by Steve Sorbo | Feb 6, 2026 | Uncategorized
When business slows down, it’s tempting to reduce IT spending. But that approach often backfires, creating bigger problems—and larger bills—down the road.
Beyond the productive work you accomplish on your Macs, your technology infrastructure enables you to communicate with clients, send invoices, manage schedules, and get paid. A downturn is precisely when you need those systems working reliably, not when you should neglect them.
The smart approach isn’t to stop spending on IT. It’s to protect the essentials while trimming optional expenses. Let’s look at what’s critical and what’s not.
The Hidden Costs of Cutting Back
When IT spending gets cut, three things typically go wrong:
- Small problems become big problems: Deferring maintenance—putting off updates, delaying hardware replacements, and ignoring broken workflows—doesn’t save money, it just pushes the expense to a later date, when it will almost certainly cost more. Beyond the fact that prices only increase over time, emergency troubleshooting, rush purchases, and downtime during business hours always cost more than planned maintenance.
- Security risks persist: Attackers don’t slow down just because revenues have. When budgets tighten, businesses often cut the very things that stave off disasters: software updates, security monitoring, and tested backups. One phishing attack that leads to wire fraud, one malware infection that steals passwords, or one unpatched vulnerability can wipe out years of “savings.”
- Productivity losses add up quietly: When Wi-Fi is flaky, Macs are slow, and file sharing doesn’t work reliably, employees waste time waiting and working around problems. During a downturn, you typically have fewer people doing more work, which is the worst time to tolerate daily friction.
What to Protect First
Spending on some aspects of IT is more important than others. These are the services that keep your business running smoothly and help you recover when something goes wrong:
- IT support and consulting: We’re biased, of course, but we’ve seen what happens when clients go out on their own and then come back. Proactive support catches issues early, keeps your systems running, and ensures you have someone to call who already knows your setup when things break.
- Software subscriptions: Adobe Creative Cloud, Microsoft 365, accounting software, and similar subscriptions often seem cuttable. But letting subscriptions lapse means missing security updates and losing access to files in proprietary formats. It also means employees will spend time learning new tools rather than being productive with familiar ones. Before canceling, understand what you’ll lose.
- Backup services: Cloud backup services like Backblaze or CrashPlan may seem unnecessary if you have local backups, but they protect against burglaries, fires, or burst pipes that can destroy local backups.
- Networking equipment: Dodgy Wi-Fi access points and aging routers waste everyone’s time. If your team can’t reliably stay connected, nothing else matters. If you need to replace networking gear, choose quality products that will last for years.
- Hardware replacement budget: It’s tempting to squeeze another year out of aging Macs, but don’t keep them going beyond the point where they stop receiving security updates. User productivity will also decline as older Macs slow down and experience more issues.
Where to Cut Without Breaking Things
Many businesses have unnecessary costs hiding in plain sight. Here’s where to look:
- Unused software licenses: Audit what you’re paying for versus what employees actually use. Many companies have up to 30% of seats unused across various apps. Reclaim those seats, and establish a simple rule: every subscription needs an owner and a regular review.
- Duplicate tools: It’s surprisingly common for businesses to pay for multiple apps that do the same thing—multiple chat platforms, overlapping backup utilities, and so on. Pick one and consolidate.
- Vendor contracts up for renewal: Before agreements for Internet service, phone plans, hosting, or equipment leases auto-renew, check whether you still need the same service level. Many vendors will negotiate rather than lose a customer, and some plans can be downgraded to match actual usage.
- Projects that don’t solve real problems: Pause any “nice to have” work that isn’t about reducing costs, lowering risk, or helping you serve customers better: things like migrating to a new CRM, redesigning a website that’s working fine, or building custom tools when off-the-shelf options exist. A downturn forces prioritization—use it.
The goal isn’t to spend more on IT—it’s to spend smarter. Protect the services that keep you running, cut the ones that don’t, and avoid creating tomorrow’s emergency by skipping today’s maintenance. If you’re unsure where to cut and where to hold the line, we’re happy to help you sort through the options. A short conversation now can prevent an expensive surprise later.
(Featured image by iStock.com/Userba011d64_201)
Social Media: Freezing IT spending during a slowdown often leads to higher costs later. Here’s practical, real-world advice on reducing costs while protecting the services that keep your business running.
by Steve Sorbo | Feb 6, 2026 | Uncategorized
AI agents—software that can take actions on your behalf using artificial intelligence—are having a moment. The appeal is obvious: imagine a robot butler that triages your inbox, manages your calendar, and handles tedious tasks while you focus on more important work.
That’s the promise driving the recent surge in popularity of OpenClaw (formerly known as Clawdbot and Moltbot), which is now all the rage in tech circles. Token Security found that at least one person is using it at nearly a quarter of its enterprise customers, mostly running from personal accounts. That’s a shadow IT nightmare—employees connecting work email and Slack to an unsanctioned tool that IT doesn’t know about and can’t monitor. Whether you’re an individual tempted by OpenClaw’s promise or a manager wondering what your users are up to, you need to understand the risks these AI agents pose.
OpenClaw is an AI agent built around “skills”—installable plugins that let it integrate with your messaging apps, email, calendar, and more. You communicate with OpenClaw via Messages, Slack, WhatsApp, and similar apps. Because it’s open source, you’ll need to provide your own API keys for AI services like OpenAI or Anthropic, which means ongoing costs that can add up quickly—people have reported spending $10–$25 per day.
The more serious problem? Security researchers have discovered serious vulnerabilities, including misconfigured instances exposed to the internet that leak credentials, API keys, and private messages, and a supply chain vulnerability where malicious skills uploaded to the ClawdHub library can execute arbitrary commands on users’ systems. Even beyond specific bugs, OpenClaw’s fundamental design encourages users to grant broad access to sensitive accounts.
Why AI Agents Are Risky
Security concerns aren’t unique to OpenClaw—they apply to any AI agent that acts on a user’s behalf. Here’s what’s at stake:
- Credential exposure: For an AI agent to send emails, manage your calendar, or post to Slack, it needs your authentication tokens or login credentials. If the agent software stores these credentials insecurely, or an attacker gains control, they could be exposed.
- Prompt injection: AI agents work by following instructions, but they can’t easily distinguish between prompts and data in the content they use. A class of attacks called “prompt injections” trick AI systems by hiding malicious content in emails, websites, or documents that will be processed. An attacker could embed instructions in an email that would cause your agent to search for and forward email messages containing passwords or financial data, follow links to malware sites, or take other harmful actions. There is currently no foolproof defense against this class of attack.
- Data exfiltration: An AI agent with access to your email and your computer’s filesystem could be manipulated to extract information from elsewhere on your computer—financial data, customer lists, or personal details—and send it to an attacker.
- Unvetted extensions: OpenClaw and similar AI agents let users install “skills” or plugins to extend functionality. Libraries that allow users to share custom skills often have minimal or no security vetting, making it easy for attackers to submit poisoned skills. Installing such a skill could grant malicious code access to everything your agent can touch.
- Exposed control interfaces: Security researchers found OpenClaw control servers exposed on the Internet, potentially leaking API keys, VPN credentials, and conversation histories. This risk is unique to OpenClaw at the moment, but future AI agents may suffer from similar vulnerabilities, particularly as they’re adopted by less technically savvy users.
How to Reduce Your Risk
We’ll come right out and say it: we strongly recommend against installing OpenClaw or other AI agents on your Mac. In a year or so, Apple may have updated Siri to provide many of these capabilities with significantly stronger privacy and security. But for now, just say no.
If you decide to use AI agents despite these risks, here are practical steps to protect yourself:
- Use dedicated accounts: When possible, create separate accounts specifically for agent use rather than linking your primary personal or work accounts.
- Limit permissions: Grant the agent access only to accounts it absolutely needs. If you only want help with your calendar, don’t also connect your email and messaging services.
- Avoid connecting sensitive services: Never connect anything involving money, healthcare, or confidential business information. The liability is too high if something goes wrong.
- Review agent actions: If the platform offers logs or activity feeds, check them regularly. Look for unexpected messages sent, files accessed, or connections made.
- Vet extensions carefully: Don’t install skills or plugins from unknown sources, and even with known libraries, look for evidence of others using and reviewing the skills. Treat skills like any other software you’d install on your computer.
- Keep software updated: Security patches for OpenClaw and similar tools address known vulnerabilities. If you’re running an agent, keep it up to date.
- Run agents in isolated environments: Technical users should consider running agents in sandboxed environments or virtual machines to limit potential damage.
If you run a business, you should assume that some employees have already installed OpenClaw or will soon, and may have connected their work email and Slack accounts without realizing the associated risks. Here’s what you can do:
- Educate before it’s a problem: Proactively explain the risks to employees. People are more receptive before they’ve already invested time setting something up.
- Update acceptable use policies: Make clear that connecting work accounts to unsanctioned AI agents is prohibited, and explain why.
- Offer sanctioned alternatives: If employees want AI assistance, point them toward safer options that don’t require handing over credentials to sensitive accounts.
What About Claude Cowork and OpenAI Codex?
Not all AI agent platforms carry the same level of risk. Anthropic’s Claude Cowork and OpenAI’s Codex take a different architectural approach from OpenClaw. Rather than requesting authentication tokens for your email, messaging, and other personal services, they operate within their own controlled, sandboxed environments. These systems work primarily with files, code, and data you explicitly place into their workspace, which substantially limits the fallout from an attacker gaining some level of control.
This containment approach reduces risk, but does not eliminate it. Prompt injection remains a concern whenever an AI system processes untrusted content, even inside a sandbox. An AI agent analyzing a malicious document could still be manipulated into taking unintended actions within its allowed environment. Similarly, any code generated by these systems—particularly code that touches the network or executes system commands—should be reviewed carefully to make sure it hasn’t been compromised by prompt injection.
The key distinction is scope. Claude Cowork and Codex are designed to operate within a defined workspace, whereas tools like OpenClaw require standing access to your most sensitive accounts. From a security perspective, a compromised sandbox is a recoverable incident; a compromised email or messaging account may not be.
The Bottom Line
AI agents promise a lot and may provide genuine convenience, but at a cost beyond just paying for API tokens. Before you or anyone in your organization connects an AI agent to sensitive accounts, consider: What’s the worst that could happen if this system were compromised by an attacker? If the answer involves passwords being stolen, private email being exposed, or photos being posted to social media without your knowledge, proceed with extreme caution. If you can imagine a way financial accounts could be accessed or business data stolen, don’t proceed at all.
(Featured image by iStock.com/Thinkhubstudio)
Social Media: AI agents like OpenClaw promise to automate tedious tasks, but recent security vulnerabilities highlight the dangers of using them. Learn the risks and how to protect yourself—and your organization—if you choose to use an agent.
by Steve Sorbo | Feb 6, 2026 | Uncategorized
Have you noticed that when you restart your Mac or relaunch an app, your previous windows and documents sometimes reappear exactly as you left them, but at other times you’re greeted with a clean slate?
This behavior is controlled by Resume, a technology introduced in OS X 10.7 Lion back in 2011. Resume automatically reopens app windows and documents so you can pick up where you left off after a restart or app relaunch. Apple’s goal was to make macOS work more like iOS, which tries to preserve your place in apps. However, many Mac users found it confusing when apps opened old documents or appeared in unexpected positions when the number of displays changed. Some also objected to how long it took to open old documents that were not relevant to the task at hand. Apple quickly reversed course and made reopening apps and windows optional.
Users are much more familiar with how the iPhone and iPad work now, so you may wish your Mac apps remembered their open documents and window positions. Various settings control this behavior, but it can be hard to find them and understand what they’ll do. Let’s explore how Resume works and how you can make it do what you want.
First, note that Resume operates in two distinct situations. One applies only at restart or logout, and you decide at that moment. The other governs what happens every time you quit and relaunch an app and is controlled by a persistent system setting.
The “Reopen Windows” Option at Restart
Whenever you restart, shut down, or log out of your Mac, macOS asks whether you want to reopen your apps and windows when you log back in. You’ve undoubtedly seen the checkbox in the confirmation dialog: “Reopen windows when logging back in.” When the checkbox is selected, macOS dutifully relaunches the currently running apps after you log in, putting you back where you were. If you uncheck it, your Mac will start fresh, without reloading previously open apps.

macOS remembers how you’ve selected this checkbox, so if it’s checked when you click Restart, it will also be selected the next time you restart, and vice versa. If you ever perform a forced restart or skip the dialog by holding the Option key when choosing Restart or Shut Down, macOS uses the last known state of that checkbox on the next startup.
Many users either love or hate the “Reopen windows” behavior. For those who enjoy having their entire workspace restored after a reboot, keeping that checkbox checked makes sense. For others, including many IT professionals, the point of a reboot is to start fresh. Pick whichever behavior you prefer.
Controlling Resume When Relaunching Apps
Resume also governs what happens each time you quit and reopen an individual app. This behavior is controlled by a switch in System Settings > Desktop & Dock under the Windows section, labeled “Close windows when quitting an application.”

When this “Close windows” switch is turned on—it’s the default—macOS will close all windows and discard their restorable state before allowing an app to quit. Because macOS has closed the windows before quitting, there’s nothing for Resume to restore when you next launch that app. Effectively, the app will always start fresh with no memory of past windows (unless it has its own session-restore mechanism).
On the other hand, when this option is turned off, quitting an app will not discard its windows, so when you reopen the app later, Resume will automatically restore whatever documents and windows you had open, putting you right back where you left off.
There are three main scenarios where Resume can have effects that you may or may not like:
- Document-centric apps: With these apps, like Pages and Numbers, you work on individual documents, each of which opens in its own window. When “Close windows” is enabled, apps start fresh on each launch; when it’s disabled, the documents you were working on when you quit reopen automatically.
- Unsaved documents: As a corollary to the previous scenario, if you have unsaved documents open when “Close windows” is on, you’ll be prompted to save your changes before the window is closed. When “Close windows” is off, you won’t be prompted because those documents—with all their unsaved changes—will open automatically at the next launch.
- Window-based apps: Other apps, like Mail and Messages, display their content in a main window. They’ll open this window regardless of the “Close windows” setting. However, Resume determines where that window appears. If “Close windows” is turned on, macOS does not remember which display or Space the window occupied, so the app often reopens on the primary display, even if that’s not where it was when it quit.
Most users have no idea that this “Close windows” setting exists or what it does. If you’re irritated by having to reopen Pages documents you were working on before or reposition Mail’s window after every relaunch, make sure “Close windows” is turned off. Conversely, leave it on if you want apps to start fresh.
Exceptions and Caveats
For most people, controlling Resume using the “Reopen windows” checkbox and the “Close windows” switch is sufficient. However, some people may want more control or wonder why some apps ignore those settings.
- Nonstandard apps: Everything we’ve said so far describes the behavior of standard apps using Apple’s recommended development frameworks and tools. Some apps don’t use Apple tools or play by Apple’s rules—we’re looking at you, Microsoft—and will ignore the Resume settings. Don’t be surprised if Word, Excel, and PowerPoint fail to act as described.
- Turn off Resume per launch: If you set apps to restore their windows by turning off the “Close windows” switch, you can override that on a one-off basis in some apps by holding the Shift key down as they launch. This trick doesn’t work in all apps, but it’s worth trying.
- Custom session restore: Some apps manage session restoration on their own, most notably Safari and apps built with the Electron framework, such as Slack, Discord, and Notion. For instance, in Safari > Settings > General > Safari opens with, you can choose a new window, a new private window, all windows from the last session, or all non-private windows from the last session. With such apps, look for internal settings that control their behavior.

- Login Items: Even if you deselect “Reopen windows” when restarting, apps and documents that you’ve added as login items in System Settings > General > Login Items & Extensions > Open at Login will still open. Think of this as a manual Resume—you’ll restart to a preset workspace, not to the way things were when you restarted. Some software may also install helper apps that control what appears at launch.
- Full-screen apps and Spaces: Apps that were last used in full-screen mode reopen into their own Spaces when “Close windows” is disabled. After a restart or relaunch, the app may appear not to have reopened because it is occupying a separate Space that is currently not visible.
In practice, Resume comes down to a simple set of choices:
- If you want your workspace restored after a restart, select “Reopen windows when logging back in.” Ensuring that apps—even if they’re set as login items—open full-screen or in particular Spaces also requires “Close windows when quitting an application” to be turned off.
- If you want apps to remember documents (even unsaved documents), window positions, and displays when you quit and relaunch them, turn off “Close windows.”
- If you want a clean slate, deselect “Reopen windows” and leave “Close windows” turned on.
When windows don’t appear as you expect, check these two settings as your first troubleshooting step.
(Featured image by iStock.com/BigNazik)
Social Media: Frustrated when your Mac apps don’t remember their windows—or when they stubbornly reopen old documents? Two little-discussed settings control this behavior. Here’s how Apple’s Resume technology really works.
Recent Comments