Category: Blog

Blog posts from The Unite group.

Here at the Unite Group, we like to keep our clients and network up to date with the information that can help them in their business using our blog pages.

We cover topics such as IT support, Hosted telephony, Cyber security, Digital marketing, and much more. We think it is important to educate our audience using our blog, not only on these topics but to give a behind-the-scenes view on what is going on day to day at the Unite Group and the people who make up our team. Having knowledge of what we offer can help you to make a more informed choice on the services you need and which ones would work best for your business.

If there are topics you would like to see us create content around then drop us an email and we will get these added for you.

  • Cyber Essentials v3.3: What Changed and How to Pass First Time

    Cyber Essentials v3.3: What Changed and How to Pass First Time

    Cyber Essentials v3.3 took effect on 27 April 2026. All new assessment accounts created after that date use the updated requirements and the new Danzell question set. If your certification is due for renewal or you are certifying for the first time, v3.3 now applies to your assessment.

    The core scheme has not changed. It still tests the same five control themes: firewalls, secure configuration, user access control, malware protection, and security update management. The updated version marks certain areas more strictly, changes how cloud services are scoped, and introduces clearer automatic failure triggers. The businesses that understand these changes pass first time. The ones that assume last year’s answers still work are the ones that fail. It is crucial to keep up to date with Cyber Essentials v3.3 compliance requirements.

    The Three Changes That Matter Most

    1. MFA is now a hard fail. Cyber Essentials has included multi-factor authentication for several years, but v3.3 now marks it more strictly. If a cloud service supports MFA and you have not enabled it for all users, you automatically fail. No discussion, no mitigation, no partial credit. Adhering to Cyber Essentials version 3.3 is mandatory in this respect.

    This applies regardless of whether MFA is free, bundled with the service, or only available as a paid add-on. If the option exists and you have not switched it on, the assessment stops there. Cyber Essentials v3.3 no longer accepts IP allowlisting as a form of multi-factor authentication.

    The practical impact is significant. Most businesses have MFA enforced on their main platforms, Microsoft 365, for example, but have not enabled it on every cloud service they use. Project management tools, accounting software, CRM platforms, HR systems, social media accounts used for business, and even free-tier SaaS tools all count. Being thorough is now an integral part of the Cyber Essentials v3.3 requirements.

    2. Cloud services cannot be excluded from scope. For the first time, v3.3 includes a formal definition of a cloud service: an on-demand, scalable service hosted on shared infrastructure, accessible via the internet, accessed via an account, and used to store or process organisational data. This update is outlined clearly in the Cyber Essentials v3.3 documentation.

    If your business uses it and company data flows through it, it is in scope. Microsoft 365, Google Workspace, your CRM, your accounting platform, your file sharing tools, your HR system. Previous versions allowed some ambiguity that let businesses argue certain services were out of scope. That argument no longer holds. The new Cyber Essentials v3.3 designation closes these gaps.

    What This Means in Practice

    The practical step is to build a cloud service inventory before your assessment. List every service accessed with a business email or company account. For each one, confirm that MFA is enabled, that access controls are appropriate, and that the service is included in your scope statement as required by Cyber Essentials v3.3, ensuring no service is missed.

    3. The 14-day patching rule is now an auto-fail. High-risk and critical security updates, those with a CVSS v3 base score of 7 or above, must be applied within 14 days of release. Two new auto-fail questions, A6.4 and A6.5, mean that failure to meet this requirement results in an automatic assessment failure. These specifics stem from the new Cyber Essentials v3.3 guidance.

    This applies across all devices and software in scope: operating systems, firmware, browsers, plugins and applications. If your patching process is informal or relies on users accepting update prompts, you need a structured approach before your assessment. A managed IT provider with centralised patch management can enforce this consistently. Maintaining Cyber Essentials v3.3 patching standards gives your organisation the best chance at passing.

    What Catches Businesses Out

    Beyond the three headline changes, several areas consistently trip up businesses. Many common issues stem from misinterpreting Cyber Essentials v3.3 scope and requirements.

    Scope that excludes end-user devices. A scope that does not include laptops, desktops, tablets or phones used to access organisational data is not acceptable under v3.3. If your staff use devices to access business email, files or cloud services, those devices are in scope. This includes BYOD arrangements where personal devices access company systems—a non-compliance with Cyber Essentials v3.3.

    Social media accounts. Cyber Essentials v3.3 treats business social media accounts, including LinkedIn, Facebook and X, as cloud services. If your marketing team logs into these accounts with a business email, you must enable MFA to protect your assessment. The rules were clarified in Cyber Essentials v3.3, so businesses must review every account accordingly.

    Unsupported operating systems. Devices running operating systems past end of support, including Windows 10 without ESU, fail the secure configuration and patching requirements. If your estate includes machines that you cannot patch, you need to upgrade them, replace them, or formally exclude them from scope with documented network segregation. Cyber Essentials v3.3 helps you handle these systems properly.

    Admin account hygiene. Assessors check whether you enforce MFA on administrator accounts, limit admin privileges to the people who need them, and use separate admin and standard accounts. Shared admin accounts without MFA are a common failure point. These rules are specifically included in the Cyber Essentials v3.3 assessment process.

    Incomplete evidence. Even when the right controls are in place, businesses can struggle to prove it during assessment. Screenshots, policy records, patch reports, MFA settings and scope details all need to be clear, current and consistent. If the evidence does not match the answers given in the assessment, it can delay certification or lead to follow-up questions.

    How to Prepare for a v3.3 Assessment

    Start with three exercises. First, build your cloud service inventory and confirm MFA status on every service. Second, run a patching audit to confirm you can evidence 14-day compliance for critical updates. Third, review your scope statement to ensure it covers all devices and cloud services that handle organisational data. These actions are vital for Cyber Essentials v3.3 readiness.

    If you hold Cyber Essentials certification through Unite, we review your environment against v3.3 requirements before your assessment begins. If you are certifying for the first time, we run a readiness check that identifies gaps and helps you close them before your assessment account is created. This process is central to a successful Cyber Essentials version 3.3 certification journey.

    As an IASME certification body, The Unite Group assesses businesses against the Cyber Essentials scheme directly. We understand how assessors interpret the requirements because we are the assessors. If your renewal is coming up or you want to certify for the first time under v3.3, contact us for a readiness review. Make sure you are fully prepared for Cyber Essentials v3.3 assessment changes.

  • Making Tax Digital April 2026: What Your IT Setup Needs to Be Ready

    Making Tax Digital April 2026: What Your IT Setup Needs to Be Ready

    Making Tax Digital for Income Tax went live on 6 April 2026. If you are a sole trader or landlord with gross income above £50,000, you are now required to keep digital records and submit quarterly updates to HMRC using compatible software. The threshold drops to £30,000 from April 2027 and £20,000 from April 2028.

    Every accountancy firm in the country has written about the tax side. What almost nobody is covering is the IT infrastructure side. MTD does not just require new software. It requires reliable broadband, secure file storage, compatible devices, proper backup, and an email setup that can handle sensitive financial data safely. If you currently rely on a personal laptop, a free email account and a filing cabinet, use MTD as the trigger to sort out your IT setup.

    What MTD Requires From Your IT

    HMRC requires three things: digital record-keeping using compatible software, quarterly submissions via a digital link to HMRC, and a year-end tax return filed through the same system. Paper records alone are no longer sufficient.

    In practice, this means you need software that is MTD-compatible, HMRC maintains a list of approved providers, a device that can run that software reliably, an internet connection stable enough to submit quarterly without disruption, and a way to store financial records digitally and securely.

    If you are using a spreadsheet for record-keeping, you also need bridging software that creates the digital link to HMRC. The spreadsheet itself does not connect directly.

    The IT Checklist Your Accountant Will Not Give You

    Your accountant will help you choose MTD-compatible software and set up quarterly reporting. They are unlikely to check whether your IT setup can support it. That is where the gaps appear.

    Reliable broadband. Quarterly submissions have fixed deadlines, 7th of the month after each quarter end. If your broadband drops out on submission day, you risk penalty points. If you work from multiple sites or from home, check that every location has sufficient connectivity. Businesses still running on legacy broadband should consider whether SoGEA or a dedicated business line is more appropriate.

    A device that is current and secure. MTD software runs on laptops, desktops and in some cases tablets. The device needs to be running a supported operating systemwith current security updates. A Windows 10 machine past end of support, without ESU, is an unpatched device handling financial data. That is a risk to your records and a red flag if HMRC or your insurer ever asks questions.

    Secure file storage. Digital records need to be stored securely and accessibly. A folder on your desktop is not secure storage. Cloud storage through Microsoft 365, OneDrive or SharePoint, with appropriate sensitivity labels and access controls gives you secure, backed-up, accessible storage that meets the spirit of digital record-keeping.

    Email security. You will exchange financial information with your accountant, HMRC and potentially clients via email. If you are using a free personal email account, Gmail, Yahoo, Outlook.com, for business correspondence containing National Insurance numbers, income figures and tax records, you have no control over data protection, no audit trail, and no recourse if the account is compromised. A business email account with MFA enforced is the minimum standard.

    Backup. HMRC expects you to maintain digital records for at least five years. If your device fails, is stolen, or is hit by ransomware, those records need to be recoverable. A proper backup strategy covering your financial records, whether stored locally or in the cloud, is essential. If you have never tested a restore, now is the time.

    What Happens If You Are Not Ready

    HMRC has confirmed a soft landing for the first year. HMRC will not apply penalty points for late quarterly submissions to the April 2026 cohort during 2026/27.But this grace period does not extend to late tax returns, due 31 January 2028 for the 2026/27 year, or late payments.

    From 2027/28 onwards, the penalty regime applies in full. Each missed quarterly deadline earns a penalty point. Four points within two years triggers a £200 fine. Late payments attract escalating penalties from day 16 after the due date.

    The grace period is time to get your systems right, not time to ignore the requirement.

    MTD Is a Trigger, Not Just a Tax Change

    For many sole traders, landlords and small partnerships, MTD is the first time their IT setup faces formal external requirements. It forces questions that should have been asked earlier: is my data backed up? Is my device secure? Am I storing financial records in a way that is accessible, auditable and protected?

    If the answer to any of those is unclear, MTD is the trigger to fix it. Businesses that treat this as both an IT project and a tax project will strengthen their position for HMRC compliance, insurance renewals, client confidence and day-to-day resilience.

    Get Your IT MTD-Ready

    If you are not sure whether your current setup supports MTD, or you want help putting the right infrastructure in place, contact The Unite Group. We help businesses across the North East with managed IT services that cover secure email, cloud storage, device management, backup and broadband, everything MTD demands from your IT, handled properly.

  • Windows 10 in 2026: ESU vs Upgrade vs Replace for UK SMEs

    Windows 10 in 2026: ESU vs Upgrade vs Replace for UK SMEs

    Windows 10 reached its end of support on 14 October 2025, but many organisations are already planning for Windows 10 end of support 2026 as they consider their next steps. Microsoft no longer provides free security updates for any Windows 10 device. If your business still has machines running Windows 10, you have three options: pay for Extended Security Updates (ESU) as a temporary measure, upgrade eligible machines to Windows 11, or replace hardware that cannot make the jump. Doing nothing means running unpatched systems that become more vulnerable with every month that passes.

    What Extended Security Updates Actually Give You

    ESU is a paid subscription that continues delivering critical and important security patches for Windows 10 devices after end of support. It does not include new features, design changes, or general technical support. It is a security-only stopgap.

    Year 1 (October 2025 to October 2026) costs approximately £60 per device. Year 2 doubles to around £120 per device. In year 3 doubles again to around £240. You cannot skip years, so if you start in Year 2, you must pay for Year 1 as well. The total three-year cost per device reaches roughly £420.

    Devices must be running Windows 10 version 22H2 to qualify. Earlier versions need updating before ESU can be activated.

    ESU makes sense for businesses with a small number of devices that cannot yet be upgraded, typically because of legacy software dependencies or a hardware refresh cycle that extends into 2027. It buys time. It does not solve the underlying problem.

    When Upgrading to Windows 11 Is the Right Move

    If a device meets Windows 11’s hardware requirements, upgrading is free for licensed Windows 10 users and is the most cost-effective long-term option.

    The key hardware requirements are a TPM 2.0 chip, Secure Boot capability, and a supported processor. Most business laptops and desktops purchased from 2019 onwards meet these requirements. Machines older than that typically do not.

    To check your estate, run the Microsoft PC Health Check tool on each device or use a centralised tool like Intune to assess compatibility across all machines at once. This gives you a clear picture of how many devices can upgrade in place and how many cannot.

    Upgrading in place preserves applications, files and settings. For most users, the transition is straightforward, but testing any specialist or line-of-business software against Windows 11 before rolling out across the team is worth the time.

    When Replacement Is the Only Practical Option

    If a device fails the Windows 11 compatibility check, particularly on the processor or TPM requirement, it cannot be upgraded. ESU extends its life temporarily, but you are paying £60+ per year per device for a machine that is already at the end of its useful life.

    For devices over five years old, replacement is usually more cost-effective than ESU once you factor in declining performance, battery degradation, increased failure rates and the cumulative ESU cost. A new business laptop running Windows 11 Pro costs roughly £400 to £700 depending on specification.

    Replacement does not have to happen all at once. A phased approach, replacing the oldest or most critical machines first and scheduling the rest across two or three quarters, spreads the cost and reduces disruption.

    A Simple Decision Framework

    For each Windows 10 device in your business, ask three questions.

    Can it run Windows 11? Check hardware compatibility. If yes, schedule the upgrade. If no, move to the next question.

    Does it run software that requires Windows 10? If yes, ESU buys time while you work with the software vendor on Windows 11 compatibility. If no, move to the next question.

    Is the device less than four years old and performing well? If yes, ESU for one year while you plan a phased replacement may make sense. If no, replace it.

    What Happens If You Do Nothing

    After October 2026, ESU Year 1 expires and consumer devices stop receiving any patches at all. Businesses on the enterprise ESU programme can extend to October 2028, but at escalating cost.

    Running unpatched Windows 10 devices creates real risk. New vulnerabilities discovered after your ESU coverage ends will not be fixed. Attackers specifically target end-of-life operating systems because they know patches are not coming. Cyber insurers ask about operating system currency during underwriting, and unpatched devices may affect your coverage.

    The Windows Server 2016 end of support deadline in January 2027 creates a similar pressure point for server infrastructure. If your business has both ageing desktops and ageing servers, planning both transitions together is more efficient.

    Get a Device Estate Audit

    If you are not sure which devices can upgrade, which need replacing, and how to plan the rollout without disrupting your team, contact The Unite Group for a device estate audit. We will assess every machine, recommend the right path for each, handle procurement for any replacements, and deliver them configured and ready to use as part of your managed IT services.

  • Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For

    Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For

    If your cyber insurance renewal is approaching, the application will look different from last time. Insurers have moved beyond generic questionnaires.They now ask detailed questions about your security controls. They also expect clear proof that these controls are active, enforced, and tested. A verbal confirmation that you “have MFA” is no longer enough.

    For SMEs, this shift can feel overwhelming. The questions reference tools and processes that your team may not manage directly, and assembling the evidence often falls between your IT provider and your internal admin with no clear owner. The result is a last-minute scramble, higher premiums, or in some cases, declined coverage.

    This blog explains what UK cyber insurers ask for in 2026. It also outlines the evidence needed for each requirement and how to build a proof pack before your renewal.

    What Insurers Are Asking For in 2026

    Underwriting has become technical. Carrier applications and renewal questionnaires now routinely cover six areas, and they want evidence for each.

    Multi-factor authentication. Insurers want to see MFA enforced on email, remote access, VPN and all administrative accounts. Partial coverage (MFA on email but not on remote desktop, for example) is specifically flagged. Microsoft reports that MFA blocks over 99% of account compromise attacks, which is why it tops every insurer’s checklist.

    Endpoint detection and response. Traditional antivirus no longer satisfies underwriters. They expect EDR or managed detection and response running on all endpoints, with evidence of 24/7 monitoring and active response capability. If you use Huntress Managed EDR, your provider dashboard shows deployment coverage, alert history and response timelines, all of which map directly to what insurers ask for.

    Backup and recovery. Insurers ask if you have backups in place, whether you keep them isolated or immutable so ransomware cannot encrypt them, and if you test restores regularly. If you have never tested a backup, insurers will not consider it reliable.

    Incident response plan. A written incident response plan with named contacts, defined escalation steps and evidence that it has been tested (even a simple tabletop exercise) is now a standard underwriting requirement. Insurers often ask for the date of the last test and any remediation actions that followed.

    Security awareness training. Insurers want evidence that staff receive regular training and that phishing simulations are part of the programme. A single annual session no longer satisfies most carriers. Managed security awareness training with monthly modules and automated reporting gives you exactly the documentation they expect.

    Patching and vulnerability management. Carriers ask about your patching cadence for critical vulnerabilities. Insurers expect you to apply critical patches within 14 to 30 days. They also expect you to remove end-of-life software or carry out a formal risk assessment.

    How to Build the Evidence Pack

    Start assembling documentation 60 to 90 days before your renewal date. Rushing this in the final week leads to gaps, and gaps lead to follow-up questions, higher premiums or declined coverage.

    For each of the six areas above, prepare a simple evidence file. This should include screenshots of MFA policies and EDR deployment reports. It should also cover backup test logs with dates and a copy of your incident response plan. Include training reports, phishing simulation results, and patch management reports showing update frequency.

    If your IT provider manages these controls for you, ask them to compile this pack as part of their service. A good managed IT provider should be able to produce most of this from their existing dashboards and reporting tools.

    Does Cyber Essentials Help with Insurance?

    Yes. Holding Cyber Essentials certification demonstrates that your business meets a government-backed baseline of security controls. Many UK insurers recognise it as a positive signal during underwriting, and some specifically ask whether you hold it.

    Cyber Essentials does not replace the evidence pack, but it covers key areas such as access control, patching, malware protection, and secure configuration. It also gives insurers confidence that these basics are formally verified rather than self-declared.

    The Cost of Getting This Wrong

    Businesses that cannot provide adequate evidence at renewal face three outcomes: significantly higher premiums, reduced coverage with broader exclusions, or outright refusal. In a market where the Cyber Security and Resilience Bill is increasing regulatory expectations across supply chains, having your insurance declined creates a compounding problem.

    The controls insurers ask about are the same controls that protect your business from the incidents insurance is designed to cover. Investing in them reduces your premium and reduces your risk at the same time.

    Get Your Evidence Pack Ready Before Renewal

    If your renewal is coming up and you are not sure whether your current setup meets insurer expectations, contact The Unite Group for an insurance readiness audit. We deliver every control insurers ask about, from managed EDR and security awareness training to backup management and incident response support, and we can assemble your evidence pack as part of our managed IT service.

  • 2G Switch-Off: Why UK Businesses Should Start a Device Audit Now

    2G Switch-Off: Why UK Businesses Should Start a Device Audit Now

    UK mobile network operators will switch off their 2G networks between 2029 and 2033. The 3G switch-off is already nearly complete, with most operators finishing by early 2026. DSIT published formal guidance on 24 March 2026 confirming the timeline and urging businesses to identify affected devices well ahead of the shutdown.

    The deadline feels distant, but the audit should not wait. Many SMEs have devices, SIMs and connected equipment running on 2G that they are not aware of. The businesses that identify these now have time to plan upgrades on their own terms.

    The ones that leave it until the final year face the same last-minute scramble the PSTN switch-off is already creating.

    Why 2G Matters More Than You Think

    Most smartphones sold in the last five years support 4G and 5G. For handsets, the switch- off will be invisible to most users. The problem sits with older devices and connected equipment that was never designed to move beyond 2G.

    Business mobiles issued three or four years ago to warehouse staff, drivers or site workers may still be basic feature phones running on 2G. Company-issued handsets are often replaced less frequently than personal phones, particularly for roles where a smartphone is not needed.

    Beyond handsets, many businesses have equipment that connects over 2G without anyone thinking about it. Vehicle trackers in fleet vans, IoT sensors for temperature monitoring, alarm communicators that fall back to 2G when broadband fails, agricultural monitoring devices, personal safety alarms, and older EPOS terminals with SIM-based connectivity all potentially rely on 2G.

    What to Audit in Your Business

    Walk through your operations and identify every device that uses a mobile connection. The categories most SMEs miss are listed here.

    Staff handsets. Check whether any company-issued phones are 2G-only. Look for “2G” or “E” on the signal indicator. If the phone never shows “4G” or “5G”, it will stop working when 2G is switched off.

    Vehicle and fleet trackers. GPS tracking devices in vans, trucks or company vehicles often use 2G to transmit location data. Check with your tracking provider whether the hardware supports 4G.

    Alarm systems. Some intruder and fire alarm communicators use 2G SIMs as a backup path when the primary broadband connection fails. This is separate from the ISDN/PSTN switch-off issue, which affects landline-connected alarms. Check with your alarm monitoring provider.

    IoT and environmental sensors. Temperature monitors in cold storage, water leak sensors, air quality monitors and similar connected devices may use 2G or 3G SIMs. These are often installed once and forgotten until they stop reporting.

    Personal safety devices. Lone worker alarms and personal safety pendants used by staff working remotely or in high-risk environments may depend on 2G to contact monitoring centres.

    Payment terminals. Older mobile card machines with SIM-based connectivity may still fall back to 2G in areas with weak 4G coverage.

    The Timeline and What It Means

    The government’s confirmed timeline is 2029 to 2033 for 2G switch-off across all operators. Each network will set its own schedule within that window. VMO2 withdrew 2G roaming services in October 2025 and completed its 3G switch-off by early 2026. Other operators are expected to publish their 2G timelines during 2026 and 2027.

    For businesses, the practical implication is straightforward. Devices purchased or installed today should support 4G at minimum. Any procurement decisions made from now on should exclude 2G-only equipment. And existing 2G devices should be catalogued so they can be replaced in phases rather than all at once under deadline pressure.

    Start the Audit Before It Becomes Urgent

    The ISDN switch-off has shown what happens when businesses delay infrastructure migration. Engineers become scarce, equipment availability tightens, and costs increase. The 2G timeline is longer, but the principle is the same: businesses that act early have more options and lower costs.

    If you need help auditing your mobile estate, identifying 2G-dependent devices, or planning replacements, contact The Unite Group. We manage business communications and connectivity across the North East, and we can assess your device fleet alongside your broader telecoms infrastructure.

  • 10 Power Automate Workflows Every SME Office Can Set Up This Quarter

    10 Power Automate Workflows Every SME Office Can Set Up This Quarter

    If your business uses Microsoft 365, you already have access to Power Automate. Most SMEs never touch it. The tool sits inside your existing subscription, capable of automating repetitive admin tasks that eat into your team’s working day, but nobody has time to explore what it actually does.

    Power Automate connects the Microsoft 365 apps your team already uses (Outlook, Teams, SharePoint, Excel, Forms) and lets you build automated workflows between them without writing code. An invoice arrives by email and the system routes it for approval automatically.A new starter joins and their onboarding checklist populates in Teams. A contract renewal date approaches and the account manager gets a reminder. These are not complex IT projects. Most take under an hour to set up using built-in templates. Here are ten that deliver immediate time savings for a typical SME office.

    Approvals That Do Not Live in Someone’s Inbox

    1. Expense approvals via Teams. When a staff member submits an expense (through a SharePoint list or Microsoft Form), Power Automate sends an approval request to their manager in Teams. The manager approves or rejects with one tap.The system logs the result automatically and sends the employee a confirmation email. No chasing, no lost receipts, no paper forms.

    2. Document sign-off. Upload a document to a specific SharePoint folder and Power Automate triggers an approval request to the designated reviewer. Once approved, the file moves to an “Approved” folder automatically. Useful for policies, proposals, marketing materials, or anything that needs a second pair of eyes before it goes out.

    3. Purchase order approvals. Route purchase requests through a defined approval chain based on value. Orders under a set threshold get approved by a team lead. Orders above it escalate to a director. The entire trail is logged in SharePoint.

    Onboarding and Off-boarding

    4. New starter onboarding checklist. When a new employee is added to your HR list (or a Microsoft Form is submitted by the hiring manager), Power Automate creates a task list in Planner or Teams with every onboarding step: equipment request, account setup, induction booking, policy acknowledgements. Each task is assigned to the relevant person with a due date.

    5. Leaver process trigger. When someone’s leaving date is entered, the flow notifies IT to schedule account deactivation, reminds their manager to reassign shared files, and sends HR a checklist for final paperwork. This reduces the risk of ex-employees retaining access to systems, which is a common security gap flagged during Cyber Essentials assessments.

    Finance and Admin Automation

    6. Invoice payment reminders. Connect Power Automate to an Excel tracker or SharePoint list of outstanding invoices. When a payment date arrives, the flow sends a polite reminder email to the client and posts a notification in your finance Teams channel. No more manually checking spreadsheets every morning.

    7. Contract renewal alerts. Store contract end dates in a SharePoint list. Power Automate sends an alert 90 days, 30 days and 7 days before each renewal, giving your team time to review terms, renegotiate or switch providers. This is especially useful for software licences, insurance policies and supplier agreements.

    Communication and Reporting

    8. Weekly team summary from Forms. Set up a recurring Microsoft Form for weekly updates (project status, blockers, wins). Power Automate collects responses every Friday and compiles them into a single Teams message or email to the manager. Replaces the meeting that could have been an email.

    9. Customer enquiry routing. When a contact form submission arrives (via Microsoft Forms or a connected web form), Power Automate sends it to the right person based on the enquiry type, logs it in a SharePoint list, and sends the customer an acknowledgement email within seconds.

    10. Teams channel notifications for key events. Set up Teams notifications for important activity across your M365 environment, such as large external file shares, SharePoint site membership changes, or critical Planner tasks becoming overdue.This keeps your team aware without relying on people checking dashboards.

    A Note on Governance

    Shadow flows can become a problem if everyone creates automations without oversight. Set clear ownership for each flow, document what it does and who maintains it, and review active flows quarterly. If a flow breaks or a staff member leaves, someone needs to know it exists. Your managed IT provider can help set up a governance framework alongside the automations themselves.

    Where to Start

    Pick one workflow that solves a real, daily frustration for your team. Set it up using a Power Automate template, test it, and let it run for two weeks. Once people see admin tasks disappearing, the appetite for more automation follows naturally.

  • How to Create a Cyber Incident Response Plan for Your SME

    How to Create a Cyber Incident Response Plan for Your SME

    Most small businesses know a cyber attack could happen to them. Far fewer have a written plan for what to do when it does.

    The result is predictable. When something goes wrong, whether it is a ransomware notification, a compromised email account, or unusual activity on the network, there is confusion. Who makes the call? Do you know who contacts the IT provider? Who tells customers? Decisions get made under pressure, and the wrong ones make the damage worse.

    A cyber incident response plan does not require a dedicated security team or a 50-page document. It needs to answer a handful of critical questions in advance so your business can respond quickly, limit damage and recover faster. Here is how to build one.

    What Counts as a Cyber Incident

    Before building a plan, define what triggers it. A cyber incident is any event that threatens the confidentiality, integrity or availability of your systems or data.

    Obvious examples include ransomware encryption, unauthorised access to email accounts, data breaches and phishing attacks that result in credential theft. Less obvious ones include a staff member losing an unencrypted laptop, finding unexpected admin accounts on your network, or discovering that someone has been forwarding company emails to a personal address.

    Your plan does not need to cover every scenario in detail. It needs to make clear that when something looks wrong, there is a defined process to follow rather than a scramble.

    The Five Steps Your Plan Should Cover

    A practical incident response plan follows five stages: prepare, identify, contain, recover and learn.

    1. Prepare. Assign roles before anything happens. Do you have a primary contact for your IT provider? Is it clear who has authority to shut down systems if needed? Who handles communication with customers or regulators? Write these names, phone numbers and responsibilities down. If one person is unavailable, name a backup.

    2. Identify. Define how incidents get reported internally. A simple rule works: if someone sees anything suspicious, they report it to a named person immediately, no judgement. That person contacts your IT provider or internal IT lead to assess whether it is a genuine incident. Speed matters here. The average attacker dwell time inside a compromised environment is 90 to 120 days.

    3. Contain. Once an incident is confirmed, the priority is stopping it from spreading. This might mean isolating an affected machine from the network, disabling a compromised account, or temporarily shutting down a system. Your IT provider should be leading this, but your plan should make clear who authorises these decisions internally.

    4. Recover. Restore affected systems from clean backups. Reset credentials. Verify that the threat has been fully removed before bringing systems back online. Document what happened and when.

    5. Learn. After recovery, review what went wrong, what went well and what needs to change. Update the plan based on what you learned. This step is the one most businesses skip, and it is the one that prevents the same thing happening again.

    Reporting Requirements Are Tightening

    Under the Cyber Security and Resilience Bill progressing through Parliament, organisations in scope will need to report cyber incidents within 24 hours, with a full report within 72 hours. Even if your business is not directly in scope, larger clients may require evidence that you have a documented incident response process as part of supply chain assurance.

    Having a plan already in place puts you ahead of the curve.

    Keep It Short, Test It Regularly

    The best incident response plans are short enough that people actually read them. One to two pages covering roles, contact details, the five steps and any specific instructions for your IT setup.

    Print a copy and keep it somewhere accessible. If your systems are encrypted by ransomware, a plan saved only on the network is useless.

    Test the plan at least once a year. Run a tabletop exercise: describe a scenario and talk through who does what. You will quickly find gaps, whether that is an out-of-date phone number, an unclear decision point or a step that nobody actually knows how to execute.

    You Do Not Have to Build This Alone

    If you want help creating an incident response plan that fits your business, or you want to make sure your current setup can detect and contain threats quickly, speak to The Unite Group about a managed security review. We work with SMEs across the North East to build practical, proportionate security processes backed by 24/7 monitoring and rapid response tools.

  • Phishing Attacks in 2026: What UK Businesses Still Get Wrong

    Phishing Attacks in 2026: What UK Businesses Still Get Wrong

    Phishing attacks remain the most common cause of cyber breaches in the UK. The government’s Cyber Security Breaches Survey found that 85% of businesses that experienced a breach identified phishing as the attack method. That figure has barely shifted in three years. What has changed is how the attacks look, how they arrive, and why email filters alone no longer catch them.

    For SMEs, the risk is straightforward. Phishing works because it targets people, not systems. And unless your team knows what to look for, a single click can give an attacker access to your email accounts, customer data or financial systems.

    Why Phishing Has Become Harder to Spot

    A few years ago, most phishing emails were easy to identify. Poor spelling, generic greetings, suspicious sender addresses. That is no longer the case.

    Attackers now use AI tools to generate phishing emails that match the tone, formatting and language of legitimate business communication. They research targets using LinkedIn, company websites and public data to craft messages that feel personal and relevant. A finance team member might receive what looks like a genuine invoice from a known supplier. A director might get a convincing request from what appears to be their bank.

    Beyond email, phishing has expanded into other channels. Voice phishing (vishing) uses phone calls, often spoofing real numbers, to pressure staff into sharing credentials or making payments. QR code phishing (quishing) embeds malicious links in printed materials or PDF attachments, bypassing email filtering entirely. SMS phishing (smishing) targets mobile devices where people tend to be less cautious.

    The Mistakes Businesses Keep Making

    Relying entirely on email filters. Filters catch a lot, but they are not infallible. AI-generated phishing emails are specifically designed to pass through automated detection. Filters should be a layer of defence, not the only one.

    Running training once a year. An annual awareness session does not change behaviour. Monthly, bite-sized training with simulated phishing tests is what actually builds recognition skills over time. Staff need to practise identifying threats in realistic conditions, not just sit through a slide deck.

    No clear process for reporting. If someone suspects a phishing email, do they know what to do? Many businesses have no defined process, and staff worry about looking foolish for flagging something that might be legitimate. A simple, blame-free reporting process catches threats faster and encourages vigilance.

    Assuming small businesses are not targeted. Attackers increasingly target SMEs because they tend to have weaker defences and less formal processes. Automated phishing campaigns do not discriminate by company size. If your email addresses are publicly listed, you are a target.

    What Actually Reduces Risk

    Effective phishing defence combines technical controls with regular staff training.

    On the technical side, ensure your email platform has modern anti-phishing protections enabled. If you use Microsoft 365, check that Safe Links and Safe Attachments are turned on. Make sure multi-factor authentication is active on every account, so that even if credentials are stolen, attackers cannot log in without a second factor.

    On the people side, invest in ongoing cyber security training that includes regular phishing simulations. This does not need to be time-consuming or expensive. Managed training platforms run automatically, track completion, and provide targeted follow-up for anyone who falls for a test. The data from simulations shows you exactly where your team’s weaknesses are.

    Create a clear internal process: if you receive a suspicious email, forward it to a designated address or flag it in your email client. Do not click, do not reply, do not forward it to colleagues to ask ‘does this look dodgy to you?’

    What to Do If Someone Clicks

    If a staff member clicks a phishing link or enters credentials on a suspicious page, act quickly. Change the affected passwords immediately. Check whether the compromised account has been used to send further phishing emails internally or to contacts. Review recent sign-in activity for anything unusual.

    If you work with a managed IT provider, report it to them straight away. Providers with proactive monitoring tools can isolate affected accounts and check for signs of deeper compromise before it spreads.

    The speed of response matters more than blame. Businesses that have a tested incident response process recover faster and limit damage. Businesses that do not often discover the breach weeks later, after significant harm has already been done.

    Phishing Prevention Starts with People

    Technical tools help, but phishing exploits human judgement. The businesses that handle it best are the ones where staff feel confident identifying threats and comfortable reporting them.

    If your team has not had structured phishing awareness training recently, or if you are unsure how your current defences measure up, talk to The Unite Group about managed security awareness training. We run phishing simulations and ongoing training programmes that fit around your team’s working day and give you clear data on where to focus.

  • Zero Trust Security for Small Businesses

    Zero Trust Security for Small Businesses

    Zero trust security, the unite group IT

    Zero trust is a security approach built on one principle: never trust anything automatically, always verify. Every user, device, and application must prove who they are and what they are allowed to access before being let in, every single time. There is no ‘inside the network means you are safe.’

    For years, zero trust was treated as an enterprise concept requiring dedicated security teams and six-figure budgets. That has changed. The tools most SMEs already use, particularly Microsoft 365, now include zero trust controls that can be switched on without buying anything new. If you have 10 to 50 people and you use cloud services, zero trust is not only relevant to your business; some of it is probably already within reach.

    Why the Old Approach No Longer Works

    Traditional security worked like a castle with a moat. Build a strong perimeter (firewall, VPN) and trust everything inside it. Once you were past the drawbridge, you could go anywhere.

    That model breaks down the moment your staff work from home, use personal phones, access cloud applications or share files externally. The perimeter no longer exists in any meaningful sense. Your data is everywhere: in Microsoft 365, on laptops in coffee shops, in shared folders accessible from any browser.

    Attackers know this. Phishing steals a set of credentials, and once inside, there is nothing stopping lateral movement across email, SharePoint, OneDrive and anything else that login has access to. The castle-and-moat model offers no protection once someone is through the door.

    Consider a common scenario: A staff member clicks a convincing phishing link and enters their Microsoft 365 password. Without zero trust controls, the attacker now has the same access as that employee: email, shared files, client data, internal Teams channels. If that person happens to have admin rights, the attacker has those too. In a zero trust environment, the stolen password alone is not enough. MFA blocks the login attempt. Conditional access flags the unfamiliar device or location. Even if the attacker gets past those layers, least-privilege access means they reach only what that specific role requires, not the entire business.

    Zero Trust Principles

    Strip away the frameworks and the jargon, and zero trust comes down to three things.

    Verify every access request

    Do not assume that because someone logged in this morning, they should still have access this afternoon. Instead, check who they are, what device they are using, where they are connecting from, and whether the access request makes sense.

    This is where multi-factor authentication becomes essential, but it goes beyond MFA into conditional access policies that evaluate context with every request.

    Give people only what they need

    This is least-privilege access. For example, if someone in marketing does not need access to the finance folder, they should not have it. Likewise, if an employee leaves or changes role, their permissions should be updated immediately rather than left open indefinitely. Most businesses discover they have far more shared access than they realised when they actually audit it.

    Assume a breach has already happened

    Design your systems as though an attacker is already inside. Segment access so that compromising one account does not hand over everything. Monitor for unusual behaviour, like a user logging in from two countries within an hour, or downloading thousands of files at midnight. This aligns with identity-based threat detection.

    Practical Steps for a Small Business

    You do not need a dedicated security operations centre to start applying zero trust. Here is where most SMEs should begin.

    Turn on conditional access in Microsoft 365

    If you have Microsoft 365 Business Premium, you already have the tools. Set up policies that require MFA, block sign-ins from risky locations, and ensure devices meet basic compliance standards before granting access.

    Audit your permissions

    Check who has access to what across SharePoint, OneDrive, Teams and any other shared systems. Remove access people no longer need. Set shared folders to restricted rather than open by default.

    Use separate admin accounts

    Anyone with administrative privileges should have a separate admin account that they only use for admin tasks. Day-to-day work should happen on a standard account. This limits the damage if a credential is compromised.

    Enable security defaults or conditional access policies

    Microsoft’s security defaults provide a baseline of zero trust controls at no extra cost. For more granular control, conditional access policies let you define specific rules based on user, device, location and risk level.

    Review access regularly

    Zero trust is not a one-time project. Schedule quarterly reviews of user permissions, admin accounts and access policies. When someone changes role or leaves the business, update their access on the same day.

    Require device compliance before granting access

    If you use Microsoft Intune (included with Business Premium), you can set policies that only allow access from devices that meet your security standards, such as having an up-to-date operating system, active antivirus and disk encryption enabled. A personal laptop that has not been patched in six months should not have the same access as a managed company device.

    Segment your network

    At a basic level, this means keeping your guest Wi-Fi separate from your business network. Visitors and personal devices should not sit on the same network as your servers, printers and business systems. Most modern routers support this, and it is one of the simplest ways to limit what an attacker can reach if they gain access through a less secure device.

    How Zero Trust Relates to Cyber Essentials

    If your business holds or is working toward Cyber Essentials certification, you are already aligned with some zero trust principles. Cyber Essentials requires access control, secure configuration and malware protection, all of which overlap with the zero trust model. Zero trust builds on that foundation. Where Cyber Essentials provides a baseline, zero trust extends it with continuous verification, conditional access and the assumption that no network location is inherently safe. The two work together, not in competition.

    Getting Started Without a Security Team

    Zero trust is a direction, not a destination. You do not need to implement everything at once. Start with MFA and conditional access. Audit your permissions. Enable basic monitoring. Each step reduces your attack surface. If you want help applying zero trust principles to your managed IT environment, speak to The Unite Group. We will review your current setup, identify the quick wins and build a practical roadmap that fits your business, not an enterprise framework.

  • ISDN Switch-Off Checklist: Every Device Your Business Needs to Migrate Before 2027

    ISDN Switch-Off Checklist: Every Device Your Business Needs to Migrate Before 2027

    All ISDN and PSTN services in the UK will be permanently switched off on 31 January 2027. An estimated six million businesses still rely on these legacy connections for phone systems, broadband or connected devices, and many have not started planning their migration. No new ISDN lines have been available since September 2023, Openreach is withdrawing remaining services region by region through 2026, and there will be no further extension.

    The replacement technology, VoIP and IP-based connectivity, is already well established and brings genuine improvements in flexibility, cost and reliability. But the transition is not as simple as swapping a handset. Businesses that only think about their phone system risk overlooking the alarms, payment terminals, lift phones and monitoring equipment that also depend on copper lines.

    At The Unite Group, we handle ISDN-to-IP migrations for businesses across the North East and beyond, covering phones, broadband and every connected device in between. This checklist is designed to help you audit your premises and identify everything that needs to move before the deadline.

    Your Room-by-Room Migration Checklist

    Walk through your premises and check every device that connects to a phone socket or ISDN line. Here is what to look for.

    Phone system

    If you are running a traditional PBX connected to ISDN30 or ISDN2 lines, it will stop working entirely. You need to move to a cloud-hosted phone system or, if your existing PBX supports it, add a SIP gateway to route calls over your broadband instead. Your existing phone numbers can be ported to the new system.

    Broadband

     If your internet connection runs over an ADSL line or FTTC broadband that depends on an active phone line, you will need to switch to SoGEA or FTTP (full fibre) where available. Check with your provider which options are available at your premises.

    Intruder alarm

    Many alarm systems use a phone line to call the monitoring centre when triggered. After the switch-off, that connection will not work. Contact your alarm provider to check whether your system is IP-compatible or needs replacing with one that communicates over broadband or 4G.

    Fire alarm

    Fire panel communicators that dial out over PSTN will fail. These need upgrading to IP-based or cellular communicators. Given the safety implications, this should be a priority rather than something left until the final months.

    Lift emergency phone

    Building regulations require lifts to have a working emergency phone. Most use an analogue phone line. After the switch-off, these need replacing with IP or GSM-based lift communicators. Speak to your lift maintenance provider about compatible options.

    Card payment terminals

    Older EPOS and card terminals that dial out over a phone line will stop processing payments. Most modern terminals use broadband or 4G connectivity, but if your terminal still has a phone cable connected, it needs replacing or upgrading.

    Fax machine

    If your business still uses fax (some legal and healthcare businesses do), physical fax machines connected to a phone line will stop working. Online fax services that send and receive via email are the practical replacement.

    Door entry and intercom systems

    Some door entry systems use phone lines to call internal extensions or mobile numbers. These need checking for IP compatibility.

    Building management systems (BMS) 

    HVAC monitoring, water treatment controls and similar systems sometimes phone home using analogue lines. Check with your building management provider.

    CCTV and remote monitoring

    Older CCTV systems that transmit footage via phone lines need upgrading to IP-based cameras and network video recorders.

    Telecare and health monitoring devices

    Pendant alarms and health monitoring equipment that use phone lines require urgent attention. BT has paused forced migrations for vulnerable customers, but replacement devices still need to be in place before the deadline.

    When to Start (and When It Gets Difficult)

    Migration is not something you can do in a week. A typical business needs to audit what it has, choose replacement solutions, order equipment, schedule installations and test everything. For most SMEs, the whole process takes two to four months when planned properly.

    As January 2027 approaches, demand for engineers, equipment and installation slots will spike. Businesses that leave it until the final quarter of 2026 risk delays, limited availability, and higher costs from providers under pressure to deliver.

    The sensible window for migration is now through the end of 2026. Starting earlier gives you time to test, resolve issues, and avoid the inevitable last-minute scramble.

    What Happens If You Miss the Deadline

    On 1 February 2027, every service still connected to the old copper phone network stops working. Phone lines go silent. Alarm systems lose their connection to monitoring centres. Card terminals stop processing payments. Broadband connections that depend on a phone line drop offline.

    There will be no extension. The infrastructure is being physically retired because it is too old and expensive to maintain. Ofcom reported a 45% increase in PSTN resilience incidents in 2024, underlining why the network is being replaced.

    Get a Free Migration Audit

    If you are not sure which devices in your business still rely on ISDN or PSTN, that is the first thing to find out. Contact The Unite Group for a free migration audit. We will walk through your setup, identify every affected device and service, and give you a clear plan for migrating everything before the deadline, including your phone system, broadband and connected equipment.