Skip to main content

#security

Security

Protect your financial data with security best practices and tools

Zscaler FY2026 Q4: $898M Revenue, $3.8B ARR, and a 23% Free-Cash-Flow Margin

Zscaler's fiscal Q4 2026 (ended July 31, 2026) posted $898 million of revenue (+25%), ending ARR of $3.77 billion, and a full-year 23% free-cash-flow margin against a $63 million GAAP net loss. Deferred revenue of $2.93 billion and RPO of roughly $7.4 billion carry the growth signal before the income statement recognizes it — modeled FY2022–FY2026 in a public Beancount ledger alongside CrowdStrike and Palo Alto Networks.

Your App Doesn't Have to Be 'for Kids' to Owe Kids Privacy: A Small Business Guide to COPPA in 2026

The FTC's amended COPPA Rule, finalized in January 2025 with compliance required by April 2026, reaches any app or website with actual knowledge of users under 13, not just products built for children. It requires a separate opt-in parental consent before sharing a child's data or serving targeted ads, a published retention schedule that bars indefinite storage, and a written security program, with civil penalties above $50,000 per violation. This guide lays out who is covered, which consent methods the FTC accepts, and a seven-step checklist a small team can run without a privacy department.

Running an AI Red-Teaming Consultancy: Bookkeeping for $8K-to-$150K Engagements and Monthly Retainers

AI red-teaming firms bill two ways — $8,000-to-$150,000 project engagements and $1,500-to-$15,000 monthly retainers — and the books must keep them apart. A practical guide to the chart of accounts, ASC 606 treatment of deposits and milestones, per-engagement job costing, utilization and realization targets, 13-week cash forecasting, and contractor tax compliance.

Why Your Business Emails Land in Spam (and How SPF, DKIM, and DMARC Fix It)

Gmail, Yahoo, and Outlook filter mail from domains without SPF, DKIM, and DMARC, and bulk senders must also keep spam complaints under 0.3% and offer one-click unsubscribe. Here is what each DNS record proves, how to publish all three in about an hour, the seven mistakes that keep small-business invoices in spam, and why unread invoices show up in your receivables.

Failing Your Cyber Insurance Assessment? The MFA, EDR, and Backup Controls Insurers Demand in 2026

Cyber underwriters in 2026 condition or decline coverage on five control families — MFA on all email, remote and admin access, EDR on roughly 95% or more of endpoints, immutable backups with dated restore tests, patching and privileged-access hygiene, and an incident response plan exercised within 12 months. This guide lists the evidence each control needs, four methods for sizing limits against revenue, records, regulators and contracts, typical small-business premiums, and seven mistakes that fail assessments.

Fake AI Tools Are Now a Top Malware Disguise: A Download-Safety Guide for Small Businesses

Malware disguised as popular AI tools hit small and mid-sized businesses more than 33,300 times in the first four months of 2026, nearly five times the 2025 count. Learn the five disguises most likely to reach your team, what one bad download costs, a shareable download-safety checklist, and a 15-minute software-approval routine that stops most fake installers.

Regulation S-P in 2026: The Incident-Response, Customer-Notice, and Recordkeeping Checklist for Small RIAs and Broker-Dealers

The SEC's amended Regulation S-P has applied to smaller covered institutions since June 3, 2026, requiring a written incident-response program, customer notice within 30 days of awareness, and 72-hour service-provider breach escalation. A practical checklist for small RIAs, broker-dealers, and transfer agents covering the notice decision, vendor oversight, disposal rules, and the records that prove each step.

Payroll Data Privacy in 2026: A Small-Employer Guide to California, Colorado, and Virginia

Since January 1, 2023 California treats payroll records as protected personal information under CCPA/CPRA, while Colorado's 2025 biometric amendment and Virginia's 2026 changes narrow the "employee exemption." Here is a 30-day compliance plan covering the workforce privacy notice, retention schedule, security, rights requests, and vendor contracts for small employers.

When Your EIN Gets Stolen: A Small Business Guide to IRS Letters 5263C, 6042C, and Business Identity Theft

IRS Letter 6042C verifies a specific business return; Letter 5263C verifies the entity itself on file from Form SS-4, and both carry a 30-day response window that, if missed, stalls your returns, refunds, and overpayment applications. This guide explains how thieves obtain an EIN, the tax and non-tax red flags that signal fraud, exactly what to fax back in each case, when Form 8822-B is required within 60 days of a responsible-party change, and a monthly-quarterly-annual monitoring routine that catches misuse early.