<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Smart Dolphins IT Solutions Inc.</title>
	<atom:link href="https://www.smartdolphins.com/feed" rel="self" type="application/rss+xml" />
	<link>https://www.smartdolphins.com</link>
	<description>Managed IT for Businesses</description>
	<lastBuildDate>Thu, 02 Jul 2026 17:48:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.smartdolphins.com/wp-content/uploads/2024/07/cropped-Main-Brand-Mark-1-150x150.png</url>
	<title>Smart Dolphins IT Solutions Inc.</title>
	<link>https://www.smartdolphins.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Why Are We Paying Nearly the Same Money for Less Protection?</title>
		<link>https://www.smartdolphins.com/blog/why-are-we-paying-nearly-the-same-money-for-less-protection</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 17:00:36 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[business email compromise]]></category>
		<category><![CDATA[conditional access]]></category>
		<category><![CDATA[M365 Business Premium]]></category>
		<category><![CDATA[M365 Business Standard]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[Microsoft Licensing]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=50823</guid>

					<description><![CDATA[Microsoft just raised prices across most of its business SKUs. Business Basic, Standard, E3, E5, F1, F3. All up. One plan stayed flat: Business Premium. For years, the conversation we&#8217;d have with a leader on Business Standard went something like this. &#8220;Premium costs more. Standard covers what my team uses: email, Teams, Office apps. The&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft just raised prices across most of its business SKUs. Business Basic, Standard, E3, E5, F1, F3. All up. One plan stayed flat: Business Premium.</p>



<p class="wp-block-paragraph">For years, the conversation we&#8217;d have with a leader on Business Standard went something like this. &#8220;Premium costs more. Standard covers what my team uses: email, Teams, Office apps. The security stuff in Premium sounds like something for bigger companies.&#8221; That was an arguable position when the gap was wider and the threat picture was quieter. Neither is true anymore.</p>



<p class="wp-block-paragraph">Premium includes the controls Standard lacks for current attacks: conditional access (rules about who can sign in, from where, on what device), Intune for managing the laptops and phones touching your data, Defender for Business and Defender for Office 365 for endpoint and email threat protection, and information protection controls for labeling sensitive documents. Those controls used to feel like enterprise extras. Now most businesses need them.</p>



<p class="wp-block-paragraph">These aren&#8217;t luxury features. Consider session token theft, where an attacker steals the credential your browser uses to stay signed in and walks right past MFA. Or business email compromise, where someone lives inside a mailbox for weeks setting up a fake invoice. The defenses that matter against those attacks are largely on the Premium side of the line. The <a href="https://news.microsoft.com/source/emea/features/microsoft-digital-defense-report-2025-extortion-and-ransomware-drive-over-half-of-cyberattacks-2/">Microsoft Digital Defense Report 2025</a> found that 52% of cyberattacks with known motives were driven by extortion or ransomware. It also found that phishing-resistant MFA can block over 99% of identity-based attacks. That control is enabled by Business Premium&#8217;s Conditional Access and Entra ID P1. The gap between &#8220;we have MFA on&#8221; and &#8220;we have MFA configured the way Premium lets us configure it&#8221; is most of the risk.</p>



<p class="wp-block-paragraph">When we do onboarding assessments, a Standard tenant and a Premium tenant can carry nearly the same cost per user and still look nothing alike in what we can configure. On Standard, we can turn on MFA, clean up admin accounts, and set some sensible defaults. Past that, the levers run out. On Premium, we can set conditional access policies that block sign-ins from unusual locations, require compliant devices, and quarantine risky sessions. We can push consistent settings to every laptop. We can see what&#8217;s happening on those endpoints when something goes wrong. You start from a safer baseline.</p>



<p class="wp-block-paragraph">For years the counter-argument was cost, and it was a fair one. On a 40-person company, the delta between the two plans was roughly $4,500 a year. Still is. That math looks different now that more than half of motivated attacks are aimed at extortion and ransomware, and the controls that block the identity-based path in are the ones sitting behind the Premium license.</p>



<p class="wp-block-paragraph">The better question is: &#8220;Why are we paying nearly the same money for less protection?&#8221;</p>



<p class="wp-block-paragraph">Then there&#8217;s the insurance side. Your cyber insurer is now asking about the specific controls Premium enables. Conditional access. Managed devices. Endpoint detection. If your carrier&#8217;s questionnaire asks whether you enforce device compliance for access to email, &#8220;no&#8221; is an increasingly expensive answer. Sometimes it&#8217;s a decline-to-renew answer. Any license savings can disappear through a higher insurance premium, a lower coverage limit, or a larger retention.</p>



<p class="wp-block-paragraph">Premium will not fix the problem by itself. The license only gives you access to the controls. Configuring conditional access policies, enrolling devices in Intune, tuning Defender, writing the exception process for the executive who travels internationally, that&#8217;s real work. Someone has to do the configuration work: internal, partner, or both. Buying Premium and leaving it in the box gives you a heavier receipt and roughly the same security posture as Standard.</p>



<p class="wp-block-paragraph">But you can&#8217;t configure controls you don&#8217;t have licensed. Get that part right first.</p>



<p class="wp-block-paragraph">If you&#8217;re heading into your next renewal, a few questions worth working through with whoever handles your IT.</p>



<p class="wp-block-paragraph">What Microsoft plan are we on right now, and what&#8217;s the delta to Premium given the new pricing? The math shifted this year. Redo it.</p>



<p class="wp-block-paragraph">If we moved to Premium, what would we turn on in the first 90 days? Conditional access, Intune enrollment, Defender policies. If your provider or internal team can&#8217;t sketch a rollout, that&#8217;s a different conversation to have.</p>



<p class="wp-block-paragraph">What does our cyber insurance renewal look like in the next 12 months, and what controls will the carrier ask about? If the answer includes conditional access or managed devices, the licensing question is already partly answered.</p>



<p class="wp-block-paragraph">Is there anyone in our environment (often an owner, or whoever set the tenant up years ago) whose everyday account also has global admin rights? Premium doesn&#8217;t fix that on its own, but the identity controls make it easier to contain the damage if that account gets compromised.</p>



<p class="wp-block-paragraph">Microsoft didn&#8217;t announce &#8220;Premium is the new floor&#8221; this year; the pricing said it for them. Every SKU below Premium got more expensive, and Premium held. That tells you where Microsoft thinks business tenants should be, and it matches what we see in incident response and insurance renewals.</p>



<p class="wp-block-paragraph">If you haven&#8217;t looked at your Microsoft licensing since your last renewal, now is a good time. Not because Microsoft told you to. Because the ground moved.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MFA is on. The floor for attacking it just dropped.</title>
		<link>https://www.smartdolphins.com/blog/mfa-is-on-the-floor-for-attacking-it-just-dropped</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 18:24:09 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT leadership]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=50551</guid>

					<description><![CDATA[MFA was on. It had been on for years. The training had been done, the boxes had been checked. And someone still got into the business manager&#8217;s email. Leaders deserve a clearer answer than &#8220;well, no security is perfect.&#8221; MFA didn&#8217;t get weaker. The floor for attacking it dropped. Five years ago, the attacks that&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">MFA was on. It had been on for years. The training had been done, the boxes had been checked. And someone still got into the business manager&#8217;s email.</p>



<p class="wp-block-paragraph">Leaders deserve a clearer answer than &#8220;well, no security is perfect.&#8221;</p>



<p class="wp-block-paragraph">MFA didn&#8217;t get weaker. The floor for attacking it dropped.</p>



<p class="wp-block-paragraph">Five years ago, the attacks that beat MFA needed a real operator on the other end. Skilled, patient, custom tooling. Today those same attacks ship as kits. <a href="https://www.stingrai.io/blog/phishing-statistics-2026">Sekoia.io tracks the adversary-in-the-middle phishing-kit market at under $350 a month</a>, which means someone with roughly $250 in crypto and a Telegram channel can run kit-quality MFA-bypass campaigns. That&#8217;s what changed, and it changes what &#8220;we have MFA&#8221; actually buys you.</p>



<p class="wp-block-paragraph">Most of the break-ins come from three familiar attacks.</p>



<p class="wp-block-paragraph">Start with prompt bombing. An attacker has your password (purchased, phished, or reused from somewhere else) and starts hammering the login button. Your phone buzzes. Approve? No. Buzzes again. Approve? No. Buzzes at 2am. Buzzes during a meeting. Buzzes while you&#8217;re driving. Eventually somebody taps yes to make it stop. That&#8217;s the whole attack. There&#8217;s no genius on the other end.</p>



<p class="wp-block-paragraph">SIM swapping works differently. An attacker calls your mobile carrier, cons the rep, and gets your phone number moved to a SIM card they control. Your texts now go to them. If your MFA is &#8220;we&#8217;ll text you a code,&#8221; your MFA now belongs to them too. This used to be a targeted attack on crypto traders and executives. It&#8217;s now run at scale.</p>



<p class="wp-block-paragraph">The hardest one to spot is real-time phishing, the adversary-in-the-middle attack those cheap kits are built for. You click a link, land on what looks exactly like your Microsoft 365 login page, type your password, get prompted for your code, type that too. The page in the middle is relaying everything to the real Microsoft login in real time and capturing the session token at the end. You log in successfully. So do they. <a href="https://www.stingrai.io/blog/phishing-statistics-2026">Microsoft&#8217;s 2025 Digital Defense Report attributed 80% of MFA-bypass breaches to session-token theft</a>, which is the prize at the end of that attack.</p>



<p class="wp-block-paragraph">In all three cases, the user did the MFA. The MFA worked the way it was designed to work. The attacker still got in.</p>



<p class="wp-block-paragraph">What should a leader do on Monday? Start with work your team or IT provider can begin this week.</p>



<p class="wp-block-paragraph">Move everyone to phishing-resistant MFA: FIDO2 security keys or passkeys, which only release credentials to the real site, not a lookalike. There&#8217;s a temptation to scope this to &#8220;high-risk&#8221; accounts (finance, HR, IT admins, leadership), but the business manager whose mailbox got hit probably wasn&#8217;t on anyone&#8217;s high-risk list either. Every account is a way in, and every account leads somewhere.</p>



<p class="wp-block-paragraph">Turn on number matching, which kills prompt bombing by requiring you to type a two-digit number from the login screen into your phone instead of just tapping approve.</p>



<p class="wp-block-paragraph">Use conditional access to narrow the windows. Block logins from countries you don&#8217;t operate in, require a managed device for admin accounts, re-prompt when something looks off. Conditional access does need careful configuration and ongoing tuning. Otherwise you&#8217;ll lock out your bookkeeper the week she&#8217;s working from Mexico, so this is a policy conversation, not a one-time toggle.</p>



<p class="wp-block-paragraph">These controls are already sitting in licenses many organizations pay for. The reason it&#8217;s not already in place isn&#8217;t usually negligence. It&#8217;s that the people running your IT, whether that&#8217;s an internal admin or a managed IT services provider, are juggling fifty other fires, and &#8220;MFA is on, we&#8217;re fine&#8221; was a defensible answer until pretty recently.</p>



<p class="wp-block-paragraph">It&#8217;s not a defensible answer anymore.</p>



<p class="wp-block-paragraph">Here&#8217;s the one question worth bringing to your team or IT provider this week:</p>



<p class="wp-block-paragraph"><em>&#8220;Which of our accounts are still using SMS or basic approve/deny MFA, and what&#8217;s our plan to move them all to phishing-resistant MFA this quarter?&#8221;</em></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Too Many People Have Too Many Keys</title>
		<link>https://www.smartdolphins.com/blog/too-many-people-have-too-many-keys</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Wed, 03 Jun 2026 23:04:42 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Global Administrator]]></category>
		<category><![CDATA[Microsoft 365]]></category>
		<category><![CDATA[Microsoft 365 admin]]></category>
		<category><![CDATA[Permission Control]]></category>
		<category><![CDATA[security controls]]></category>
		<category><![CDATA[Small business]]></category>
		<category><![CDATA[SMB]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=49226</guid>

					<description><![CDATA[When we onboard a new client, one of the first things we look at is who has the keys. Not metaphorically. Literally. Who in this Microsoft 365 tenant can do anything they want, and what else are those accounts doing all day? The answer, more often than it should be, is the owner. Or the&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">When we onboard a new client, one of the first things we look at is who has the keys. Not metaphorically. Literally. Who in this Microsoft 365 tenant can do anything they want, and what else are those accounts doing all day?</p>



<p class="wp-block-paragraph">The answer, more often than it should be, is the owner. Or the office manager. Or the person who set the whole thing up six years ago and never thought about it again. Their everyday email (the one they use to send quotes, open PDFs from strangers, click links from vendors, sign into apps on their phone) is also the account that can do anything inside the environment. Reset anyone&#8217;s password. Read anyone&#8217;s mail. Turn off security controls. Wipe a laptop. Hand the same keys to someone else.</p>



<p class="wp-block-paragraph">That&#8217;s the tell. When the daily-use account and the top-level admin account are the same account, nobody has been thinking about how bad a bad day could get.</p>



<p class="wp-block-paragraph">Picture it this way. If this account gets compromised (phished, password reused on some breached site), how far does the damage reach? When it&#8217;s the top-level admin, the answer is &#8220;everywhere.&#8221; Email, files, identities, backups, settings, the whole environment. One bad click and an attacker doesn&#8217;t just get into one mailbox. They own the place.</p>



<p class="wp-block-paragraph">There are two fixes, and most organizations skip both. They&#8217;re not exotic. They&#8217;re not expensive. Microsoft has recommended them for years. The honest reason they get skipped is that they take real hours to set up, and someone has to make the case for spending those hours when nothing is currently on fire. That&#8217;s a hard sell internally, and it&#8217;s a hard sell to a client when the invoice shows up. Often there are just too many other fires to put out, and this isn&#8217;t one of them yet. So it sits.</p>



<p class="wp-block-paragraph">The first fix: a separate admin account you only sign into when you need it. Your everyday account, the one used for email and Teams and the apps on your phone, has no admin rights at all. When you need to do something administrative, you sign into a different account that exists only for that. Different username, different password, different MFA. The account exposed to the internet all day, clicking links and opening attachments, is not the account that can blow up your environment. If it gets compromised, the damage stops at one person.</p>



<p class="wp-block-paragraph">The second fix is giving people only the access they actually need. Stop handing out top-level admin as the default. Someone who resets passwords for the help desk doesn&#8217;t need it. Someone who manages email groups doesn&#8217;t need it. Someone who handles new hires and departures doesn&#8217;t need it. Microsoft 365 has more specific roles for all of these. They give people what they need to do their job and nothing more.</p>



<p class="wp-block-paragraph">This one gets skipped because it takes extra thought and care. Figuring out who needs to do what, and matching that to the right role, is a small project. It&#8217;s easier to just make everyone a top-level admin and move on. That&#8217;s how it quietly becomes the norm. Three people need to do &#8220;some admin stuff,&#8221; three people get full keys, and nobody ever revisits it. If one of those accounts gets compromised, or one of those people leaves on bad terms, the damage is the same as if the owner&#8217;s account got hit.</p>



<p class="wp-block-paragraph">This is one of the quieter reasons IT support for a small business looks different than people expect. The flashy work is the new laptop, the migration, the helpdesk ticket closed in twenty minutes. The work that actually saves the company is the boring inventory of who has what, and the patience to keep it tidy over time. Whether that work happens inside the building or through outsourced IT, somebody has to own it. If nobody owns it, it doesn&#8217;t happen.</p>



<p class="wp-block-paragraph">This isn&#8217;t about distrust. It&#8217;s about containment. The fewer rights any one account has, the smaller the damage when something goes wrong. And something will go wrong eventually. That&#8217;s the whole reason we&#8217;re talking about this.</p>



<p class="wp-block-paragraph">A worthwhile thing to do this week: open your Microsoft 365 admin center, go to Roles, and look at who has Global Administrator assigned. If the list includes the everyday email accounts of people who use those mailboxes all day, you&#8217;ve found a real problem. In a small business, more than two or three names is usually a flag too. In a larger org, the right number scales up, but the principle holds: it should be a deliberate list, not an accidental one.</p>



<p class="wp-block-paragraph">Then have the conversation with your team or your managed IT services provider. Not &#8220;are we secure.&#8221; That question is too big to answer usefully. Ask the specific one: &#8220;Who has what admin permissions in our environment, why do they have it, and what would happen if any one of those accounts got phished tomorrow?&#8221;</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Stop delegating tasks. Delegate the function.</title>
		<link>https://www.smartdolphins.com/blog/stop-delegating-tasks-delegate-the-function</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Tue, 19 May 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[IT Plan]]></category>
		<category><![CDATA[IT Roadmap]]></category>
		<category><![CDATA[IT Services]]></category>
		<category><![CDATA[Leadership]]></category>
		<category><![CDATA[The Lifecycle Roadmap]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=47812</guid>

					<description><![CDATA[Some leaders think they&#8217;re delegating when they&#8217;re really just dispatching. The difference shows up in how the work moves. When you delegate a task, you stay in the loop. You&#8217;re approving, nudging, checking in, holding the outcome in your head. When you delegate a function, someone else owns the outcome and moves it forward whether&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Some leaders think they&#8217;re delegating when they&#8217;re really just dispatching.</p>



<p class="wp-block-paragraph">The difference shows up in how the work moves. When you delegate a task, you stay in the loop. You&#8217;re approving, nudging, checking in, holding the outcome in your head. When you delegate a function, someone else owns the outcome and moves it forward whether you&#8217;re watching or not.</p>



<p class="wp-block-paragraph">Picture a strong finance lead who owns the function. Budgets get built, forecasts get updated, the audit gets scheduled, cash gets watched. None of it waits on you to ask. Now picture a bookkeeper you have to poke every month to send the close report. Same domain, completely different relationship.</p>



<p class="wp-block-paragraph">The same pattern shows up in marketing, HR, facilities, and IT.</p>



<p class="wp-block-paragraph">This is where the conversation about managed IT services tends to go sideways. Leaders evaluate providers on task-level questions: how fast does the helpdesk respond, how quickly do tickets close, how smoothly do new users get set up. Those questions matter. They just aren&#8217;t function-level questions. They&#8217;re dispatching questions wearing a managed-services costume.</p>



<p class="wp-block-paragraph">A function-level question sounds different. Does the proactive work that nobody is going to nag anyone about actually happen?</p>



<p class="wp-block-paragraph">Things like: the annual IT plan that ties technology decisions to where the organization is actually going. The IT budget that doesn&#8217;t surprise the board in March. The lifecycle roadmap that says which devices and systems are aging out and when. The cybersecurity audit that gets scheduled because it&#8217;s time, not because something broke. The risk review that surfaces what&#8217;s quietly drifting. The governance conversation about Microsoft 365, or Copilot, or AI tools that staff are already using whether you&#8217;ve sanctioned it or not.</p>



<p class="wp-block-paragraph">Nobody is going to file a ticket for any of that. It only happens if someone owns it.</p>



<p class="wp-block-paragraph">A quick example of what function-level ownership actually looks like in practice. We worked with an <a href="https://www.smartdolphins.com/case-studies/it-support-engineering">engineering firm</a> where the brief wasn&#8217;t &#8220;fix this ticket&#8221; or &#8220;stand up this server.&#8221; It was: build a phased IT roadmap, reduce reliance on aging in-house servers, get SOLIDWORKS workloads into Azure, and set the team up for flexible remote work with centralized cloud storage. That&#8217;s a function-level engagement. The output wasn&#8217;t a faster helpdesk. The output was a hybrid environment with less complexity, a scalable cost model that grows with the team instead of front-loading capital expense, and the security posture that comes with running inside Microsoft 365. None of that work was going to surface from a ticket queue. Someone had to be thinking about it on the firm&#8217;s behalf.</p>



<p class="wp-block-paragraph">Here&#8217;s a test worth running: if you went on a three-month sabbatical tomorrow, would your IT function still move forward? Would the planning happen? Would the renewal conversations get scheduled? Would the risks get surfaced? Would you come back to find decisions waiting for you, or work already moving?</p>



<p class="wp-block-paragraph">If the honest answer is that tickets would keep closing fast enough that nobody complains, but nothing forward-looking would happen, you haven&#8217;t handed off a function. You&#8217;ve outsourced a queue. That&#8217;s a real service. It just isn&#8217;t the same thing.</p>



<p class="wp-block-paragraph">This is also the question to sit with before deciding whether to outsource IT or build it in-house. The choice isn&#8217;t really internal vs. external. It&#8217;s queue vs. function. A small in-house team can own the function beautifully if that&#8217;s what you&#8217;ve asked them to own. An outsourced IT partner can own it too. Either one can also drift into pure dispatch mode if nobody is clear about the brief.</p>



<p class="wp-block-paragraph">The distinction matters more than it used to, because identity, security, data governance, productivity tooling, vendor sprawl, and employee experience are all being re-examined at once. The organizations that handle this well are the ones where someone is actively thinking about all of that on their behalf, not just reacting when something breaks.</p>



<p class="wp-block-paragraph">And here&#8217;s the part worth sitting with: this isn&#8217;t a vendor problem first. It&#8217;s a leadership problem first. If you&#8217;ve never asked your IT partner (or your internal team) to own the function, they&#8217;ve probably defaulted to owning the queue. That&#8217;s a rational response to how they&#8217;ve been measured. The fix isn&#8217;t necessarily a new provider. The fix is changing the conversation about what you&#8217;re asking them to own.</p>



<p class="wp-block-paragraph">A few questions that get at this directly:</p>



<p class="wp-block-paragraph">What&#8217;s our IT plan for the next twelve months, and how does it connect to the business plan? Where are we on the technology lifecycle, and what&#8217;s the replacement schedule? What&#8217;s our current cybersecurity posture, and what&#8217;s changed since last review? What are the top three risks in our environment right now, and what are we doing about each? Where is shadow IT or shadow AI showing up, and how are we responding?</p>



<p class="wp-block-paragraph">If those questions get answered crisply, without scrambling, you&#8217;ve handed off a function. If they get answered with &#8220;let me get back to you&#8221; or &#8220;we&#8217;d need to look into that,&#8221; you&#8217;ve got a dispatcher, not an owner.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Practical Guide to AI Data Residency in Canada</title>
		<link>https://www.smartdolphins.com/blog/a-practical-guide-to-ai-data-residency-in-canada</link>
		
		<dc:creator><![CDATA[Mariola Czerkawska]]></dc:creator>
		<pubDate>Thu, 14 May 2026 23:33:21 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Canadian Businesses]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Residency]]></category>
		<category><![CDATA[PIPEDA]]></category>
		<category><![CDATA[US Cloud Act]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=47885</guid>

					<description><![CDATA[Businesses are adopting AI securely by using the security features available in paid accounts. This allows businesses to configure how their data is handled according to their security regulations and preferences. However, one critical factor often overlooked is where that data is actually stored.  This question becomes especially important for organizations responsible for managing client data, whether due to insurance requirements, legal obligations, or commitments made&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Businesses are adopting AI securely by using the security features available in paid accounts. This allows businesses to configure how their data is handled according to their security regulations and preferences. However, one critical factor often overlooked is where that data is actually stored. </p>



<p class="wp-block-paragraph">This question becomes especially important for organizations responsible for managing client data, whether due to insurance requirements, legal obligations, or commitments made to clients about how their information&nbsp;is&nbsp;managed.<img decoding="async" width="0" height="2" src="blob:https://www.smartdolphins.com/ebd83bd9-fba6-482c-96a3-a0f69fefabb1">&nbsp;</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image.png" alt="image" class="wp-image-47886"/></figure>



<p class="wp-block-paragraph"><strong>What Is AI Data Residency?</strong>&nbsp;</p>



<p class="wp-block-paragraph">Data residency refers to the&nbsp;geographic location&nbsp;where your&nbsp;data&nbsp;is physically stored.&nbsp;When you type a prompt into an AI&nbsp;system,&nbsp;the&nbsp;data&nbsp;can be processed on servers anywhere in&nbsp;the world. If those servers are in Canada&nbsp;and owned by a Canadian company,&nbsp;the&nbsp;data&nbsp;remains&nbsp;in Canada&nbsp;and will be subject to Canadian Privacy Law, including PIPEDA. If the&nbsp;data is stored at rest on&nbsp;servers&nbsp;in another&nbsp;country,&nbsp;the&nbsp;data may be subject to that country’s&nbsp;privacy&nbsp;laws.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">However, due to the Cloud Act in the United States&nbsp;even if the server is in Canada,&nbsp;the US government can&nbsp;gain access to that data&nbsp;if the server is owned by an&nbsp;American&nbsp;company.&nbsp;This does not mean that the US government has unlimited access to data stored on American owned servers. It also does not mean storing&nbsp;data with American companies violates PIPEDA.&nbsp;It&nbsp;is, however,&nbsp;important&nbsp;for business leaders&nbsp;to understand who can access&nbsp;their&nbsp;data under what circumstances.&nbsp;</p>



<p class="wp-block-paragraph">For Canadian business owners,&nbsp;data&nbsp;residency&nbsp;is not just a technical detail&nbsp;– it affects&nbsp;privacy obligations, client trust, and risk exposure.&nbsp;&nbsp;Business&nbsp;leaders&nbsp;have the ultimate responsibility of ensuring they have a well-configured and secure account&nbsp;to&nbsp;protect client data, regardless of where the data is stored.&nbsp;</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image.png" alt="image" class="wp-image-47886"/></figure>



<p class="wp-block-paragraph"><strong>ChatGPT and&nbsp;Canadian&nbsp;Data Residency</strong>&nbsp;</p>



<p class="wp-block-paragraph">If employees are using the free version of ChatGPT, their data is&nbsp;generally stored&nbsp;and processed in the United States. The same applies to lower-tier paid plans such as Plus and Team. These plans do not currently offer Canadian data residency&nbsp;meaning that&nbsp;company information&nbsp;entered into&nbsp;those&nbsp;accounts&nbsp;is primarily handled through U.S.-based servers&nbsp;and may be subject to&nbsp;further&nbsp;American legislation, such as the&nbsp;Stored Communications Act.&nbsp;</p>



<p class="wp-block-paragraph">Paid plans do offer stronger privacy controls than the free version. For example, business subscriptions can limit whether&nbsp;the&nbsp;data is used to improve public models. This&nbsp;is an important distinction for companies that are concerned about confidential information being reused&nbsp;by the model.&nbsp;Even with these&nbsp;improvements, the data storage&nbsp;is still primarily stored&nbsp;outside&nbsp;of&nbsp;Canada.&nbsp;</p>



<p class="wp-block-paragraph">ChatGPT Enterprise&nbsp;is where things change. Enterprise and Education customers have the&nbsp;option&nbsp;to store their data “at rest” in Canada or other supported regions.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">In practical terms, if Canadian data residency is a requirement for your organization, Enterprise deployment is currently the only ChatGPT option that supports it. Even then, it is important to understand that some limited technical processing or metadata may still occur outside&nbsp;Canada.&nbsp;As with all&nbsp;global cloud systems,&nbsp;this is an unavoidable and&nbsp;common practice.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">The key takeaway for Canadian businesses is straightforward: the safety of ChatGPT for business use depends heavily on the subscription level,&nbsp;how it is configured, and what information your team&nbsp;enters into&nbsp;it.&nbsp;</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image-5.png" alt="image" class="wp-image-47890"/></figure>



<p class="wp-block-paragraph"><strong>Microsoft Copilot and Canadian Data Residency</strong>&nbsp;</p>



<p class="wp-block-paragraph">Microsoft Copilot&nbsp;operates&nbsp;within&nbsp;your organization&#8217;s&nbsp;Microsoft 365 environment. For many Canadian organizations already using Microsoft 365, this simplifies the conversation around AI data residency.&nbsp;</p>



<p class="wp-block-paragraph">If your organization’s Microsoft tenant is configured in Canada, Copilot&nbsp;generally follows&nbsp;those same regional settings. It also&nbsp;operates&nbsp;within Microsoft’s enterprise security framework, meaning your business data is not used to train public AI models and&nbsp;remains&nbsp;inside your organization’s boundary.&nbsp;</p>



<p class="wp-block-paragraph">However, configuration still matters. If your tenant is not set up with Canadian data residency, your data may be stored elsewhere.&nbsp;If your&nbsp;Microsoft 365 environment is in&nbsp;line&nbsp;with your&nbsp;organization&#8217;s&nbsp;needs,&nbsp;then your Copilot license will be as well.&nbsp;</p>



<p class="wp-block-paragraph">Enabling Copilot can be&nbsp;a great opportunity&nbsp;for businesses to review their security settings. If you are concerned about data residency and security with AI,&nbsp;Copilot&nbsp;is considered the safest&nbsp;option.&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image-2.png" alt="image" class="wp-image-47887"/></figure>



<p class="wp-block-paragraph"><strong>Google Gemini and Canadian Data Residency</strong></p>



<p class="wp-block-paragraph">Google Gemini, integrated into Google Workspace, follows a similar pattern&nbsp;as&nbsp;Microsoft Copilot. Business-level subscriptions provide administrative controls and do not use company data to train public AI models. Data residency depends on how your Google Workspace environment is configured.&nbsp;</p>



<p class="wp-block-paragraph">If your organization has selected a Canadian region for data storage, your information&nbsp;will&nbsp;remain there. If not, it may be stored in another country. Like&nbsp;Copilot, the product itself is only part of the equation. The way your environment is set up&nbsp;determines&nbsp;where your data lives.&nbsp;</p>



<p class="wp-block-paragraph">For Canadian companies evaluating Gemini, the right question is not simply whether the tool is secure, but rather&nbsp;if&nbsp;your Google configuration aligns with your data residency expectations.&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image-4.png" alt="image" class="wp-image-47889"/></figure>



<p class="wp-block-paragraph"><strong>The Real Risk: Unmanaged AI Use</strong>&nbsp;</p>



<p class="wp-block-paragraph">In many organizations, the biggest risk is not the AI platform itself.&nbsp;&nbsp;Instead, it is the absence of structure around how employees are using it.&nbsp;</p>



<p class="wp-block-paragraph">Across Canada, staff are experimenting with AI every day. They paste client emails into ChatGPT to rewrite them. They summarize financial data. They draft HR responses. They brainstorm strategy documents. Most of the time,&nbsp;employees&nbsp;are trying to be more productive, not careless.&nbsp;</p>



<p class="wp-block-paragraph">The issue is that leadership often has no visibility&nbsp;into&nbsp;this activity. There is no approved tool, no clear policy, or&nbsp;guidance on what can and cannot be entered into AI systems.&nbsp;Without&nbsp;this&nbsp;regulation,&nbsp;an organization can&nbsp;lose control of their data&nbsp;without realizing it.&nbsp;When it is unmanaged, risk grows quietly in the background.&nbsp;</p>



<p class="wp-block-paragraph">Canadian business owners&nbsp;must consider&nbsp;whether&nbsp;the&nbsp;AI use inside&nbsp;their&nbsp;organization is intentional and governed. When companies standardize approved tools, understand AI data residency in Canada, and set clear internal guidelines, AI can be used confidently&nbsp;and securely.&nbsp;&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image-3.png" alt="image" class="wp-image-47888"/></figure>



<p class="wp-block-paragraph"><strong>Does Data Residency Matter for Every Business?</strong>&nbsp;</p>



<p class="wp-block-paragraph">Just because your company’s data is stored on servers outside Canada does not automatically make it unsafe. Large cloud providers such as OpenAI, Microsoft, and Google&nbsp;operate&nbsp;highly secure global infrastructure. In many cases, these international data&nbsp;centers&nbsp;have stronger physical and digital security controls than what most small or mid-sized businesses could ever implement internally.&nbsp;</p>



<p class="wp-block-paragraph">For many Canadian businesses, especially those in&nbsp;less-regulated&nbsp;industries, storing data in the United States may present little practical risk. U.S.-based cloud infrastructure is mature, secure, and widely used by Canadian companies every day.&nbsp;</p>



<p class="wp-block-paragraph">Where data residency becomes more important is in situations such as:&nbsp;</p>



<ul class="wp-block-list">
<li>Highly regulated industries </li>
</ul>



<ul class="wp-block-list">
<li>Government or public sector work </li>
</ul>



<ul class="wp-block-list">
<li>Organizations with strict contractual data location requirements </li>
</ul>



<ul class="wp-block-list">
<li>Businesses handling sensitive personal, health, or financial information </li>
</ul>



<p class="wp-block-paragraph">In those cases,&nbsp;the data can carry legal, contractual, or reputational implications.&nbsp;For others, it may simply be a matter of preference rather than&nbsp;necessity. The&nbsp;key is understanding&nbsp;what regulations you are&nbsp;bound by and what you can do to&nbsp;ensure your tools&nbsp;aren’t&nbsp;compromising&nbsp;your commitments to data security.&nbsp;</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1" height="1" src="https://www.smartdolphins.com/wp-content/uploads/2026/05/image-6.png" alt="image" class="wp-image-47891"/></figure>



<p class="wp-block-paragraph"><strong>A More Balanced Way to Think About AI and Data Location</strong>&nbsp;</p>



<p class="wp-block-paragraph">AI adoption does not need to be driven by fear. It should be driven by informed decisions.&nbsp;</p>



<p class="wp-block-paragraph">International cloud systems are not “less secure” simply because they are outside Canada. In fact, the global infrastructure&nbsp;operated&nbsp;by major providers&nbsp;is&nbsp;designed to meet extremely high security standards. Encryption, access controls, monitoring, and compliance certifications are standard&nbsp;practice.&nbsp;</p>



<p class="wp-block-paragraph">Instead of asking if&nbsp;foreign&nbsp;servers&nbsp;are&nbsp;dangerous, business leaders need to ask if the organization has&nbsp;legal, regulatory, or contractual reasons to keep data in Canada.&nbsp;</p>



<p class="wp-block-paragraph">If the answer is yes, then Canadian data residency should be part of your AI decision-making process.&nbsp;</p>



<p class="wp-block-paragraph">If the answer is no, the focus may shift more toward choosing the right subscription level, setting clear internal policies, and ensuring employees are using approved tools appropriately.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Sources</strong>&nbsp;</p>



<ul class="wp-block-list">
<li><a href="https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener"><strong>Data residency and inference Residency for ChatGPT | OpenAI Help Center</strong></a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/locations?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener"><strong>Gemini Enterprise Standard and Plus Editions data residency and ML regional processing commitments  |  Google Cloud Documentation</strong></a> </li>
</ul>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-workload-copilot?view=o365-worldwide&amp;utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener"><strong>Data Residency for Microsoft 365 Copilot and Copilot Chat &#8211; Microsoft 365 Enterprise | Microsoft Learn</strong></a> </li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your Cyber Insurer is Becoming Your Auditor</title>
		<link>https://www.smartdolphins.com/blog/your-cyber-insurer-is-becoming-your-auditor</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Tue, 12 May 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<category><![CDATA[Cybersecurity Insurance]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=47533</guid>

					<description><![CDATA[For most of the last decade, cyber insurance worked like this: you filled out an application, attested to a handful of controls, paid the premium, and filed the policy in a drawer. Renewal looked a lot like the year before. The questions were broad. &#8220;Do you have MFA?&#8221; Yes. &#8220;Do you have endpoint protection?&#8221; Yes.&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">For most of the last decade, cyber insurance worked like this: you filled out an application, attested to a handful of controls, paid the premium, and filed the policy in a drawer. Renewal looked a lot like the year before. The questions were broad. &#8220;Do you have MFA?&#8221; Yes. &#8220;Do you have endpoint protection?&#8221; Yes. &#8220;Do you back up your data?&#8221; Yes. Move on.</p>



<p class="wp-block-paragraph">That era is ending, and some leaders haven&#8217;t caught up to what&#8217;s replacing it.</p>



<p class="wp-block-paragraph">Your cyber insurer is quietly becoming one of the more consequential auditors of your IT environment. Not in the traditional sense, where someone gives you a finding and a remediation date. The underwriter&#8217;s audit is the one that runs after an incident, when the question isn&#8217;t &#8220;what do we fix by Q3&#8221; but &#8220;does the policy actually pay.&#8221;</p>



<p class="wp-block-paragraph">Look at what&#8217;s driving the shift. The <a href="https://www.insurancebusinessmag.com/ca/news/cyber/whats-happening-in-the-canadian-cyber-insurance-market-495999.aspx">Insurance Bureau of Canada</a> reports that Canadian cyber premiums climbed from $18 million in 2015 to $550 million in 2023. And yet from 2019 through 2023, insurers paid out roughly $1.53 in claims for every $1 they collected in premium. That&#8217;s not a sustainable book of business. It&#8217;s a market that has to tighten or collapse, and tightening is what we&#8217;re seeing.</p>



<p class="wp-block-paragraph">Tightening doesn&#8217;t only mean higher prices. It means underwriters are now grading deployment depth, not checkbox presence. They want to know not just whether you have MFA, but whether it&#8217;s phishing-resistant, and whether it&#8217;s deployed on the accounts that matter. They want to know not just whether you have endpoint detection and response (EDR), but what percentage of your laptops, workstations, and servers it actually covers. <a href="https://www.insurancebusinessmag.com/us/news/cyber/incident-response-planning-linked-to-fewer-cyber-insurance-claims-marsh-547642.aspx">Marsh McLennan&#8217;s 2025 cyber risk study</a> put numbers on it: each 25% jump in EDR coverage cut breach probability by 10%, and phishing-resistant MFA users were 9% less likely to suffer a cyber event than those on weaker MFA. Underwriters have read that study too.</p>



<p class="wp-block-paragraph">Then there&#8217;s the part that should make every leader pause. <a href="https://comparecheapssl.com/cyber-insurance-statistics/">Coalition&#8217;s 2024 claims data</a> found that 82% of denied cyber insurance claims involved organizations that hadn&#8217;t fully implemented the MFA they had attested to.</p>



<p class="wp-block-paragraph">Read that again. Most denied claims came from organizations that thought they had coverage. They paid the premium. They filed the policy. Then something went wrong, the adjuster came in, and the gap between the application and the environment was wide enough to deny the claim.</p>



<p class="wp-block-paragraph">For Canadian leaders the picture is sharper still. A <a href="https://www.insurancebusinessmag.com/ca/news/cyber/smes-underestimate-cyber-risks-leaving-gaps-in-insurance-protection-ibc-551686.aspx">2025 IBC and Angus Reid survey</a> found that only 22% of Canadian small and mid-sized organizations carry any form of cyber insurance, and just 12% hold a dedicated stand-alone policy. Meanwhile 72% of those same respondents said AI is making cyber risk harder to defend against. So most organizations are underinsured, increasingly exposed, and walking into a market that is getting pickier about who it covers and how much it pays when something goes wrong.</p>



<p class="wp-block-paragraph">What does this mean for the work?</p>



<p class="wp-block-paragraph">The renewal conversation is no longer a procurement exercise. It&#8217;s a controls conversation. And the questions worth bringing to it aren&#8217;t mostly about price. They&#8217;re about proof.</p>



<p class="wp-block-paragraph">Can you demonstrate, today, that the controls you attested to last year are deployed the way you described? Not in theory, in the policy document, but in the actual environment, on the actual endpoints, for the actual accounts. If a claims adjuster walked in tomorrow and pulled the configuration of your MFA, your EDR coverage, your backup retention and isolation, and your admin account hygiene, would the picture match the application?</p>



<p class="wp-block-paragraph">Some of the ambiguity is on the application itself. Older policies asked broad questions (&#8220;are all accounts protected by MFA?&#8221;) that were difficult to answer cleanly in a real environment with service accounts, legacy systems, and vendor exceptions. Newer applications are getting more specific (&#8220;all email accounts protected by MFA&#8221;), which helps, but the language still varies policy to policy. Part of the work at renewal is reading carefully enough to know what you&#8217;re actually attesting to.</p>



<p class="wp-block-paragraph">Where would an adjuster find a gap? Because there is often a gap. The acquired entity that hasn&#8217;t been fully integrated. The line-of-business system whose vendor still doesn&#8217;t support modern MFA. The shared service account everyone forgot about. The backup job that&#8217;s been failing silently for six weeks. These are the gaps that don&#8217;t matter on a normal Tuesday and matter enormously on the Tuesday something goes wrong.</p>



<p class="wp-block-paragraph">A useful exercise before your next renewal: take last year&#8217;s application and walk through the attested controls with your IT team or partner. For the ones that are clearly worded, ask for evidence (a configuration export, a coverage report, a screenshot) that they&#8217;re deployed the way the application described. For the ones that are ambiguous, get aligned on how you&#8217;re interpreting the question before you sign the next attestation. The deltas you find are the deltas the adjuster would find.</p>



<p class="wp-block-paragraph">The policy you think you have is the one that pays if those two pictures match.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Buying tools is easy. Running them is the actual job.</title>
		<link>https://www.smartdolphins.com/blog/buying-tools-is-easy-running-them-is-the-actual-job</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Fri, 01 May 2026 18:04:30 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=47431</guid>

					<description><![CDATA[Any IT company or team can swipe a credit card and sign up for intrusion monitoring, backup software, endpoint protection, and spam filtering before lunch. The vendors have made it that easy. Trial accounts, slick dashboards, a few green checkmarks, and you can tell leadership you&#8217;re &#8220;covered.&#8221; The trouble is, buying the tool isn&#8217;t the&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Any IT company or team can swipe a credit card and sign up for intrusion monitoring, backup software, endpoint protection, and spam filtering before lunch. The vendors have made it that easy. Trial accounts, slick dashboards, a few green checkmarks, and you can tell leadership you&#8217;re &#8220;covered.&#8221;</p>



<p class="wp-block-paragraph">The trouble is, buying the tool isn&#8217;t the job. Running it is.</p>



<p class="wp-block-paragraph">We&#8217;ve watched this pattern play out in IT security and backup for twenty-five years. An organization licenses the right products, the dashboards turn green, and everyone moves on. Then something goes wrong, and the gap between &#8220;we have the tool&#8221; and &#8220;the tool actually did its job&#8221; turns out to be wider than anyone realized.</p>



<p class="wp-block-paragraph">Backup is the cleanest example. Industry surveys consistently find that a meaningful share of organizations who go to restore from backup don&#8217;t get all their data back. The [2024 State of the Backup Survey](https://drj.com/industry_news/2024-state-of-the-backup-survey-says-security-incidents-and-data-loss-on-the-rise/) found that only 42% of organizations who experienced data loss recovered all of their data on restore. These are organizations with backup systems in place. The tools were running. The jobs were completing. The restore still came up short. Somebody, somewhere, looked at a green dashboard last Tuesday and told themselves things were fine.</p>



<p class="wp-block-paragraph">The tool isn&#8217;t the thing. The human running it is.</p>



<p class="wp-block-paragraph">At Smart Dolphins we run a centralized services team whose whole job is making the tech, security, and backup stack do what it claims to do. We human-verify backup jobs daily. Not &#8220;the dashboard says green,&#8221; but a person confirming the job ran, the data is recoverable, and yesterday&#8217;s quiet failure isn&#8217;t sitting there waiting to ruin somebody&#8217;s week. That sounds unglamorous because it is. It&#8217;s also the part of the work that determines whether the protection you&#8217;re trusting in is real on the day you actually need it.</p>



<p class="wp-block-paragraph">The same logic applies to patching, to endpoint protection, to spam filtering, to identity and access. Each of those tools has a dashboard. Each dashboard can be green while something underneath is quietly broken or misconfigured or drifting out of policy. The work of catching that drift isn&#8217;t done by the tool. It&#8217;s done by someone whose job is to look, verify, tune, and fix.</p>



<p class="wp-block-paragraph">So when you&#8217;re thinking about your own setup, whether that&#8217;s your MSP, your internal IT team, or the security stack you&#8217;ve been told is handled, the question worth sitting with isn&#8217;t which tools you have. It&#8217;s who&#8217;s watching them, tuning them, and verifying them on a Tuesday afternoon when nothing is on fire. That Tuesday afternoon work is what determines whether the tool is an asset or an expensive illusion.</p>



<p class="wp-block-paragraph">Buying tools is easy. Running them is the actual job, and it always has been.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Question That Can Reframe How You Think About IT</title>
		<link>https://www.smartdolphins.com/blog/from-firefighting-to-forward-strategy-rethinking-your-it-budget</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Tue, 28 Apr 2026 23:55:34 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Dave Monahan]]></category>
		<category><![CDATA[IT leadership]]></category>
		<category><![CDATA[IT planning]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=47378</guid>

					<description><![CDATA[&#8220;I honestly have no idea if we&#8217;re spending our IT budget well. I don&#8217;t even know what question to ask.&#8221; That&#8217;s the kind of thing some leaders say when they&#8217;re thinking about their IT setup. No crisis. No systems on fire. Just a quiet, hard uncertainty that a lot of leaders share but rarely say&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">&#8220;I honestly have no idea if we&#8217;re spending our IT budget well. I don&#8217;t even know what question to ask.&#8221;</p>



<p class="wp-block-paragraph">That&#8217;s the kind of thing some leaders say when they&#8217;re thinking about their IT setup. No crisis. No systems on fire. Just a quiet, hard uncertainty that a lot of leaders share but rarely say out loud. And there&#8217;s one simple question that can reframe the thinking productively:</p>



<p class="wp-block-paragraph">&#8220;What percentage of the work your team or IT provider does for you is reactive versus proactive?&#8221;</p>



<p class="wp-block-paragraph">One question. But the answer reshapes how you think about the effectiveness of your IT budget, and it gives you a sentence you can take straight to your board or leadership team: &#8220;Right now, 70% of our IT spend is keeping things from falling apart. 30% is building stability, capacity, and new capability. Here&#8217;s our plan to shift that over the next twelve months.&#8221; Decision-makers understand that framing instantly.</p>



<p class="wp-block-paragraph"><strong>The distinction that matters</strong></p>



<p class="wp-block-paragraph">Reactive work is everything that happens after something breaks: tickets, outages, emergency calls. It&#8217;s necessary, but it&#8217;s pure expense. You&#8217;re paying to get back to where you were before the problem happened.</p>



<p class="wp-block-paragraph">Proactive work is the other side. Most people assume that means patching, backups, and hardware planning — the defensive layer that prevents future fires. That matters. But usually the bigger value comes from aligning technology with where your organization is heading, redesigning a workflow that&#8217;s costing your staff hours every week, surfacing opportunities you didn&#8217;t know were available because you&#8217;ve been too deep in the day-to-day to look up.</p>



<p class="wp-block-paragraph">Proactive work that only prevents problems is optimization. Proactive work that opens up new capacity or improves how your organization operates is opportunity. If your IT function is only doing the first kind, you&#8217;re leaving a lot on the table.</p>



<p class="wp-block-paragraph"><strong>What the answer tells you</strong></p>



<p class="wp-block-paragraph">If the work is mostly reactive, that doesn&#8217;t necessarily mean your team or provider is failing. Some organizations have years of accumulated technical decisions creating a heavy reactive load, and the environment needs to be stabilized before proactive efforts can gain traction. But now you know, and knowing gives you a starting point: what would it take to shift the ratio? What proactive work has been deferred? Where should you invest intentionally instead of absorbing whatever comes?</p>



<p class="wp-block-paragraph">If the answer is mostly proactive, ask whether that work maps to your actual strategic priorities or just a standard checklist applied regardless of context. If your team or provider can&#8217;t draw that line, the work needs to be revisited.</p>



<p class="wp-block-paragraph"><strong>Turning the ratio into a tool</strong></p>



<p class="wp-block-paragraph">Here&#8217;s what this can look like in practice. Imagine an organization sitting at roughly 80/20, reactive to proactive. That&#8217;s not unusual. After about eighteen months of intentional work — stabilizing the environment, retiring old systems, putting monitoring in place — an organization like that could realistically get somewhere between 50/50 and 20/80. Total monthly IT spend might go up significantly, but the number of disruptions staff deal with could drop dramatically. In practical terms, that often looks like an administrative team reclaiming dozens of hours a month that had been eaten by workarounds, manual processes, and waiting on broken systems.</p>



<p class="wp-block-paragraph">That recovered capacity is where the real story is. It&#8217;s what lets a team finally launch the program expansion they&#8217;ve been deferring, or redirect staff time toward work that actually moves the mission forward.</p>



<p class="wp-block-paragraph">That&#8217;s a fundamentally different budget conversation than &#8220;we need more money for IT.&#8221;</p>



<p class="wp-block-paragraph">Knowing the ratio also creates accountability in a healthy way. If you agree together that the goal is to shift from 70% reactive to 50% reactive over the next year, you&#8217;ve got something concrete to track. Not as a gotcha, but as a shared objective — something both sides can look at quarterly and make decisions around together.</p>



<p class="wp-block-paragraph">You don&#8217;t need a fancy assessment to start. Just ask this fundamental question. See what your team or provider says. If they can answer clearly and specifically, that&#8217;s a good sign regardless of the ratio. If they can&#8217;t, that tells you something too.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A Business Guide to AI Policy</title>
		<link>https://www.smartdolphins.com/blog/a-business-guide-to-ai-policy</link>
		
		<dc:creator><![CDATA[Mariola Czerkawska]]></dc:creator>
		<pubDate>Thu, 09 Apr 2026 22:33:39 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[AI for Businesses]]></category>
		<category><![CDATA[AI Policy]]></category>
		<category><![CDATA[Data Residency]]></category>
		<category><![CDATA[IT leadership]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=46814</guid>

					<description><![CDATA[The Reality of Unstructured AI Use&#160; AI use is already happening in most organizations, whether&#160;it’s&#160;formally approved or not. Without clear expectations, employees make individual judgment calls about what data to use, how outputs are applied, and whether results are reviewed.&#160; This creates&#160;real challenges:&#160; The result is increased risk, wasted time, and uneven return on AI&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>The Reality of Unstructured AI Use</strong>&nbsp;</p>



<p class="wp-block-paragraph">AI use is already happening in most organizations, whether&nbsp;it’s&nbsp;formally approved or not. Without clear expectations, employees make individual judgment calls about what data to use, how outputs are applied, and whether results are reviewed.&nbsp;</p>



<p class="wp-block-paragraph">This creates&nbsp;real challenges:&nbsp;</p>



<ul class="wp-block-list">
<li>Data risk from sensitive information entered into public tools  </li>
</ul>



<ul class="wp-block-list">
<li>Inconsistent outputs and client experience  </li>
</ul>



<ul class="wp-block-list">
<li>Lack of accountability for outcomes  </li>
</ul>



<ul class="wp-block-list">
<li>Duplicated effort across teams  </li>
</ul>



<p class="wp-block-paragraph">The result is increased risk, wasted time, and uneven return on AI investment.&nbsp;</p>



<p class="wp-block-paragraph">Unstructured AI use also creates opportunity cost. Teams work in isolation, repeat mistakes, and&nbsp;fail to&nbsp;scale what works across the organization.&nbsp;</p>



<p class="wp-block-paragraph">AI policy is a key step in moving from ad hoc experimentation to consistent, reliable use.&nbsp;</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-dots"/>



<p class="wp-block-paragraph"><strong>Pillar 1: Make AI Use Visible</strong>&nbsp;</p>



<p class="wp-block-paragraph"><strong>Understanding Shadow AI</strong>&nbsp;</p>



<p class="wp-block-paragraph">Shadow AI refers to AI use that happens informally, without oversight or defined expectations. It often&nbsp;emerges&nbsp;because employees are trying to work more efficiently without clear guidance.&nbsp;</p>



<p class="wp-block-paragraph">This can compromise sensitive information or degrade the client experience.&nbsp;</p>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Common Risky Use Cases</strong>&nbsp;</p>



<p class="wp-block-paragraph">Examples include:&nbsp;</p>



<ul class="wp-block-list">
<li>Publishing client-facing content generated by AI without proper review  </li>
</ul>



<ul class="wp-block-list">
<li>Summarizing internal reports using public tools  </li>
</ul>



<ul class="wp-block-list">
<li>Entering internal or client data into AI tools without understanding how that data is handled </li>
</ul>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Creating Visibility&nbsp;into&nbsp;AI Usage</strong>&nbsp;</p>



<p class="wp-block-paragraph">The first step in governing AI is visibility. Leaders should acknowledge that AI is already part of daily work and take a simple inventory of where and how it is currently being used.&nbsp;</p>



<p class="wp-block-paragraph">This is often done through an internal survey. The goal is to surface existing use cases and&nbsp;identify&nbsp;where guidance is needed.&nbsp;</p>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Building Guidelines for Safe AI Use</strong>&nbsp;</p>



<p class="wp-block-paragraph">Organizations may choose to approve specific tools or define which use cases are&nbsp;appropriate in&nbsp;different environments.&nbsp;</p>



<p class="wp-block-paragraph">The goal is to allow teams to experiment safely while ensuring sensitive workflows are handled within secure tools.&nbsp;</p>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Encouraging Shared Learning and Transparency</strong>&nbsp;</p>



<p class="wp-block-paragraph">Creating a shared space for AI learnings helps teams build capability together. For example, a dedicated Teams channel can be used to share workflows, prompts, and lessons learned.&nbsp;</p>



<p class="wp-block-paragraph">This allows organizations to&nbsp;monitor&nbsp;usage patterns while helping teams learn from each other.&nbsp;</p>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Reducing Risk Through Transparency</strong>&nbsp;</p>



<p class="wp-block-paragraph">Shadow AI creates risk when usage is hidden. Encouraging transparency reduces that risk and helps organizations scale AI&nbsp;use&nbsp;more effectively.&nbsp;</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-dots"/>



<p class="wp-block-paragraph"><strong>Pillar 2: Ownership and Accountability</strong>&nbsp;</p>



<p class="wp-block-paragraph">One of the biggest gaps in AI governance is ownership. When no one owns AI, decisions become fragmented and risks go unnoticed.&nbsp;</p>



<p class="wp-block-paragraph">Most organizations&nbsp;benefit&nbsp;from defining two roles:&nbsp;</p>



<ul class="wp-block-list">
<li><strong>AI Owner:</strong> Oversees usage patterns and ensures governance is addressed at a leadership level  </li>
</ul>



<ul class="wp-block-list">
<li><strong>AI Adoption Lead:</strong> Helps teams apply AI in real workflows and supports ongoing adoption  </li>
</ul>



<p class="wp-block-paragraph">These responsibilities can sit within existing roles and typically require only 1–2 hours per week.&nbsp;</p>



<p class="wp-block-paragraph">What matters is clear ownership and a defined path for support and escalation.&nbsp;</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-dots"/>



<p class="wp-block-paragraph"><strong>Pillar 3: AI Principles</strong>&nbsp;</p>



<p class="wp-block-paragraph"><strong>Draw Principles from Your Values</strong>&nbsp;</p>



<p class="wp-block-paragraph">AI principles should be grounded in company values and focused on behavior, not technology. They should be simple, practical, and easy to apply.&nbsp;</p>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Examples of Practical AI Principles</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>AI-generated work is reviewed before being shared externally  </li>
</ul>



<ul class="wp-block-list">
<li>AI supports decision-making but does not replace accountability  </li>
</ul>



<ul class="wp-block-list">
<li>AI is used to improve efficiency without sacrificing quality  </li>
</ul>



<ul class="wp-block-list">
<li>AI outputs are reviewed with the same scrutiny as a new employee’s work<strong> </strong> </li>
</ul>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Guiding Decisions in New Situations</strong>&nbsp;</p>



<p class="wp-block-paragraph">AI policies cannot cover every scenario.&nbsp;Principles help teams make decisions in new or evolving situations while staying aligned with company expectations.&nbsp;</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-dots"/>



<p class="wp-block-paragraph"><strong>Pillar 4: AI Policy Contents</strong>&nbsp;</p>



<p class="wp-block-paragraph"><strong>Positioning the Policy as a Practical Guide</strong>&nbsp;</p>



<p class="wp-block-paragraph">An AI policy should function as a practical guide, not a legal document.&nbsp;It should be clear, concise, and grounded in real workflows.&nbsp;</p>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Core Elements of an AI Policy</strong>&nbsp;</p>



<p class="wp-block-paragraph">At a minimum, an AI policy should include:&nbsp;</p>



<ul class="wp-block-list">
<li>The purpose of AI within the organization  </li>
</ul>



<ul class="wp-block-list">
<li>AI principles  </li>
</ul>



<ul class="wp-block-list">
<li>Approved and prohibited uses  </li>
</ul>



<ul class="wp-block-list">
<li>Expectations for review and oversight  </li>
</ul>



<ul class="wp-block-list">
<li>Ownership and governance structure  </li>
</ul>



<ul class="wp-block-list">
<li>How and when the policy will be updated </li>
</ul>



<div style="height:15px" aria-hidden="true" class="wp-block-spacer"></div>



<p class="wp-block-paragraph"><strong>Keeping Policies Usable and Relevant</strong>&nbsp;</p>



<p class="wp-block-paragraph">Policies that are too complex or disconnected from daily work will be ignored. Clarity and usability should be&nbsp;the priority.&nbsp;</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-dots"/>



<p class="wp-block-paragraph"><strong>From Control to Capability</strong>&nbsp;</p>



<p class="wp-block-paragraph">AI is becoming a core business capability,&nbsp;similar to&nbsp;email or cloud platforms. Organizations that succeed do not rely on informal experimentation. They build light, intentional structure through visibility, ownership, shared principles, and practical policy.&nbsp;</p>



<p class="wp-block-paragraph">The goal of AI governance is confidence, not restriction. When expectations are clear, teams can use AI effectively, responsibly, and with less risk.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Not Done</title>
		<link>https://www.smartdolphins.com/blog/not-done</link>
		
		<dc:creator><![CDATA[Dave Monahan]]></dc:creator>
		<pubDate>Wed, 18 Feb 2026 23:32:20 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Dave Monahan]]></category>
		<category><![CDATA[Smart Dolphins IT Solutions]]></category>
		<guid isPermaLink="false">https://www.smartdolphins.com/?p=45310</guid>

					<description><![CDATA[People have started asking me the question. Not directly, usually. It shows up sideways, in conversations at industry events or over coffee. &#8220;So, 25 years&#8230; what&#8217;s next?&#8221; The question carries a set of assumptions. Guy in his 50s, been at it a while, business is doing well. The script says this is where you start&#8230;]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph" id="ember53">People have started asking me <em>the question</em>.</p>



<p class="wp-block-paragraph" id="ember54">Not directly, usually. It shows up sideways, in conversations at industry events or over coffee. &#8220;So, 25 years&#8230; what&#8217;s next?&#8221; The question carries a set of assumptions. Guy in his 50s, been at it a while, business is doing well. The script says this is where you start thinking about an exit. Cash out. Slow down. Enjoy the fruits.</p>



<p class="wp-block-paragraph" id="ember55">I get it. And I&#8217;ve watched a lot of my peers follow that script. Some were tired. Some hit a ceiling they didn&#8217;t want to push through. Some just saw a good offer and took it. I don&#8217;t judge any of that. Everyone&#8217;s working with their own set of circumstances, and selling a business you built is a legitimate choice that can change your life in meaningful ways.</p>



<p class="wp-block-paragraph" id="ember56">But it&#8217;s not my choice. At least not right now. And I think the reasons why might be worth sharing.</p>



<p class="wp-block-paragraph" id="ember57">There&#8217;s a common philosophy in business: build it like you&#8217;re going to sell it. Get your systems tight, your team strong, your financials clean. Make the thing attractive to a buyer. Here&#8217;s what&#8217;s funny about that. It&#8217;s the same logic as fixing up your house to put it on the market. You finally renovate the kitchen, paint the trim, stage everything just right. Then you walk through it and think&#8230; why am I selling this place? It&#8217;s never been better.</p>



<p class="wp-block-paragraph" id="ember58">I think the same thing applies to a business. If you do the hard work of building something that doesn&#8217;t revolve around you, that runs well, that creates value for the people in it, you&#8217;ve built something worth keeping. The very things that make it sellable are the things that make it worth owning and the things that make it worth continuing.</p>



<p class="wp-block-paragraph" id="ember59">And I think that&#8217;s where some business owners get stuck. It&#8217;s not that owning a business is inherently draining. It&#8217;s that they built one that needs them at the centre of everything. Every decision, every client relationship, every fire. That&#8217;s exhausting after 15 or 20 years. Of course you want to escape that.</p>



<p class="wp-block-paragraph" id="ember60">But the escape impulse might be a symptom, not a solution. Selling doesn&#8217;t fix the pattern. It just ends it.</p>



<p class="wp-block-paragraph" id="ember61">I&#8217;ve tried, imperfectly and over a long time, to build Smart Dolphins so it doesn&#8217;t need me in the middle of things. Not because I was planning to leave, but because I think that&#8217;s just a better business. It&#8217;s better for the team. It&#8217;s better for clients. It&#8217;s better for me. I get to choose where I put my energy instead of the business making that choice for me.</p>



<p class="wp-block-paragraph" id="ember62">So when I think about what I actually want, it&#8217;s not an exit. It&#8217;s flexibility. Working from somewhere warm for a couple months in the winter. Spending my time on things that matter most rather than whatever&#8217;s on fire. Still learning, still being challenged by new problems.</p>



<p class="wp-block-paragraph" id="ember63">That probably sounds simple, but getting there has been the work of 25 years. And I&#8217;m still working at it!</p>



<p class="wp-block-paragraph" id="ember64">Here&#8217;s what I&#8217;ve come to believe, though. A business built with intention can actually be one of the most freeing things in your life. You have a place to be productive and creative. You&#8217;re connected to people you care about. You have problems worth solving. What does selling give you? A blank calendar. Some of the people I know who sold eventually went looking for something similar to fill it.</p>



<p class="wp-block-paragraph" id="ember65">I&#8217;ve watched peers cash out, enjoy life for six months or a year, and then start circling back. Some started consulting. Some got into private equity. Some started new businesses in the same or adjacent industry they just left. Which always makes me wonder: what if they&#8217;d just kept building what they originally built?</p>



<p class="wp-block-paragraph" id="ember66">I&#8217;ll be honest. There have been hard stretches where I wondered if I should move on. Big challenges that tested me. Times where I genuinely wasn&#8217;t sure I could lead the next version of this company. A growing business asks things of you that you haven&#8217;t learned yet, and that gap can feel pretty permanent when you&#8217;re in it.</p>



<p class="wp-block-paragraph" id="ember67">But I think most of those ceilings are ones we build for ourselves. We get comfortable. We mistake familiarity for limitation. The skills and growth required to lead a bigger, more complex business aren&#8217;t genetic. They&#8217;re learnable. The question is whether you&#8217;re willing to do the uncomfortable thing.</p>



<p class="wp-block-paragraph" id="ember68">And look, when you&#8217;ve been at it this long and things are going well, coasting is tempting. Just protect what you&#8217;ve built. Stay comfortable. But the stretches I look back on most fondly aren&#8217;t the easy ones. They&#8217;re the ones that cost me sleep. The ones where I wasn&#8217;t sure it would work out. Doing hard things doesn&#8217;t feel meaningful while you&#8217;re in it. It does after.</p>



<p class="wp-block-paragraph" id="ember69">Writing 25 insights from 25 years has a feeling of finality to it. Like I&#8217;m packaging up the lessons and putting a bow on things. But I might only be halfway through. There&#8217;s a lot of runway ahead, and I have a belief that some of the most interesting chapters are still ahead.</p>



<p class="wp-block-paragraph" id="ember70">I&#8217;m not naive about that. The world changes. Circumstances change. Maybe something happens that makes selling the right call. I&#8217;m open to that possibility. But I&#8217;m not looking for an exit. I&#8217;m not building toward a finish line. I&#8217;m building toward more of what I already love: a great team, work that matters for clients that matter, interesting problems, and the room to keep evolving how I show up in all of it.</p>



<p class="wp-block-paragraph" id="ember71">So no, I&#8217;m not retiring. I&#8217;m not done.</p>



<p class="wp-block-paragraph" id="ember72">Can&#8217;t wait to write 50 insights from 50 years.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph">What’s this 25/25 stuff about?:&nbsp;<a href="https://www.smartdolphins.com/blog/25-years-25-insights">25 YEARS, 25 INSIGHTS – Reflections on Growth, Leadership and Resilience | Smart Dolphins IT Solutions Inc.</a></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
