SMB Cyber Advisor
banner
mcborroughvcxo.bsky.social
SMB Cyber Advisor
@mcborroughvcxo.bsky.social
Field CISO, vCXO, Professor, Entrepreneur, and SMB Cyber Risk Advisor sharing insights about cybersecurity and things.....
Too many SMBs think cyber risk is “a big company problem.” It is not. The cybersecurity poverty line is real—and it’s endangering your operations, customer trust, and survival.
💡 Learn how to close the gap with pragmatic, cost-effective strategies:
zurl.co/Eo1EE
The Cybersecurity Poverty Line: Why SMBs Remain Vulnerable – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
November 13, 2025 at 9:16 PM
AI is everywhere but governance is nowhere, security leaders must step up.

This SMB Cyber Insights article addresses why AI needs cybersecurity leadership now:

🔗 zurl.co/M7WLl

#CISO #AI #Cybersecurity #AIGovernance #RiskManagement
CISOs: The New Champions of AI
Artificial Intelligence is no longer a niche capability. It is the default.
zurl.co
November 13, 2025 at 9:15 PM
Get expert insights, musings and occasional rantings a 20-year cyber pro, entrepreneur, & professor.
I cover real-world challenges, practical advice, and leadership lessons.

📰 Subscribe now: zurl.co/TY6Pn
#Cybersecurity #InfoSec #Leadership #SMBs #CISO
November 13, 2025 at 5:15 PM
Building a Security Program for a Small Business by a Fractional CISO
zurl.co/MRzsn

#mcborroughvcxo #CISO #FractionalCISO #Smallbusiness #Cybersecurity
Building a Security Program for a Small Business by a Fractional CISO – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
November 11, 2025 at 3:32 PM
Learn the differences between SOC 2 Type I and SOC 2 Type II attestation reports. Read a CISO's guide to help you decide which is right for your small business?
zurl.co/Kwx7g

#FractionalCISO #Smallbusiness #Cybersecurity
SOC 2 Type I vs. Type II Attestation: Guidance for Small Businesses – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
November 9, 2025 at 5:59 PM
In this SMB CISO Insights article, I explore Cybersecurity Risk Appetite and Tolerance, who should define these boundaries, who actually does, and what happens when no one does.

zurl.co/JKwit

#SMBCISOInsights #cybersecurity #riskmanagement
Risk Tolerance and Appetite: Who Really Decides?
Comments on my last article, “Rethinking ‘Security First’,” had me thinking about risk tolerance and risk appetite over the past week. My friend, Taiye Tambo, described the difference perfectly: “Risk appetite is like having an appetite for spicy food.
zurl.co
November 9, 2025 at 2:26 PM
How to Find the Right IT Managed Service Provider (MSP): A CISO's Guide for Small Business Owners
zurl.co/CRg9L
#mcborroughvcxo #CISO #FractionalCISO #Smallbusiness #Cybersecurity
How to Find the Right IT Managed Service Provider (MSP): A CISO’s Guide for Small Business Owners – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
November 7, 2025 at 3:25 PM
Get expert insights, musings and occasional rantings a 20-year cyber pro, entrepreneur, & professor.
I cover real-world challenges, practical advice, and leadership lessons.

📰 Subscribe now: zurl.co/TY6Pn
#Cybersecurity #InfoSec #Leadership #SMBs #CISO
November 6, 2025 at 5:15 PM
Check out the fourth article of our Cybersecurity Essentials series on Cybersecurity Awareness and Incident Response. zurl.co/iTnP2

#mcborroughvcxo #CISO #Smallbusiness #Cybersecurity
Cybersecurity Essentials for Small Business: A Fractional CISO’s Guide – Part 4: Cybersecurity Awareness and Incident Response – Preparing Your Team – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
November 5, 2025 at 3:38 PM
The Risks of Unmanaged AI Tools to Small Businesses
zurl.co/OT5yS
The Risks of Unmanaged AI Tools to Small Businesses – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
November 4, 2025 at 3:30 PM
Employees can be risky. But so can bad security design.

This article digs into the real insider threat: employee fatigue, created by well-meaning security teams.

#CISO #SecurityLeadership #CyberAwareness #HumanFactors #RiskManagement
zurl.co/pOxe2
The Insider Threat You’re Ignoring: Employee Cyber Fatigue
Let’s clear something up: your employees aren’t always ignoring cybersecurity because they don’t care. They’re probably overwhelmed.
zurl.co
November 1, 2025 at 1:56 PM
Security leaders have a unique opportunity to champion AI adoption while ensuring it is done securely. Read my latest article on six strategies to help champion AI within your organization:

zurl.co/sz9J6

#CISO #CyberSecurity #AI #AIGovernance #RiskManagement
From Risk Managers to AI Champions: How CISOs Can Lead the Next Wave
Last week, I published CISOs: The New Champions of AI, and the response from my network has led to some of the best conversations with fellow security and IT leaders that I have had in a long time. We did not always agree on who should “own” AI governance.
zurl.co
November 1, 2025 at 1:55 PM
In this latest SMB CISO Insights newsletter article on LinkedIn, I wrote about why the pressure on CISOs is rising and what needs to change if we want this role to be sustainable.

#CISO #Cybersecurity #Burnout #Leadership #FractionalCISO #InfoSec zurl.co/OMUXi
CISO Burnout Is Real: Let’s Talk About It
Lately, I’ve seen an increasing number of CISOs speaking publicly about burnout, and it’s a conversation that is long overdue. From posts on LinkedIn to candid comments at industry events, security leaders are opening up about the mental and emotional strain of the role.
zurl.co
October 30, 2025 at 11:04 PM
Get expert insights, musings and occasional rantings a 20-year cyber pro, entrepreneur, & professor.
I cover real-world challenges, practical advice, and leadership lessons.

📰 Subscribe now: zurl.co/TY6Pn
#Cybersecurity #InfoSec #Leadership #SMBs #CISO
October 30, 2025 at 4:15 PM
Considering ISO 727001 or SOC 2 for your business? As a fractional CISO, I often guide clients through this critical decision point. Here are the key features of both. zurl.co/bxG82

#mcborroughvcxo #CISO #FractionalCISO #Smallbusiness #Cybersecurity
ISO 27001 vs. SOC 2: Which Is Right for Your Small Business? – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
October 28, 2025 at 6:11 PM
In this edition of the SMB CISO Insights, I break down the “Security vs. Compliance” debate and explain why it’s a false choice for today’s organizations.

👉Join the discussion!

#cybersecurity #GRC #compliance #riskmanagement
zurl.co/P3X4V
The False Choice of Security vs. Compliance: Why It’s Time to End This Debate
If you’ve been in cybersecurity for any length of time, you’ve no doubt heard someone declare, “Being compliant doesn’t mean you’re secure!” I hear it all the time from articles, social media, conference panels, and even students in my classes. I think it’s time we retire the security versus complia
zurl.co
October 23, 2025 at 10:35 PM
Get expert insights, musings and occasional rantings a 20-year cyber pro, entrepreneur, & professor.
I cover real-world challenges, practical advice, and leadership lessons.

📰 Subscribe now: zurl.co/TY6Pn
#Cybersecurity #InfoSec #Leadership #SMBs #CISO
October 23, 2025 at 4:15 PM
What Makes a Great Field CXO: Lessons from the Front Lines
zurl.co/1sMqL
What Makes a Great Field CXO: Lessons from the Front Lines
If you are recruiting for a Field CISO, Field CTO, etc., or are looking to leverage a resource at your company in one of these roles, what are some things you should be aware of?
zurl.co
October 23, 2025 at 2:30 PM
Check out Part 3 of our Cybersecurity Essentials for Small Business: A Fractional CISO’s Guide series. We discuss Compliance and Legal Risks – What Every Small Business Owner Needs to Know. zurl.co/YUxbi

#mcborroughvcxo #FractionalCISO #Smallbusiness #Cybersecurity
Cybersecurity Essentials for Small Business: A Fractional CISO’s Guide – Part 3: Compliance and Legal Risks – What Every Small Business Owner Needs to Know – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
October 22, 2025 at 10:30 PM
AI-enabled ransomware attacks: CISO’s top security concern — with good reason
zurl.co/0TIWC
AI-enabled ransomware attacks: CISO’s top security concern — with good reason
New surveys from CSO and CrowdStrike reveal growing fears that generative AI is accelerating ransomware attacks while defenders rush to harness the same technology to fight back.
zurl.co
October 22, 2025 at 2:30 PM
Most AI privacy research looks the wrong way
zurl.co/YBKsn
Most AI privacy research looks the wrong way - Help Net Security
Researchers warn that studies overlook AI data privacy risks, focusing on memorization and ignoring threats from inference, data collection.
zurl.co
October 20, 2025 at 10:00 PM
AI Chat Data Is History's Most Thorough Record of Enterprise Secrets. Secure It Wisely
zurl.co/8Qb2u
#cybersecurity
AI Chat Data Is a Thorough Record of Enterprise Secrets
AI interactions are becoming one of the most revealing records of human thinking. We’re only beginning to understand what that means.
zurl.co
October 20, 2025 at 2:30 PM
Check out our final article in our 5-part Cybersecurity Essentials for SMBs: A Fractional CISO's Guide. We discuss cyber trends and predictions for 2025. zurl.co/IFv1F

#mcborroughvcxo #CISO #FractionalCISO #Smallbusiness #Cybersecurity
Cybersecurity Essentials for Small Business: A Fractional CISO’s Guide – Part 5: The Future of Cybersecurity for Small Businesses – Trends and Predictions – William J McBorrough, CISSP, CRISC, CISA, CMMC CCP
zurl.co
October 19, 2025 at 12:27 PM