<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>Become a Proton Pass managed service provider (MSP) with our new program</title><link>https://proton.me/business/blog/password-manager-msp-pilot</link><guid isPermaLink="true">https://proton.me/business/blog/password-manager-msp-pilot</guid><description>We&apos;re introducing a pilot program for MSPs to offer Proton Pass to their clients. Find out how to apply and what to expect.</description><pubDate>Tue, 01 Sep 2026 11:56:18 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Small and medium-sized businesses are under threat from hackers in a way they&amp;#8217;ve never been before. They&amp;#8217;re the new favorite &lt;a href=&quot;https://proton.me/business/blog/ransomware-threats-smbs&quot;&gt;targets of ransomware attacks&lt;/a&gt;. AI-fueled phishing scams and malware-as-a-service make criminal work easier than ever. Our &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;SMB Cybersecurity Report&lt;/a&gt; found that hackers breached one in four SMBs last year, costing most of them between $10,000 and $100,000.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The best solution is also the simplest: Use a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To make strong cybersecurity even more accessible to SMBs, Proton Pass is launching a &lt;strong&gt;&lt;/strong&gt;&lt;strong&gt;pilot program&lt;/strong&gt; &lt;strong&gt;for managed service providers&lt;/strong&gt;. We&amp;#8217;re inviting MSPs in our community and beyond to take part. By joining the program now, &lt;strong&gt;you&amp;#8217;ll be able to offer and manage Proton Pass Professional subscriptions&lt;/strong&gt; from a dedicated portal in your own Proton Pass dashboard.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many organizations use our Proton Pass password manager within their own infrastructure, and some IT firms and MSPs deploy it for other businesses. But until now, a more feature-rich managed services portal hasn&amp;#8217;t been available. This program gives you the opportunity to add Proton Pass to the product portfolio offered to your customers while helping to shape the development and features of the Proton Pass MSP product.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is the Proton Pass MSP pilot?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The pilot program introduces a dedicated portal that allows MSPs to sell and manage Pass Professional subscriptions across multiple client organizations from one interface.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before we roll out MSP services for broader availability, we&amp;#8217;re inviting MSP businesses to take part in this initial pilot program. We&amp;#8217;ll work closely with them to understand how they use the portal and what new features they would like to see.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This launch focuses on the core features you need as an MSP, including:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Allowing multi-organization user provisioning and management&lt;/li&gt;



&lt;li&gt;Having an overview of all sub-organizations that you manage, showing allotted vs. used licenses per client, with one-click access to each client&amp;#8217;s admin dashboard&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What to know about the pilot program&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re interested in taking part, here&amp;#8217;s what to expect:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;After you &lt;a href=&quot;https://proton.me/business/contact?pd=pass&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/contact?pd=pass&quot;&gt;get&lt;/a&gt; &lt;a href=&quot;https://proton.me/partners/msp-registration&quot;&gt;in touch with our sales team&lt;/a&gt; and set up an agreement, you&amp;#8217;ll be granted access to the new MSP portal.&lt;/li&gt;



&lt;li&gt;You&amp;#8217;ll be subscribed to your own Proton Pass plan that allows you to create and manage client sub-organizations from the dedicated MSP portal.&lt;/li&gt;



&lt;li&gt;Every seat allocation or disablement is recorded as a timestamped event.&lt;/li&gt;



&lt;li&gt;At the end of each month, you can export a detailed report that you can use to bill your own clients.&lt;/li&gt;



&lt;li&gt;You&amp;#8217;ll also be &lt;strong&gt;sent a&lt;/strong&gt;&lt;strong&gt;n&lt;/strong&gt; &lt;strong&gt;invoice by Proton&lt;/strong&gt; in line with the detailed report.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/msp&quot;&gt;Find out more about the pilot program.&lt;/a&gt;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why partner with Proton Pass as an MSP?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you provide third-party password management services for businesses, your clients trust you to protect their entire IT perimeter, which includes valuable and &lt;a href=&quot;https://proton.me/business/blog/sensitive-information&quot;&gt;sensitive business data&lt;/a&gt;. That means choosing reliable tools that meet high security standards, not just ones that offer the right price or make claims you can&amp;#8217;t verify.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Security your clients can rely on&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Everything we claim about &lt;a href=&quot;https://proton.me/pass/security&quot;&gt;Proton Pass&amp;#8217;s security&lt;/a&gt; is backed up by regular &lt;a href=&quot;https://proton.me/business/blog/proton-pass-audit-2026&quot;&gt;third-party security audits&lt;/a&gt; and our application code is all &lt;a href=&quot;https://proton.me/community/open-source&quot;&gt;open-source&lt;/a&gt; so anyone can verify it. Our &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/zero-access&quot;&gt;zero-knowledge architecture&lt;/a&gt; and &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt; form a secure foundation for any business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/customer/elemnta&quot;&gt;&lt;em&gt;Read why fintech Elemnta chose Proton Pass&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Effective password management for teams&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass provides secure credential management with &lt;a href=&quot;https://proton.me/support/pass-business-policies&quot;&gt;customizable policies&lt;/a&gt; and granular reporting that make it an ideal choice for managed service providers. You can manage all of your clients&amp;#8217; organizations from one console, ensuring that &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;business password policies&lt;/a&gt; are followed and strict security standards are met.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Easy enough for anyone to use&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you&amp;#8217;re introducing a new password manager, encouraging adoption can be a challenge. Proton Pass was designed to work for anyone, no matter their familiarity or confidence with tech. Companies that switch to Proton Pass say the intuitive interface led to more widespread adoption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/pass/customer/morning&quot;&gt;&lt;em&gt;See how French coworking firm Morning rolled out Proton Pass&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;An EU-based alternative for digital sovereignty&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many businesses are looking for &lt;a href=&quot;https://proton.me/blog/european-alternative-us-tech-survey&quot;&gt;European alternatives&lt;/a&gt; to the American tech they&amp;#8217;ve relied on because they&amp;#8217;ve realized they don&amp;#8217;t truly have control of their own data. When clients ask how you address this problem, Proton Pass can be the simple answer.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can learn about &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;all the Proton Pass features&lt;/a&gt; and see &lt;a href=&quot;https://proton.me/alternatives#pass&quot;&gt;how Pass compares&lt;/a&gt; to other password managers. Our &lt;a href=&quot;https://proton.me/partners/msp-registration&quot;&gt;sales team&lt;/a&gt; is also available to help you if you have any questions about the MSP program or need answers for your clients.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find out more about the &lt;a href=&quot;https://proton.me/business/pass/msp&quot;&gt;pilot program&lt;/a&gt; and how businesses can benefit from adopting a secure European business password manager.&lt;/p&gt;
</content:encoded><category>For business</category><author>Raphael Auphan</author></item><item><title>August 27 outage: Incident report</title><link>https://proton.me/blog/august-27-outage-incident-report</link><guid isPermaLink="true">https://proton.me/blog/august-27-outage-incident-report</guid><description>Here&apos;s a timeline of what happened, what choices we made during the incident and why, and how it was resolved.</description><pubDate>Fri, 28 Aug 2026 21:12:56 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;In the early hours of August 27, 2026, Proton experienced a widespread outage that impacted services for a number of users. The root cause was a total failure of the cooling system in our Frankfurt datacenter. While all systems at Proton are redundant and we have enough capacity to endure a complete data center failure, there are a small number of scenarios where the failover can take longer and lead to user-facing disruptions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s a timeline of what happened, what choices we made during the incident and why, and how it was resolved.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Timeline&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Just after 11 p.m. (Central European time) on Wednesday, August 26, a cooling system failure occurred in the main room of our Frankfurt datacenter. At around 11:15 p.m., the temperature started rising from approximately 21.8°C (nominal temperature) to 51.9°C in less than half an hour, with some measurement probes reporting 60°C air temperature in the room. As the temperatures rose, server and networking equipment within the facility started to die one by one.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The user-facing incident began at around midnight on August 27, when the failures escalated to the point that critical redundancy was lost. This occurred when both the primary and backup network switch on a critical rack failed, and this rack unfortunately contained several primary database copies. While almost all Proton systems are redundant and will failover automatically/immediately, primary database failovers are not done automatically without human supervision.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We retain this control out of a desire to avoid so-called &amp;#8220;split brain&amp;#8221; situations, where a temporary unavailability of a primary database means that the replica copies miss some updates and become de-synced in ways that can be difficult to reconcile later. Furthermore, when a primary database failover occurs, the standard operating procedure is to failover to a replica in the same datacenter for latency and performance reasons. However, the specific nature of the problem meant that this might be ill-advised, since we potentially could be failing over to something that would also go down.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The decisions&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At this point, Proton&amp;#8217;s on-call engineers needed to make a couple consequential decisions while operating under extreme pressure.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Do they prioritize bringing the service back online, or prioritize addressing the cooling problem and saving the hardware inside the datacenter?&lt;/li&gt;



&lt;li&gt;Should we failover to replicas within the same building Frankfurt (faster and less disruptive, but possibly a temporary fix if the heat could not be brought under control), or failover to Zurich?&lt;/li&gt;



&lt;li&gt;Do we failover everything or just what is down at the moment? We have contingencies for complete data center failure where things failover fully and mostly automatically rather quickly, but a situation where random servers are dying one by one is not handled well by our failover logic.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ultimately the rate at which temperatures were rising forced us to prioritize saving the hardware versus bringing services back online. This is not a choice that typically needs to be made, because cooling systems are typically redundant, and the complete loss of cooling is quite rare, meaning that there is quite a bit of time before temperatures become critical. The problem is exacerbated by large increase in server power density in recent years with higher power CPUs and GPUs for AI. As a result, what used to take 3-4 hours to go critical went critical in 20 minutes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The on-call team therefore focused their attention on communicating with the on-site datacenter operations team to restore cooling while powering off as many servers as possible to protect them. Due to a server equipment shortage tied to the ongoing AI boom, lots of this equipment — if lost — would not be possible to replace on short timelines. Saving it had to be a priority, even at the cost of potentially extending the downtime.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By &lt;strong&gt;00:45 CEST&lt;/strong&gt;, we were able to restore cooling and temperatures at the facility began to drop, and the on-call team switched focus to service recovery. At this point, we made the decision to failover the primary databases to Frankfurt if a replica was still alive, and to Zurich in cases where there was no replica alive in Frankfurt, to avoid changing our traffic flows too much and possibly creating new instability. This option was selected because we assumed that, now that we had the cooling under control, it would be relatively easy to bring Frankfurt back online and faster than switching over to Zurich.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, this turned out not to be the case. During the incident, many network cards in the Frankfurt infrastructure reached a temperature of 105C (normal operating temperature is 45C), which triggers a special temperature protection mode and causes the network cards to be disabled until there is a cold system reset. Our security posture limits the ability to access the out-of-band controller for our systems, which required us to wake up additional staff to assist with the recovery.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;By &lt;strong&gt;01:30 CEST&lt;/strong&gt;, we were able to get most services back online for most users. However, some less critical systems, such as push notifications or payment processing, were not recovered until around 02:00 CEST.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As we reported during the initial incident report, no emails were lost, but email delivery in both directions was delayed during the incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While user-facing services were fully restored, that was not the end of the night for our engineers, in particular the database team. Our infrastructure was left in a highly abnormal state, with some primary databases in Zurich and others in Frankfurt, and several of them operating with reduced redundancy and/or reduced performance. Our team worked through the night to resolve the most pressing of these issues, and the work continued through the day on August 27 to restore full redundancy.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While we were able to save almost all of the infrastructure, some servers unfortunately suffered heat death, and we don&amp;#8217;t know yet if the heating incident will impact the lifespan of the surviving equipment.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Root cause and next steps&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A subsequent investigation on August 27 traced the root cause of the cooling failure to an air filter replacement on both of the redundant air compressors powering the cooling system. Unfortunately, the datacenter operator performed this operation in the middle of the night, without prior notice, and also failed to communicate the cooling failure when it happened, which dramatically cut down the time we had to respond. We are working closely with the operator to prevent a repeat of this incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, it is also a known limitation of our current database infrastructure that an outage of this type could lead to a longer than normal recovery process. The series of events that led to this incident are highly improbable — yet they happened.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The database resilience work required to address this failure mode is already underway and remains planned for completion by the end of the year. Additional infrastructure capacity, including new datacenter space, is also currently being commissioned and is expected to become available within the next few weeks, which will further reduce our single site dependency.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, this incident occurred before those improvements were fully in place. We are now reviewing where we can safely accelerate the remaining work while maintaining the level of care required for changes to critical database infrastructure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We recognize that our users expect a very high level of reliability from Proton, and this incident reinforces the importance of completing this work and continuing to raise our resilience standards. We apologize again, unreservedly, to every user who was impacted.&lt;/p&gt;
</content:encoded><category>Company news</category><category>Proton updates</category><author>Bart Butler</author></item><item><title>How to choose remote work tools that don&amp;#8217;t create security debt</title><link>https://proton.me/business/blog/remote-work-tools</link><guid isPermaLink="true">https://proton.me/business/blog/remote-work-tools</guid><description>The remote work tools you pick on day one become the infrastructure you&apos;re stuck with. Here&apos;s how to build a stack you won&apos;t need to rebuild.</description><pubDate>Fri, 28 Aug 2026 12:32:43 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Remote work tools may not feel like a major infrastructure decision when you&amp;#8217;ve just started scaling your business. They can feel like a relatively minor task compared to making payroll, shipping your MVP, or keeping your runway alive&amp;#8230; But that’s where the danger lies.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The remote work tools you pick on day one become infrastructure you&amp;#8217;re stuck with, and the gaps between those tools quietly accumulate into serious problems you won&amp;#8217;t notice until it&amp;#8217;s too late. That&amp;#8217;s security debt — and it&amp;#8217;s more common than you&amp;#8217;d think.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;One in four SMBs&lt;/u&gt;&lt;/a&gt; experienced a breach last year, despite actively investing in security tools. The problem wasn’t the password managers or VPN they chose: it was the gaps between them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security debt doesn&amp;#8217;t hit you immediately, but it does&amp;nbsp;compound in the background until the worst possible moment: When an enterprise customer asks for your audit trail and you don&amp;#8217;t have one. Or an investor asks where your data is stored and you tell them it falls under US jurisdiction. Or a security questionnaire asks you to list everyone who has had access to your core systems in the last 24 months, and you realize you never tracked this.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s how to build a secure stack of remote work tools that closes those gaps and is built to last.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;11 of the best remote work tools for your team&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every business has different needs, but there are certain categories of remote work tools that just about every business needs to fill. Here are the 11 tools we recommend for each.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;1. Slack (Best for team chat) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Launched in 2013, Slack has become the default choice for teams that want chat, voice, and video in one place. It replaced the endless email threads of old with channels organized by team, topic, or project, and its deep integration library (Google Calendar, Jira, and hundreds more) makes it a notification hub for your whole stack. One drawback to consider: on some plans, admins can access message history, a potential privacy concern for some businesses.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;To find out what else is out there, read our list of the best &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/blog/internal-communication-tools&quot;&gt;&lt;u&gt;&lt;strong&gt;internal communication tools.&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;2. Proton Mail (Best for business mail) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Email providers with economic models built around ad targeting can’t guarantee that your emails won’t be read by anybody else, whatever their privacy policy claims. &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;Proton Mail&lt;/a&gt; is end-to-end encrypted by default, and protected under stringent &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;Swiss privacy law&lt;/a&gt;, so only you and your recipient can read what&amp;#8217;s sent. (Please note: emails to non-Proton recipients aren’t end-to-end encrypted unless you password-protect them first.)&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;3. Loom (Best for async video)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’ve ever been in a meeting that could easily have been a two minute video, Loom could be the solution for you. It lets you create video notes, recording your screen, face, and voice together, to be shared as a link. Popular use cases include recording onboarding walkthroughs, bug reports, and async updates across time-zones. (Note that Loom recordings are stored on Loom&amp;#8217;s own servers rather than your team&amp;#8217;s infrastructure, worth knowing if you prefer to keep company data under your own control.)&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;4. Proton Meet (Best for video conferencing) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unlike Zoom, &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;Proton Meet&lt;/a&gt; is end-to-end encrypted by default, which means not even Proton can access what&amp;#8217;s said or shared on a call. Guests join with just a link, no account required, and the free plan covers one-hour calls with up to 50 participants. One caveat: Proton Meet works well for internal team calls, but if your workflow leans on integrating video directly into a CRM or support tool, you should check compatibility before switching. &lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;5. Jira (Best for project management) &lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Jira is built for software teams running agile workflows: think sprints, backlogs, and issue tracking that ties directly to your codebase through Bitbucket or GitHub integrations. As such, Jira is the default choice for many engineering teams already inside the Atlassian ecosystem. On the downside, it is more configuration-heavy than general-purpose tools like Asana, and outside of a dev team it can feel like overkill. &lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;6. Trello (Best for tracking tasks)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Simplicity is Trello’s strength, stripping task management down to cards moving across boards labeled &lt;strong&gt;&lt;strong&gt;to do&lt;/strong&gt;&lt;/strong&gt;, &lt;strong&gt;&lt;strong&gt;doing&lt;/strong&gt;&lt;/strong&gt;, and &lt;strong&gt;&lt;strong&gt;done&lt;/strong&gt;&lt;/strong&gt;. There’s almost no learning curve, making Trello a natural starting point for a small team. Once your team grows, however, that simplicity can become a limitation: you won’t find it so easy to perform cross-project reporting on it.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;7. Miro (Best for visual collaboration)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When gathering around a physical whiteboard is impossible, a Miro board gives teams a remote —  and much more flexible — option: an infinite digital canvas for planning, collaboration, and brainstorming. You can drag and drop files onto boards, set up repeat workshops with templates for retrospectives and planning sessions. While Miro is great for teams who can work in live, synchronous sessions, it&amp;#8217;s less useful for teams working async across time zones.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;8. Proton Drive (Best for cloud storage)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive&quot;&gt;Proton Drive&lt;/a&gt; is the privacy-first alternative to Dropbox and Google Drive. Though it has fewer direct integrations than those apps, Proton Drive does a better job of protecting your data, encrypting files on your device before they ever reach Proton&amp;#8217;s servers so that Proton can never decrypt them, even under a court order. Version history, access logs, and granular permissions come built in, and shared links expire by default rather than staying open indefinitely. &lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;9. Proton Pass (Best for password/credential management)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk of credentials leaking increases sharply outside of a controlled office environment. Unlike most password managers, &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;Proton Pass&lt;/a&gt; encrypts every field of every saved item by default: not just passwords, but usernames and notes too. It also includes email alias generation to keep your team’s real email addresses out of signup forms. (Note that advanced admin controls — SSO and SCIM directory sync — are reserved for the Pass Professional tier, not the base plan.)&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;10. Notion (Best for building a knowledge base)&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With Notion, you can organize and centralize your business’s internal knowledge and documentation in pages, databases, and wikis, building a single source of truth for your teams and eliminating doubt over which document versions are current. But be warned: Notion’s flexibility can become a risk, enabling the building of an unstructured wiki that sprawls unless someone keeps an eye on it.&lt;/p&gt;



&lt;h4 class=&quot;wp-block-heading&quot;&gt;11. Lumo&lt;/h4&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even small teams benefit from AI assistance that lets them draft, edit, summarize, and research faster without having to add to head count. &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;Lumo&lt;/a&gt; is Proton&amp;#8217;s AI assistant, built to offer all the power of AI without compromising your IP and sensitive data. Gemini and Copilot need access to your document data to function, but Lumo never trains on your inputs. (Lumo is available on Premium Proton plans only.)&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why even the best remote work tools can put you in security debt without you knowing it&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even genuinely good remote collaboration tools add up to a shaky stack when each one operates under its own security model. A stack with no unified access control, no audit trail, no &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty&quot;&gt;data sovereignty&lt;/a&gt;, and security debt accumulating from day one.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security debt comes in four types:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Access debt:&lt;/strong&gt; Your stack forces you to manually provide and revoke access across five or six different platforms. It’s on you to remember (and memory is far from 100% reliable). Result: the contractor who left you six months ago &lt;a href=&quot;https://proton.me/business/blog/spreadsheet-security-business-survey&quot;&gt;can still open your files&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Audit trail debt&lt;/strong&gt;: The access that you’re controlling isn’t recorded anywhere. You know someone accessed that folder, but you can’t prove it. And when a future investor, customer, or regulator asks you who had access to what, when, you haven’t got a good answer.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Jurisdiction debt:&lt;/strong&gt; Your files are sitting on servers that fall under &lt;a href=&quot;https://proton.me/blog/us-tech-rules-europe&quot;&gt;&lt;u&gt;the CLOUD Act&lt;/u&gt;&lt;/a&gt;. You didn’t mean for that to happen: you just chose Dropbox.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Human error debt:&lt;/strong&gt; Fragmentation means more manual steps, which means more human error, which means…? Let’s just say that &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;39% of breaches&lt;/u&gt;&lt;/a&gt; last year were caused by human error.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of this is inevitable. Every risk we&amp;#8217;ve listed is easier to cleanly avoid if you choose a more unified stack of remote collaboration tools from Day One.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What a secure remote work stack actually looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;Most SMBs (66%)&lt;/a&gt; say demonstrating &lt;a href=&quot;https://proton.me/business/drive/cloud-data-security&quot;&gt;cloud data security&lt;/a&gt; (especially as far as client data is concerned) is very or critically important when winning new business. A unified platform gives you that — by closing the gaps where security debt accumulates:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Unified access control:&lt;/strong&gt; One admin layer. Instead of having to work through a six-platform checklist, you need to be able to perform one action to add and remove a team member from your infrastructure.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Encryption by default:&lt;/strong&gt; Your data is encrypted in transit &lt;em&gt;and&lt;/em&gt; at rest. End-to-end encryption means your provider can&amp;#8217;t read your files and can&amp;#8217;t be compelled to hand them over.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Data sovereignty:&lt;/strong&gt; Your data is governed by laws you understand, in a jurisdiction you trust. (Not one that falls under the CLOUD Act.)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Automatic audit trails:&lt;/strong&gt; So you never need to tell an investor (much less a regulator) that you don’t have one.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Built to scale securely: &lt;/strong&gt;Your permissions, access tiers, and admin controls work whether your company is ten people or 100. No need to rebuild, no need to slow down.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/cybersecurity-for-startups&quot;&gt;Cybersecurity for startups&lt;/a&gt; starts earlier than you think — the earlier you build it in, the less you&amp;#8217;ll have to bolt on (or clean up) later.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Your remote work toolkit, built on Proton Workspace&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We&amp;#8217;ve already introduced you to Proton Mail, Meet, Drive, Pass, and Lumo in this article. But selecting the best tool for each job doesn&amp;#8217;t automatically close the gaps between those tools. To do that, you need a unified stack like &lt;a href=&quot;https://proton.me/business&quot;&gt;Proton Workspace&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With Workspace, the security-critical layer of your stack is in safe hands: yours. Your data is under your control, encrypted from end to end (not even Proton can see it) and protected under one of the world’s &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;strongest privacy jurisdictions&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Compliance isn’t a concern: Proton is&lt;strong&gt; &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/trust&quot;&gt;&lt;u&gt;ISO 27001 certified, GDPR and HIPAA compliant&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You’ll need to add tools on top for management and team messaging. But you&amp;#8217;ll do so on a foundation that&amp;#8217;s already secure.&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Access debt&lt;/strong&gt;:&lt;strong&gt; resolved.&lt;/strong&gt; One admin dashboard. One action to provision a new team member across every Proton service, one to remove them when they leave&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Audit trail debt: resolved.&lt;/strong&gt; Version history, access logs, and granular permissions are built into &lt;a href=&quot;https://proton.me/drive&quot;&gt;&lt;u&gt;Proton Drive&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/drive/docs&quot;&gt;&lt;u&gt;Proton Docs&lt;/u&gt;&lt;/a&gt; by default&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Jurisdiction debt: resolved. &lt;/strong&gt;Headquartered in Switzerland, outside US and EU jurisdiction&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Human error debt: resolved. &lt;/strong&gt;Expiration dates are set on links by default. Files are automatically encrypted in storage. Security is enforced automatically, not manually&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The tools you pick on day one create the security debt you&amp;#8217;ll pay off later. Build on the right foundation, and you can stop worrying about security debt — and start using your security posture as a selling point.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/&quot;&gt;Try Proton Workspace&lt;/a&gt;
&lt;/div&gt;

</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>Team collaboration software: 7 tools that won’t waste your money</title><link>https://proton.me/business/blog/team-collaboration-software</link><guid isPermaLink="true">https://proton.me/business/blog/team-collaboration-software</guid><description>Your team collaboration software stack isn&apos;t free — it&apos;s just expensive in ways you haven&apos;t counted yet. Here&apos;s how to fix that.</description><pubDate>Thu, 27 Aug 2026 18:35:04 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most businesses build their team collaboration software stack the same way: one tool at a time, filling needs as they come up. When you’re just starting out, this seems like a reasonable approach.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But there’s a catch. Approaching the challenge of enabling team collaboration this way is how you end up with a Frankenstein’s monster of a stack, made entirely of parts that are stitched together inorganically.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Even if the parts are good, the disconnection between them causes problems. You’re paying more subscription fees than you can track. You’re not sure who has access to what. And you’re drowning in admin work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is a guide to taking the alternative route: building a team collaboration stack that has the essential tools in one place and is as consolidated as possible to save you money and time.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;7 team collaboration tools your stack needs&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every team collaboration stack needs to cover the same ground: chat, email, video, documents, storage, and project management. It’s also worth adding visual collaboration and a knowledge base to that list.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are the seven tools you need to cover everything you need while protecting the confidentiality of your data.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. For team chat: Slack&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Slack is the go-to choice for team chat. It turns conversations into organized, searchable channels — set up by project, team, or topic — instead of long, scattered email threads. Voice and video huddles let anyone start a quick call without leaving the app, and file sharing keeps context attached to the conversation. Providing all the structure a small team needs, Slack scales with your headcount, fitting seamlessly into your growing stack via an integration library connecting hundreds of other tools.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. For business email and calendar: Proton Mail &lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Mail gives you all the same essential &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; functionality as &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt; or &lt;a href=&quot;https://proton.me/business/mail/outlook-alternative&quot;&gt;Outlook&lt;/a&gt;, with the added bonus of &lt;a href=&quot;https://proton.me/security/end-to-end-encryption&quot;&gt;end-to-end encryption&lt;/a&gt;. Google and Microsoft process messaging content to power search and AI features; Proton Mail’s encrypted architecture ensures your business communications are for your eyes only. &lt;a href=&quot;https://proton.me/business/calendar&quot;&gt;Proton Calendar&lt;/a&gt; is bundled in, so your event details — including meeting titles and guest lists — also stay private, and scheduling doesn&amp;#8217;t require a separate app or another login.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. For project and task management: Trello&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Trello simplifies task tracking to its bare essentials without sacrificing utility: managing boards and task cards that move from to do to done, with almost no learning curve for new team members. When we talk about consolidated platforms later, bear in mind that this is a tool most platforms don&amp;#8217;t replace — so it&amp;#8217;s worth budgeting for as its own line item in your stack.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. For video conferencing: Proton Meet &lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Zoom might be the go-to for &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;video conferencing&lt;/a&gt; for many businesses, but it&amp;#8217;s far from the most private option. Its AI Companion feature processes call content — including anything commercially sensitive — to generate summaries and transcripts. Proton Meet&amp;#8217;s default end-to-end encryption ensures that what&amp;#8217;s said on a call stays between the people on that call. Guests join with a link and no account, and the free tier covers one-hour calls with up to 50 participants.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;5. For visual collaboration: Miro&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Miro is essentially a digital whiteboard, but its infinite canvas gives distributed teams a shared space for planning, brainstorming, and workshops that no whiteboard — or even chat thread or document — can replicate. Miro packs in enough features that mastering all of it takes time, but getting started takes just minutes: templates for retrospectives and roadmapping sessions mean new teams aren’t starting from a blank canvas.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;6. For cloud storage and document collaboration: Proton Drive &lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive offers &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; that matches &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt; and &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt; on granular per-file permissions and version history. Where it pulls ahead is what happens if a breach occurs. Google and Dropbox need access to your file content to index it for search and power AI features; that means they hold the keys to your contracts, financial records, and product roadmaps, and a breach on their end could expose that content directly. Proton Drive is end-to-end encrypted by default with zero-access architecture: Proton can&amp;#8217;t decrypt your files, so neither can anyone who breaches its servers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive also covers document collaboration, since &lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;&lt;u&gt;Proton Docs&lt;/u&gt;&lt;/a&gt; and&lt;a href=&quot;https://proton.me/business/drive/sheets&quot;&gt; &lt;u&gt;Proton Sheets&lt;/u&gt;&lt;/a&gt; are included with every Proton Drive plan. Docs and Sheets cover the same core functionality as Google and Microsoft’s document tools (real-time co-editing, comments, and version history), while adding end-to-end encryption, ensuring your contracts, drafts, and financial models get the same protection as everything else in your stack.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;7. For a knowledge base: Notion&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many businesses — particularly those scaling fast — struggle with the chaos that comes with disorganized &lt;a href=&quot;https://proton.me/business/blog/internal-documentation&quot;&gt;internal documentation&lt;/a&gt;. Notion centralizes internal documentation, wikis, and reference material in one searchable space, cutting down on the scattered, outdated copies competing for attention. Plus, it&amp;#8217;s flexible enough to double as light project tracking if your team doesn&amp;#8217;t need a dedicated tool like Trello.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But if your team stores confidential client files, strategy documents, product plans, or company IP in the cloud, we recommend using a more secure &lt;a href=&quot;https://proton.me/drive/notion-alternative&quot;&gt;Notion alternative&lt;/a&gt; such as Proton Drive.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The hidden cost of a disconnected collaboration stack&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Let’s say you’re starting from scratch and decide to go with the seven tools we recommend. Here’s how your collaboration stack will look (notice that there are’s only seven rows, as Drive includes both Docs and Sheets) — and it looks pretty solid.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;&lt;br&gt;Platform&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Best for&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Pricing&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Key feature&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Slack&lt;/td&gt;&lt;td&gt;Team chat&lt;/td&gt;&lt;td&gt;Free; Pro from $7.25/user/month (annual)&lt;/td&gt;&lt;td&gt;Channels, huddles, deep integration library&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Mail&lt;/td&gt;&lt;td&gt;Business email&lt;/td&gt;&lt;td&gt;Mail Essentials (includes &lt;a href=&quot;https://proton.me/business/calendar&quot;&gt;&lt;u&gt;Proton Calendar&lt;/u&gt;&lt;/a&gt;) $6.99/user/month(annual)&amp;nbsp;&lt;/td&gt;&lt;td&gt;Shared domain, encrypted calendar and contacts built in&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Meet&lt;/td&gt;&lt;td&gt;Video conferencing&lt;/td&gt;&lt;td&gt;Meet Professional&lt;br&gt;$7.99/user/month(annual)&lt;/td&gt;&lt;td&gt;Link-based guest access, no download required&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Drive&amp;nbsp;&lt;/td&gt;&lt;td&gt;Cloud storage &amp;amp; document collaboration&lt;/td&gt;&lt;td&gt;Drive Professional (also includes &lt;a href=&quot;https://proton.me/business/drive/sheets&quot;&gt;&lt;u&gt;Proton Sheets&lt;/u&gt;&lt;/a&gt;)&lt;br&gt;$7.99/user per month&lt;br&gt;(annual)&lt;/td&gt;&lt;td&gt;Granular per-file permissions, realtime co-editing, version history&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Trello&lt;/td&gt;&lt;td&gt;Project &amp;amp; task management&lt;/td&gt;&lt;td&gt;Free; Standard from $5/user/mo (annual)&lt;/td&gt;&lt;td&gt;Boards, cards, automation rules&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Miro&lt;/td&gt;&lt;td&gt;Visual collaboration&lt;/td&gt;&lt;td&gt;Free; Starter from $8/user/mo (annual)&lt;/td&gt;&lt;td&gt;Infinite canvas, templates for recurring sessions&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Notion&lt;/td&gt;&lt;td&gt;Knowledge base&lt;/td&gt;&lt;td&gt;Free; Plus from $10/user/mo (annual)&lt;/td&gt;&lt;td&gt;Pages, databases, wikis&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, if these tools are all running individually, not consolidated under one platform, you’re opening yourself up to three big problems.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. The hidden subscription bill&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Individually, the tools in our seven-tool stack don’t seem to cost that much. Add those subscriptions up, however, and (at the time of writing) a team of 25 is running up a bill of approximately $15,900 a year. And your team probably isn’t even using every seat.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s easy to lose track of what you’re spending on a set of disconnected team collaboration tools. You know they’re automatically renewing, but you’re reluctant to cancel the one you suspect nobody’s using because that means finding the login details. Or you’re worried that someone on your team must need it. (Why else would you have it?)&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. The cost of insecurity&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disconnected tools multiply your attack surface, with each surface a potential misconfiguration waiting to happen. In the long run, that could cost you dearly. Proton research shows that 25% of SMBs experienced a data breach last year, and 57% of &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;breached SMBs&lt;/a&gt; lost between $10,000–$100,000.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. The burden of admin&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Time is money, and multiple tools demand that you spend a lot of both. Think of all that time spent adding and revoking permissions across seven tools (assuming you remember to), or reconciling seven separate invoices, or trying to figure out if anybody’s actually using that Miro seat you’ve been paying for since March. All these costs might not show up on one invoice. But they’re there.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What a consolidated collaboration stack gives you&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The answer to reducing the cost and waste of a disconnected stack isn’t better tools, and it certainly isn’t &lt;em&gt;more&lt;/em&gt; tools. The answer is a team collaboration platform that covers as many of the functions your disconnected tools are currently fulfilling as possible, while also giving you a secure and easily administered foundation for whatever other tools you need.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pick your platform wisely, and replacing multiple tools with one platform will simplify and secure your team collaboration in a single stroke. When you have one platform handling team communication, file storage, document collaboration, and admin, you’re only dealing with:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;One bill,&lt;/strong&gt; &lt;strong&gt;one renewal date, with one owner. &lt;/strong&gt;Zero autopilot charges for unused tools&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;One admin dashboard &lt;/strong&gt;to control &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt;, and access permissions. (No contractors hanging around in your Dropbox months after project completion)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;One security model, &lt;/strong&gt;with one permissions system to administer, no gaps between tools, and no seven-tool misconfiguration risk&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;One audit trail &lt;/strong&gt;so you can see who accessed what, when, all in one place (and provide proof when investors or regulators come calling)&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A consolidated, encrypted stack won’t just save you in subscriptions and security incidents. It sends a signal to your customers that you’re serious about handling their data seriously. It lets investors know that your operations are under control.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The platform to consolidate your stack: Proton Workspace&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With our digital &lt;a href=&quot;https://proton.me/business&quot;&gt;workspace platform&lt;/a&gt; for businesses Proton Workspace, you get all the Proton products and features we’ve mentioned on one platform: Mail (including Calendar), Meet, and Drive (including Docs and Sheets).&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of running those products as separate subscriptions, each with its own admin panel and its own bill, you get all of them under one account and one security model.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;The subscription saving: &lt;/strong&gt;purchasing Mail, Meet, and Drive as separate subscriptions costs more than getting them together, since each one carries its own base fee on top of your per-seat pricing. Proton Workspace consolidates all of them into a single line item instead. Proton Workspace doesn&amp;#8217;t replace Slack, Trello, or Miro (you&amp;#8217;ll still need separate tools for chat, project management, and visual collaboration) but on the tools it &lt;strong&gt;does&lt;/strong&gt; replace, the saving is real.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The admin relief: &lt;/strong&gt;Instead of three dashboards, you have one. Instead of three invoices on three different renewal dates, one. You can see exactly who&amp;#8217;s using what, so no more paying for seats nobody&amp;#8217;s touched since March. And when someone joins or leaves, &lt;a href=&quot;https://proton.me/business/drive/templates/onboarding-checklist&quot;&gt;onboarding&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt; means one action for each user, not three. (And no more contractors retaining access to folders that are no longer their business.)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;The security foundation: &lt;/strong&gt;You’ve established a secure foundation for collaboration. Proton Workspace is ISO 27001 certified, and GDPR and HIPAA compliant. All its services keep your data protected with &lt;a href=&quot;https://proton.me/security/end-to-end-encryption&quot;&gt;&lt;u&gt;end-to-end encryption&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;Swiss jurisdiction&lt;/u&gt;&lt;/a&gt;. Not even Proton can access your files.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;On top of this, you get extra products bundled in: Workspace Standard subscribers get a &lt;a href=&quot;https://proton.me/business/vpn&quot;&gt;&lt;u&gt;business VPN&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;&lt;u&gt;team password manager&lt;/u&gt;&lt;/a&gt; bundled in; Premium subscribers get these, plus Lumo, our &lt;a href=&quot;https://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Migrating your email and calendar to Proton is straightforward: Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/easyswitch&quot;&gt;&lt;u&gt;Easy Switch&lt;/u&gt;&lt;/a&gt; tool imports your existing emails, contacts, and calendars automatically (including from &lt;a href=&quot;https://proton.me/mail/best-gmail-alternative&quot;&gt;Gmail&lt;/a&gt;).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Few SMBs get their collaboration stack right the first time around. The right &lt;a href=&quot;https://proton.me/business&quot;&gt;team collaboration platform&lt;/a&gt; is the one your team uses, your admin controls, and your finance team can see on one invoice.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;
  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/&quot;&gt;Try Proton Workspace&lt;/a&gt;
&lt;/div&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>AI is making phishing attacks more sophisticated: What can businesses do about it?</title><link>https://proton.me/business/blog/ai-phishing-attacks</link><guid isPermaLink="true">https://proton.me/business/blog/ai-phishing-attacks</guid><description>Learn how AI phishing attacks are changing business risk, from AI-generated emails to deepfake phishing, and how to protect your team.</description><pubDate>Thu, 27 Aug 2026 17:46:23 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI &lt;a href=&quot;https://proton.me/business/blog/phishing-attacks&quot;&gt;phishing attacks&lt;/a&gt; are changing one of the oldest rules in security awareness: bad grammar is no longer a reliable red flag.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For years, employees were taught to look for awkward wording, strange formatting, spelling errors, and generic greetings. These clues are still important, but they can’t detect AI-powered phishing attacks.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Generative AI can help attackers write personalized messages in seconds. It can imitate a company’s tone, summarize public information about an employee, turn a short prompt into a convincing invoice request, or localize a scam to sound native in any target language.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, this isn’t a completely new threat. It’s leveled up &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; with better writing, faster preparation, and more convincing impersonation. Phishing still aims to make someone click, share credentials, approve a payment, open a file, or move a conversation to a channel the attacker controls. AI simply makes that manipulation more convincing and easier to scale.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Within businesses, teams need to build new habits. We’ll explain what to look for and how to build better phishing and &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protections&lt;/a&gt; within your business network.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#how-are&quot;&gt;How are AI phishing attacks different?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#look-like-real&quot;&gt;AI-generated phishing emails look like real work&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#new-forms&quot;&gt;New forms of AI social engineering&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#why-SMBS&quot;&gt;Why SMBs are increasingly exposed&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#how-to-adapt&quot;&gt;How to adapt your phishing training to AI-enabled attacks&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-businesses&quot;&gt;What businesses need to do differently&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#how-proton-pass&quot;&gt;How Proton Pass for Business helps reduce credential risk&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;how-are&quot; class=&quot;wp-block-heading&quot;&gt;How are AI phishing attacks different?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before generative AI, phishing required more manual effort. Attackers had to research a target, write believable copy, adjust the tone, and sometimes translate messages for different markets. Generative AI lowers these barriers to entry significantly.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK National Cyber Security Centre’s report on the &lt;a href=&quot;https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;impact of AI on cyber threats&lt;/a&gt; from now to 2027 notes that AI will almost certainly make parts of cyber intrusion more effective and efficient, increasing the frequency and intensity of cyber threats. It also notes that threat actors are already using AI to improve existing tactics, including &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Attackers can now produce phishing attack messages that look more natural and more specific. A scam email can refer to a real supplier, a recent LinkedIn post, a job title, a regional event, or an internal project name. Even when the attacker has limited information, AI can fill the gaps with language that sounds plausible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The warning signs of a phishing attack remain the same. Suspicious links, urgent requests, unexpected attachments, and strange sender domains still matter. But the content itself is no longer enough to give the attack away.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Traditional phishing attacks&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;AI-powered phishing attacks&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Often have typos, awkward grammar, or generic greetings&lt;/td&gt;&lt;td&gt;Can use polished, natural writing with the right tone&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Usually rely on broad, generic messages&lt;/td&gt;&lt;td&gt;Can include personal details, company context, or vendor references&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Mostly appear as suspicious emails&lt;/td&gt;&lt;td&gt;Can combine email, voice cloning, fake invoices, and deepfake video&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;look-like-real&quot; class=&quot;wp-block-heading&quot;&gt;AI-generated phishing emails look like real work&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Phishing attacks have always ranged from crude to highly sophisticated, but generative AI lowers the skill and time needed to produce messages that are fluent, well-structured, and written in professional-sounding language.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The NCSC’s&lt;a href=&quot;https://www.ncsc.gov.uk/guidance/phishing&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; phishing guidance&lt;/a&gt; notes that phishing campaigns may try to steal sensitive information like passwords, or trick people into transferring money. It also explains that more targeted campaigns use information about employees or the company to make messages feel more realistic. AI makes that easier to do at scale.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Defense against modern phishing attacks requires layered controls rather than a single filter: &lt;a href=&quot;https://proton.me/business/blog/multi-factor-authentication-business&quot;&gt;multi-factor authentication&lt;/a&gt; (MFA) to make stolen credentials less of a threat, verified communication processes for critical requests, and employee training to recognize social engineering before credentials are surrendered.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Secure &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt; is also a key aspect of your defenses. A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business makes it easy to generate a strong, unique password for every account. You can also monitor for exposure within your business network, so even if a team member is convinced by a single message, their credentials can’t unlock more than one account.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For employees, phishing awareness needs to evolve in order to detect these new AI-powered threats. It requires asking yourself three questions:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Does this email look fake?&lt;/li&gt;



&lt;li&gt;Does this request make sense?&lt;/li&gt;



&lt;li&gt;Have I verified it or can I verify it through a trusted channel?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Going beyond the spelling and formatting of the email and looking at the wider context in which it was sent can go a long way. A polished email can still be a phishing attempt if it asks for credentials, changes payment details, creates unusual urgency, or pushes someone outside the normal process.&lt;/p&gt;



&lt;h2 id=&quot;new-forms&quot; class=&quot;wp-block-heading&quot;&gt;New forms of AI social engineering&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI phishing isn’t limited to email. Attackers can now use AI to combine text, voice, images, and video into a single convincing story.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;AI-generated spear phishing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/whaling-spear-phishing&quot;&gt;Spear phishing&lt;/a&gt; works because the message is targeted to the person receiving it. AI makes targeting even easier: An attacker no longer needs to spend as much time writing from scratch or adapting the tone for each target. They can use public information, &lt;a href=&quot;https://proton.me/blog/journalist-data-leaks&quot;&gt;leaked data&lt;/a&gt;, or a compromised inbox to create a message that appears legitimate.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That could be a contract update that arrives at the right moment, a candidate file sent to HR, a vendor request that uses familiar language, or a payment instruction that matches the rhythm of normal finance work. The danger is not perfection, but plausibility. A spear phishing message only needs to feel relevant enough for someone to open the file, approve the request, or enter their credentials before they stop to verify.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Voice cloning and vishing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/vishing-attacks-business&quot;&gt;Vishing&lt;/a&gt;, or voice phishing, is becoming more convincing as AI-generated audio improves. The &lt;a href=&quot;https://www.ic3.gov/PSA/2025/PSA250515&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;FBI’s Internet Crime Complaint Center warned in 2025&lt;/a&gt; about malicious actors using text messages and AI-generated voice messages to impersonate senior US officials. The alert explains that vishing may incorporate AI-generated voices and recommends verifying callers through independently identified contact details.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s&lt;a href=&quot;https://proton.me/business/blog/data-breach-observatory-2026&quot;&gt; Data Breach Observatory 2026&lt;/a&gt; also highlights the rise of vishing campaigns, including coordinated attacks that led to large-scale breaches and exposed tens of millions of records. The same report found that passwords appeared in 47% of tracked incidents, showing why &lt;a href=&quot;https://proton.me/blog/what-is-social-engineering&quot;&gt;social engineering&lt;/a&gt; and credential protection are closely connected.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Deepfake phishing in video calls&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Deepfake phishing can also happen through video. In 2024, a finance worker in Hong Kong was&lt;a href=&quot;https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; reportedly tricked into transferring about $25 million&lt;/a&gt; after fraudsters used deepfake video to impersonate senior colleagues during a video meeting.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Seeing a familiar face on a call is no longer enough to approve a sensitive request. Large payments, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;credential sharing&lt;/a&gt;, access changes, and unusual requests still need a separate verification step through a trusted channel.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;AI-generated fake invoices&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Invoice fraud is much easier with AI. A fake invoice can use polished language, realistic payment terms, a familiar supplier name, and a plausible explanation for a bank detail change. If the attacker has access to a breached inbox or leaked vendor information, the request may look even more believable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A polished invoice should not be enough to move money. If the bank details have been changed, the timing feels unusual, or the message asks someone to skip the normal approval flow, the request needs to be checked through a trusted channel before anyone pays it.&lt;/p&gt;



&lt;h2 id=&quot;why-SMBS&quot; class=&quot;wp-block-heading&quot;&gt;Why SMBs are increasingly exposed&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI has changed the economics of phishing by lowering the cost of targeting. In the past, highly personalized attacks were more likely to focus on large companies because they took more time to prepare. AI makes it easier to create targeted messages for smaller businesses. Attackers can generate more variants, test more angles, and adapt messages quickly without spending the same amount of time or effort.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Smaller businesses are attractive because money, access, and decision-making are often concentrated between fewer people. One person may approve invoices, manage vendor relationships, and hold access to several business tools. When processes are informal, one convincing AI-generated request can reach payment workflows, shared accounts, customer data, or admin systems before anyone has a chance to challenge it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The risk is visible in breach data too. The same Proton &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt; report found that SMBs accounted for 63% of breaches tracked since January 2025 and were disproportionately affected by critical incidents involving sensitive data such as authentication data, personal identifiers, or financial details.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI helps attackers exploit weaknesses small businesses already have: reused passwords, informal credential sharing, weak approval processes, and training that still assumes scams will look obvious.&lt;/p&gt;



&lt;h2 id=&quot;how-to-adapt&quot; class=&quot;wp-block-heading&quot;&gt;How to adapt your phishing training to AI-enabled attacks&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To properly combat AI phishing attacks, your &lt;a href=&quot;https://proton.me/business/blog/security-awareness-training&quot;&gt;security awareness&lt;/a&gt; requires more consideration than checking for typos. Employees need to learn how to verify the request, not just judge the message.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The baseline your training needs is simple: If a request is unusual, sensitive, or urgent, verify it before acting:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Stop before replying, don’t respond on the same email thread.&lt;/li&gt;



&lt;li&gt;Ignore the contact details in the message, never use the phone number, link, or reply address it provides.&lt;/li&gt;



&lt;li&gt;Don’t treat a voice or video call as proof, because a familiar voice on a call or a familiar face on screen can both be generated.&lt;/li&gt;



&lt;li&gt;Reach the person through a channel you already trust, an internal directory, a saved vendor record, or a previously verified contact method.&lt;/li&gt;



&lt;li&gt;Confirm the request itself, not just the sender, ask whether the payment, access change, or file request is real.&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Training should also focus on helping team members spot the moments where AI phishing is most likely to succeed:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Payment detail changes&lt;/li&gt;



&lt;li&gt;Requests for passwords, recovery codes, or MFA approvals&lt;/li&gt;



&lt;li&gt;Urgent file-sharing requests&lt;/li&gt;



&lt;li&gt;Unusual login prompts&lt;/li&gt;



&lt;li&gt;Vendor portal changes&lt;/li&gt;



&lt;li&gt;Executive requests that bypass normal processes&lt;/li&gt;



&lt;li&gt;Invitations to move a conversation to a personal messaging app&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s guide to building a &lt;a href=&quot;https://proton.me/blog/small-business-cyber-security-culture-workplace&quot;&gt;small business cybersecurity culture&lt;/a&gt; in the workplace is a useful and timely resource for making security behavior part of daily work.&lt;/p&gt;



&lt;h2 id=&quot;what-businesses&quot; class=&quot;wp-block-heading&quot;&gt;What businesses need to do differently&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI-powered phishing changes the standard for verification. If the message looks real, the process has to catch what’s no longer immediately obvious.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Use out-of-band verification&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When a request involves money, credentials, sensitive files, or privileged access, the reply should not stay inside the same thread that created the risk. The team needs a second path to confirm whether the request is real.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That might mean calling a supplier using a number already saved in the vendor record, checking an executive request through an internal channel, or confirming access changes with the project owner. The key is to use contact details the business already trusts, not the phone number, link, or reply path provided in the suspicious message.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Require multi-person approval&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;High-risk actions should not depend on one person’s judgment. Payment changes, large transfers, new vendor bank details, privileged access grants, and bulk data exports should require a second approval to reduce &lt;a href=&quot;https://proton.me/business/blog/vulnerability&quot;&gt;vulnerability&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One urgent-looking message doesn’t need to derail normal work. A second approval gives the team a pause point before money is transferred, access is granted, or sensitive data leaves the business.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Protect credentials before they are targeted&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;AI phishing often ends at the same place as traditional phishing: credentials. The attacker wants a password, a session token, an MFA approval, or access to an account that opens the door to other systems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IBM’s&lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; Cost of a Data Breach Report 2025&lt;/a&gt; recommends strengthening identity security and adopting phishing-resistant authentication methods to reduce the risk of credential abuse. It also reports a global average breach cost of $4.4 million, showing why identity and access controls have financial consequences, not just technical ones.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Containment is key for SMBs. AI may make the first message harder to detect, but the business can still control what happens after a mistake. Strong, unique passwords, MFA, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, limited admin access, and consistent &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt; reduce the chance that one compromised account turns into access across email, finance tools, &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;enterprise cloud storage&lt;/a&gt;, or other business systems.&lt;/p&gt;



&lt;h2 id=&quot;how-proton-pass&quot; class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business helps reduce credential risk&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your organization&amp;#8217;s &lt;a href=&quot;http://proton.me/business/pass/password-policy&quot;&gt;password policy&lt;/a&gt; should bring credential habits under control before an employee is targeted. Limit password reuse across business accounts, use encrypted &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vaults&lt;/a&gt;, keep sensitive access out of browsers, spreadsheets, and chat threads, and provide secure sharing options. Those measures give teams a controlled way to grant or remove access without searching through old messages or documents.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business limits how much damage a phishing attack can do. When credentials are unique, encrypted, and centrally managed, a single successful message compromises one account instead of opening a path across email, finance tools, and cloud storage. It works alongside awareness training, email filtering, and payment controls rather than replacing them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business also helps teams &lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;generate strong passwords&lt;/a&gt;, use autofill, and manage credentials through centralized admin controls. Unique passwords, strong authentication, secure credential sharing, and controlled access make it harder for one successful phishing attempt to spread across the business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Protect your team from AI-powered phishing with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>Data exfiltration: how attackers steal business data and how to stop them</title><link>https://proton.me/business/blog/data-exfiltration-prevention</link><guid isPermaLink="true">https://proton.me/business/blog/data-exfiltration-prevention</guid><description>Getting in is only half the attack. Learn how data exfiltration works, why it goes undetected for months, and how to catch it early.</description><pubDate>Thu, 27 Aug 2026 16:36:47 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most breach prevention advice, including our own guide to &lt;a href=&quot;https://proton.me/blog/data-breach-prevention-for-businesses&quot;&gt;preventing data breaches&lt;/a&gt;, is focused on keeping attackers out of your business network. Using stronger credentials, &lt;a href=&quot;https://proton.me/blog/what-is-phishing&quot;&gt;phishing&lt;/a&gt; resistance, patched systems, vetted suppliers are all key components of this practice. They’re all essential practices, but they can’t be your only &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; tactics: they won’t support you if an attacker manages to breach your network.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Gaining access and data theft are different. An attacker who compromises one inbox, one laptop, or one supplier connection has not yet stolen anything. They&amp;#8217;ve gained a foothold, and what happens between that foothold and the moment data leaves the building is a phase most SMB security guidance skips entirely, because it isn&amp;#8217;t just about securing your network; it&amp;#8217;s also about noticing that data is being moved outside of it.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This phase is called exfiltration, and it typically lasts for days or even stretches across months undetected. It’s possible because of tools and channels that look completely ordinary to anyone not specifically watching for them. Breach notifications frequently arrive late not because organizations were careless about the initial compromise, but because the attacker wasn’t detected inside the business network.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#access-theft&quot;&gt;The exfiltration phase: what happens between access and theft&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-exfiltration-looks&quot;&gt;What data exfiltration looks like&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#difficult&quot;&gt;Why is exfiltration difficult to spot?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#monitor&quot;&gt;What businesses should monitor for&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#early-detection&quot;&gt;How early detection can change your legal position&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#exfiltrated-data&quot;&gt;What happens to exfiltrated business data?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#contain&quot;&gt;Contain what an attacker can reach&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;access-theft&quot; class=&quot;wp-block-heading&quot;&gt;The exfiltration phase: what happens between access and theft&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once an attacker gains initial access, whether through a phishing email, a stolen credential, or a compromised supplier connection, they rarely move straight to stealing data. Acting immediately risks triggering an alert before they&amp;#8217;ve found anything worth taking, so the more common pattern is patience.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The attacker spends time mapping the environment, including:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Where financial records are stored&lt;/li&gt;



&lt;li&gt;Assessing which SaaS tools contain customer data&lt;/li&gt;



&lt;li&gt;Locating accounts with the broadest access&lt;/li&gt;



&lt;li&gt;Detecting whether activity monitoring, if any, is in place.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This reconnaissance stage can be slow. Some attackers move within hours, particularly in opportunistic &lt;a href=&quot;https://proton.me/blog/ransomware-attack&quot;&gt;ransomware cases&lt;/a&gt; where speed matters more than stealth. Others, especially in cases built around long-term data theft or espionage, stay embedded for weeks or months, learning normal patterns of activity well enough to blend into them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Either way, by the time the attacker starts moving data out, they usually already know exactly what they want and which account or system will let them take it without tripping an alarm.&lt;/p&gt;



&lt;h2 id=&quot;what-exfiltration-looks&quot; class=&quot;wp-block-heading&quot;&gt;What data exfiltration looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Malicious exfiltration is difficult to spot because it looks like everyday activity. IT admins aren’t looking for slightly larger file transfers than usual or folders synced somewhere they shouldn&amp;#8217;t be.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Large or unusual data transfers&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the most direct form of exfiltration. For example, an account may suddenly pull gigabytes from a file server or database it normally touches only occasionally, or bulk export from a CRM or HR platform.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In SaaS-heavy environments, exfiltration often happens through the platform&amp;#8217;s own export features: bulk CSV downloads, PDF exports of customer records, or a sequence of screenshots taken of a dashboard that doesn&amp;#8217;t have an export button at all.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A typical case might look like this: a compromised HR account is used, over several weeks, to run small, staggered exports of employee records rather than one obvious bulk download. Each individual export looks unremarkable on its own, well within what an HR platform expects someone in that role to do.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It&amp;#8217;s only the pattern across weeks, the same account exporting similar data at odd intervals, that would reveal what&amp;#8217;s happening, and that pattern only becomes visible to a business that&amp;#8217;s looking for it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Inbox compromise&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An attacker who compromises a &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business email&lt;/a&gt; mailbox can set up a rule that silently copies every message, or every message matching certain keywords, to an external address, giving them an ongoing feed of sensitive correspondence long after the original phishing email is forgotten.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Cloud storage compromise&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Personal cloud storage is another common route. An employee&amp;#8217;s compromised laptop, or a compromised account with access to company files, can be used to copy documents into a personal &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, or similar service, a transfer that often looks identical to a legitimate file backup unless someone is checking where the data ended up.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;difficult&quot; class=&quot;wp-block-heading&quot;&gt;Why is exfiltration difficult to spot?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The uncomfortable truth about exfiltration is that it usually doesn&amp;#8217;t require any &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt; at all. An attacker using a compromised account to export a report, forward some emails, or upload files to a cloud drive is using the same tools and permissions a legitimate employee uses every day.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;There&amp;#8217;s no suspicious executable for antivirus software to flag, or any unusual processes for endpoint detection to catch, because nothing about the activity is technically abnormal. It only looks wrong in context, and context is exactly what most SMB security tooling isn&amp;#8217;t built to evaluate.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is why perimeter-focused defenses, however well implemented, aren’t enough on their own. A business can do everything right at the point of entry, enforce strong credentials, train employees against phishing, patch every system, and still have no way of knowing that a compromised account is steadily moving files to an external destination, because that activity was never designed to look suspicious in the first place.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security researchers sometimes call this “living off the land”: using the target&amp;#8217;s own legitimate software, cloud integrations, and administrative tools rather than using any tools that an antivirus product would recognize as illegitimate.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A file sync client, a built-in export feature, or a standard email rule aren’t malicious tools in themselves. This is why an attacker who relies on them can operate for so long without setting off anything designed to catch malware.&lt;/p&gt;



&lt;h2 id=&quot;monitor&quot; class=&quot;wp-block-heading&quot;&gt;What businesses should monitor for&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Catching exfiltration early comes down to watching for a small number of specific signals, rather than scanning broadly for suspicious activity.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Traffic and exports&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unusual data transfer volumes or destinations deserve the closest attention. Your organization should be watching for a spike in outbound traffic, a bulk export from a system that doesn&amp;#8217;t normally see them, or any transfer heading to a destination you don’t recognize.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/10-steps/data-security&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;NCSC&amp;#8217;s guidance on data security&lt;/a&gt; specifically recommends logging access to sensitive data and monitoring for unusual queries or attempted bulk exports, precisely because that pattern is a sign that something has moved beyond normal use.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Email forwarding rules&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/blog/how-to-forward-emails&quot;&gt;Email forwarding rules&lt;/a&gt; are worth auditing directly, especially for any account that has been involved in a suspected phishing incident. A rule quietly forwarding messages to an unfamiliar address can sit unnoticed for months, and it&amp;#8217;s one of the simplest things to check once you know to look.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Unusual logins&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Login activity from unexpected locations or times is a signal worth taking seriously. A login at 3 AM from a country the business has no presence in isn&amp;#8217;t proof of anything on its own, but when cross-referenced with a data transfer around the same time, it&amp;#8217;s a detail that can confirm an incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Admin account activity outside business hours deserves particular scrutiny, since admin accounts typically have the broadest reach into a system and are a preferred target precisely because of that reach.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Activity on these accounts late at night, on weekends, or during a period when the actual administrator is known to be out of office is one of the more reliable indicators that an account, not just a device, has been compromised.&lt;/p&gt;



&lt;h2 id=&quot;early-detection&quot; class=&quot;wp-block-heading&quot;&gt;How early detection can change your legal position&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Under both EU GDPR and UK GDPR, &lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32016R0679#d1e3300-1-1&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Article 33&lt;/a&gt; gives organizations 72 hours to notify the relevant supervisory authority once they become aware that a breach affecting personal data has occurred; &lt;a href=&quot;https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;the ICO in the UK&lt;/a&gt; or the national data protection authority in each EU member state. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The requirement is materially the same for all jurisdictions: the clock starts for your organization at the moment of awareness, not from the moment the breach actually happened. This is why thorough exfiltration monitoring matters so much for compliance, not just security.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A business that detects exfiltration early, through forwarding-rule audits, transfer monitoring, or unusual login alerts, can notify proactively, on its own timeline, with a reasonably clear picture of what was taken.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A business that only discovers a breach weeks or months later, often because a customer complained or stolen data surfaced on a criminal forum, is notifying reactively, under pressure, often with an incomplete picture of scope and a regulator asking why it took so long to notice.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The difference goes beyond how your reputation is affected. It shapes how the entire incident is assessed, and how much latitude a regulator is inclined to extend.&lt;/p&gt;



&lt;h2 id=&quot;exfiltrated-data&quot; class=&quot;wp-block-heading&quot;&gt;What happens to exfiltrated business data?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;Data Breach Observatory&lt;/a&gt; tracks what surfaces on the dark web once a breach has occurred, and the pattern is a useful reality check on what exfiltration is really after.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;According to the &lt;a href=&quot;https://proton.me/blog/data-breach-observatory-2026&quot;&gt;2026 Data Breach Observatory update&lt;/a&gt;, names and email addresses appear in nearly nine out of ten tracked breaches, contact details such as phone numbers and physical addresses show up in roughly three-quarters of them, and passwords are exposed in close to half.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;More sensitive categories, government-issued IDs, health records, and other &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information&lt;/a&gt;, appear in just over a third of breaches, while direct financial information shows up in a smaller share, around one in twenty.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;SMBs make up the majority of breaches the Observatory tracks, and they are disproportionately represented among the incidents involving the most sensitive data categories.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This combination, frequent targeting and a high rate of sensitive-data exposure, is consistent with the type of exfiltration this article describes: attacks that occur over a long period of time within a smaller organization&amp;#8217;s systems tend to pay more dividends, because nobody knew that data was being leaked and attackers could take everything.&lt;/p&gt;



&lt;h2 id=&quot;contain&quot; class=&quot;wp-block-heading&quot;&gt;Contain what an attacker can reach&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Exfiltration monitoring catches data on its way out, but the size of the problem is decided earlier, by what a compromised account can reach in the first place. An attacker who gains access to an account with broad, unrestricted permissions can pull from far more systems than one who compromises an account scoped tightly to what that specific role needs.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unique credentials on every account, combined with access limited to what a role genuinely requires, directly shrinks the exfiltration surface. If a compromised marketing account can only reach marketing systems, the worst-case scenario is bounded by design, rather than depending on an attacker&amp;#8217;s restraint or a monitoring system catching them in time.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is the same containment logic that limits blast radius in a credential-based breach generally: the account that gets compromised should only ever be able to leak what it was legitimately allowed to touch.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business makes this scoping realistic to maintain, since it removes the temptation to reuse a convenient set of broad credentials across tools simply because managing unique ones by hand doesn&amp;#8217;t scale.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When every account has its own credential and access is reviewed against what a role actually needs, a single compromised account stops being a route to the entire organization&amp;#8217;s data and becomes, at worst, a contained incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Pass for Business can support your business with:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Customizable team policies that help you enforce your &lt;a href=&quot;https://proton.me/business/blog/password-policy-template&quot;&gt;password policy&lt;/a&gt; with password requirements, mandatory &lt;a href=&quot;https://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt;two-factor authentication&lt;/a&gt; (2FA) and revoked data sharing rules&lt;/li&gt;



&lt;li&gt;Usage logs that allow you to see activity within your network, with additional support from our advanced high security program &lt;a href=&quot;https://proton.me/blog/sentinel-high-security-program&quot;&gt;Proton Sentinel&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;Groups organized by role, project or access level, simplifying access management and ensuring that every team member only has access to what they need. &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Stop credential-based data exfiltration with&lt;strong&gt; &lt;/strong&gt;a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>Does Chrome track you? Of course, but these steps can help</title><link>https://proton.me/blog/chrome-tracking-privacy</link><guid isPermaLink="true">https://proton.me/blog/chrome-tracking-privacy</guid><description>Learn how Chrome tracks your activity, what information it sends to Google, and which privacy settings can reduce tracking while you browse.</description><pubDate>Wed, 26 Aug 2026 20:06:58 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome is the most used browser on the planet, which gives Google access to a considerable amount of information about how people use the internet. Some of that collection happens even when you&amp;#8217;re not signed in.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google says some of Chrome’s data collection helps improve features, security, and search suggestions. But it can also send information back to Google that contributes to a broader picture of your browsing habits. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you&amp;#8217;re not OK with that, your best course is to ditch Chrome once and for all. Here are the &lt;a href=&quot;https://proton.me/blog/best-browser-for-privacy&quot;&gt;best browsers for privacy&lt;/a&gt;, and if you&amp;#8217;d like to steer clear of American tech entirely, these are the &lt;a href=&quot;https://proton.me/learn/european-alternatives/european-web-browsers&quot;&gt;best private European web browsers&lt;/a&gt;. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Unfortunately, there&amp;#8217;s no way to eliminate Google&amp;#8217;s data collection if you&amp;#8217;re determined to keep using Chrome. But you can limit the damage.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;How Chrome Tracks Everything You Do and How to Stop It&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/LE-TMEM1FS4?feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why Chrome tracks your activity&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A web browser is a little like your front door to the internet. Everything you do &lt;a href=&quot;https://protonvpn.com/blog/digital-footprint&quot;&gt;&lt;u&gt;online&lt;/u&gt;&lt;/a&gt; passes through it. If that door also has cameras and sensors recording who comes and goes, it becomes much easier to understand your habits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome can &lt;a href=&quot;https://www.wired.com/story/google-chrome-browser-data&quot;&gt;&lt;u&gt;collect information&lt;/u&gt;&lt;/a&gt; even when you aren&amp;#8217;t signed in. It can also use identifiers associated with your browser and device, while other settings allow it to share information with Google to improve features and services.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some of these settings are easy to overlook because they are presented as ways to make Chrome better. Enhanced &lt;strong&gt;Safe Browsing&lt;/strong&gt;, for example, can send information about websites you visit to Google as part of its &lt;a href=&quot;https://protonvpn.com/blog/google-ip-protection&quot;&gt;&lt;u&gt;security features&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That doesn&amp;#8217;t mean every privacy-related feature is inherently bad. It does mean you should know what you&amp;#8217;re agreeing to before leaving everything enabled.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Chrome sends what you type to Google&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One of the more direct forms of data sharing happens while you type into Chrome’s address bar. With &lt;a href=&quot;https://protonvpn.com/blog/delete-search-history&quot;&gt;&lt;u&gt;search suggestions&lt;/u&gt;&lt;/a&gt; enabled, Chrome can send what you type to Google before you actually submit a search.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That can be useful if you want faster suggestions, but it also means Google may receive queries you never intended to search.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can limit this by going to: &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Settings&lt;/strong&gt; &amp;gt; &lt;strong&gt;You and Google&lt;/strong&gt; &amp;gt; &lt;strong&gt;Sync and Google services&lt;/strong&gt;&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA&quot; alt=&quot;Google Chrome privacy settings 1&quot; class=&quot;wp-post-276448 wp-image-276449&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;114 KB&quot; data-optsize=&quot;45 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;60.5&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276449&quot; data-version=&quot;1787682600&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787682600/wp-pme/google-chrome-settings-1/google-chrome-settings-1.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Next turn off &lt;strong&gt;Improve search suggestions&lt;/strong&gt;.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA&quot; alt=&quot;Google Chrome privacy settings 2&quot; class=&quot;wp-post-276448 wp-image-276473&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;187 KB&quot; data-optsize=&quot;91 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;51.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276473&quot; data-version=&quot;1787682689&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787682689/wp-pme/google-chrome-privacy-settings-2/google-chrome-privacy-settings-2.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This prevents Chrome from sending your typing to Google simply to generate predictions and suggestions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s a small setting, but it addresses a particularly revealing type of data: things you started typing but never actually searched for.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Chrome builds a profile of your browsing habits&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome can also send information about how you use the browser back to Google. Combined with other data, this can help build a picture of your interests, the devices you use, and even your physical location.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To reduce this collection:&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Open &lt;strong&gt;You and Google&lt;/strong&gt; &amp;gt; &lt;strong&gt;Sync and Google services&lt;/strong&gt; &amp;gt; toggle off &lt;strong&gt;Help improve Chrome’s features and performance&lt;/strong&gt; and &lt;strong&gt;Make searches and browsing better&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA&quot; alt=&quot;Google chrome privacy settings 3&quot; class=&quot;wp-post-276448 wp-image-276497&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;188 KB&quot; data-optsize=&quot;92 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;51.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276497&quot; data-version=&quot;1787684352&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787684352/wp-pme/google-chrome-privacy-settings-3/google-chrome-privacy-settings-3.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also disable &lt;strong&gt;Background Sync&lt;/strong&gt; under &lt;strong&gt;Privacy and Security&lt;/strong&gt;, then &lt;strong&gt;Site settings and Additional permissions&lt;/strong&gt;.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-276448 wp-image-276521&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;174 KB&quot; data-optsize=&quot;79 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;54.7&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276521&quot; data-version=&quot;1787833731&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787833731/wp-pme/google-chrome-privacy-settings-4/google-chrome-privacy-settings-4.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;This prevents websites from continuing to exchange data after you have closed a tab.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;While you&amp;#8217;re reviewing those settings, check your site permissions too. Remove access to your location, camera, or microphone from websites that don&amp;#8217;t genuinely need it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to reduce Chrome’s ad tracking&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome also includes advertising features that use browsing activity to group you into advertising interests. These settings are separate from the basic functions you need to browse the web.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://protonvpn.com/blog/what-are-cookies&quot;&gt;&lt;u&gt;Third-party cookies&lt;/u&gt;&lt;/a&gt; are one such source of persistent tracking. These cookies can be placed by companies that aren&amp;#8217;t related to the website you&amp;#8217;re visiting, such as advertising networks and social media companies. Because the same companies can appear across many different websites, their cookies can help connect activity from one site to another.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can &lt;a href=&quot;https://protonvpn.com/blog/how-to-block-third-party-cookies-on-all-browsers&quot;&gt;&lt;u&gt;block third-party cookies&lt;/u&gt;&lt;/a&gt; by: &lt;strong&gt;Privacy and Security&lt;/strong&gt; &amp;gt; &lt;strong&gt;Third-Party Cookies&lt;/strong&gt;. &lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA&quot; alt=&quot;Google Chrome Privacy settings 5&quot; class=&quot;wp-post-276448 wp-image-276545&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;141 KB&quot; data-optsize=&quot;63 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;55.2&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276545&quot; data-version=&quot;1787684785&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787684785/wp-pme/google-chrome-privacy-settings-5/google-chrome-privacy-settings-5.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome also offers a &lt;strong&gt;Do Not Track&lt;/strong&gt; request, although websites don&amp;#8217;t always honor it.&lt;/p&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;711&quot; data-public-id=&quot;wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA&quot; alt=&quot;Google chrome privacy settings&quot; class=&quot;wp-post-276448 wp-image-276569&quot; data-format=&quot;jpeg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;204 KB&quot; data-optsize=&quot;103 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;49.4&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276569&quot; data-version=&quot;1787684856&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_711,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_208,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_533,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_1066,c_scale/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787684856/wp-pme/google-chrome-privacy-settings-6/google-chrome-privacy-settings-6.jpeg?_i=AA 1556w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;p class=&quot;wp-block-paragraph&quot;&gt;For an additional layer of privacy, you can set Chrome to clear cookies whenever you close the browser. The trade-off is that you&amp;#8217;ll have to sign in to some websites more often.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Chrome gives you several ways to reduce how much information it collects, and changing a few settings can make a meaningful difference. But if you want to stop Google from collecting data through the browser entirely, Chrome may not be the right tool for you.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A different browser can give you more control over how your browsing data is handled. For Chrome users who want to stay put, though, reviewing these settings is a practical place to start.&lt;/p&gt;
</content:encoded><category>Videos</category><author>Proton Team</author></item><item><title>Meta reaches $18 billion settlement over teen social media addiction claims</title><link>https://proton.me/blog/meta-teen-addiction-settlement</link><guid isPermaLink="true">https://proton.me/blog/meta-teen-addiction-settlement</guid><description>Meta has agreed to pay a $18 billion settlement and implement child-safety measures on Instagram and Facebook, ending a landmark trial.</description><pubDate>Wed, 26 Aug 2026 17:34:34 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://apnews.com/article/meta-trial-instagram-settlement-97d342f2a33d835eda2356c5e1af9e37&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Meta has agreed to pay up to $18 billion and overhaul Facebook and Instagram&lt;/a&gt; to settle claims from 48 states, D.C. and U.S. territories that it engineered its platforms to hook young users.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The deal ends a federal trial in Oakland in which California, Colorado, Kentucky and New Jersey had sought roughly $200 billion in damages — a trial that was about to send CEO Mark Zuckerberg back to the witness stand.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The agreement, filed Wednesday morning in the U.S. Northern District of California, resolves claims that Meta built features designed to addict children and collected data from users under 13 without parental consent — all violations of federal child-privacy law and state consumer-protection statutes. Judge Yvonne Gonzalez Rogers is expected to approve it.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What the settlement says&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The settlement outlines injunctive terms intended to protect teens from mental health harms, including:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;A daily time limit of two hours for under-18s, liftable only by a parent, dropping to one hour if other platforms accept similar terms.&lt;/li&gt;



&lt;li&gt;A usage block from midnight to 6 a.m. for under-18s, expanding to 10 p.m.–7 a.m. if other platforms follow.&lt;/li&gt;



&lt;li&gt;Notifications silenced for under-18s from 10 p.m. to 7 a.m., and from 8 a.m. to 3 p.m. on school days between August 15 and June 15.&lt;/li&gt;



&lt;li&gt;A ban on displaying like or reaction counts to under-18s, and a ban on cosmetic image filters.&lt;/li&gt;



&lt;li&gt;An optional non-personalized feed that stops using an algorithm to target teens with endless-scroll content.&lt;/li&gt;



&lt;li&gt;A requirement to respond to 90% of teen reports of potentially harmful content within six hours.&lt;/li&gt;



&lt;li&gt;Robust age-assurance measures to detect under-18s, plus removal of users under 13.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Is $18 billion enough?&lt;/h2&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;2400&quot; height=&quot;1200&quot; data-public-id=&quot;wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_2400,h_1200,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA&quot; alt=&quot;Big Tech&amp;#039;s annual fines (the cash in red) are dwarfed by its annual free cash flow&quot; class=&quot;wp-post-276734 wp-image-81717&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;1 MB&quot; data-optsize=&quot;109 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;89.4&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=81717&quot; data-version=&quot;1737033282&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 2400w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_150,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_512,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_384,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_1536,h_768,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 1536w, https://res.cloudinary.com/dbulfrlrz/images/w_2048,h_1024,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 2048w, https://res.cloudinary.com/dbulfrlrz/images/w_1568,h_784,c_scale/f_auto,q_auto/v1737033282/wp-pme/big_tech_fines2024_blog_cover2x/big_tech_fines2024_blog_cover2x.png?_i=AA 1568w&quot; sizes=&quot;auto, (max-width: 2400px) 100vw, 2400px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton&amp;#8217;s &lt;a href=&quot;https://proton.me/tech-fines-tracker&quot;&gt;Big Tech Fines tracker&lt;/a&gt;, which has been compiling regulatory penalties since 2022, shows that Alphabet, Apple, Meta and Amazon together racked up roughly $7.8 billion in fines in 2025 alone for privacy and competition violations. Meta&amp;#8217;s $18 billion settlement now outstrips the four companies&amp;#8217; entire 2025 penalty bill, and more than doubles Meta&amp;#8217;s own prior annual fine totals.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Measured against free cash flow, however, the four firms could have cleared that full $7.8 billion in about 28 days and 48 minutes. The story remains largely the same today. Meta&amp;#8217;s stock rose 2.3% following news of the settlement, &lt;a href=&quot;https://www.reuters.com/world/us/meta-settles-with-us-states-over-social-media-harms-2026-08-26/&quot;&gt;according to Reuters&lt;/a&gt;, adding roughly $33 billion in market value to the company.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Penalties are being treated as a cost of doing business rather than a mechanism that actually changes behavior.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Now the real test begins&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;On paper this might look like accountability. In practice, however, it is a clear win for Mark Zuckerberg and the $1.5 trillion company he controls. Prosecutors were seeking $200 billion. Meta will pay $18 billion, admit no wrongdoing, and agree to a set of product changes that are largely cosmetic.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The diagnosis in the claims is real, and that matters. It puts on the record that Meta, like Google and TikTok, has &lt;a href=&quot;https://proton.me/blog/what-is-your-data-worth&quot;&gt;put ad revenue and engagement ahead of its users&amp;#8217; best interests,&lt;/a&gt; building addictive products, and &lt;a href=&quot;https://proton.me/blog/what-is-your-data-worth-to-google&quot;&gt;harvesting data at massive scale&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But a diagnosis is not a treatment, and this settlement does nothing to change &lt;a href=&quot;https://proton.me/blog/stop-meta-tracking&quot;&gt;a business model that prioritizes revenue over the wellbeing and privacy of its users&lt;/a&gt;. The real test is whether the rules actually change, and whether &amp;#8220;cost of doing business&amp;#8221; ever stops being an acceptable answer for &lt;a href=&quot;https://apnews.com/article/social-media-addiction-trial-la-5e54075023d837ccdc76c4ca512e925d&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;the damage done to kids&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For families concerned about the impact of social media on their children, &lt;a href=&quot;https://proton.me/blog/family-internet&quot; data-type=&quot;link&quot; data-id=&quot;https://proton.me/blog/family-internet&quot;&gt;our guide to keeping kids safe online&lt;/a&gt; is a good place to start.&lt;/p&gt;



&lt;figure class=&quot;wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio&quot;&gt;&lt;div class=&quot;wp-block-embed__wrapper&quot;&gt;
&lt;iframe loading=&quot;lazy&quot; title=&quot;Every Way Meta Tracks You, and How to Fight Back&quot; width=&quot;750&quot; height=&quot;422&quot; src=&quot;https://www.youtube-nocookie.com/embed/Yv2Eb_kJous?start=143&amp;amp;feature=oembed&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; allowfullscreen&gt;&lt;/iframe&gt;
&lt;/div&gt;&lt;/figure&gt;
</content:encoded><category>News</category><author>Proton Team</author></item><item><title>How to scan a document on iPhone</title><link>https://proton.me/blog/how-to-scan-a-document-on-iphone</link><guid isPermaLink="true">https://proton.me/blog/how-to-scan-a-document-on-iphone</guid><description>Learn how to scan a document on iPhone using Notes, Files, Preview, and Proton Drive. Only one of these protects your privacy by default.</description><pubDate>Wed, 26 Aug 2026 12:28:59 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;You don’t need a scanner to turn paperwork into a &lt;a href=&quot;https://proton.me/business/blog/pdf-virus&quot;&gt;&lt;u&gt;PDF&lt;/u&gt;&lt;/a&gt;. Chances are, you already have one: Your &lt;a href=&quot;https://proton.me/blog/iphone-storage&quot;&gt;&lt;u&gt;iPhone&lt;/u&gt;&lt;/a&gt; has document scanning built into several apps, including Notes and Files. Starting with iOS 26, you can also scan &lt;a href=&quot;https://proton.me/drive/docs&quot;&gt;&lt;u&gt;documents&lt;/u&gt;&lt;/a&gt; with Preview. Whichever app you pick, scanning a document on an iPhone takes just a few taps.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The best way to scan a document largely depends on what you’re scanning and why. Receipts and meeting notes might not contain much &lt;a href=&quot;https://proton.me/business/blog/sensitive-information&quot;&gt;&lt;u&gt;sensitive information&lt;/u&gt;&lt;/a&gt;, but passports, contracts, tax records, medical documents, invoices, and business paperwork do. In business settings, a leaked copy doesn&amp;#8217;t just expose you; it can breach client confidentiality, violate a contract&amp;#8217;s data-handling terms, or create liability for your organization.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For sensitive documents, Proton Drive lets you scan and save directly to end-to-end encrypted &lt;a href=&quot;https://proton.me/drive&quot;&gt;&lt;u&gt;cloud storage&lt;/u&gt;&lt;/a&gt;, then share them securely, without handing a copy to Big Tech.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;#ways&quot;&gt;4 ways to scan a document on your iPhone&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#notes&quot;&gt;How to scan a document on iPhone using Notes&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#files&quot;&gt;How to scan a document to PDF using Files&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#preview&quot;&gt;How to scan a document on iPhone using Preview&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#drive&quot;&gt;How to securely scan a document with Proton Drive&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#can&quot;&gt;Can you scan multiple pages into one PDF on iPhone?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#tips&quot;&gt;Tips for getting a clear document scan&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#safe&quot;&gt;Is the iPhone&amp;#8217;s built-in document scanner safe to use?&lt;/a&gt;&lt;/li&gt;



&lt;li&gt;&lt;a href=&quot;#proton&quot;&gt;Scan sensitive documents with Proton Drive&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;ways&quot; class=&quot;wp-block-heading&quot;&gt;4 ways to scan a document on your iPhone&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Method&lt;/th&gt;&lt;th&gt;Best for&lt;/th&gt;&lt;th&gt;Setup&lt;/th&gt;&lt;th&gt;Encryption&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Notes&lt;/td&gt;&lt;td&gt;Quick scans and signatures&lt;/td&gt;&lt;td&gt;Already on your iPhone&lt;/td&gt;&lt;td&gt;Standard iCloud encryption; Apple holds the key by default&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Files&lt;/td&gt;&lt;td&gt;Creating a standalone PDF&lt;/td&gt;&lt;td&gt;Already on your iPhone&lt;/td&gt;&lt;td&gt;Standard iCloud encryption; Apple holds the key by default&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Preview&lt;/td&gt;&lt;td&gt;Scanning and working with PDFs&lt;/td&gt;&lt;td&gt;Already on your iPhone, starting with iOS 26&lt;/td&gt;&lt;td&gt;Standard iCloud encryption where Apple holds the key by default, unless saved elsewhere&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Proton Drive&lt;/td&gt;&lt;td&gt;Secure scanning, storing, and sharing documents&amp;nbsp;&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://proton.me/drive/download&quot;&gt;&lt;u&gt;Free app download&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;End-to-end encrypted by design, only you hold the keys&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;notes&quot; class=&quot;wp-block-heading&quot;&gt;How to scan a document on iPhone using Notes&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Apple Notes has a built-in document scanner, starting with iOS 26. To scan a document:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open Notes and create a new note or select an existing one.&lt;/li&gt;



&lt;li&gt;Tap the &lt;strong&gt;Attachment&lt;/strong&gt; button, then &lt;strong&gt;Scan Documents&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1149&quot; height=&quot;2189&quot; data-public-id=&quot;wp-pme/scan-document-iphone-1/scan-document-iphone-1.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1149,h_2189,c_scale/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA&quot; alt=&quot;How to scan a document on iPhone using the Notes app&quot; class=&quot;wp-post-276622 wp-image-276647&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;195 KB&quot; data-optsize=&quot;31 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;84.3&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276647&quot; data-version=&quot;1787739603&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA 1149w, https://res.cloudinary.com/dbulfrlrz/images/w_157,h_300,c_scale/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA 157w, https://res.cloudinary.com/dbulfrlrz/images/w_537,h_1024,c_scale/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA 537w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1463,c_scale/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_806,h_1536,c_scale/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA 806w, https://res.cloudinary.com/dbulfrlrz/images/w_1075,h_2048,c_scale/f_auto,q_auto/v1787739603/wp-pme/scan-document-iphone-1/scan-document-iphone-1.png?_i=AA 1075w&quot; sizes=&quot;auto, (max-width: 1149px) 100vw, 1149px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol start=&quot;3&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Let your iPhone capture the page automatically, or switch from &lt;strong&gt;Auto&lt;/strong&gt; to &lt;strong&gt;Manual&lt;/strong&gt; and tap the &lt;strong&gt;Shutter&lt;/strong&gt; button. Adjust the corners if necessary and tap &lt;strong&gt;Keep Scan&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Scan any additional pages.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Done&lt;/strong&gt;. The scanned document is saved as a PDF inside the note.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;files&quot; class=&quot;wp-block-heading&quot;&gt;How to scan a document to PDF using Files&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Files app is a good option if you want to create a PDF and save it directly to a folder rather than keep it inside a note. To scan a document:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open &lt;strong&gt;Files&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Navigate to the location or folder where you want to save the scan.&lt;/li&gt;



&lt;li&gt;Tap the &lt;strong&gt;More (…)&lt;/strong&gt; button.&lt;/li&gt;



&lt;li&gt;Select &lt;strong&gt;Scan Documents&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1170&quot; height=&quot;2397&quot; data-public-id=&quot;wp-pme/scan-document-iphone-2/scan-document-iphone-2.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1170,h_2397,c_scale/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA&quot; alt=&quot;How to scan a document on iPhone using the Files app&quot; class=&quot;wp-post-276622 wp-image-276671&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;236 KB&quot; data-optsize=&quot;40 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;82.9&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276671&quot; data-version=&quot;1787739616&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA 1170w, https://res.cloudinary.com/dbulfrlrz/images/w_146,h_300,c_scale/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA 146w, https://res.cloudinary.com/dbulfrlrz/images/w_500,h_1024,c_scale/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA 500w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1573,c_scale/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_750,h_1536,c_scale/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA 750w, https://res.cloudinary.com/dbulfrlrz/images/w_1000,h_2048,c_scale/f_auto,q_auto/v1787739616/wp-pme/scan-document-iphone-2/scan-document-iphone-2.png?_i=AA 1000w&quot; sizes=&quot;auto, (max-width: 1170px) 100vw, 1170px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol start=&quot;5&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Let your iPhone capture the page automatically, or switch from &lt;strong&gt;Auto&lt;/strong&gt; to &lt;strong&gt;Manual&lt;/strong&gt; and tap the &lt;strong&gt;Shutter&lt;/strong&gt; button. Adjust the corners if necessary and tap &lt;strong&gt;Keep Scan&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Scan any additional pages.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Done&lt;/strong&gt;, choose where you want to save the PDF, then tap &lt;strong&gt;Save&lt;/strong&gt;. &lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;preview&quot; class=&quot;wp-block-heading&quot;&gt;How to scan a document on iPhone using Preview&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’re using iOS 26 or newer, Apple’s Preview app creates a PDF that you can then rename, annotate, fill out, sign, or share. To scan a document:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Open &lt;strong&gt;Preview&lt;/strong&gt;.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Scan Documents&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1164&quot; height=&quot;2384&quot; data-public-id=&quot;wp-pme/scan-document-iphone-3/scan-document-iphone-3.png&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1164,h_2384,c_scale/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA&quot; alt=&quot;How to scan a document on iPhone using the Preview app&quot; class=&quot;wp-post-276622 wp-image-276695&quot; style=&quot;width:400px&quot; data-format=&quot;png&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;450 KB&quot; data-optsize=&quot;50 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;88.9&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=276695&quot; data-version=&quot;1787739626&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA 1164w, https://res.cloudinary.com/dbulfrlrz/images/w_146,h_300,c_scale/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA 146w, https://res.cloudinary.com/dbulfrlrz/images/w_500,h_1024,c_scale/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA 500w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1573,c_scale/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_750,h_1536,c_scale/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA 750w, https://res.cloudinary.com/dbulfrlrz/images/w_1000,h_2048,c_scale/f_auto,q_auto/v1787739626/wp-pme/scan-document-iphone-3/scan-document-iphone-3.png?_i=AA 1000w&quot; sizes=&quot;auto, (max-width: 1164px) 100vw, 1164px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol start=&quot;3&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Let your iPhone capture the page automatically, or switch from &lt;strong&gt;Auto&lt;/strong&gt; to &lt;strong&gt;Manual&lt;/strong&gt; and tap the Shutter button.&lt;/li&gt;



&lt;li&gt;Scan any additional pages. Tap a page thumbnail if you want to adjust its appearance.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Done&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 id=&quot;drive&quot; class=&quot;wp-block-heading&quot;&gt;How to securely scan a document with Proton Drive&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Scanning with Proton Drive is quick and straightforward. Pages are detected and captured automatically, and you can crop, rotate, apply filters, or add more pages before saving. The app only receives access to the pages you choose to keep, and nothing else from your camera roll.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To &lt;a href=&quot;https://proton.me/support/drive-scan-document&quot;&gt;&lt;u&gt;scan a document in Proton Drive&lt;/u&gt;&lt;/a&gt;:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/drive/download&quot;&gt;&lt;u&gt;Get Proton Drive for iOS&lt;/u&gt;&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;Sign in with your Proton Account. You can &lt;a href=&quot;https://proton.me/drive/pricing&quot;&gt;start with 5GB free&lt;/a&gt;.&lt;/li&gt;



&lt;li&gt;Go to &lt;strong&gt;Files&lt;/strong&gt; and open the folder where you want to save your scan.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;+&lt;/strong&gt; in the top-right corner and select &lt;strong&gt;Scan document&lt;/strong&gt;. Allow camera access if prompted.&lt;/li&gt;
&lt;/ol&gt;


&lt;div class=&quot;wp-block-image&quot;&gt;
&lt;figure class=&quot;aligncenter size-full is-resized&quot;&gt;&lt;img width=&quot;1170&quot; height=&quot;2355&quot; data-public-id=&quot;wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1170,h_2355,c_scale/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA&quot; alt=&quot;The Proton Drive iOS app shows how to scan a document&quot; class=&quot;wp-post-276622 wp-image-137243&quot; style=&quot;width:400px&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;357 KB&quot; data-optsize=&quot;139 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;61.2&quot; data-permalink=&quot;https://pme.protonblog.tech/wp-admin/admin.php?page=cloudinary&amp;amp;section=edit-asset&amp;amp;asset=137243&quot; data-version=&quot;1778681690&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA 1170w, https://res.cloudinary.com/dbulfrlrz/images/w_149,h_300,c_scale/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA 149w, https://res.cloudinary.com/dbulfrlrz/images/w_509,h_1024,c_scale/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA 509w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_1546,c_scale/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/w_763,h_1536,c_scale/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA 763w, https://res.cloudinary.com/dbulfrlrz/images/w_1017,h_2048,c_scale/f_auto,q_auto/v1778681690/wp-pme/proton-drive-ios-scan-document/proton-drive-ios-scan-document.jpg?_i=AA 1017w&quot; sizes=&quot;auto, (max-width: 1170px) 100vw, 1170px&quot; /&gt;&lt;/figure&gt;
&lt;/div&gt;


&lt;ol start=&quot;5&quot; class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Position the document in the viewfinder. Proton Drive automatically detects and captures the page, or you can switch to manual capture.&lt;/li&gt;



&lt;li&gt;Scan any additional pages. You can retake or delete scans, apply filters, rotate pages, and adjust the document edges.&lt;/li&gt;



&lt;li&gt;Tap &lt;strong&gt;Save&lt;/strong&gt;. Your scan is saved as an end-to-end encrypted PDF in Proton Drive.&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can keep the scanned document safely stored to end-to-end encrypted cloud storage, knowing that no one can access it but you — not even us. If you decide to share the scan with someone, you can &lt;a href=&quot;https://proton.me/support/drive-how-to-share-files-via-email&quot;&gt;invite people by email&lt;/a&gt; or &lt;a href=&quot;https://proton.me/support/drive-shareable-link&quot;&gt;create a sharing link&lt;/a&gt; with &lt;a href=&quot;https://proton.me/drive/file-sharing/password-protection&quot;&gt;password protection&lt;/a&gt; and an expiration date. Recipients don’t need a Proton account to view or download your shared links, and they can even upload their own files to your cloud storage.&lt;/p&gt;



&lt;h2 id=&quot;can&quot; class=&quot;wp-block-heading&quot;&gt;Can you scan multiple pages into one PDF on iPhone?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Yes. Notes, Files, Preview, and Proton Drive all let you capture multiple pages during the same scanning session. Keep scanning until you have captured every page, review them in the correct order, then save the document. Your pages will be combined into a single PDF.&lt;/p&gt;



&lt;h2 id=&quot;tips&quot; class=&quot;wp-block-heading&quot;&gt;Tips for getting a clear document scan&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your iPhone can automatically detect, crop, and straighten documents, but a few simple steps can help produce a cleaner scan:&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Lay the document flat.&lt;/strong&gt; Creases or curled edges can make the page harder to detect and can distort the text.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use bright, even lighting.&lt;/strong&gt; Shadows can obscure text and interfere with automatic edge detection.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use a contrasting background.&lt;/strong&gt; A white sheet of paper is easier to detect against a darker surface than another white surface.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Keep your iPhone parallel to the page.&lt;/strong&gt; Scanning at an angle can distort the document.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Check the edges. &lt;/strong&gt;A bad crop can cut off text, signatures, or other important details.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Use a filter when necessary.&lt;/strong&gt; A black-and-white or high-contrast filter can make faded documents easier to read.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Review every page.&lt;/strong&gt; Make sure important details such as names, numbers, and signatures are visible.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Check the finished PDF.&lt;/strong&gt; Confirm every page has been saved, appears in the right order, and is readable.&amp;nbsp;&lt;/p&gt;



&lt;h2 id=&quot;safe&quot; class=&quot;wp-block-heading&quot;&gt;Is the iPhone&amp;#8217;s built-in document scanner safe to use?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For everyday paperwork, Apple’s built-in scanners are convenient. For more sensitive documents, it’s worth considering how the finished file is stored and shared. Scans stored in &lt;a href=&quot;https://proton.me/drive/icloud-alternative&quot;&gt;&lt;u&gt;iCloud Drive&lt;/u&gt;&lt;/a&gt; or Notes are encrypted, but Apple retains the &lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;&lt;u&gt;encryption&lt;/u&gt;&lt;/a&gt; keys by default, meaning the company can technically access them, including in response to a legal request. Apple&amp;#8217;s &lt;a href=&quot;https://proton.me/blog/protect-data-apple-adp-uk&quot;&gt;&lt;u&gt;Advanced Data Protection (ADP)&lt;/u&gt;&lt;/a&gt; can close this gap, but it&amp;#8217;s off by default and not available to all users, such as in the UK.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If the idea that someone else could look through your scans doesn&amp;#8217;t sit right with you, a secure-by-default option like Proton Drive is worth switching to instead.&lt;/p&gt;



&lt;h2 id=&quot;proton&quot; class=&quot;wp-block-heading&quot;&gt;Scan sensitive documents with Proton Drive&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Drive protects scanned PDFs with end-to-end encryption, which means no one can access your sensitive data besides you and those you choose to share it with, not even Proton. You can also &lt;a href=&quot;https://proton.me/drive/file-sharing&quot;&gt;&lt;u&gt;share documents&lt;/u&gt;&lt;/a&gt; using password-protected or expiring links and easily revoke access later. If you&amp;#8217;re scanning on behalf of your company, our &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;&lt;u&gt;cloud storage for business&lt;/u&gt;&lt;/a&gt; extends the same protection to team storage and sharing.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt; &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/drive/pricing&quot;&gt;Start with 5GB free&lt;/a&gt; &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-outlined-purple&quot; href=&quot;https://proton.me/business/drive/pricing&quot;&gt;View plans&lt;/a&gt; &lt;/div&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;/p&gt;
</content:encoded><category>Guides</category><author>Tom Odlin</author></item><item><title>Nonprofits say Microsoft locked them out of years of data</title><link>https://proton.me/business/blog/microsoft-nonprofit-data-deletion</link><guid isPermaLink="true">https://proton.me/business/blog/microsoft-nonprofit-data-deletion</guid><description>A new report alleges Microsoft locked nonprofits out of years of data. Here&apos;s what you need to know and what you can do about it.</description><pubDate>Tue, 25 Aug 2026 18:59:02 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;In 2013, Microsoft began offering its software free to nonprofits: &lt;a href=&quot;https://proton.me/business/drive/microsoft-word-alternative&quot;&gt;Word&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/excel-alternative&quot;&gt;Excel&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/onedrive-alternative&quot;&gt;OneDrive&lt;/a&gt;, and the full &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Office 365&lt;/a&gt; suite, at a time when tech companies, including Microsoft, were promoting their charitable giving. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Over the next decade, nonprofits built themselves up around that offer, storing donor records, grant applications, and years of institutional knowledge within the Microsoft suite.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Then, sometime in the past year, without most of them noticing, access to that data began to disappear.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A recent &lt;a href=&quot;https://slate.com/technology/2026/08/microsoft-software-nonprofit-data-delete.html&quot;&gt;Slate report&lt;/a&gt; alleges that Microsoft&amp;#8217;s wind-down of the free nonprofit grant left small organizations locked out of years of data, with little or no warning.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What sources are alleging&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ronald Khosla, who runs the environmental nonprofit Canopy, got an email in May 2025 warning that his organization&amp;#8217;s Microsoft grant would be discontinued and his license would expire that October. When he renewed that October, though, Microsoft&amp;#8217;s confirmation email said nothing about the phaseout, and told him he would retain access until October 4, 2026. He logged in that June to find years of files gone anyway. A Microsoft representative later told him roughly 171,000 nonprofits had lost their &lt;a href=&quot;https://proton.me/business/drive/onedrive-alternative&quot;&gt;OneDrive&lt;/a&gt; data the same way, a figure relayed to Khosla by phone.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;One source, who runs a child healthcare nonprofit, said he searched his organization&amp;#8217;s &lt;a href=&quot;https://proton.me/business/blog/email-archiving&quot;&gt;email archives&lt;/a&gt;, including the spam folder, and found &amp;#8220;zero notification&amp;#8221; from Microsoft about the license termination. The operator of a disability services nonprofit told Slate it will take him and his mother &amp;#8220;hundreds of hours&amp;#8221; to recreate the instructional videos and documents they lost. Microsoft told Slate it &amp;#8220;began notifying nonprofit customers in Spring 2025.&amp;#8221;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The complaints are on Microsoft&amp;#8217;s own platform, too&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These allegations aren&amp;#8217;t confined to one article. Nonprofit admins have posted the same complaint, data suddenly inaccessible after a licensing change, directly on &lt;a href=&quot;https://techcommunity.microsoft.com/discussions/admincenter/not-for-profit-licence-suddenly-disappeared-and-then-deleted/4528916&quot;&gt;Microsoft&amp;#8217;s own Tech Community forums&lt;/a&gt;, in &lt;a href=&quot;https://techcommunity.microsoft.com/discussions/exploringai/500-gbs-of-data-inaccessible-on-365-for-nonprofits/4529667/replies/4541673&quot;&gt;multiple&lt;/a&gt; &lt;a href=&quot;https://techcommunity.microsoft.com/discussions/microsoftfornonprofits/onedrive--sharepoint-data-loss-after-nonprofit-licence-issue-%E2%80%93-recovery-deadline/4535689&quot;&gt;threads&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Security researcher Kevin Beaumont, a former senior threat intelligence analyst at Microsoft, has separately &lt;a href=&quot;https://www.linkedin.com/posts/kevin-beaumont-security_check-your-email-logs-including-exchange-activity-7215355395878305793-K8n_/&quot;&gt;flagged&lt;/a&gt; that Microsoft&amp;#8217;s own notification emails often go unseen because they&amp;#8217;re sent to admin accounts that aren&amp;#8217;t set up to be monitored, which often land in the spam folder.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A free grant isn&amp;#8217;t a backup plan&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whatever the exact numbers, the pattern alleged here is structural: Nonprofits built infrastructure around a single vendor&amp;#8217;s free tier, with no easy export path or independent &lt;a href=&quot;https://proton.me/business/drive/cloud-backup-small-business&quot;&gt;backup&lt;/a&gt;. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For nonprofits with budgets under $1 million (the majority of US nonprofits), the value of Microsoft&amp;#8217;s free software equated to about 30% of their IT spending, according to Slate.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When that vendor changed course, the data went with it. A free grant is not a guarantee; it&amp;#8217;s a product decision, reversible at any time, with an organization&amp;#8217;s data as collateral.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The dependency problem isn&amp;#8217;t unique to nonprofits either, as over 74% of publicly listed &lt;a href=&quot;https://proton.me/business/europe-tech-watch&quot;&gt;European companies depend on US tech&lt;/a&gt; like Microsoft and Google.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A special Proton offer for impacted nonprofits&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Nonprofits affected by Microsoft&amp;#8217;s rollback can now get &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;Proton Drive&lt;/a&gt; free for the first year — for up to 20 users — then move to nonprofit pricing for subsequent years. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Every other Proton product, including the full Workspace suite covering Mail, Drive, Docs, VPN, Pass, and Calendar, is also available at &lt;a href=&quot;https://proton.me/business/nonprofit-discount&quot;&gt;nonprofit discount&lt;/a&gt; rates. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Both offers run through Proton&amp;#8217;s sales team, and organizations applying will need to show proof of eligibility, that they&amp;#8217;re a nonprofit and that they were affected by the Microsoft data loss. &lt;/p&gt;
</content:encoded><category>For business</category><author>Edward Komenda</author></item></channel></rss>