Kevin Williams

All posts by Kevin Williams

Kevin Williams is a journalist based in Ohio. Williams has written for a variety of publications including the Washington Post, New York Times, USA Today, Wall Street Journal, National Geographic and others. He first wrote about the online world in its nascent stages for the now defunct “Online Access” Magazine in the mid-90s.

The 3-2-1 backup rule isn’t enough anymore

The 3-2-1 backup rule isn’t enough anymore

For decades, the 3-2-1 backup rule has been the mainstay of data protection: keep three copies of your data, on two different types of media, with one copy stored offsite. It was a sound framework for a world where the...

/ August 18, 2026
The hidden costs of backup sprawl

The hidden costs of backup sprawl

A lot of businesses end up with a piecemeal approach to backup. While that’s certainly better than having no backup at all, it often creates a patchwork environment that is far less reliable than it appears. As someone who regularly...

/ August 11, 2026
The MSP playbook for agentic AI

The MSP playbook for agentic AI

For years, AI helped security teams detect threats faster while humans remained responsible for taking action. Agentic AI changes that model. Today’s tools can isolate endpoints, disable accounts, block traffic, and launch remediation workflows automatically. The speed benefits are clear,...

/ August 4, 2026
Deepfakes are now an MSP problem

Deepfakes are now an MSP problem

Not long ago, creating a convincing deepfake required a team of specialists, weeks of production, and significant technical expertise. What a difference a few years make. That world is gone. According to the 2026 HYPR State of Passwordless Identity Authentication...

/ July 28, 2026
Why MFA fatigue attacks keep working

Why MFA fatigue attacks keep working

MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior. MFA fatigue attacks, also called...

/ July 21, 2026
When MFA isn’t enough: The session hijacking problem

When MFA isn’t enough: The session hijacking problem

Good ol’ MFA. It’s the bane of existence for people who want to log in quickly. For cybersecurity professionals, however, MFA has long been a source of reassurance. But some of that confidence is beginning to fade. For years, organizations...

/ July 14, 2026
How MSPs can fix burnout (hint: it’s not more people)

How MSPs can fix burnout (hint: it’s not more people)

SOC burnout has become a festering issue in the MSP world. Symptoms include analysts cycling through client environments, drowning in alerts, and quietly heading for the door. But the experts working closest to the problem say the conversation has been...

/ July 7, 2026
Nation-state tactics are now in criminal hands

Nation-state tactics are now in criminal hands

Government-backed hackers once reserved these techniques for targeted campaigns. Today, those techniques appear in everyday malware. For MSPs, the distinction between “targeted” and “opportunistic” attacks is disappearing. “The line between nation-state attacks and criminal attacks is disappearing faster than many...

/ June 30, 2026
What MSPs should know in the age of AI

What MSPs should know in the age of AI

Employees aren’t waiting for IT’s permission to use AI. They’re connecting ChatGPT plugins, Grammarly, Notion AI, and dozens of other tools directly to work accounts. In many cases, they are uploading sensitive company data to third-party servers that nobody in...

/ June 23, 2026
The hidden data risks of MSP acquisitions

The hidden data risks of MSP acquisitions

MSP consolidation is accelerating, yet most clients treat an acquisition as a routine business update—a new logo on invoices or a new account manager. In reality, far more is changing behind the scenes than branded T-shirts and welcome kits. In...

/ June 16, 2026