The Compliance Gaps Costing You Thousands

The Compliance Gaps Costing You Thousands

Not all compliance failures start with a breach, but they all start with assumptions.

A business can have the right tools in place and still be unclear on what’s working. 

But when a client asks for proof or when a cyber incident forces a closer look, assumptions aren’t enough. You need to know what’s in place, what’s documented and what needs attention. Compliance stops being a checkbox and starts becoming a cost. 

Unfortunately, most businesses don’t discover their compliance gaps during normal operations. They discover them under pressure, when the answer is needed immediately and the stakes are already high.

Here are four compliance gaps that can cost businesses thousands when left unchecked.

Gap #1: Security tools nobody monitors

Most businesses already pay for security tools like endpoint protection, multifactor authentication, firewalls, threat detection and email filtering.

On paper, your business looks protected and everyone feels reasonably comfortable. The problem is ownership.

Who confirms those tools are configured correctly? Who checks that they're installed on every device? Who reviews the alerts? Who catches failed updates? Who responds when a system flags something suspicious?

Security software can't protect what it doesn't see. It can't respond to alerts nobody reads. It can't close gaps left open by weak setup, partial deployment or warning signs that got ignored.

From a distance, your business looks covered, but under closer scrutiny, the picture changes. 

Buying the tool is step one. The protection comes from how that tool gets managed, monitored and maintained month after month. That distinction matters during audits, insurance renewals and client reviews. A checkbox answer gets noticed. Proof of active management earns trust.

Gap #2: Employee behavior no one has revisited

Employees usually aren’t trying to create risk. They’re trying to get work done.

That’s why many compliance issues come from routine behavior such as sending sensitive data through the wrong channel, reusing passwords, clicking fake invoices or accessing company files from a personal device after hours.

The problem is that everyday shortcuts can become compliance gaps when no one reviews them or corrects them.

Employees need clear expectations, practical guidance and systems that make safe behavior simple to follow.

Gap #3: Documentation that gets built after someone asks

You may be doing everything right, but if the evidence is scattered or missing, that becomes a problem the moment someone asks for proof.

That’s the wrong time to start scrambling for documentation.

Scrambling creates mistakes and makes your business look less prepared than it may be. It can also raise doubts about whether proper controls were being followed in the first place.

Strong compliance means policies are reviewed before audits, access records are maintained before disputes and vendor checks are tracked before client requests. It also means incident plans are written before incidents happen.

Documentation needs to be current, clear and easy to show.

Gap #4: The business changed, but security stayed where it was

This gap matters during a midyear review because your business may have changed more than your security has this year.

Maybe you added vendors, hired new team members, changed software, expanded remote work or took on clients with stricter requirements. 

A setup built for 10 employees may not work for 30. A backup plan may not cover new cloud tools. Access rules that made sense last year may be too loose now.

That’s how you outgrow your protection.

A midyear review helps confirm whether your current security and compliance controls align with how the business operates today.

The cost comes from finding out late

Compliance gaps usually surface when money, trust or liability are on the line. At that point, you’re doing damage control, not fixing a gap.

The time to find these issues is before someone else asks the hard questions.

A focused review can show where your business is exposed, where systems have drifted, and whether today’s security or insurance requirements are being met.

We offer a 10-minute discovery call to help identify compliance blind spots and see whether your current controls still line up with today’s requirements.

Call us at 619-782-0170 or visit www.mycre.com to get on the calendar.

The Most Dangerous Risks in Your Business Don’t Swim on the Surface 

The Most Dangerous Risks in Your Business Don’t Swim on the Surface 

On the surface, the water looks calm.

That's what makes Shark Week fascinating every year. The danger is never visible on the surface. It’s what’s already moving underneath. 

Cybercriminals operate the same way. The threats businesses face right now are designed to blend in with normal operations until the moment something breaks, money moves or systems go down.

During the summer months, when schedules shift, employees travel and oversight gets thinner, cybercriminals know businesses are often paying less attention.

Here are three ways they're circling right now.

1. Fake invoices and vendor impersonation

Attackers don’t need to hack anything. In many cases, they need to send just one believable email.

This is called business email compromise (BEC) and it works by impersonating a vendor, supplier or executive your team already trusts. 

The email arrives looking completely normal, someone on your team pays the “vendor,” and by the time anyone realizes the request wasn't legitimate, the damage is done.

These attacks spike during vacation season for a simple reason. When the person who normally approves payments is out, requests get rerouted to people who don't always know what normal looks like. Temporary stand-ins are less likely to question urgency and attackers know it.

The fix is simple to implement: Build a verification process for any financial request received via email. A quick confirmation call to a known number, not the number listed in the email, is enough to stop most of these before they go anywhere. 

2. Phishing attacks that target distracted employees

Phishing works because it’s engineered around how people behave when they’re busy.  

Cybercriminals design these moments deliberately. A distracted employee sees a password reset notification and clicks the link. Someone gets a text that looks like it came from IT. An email lands right before a meeting asking for urgent approval on a wire transfer. Nobody stops to verify because stopping feels like losing time.

The most effective protection isn’t a software solution; it’s culture. 

Employees need to feel comfortable slowing down when something seems off:

  • An unexpected login request
  • A payment instruction that came out of nowhere
  • A link in an email they weren’t expecting

Speed is a weapon attackers use against you. Slowing down is how you take it away from them.

3. Third-party risks that travel fast

When a vendor with access to your systems is compromised, the threat doesn't stay contained to them. It travels directly into your environment through whatever connection they have to your business.

This is supply chain exposure, and most businesses have significantly more of it than they realize. Software tools connected to their network, service providers holding credentials and contractors whose access was never removed after a project ended all present a path that most business owners have never mapped out.

Outsourcing a service doesn’t outsource accountability.

Knowing where you stand with supply chain exposure means being able to answer three questions: 

  1. Which vendors can access your data or systems?
  2. What are they connecting to?
  3. Who is responsible internally for managing those relationships?

If those answers aren’t clear, your exposure is opening you up to risk. 

By the time you see it, it's already moving

Sharks don't announce themselves and neither do the cybercriminals targeting your business right now.

The companies that get hit aren't always the ones that ignore obvious warning signs. They're the ones who assume everything is fine because nothing looks wrong. 

Summer is when schedules get loose, attention drifts and the water looks the calmest. It’s also when attackers are most active.

We help businesses get a clear picture of where they’re exposed across vendors, employee activity and day-to-day operations before something goes wrong.

If you don’t know where your business stands, schedule a 10-minute discovery call.

Call us at 619-782-0170 or visit www.mycre.com.

Midyear Reality Check: What’s Changed In Your Systems Since January?

Midyear Reality Check: What’s Changed In Your Systems Since January?

Your business hasn't stood still since January and your systems haven't either.

You've added people to the team, adopted new tools and made fast calls to keep things moving.

What’s hard to keep track of is the trail those decisions leave behind, including who still has access to systems they no longer need, where your data ended up and who’s responsible for what.

By July, most businesses are running on assumptions about how their systems work. Here are four things to examine before those assumptions become expensive.

1. Access was expanded. Was it ever revisited?

New hires came in and needed to get on systems quickly. Other employees moved into new roles and picked up permissions along the way. Temporary access was granted to keep a project moving or cover for someone who was out.

But access almost never gets revisited after it’s needed, which means the picture inside most businesses looks like this:

·       People have more privileges than their current role requires

·       Former employees likely still carry active permissions

·       You don’t have a clean view of who can reach what

It’s time to ask the question, do the right people have the correct access today?

Do you know who can see what inside your business right now? If that answer takes longer than a few seconds, pay attention.

2. Your tools solved problems while creating new ones

Your sales team needed a better way to track conversations, so a CRM was added. Marketing brought on a platform to run campaigns faster. Finance adopted an application to simplify billing. Operations signed up for a project tool that seemed lightweight at the time.

Every one of those was a reasonable decision. Collectively, they created something messier.

Data now lives in more places, integrations were set up quickly and may not be working as intended, and visibility across systems has fragmented. 

When systems coexist without anyone owning the full picture, the risk doesn't announce itself. It shows up later in slower decisions, inconsistent reporting and gaps that belong to nobody. 

Do your systems work together or is your team quietly working around them? By the time that question becomes urgent, it's been a problem for a while.

3. Your backup and recovery confidence is probably assumed

Most businesses have backups in place and operate under a false sense of security, believing they're protected. Recovery is rarely tested, the timeline to restore operations is unclear, and ownership of the process often isn’t defined.

When something goes wrong, whether it’s ransomware, a server failure or an accidental deletion, the conversation starts with "wait, who handles this?"

Having backups is not the same as being able to recover. The difference between them only becomes clear at the worst possible time.

If something went down tomorrow, would you know exactly what happens next? Or would you be figuring it out on the spot?

4. Responsibility has blurred as your business has grown

Remember back when who owned what was clear?

Your internal team handled certain systems, vendors handled others and responsibilities were roughly defined, even if nobody had documented them.

Then systems expanded, new vendors came in, internal roles shifted and somewhere in the middle of all that growth, ownership got blurry.

Now when something breaks and it crosses systems or providers, the question of who takes the lead often gets answered in real time. Issues bounce, small problems sit unresolved longer than they should and nobody knows whose job it is to fix the problems.

When something alarming happens in your systems, do you know who is responsible for resolving it? Or do you figure it out in the moment?

Most risk doesn't come from what's broken

It comes from what's changed without being revisited.

Businesses that stay ahead of this aren’t doing anything complicated. They have a clear view of who has access to what, they know their backups work, and they know who owns what when something goes wrong. 

That clarity lets them move fast without things falling through the cracks. 

That’s what we’re here to help you achieve. A discovery call takes 10 minutes and will help give you a straight answer on where your systems stand today and what needs attention.

Call us at 619-782-0170 or visit www.mycre.com to schedule yours.

Windows Server 2016 End of Life: What Construction Companies Running Sage Need to Know

Windows Server 2016 End of Life: What Construction Companies Running Sage Need to Know

For most businesses, an operating system update is background noise. A version number changes, IT handles it, everyone moves on. But when an operating system reaches true end of life, something different happens, and most construction executives don't find out what until it's already a problem.

Windows Server 2016 reaches the end of Microsoft's extended support on January 12, 2027. If your Sage 300 CRE or Sage 100 Contractor environment is still running on it, here is what that date actually means, why it matters more for a construction company than for almost any other type of business, and what a responsible plan looks like before the deadline makes the decision for you.

What "End of Life" Actually Means

When Microsoft retires support for a server operating system, it doesn't slow down. It stops, permanently. No more security patches. No more bug fixes. No more technical support if something breaks at the OS level. Every vulnerability discovered in Server 2016 after January 2027 stays open, on every machine still running it, indefinitely.

This matters because new vulnerabilities are found constantly, in every operating system, every year. On a supported platform, Microsoft closes them as they're discovered. On an unsupported one, they simply accumulate. The server doesn't stop working the day support ends. It keeps running, which is exactly what makes the risk easy to underestimate. Nothing visibly changes. The exposure builds quietly in the background instead.

Why Attackers Specifically Target End-of-Life Systems

This isn't a theoretical risk that only matters to security professionals. Threat actors actively look for infrastructure running outdated, unpatched operating systems, precisely because they know those systems have no upcoming fix. An end-of-life server isn't just more vulnerable in the abstract, it becomes an identifiable target the moment support ends.

Microsoft's own threat intelligence backs this up with hard numbers. According to Microsoft's Digital Defense Report, the overwhelming majority of ransomware attacks that succeed in fully encrypting a target's data begin on unmanaged, unpatched, or unsupported systems, the exact profile of a server running an end-of-life operating system. Ransomware groups favor this kind of infrastructure for a simple reason: it offers a long, predictable window to operate, with no patch cycle working against them.

Why This Hits Construction Companies Differently

Most generic advice about server end of life is written for a generic business. Construction firms running Sage carry a different and more concentrated kind of exposure.

Your Sage environment isn't a side application. It holds job cost data across every active project, payroll for every employee, banking and ACH details, subcontractor records, and in many cases certified payroll tied to public contracts. A ransomware event doesn't just lock files somewhere on a network. It can halt payroll runs mid-cycle, freeze billing during an active draw, and stall project approvals while the business works through recovery, all while jobs in the field keep moving regardless of what's happening on the server.

For a firm managing several projects simultaneously, even a short disruption compounds fast. And if the incident involves payroll or banking data, it can trigger breach notification obligations most construction firms have never had to navigate and aren't staffed to handle on short notice.

The Risk Doesn't Stay in IT. It Reaches Bonding, Insurance, and Compliance

This is the part that surprises most executives: an outdated operating system doesn't stay an IT problem. It can quietly become a liability in conversations that have nothing to do with technology.

Many cyber insurance policies require running supported, patchable software as a condition of coverage. If a breach is later traced to a known, unpatched vulnerability on an end-of-life system, that can give an insurer grounds to deny a claim entirely, at the exact moment a firm needs that coverage most. The same logic applies to compliance postures like SOC or PCI that some lenders, sureties, and general contractors now expect from their subcontractors and vendors as a condition of doing business. An aging OS sitting quietly in a server closet can show up later as a problem in a bonding conversation, a lender review, or a prequalification questionnaire.

The Cost of Waiting Compounds. The Cost of Planning Doesn't

The exposure here isn't flat, it steepens over time. Between now and January 2027, risk grows every month as new vulnerabilities are discovered and never patched on Server 2016. After the deadline passes, that curve gets steeper still, because the vendor safety net disappears completely and there is no longer any patch coming, ever, for anything.

Firms that get ahead of this on their own timeline get to do it on their own terms: planned testing, a controlled cutover window, no pressure. Firms that wait usually end up moving anyway, just under worse conditions, after an incident, under time pressure, with far less control over cost or scheduling. The deadline doesn't go away if it's ignored. It just shifts who's in control of how the transition happens.

What This Means If You're Hosted With myCREcloud

If your Sage environment is hosted with myCREcloud, this transition looks different than it would for a firm managing its own on-premise infrastructure, and it's worth understanding why.

A firm running Sage on premise that wants to get ahead of this deadline has to do all of it themselves: source and budget for a new server OS license, plan and execute the OS-level rebuild, and then handle the Sage migration on top of that, usually while also juggling whatever else is competing for the IT budget that quarter. That's a real project with real cost before the Sage piece even starts.

For myCREcloud clients, the OS layer is something we manage as part of hosting your environment, not something you have to plan, budget, or execute on your own. As Server 2016 approaches its end of life, we're building current, supported environments for affected clients at no cost for the new server OS itself. The remaining piece, migrating your Sage application and database into that new environment, is a real project with real scope, but it's one we can schedule around your calendar rather than a hard deadline forcing the timing.

The point isn't that the work disappears. It's that being hosted means you're not solving this alone, on your own infrastructure, against your own clock.

A Readiness Checklist Before Your Migration Conversation

You don't need every answer before reaching out, but having these on hand makes the first conversation more productive:

    • Your current Sage version and which modules are active

    • Your user count and where they're located

    • Your full list of integrations (Procore, hh2, Autodesk, Microsoft 365, or others)

    • When your backups were last tested with an actual restore, not just confirmed as completed

    • Whether any custom reports, macros, or workflows depend on specific file paths

    • Your current remote access method, if any

    • Where Sage already feels slow or painful today, since that often points to other improvements worth making during the same project

The Bottom Line

January 12, 2027 isn't a soft target. It's the date Microsoft stops protecting Server 2016 against every vulnerability discovered after it. The risk isn't hypothetical and it isn't a future problem sitting safely down the road, it's a clock that's already running, and it gets harder to manage the closer it gets to zero.

The fix isn't complicated: a planned, tested move to a current, supported environment before the deadline forces the timing. If you're hosted with myCREcloud, that move is already underway for affected environments, and the only real decision left is when it fits your schedule.

If you have questions about where your environment stands, reach out to your myCREcloud contact directly, or request time on our calendar to walk through it together.


Sources: Microsoft Digital Defense Report (microsoft.com); Microsoft Windows Server Blog, "Planning ahead for Windows Server 2016 end of support"; Microsoft Lifecycle documentation for Windows Server 2016.

myCREcloud Achieves SOC 2 Compliance Certification

myCREcloud Achieves SOC 2 Compliance Certification

myCREcloud Achieves SOC 2 Compliance Certification

June 1, 2026 - myCRECloud, a provider of cloud-based Sage hosting and IT services for construction professionals, today announced it has successfully completed its SOC 2 Type II audit, achieving certification that validates the company's commitment to data security, availability, and confidentiality. The certification, awarded following an independent audit by a licensed CPA firm, confirms that myCREcloud's systems and processes meet the rigorous standards set by the American Institute of Certified Public Accountants (AICPA).

"Earning our SOC 2 certification is a meaningful milestone for our team and our customers," said Tanner Evenrud, Founding Partner, Chief Revenue Officer, at myCREcloud. "It reflects the work we've put into building a platform that our clients can trust with their most sensitive business data. Security has always been a priority for us, and this certification provides independent verification of that commitment."

The SOC 2 audit examined myCREcloud's internal controls related to security, processing integrity, and data protection over an extended review period. With this certification, customers and partners can have greater confidence that their information is managed with the highest level of care. myCREcloud remains dedicated to continuous improvement of its security practices and looks forward to maintaining this standard as the company grows. For more information, visit www.mycrecloud.com or contact sales@mycrecloud.com.

AI’s Hunger for Compute Is Fueling a Cloud Spending Boom

AI’s Hunger for Compute Is Fueling a Cloud Spending Boom

The AI boom has quietly become a cloud infrastructure boom. As companies race to roll out AI tools, the biggest line items in tech budgets are no longer flowing into software. They are pouring into chips, servers, power systems, and the massive data centers needed to run large models at scale.

The numbers keep getting bigger

According to figures cited by Reuters, Alphabet, Amazon, Meta, and Microsoft are collectively on pace to spend around $650 billion on AI-related infrastructure in 2026. That is up from roughly $410 billion in 2025, a leap that shows just how quickly the center of gravity in tech spending has shifted toward physical capacity.

Other efforts are adding to the pile. Stargate, a joint project backed by OpenAI, SoftBank, and Oracle, aims to put as much as $500 billion into AI infrastructure across the United States over the coming years. On the venture side, the Stanford AI Index Report pegged global private investment in generative AI at $33.9 billion for 2024, an 18.7 percent jump over the year before.

The bottleneck has moved

Training and running modern AI models is enormously compute intensive. It typically means thousands of GPUs working in parallel across distributed facilities, which makes the networking between chips matter nearly as much as the chips themselves.

That context helps explain Nvidia's recent decision to commit $2 billion each to photonics firms Lumentum and Coherent. Photonics uses light instead of electrical signals to move data, which can be faster and more power efficient. As AI clusters grow, those internal links increasingly dictate how quickly a system can actually learn and serve predictions.

The lesson for the industry is clear. For most teams building AI, the limiting factor is no longer code. It is whether the underlying hardware, facilities, and power supply can keep up.

What this means for enterprises

Enterprise adoption is a major piece of the story. Businesses are folding AI into customer support, analytics, and internal productivity tools, and very few of them can host that workload on their own servers. They rent capacity from cloud providers instead, often through multi-year commitments worth billions.

For IT leaders, this shifts how cloud decisions get made. GPU availability, data center location, energy supply, and long-term compute costs are all becoming central to vendor evaluations. The next chapter of cloud computing will be shaped less by clever software and more by who has the physical capacity to run it.

Want to learn more about the cloud? Contact Tyler at Tyler.mathis@mycrecloud.com or 619.704.2969!