Sourcepass
Businesses are often held back by lackluster technology vendors that leave them underserved and overcharged for IT services.
An opportunity existed for innovation through leveraging Software-as-a-Service (SaaS) technologies such as Artificial Intelligence (AI) and Robotic Process Automation (RPA) married with premier managed services to provide a revolutionary client experience.
As a result, Sourcepass was born with the vision to provide businesses of all sizes a technology experience that elevates their company.
Sourcepass puts you in control of your digital universe, so you have the power to transform your business.
With Sourcepass, you have a team of guardians that maintains data networks, manages cloud and security monitoring, and guides productivity and digital transformation. The right blend of technologies work seamlessly and powerfully, backed and boosted by our tech smarts and business savvy.
Endpoint Detection and Response for SMBs: A Practical Guide
Endpoint detection and response (EDR) has become a foundational component of SMB cybersecurity. As organizations continue to adopt cloud applications, remote work models, and Microsoft 365-based collaboration, endpoints remain one of the most valuable sources of security visibility. Laptops, desktops, servers, and mobile devices are where users access business systems, interact with data, and perform daily operations. They are also where many security incidents first become visible. For SMBs, endpoint detection and response provides more than threat detection. It enables organizations to ide
Endpoint detection and response (EDR) has become a foundational component of SMB cybersecurity. As organizations continue to adopt cloud applications, remote work models, and Microsoft 365-based collaboration, endpoints remain one of the most valuable sources of security visibility. Laptops, desktops, servers, and mobile devices are where users access business systems, interact with data, and perform daily operations. They are also where many security incidents first become visible. For SMBs, endpoint detection and response provides more than threat detection. It enables organizations to identify suspicious behavior, investigate incidents, contain affected devices, and improve security outcomes over time. The value of endpoint security is not measured by whether software is installed. It is measured by coverage, response effectiveness, and the organization's ability to reduce operational risk through consistent security practices. Why Endpoint Visibility Matters Beyond Traditional Antivirus Traditional antivirus technology remains an important layer of protection. However, many modern attacks rely on compromised credentials, legitimate administrative tools, scripts, and user activity that may not appear as traditional malware. Endpoint detection and response helps organizations understand what is happening on their devices by collecting and analyzing endpoint telemetry. This visibility allows security teams to identify suspicious behavior that might otherwise go unnoticed. Common indicators visible through EDR platforms include: Credential theft activity Unusual process execution Suspicious command-line activity Unexpected network connections Attempts to disable security controls Unauthorized software deployment Lateral movement between devices Microsoft's Microsoft Defender for Endpoint provides an example of how endpoint protection, detection, investigation, and response capabilities can work together within a Microsoft-first environment. How Endpoint Compromise Affects Business Risk A single compromised endpoint can become the starting point for broader business disruption. Potential outcomes include: Microsoft 365 account compromise Unauthorized access to sensitive data Business email compromise Ransomware deployment Internal network discovery Third-party access abuse This is why endpoint visibility matters. Security teams need the ability to identify and investigate suspicious behavior before it develops into a larger operational issue. Effective Endpoint Security Requires Ownership Many organizations focus on deploying endpoint agents but spend less time defining operational responsibility. A mature endpoint detection and response program answers questions such as: Who reviews alerts? Who owns investigations? Who can isolate a device? Who communicates with affected users? Who determines whether an event requires escalation? Technology creates visibility, but accountability determines whether risks are addressed effectively. Connecting Endpoint Detection and Response to Triage, Containment, and Recovery Endpoint detection and response delivers value when detections lead to informed security decisions. Successful programs establish clear processes for triage, containment, remediation, and recovery. Establish an Effective Triage Process When a security alert occurs, responders should quickly determine whether it represents: Malicious activity A policy violation Administrative activity A benign event Analysts need sufficient context to make accurate decisions. Key investigation details typically include: The affected device Associated user accounts Running processes Command-line activity Network connections Recent configuration changes Related security alerts Microsoft's Endpoint Management Overview highlights how endpoint security programs can integrate prevention, detection, investigation, and response capabilities. Define Clear Containment Procedures Containment decisions should balance security needs with business continuity requirements. For example, isolating a compromised endpoint may help prevent additional spread but could also interrupt critical business operations. Organizations should establish response procedures before an incident occurs. Key containment considerations include: Device isolation authority Alternative communication channels Evidence preservation requirements Credential reset procedures Malware removal processes Validation and recovery steps The goal is not simply to stop suspicious activity. It is to restore operations confidently while preserving necessary evidence for investigation. Connect Endpoint Security With Microsoft 365 Data Endpoint telemetry becomes significantly more valuable when combined with identity and cloud activity. For example, an endpoint alert may help explain: Unusual Microsoft 365 sign-ins Suspicious mailbox activity Unauthorized file downloads Application consent abuse Privileged account misuse Correlating endpoint and identity signals provides greater context and allows responders to understand an incident as a whole rather than as isolated alerts. For organizations operating in Microsoft environments, this integrated view often improves both response speed and investigation quality. Measuring Endpoint Security Outcomes Over Time Organizations should evaluate endpoint detection and response based on measurable outcomes rather than software deployment alone. Installing an agent does not automatically reduce risk. Effective programs measure visibility, response performance, and continuous improvement. Track Endpoint Coverage Coverage remains one of the most important endpoint security metrics. Organizations should regularly monitor: Percentage of devices reporting telemetry Devices missing recent check-ins Unsupported devices Unmanaged assets Coverage by business function Coverage across physical locations Not all endpoint gaps carry the same level of risk. Missing coverage on an executive device, critical server, or privileged administrator workstation often presents greater operational concern than a gap involving a non-production system. Microsoft's Defender for Endpoint Planning Guide provides useful guidance for deployment planning and operational readiness. Measure Response Quality Security leaders should establish clear response metrics that support continuous improvement. Examples include: Time to acknowledge high-severity alerts Time to begin investigation Time to contain confirmed threats Number of recurring detections Incidents requiring recovery activities Detection-to-resolution timelines These measurements help organizations determine whether response processes are functioning as intended and identify opportunities for improvement. Use Detection Trends to Strengthen Security Controls Recurring endpoint detections often reveal underlying operational issues. Examples include: Unauthorized software installation Excessive local administrator privileges Weak application governance Credential misuse patterns Misconfigured security controls Delayed patching processes Rather than treating alerts as isolated events, organizations should use detection data to inform broader cybersecurity decisions. EDR findings can contribute to: Risk management discussions Security awareness training Patch management priorities Identity security improvements Incident response exercises Policy updates This approach turns endpoint security into a continuous improvement function rather than a reactive monitoring activity. Building a Sustainable Managed Detection and Response Strategy Many SMBs lack the internal resources required to investigate endpoint alerts continuously. As a result, organizations often adopt a managed detection and response model to supplement internal capabilities. The most effective approach depends less on who performs the work and more on whether responsibilities are clearly defined. Regardless of operating model, organizations should ensure: High-severity alerts are monitored continuously Escalation procedures are documented Response authority is established Investigations are consistently reviewed Metrics are reported to leadership Lessons learned are incorporated into future improvements For executive leadership, endpoint detection and response reporting should remain focused on measurable outcomes: Endpoint coverage rates Alert response performance Threat containment effectiveness Key risk reduction initiatives Outstanding security gaps When endpoint detection and response is measured this way, it becomes a practical business resilience capability rather than simply another security tool. FAQ What is endpoint detection and response? Endpoint detection and response (EDR) is an endpoint security capability that collects data from devices, identifies suspicious activity, supports investigations, and enables security teams to contain and remediate threats. Why is endpoint detection and response important for SMBs? Endpoint detection and response helps SMBs identify threats earlier, investigate suspicious activity more effectively, and respond to incidents before they cause significant operational disruption. It provides visibility that traditional antivirus solutions may not offer. What is the difference between antivirus and endpoint detection and response? Antivirus primarily focuses on preventing known threats. Endpoint detection and response adds behavioral monitoring, investigation capabilities, threat hunting, and response actions that help organizations identify and contain sophisticated attacks. How does endpoint detection and response support Microsoft 365 security? Endpoint detection and response can provide context for Microsoft 365 security events by correlating device activity with identity, email, and cloud application activity. This helps organizations investigate incidents more comprehensively. What metrics should organizations track for endpoint security? Organizations should monitor endpoint coverage, device health, alert response times, containment times, recurring detections, and incident recovery metrics. These measurements help assess whether endpoint security controls are reducing risk. Is managed detection and response the same as endpoint detection and response? No. Endpoint detection and response refers to the technology and capabilities used to detect and investigate threats. Managed detection and response (MDR) adds human monitoring, investigation, escalation, and response services to help organizations operate those capabilities effectively.
Read full post on blog.sourcepass.com
Control Microsoft Copilot Credits and AI Agent Costs | Sourcepass MCOE
AI can improve productivity, automate repetitive work, and help teams move faster. It can also introduce a new budgeting challenge that many organizations are not prepared for. Traditional Microsoft licensing is predictable. Organizations purchase licenses, assign them to users, and know exactly what the monthly bill will be. Microsoft Copilot, Copilot Studio agents, and consumption-based AI services introduce a different model where costs can increase based on usage. Understanding AI FinOps is becoming essential for IT leaders, business leaders, and finance teams that want to scale Micros
AI can improve productivity, automate repetitive work, and help teams move faster. It can also introduce a new budgeting challenge that many organizations are not prepared for. Traditional Microsoft licensing is predictable. Organizations purchase licenses, assign them to users, and know exactly what the monthly bill will be. Microsoft Copilot, Copilot Studio agents, and consumption-based AI services introduce a different model where costs can increase based on usage. Understanding AI FinOps is becoming essential for IT leaders, business leaders, and finance teams that want to scale Microsoft AI technologies without creating unexpected spending. Why does Microsoft Copilot Require AI FinOps? AI FinOps is the practice of managing, monitoring, and optimizing AI-related costs. Many organizations are familiar with cloud FinOps from Azure and AWS, where Azure subscriptions and cloud resources generate costs based on consumption. Microsoft's newer AI services are introducing a similar model. Features such as Microsoft Copilot Cowork, Copilot Studio agents, scheduled AI processes, and API-driven workloads consume credits and resources as they run. The more frequently AI tools are used, the more important cost visibility becomes. In this episode of the Demystifying Microsoft podcast, Nathan Taylor speaks with Graham Rosenberg, Director of Intelligence and Automation at Sourcepass, about how organizations can approach AI FinOps, avoid billing surprises, and build governance around Microsoft Copilot and AI agents. What is AI FinOps? AI FinOps is a discipline that combines IT, finance, and business leadership to manage AI spending and maximize return on investment. The goal is not simply to reduce costs. The goal is to understand how AI usage, automation, and agent workloads translate into business value while maintaining predictable spending. Organizations using Microsoft Copilot, Copilot Studio, Azure AI Foundry, and other AI platforms need ways to: Monitor AI consumption Establish spending limits Identify power users Measure business value Prevent unplanned expenses As AI adoption increases, AI FinOps is becoming a necessary extension of cloud financial management practices. How are Microsoft Copilot Credits Calculated? Microsoft Copilot consumption is measured using credits. Organizations can purchase Copilot credits in advance and allocate those credits to users, teams, and workloads. Credits are consumed whenever supported AI activities run. Because spending is tied to usage, organizations need visibility into how AI workloads consume resources. This represents a significant shift from traditional per-user licensing models where costs remain fixed regardless of usage. What Changed with Microsoft Copilot Cowork? One of the biggest changes organizations are navigating is Microsoft's transition to usage-based billing for Copilot Cowork. Prior to the change, organizations could use Cowork without directly monitoring credit consumption. Once usage-based billing became available, organizations had to begin managing budgets, spending policies, and credit allocations. This introduced a new requirement for organizations to understand how AI usage affects operational expenses and budgeting decisions. How do you Manage Microsoft Copilot Spending Limits? Organizations can control Copilot spending through policies configured in the Microsoft 365 Admin Center. These policies allow administrators to: Set credit consumption limits Assign budgets to users Control agent access Establish spending ceilings Monitor usage activity A common recommendation is to start with conservative limits while users learn how AI tools consume credits. This approach allows teams to experiment with AI while protecting the organization from unexpected costs. How do Copilot Studio Agents Affect AI Costs? Copilot Studio agents introduce another layer of AI cost management. Organizations can build custom agents that interact with Microsoft 365 data, automate workflows, and perform business-specific tasks. These agents can generate ongoing consumption based on how frequently they run and how complex their workloads become. For organizations without full Copilot licensing, agent consumption often becomes a primary area of AI spend that requires governance and monitoring. Because of this, AI agents should be treated as both technical assets and financial assets. What is the Best Way to Prevent Unexpected AI Charges? The most effective strategy is implementing guardrails before widespread adoption. Several best practices can help organizations control AI spending and avoid unexpected charges: Start with Small Pilot Groups Avoid deploying new AI capabilities across the entire organization immediately. A smaller pilot group helps establish realistic consumption patterns before scaling. Enable Budget Caps Spending limits should include enforcement controls, not just notifications. Hard caps help prevent surprise bills and create accountability. Create Alerts and Thresholds Usage alerts at 50%, 70%, 90%, and 100% of budget can provide valuable visibility before limits are reached. Monitor Power Users Organizations often discover that a small group of users generates the majority of AI consumption. Understanding usage patterns helps determine whether additional licensing or budget adjustments make sense. Should IT and Finance Teams Manage AI Costs Together? Yes. AI FinOps should not be owned exclusively by IT. Successful AI governance typically requires collaboration between: IT leaders Finance teams Department managers Executive stakeholders Business leaders determine where value exists. Finance teams evaluate cost impact. IT teams implement governance and controls. When all three groups participate, organizations are better positioned to scale AI successfully. When Should Organizations Use Copilot Studio vs Azure AI Foundry? The answer depends on the use case. Copilot Studio is often the fastest way to build conversational agents that users interact with through a chat interface. Azure AI Foundry and Azure-native services are often better suited for advanced agentic workflows, automation scenarios, and highly customized solutions that require greater flexibility. Organizations frequently begin with Copilot Studio and expand into Azure-native AI architectures as requirements become more complex. Why is AI Cost Governance Becoming More Important? As organizations adopt AI agents, automation, and advanced Microsoft's AI capabilities, the risk of uncontrolled consumption increases. Without governance, organizations can quickly lose visibility into: Who is using AI Which agents are consuming resources How much AI workloads cost Whether AI investments are delivering value AI FinOps creates the framework required to manage these risks while supporting innovation. How to Get Started with AI FinOps Microsoft Copilot, AI agents, and Azure AI services can create significant business value, but organizations need a strategy for managing consumption and controlling costs. The right AI FinOps framework helps organizations balance innovation with financial accountability while giving users the freedom to explore new AI capabilities responsibly. If you need help implementing Microsoft Copilot, Copilot Studio, AI governance, or AI FinOps strategies, the Sourcepass MCOE team can help you build a scalable approach that aligns technology investments with business outcomes. Interested in more conversations about Microsoft Copilot, AI governance, security, licensing, and cloud strategy? Subscribe to the Demystifying Microsoft podcast for the latest insights from Microsoft experts and industry practitioners.
Read full post on blog.sourcepass.com
New York Water Cybersecurity Requirements for 2027 | Sourcepass
New York public water systems face a new cybersecurity compliance deadline that requires action before January 1, 2027. The New York State Department of Health's new cybersecurity requirements apply to covered community water systems serving more than 3,300 people and require organizations to establish a cybersecurity program, conduct a cybersecurity vulnerability analysis, address identified vulnerabilities, and maintain documentation.
New York public water systems face a new cybersecurity compliance deadline that requires action before January 1, 2027. The New York State Department of Health's new cybersecurity requirements apply to covered community water systems serving more than 3,300 people and require organizations to establish a cybersecurity program, conduct a cybersecurity vulnerability analysis, address identified vulnerabilities, and maintain documentation.
Read full post on blog.sourcepass.com
Why Every Tax Preparation Firm Needs a Written Information Security Plan (WISP)
Tax preparation firms handle some of their clients' most sensitive information, including Social Security numbers, tax returns, banking information, payroll records, financial statements, and other nonpublic financial data.
Tax preparation firms handle some of their clients' most sensitive information, including Social Security numbers, tax returns, banking information, payroll records, financial statements, and other nonpublic financial data.
Read full post on blog.sourcepass.com
GLBA Security Incident Response for Accounting Firms | Sourcepass
A security incident at an accounting firm creates two separate challenges: responding to the technical problem and determining what the incident means for the firm's regulatory and business responsibilities.
A security incident at an accounting firm creates two separate challenges: responding to the technical problem and determining what the incident means for the firm's regulatory and business responsibilities.
Read full post on blog.sourcepass.com
GLBA Cybersecurity: 7 Questions for Your IT Provider | Sourcepass
For accounting firms subject to the Gramm-Leach-Bliley Act (GLBA), cybersecurity is not simply an IT responsibility. The GLBA Safeguards Rule requires covered financial institutions under the Federal Trade Commission's jurisdiction to maintain a written information security program designed to protect customer information.
For accounting firms subject to the Gramm-Leach-Bliley Act (GLBA), cybersecurity is not simply an IT responsibility. The GLBA Safeguards Rule requires covered financial institutions under the Federal Trade Commission's jurisdiction to maintain a written information security program designed to protect customer information.
Read full post on blog.sourcepass.com
The GLBA Safeguards Rule Checklist for Accounting Firms | Sourcepass
For accounting firms, GLBA compliance is not just a privacy requirement. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires covered financial institutions to develop, implement, and maintain a written information security program designed to protect customer information.
For accounting firms, GLBA compliance is not just a privacy requirement. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires covered financial institutions to develop, implement, and maintain a written information security program designed to protect customer information.
Read full post on blog.sourcepass.com
Does GLBA Apply to Your Accounting Firm? Guide to the Safeguards Rule
If you run an accounting firm, you may already have a basic cybersecurity program, but a more specific question may be harder to answer: Does GLBA apply to our firm?
If you run an accounting firm, you may already have a basic cybersecurity program, but a more specific question may be harder to answer: Does GLBA apply to our firm?
Read full post on blog.sourcepass.com