If you own a business in Columbus or Central Ohio, you probably spend hours worrying about the right things: growing revenue, keeping customers happy, and protecting your bottom line. But here’s what keeps most business owners up at night that they don’t talk about openly: is their data actually secure?
Most Columbus businesses rely on Microsoft 365 to run their operations. Email, documents, spreadsheets, video calls, collaboration tools. It’s all there. But here’s the uncomfortable truth that your IT company might not want to tell you: if you set up your Microsoft 365 account before 2022, or if a previous IT provider configured it and never touched it again, you’re probably running on legacy settings that Microsoft itself has worked hard to move away from.
This isn’t about negligence. This is about how software updates work in the real world. Microsoft changes the defaults, but those changes don’t automatically apply to existing accounts that were set up years ago. Think of it like a building code. New buildings have to meet the latest safety standards, but older buildings that were built to code at the time don’t automatically upgrade themselves.
The difference? Your data is on the line.
Why This Matters for Your Business Right Now
Cybersecurity for small business isn’t just about hiring the right IT company. It’s about asking the right questions. And the question most Columbus business owners should be asking is: ‘Are my Microsoft 365 settings actually protecting me, or am I just assuming they are?’
Here’s what we see every week working with SMBs across Central Ohio: companies that think they’re locked down, but they’re not. They have gaps in their IT compliance that they don’t even know about. They’re one email compromise away from a serious problem.
Let’s talk about five specific settings that your managed service provider should have checked and configured correctly.
Setting #1: External File Sharing Rules
If you use SharePoint or OneDrive, you need to know who can access your files when they’re shared with people outside your organization.
The old default setting? Anyone with a link can access your files. No password. No verification. Whoever has the link, has access.
For a Columbus business handling anything sensitive, that’s scary. Customer data. Financial records. Trade secrets. All potentially exposed to anyone who guesses the right link.
What should your IT services provider have set up? Specific sharing controls that limit who can access shared files and what they can do with them. This is basic IT compliance, but it’s overlooked constantly.
Ask your IT company this week: ‘Are our external sharing permissions set to the most restrictive setting that still lets us work with our partners?’
Setting #2: Email Forwarding to External Addresses
Here’s a scenario that happens more often than you’d think in Central Ohio businesses:
An employee’s email account gets compromised. A hacker logs in. The first thing they do? Set up email forwarding to an external email address. Now every email your company receives is being copied to someone outside your organization. Your client emails. Your vendor communications. Your internal discussions about strategy and pricing.
The attacker sits back and watches your business bleed information.
This is one of the most common ways cybersecurity for SMBs gets breached. And the fix is simple: your managed service provider should have disabled external email forwarding by default.
If employees legitimately need to forward emails to external addresses, that should require explicit approval and be monitored constantly.
Setting #3: Third-Party App Consent Permissions
You know all those apps you connect to your Microsoft 365 account? The project management tool. The CRM. The marketing automation platform. The calendar sync service.
Every one of them asks for permission to access your data. Most businesses just click ‘approve’ and move on.
Here’s the problem: some of those apps ask for permissions they don’t actually need. They want access to your entire mailbox. Your calendar. Your contact list. Your file storage. Worse, some malicious apps are specifically designed to harvest this data.
Any Columbus IT company worth hiring should have locked down these permissions in your tenant. Only approved apps should be allowed. Only necessary permissions should be granted.
This is part of IT compliance that separates serious managed service providers from the ones who just keep the lights on.
Setting #4: Audit Log Retention
Imagine this: someone accesses a confidential client file at 2 AM. You want to know who, when, and what they did with it.
Do you have that information?
If your audit logs aren’t being retained and monitored, the answer is no.
The default Microsoft 365 settings for audit log retention used to be pretty limited. Older tenants might not have the settings in place to keep a complete record of who’s doing what in your Microsoft 365 environment.
Your IT services company in Columbus should have configured extended audit log retention and set up monitoring alerts for suspicious activity. This isn’t just good practice. It’s often required for IT compliance in certain industries.
Setting #5: Multi-Factor Authentication Enforcement
This is the big one. This is the setting that stops the majority of cyberattacks before they even get started.
Multi-factor authentication means that even if someone has your password, they can’t log in without a second verification step. Usually it’s an app on your phone or a text message code.
The problem? A lot of older Microsoft 365 tenants have MFA as optional, not required.
Employees skip it. They say it’s inconvenient. They promise they’ll set it up later. And suddenly, you have part of your team protected and part of your team completely exposed.
Any serious IT company in Columbus will tell you the same thing: MFA enforcement is non-negotiable for cybersecurity for small business. It’s the single most effective defense against account compromise.
How to Know If Your IT Company Is Handling This
Here’s a simple test: ask your managed service provider point-blank about each of these five settings.
Their answer should be specific. Not vague. Not ‘we’ll look into it.’ Specific answers like:
- We reviewed your external sharing policies last quarter and we restrict sharing to verified domains only.
- Email forwarding to external addresses is completely disabled except for three exceptions we approved in writing.
- We have a list of 12 approved third-party apps, and we audit their permissions quarterly.
- Your audit logs are retained for 365 days and we monitor them with automated alerts.
- Multi-factor authentication is required for all users, with no exceptions, and it’s enforced by our security policies.
If your IT services provider can’t give you answers like that, you have a problem. Not a minor IT compatibility issue. A real security problem.
The Real Cost of Getting This Wrong
You might be thinking: ‘These are technical details. This is what I pay my IT company to handle.’
And you’re right. You do pay them to handle it. But here’s what most Columbus business owners don’t realize: not all IT companies take cybersecurity for small business seriously enough.
Some managed service providers are just focused on keeping your systems running. Others are focused on proactive security. There’s a huge difference.
The cost of a data breach for a small or medium-sized business in Ohio isn’t just the immediate damage. It’s the notification costs. It’s the potential fines. It’s the reputation damage. It’s the lost customer trust.
For many SMBs, one serious breach ends the business.
What You Should Do This Week
Email your IT company. Or call them. Or schedule a meeting. Ask them directly about these five settings in your Microsoft 365 tenant.
If you’re working with a managed service provider in Columbus who takes IT compliance seriously, they should welcome this conversation. In fact, they probably already have documentation about these settings.
If they seem confused. If they give you vague answers. If they tell you they’ll ‘look into it and get back to you,’ that’s a red flag.
Cybersecurity for SMBs isn’t optional anymore. It’s fundamental. And it starts with the basics. With settings. With attention to detail.
If your current IT company can’t or won’t give you clarity on where your Microsoft 365 security actually stands, it might be time to have a conversation with an IT company in Columbus that specializes in security-first managed IT services.
Questions to Ask Your IT Company
- When was the last comprehensive security audit of our Microsoft 365 tenant?
- Which of these five settings have you reviewed and configured?
- Do you have written documentation of our current configuration?
- How do you monitor for suspicious activity in our Microsoft 365 environment?
- What’s your incident response plan if we get compromised?
The Bottom Line
You don’t need to be a Microsoft 365 expert. You don’t need to understand every technical detail. What you need is an IT services provider who cares about protecting your business.
These five settings aren’t theoretical. They’re the difference between a company that’s locked down and a company that’s vulnerable.
Your customers trust you with their data. Your employees trust you with their information. Your business depends on systems that actually work.
Make sure the people you’re paying to protect that infrastructure are actually doing the job.
If you need help securing your Microsoft 365 environment, or if you’re looking for a managed service provider in Columbus that takes security as seriously as you do, let’s talk. Contact us for a free security assessment of your current setup.
Writing heavily inspired by The Technology Press.