's the entire attack.

The rules to give your team:

1. No business decision happens over text. That includes wire transfers, vendor changes, payroll changes, gift card requests, and password resets.
2. If a text claims to be from a coworker, verify through a different channel before responding. A 30-second Slack message or phone call kills most of these attacks.
3. Never click a login link inside a text. Open the app or website directly.
4. Forward suspected smishing to 7726 (which spells SPAM on a phone keypad). Carriers use it to block the source.

Smishing works when the response happens before the thinking. Train your team to slow down, and most of these attacks dead-end before the attacker has time to react.

07/29/2026

Your salesperson stops at a coffee shop between meetings. They set up at a table, open their laptop, order a drink, and walk back to the counter when their name is called. The laptop is unattended for 90 seconds. That's enough time for someone to ruin your business week.

The attacker doesn't need to be sophisticated. A $40 USB device called a "Rubber Ducky" plugs in and looks like a keyboard to the computer. It runs pre-loaded keystrokes faster than any human can type. In 90 seconds it can open a terminal, download a remote access tool, install it, and disable the screen lock notification, all without a click from your salesperson.

When your salesperson comes back to the table, the laptop looks the same as they left it. The next time they connect to your office network, the attacker has a path in.

This kind of attack has been demonstrated at every major security conference for the last 10 years. The hardware is cheaper now than it was then.

The defense is straightforward.

- Set every laptop to lock automatically after 30 seconds of inactivity, and train your team that any unattended laptop gets locked first.
- Disable USB device auto-execute across your fleet. On Windows, that's the "AutoPlay" setting plus USB device blocking in Group Policy or Intune.
- Use endpoint detection and response (EDR) software that flags new processes, persistence mechanisms, and suspicious network connections within seconds of installation.
- For people who travel often, give them USB data blockers (small adapters that allow charging but block data transfer) for airports and coffee shops.

Physical security still matters even though most of your defenses sit in software. Don't let the five steps from your laptop to the counter at the coffee shop be the weakest part.

07/27/2026

When an employee leaves your business, the security gap is usually bigger than you'd guess.

A typical 25-person business has dozens of cloud accounts per employee.

Email, payroll, file storage, CRM, accounting, internal tools, and third-party SaaS subscriptions.

When the employee leaves, every one of those accounts should be disabled, but in most businesses only the obvious ones (email, computer login) get touched.

The rest sit dormant for months or years, still with the employee's credentials, still accessible if those credentials were ever leaked in a breach.

That's how a fired employee from 18 months ago becomes the entry point for next year's breach.

The fix is a written offboarding checklist that includes every account, not just the obvious ones.

- Day of departure: disable email, computer login, VPN, and any single-sign-on (SSO) accounts that gate everything else.
- Within 48 hours: revoke access on every SaaS tool by checking the actual admin panel of each.
- Within 7 days: change shared credentials the employee knew
- Within 30 days: do a "did we miss anything" review with someone who worked closely with the employee.

Without a checklist, "what did this person have access to?" is impossible to answer in a few months.

07/25/2026

The quarterly review with your IT provider is one of the most useful meetings on your calendar, but it's easy to let it run on autopilot. Walk in with six real questions and you turn it from a status update into a strategic check-in.

Six to ask at your next review:

1. What changed in our security posture since last quarter? Not "what did you do." What CHANGED. The answer should reference specific risks reduced.
2. Which CISA Known Exploited Vulnerabilities are still unpatched in our environment, and why?
3. When did we last test our backup restore on a real workload, and what did the test show?
4. How many user accounts have privileged or admin access, and is that list smaller than it was last quarter?
5. What incidents (security events, near-misses, alerts) did we have this quarter that I didn't hear about, and why didn't I hear about them?
6. If we were hit by ransomware tonight, what's our realistic Recovery Time Objective for the most important systems?

If your IT provider can answer all six with specifics, they're operating at the standard you're paying for. Hedging or "let me get back to you" on more than one is information worth acting on.

07/23/2026

The old rules about strong passwords are out of date.

For years the standard advice was eight characters, mix uppercase and lowercase, throw in a number and a symbol. NIST, CISA, and Microsoft's own identity team all moved off that advice years ago. The current recommendation is simpler and stronger. Use long passwords or passphrases, and stop forcing your team to rotate them on a schedule.

The math is straightforward. Modern password-cracking hardware can guess a complex 8-character password in less than an hour. A 16-character passphrase made of common words takes centuries against the same hardware. Length wins because every extra character multiplies the work an attacker has to do, while complexity adds only modest barriers.

The policy update for your business is short. Set a minimum of 14 characters for general accounts and 16 or more for admin or sensitive ones. Mandatory rotation creates more weak passwords than it prevents, so stop forcing it. Required complexity rules tend to push people toward simpler, less secure patterns, so drop those too. Block any password that appears in known breach databases, and require MFA on every account that supports it.

If your business is still using 8-character passwords with quarterly rotation, you're following the rules from 2010. The new rules are easier on your team and harder on attackers.

In May 2026, Intuit announced it would lay off around 3,000 employees to refocus the company on AI.Intuit owns QuickBook...
07/22/2026

In May 2026, Intuit announced it would lay off around 3,000 employees to refocus the company on AI.

Intuit owns QuickBooks, TurboTax, Mailchimp, and Credit Karma. Most small businesses use at least one of these. The layoffs are part of a bigger pattern across the tech industry, where companies built around traditional software are rebuilding around AI products. Small business tools are next in line.

Four things to expect over the next 18 months:

1. Product changes. Familiar features get replaced or buried inside AI-first workflows. The QuickBooks you use in 2027 probably won't look like the one you use today.
2. Support friction. Fewer humans on the support line means longer queues and more chatbot-first triage. Get to know your account manager's direct line before you need it.
3. Pricing changes. AI features get bundled into higher tiers, and the base tier loses ground. Expect a renewal call where the rep asks "have you seen our new AI plan?"
4. Data going somewhere new. Your accounting, payroll, and marketing data is the fuel for the new AI features. Check the privacy and data-use settings on each Intuit product you use, and find out what's opted in by default.

Stay on Intuit if it works for you. Just spend the next 18 months auditing what you're paying for, where your data goes, and who answers your calls when something breaks.


In a memo to employees, CEO Sasan Goodarzi said the layoffs are meant to reduce complexity, simplify the company's corporate structure, and deliver better AI products.

07/21/2026

Your office printer is probably the least secured device on your network.

Default admin passwords are still in place. The hard drive inside it stores copies of every document scanned or printed in the last few months. Its web interface is exposed to anyone on the same network, and many printers have known vulnerabilities that haven't been patched in years.

Five settings to change today: replace the default admin password, turn off any wireless or guest networks the printer broadcasts, disable old services you don't use (FTP, Telnet, SMB v1), turn on encryption for stored print jobs and schedule a regular wipe of the hard drive, and put the printer on a separate network segment if your firewall supports VLANs.

Most attackers look at office printers before they look at servers, because nobody changes the password.

07/17/2026

Your primary work email is on every business card, contract, and website. It's also the first thing attackers look for when they're targeting your business.

Phishing crews scrape your company website and LinkedIn for the format and patterns of your email addresses. Once they have one address, they can guess the rest of your team's emails in seconds. That gives them targets for credential phishing, fake invoice scams, and CEO impersonation.

Email aliases reduce that exposure. An alias is an extra email address that delivers to the same inbox without exposing the real one. Microsoft 365 supports up to 400 aliases per mailbox. Google Workspace supports up to 30 per user. Both are free and built in.

A simple pattern that works for most small businesses:

- Use a public-facing alias for any address that lives on your website, business cards, and signup forms (info@, hello@, sales@). Keep your real email off public pages.
- Create vendor-specific aliases for major suppliers ([email protected], [email protected]). If one vendor leaks and you start seeing phishing on that alias, you know exactly which one.
- Use one tightly held internal email for sensitive operations like banking and payroll. That one stays off everything public.

If a phishing campaign hits one of your aliases tomorrow, you'll know which list you ended up on. You can shut that alias off without changing your main address.

A ransomware group called "The Gentlemen" is one of the fastest-growing names in cybercrime right now. You probably have...
07/16/2026

A ransomware group called "The Gentlemen" is one of the fastest-growing names in cybercrime right now. You probably haven't heard of them.

In April 2026, The Gentlemen accounted for roughly 10% of all logged ransomware attacks worldwide and climbed into the top three most active ransomware operations, alongside Qilin and DragonForce. One of their named victims that month was Adaptavist, an Atlassian platinum partner that serves thousands of business customers.

This shift matters because the names you might already know are out of the picture. LockBit, Conti, REvil, and Hive are all gone or rebranded after law enforcement crackdowns and infighting. The replacements use different aliases but the same tactics: phishing, credential theft, vulnerable VPN appliances, and unpatched servers. They encrypt your data and steal a copy to threaten you twice.

The good news is that the defense looks the same regardless of which group is hitting your industry. Five things work against all of them: patching CISA KEV systems within two weeks, MFA with number matching on internet-facing systems, immutable offsite backups that you actually test, security tools that watch for behavior instead of relying on known viruses, and phishing training that covers 2026 forms like QR codes, voice cloning, and fake CAPTCHA pages.

You can't keep up with which ransomware group is hot this month, and you don't have to. The defenses that work today will still work when The Gentlemen rebrand into something else next year.


Every Region Recorded Higher Attack Volumes in April In April 2026, global cyber-attack activity rebounded sharply following the brief moderation observed Global cyberattacks rose 10% in April 2026 as ransomware expanded and GenAI risks persisted. See key trends across sectors, regions, and industri...

Address

204 E Arlington Boulevard, Suite M
Greenville, NC
27858

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when CPU Managed IT Solutions posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to CPU Managed IT Solutions:

Shortcuts

Share