The VienerX Bi-Weekly Newsletter is Produced Entirely In-House at VienerX Offices in Rockville, MD

For the full experience, please click the view in browser option located in the top right, or enable media for this email.

Table of Contents

Follow Us on Social Media

DanFree via Pixabay

ETM & Business Performance

VienerX has long helped companies align technology with the way their business actually works. That work began under Enterprise Technology Management, or ETM: the strategy, support, systems, and execution that keep organizations moving.

Now, VienerX is taking the next step and leading with the outcome our clients have always counted on: Business Performance.

“At VienerX, we have always believed technology should do more than operate in the background. It should help your business perform better,” said VienerX Founder/CEO Wayne Viener. “When people ask what we do for our clients, I often say, ‘We Make Your Company Work.’ But the deeper answer is that we help businesses win. Whether that means top-level support, a smarter technology strategy, stronger systems, or guidance through growth, our goal is always better business performance. That is why we keep clients for decades. Business Performance is not a new direction for us. It is who we have always been. Now we are putting it at the center of how we lead.”

We invite you to visit our new Business Performance page to see how VienerX turns IT from an expense into a pathway for growth. ETM is the foundation. Business Performance is the promise.

SunRiseForever via Pixabay

The Next Big Scam, AI Deepfakes

VienerX Technology Insights

One of the most pressing issues in IT has always been, and will always be, phishing scams. Phishing is the digital version of an old-fashioned confidence game: someone earns just enough trust to make you act against your own interest.

These have been around for almost as long as email itself. Most people know the general idea: a malicious actor sends a message requesting information, pretending to be a legitimate figure of some kind. Usually, they pose a threat (e.g., send your social security number or your driver's license will be suspended) or offer some sort of reward (the infamous foreign prince who needs your bank account information to wire you money).

These exploded in popularity in the late 2000s and early 2010s and are now a multi-billion dollar global industry. In fact, phishing scams cost Americans alone $7.7 billion in 2024, per the FBI. Legal or not, and it’s very much not, for an industry as expansive as this, innovation is to be expected. The latest innovation is one that has dangerous potential: deepfakes.

What are Deepfakes?

Deepfakes are forms of media (audio, photo, video, etc.) that are designed to mimic someone else. For example, if you wanted to have a fake Tom Cruise say happy birthday to you in a video, the technology exists for you to do so.

Deepfakes have existed in various forms for decades but shot into the wider public sphere in late 2017 as AI technologies became more widely used. By 2020, the technology evolved to the point that, by using just a few seconds of audio, AI models could replicate a human voice.

This technology has had a largely negative response, with many pointing to the numerous ways it could be weaponized to harm organizations and institutions. Several platforms, including Google, Reddit, and X (formerly Twitter), have either outright banned or taken major steps to limit the spread of deepfake content. The states of Virginia, Texas, California, New York, and others have passed legislation to criminalize certain deepfake uses.

Phishing Using Deepfakes

One of the more dangerous applications of this tech is deepfake phishing. The ability to copy someone’s likeness, be it a photo, video, or voice, has huge implications for scamming.

A popular combination is pairing voice deepfakes with call masking (a technology that allows phone numbers to appear as other numbers). This allows a call to come in that appears to be from a loved one, using their exact voice, asking you to deposit funds into a malicious account.

This can go a step further. More advanced scammers can use video deepfakes to impersonate people on video calls. This is even more potent if a hacker has already breached a system tenant and can send invitations from inside the organization.

What To Do About It?

Technology companies and governmental organizations are already well aware of these threats and are working on safeguards. What users and businesses can do today is develop their own policies to prevent funds and information from falling into the wrong hands:

  • Establish safe words/phrases: Develop a passphrase that only those inside your trusted circle know. This can be asked for in situations that seem suspicious.

  • Verify via another channel: If the situation is not urgent, you can always verify with another form of communication. If a call seems odd, volunteer to verify via email or a direct message, or hang up and call them back on a known, trusted number to see if the story is consistent.

This technology is frightening, but it is not a lost battle. As the bad guys get stronger, the defense systems and techniques of the good guys will as well. If you are concerned about your organization's security policies, contact us to help you set up robust defenses and training.

Image: BSDrouin via Pixabay

Managed AI – The Next Enterprise Security Layer

Managed IT is an expansive product category. It can include several things, PCs, cell phones, local software, firewalls, backups, cloud solutions, and more. The truly insane part, it keeps getting bigger. Just in the last decade, cell phones have gone from an add-on to a critical component, cloud solutions have moved to a nice to have abstract function to one of the larger industries on earth, the list goes on and on.

The next critical function of the managed IT field we have begun to believe, is what we are calling Managed AI.

What is Managed AI?

Managed AI, as we are using the term, is an LLM AI platform that is secured and managed the same way that devices and email tenants. Secure, organizational control, easy to maintain and track data. It’s a platform, managed by an IT provider, for an organization, that LLMs run through. Managed AI is not a common term yet, even in the MSP space. A Google search will not yield the definition we are using (you can go try, we can wait). The product category is still in its infancy.

Why Now?

While it might already feel like AI has been around forever, LLMs in the mainstream are still very new by both technology and business standards. ChatGPT only hit 50 million users three years ago in 2023. CoPilot became native to Windows in December of the same year. One could easily argue that LLM AI models only became a common business tool in the last two years, and most of those two years have been consumed by ongoing battles on if/how/why AI should be used in the workplace.

At this point in time, while the how/why part of AI is still a scorching hot issue, many have accepted that it is probably here to stay to at least some extent. The next question IT professionals should be asking is “Ok, it’s sticking around. So, what are the risks in that?” The answer is, it’s a web-based piece of software that employees are throwing countless pieces of company data into, it’s the same risk as anything else online, and a massive one at that.

The Threat of "Shadow AI"

When an employee copies and pastes a confidential client meeting transcript into a public AI tool to “generate a quick summary,” or feeds it a block of proprietary code to "check for bugs," they are effectively taking company data outside of the secure environment.

The danger with free, public AI tools is that your inputs are often used to train future versions of their models. Once you put sensitive information into a public LLM, it is no longer just yours, it is in the wild. You have no control over what happens next.

This phenomenon, often referred to as "Shadow AI," creates a massive blind spot for businesses. It opens the door to severe data leaks, intellectual property theft, and major compliance violations for regulated industries (like HIPAA or SOC 2).

How Managed AI Solves the Problem

If employees are going to use AI to work more efficiently, and they absolutely are, the solution isn’t to ban it. Banning AI just forces employees to use it secretly on their personal devices which introduces ever more problems. The solution is to secure it.

That is exactly what a Managed AI layer does. By deploying an enterprise-grade AI solution managed by your IT provider, you get the best of both worlds: productivity and security.

  • Walled Data: A Managed AI instance lives entirely within your company’s secure environment. When your team interacts with the AI, the data stays in-house and is never used to train public models.

  • Visibility and Control: Just like managing a fleet of laptops or Microsoft 365 accounts, IT can control exactly who has access to your data.

  • Compliance and Logging: If there is ever an audit, IT has full visibility into the environment, ensuring that the company's data governance policies are being followed.

The Bottom Line

We are moving past the phase of asking if AI belongs in the workplace, and entering the phase of asking how to secure it.

Don't wait for a data leak to realize your team is using public AI tools. Reach out to the VienerX team today to talk about auditing your current AI usage and setting up a secure Managed AI layer for your business.