SoCo Signals
Practical guidance on IT strategy, AI adoption, and getting more value from your technology investments — from a 25-year IT executive who works in Southern Colorado.
When Your Software Bill Jumps 1,500% Overnight
QuickBooks went up quietly. Harvest went up sixteen-fold. VMware gave its customers no choice. Different speeds, same playbook.
A UK firm's software bill went from $130 to $2,110 a month after its new owners changed the pricing model. QuickBooks and VMware tell the same story at different speeds. Five habits that catch the next increase before it lands.
AI Meeting Assistants Are Listening to Everything — and Nobody Read the Fine Print
The tools are useful. The legal exposure is real. Most businesses haven’t thought through either.
AI meeting assistants have spread into business meetings faster than almost any technology in 25 years. They’re genuinely useful — but the convenience hides consent law violations, litigation discovery risks, and data ownership questions most businesses haven’t considered. Here’s what to do about it.
Ransomware's Favorite Target Isn't Who You Think
New data shows three-quarters of victims sit in a narrow revenue band — and most don't realize they're in it.
A Black Kite study of 13,336 ransomware incidents found 73% of victims are mid-sized companies with $10M–$1B in revenue. The lower mid-market — $10M to $50M — accounts for the largest share. The gaps are basics: unpatched software, weak email authentication, known vulnerabilities nobody fixed.
The AI Adoption Gap Is Getting Wider — and Small Businesses Are on the Wrong Side
The tools are everywhere. The know-how to use them isn't. That's the real divide.
Census Bureau data shows AI adoption rising among large companies but flat for businesses with fewer than 20 employees. The bottleneck isn't access to tools — it's the knowledge and capacity to implement them. Here's what actually closes the gap.
T-Mobile Just Lost a Lawsuit Over How It Told You About a Breach
The breach isn't always what gets you sued. Sometimes it's the notification.
A judge ruled T-Mobile violated Washington State's data breach notification law — not because of the hack, but because of how they told people about it. Every state has its own notification rules. If your breach response plan doesn't account for them, the notification itself becomes a separate liability.
159 AI Laws Passed Last Year — Is Your Business Keeping Up?
States enacted 159 AI-related laws in 2025 and another 109 by mid-2026. Federal pushback hasn't slowed the pace. If your business uses AI for hiring, customer service, pricing, or content, this matters whether you know it or not.
State legislatures passed 159 AI-related laws in 2025, and another 109 in the first half of 2026 alone. The pace isn't slowing — it's accelerating. Here's which of them actually reach a small business, and what to do before one of them reaches yours.
When to Fire Your MSP
Most businesses don't fire their managed service provider because of a single failure. They fire them because of a thousand small disappointments — and they usually wait two years longer than they should have.
Your MSP holds the keys to your network, your data, your email, and your backups. When it works, it's invisible; when it doesn't, everything stops. Here's how to tell the difference between a rough patch and a relationship that's finished — and how to leave without making things worse.
Where Your IT Budget Is Bleeding (and You Don't Know It)
SaaS subscriptions nobody uses, cloud bills nobody reads, and MSP invoices that haven't been reviewed in years. Most businesses are leaking 15 to 25 percent of their IT spend — and finding it is simpler than you think.
Most owners know their rent and their payroll to the dollar. Ask what they spend on technology and the answer is a guess — because IT costs are scattered across credit cards, department budgets, and auto-renewals nobody reads. That's exactly where the money leaks, and here's how to find it.
You Replaced People With AI. Now You're Rehiring Them.
Ford, Klarna, and a growing list of companies are walking back AI-driven layoffs. The reasons: performance gaps, customer backlash, and a cost equation that doesn't add up.
Ford just rehired 350 engineers after the AI it deployed for quality control couldn't match what humans caught. It's not an isolated reversal. Here's what the companies walking back AI layoffs got wrong — and how to avoid making the same bet.
Six Weeks Ago We Said the CMMC Math Didn't Work. The Pentagon Just Agreed.
Phase II of the Pentagon's cybersecurity certification program was set to hit small contractors in November. Yesterday, the Department of War hit pause — citing the same cost burden we flagged in June.
In June we argued that CMMC Phase II would hit small defense contractors with requirements they couldn't afford. The Pentagon has now suspended it, citing the same cost burden. Here's what the pause actually changes for Colorado suppliers — and what you should keep doing anyway.
Your Cyber Insurance Renewal Just Got Harder. Here's What They're Asking For.
The questionnaire that used to be two pages is now twelve. The carriers have stopped taking your word for it — and that's actually good news.
The global cyber insurance market is projected to hit $28 billion by 2030 — and premiums and requirements are both climbing. MFA everywhere, documented incident response plans, and proof of restore testing are now table stakes. Here's what to do before your next renewal lands.
Fractional CIO: What It Is, What It Costs, and Why It Beats Hiring
You need senior technology leadership. You don't need a six-figure executive on payroll. There's a middle ground, and more businesses are finding it.
A full-time CIO costs $180K–$250K a year. A fractional CIO delivers the same leadership at $3K–$8K a month. Here's what they actually do, when the model makes sense, and how it's different from what your MSP provides.
When Your Vendor's Vendor Gets Hacked
You can lock every door in your own building. But if the company that runs your payroll, hosts your email, or manages your customer data gets breached — it's your problem too. And it's happening more than most business owners realize.
Texas Parks & Wildlife lost 3 million records through a vendor breach. 85% of CISOs can't see third-party threats. And the FBI warns of attackers who impersonate IT vendors in person. Your security is only as strong as the weakest vendor in your orbit.
Colorado Hits Reset on AI Regulation — What It Means for Your Business
The state that passed the nation's toughest AI law just replaced it with something simpler. If you use AI in your business, here's what actually changed.
Colorado's landmark AI Act was repealed and replaced with a narrower law focused on transparency instead of risk management. If you use AI for hiring, pricing, lending, or tenant screening, here's what you actually need to know — and what you don't.
CMMC Enforcement Just Got Real — and Most Contractors Aren't Ready
After years of planning and PowerPoint decks, the Pentagon's cybersecurity certification program is finally in contracts. For small defense suppliers — including hundreds in Colorado — the math doesn't add up.
CMMC is no longer a future problem. Phase 2 enforcement arrives November 10, and 70% of defense contractors budgeted less than the Pentagon's own minimum estimate. For Colorado's 55,000 aerospace workers, the math on compliance costs doesn't work — and 15–20% of the defense industrial base may exit by 2027.
The Government's Cybersecurity Agency Leaked Its Own Secrets on GitHub
When CISA and Colorado both leave the keys out in public, what does that mean for the rest of us?
A CISA contractor left AWS GovCloud keys and internal passwords on a public GitHub repo for six months. Combined with Colorado's 2024 voting-system password leak, these incidents reveal a pattern that has nothing to do with technology — and everything to do with governance gaps every small business shares.
Small Businesses Are Spending More on Security — and Still Getting Hit. Here's What's Missing.
The gap isn't money. It's having an actual plan.
New research shows small and mid-size businesses are putting real money into cybersecurity — but actual protection hasn't kept up. The gap isn't money. It's buying tools without a strategy, and it turns out that's an expensive way to stay vulnerable.
Your SMB Doesn't Need an AI Strategy. It Needs an AI Use Case.
Why the 12-month roadmap starts with one problem, not a platform.
The instinct when leadership says "we need an AI strategy" is to go big — committees, consultants, 60-page frameworks. That document will be expensive and almost certainly wrong within six months. Here's what actually works: start with one problem worth solving and let strategy emerge from what you learn.