Every week, small business owners face a barrage of technology changes that can either protect their operations — or leave them exposed. This week’s Nerds News covers four stories you can’t afford to miss: Microsoft is pulling free AI access from your Office apps in five days, a new ransomware strain is encrypting files within 24 hours of infection, manufacturing companies are now the #1 ransomware target in the US, and 20 states now have active data privacy laws with real fines attached. Here’s what you need to know.
Microsoft Ends Free Copilot in Word, Excel, and PowerPoint — April 15 Deadline
If your team has been using Microsoft’s built-in AI features inside Word, Excel, or PowerPoint, that free ride ends on April 15, 2026 — five days from now. Starting that date, full Copilot functionality in those apps will require a Microsoft 365 Copilot license at $21 per user per month.
That adds up fast. One user costs roughly $252 per year. A team of five hits $1,260 annually before you’ve done anything else. Microsoft offered this capability for free during rollout to build adoption, but the billing clock is now ticking for every business that came to rely on it.
If you’re not sure which of your users have been using Copilot features, now is the time to find out. You can keep the license only for power users and remove it from the rest — but you need to make that decision before April 15 or your Microsoft billing will likely auto-upgrade affected accounts. Call us if you’re not sure what you’re paying for — we’ll audit your Microsoft 365 licensing before the deadline.
Medusa Ransomware Executes Within 24 Hours of Infection
A Microsoft security advisory is warning businesses about Medusa ransomware — a strain that is particularly dangerous because it moves fast. From the moment it infects a system, Medusa begins its encryption process within 24 hours. That’s a razor-thin window to detect, isolate, and respond before your files are locked.
Medusa is actively targeting professional services, healthcare, finance, and education organizations in the US, UK, and Australia. It typically gets in through internet-facing systems — email servers, file transfer tools, and client portals. Once inside, it’s not waiting around.
The good news: Medusa is not exploiting unknown zero-day vulnerabilities. It relies on known weaknesses that patches already address. That means keeping your computers patched and up to date is your strongest defense. This is exactly why ACS pushes patches to client computers overnight — so when a threat like Medusa is actively circulating, your systems are already protected. If your computers aren’t being patched on a regular schedule, that needs to change today.
20 States Now Have Data Privacy Laws — Including Indiana, Kentucky, and Rhode Island
You may not think of your business as a data company, but if you collect customer names, email addresses, invoicing information, or any personal data through your website or business systems — you are subject to state privacy laws. As of January 1, 2026, Indiana, Kentucky, and Rhode Island joined 17 other states with active consumer data privacy legislation on the books.
These aren’t toothless regulations. They come with real fines, and Rhode Island’s law includes no cure period — meaning if your business suffers a data breach and you’re found non-compliant, you cannot simply fix the problem and avoid the penalty. The fine is automatic.
If your business operates in any of these 20 states, or if you have customers who live there, you need to understand what data you’re collecting, how it’s stored, and who has access to it. A strong security posture — patched systems, encrypted storage, access controls — is your best protection against both the breach itself and the regulatory fallout that follows. If you’re not sure whether your business is compliant, schedule a free consultation with our team.
Manufacturing Is Now the #1 Ransomware Target — Up 61% Year Over Year
According to a new report from Huntress, manufacturing has overtaken every other industry as the top ransomware target in 2025, accounting for 17% of all cyberattacks — up from just 9% the year before. That’s a 61% year-over-year increase, and the trend is accelerating.
Here’s what makes this especially important: attackers don’t know or care whether you’re doing defense work, aerospace contracts, or making custom parts for local industry. They hit manufacturing networks because they know manufacturers can’t afford downtime, which makes them more likely to pay. They attack everyone — not just high-profile targets.
If you’re a manufacturer and you’ve been thinking “we’re too small to be a target,” that assumption is now demonstrably wrong. The attackers don’t know your size or your clients. They scan for vulnerable systems and attack whatever they find. The only protection is a proactive security posture: patched computers, endpoint protection, strong access controls, and regular backups that are tested and verified. ACS works with manufacturers across Michigan, Illinois, and Florida — if you’re in this sector and you’re not confident in your security coverage, reach out now.
Quick Hits
- Microsoft 365 Global Outage (April 2): Microsoft 365 went down globally on April 2nd, affecting email, Teams, and SharePoint for thousands of businesses. A reminder that even Microsoft’s infrastructure isn’t immune — which is why having a business continuity plan matters.
- Dutch Healthcare Provider Hit by Ransomware: A ransomware attack knocked 80% of hospitals in the Netherlands offline. Healthcare continues to be one of the most targeted sectors worldwide.
- Cloudflare Performance Issues (April 8–9): If your usual websites felt slow over the past two days, Cloudflare — which routes a massive portion of global web traffic — was experiencing a performance disruption. It’s not your internet connection. It’s not Spectrum. This one’s on Cloudflare.
Key Takeaways
- Microsoft Copilot requires a $21/user/month license starting April 15 — audit your users now
- Medusa ransomware encrypts within 24 hours — patch your computers and leave them on overnight
- 20 states have data privacy laws with real fines — Rhode Island has no grace period
- Manufacturing is the #1 ransomware target with a 61% YoY increase — no manufacturer is “too small”
Is your business protected against these threats? ACS offers a free IT consultation to help you understand your current exposure and what steps to take. Schedule your free consultation at acsapp.com — no commitment, just clarity.