Bezalu
All newsletters

February 2026: Deepfake CEO Scams and the End of SMS-Based MFA

Cybercriminals now need only a few seconds of audio to clone a voice. This issue explains how “deepfake CEO” scams work — a familiar-sounding call requesting an urgent wire transfer — and what tell-tale signs and verification habits protect your business. It’s a natural extension of the cybersecurity fundamentals we help clients put in place.

We also make the case for moving beyond SMS one-time codes to phishing-resistant MFA: FIDO2 passkeys, hardware security keys, and authenticator apps with number matching. And with Windows Server 2016 reaching end of support on January 12, 2027, we outline why now is the time to plan a migration rather than pay escalating Extended Security Update fees.

Plus: a 15-minute daily cloud checkup routine, security policies for staff working from cafes and coworking spaces, and how to audit Microsoft 365 Copilot licenses so you’re not paying for seats nobody uses. Want a migration or MFA rollout plan? See our managed IT services.

In this issue

  • The 'deepfake CEO' scam: why voice cloning is the next cyber threat
  • Why SMS codes are no longer enough (and what to use instead)
  • Windows Server 2016 end of support and your cloud migration plan
  • A simple 15-minute daily cloud checkup routine
  • Security policies for employees working from cafes and coworking spaces
  • Auditing Microsoft 365 Copilot usage to avoid licensing waste

Read the full newsletter

Your browser can't display the embedded PDF.

Download the PDF instead