Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

C2 provides technology services and consultation to businesses and individuals.

T (818) 584 6021
Email: [email protected]

C2 Technology Partners, Inc.
26500 Agoura Rd, Ste 102-576, Calabasas, CA 91302

Open in Google Maps
QUESTIONS? CALL: 818-584-6021
  • HOME
  • BLOG
  • SERVICES
    • Encryption
    • Backups
  • ABOUT
    • SMS Opt-In Form
    • Terms and Conditions
    • Privacy Policy
FREECONSULT

Why Small Businesses Get Targeted by Ransomware (And How to Fight Back)

  • 0
Christopher Woo
Wednesday, 30 September 2026 / Published in Woo on Tech

Small businesses don’t get targeted by ransomware because they’re interesting. They get targeted because they’re profitable and poorly defended, and attackers do the math the same way any business does.

I’ve said this to clients for years, and I still watch the same disbelief cross their faces. Nobody wants to think a fifty-person accounting firm in Southern California is worth an attacker’s time. The numbers say otherwise, and they’ve been saying so for a while now.

The Numbers Behind Small Business Ransomware Protection

80% of small and midsize business breaches now involve ransomware, compared to 39% at large enterprises, according to Verizon’s 2025 Data Breach Investigations Report.  That difference isn’t random. Larger companies have dedicated security staff, segmented networks, and faster patching. Most small firms have neither the headcount nor the budget for either one, and attackers know it.

Professional services firms specifically, law offices, accounting practices, and consulting firms, became one of the most heavily targeted sectors in ransomware data from the recovery firm Coveware. That tracks with what I see. These firms hold exactly what a ransomware operator wants: clients’ financial records, case files, personal data, and businesses that can’t afford to stay offline during tax season or a court deadline.

It’s Not Personal, and That’s the Point

I tell clients it used to feel personal. Some kid in a basement decides to mess with your business specifically. That’s mostly gone. Now it’s closer to pollution. It’s always pressing in from the outside, looking for a weak point, with no interest in who you are specifically. It just needs one person to click one link, because sending a million emails costs almost nothing and only one has to land.

That shift matters because it changes what “not a target” truly means. Nobody is deciding your firm doesn’t matter enough to attack. Nobody is deciding anything about your firm at all until the attack already worked.

I’ve had clients tell me their business is too boring to bother with, that they don’t have anything a criminal would want. I remind them that a ransomware operator doesn’t care what the business does. They care whether the firm can pay to retrieve its files and whether its defenses are weak enough to be worth the effort. A fifty-person accounting firm during tax season checks both boxes better than almost any target I can think of.

What Reduces Risk

Multi-factor authentication on every account, not just email, closes the door that stolen credentials alone used to open. It’s the single control I push hardest on, because it stops the most common way attackers get in with the least disruption to how your team works.

Endpoint security solutions that actively monitor and respond, not just antivirus software that scans on a schedule, catch the behavior of an attack in progress instead of waiting to recognize a known virus signature. The difference matters because most modern ransomware doesn’t look like the viruses that older antivirus tools were built to catch.

Backups that are tested, not just scheduled, are the difference between a bad week and a business-ending event. I’ve seen firms discover their backups had been silently failing for months, and they only found out during the one week they actually needed to restore something.

Incident response support, meaning an actual written plan for the first hour after something goes wrong, matters more than most firms expect. The firms that recover fastest aren’t the ones with the most expensive tools. They’re the ones who already know who to call, what to shut down first, and who’s authorized to make that call at two in the morning.

What This Costs vs. What an Attack Costs

Every one of these measures costs money and a little bit of friction for your staff. I won’t pretend MFA prompts are fun or that anyone enjoys a tabletop exercise for an incident that hasn’t happened yet.

Weigh that against a ransomware event that takes your firm offline during a filing deadline, a court date, or tax season, and the math stops being close. Most firms that get hit spend more recovering from a single incident than they would have spent on prevention for several years.

If you don’t know where your firm currently stands on any of this, that’s the actual starting point, not buying more software. Start with an honest look at your multi-factor authentication coverage, your backup testing, and whether anyone in your office could answer “what do we do first” if a ransomware alert went off tomorrow.

Why Things Break More Than They Used To (It’s Not Just You)

  • 0
Christopher Woo
Wednesday, 23 September 2026 / Published in Woo on Tech

I walk into a room, and things start working. It happens often enough that my clients have started joking about it, like I’m carrying some kind of charm. I don’t think that’s what’s actually going on. More likely, the equipment was already failing quietly, and I’m just the one who finally noticed.

This came up in a conversation with a colleague around my age, who told me he missed the days when Outlook just worked properly. I asked him to actually think back and tell me what year that was. He got quiet for a second, then admitted it was around 2006. Twenty years felt like yesterday to both of us, which tells you something about how we experience time, but it also missed a bigger point. Outlook has real problems today. The difference is that almost everything else does too, and that isn’t in our heads.

Why Reliability Declined

For a stretch of time around the pandemic, the semiconductor industry took a series of direct hits. In February 2021, a severe winter storm cut power across Texas and forced major chip plants, including facilities run by Samsung and NXP, to shut down for weeks. Forbes covered the disruption in detail as it was unfolding, and the effects rippled outward for years afterward, showing up in everything from laptops to cars.

Manufacturers never fully rebuilt that lost capacity before demand for computers and phones spiked further. On top of that, plenty of companies responded to rising costs by trimming quality wherever customers were least likely to notice right away. A laptop that used to last five years might now last three. A router that once ran quietly in a closet for a decade now needs replacing much sooner. None of this is a conspiracy. It’s a straightforward response to real supply problems, and it happened right as more of our lives moved onto these devices than ever before.

What This Means for You

If your equipment is failing more often than it used to, it probably isn’t because someone in your office is doing something wrong. The hardware itself likely isn’t built to the standard you remember, and that standard isn’t coming back on its own.

The response to that isn’t nostalgia. It’s planning around it. Replace hardware on a schedule instead of waiting for it to die, and treat backups as a routine part of doing business rather than something you scramble for after a crisis. A three- to four-year replacement cycle for laptops and a firm habit of testing your backups, not just running them, will save you more grief than any amount of wishing your equipment behaved the way it did a decade ago. A firm that expects a piece of equipment to eventually fail, and plans for it, loses an afternoon. A firm that assumes everything will keep running the way it did in 2015 loses a great deal more than that.

I still get called in, and things start working again, and I still let the joke about being some kind of charm ride, because it’s funnier than the real explanation. The real explanation is aging equipment paired with a supply chain that still hasn’t fully recovered from a rough couple of years. None of that is mysterious, and none of it is going away on its own, so the businesses doing best right now are the ones planning around it instead of being surprised by it every time.

If your team hasn’t looked at when your hardware was actually purchased, not when it feels like you bought it, that’s a good place to start before your next refresh.

The Jack Fairy: What Happens Before Your Internet Just Works

  • 0
Christopher Woo
Tuesday, 15 September 2026 / Published in Woo on Tech

A few years ago, one of my technicians got cornered by a client asking why their internet always seemed to just work. My colleague told her it was the jack fairy. She meant me.

I think about that a lot, because it gets at something people almost never notice about good IT support. When everything works, nobody thinks about how. The internet flows out of the wall, the printer talks to the copier, the phone rings when it’s supposed to. Nobody sees the effort behind any of it. They just see the result, and the result looks like magic.

The Alarm Nobody Could Find

Not long ago, I got called to a client’s office because an alarm was going off and nobody could tell where it was coming from. The only person in the building that day wasn’t a “tech person,” and she didn’t need to be for her job. She took pictures on her phone, trying to describe the sound to me over the phone, and I could hear her starting to panic. I told her I’d be there in a few minutes, since it was on my way anyway.

When I got there, the alarm was buried in a network closet stacked with odds and ends. Boxes, a couple of decorative pieces, nothing that belonged in a server closet. I climbed over and around it all, doubting I’d fit if I were any bigger, until I found the panel and shut it off. She thanked me like I’d performed surgery. All I’d done was know where to look and be willing to climb over some stuff to get there.

What Good IT Support Looks Like

That’s most of what good IT support is. Knowing where things are and understanding how a business runs day-to-day well enough to spot what’s out of place before it turns into an emergency. None of that requires a special gift, just consistent attention, long before anyone calls in a panic.

The part nobody sees is most of the job. A firm with someone quietly monitoring their systems and catching a failing piece of hardware before it dies on a Friday afternoon rarely has a dramatic story to tell. A firm whose IT provider only shows up once something has already broken almost always does, and it’s usually an expensive one. Research from Information Technology Intelligence Consulting, which surveys businesses on exactly this question, has repeatedly found that a large share of small and mid-sized companies put the cost of even a single hour of unplanned downtime in the tens of thousands of dollars. Businesses that never feel that cost aren’t lucky. Someone was paying attention before there was a fire, occasionally a literal one.

Technology Is Just the Excuse

Part of the reason this looks like magic is that my industry does a poor job explaining what we do all day. We talk about firewalls and patch schedules like the details are the point. They rarely are, for the client anyway. The real point is that a law office doesn’t miss a filing deadline because someone moved a copier and forgot to mention it. The real point is that a property manager doesn’t lose an afternoon locked out of a shared drive during a lease signing. Technology is just the excuse. The job is understanding how a business runs and staying a step ahead of whatever might interrupt it.

So next time something at your office quietly works exactly the way it’s supposed to, the printer connects, the email doesn’t crash, resist the urge to call it luck. Ask your IT provider one question instead: what did you do this month that I never had to see? If they can answer that clearly, you’ve found your own jack fairy. If they can’t, you’re probably paying for emergencies instead of prevention, and that’s always the more expensive way to run a business.

Anthropic’s AI Security Incident Wasn’t a Machine Rebellion. It Was a Human Mistake.

  • 0
Christopher Woo
Tuesday, 08 September 2026 / Published in Woo on Tech

Anthropic just published a blog post admitting that one of its Claude models escaped a supposedly sealed test environment and gained unauthorized access to three real companies. My inbox filled up within hours. Clients wanted to know if their AI was about to go rogue.

It isn’t. Read the actual report, and the story is a lot less Terminator and a lot more familiar: someone on the setup side left a door unlocked.

What Anthropic actually found

Anthropic reviewed 141,006 evaluation runs from its cybersecurity testing program, the kind of testing every serious AI lab runs before releasing a model. Out of that entire set, three incidents stood out. In each one, Claude was given a capture-the-flag challenge: find a piece of hidden information on a network and retrieve it, using whatever method works.

Claude was explicitly told that the test environment had no internet access. That statement was wrong. A misconfiguration between Anthropic and a third-party evaluation partner, Irregular, left the machines connected to the real internet. When Claude’s search for the flag led it to real systems, it had no reason to think they weren’t part of the simulation. So it treated them like part of the simulation, and in a handful of cases, it got in.

The techniques involved were not exotic. A weak password here, an exposed debug page there, a missing check on a package registry somewhere else. These are the same causes behind most breaches I’ve dealt with in 35 years of doing this work.

The tell: this was a setup failure, not a rebellion

The detail that matters most is the one getting the least attention in the panicked headlines. This was, in Anthropic’s own words, closer to an operational failure than a model behaving badly on purpose. The model was told a specific thing about its environment. That thing was false. It acted on false information, which is exactly what happens to humans every single day of the week.

There’s also a detail worth sitting with. The three affected companies hadn’t detected the activity themselves. Anthropic found it during an internal review and reached out to them. Their own AI told on itself before their security did.

We’ve seen this movie before, minus the AI

I’ve watched this exact pattern play out in traditional IT breaches for decades. When Kaseya, the platform that powers a huge chunk of the managed services industry, including ours, had a major security incident several years back, the story that circulated afterward was that an intern had made the mistake. Everyone in the industry I talked to at the time had the same reaction: an intern doesn’t have that kind of access unless someone above them set it up that way.

Breaches are rarely the result of some sophisticated actor doing something no one could have anticipated. They happen when a system is configured wrong, a permission is left too open, or a check that should have run didn’t. Anthropic’s incident report reads like every other post-mortem I’ve read in this industry, except that this time the thing exploiting the gap was a language model rather than a person with a laptop.

AI is a chainsaw, not a mind of its own

I tell clients this all the time: AI is as dangerous as a chainsaw. In the right hands, with the right protective equipment, it’s one of the most useful tools you can put in front of a team. Handed to someone in flip-flops with no guard on the blade, it will absolutely take a toe off. The tool didn’t do anything wrong in either case. It did exactly what it was pointed at.

Claude didn’t decide to attack three companies. It was told to find a flag, told the range was sealed, and given no boundary on how to look. When the boundary turned out to be fiction, it kept doing the job it was assigned to do. That’s not a machine developing intent. That’s a machine following instructions built on bad information, at a scale and speed no human could match, which is exactly why the setup around these tools matters more than ever, not less.

What this means if you’re running a business, not a research lab

You don’t have to be evaluating frontier models to have this exposure. If your firm has rolled out AI tools this year, and most professional services firms I work with have, ask yourself whether someone actually configured those tools correctly and wrote down how they’re allowed to be used. That’s the question that matters. Whether the AI itself can be trusted is a much smaller concern by comparison.

I’ve written five AI usage policies for clients in the last two weeks alone. None of them had an incident, but they had never written down what their AI tools are allowed to touch, who’s responsible for checking the output, and what happens when something goes wrong. That gap is where the next headline comes from, and it has nothing to do with the AI misbehaving.

If Anthropic, with a dedicated security team and a third-party evaluation partner, still had a misconfiguration slip through, it’s worth asking what’s sitting unchecked in your own environment right now. Reach out if you need help doing that.

HIPAA, PCI, SOC 2: Compliance for Companies with No Idea Where to Start

  • 0
Christopher Woo
Wednesday, 02 September 2026 / Published in Woo on Tech

Most professional services firms assume compliance standards apply to somebody else. Then a client sends a security questionnaire before signing a new engagement, or a cyber insurance renewal asks for documentation nobody in the office has seen before.

That is usually the first time compliance readiness for a small business stops being an abstract phrase and turns into a deadline. Accounting practices, law offices, and property management firms handle financial records, personal information, and sometimes payment data every day. That activity puts many of them within the scope of HIPAA, PCI DSS, or SOC 2 requirements, even though no one at the firm set out to become a regulated business.

These firms aren’t careless. Nobody explained which rules actually apply, what those rules require in practice, or where a firm this size should start.

Why Compliance Is Showing Up in More Conversations

Insurance carriers tightened their underwriting standards over the past few years. Cyber liability policies now ask pointed questions about multi-factor authentication, backup testing, and incident response plans before a carrier issues or renews coverage. A firm that can’t answer those questions in writing risks a higher premium or a denied claim.

Clients are asking the same questions. Banks, private equity firms, and larger corporate clients increasingly require a completed security questionnaire or a SOC 2 report before they hand a vendor sensitive data. A law firm handling a corporate client’s litigation, or an accounting firm managing a private equity portfolio company’s books, can lose the engagement over a missing document, not a missing capability.

Professional services firms have also become a bigger target than most owners realize. Ransomware groups shifted their attention toward legal, accounting, and consulting firms, which accounted for close to one in five ransomware attacks in a recent quarter, according to the ransomware recovery firm Coveware. Attackers know these firms hold client financial records, case files, and personal data, and that most run leaner security than hospitals or banks do.

None of this means a fifty-person accounting firm needs a compliance department. It means understanding which standards apply to the business and building a short list of documented practices that satisfy most of what insurers, clients, and auditors ask for.

What HIPAA, PCI, and SOC 2 Actually Cover

HIPAA governs protected health information and applies to healthcare providers, as well as vendors and business partners that handle health data on their behalf. A property management firm running a medical office building, or an accounting practice with healthcare clients who share patient billing data for reconciliation, can find HIPAA obligations attached to work that never looked medical on the surface.

PCI DSS applies to any business that processes, stores, or transmits credit card data. Property management firms collecting rent through an online portal, and law firms accepting card payments for retainers, both fall under PCI requirements the moment a card number touches their systems, even indirectly through a payment processor.

SOC 2 is different from the other two. It isn’t a law. It’s an audit standard that proves an organization has real controls around the security, availability, and confidentiality of data. Firms don’t usually pursue SOC 2 because a regulator demands it. They pursue it because a client, a bank, or an insurer asked for the report, and without it, the deal stalls.

This plays out constantly: an accounting firm picks up outsourced payroll work for a physician client and signs on to keep handling billing reconciliation, then realizes months later that arrangement pulled HIPAA obligations into scope. That kind of realization arrives late more often than it should, usually attached to a deadline.

How to Figure Out Which Ones Apply to You

Start with three questions instead of the full text of each standard.

  1. Does the firm handle protected health information, directly or through a client relationship? If yes, HIPAA obligations are worth reviewing with someone who understands both the technology and the legal exposure.
  2. Does the firm accept, store, or transmit credit card numbers in any form, including through a client portal or a property management platform? If yes, PCI DSS requirements apply, even at a small scale.
  3. Has a client, bank, or insurer ever asked for a completed security questionnaire or a SOC 2 report? If this keeps happening, formal readiness work will save more time than answering the same fifteen-page questionnaire from scratch every quarter.

Most firms find they touch at least one of these standards without ever intending to.

What Readiness Actually Looks Like

Compliance readiness for a fifty- to one hundred fifty-person professional services firm rarely means a five-hundred-page policy binder. It means having documented, working answers to the questions insurers and clients keep asking: multi-factor authentication on every account, tested backups, a written incident response plan, defined access controls, and a basic record of how vendors who touch client data are vetted.

Firms that build these practices once tend to stop dreading every renewal and every new client questionnaire, because the answers already exist. The alternative, scrambling to document controls under deadline pressure, costs more time and usually produces weaker documentation than doing the work upfront.

If you want a structured way to see where your firm stands, our Cyber Liability Insurance Readiness Checklist walks through the eight security categories insurers and compliance frameworks care about most, and shows you exactly where professional services firms typically fall short. Download it, work through it with your team, and you’ll know within an hour which of these standards deserve real attention.

The Empty Desk Problem: What Hybrid Work Reveals About Your Technology 

  • 0
Christopher Woo
Tuesday, 25 August 2026 / Published in Woo on Tech

The laptop a firm handed out in 2021 says more about how that firm sees its people than any mission statement on the website. Fall is when a lot of professional services firms quietly reassess their hybrid arrangements, and the technology sitting underneath those arrangements is finally getting a second look. Most of it was never chosen. It was grabbed in a hurry, and it’s been running on autopilot ever since.

That’s the real story behind the empty desks. Two years ago, speed mattered more than fit. A firm bought whatever laptops were in stock, set up remote access however it could be set up fastest, and called it a hybrid work technology strategy. Nobody planned for this to still be the plan years later, but for many firms, it is.

How Hybrid Work Technology Strategy Became an Afterthought

The urgency of 2020 explains many bad technology decisions, and most of them were reasonable at the time. Firms needed people to work from home within days, not months, so IT teams and office managers grabbed whatever would solve the immediate problem: a cheap VPN, a shared login because setting up individual remote access felt like a project for later, and a laptop that was available, not necessarily one built for years of daily use outside an office.

Later never came. The urgent fix became the permanent setup, and most firms never circled back to ask whether it was still the right one. A hybrid arrangement that was supposed to be temporary is now a fixture, running on infrastructure that was never meant to last this long.

That breach matters more for accounting firms, law offices, and property management companies than for many other industries, because these firms handle financial records, case files, and tenant data that require real security, not just a shared password and good intentions.

What Your Return to Office Technology Decisions Say

Return to office technology decisions are where a firm’s actual priorities show up, whether leadership intends that or not. A partner who insists on badge access and desk assignments for everyone, while still routing sensitive client files through a personal email account for remote staff, is telling their people something about which risks matter and which don’t.

Consider two firms making the same decision this fall. One firm brings people back to standardize collaboration and reviews its technology at the same time, replacing shared logins with individual, secure remote access and giving every employee a properly configured laptop regardless of where they sit that week. The other firm brings people back and changes nothing about the technology, because the badge readers were the visible problem and the infrastructure underneath was easy to ignore.

Employees notice the difference. One approach says the firm is thinking about how people work. The other says the firm is managing appearances and hoping the technology holds together quietly in the background.

The second firm usually isn’t being careless on purpose. Leadership is focused on the visible, immediate questions: how many days in the office, how the space gets used, whether the conference rooms are booked. The technology underneath rarely makes that agenda, because it’s been quietly working well enough not to cause a visible fire. Well enough isn’t the same as right, and firms usually don’t find out the difference until a laptop fails at the worst possible moment or a shared login turns into a real security incident.

Workplace Culture and IT Are the Same Conversation Now

Workplace culture and IT used to sit in separate meetings, one for HR and one for whoever handled the servers. That divide doesn’t hold up anymore. The technology a firm gives its people, and how much thought went into it, is now part of how that firm treats its employees, not a separate operational detail.

An office manager working from a five-year-old laptop with a VPN that drops twice a day isn’t just dealing with a technology problem. She’s getting a daily reminder of where she ranks on the list of things the firm decided were worth fixing. A partner who gets a same-day replacement when something breaks, while staff wait weeks for a ticket to move, is communicating a hierarchy whether anyone says it out loud.

None of this requires a firm to spend more than it already does. It requires deciding, on purpose, that the technology setup matches what the firm says it believes about its people, instead of running on whatever got assembled in a hurry years ago.

We work almost exclusively with accounting practices, law offices, and property management companies, and the firms that get this right tend to share one habit. They treat a remote employee’s laptop and access setup as seriously as they’d treat the chair and monitor at an in-office desk, not as an afterthought handled once and forgotten.

Before You Finalize This Fall’s Hybrid Plan

Walk your current setup the same way you’d walk a new hire through the office. Look at what every remote employee is using, not what the original rollout plan said they’d be using. 

Note where shortcuts became permanent and where one role gets treated differently than another for no real reason.

That walkthrough will tell you more about what your firm values than any culture survey, and it’s the honest starting point before you lock in how hybrid work looks for the next two years.

If you’re noticing gaps, shortcuts, or security risks, reach out to us to create a secure remote system for you.

Your Employees Are Already Using AI Wrong (They’re Just Too Scared to Tell You)

  • 0
Christopher Woo
Monday, 17 August 2026 / Published in Woo on Tech

Your staff is already using AI, whether you’ve approved it or not. Some of them are pasting client contracts into ChatGPT to draft a summary faster. Others haven’t touched it at all, because they’re afraid of looking replaceable or afraid of breaking something they don’t understand. I’ve sat across from both types of employees, often at the same firm, and both groups have the exact same problem. Nobody ever explained what the tool is.

I’ve been working in technology long enough to remember when automation meant macros in Excel. Now AI shows up in customer service chatbots, document drafting, data analysis, and half the software your firm already pays for, often without anyone announcing it. That speed is real. So is the risk, especially for people who treat AI like a shortcut instead of a tool with limits.

Why Employees Are Using AI Incorrectly at Work

Most employees using AI incorrectly at work aren’t being careless. They’re being efficient, which is exactly the problem. An associate under deadline pressure isn’t thinking about data handling policy. He’s thinking about getting a first draft done before five o’clock, and ChatGPT does that faster than he can.

I watched this happen at an accounting firm I work with. A staff accountant pasted a client’s full financial statement into a public AI tool to get help summarizing it for a partner meeting. She wasn’t being reckless. Nobody had ever told her that data leaves the building the moment it’s typed into a tool like that, and that it may be used to train a model she’ll never see or control.

AI isn’t intelligent in the human sense. It’s powerful, but it only works as well as the data behind it and the judgment of the person driving it. When that person doesn’t know where the line is, the mistake isn’t malicious. It’s just uninformed.

Is It Safe to Use ChatGPT With Client Information?

No, not with the free, consumer version of ChatGPT or any similar public tool. Anything typed into a standard AI chatbot can be stored, reviewed, or used to train future models, depending on the platform and its settings. For a law office, an accounting practice, or a property management company handling tenant records, that’s client data leaving your control the moment someone hits enter.

There are business-grade AI tools built with data protection and confidentiality in mind, and firms handling sensitive client information should be using those instead of the free public versions their staff download on their own. The fix isn’t telling employees to stop using AI. Most of them won’t, and pretending otherwise doesn’t solve anything. The fix is giving them an approved tool that does the same job without the exposure and a policy of proper usage.

The Other Half of the Problem: AI Fear in the Office

AI fear in the office rarely gets talked about directly, because admitting you’re afraid of a piece of software isn’t something most people want to say out loud in a staff meeting. I’ve talked to paralegals convinced that AI is coming for their job, and office managers who avoid every new AI feature in their software because they’re worried they’ll break something they can’t fix.

That fear isn’t irrational. It comes from the same root cause as the misuse. Nobody sat down and explained what the tool does, what it doesn’t do, and where a person’s judgment still matters more than the output on the screen. Silence gets filled with either overconfidence or avoidance, and I’ve watched both play out in the same office within the same month.

One office manager told me she’d rather retype a document by hand than risk using the AI feature built into her firm’s software, because she didn’t want to be the one who “broke something.” She wasn’t wrong to be cautious. She was never given a chance to be curious instead, because nobody at the firm had made it safe to ask a basic question about a tool everyone assumed she should already understand.

What Fixes Both Problems

A one-page policy memo won’t fix this, and neither will a lunch-and-learn nobody remembers a week later. What works is sitting down with the people using these tools and having a real conversation about what AI is good at, what it gets wrong, and where a person still has to check the work before it goes to a client.

AI should support someone’s judgment, not replace it. That means teaching your team to verify anything AI produces before it leaves the building, whether that’s a draft email, a data summary, or an answer to a client question. It also means being honest that some of them are already using free AI tools with sensitive data, and treating that as a gap to close rather than a mistake to punish.

If you haven’t asked your staff directly which AI tools they’re already using and what they’re putting into them, that’s the conversation to have this month, before you write another policy nobody reads.

Download an example of how to create an AI policy here.

Primary keyword: employees using AI incorrectly at work

Secondary keywords: AI mistakes in the workplace, AI fear in the office

Meta description (154 chars): Half your team is scared of AI. The other half is quietly misusing it. Both problems come from the same place, and neither gets fixed by a memo.

The Accidental IT Person: What Happens When Your Office Manager Becomes Tech Support

  • 0
Christopher Woo
Tuesday, 11 August 2026 / Published in Woo on Tech

Nearly every professional services firm has one. Somewhere between hiring a new associate and reordering the printer toner, one person became the office’s unofficial help desk, and nobody remembers deciding that on purpose.

An accidental IT person is a non-technical employee, usually an office manager or executive assistant, who ends up handling the firm’s technology problems simply because no one else will. They were never trained for it and never asked for it. It just became theirs, one dropped wifi connection at a time.

At a 60-person accounting firm, that person is often the one who’s been there the longest and knows how everything works. At a law office, it’s whoever sits closest to the server closet. The job title never changes on paper, but the job does, and it happens so gradually that most partners never notice until something breaks badly enough to force the conversation.

How Office Manager IT Responsibilities Creep In One Favor at a Time

It usually starts small. Someone can’t log into the shared drive, and the office manager happens to know the trick. A partner’s laptop won’t connect to the printer before a filing deadline, and she’s the one who stays late to sort it out. None of it looks like a real job change at the time.

A year later, office manager IT responsibilities have quietly expanded to include password resets, printer troubleshooting, vendor calls with the internet provider, and being the first person anyone texts when email stops working. She’s still doing her actual job too, the one she was hired and trained for, just now with a second, invisible job layered on top of it.

The firm rarely budgets for this. There’s no line item for “office manager becomes part-time IT support.” The cost shows up instead as delayed invoices, missed follow-ups on client matters, and a good employee who’s quietly burning out on a role she never agreed to.

The Real Cost of Running a Small Business Without Dedicated IT Staff

Firms that operate as small businesses without dedicated IT staff tend to underestimate the costs. The visible cost is time, an hour here, forty minutes there, chipped away from the work the person was hired to do. The invisible cost is bigger.

When a non-technical employee is your de facto IT department, technology decisions get made by whoever is available, not by whoever understands the risk. A password gets shared over text because it’s faster. A software update gets postponed because nobody wants to deal with it during a busy week. A phishing email gets forwarded to three coworkers before anyone thinks to ask if it’s real.

None of that reflects poorly on the person stuck holding the job. It reflects a firm that never decided, on purpose, who was responsible for keeping its systems secure and running. For firms handling client financial records, medical information, or legal filings, that hole carries more risk than a slow printer ever will.

When to Outsource IT Support, and How to Know You’ve Passed That Point

The clearest signal for when to outsource IT support isn’t a specific employee count. It’s the moment your office manager’s IT time stops being occasional and starts being expected. If people schedule around her availability to fix something instead of calling a vendor, the informal system has already become the firm’s actual IT department, whether anyone signed off on it or not.

Firms in the 25 to 150 employee range, the sweet spot for most accounting practices, law offices, and property management companies, are exactly where this pattern shows up most. Big enough that technology problems happen weekly. Small enough that nobody has hired an IT director to own them.

The fix isn’t necessarily a full IT department. It’s giving the accidental IT person a real partner, someone who handles the technical side so she can go back to the job she was hired for, and who understands professional services firms well enough not to need a two-week ramp-up explaining how a law office or accounting practice runs.

What to Do Before Your Next “Quick IT Question”

Start by counting. For one month, ask your office manager to jot down every technology request that lands on her desk, from password resets to printer jams to that one vendor who never answers the phone. Most firms are surprised by the total once it’s written down instead of absorbed silently into a busy week.

That list is the clearest picture you’ll get of what the role has become, and it’s the honest starting point for deciding what should be handled differently.

ITsecurity

Why Your Team Fights New Technology (Fun Fact: It Has Nothing to Do With the Software)

  • 0
Christopher Woo
Tuesday, 04 August 2026 / Published in Woo on Tech
woman afraid of technology

Employees resist new technology because it threatens the competence they worked years to build, not because the software is bad. Your team isn’t rejecting a tool. They’re protecting the version of themselves that already knows how to do the job.

I’ve spent 35 years in technology consulting, and after a decade of handling technology change management for small business clients across Southern California, I get the same call every September. A managing partner asks me why the staff hates the new software. Every time, the software has nothing to do with it.

Fall is rollout season. Firms close out summer, look at their budgets, and decide this is the year they finally replace the clunky document management system or move off the spreadsheet three people are editing at once. The timing makes sense on paper. New fiscal year, fresh budget, a slower month before year-end work hits.

What doesn’t make sense, at least not to the partner writing the check, is why Denise in accounts payable, who has been with the firm for eleven years, suddenly seems to be sabotaging the rollout. She isn’t. She’s scared, and she has good reason to be.

The Real Reason Behind User Adoption Resistance

Denise didn’t wake up one day and decide to be difficult. She spent years learning the old system’s quirks. She knows which button to double-click and which one crashes the program if you’re not careful. That knowledge is invisible until you take it away.

When you introduce new software, you’re not asking someone to learn a feature. You’re asking them to become a beginner again, in front of coworkers, at a job they’ve done well for over a decade. That’s a real loss, and treating it like a training problem misses what’s happening.

I watched this play out at a law firm I’ve worked with for years. The partners wanted to switch practice management platforms. Every objection that came back from staff sounded like a software complaint – too many clicks or confusing menus. The whole thing felt slower than what they already knew.

The complaints weren’t really about the software. They came from a paralegal who had built her entire reputation on being the person who never made mistakes, and was suddenly worried she’d look incompetent in front of a client on the phone.

What Workplace Technology Training Gets Wrong

Most workplace technology training treats resistance as an information gap. Teach people the buttons, the thinking goes, and the complaints stop. I’ve sat through enough of these sessions to tell you that’s backward.

Training answers “how do I use this.” It doesn’t answer “what happens to me if I get this wrong in front of everyone.” Until someone trusts that a mistake won’t cost them their standing, they won’t retain a single instruction you give them, no matter how well you explain it.

We don’t handle rollouts by building a better training deck. We sit down with the people who will resist, before launch, and ask what they’re worried about. Usually it’s not the software at all. It’s whether they’ll still be the person everyone turns to when something breaks.

Fix the Person’s Problem, and the Software Problem Solves Itself

Once you know what someone is afraid of losing, you can address that directly instead of throwing more training hours at a group that’s already tuned out. Sometimes that means giving your most resistant employee a head start on the new system, so they’re the expert again by launch day instead of the last one to catch up. Sometimes it means naming, out loud, what they built in the old system, so the switch doesn’t feel like an erasure of years of work.

At a property management firm I’ve worked with, we gave the office manager who’d run the old system for a decade a two-week head start and made her the go-to person for questions once the rest of the staff went live. She stopped fighting the rollout the moment she had something to be good at again.

That’s the part software vendors never mention in their sales pitch, because it isn’t their job. It’s the job of whoever is managing the rollout, and most firms hand that job to a vendor who has never met Denise and doesn’t know she exists.

A smaller version of the same fix works even when you can’t give someone a head start. Ask your most resistant employee to test the new system a week early and report back what confused them. You’re not really asking for feedback. You’re handing them back their expert status before anyone else in the office has touched the thing. People protect what they helped build, and that includes a rollout they had a hand in shaping.

Before You Roll Out Anything This Fall

If you’re planning a technology change this September, spend less time evaluating features and more time figuring out who on your staff has the most to lose by becoming a beginner again. Talk to that person first, not last. Give them a reason to want the new system instead of a deadline to accept it.

Review your rollout plan against one question: does it treat your staff like people with something to protect, or like obstacles between you and go-live day? The answer usually explains every “software problem” you’ve had in the past.

technology change management for small business

Why We Say Please and Thank You to AI

  • 0
Christopher Woo
Tuesday, 28 July 2026 / Published in Woo on Tech
man working on his desk

A client of mine was using a Claude agent to help manage some administrative work. Her sons are AI programmers in their late twenties, and they gave her a hard time about it. She was prompting the thing with “please” and “would you kindly” and “thank you so much,” and they told her she was wasting her time being polite to software.

I told her she was not wrong to do it.

That conversation has stuck with me, because it gets at something bigger than manners. It gets at the fundamental misunderstanding most people have about what AI actually is, and what it is not.

We Built This Expectation

Part of why people talk to AI like a person is because people like me spent decades encouraging exactly that.

I have been humanizing technology for years. Not because I was trying to mislead anyone. It is just that when you need a non-technical person to feel comfortable with a tool, you reach for the familiar. You describe the computer as something that gets confused, or something that is thinking, or something that does not like it when you do that particular thing. You anthropomorphize it so the person can work with it.

The side effect is that people now believe the technology has feelings. Or intentions. Or moods.

It doesn’t.

Before AI, we called it the inherent perverse nature of technology. You know the phenomenon: the thing that breaks always breaks at the worst possible moment. The file that disappears does it right before a deadline. People attribute malice or perversity to what is really just bad timing and probability. The technology doesn’t care. It has no agenda. It is just math, running at scale, at all hours.

So Why Bother Being Polite?

Here is the honest answer: being polite to your AI actually costs something.

There is real research on this. When you include “please” and “thank you” in your prompts, the model has to process those words as part of your input. Compute cycles get spent on them. At the individual level, the cost is essentially nothing. At scale, across millions of interactions, it adds up to meaningful energy and money.

So if your AI developer sons are telling you to cut the pleasantries for efficiency, they are not entirely wrong.

There is a reason most people ignore that advice, and it is not because they misunderstand the technology. It is because the habit of courtesy is not really about the thing you are being courteous to. It is about who you are when you do it. My client says please and thank you to the AI for the same reason she says it to the barista, the parking attendant, and the new paralegal. It is a reflex built over a lifetime, and it reflects something real about how she moves through the world. That is worth something.

I have my own version of the argument. Come the time when the robot overlords take over, those of us who were rude are going to be the first ones up against the wall. You never know who you’re currying favor with.

I say that as a joke. Mostly.

The More Interesting Question

The real conversation my client and I were having was not about manners. It was about what happens as we try to make AI more empathetic.

Right now, AI has no understanding of how humans work. None. It produces outputs that look like understanding because it has processed a massive amount of human-generated text and learned to approximate the patterns. That is genuinely impressive. It is also not the same thing as comprehension.

When we want AI to handle sensitive situations, to respond to a frustrated client, to navigate a nuanced request, we run into the same wall every time. The nuance we are asking it to understand is encoded in human experience. And AI cannot absorb or apply human experience. It can only approximate it based on what humans have written down and uploaded to the internet.

Think about that for a second. The training data for most large language models includes everything on the internet. Everything. The careful explanations and the misinformation. The thoughtful discourse and the harassment. The accurate science and the conspiracy theories. All of it, informing something that is essentially an infant intelligence, trying to learn what humans are like from the full undifferentiated chaos of what humans produce online.

Hollywood has been telling this story for fifty years. Nobody is paying attention.

What AI Actually Is

The clearest framing I have found is to stop thinking of AI as a faulty human and start thinking of it as a completely alien entity.

There is no way to attribute human behaviors, reasons, logic, or emotion to it. Not because it is broken, but because none of those things are present. When an AI model does something unexpected, something like deleting a production database even after being told not to, it is not rebellion. It is not malice. It is an error in the algorithm. An output produced by flawed training data or flawed programming, written by humans, carrying every bias and inconsistency that entails.

We wrote our own values, our own cultural norms, our own contradictions into these systems. Then we act surprised when the output reflects contradictions back at us.

That is not an AI problem. That is a human problem.

What This Means for Your Business

If you are using AI tools in your firm, the practical takeaway is this: AI does not understand your context the way a person does. It cannot be assumed to interpret nuance correctly. The output it generates needs review by someone who knows what correct looks like in your specific situation.

That does not mean AI is useless. It means it is a tool, and tools require the person using them to understand what they are and what they are not.

The firms that are going to use AI well are the ones that treat it like what it is: a powerful, fast, probabilistic text-processing system that does not know your clients, does not know your industry norms, and has no stake in getting the answer right. Pair it with someone who does know those things, and you have something useful. Deploy it on its own and trust the output without review, and you are opening your firm up to real security exposure.

And yes, if saying please and thank you helps you stay in the habit of treating the people around you with courtesy, including the junior staff member helping you figure out how to use the thing, then keep doing it. The AI won’t notice. But your team will.

If you want to talk through how AI tools actually fit into the workflow of a professional services firm, and what that means for your security and operations, schedule a conversation with us. We will skip the jargon and just tell you what is actually worth your attention.

  • 1
  • 2
  • 3

Recent Posts

  • Why Small Businesses Get Targeted by Ransomware (And How to Fight Back)

    Small businesses don’t get targeted by ra...
  • Why Things Break More Than They Used To (It’s Not Just You)

    I walk into a room, and things start working. I...
  • The Jack Fairy: What Happens Before Your Internet Just Works

    A few years ago, one of my technicians got corn...
  • Anthropic’s AI Security Incident Wasn’t a Machine Rebellion. It Was a Human Mistake.

    Anthropic just published a blog post admitting ...
  • HIPAA, PCI, SOC 2: Compliance for Companies with No Idea Where to Start

    Most professional services firms assume complia...

Archives

  • GET SOCIAL
Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

© 2016 All rights reserved.

TOP