Category: Cybersecurity

Cybersecurity

Cybersecurity focuses on protecting computer systems from unauthorised access or being otherwise damaged or made inaccessible

At The Unite Group, we take cybersecurity extremely seriously. That is why we have produced a series of blogs educating you on the latest dangers and tips to protect yourself & your business.

Cybersecurity is a crucial thing to get right, it is not one you can take any risks with due to the implications it can have on your business. We have created blogs that give you information on the Cyber essentials certification, cyber essentials plus as well as good housekeeping to keep your business in order.

Use these blogs to learn how to keep your company and personal data safe in the world of cybercrime. If you have any cybersecurity needs then please do not hesitate to get in touch. We are able to get our clients through their Cyber Essentials Certification as an awarding body of this government-backed scheme.

If there are topics you would like to see us create content around then please just send us an email or give us a call and we will get these added for you. If you find our blogs useful please let us know. You can also follow all of our blogs and content on our social media pages.

The Unite group – Cybersecurity Blog – Because technology matters.

 

  • Out of Office, Out of Pocket: How UK Businesses Stop BEC and Invoice Fraud This Summer

    Out of Office, Out of Pocket: How UK Businesses Stop BEC and Invoice Fraud This Summer

    Invoice fraud prevention is a seasonal problem for most UK SMEs, and the worst season is summer. Two of the three approvers are out, one new starter is covering the inbox, and the finance lead’s out-of-office reply tells anyone who emails that they are walking the Camino until late August. June through August is when invoice fraud lands. It lands because the people who would normally spot it are not in the building.

    Invoice fraud prevention is less about new tools and more about closing the seasonal gaps in how your business approves changes when senior staff are away. The five controls below take less than a week to put in place and cover the most common scams we see hitting UK businesses through the summer holiday window.

    Why invoice fraud prevention gets harder in summer

    In the UK Cyber Security Breaches Survey 2025/26, phishing was the most disruptive type of incident for most businesses that experienced one. The technique itself is not seasonal. The success rate is.

    When the finance director is on a beach in Crete, an email from “the finance director” asking the bookkeeper to authorise an urgent supplier bank-detail change carries more weight, not less. The bookkeeper cannot easily check. The MD who would normally be CC’d is also away. The supplier has been a real supplier for years. The bank account change is the only thing that has moved, and that is the part nobody notices.

    This is the operational reality criminals are betting on, and they are right often enough to keep doing it.

    Control 1: A deputy matrix that covers approvals

    Most businesses have an out-of-office system for replying to emails. Few have one for approvals. Build a one-page deputy matrix before staff start booking holiday. Three columns: the action that needs approval, the primary approver, the named deputy.

    Cover at minimum:

    • Supplier bank-detail changes
    • New supplier setup
    • Payments above a defined threshold
    • Payroll changes
    • Refunds above a threshold

    The matrix lives in finance, in HR and in your shared drive. Every approver knows who their deputy is, in writing, before the first holiday week. Adapting the 30-second social engineering script we published in May gives the deputy a working escalation pattern when something feels wrong.

    Control 2: Out-of-office replies that do not leak

    The default out-of-office reply tells the world the sender is away, for how long, who is covering, and often where they are. That is enough for a convincing impersonation attempt.

    A safer pattern says only what the recipient needs to know: that the message has been received, when a reply can be expected, and a generic team inbox or covering colleague for urgent matters. No travel details, or external phone numbers and no private mobile.

    The same rule applies to LinkedIn updates and team-wide announcements. Holiday plans do not need to be public.

    Control 3: A callback rule for any bank-detail change

    This is the single highest-impact control on the list. Any change to supplier banking details triggers a callback to a known phone number for that supplier, never to the number in the latest email signature. The known number lives in your purchase ledger, not in the email thread requesting the change.

    If the supplier cannot be reached, the change waits. The cultural piece matters as much as the rule: nobody gets blamed for delaying a payment to verify it. That is the no-shame part. Once it is in the cyber incident response plan and the team knows it applies to everyone including the MD, the rule holds.

    Control 4: Conditional access for travel windows

    If your team uses Microsoft 365 and your licences include conditional access, you can tighten sign-in rules during defined travel windows. Block sign-ins from countries staff are not in, require a fresh MFA prompt from new locations, and flag impossible-travel events for review.

    This sits naturally next to the controls described in our Cyber Essentials v3.3 guide. It is also the control that catches account takeover attempts before they reach finance at all.

    Control 5: A short briefing for the team

    Before the holiday season starts, send a five-bullet email to the people who handle money and inboxes. Cover the deputy matrix, the OOO rule, the callback rule, and the two scams to expect: a bank-detail change for a real supplier, and a same-day urgent payment request from a senior approver who is travelling.

    The briefing does not need to be long. It does need to be in writing, so the team can point to it when they apply the rules.

    What this looks like by mid-July

    A business that has done the five controls above answers a different question in August. Instead of “did we just send GBP18,000 to the wrong account”, the question becomes “should we approve this change today or wait for our finance lead to confirm on Monday”. That is the same conversation, with one difference. The money is still in the account.

    If you would like us to walk through your summer cover and tighten the gaps, book a 30-minute summer-readiness review and we will produce a deputy matrix, a callback rule and conditional access settings tailored to your business before the July rota change.

  • AI Governance: The 10-Point Policy You Need Before Staff Use AI Tools at Work

    AI Governance: The 10-Point Policy You Need Before Staff Use AI Tools at Work

    Your staff are already using AI tools. Whether it is ChatGPT for drafting emails, an AI image generator for social media, or a browser extension that summarises documents, generative AI has entered most workplaces without a formal decision being made about it. The question is not whether your team uses AI. It is whether you have any control over how they use it, what data they put into it, and what risks that creates for your business. Consulting an AI governance policy SME can help ensure you manage these challenges effectively.

    Most SMEs do not have an AI policy. They do not need a 30-page governance framework either. What they need is a clear, practical set of rules that staff understand and that protects the business from the most common risks: data leakage, compliance failures, reputational damage and over-reliance on unverified outputs.

    Here are ten points that cover what most SMEs need.

    The 10-Point AI Acceptable Use Policy

    1. Name the tools that are approved.

    List the AI tools your business sanctions for work use. If you use Microsoft 365 Copilot or another enterprise AI product, make it clear that this is the approved option. Unapproved tools should require sign-off before use.

    2. No sensitive data in public AI tools.

    Staff must not enter client data, financial information, employee records, passwords, contract details or any personally identifiable information into public AI tools like ChatGPT, Gemini or Claude. These tools may store or use inputs for training unless enterprise agreements say otherwise.

    3. All AI-generated content must be reviewed before use.

    AI outputs can contain factual errors, fabricated references, outdated information or biased language. Any content generated by AI that will be sent externally, published, or used in a decision must be reviewed and verified by a human before it goes out.

    4. AI must not be used for regulated decisions.

    Do not use AI to make hiring decisions, assess employee performance, approve financial transactions or take any action that has legal or regulatory implications without explicit senior approval and legal review.

    5. Declare AI use when required.

    If a client, regulator or procurement process asks whether AI was used in producing work, staff must answer honestly. Misrepresenting AI-generated work as entirely human-produced creates reputational and contractual risk.

    6. Do not install AI browser extensions or plugins without IT approval.

    Many AI tools operate as browser extensions that can read page content, access email, and interact with cloud applications. These should go through the same approval process as any other software installation. This connects directly to your shadow IT controls.

    7. Log AI tool usage for compliance.

    Maintain a simple register of which AI tools are used, by whom, and for what purpose. This does not need to be complex. A shared spreadsheet reviewed quarterly is enough to maintain visibility.

    8. Review supplier AI use.

    If your suppliers or subcontractors use AI to process your data or deliver services, understand what tools they use and what data they access. Include AI use in your supplier security questionnaire.

    9. Train staff on AI risks.

    Include a short AI safety module in your security awareness programme. Staff should understand the data leakage risk, the accuracy limitations, and the importance of not trusting AI outputs without verification. If you use managed security awareness training, discuss adding AI-specific scenarios with your provider.

    10. Review the policy every six months.

    AI tools and capabilities change fast. A policy written today may not cover the tools your team is using in six months. Build in a scheduled review rather than treating it as a one-off document.

    Why This Matters Even If You Do Not Sell AI Services

    This is not about whether your business offers AI products. It is about whether your staff use AI tools in the course of their work, and the answer is almost certainly yes. Without a policy, you have no visibility into what data is leaving your organisation, no standard for quality control on AI-generated outputs, and no defence if something goes wrong.

    The NCSC’s AI threat assessment highlights that AI is accelerating the speed and sophistication of cyber attacks, including phishing and social engineering. But the internal risk, staff pasting sensitive data into public AI tools, is just as real and far more common.

    Make It Simple, Make It Visible

    Print the 10 points. Pin them in the office. Include them in your onboarding pack. Refer to them in team meetings. A policy only works if people know it exists and understand why it matters.

    If you want help drafting an AI acceptable use policy tailored to your business, or you want to review how AI tools interact with your Microsoft 365 environmentcontact The Unite Group. We will help you put practical guardrails in place without slowing your team down.

  • Social Engineering in 2026: A 30-Second Script Your Team Can Use Today

    Social Engineering in 2026: A 30-Second Script Your Team Can Use Today

    The phishing email is no longer the only threat your team needs to worry about. The reality is that social engineering UK business threats are rapidly evolving. Social engineering attacks in 2026 are multi-channel: they start with a Teams message, follow up with a phone call from a spoofed number, and close with an email that references both previous contacts. The grammar is flawless. The caller sounds like someone your team recognises. The request feels urgent but reasonable.

    Vishing (voice phishing) volumes surged over 440% between 2024 and 2025. IT helpdesks are the primary target in 42% of attacks. Finance departments account for over 30% of successful breaches. These are not mass-blast campaigns. They are targeted, researched and designed to exploit the way your team naturally responds to authority and urgency. Technical controls help, but they cannot catch a convincing phone call. What your team needs is a simple, repeatable process they can follow when something feels off. That process is three words: Stop, Verify, Escalate.

    The 30-Second Script

    This script works for reception staff, finance teams, office managers, anyone who handles incoming requests by phone, email or Teams.

    Stop. Pause before acting on any request that involves money, credentials, access changes or sensitive information. Urgency is the attacker’s primary tool. A legitimate request can wait 60 seconds.

    Verify. Contact the person who supposedly made the request using a known, trusted channel. Do not reply to the email, return the call to the number displayed, or respond to the Teams message. Instead, look up the person’s number independently and call them directly. If they confirm the request, proceed. If they do not, you have just prevented an attack.

    Escalate. If you cannot verify the request, or if the caller pressures you not to check, escalate to your line manager or IT team immediately. No legitimate colleague or supplier will object to a verification step. Resistance to verification is itself a red flag.

    Print this script. Pin it next to every phone. Include it in your onboarding pack. The value is in its simplicity: three steps that any member of staff can follow without needing technical knowledge.

    What Multi-Channel Attacks Look Like

    Understanding the pattern helps your team recognise it. Here is how a typical multi-channel social engineering attack unfolds in 2026.

    Stage one: the setup. Your finance officer receives a Teams message from what appears to be the managing director’s account. The message says: “I need you to process a payment urgently. I will call you in five minutes to explain.” The message references a real project or client name, which the attacker found on LinkedIn or the company website.

    Stage two: the call. Five minutes later, a phone call arrives. The caller ID shows the managing director’s mobile number (spoofed). The voice sounds plausible. The caller explains that a supplier payment needs processing today to avoid a penalty. They provide bank details and ask for immediate action.

    Stage three: the follow-up. An email arrives from a slightly misspelled domain confirming the bank details “for your records.” The email includes a PDF invoice that looks legitimate. At every stage, the attack builds credibility by referencing the previous contact. Each touchpoint makes the next one harder to question. The entire sequence takes under 15 minutes.

    The Stop, Verify, Escalate script breaks this chain at stage one. The finance officer pauses, calls the managing director on their known mobile number, and discovers they never sent the Teams message.

    Where to Apply the Script

    The script applies to any request that involves transferring money or changing bank details, resetting passwords or MFA, granting system access or sharing login credentials, sending sensitive files or client data externally, and making urgent changes to payroll or supplier records.

    For payment and bank detail changes specifically, add a standing rule: no bank detail change is processed without a verbal confirmation from a known contact at the requesting organisation. This single control blocks the majority of business email compromise attacks.

    Building a No-Blame Culture

    The script only works if staff feel safe using it. If someone verifies a request and it turns out to be legitimate, they should never be criticised for checking. If someone escalates a suspicious call that turns out to be genuine, they should be thanked.

    Attackers exploit hierarchy. A junior staff member is less likely to question a request that appears to come from a director. Make it explicit: everyone in the business has permission to verify any request, regardless of who it appears to come from. Include this in your security awareness training and reinforce it in team meetings.

    Make It Part of Your Security Programme

    The script is a starting point. For ongoing protection, pair it with regular security awareness training that includes simulated phishing and vishing exercises. Test your team with realistic scenarios so that Stop, Verify, Escalate becomes a reflex rather than something they have to remember under pressure.

    If you want help rolling out the script, training your team, or setting up simulated exercises, contact The Unite Group. We deliver managed cyber security services across the North East, and staff training is a core part of how we protect your business.

  • Cyber Essentials v3.3: What Changed and How to Pass First Time

    Cyber Essentials v3.3: What Changed and How to Pass First Time

    Cyber Essentials v3.3 took effect on 27 April 2026. All new assessment accounts created after that date use the updated requirements and the new Danzell question set. If your certification is due for renewal or you are certifying for the first time, v3.3 now applies to your assessment.

    The core scheme has not changed. It still tests the same five control themes: firewalls, secure configuration, user access control, malware protection, and security update management. The updated version marks certain areas more strictly, changes how cloud services are scoped, and introduces clearer automatic failure triggers. The businesses that understand these changes pass first time. The ones that assume last year’s answers still work are the ones that fail. It is crucial to keep up to date with Cyber Essentials v3.3 compliance requirements.

    The Three Changes That Matter Most

    1. MFA is now a hard fail. Cyber Essentials has included multi-factor authentication for several years, but v3.3 now marks it more strictly. If a cloud service supports MFA and you have not enabled it for all users, you automatically fail. No discussion, no mitigation, no partial credit. Adhering to Cyber Essentials version 3.3 is mandatory in this respect.

    This applies regardless of whether MFA is free, bundled with the service, or only available as a paid add-on. If the option exists and you have not switched it on, the assessment stops there. Cyber Essentials v3.3 no longer accepts IP allowlisting as a form of multi-factor authentication.

    The practical impact is significant. Most businesses have MFA enforced on their main platforms, Microsoft 365, for example, but have not enabled it on every cloud service they use. Project management tools, accounting software, CRM platforms, HR systems, social media accounts used for business, and even free-tier SaaS tools all count. Being thorough is now an integral part of the Cyber Essentials v3.3 requirements.

    2. Cloud services cannot be excluded from scope. For the first time, v3.3 includes a formal definition of a cloud service: an on-demand, scalable service hosted on shared infrastructure, accessible via the internet, accessed via an account, and used to store or process organisational data. This update is outlined clearly in the Cyber Essentials v3.3 documentation.

    If your business uses it and company data flows through it, it is in scope. Microsoft 365, Google Workspace, your CRM, your accounting platform, your file sharing tools, your HR system. Previous versions allowed some ambiguity that let businesses argue certain services were out of scope. That argument no longer holds. The new Cyber Essentials v3.3 designation closes these gaps.

    What This Means in Practice

    The practical step is to build a cloud service inventory before your assessment. List every service accessed with a business email or company account. For each one, confirm that MFA is enabled, that access controls are appropriate, and that the service is included in your scope statement as required by Cyber Essentials v3.3, ensuring no service is missed.

    3. The 14-day patching rule is now an auto-fail. High-risk and critical security updates, those with a CVSS v3 base score of 7 or above, must be applied within 14 days of release. Two new auto-fail questions, A6.4 and A6.5, mean that failure to meet this requirement results in an automatic assessment failure. These specifics stem from the new Cyber Essentials v3.3 guidance.

    This applies across all devices and software in scope: operating systems, firmware, browsers, plugins and applications. If your patching process is informal or relies on users accepting update prompts, you need a structured approach before your assessment. A managed IT provider with centralised patch management can enforce this consistently. Maintaining Cyber Essentials v3.3 patching standards gives your organisation the best chance at passing.

    What Catches Businesses Out

    Beyond the three headline changes, several areas consistently trip up businesses. Many common issues stem from misinterpreting Cyber Essentials v3.3 scope and requirements.

    Scope that excludes end-user devices. A scope that does not include laptops, desktops, tablets or phones used to access organisational data is not acceptable under v3.3. If your staff use devices to access business email, files or cloud services, those devices are in scope. This includes BYOD arrangements where personal devices access company systems—a non-compliance with Cyber Essentials v3.3.

    Social media accounts. Cyber Essentials v3.3 treats business social media accounts, including LinkedIn, Facebook and X, as cloud services. If your marketing team logs into these accounts with a business email, you must enable MFA to protect your assessment. The rules were clarified in Cyber Essentials v3.3, so businesses must review every account accordingly.

    Unsupported operating systems. Devices running operating systems past end of support, including Windows 10 without ESU, fail the secure configuration and patching requirements. If your estate includes machines that you cannot patch, you need to upgrade them, replace them, or formally exclude them from scope with documented network segregation. Cyber Essentials v3.3 helps you handle these systems properly.

    Admin account hygiene. Assessors check whether you enforce MFA on administrator accounts, limit admin privileges to the people who need them, and use separate admin and standard accounts. Shared admin accounts without MFA are a common failure point. These rules are specifically included in the Cyber Essentials v3.3 assessment process.

    Incomplete evidence. Even when the right controls are in place, businesses can struggle to prove it during assessment. Screenshots, policy records, patch reports, MFA settings and scope details all need to be clear, current and consistent. If the evidence does not match the answers given in the assessment, it can delay certification or lead to follow-up questions.

    How to Prepare for a v3.3 Assessment

    Start with three exercises. First, build your cloud service inventory and confirm MFA status on every service. Second, run a patching audit to confirm you can evidence 14-day compliance for critical updates. Third, review your scope statement to ensure it covers all devices and cloud services that handle organisational data. These actions are vital for Cyber Essentials v3.3 readiness.

    If you hold Cyber Essentials certification through Unite, we review your environment against v3.3 requirements before your assessment begins. If you are certifying for the first time, we run a readiness check that identifies gaps and helps you close them before your assessment account is created. This process is central to a successful Cyber Essentials version 3.3 certification journey.

    As an IASME certification body, The Unite Group assesses businesses against the Cyber Essentials scheme directly. We understand how assessors interpret the requirements because we are the assessors. If your renewal is coming up or you want to certify for the first time under v3.3, contact us for a readiness review. Make sure you are fully prepared for Cyber Essentials v3.3 assessment changes.

  • Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For

    Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For

    If your cyber insurance renewal is approaching, the application will look different from last time. Insurers have moved beyond generic questionnaires.They now ask detailed questions about your security controls. They also expect clear proof that these controls are active, enforced, and tested. A verbal confirmation that you “have MFA” is no longer enough.

    For SMEs, this shift can feel overwhelming. The questions reference tools and processes that your team may not manage directly, and assembling the evidence often falls between your IT provider and your internal admin with no clear owner. The result is a last-minute scramble, higher premiums, or in some cases, declined coverage.

    This blog explains what UK cyber insurers ask for in 2026. It also outlines the evidence needed for each requirement and how to build a proof pack before your renewal.

    What Insurers Are Asking For in 2026

    Underwriting has become technical. Carrier applications and renewal questionnaires now routinely cover six areas, and they want evidence for each.

    Multi-factor authentication. Insurers want to see MFA enforced on email, remote access, VPN and all administrative accounts. Partial coverage (MFA on email but not on remote desktop, for example) is specifically flagged. Microsoft reports that MFA blocks over 99% of account compromise attacks, which is why it tops every insurer’s checklist.

    Endpoint detection and response. Traditional antivirus no longer satisfies underwriters. They expect EDR or managed detection and response running on all endpoints, with evidence of 24/7 monitoring and active response capability. If you use Huntress Managed EDR, your provider dashboard shows deployment coverage, alert history and response timelines, all of which map directly to what insurers ask for.

    Backup and recovery. Insurers ask if you have backups in place, whether you keep them isolated or immutable so ransomware cannot encrypt them, and if you test restores regularly. If you have never tested a backup, insurers will not consider it reliable.

    Incident response plan. A written incident response plan with named contacts, defined escalation steps and evidence that it has been tested (even a simple tabletop exercise) is now a standard underwriting requirement. Insurers often ask for the date of the last test and any remediation actions that followed.

    Security awareness training. Insurers want evidence that staff receive regular training and that phishing simulations are part of the programme. A single annual session no longer satisfies most carriers. Managed security awareness training with monthly modules and automated reporting gives you exactly the documentation they expect.

    Patching and vulnerability management. Carriers ask about your patching cadence for critical vulnerabilities. Insurers expect you to apply critical patches within 14 to 30 days. They also expect you to remove end-of-life software or carry out a formal risk assessment.

    How to Build the Evidence Pack

    Start assembling documentation 60 to 90 days before your renewal date. Rushing this in the final week leads to gaps, and gaps lead to follow-up questions, higher premiums or declined coverage.

    For each of the six areas above, prepare a simple evidence file. This should include screenshots of MFA policies and EDR deployment reports. It should also cover backup test logs with dates and a copy of your incident response plan. Include training reports, phishing simulation results, and patch management reports showing update frequency.

    If your IT provider manages these controls for you, ask them to compile this pack as part of their service. A good managed IT provider should be able to produce most of this from their existing dashboards and reporting tools.

    Does Cyber Essentials Help with Insurance?

    Yes. Holding Cyber Essentials certification demonstrates that your business meets a government-backed baseline of security controls. Many UK insurers recognise it as a positive signal during underwriting, and some specifically ask whether you hold it.

    Cyber Essentials does not replace the evidence pack, but it covers key areas such as access control, patching, malware protection, and secure configuration. It also gives insurers confidence that these basics are formally verified rather than self-declared.

    The Cost of Getting This Wrong

    Businesses that cannot provide adequate evidence at renewal face three outcomes: significantly higher premiums, reduced coverage with broader exclusions, or outright refusal. In a market where the Cyber Security and Resilience Bill is increasing regulatory expectations across supply chains, having your insurance declined creates a compounding problem.

    The controls insurers ask about are the same controls that protect your business from the incidents insurance is designed to cover. Investing in them reduces your premium and reduces your risk at the same time.

    Get Your Evidence Pack Ready Before Renewal

    If your renewal is coming up and you are not sure whether your current setup meets insurer expectations, contact The Unite Group for an insurance readiness audit. We deliver every control insurers ask about, from managed EDR and security awareness training to backup management and incident response support, and we can assemble your evidence pack as part of our managed IT service.

  • Phishing Attacks in 2026: What UK Businesses Still Get Wrong

    Phishing Attacks in 2026: What UK Businesses Still Get Wrong

    Phishing attacks remain the most common cause of cyber breaches in the UK. The government’s Cyber Security Breaches Survey found that 85% of businesses that experienced a breach identified phishing as the attack method. That figure has barely shifted in three years. What has changed is how the attacks look, how they arrive, and why email filters alone no longer catch them.

    For SMEs, the risk is straightforward. Phishing works because it targets people, not systems. And unless your team knows what to look for, a single click can give an attacker access to your email accounts, customer data or financial systems.

    Why Phishing Has Become Harder to Spot

    A few years ago, most phishing emails were easy to identify. Poor spelling, generic greetings, suspicious sender addresses. That is no longer the case.

    Attackers now use AI tools to generate phishing emails that match the tone, formatting and language of legitimate business communication. They research targets using LinkedIn, company websites and public data to craft messages that feel personal and relevant. A finance team member might receive what looks like a genuine invoice from a known supplier. A director might get a convincing request from what appears to be their bank.

    Beyond email, phishing has expanded into other channels. Voice phishing (vishing) uses phone calls, often spoofing real numbers, to pressure staff into sharing credentials or making payments. QR code phishing (quishing) embeds malicious links in printed materials or PDF attachments, bypassing email filtering entirely. SMS phishing (smishing) targets mobile devices where people tend to be less cautious.

    The Mistakes Businesses Keep Making

    Relying entirely on email filters. Filters catch a lot, but they are not infallible. AI-generated phishing emails are specifically designed to pass through automated detection. Filters should be a layer of defence, not the only one.

    Running training once a year. An annual awareness session does not change behaviour. Monthly, bite-sized training with simulated phishing tests is what actually builds recognition skills over time. Staff need to practise identifying threats in realistic conditions, not just sit through a slide deck.

    No clear process for reporting. If someone suspects a phishing email, do they know what to do? Many businesses have no defined process, and staff worry about looking foolish for flagging something that might be legitimate. A simple, blame-free reporting process catches threats faster and encourages vigilance.

    Assuming small businesses are not targeted. Attackers increasingly target SMEs because they tend to have weaker defences and less formal processes. Automated phishing campaigns do not discriminate by company size. If your email addresses are publicly listed, you are a target.

    What Actually Reduces Risk

    Effective phishing defence combines technical controls with regular staff training.

    On the technical side, ensure your email platform has modern anti-phishing protections enabled. If you use Microsoft 365, check that Safe Links and Safe Attachments are turned on. Make sure multi-factor authentication is active on every account, so that even if credentials are stolen, attackers cannot log in without a second factor.

    On the people side, invest in ongoing cyber security training that includes regular phishing simulations. This does not need to be time-consuming or expensive. Managed training platforms run automatically, track completion, and provide targeted follow-up for anyone who falls for a test. The data from simulations shows you exactly where your team’s weaknesses are.

    Create a clear internal process: if you receive a suspicious email, forward it to a designated address or flag it in your email client. Do not click, do not reply, do not forward it to colleagues to ask ‘does this look dodgy to you?’

    What to Do If Someone Clicks

    If a staff member clicks a phishing link or enters credentials on a suspicious page, act quickly. Change the affected passwords immediately. Check whether the compromised account has been used to send further phishing emails internally or to contacts. Review recent sign-in activity for anything unusual.

    If you work with a managed IT provider, report it to them straight away. Providers with proactive monitoring tools can isolate affected accounts and check for signs of deeper compromise before it spreads.

    The speed of response matters more than blame. Businesses that have a tested incident response process recover faster and limit damage. Businesses that do not often discover the breach weeks later, after significant harm has already been done.

    Phishing Prevention Starts with People

    Technical tools help, but phishing exploits human judgement. The businesses that handle it best are the ones where staff feel confident identifying threats and comfortable reporting them.

    If your team has not had structured phishing awareness training recently, or if you are unsure how your current defences measure up, talk to The Unite Group about managed security awareness training. We run phishing simulations and ongoing training programmes that fit around your team’s working day and give you clear data on where to focus.

  • Zero Trust Security for Small Businesses

    Zero Trust Security for Small Businesses

    Zero trust security, the unite group IT

    Zero trust is a security approach built on one principle: never trust anything automatically, always verify. Every user, device, and application must prove who they are and what they are allowed to access before being let in, every single time. There is no ‘inside the network means you are safe.’

    For years, zero trust was treated as an enterprise concept requiring dedicated security teams and six-figure budgets. That has changed. The tools most SMEs already use, particularly Microsoft 365, now include zero trust controls that can be switched on without buying anything new. If you have 10 to 50 people and you use cloud services, zero trust is not only relevant to your business; some of it is probably already within reach.

    Why the Old Approach No Longer Works

    Traditional security worked like a castle with a moat. Build a strong perimeter (firewall, VPN) and trust everything inside it. Once you were past the drawbridge, you could go anywhere.

    That model breaks down the moment your staff work from home, use personal phones, access cloud applications or share files externally. The perimeter no longer exists in any meaningful sense. Your data is everywhere: in Microsoft 365, on laptops in coffee shops, in shared folders accessible from any browser.

    Attackers know this. Phishing steals a set of credentials, and once inside, there is nothing stopping lateral movement across email, SharePoint, OneDrive and anything else that login has access to. The castle-and-moat model offers no protection once someone is through the door.

    Consider a common scenario: A staff member clicks a convincing phishing link and enters their Microsoft 365 password. Without zero trust controls, the attacker now has the same access as that employee: email, shared files, client data, internal Teams channels. If that person happens to have admin rights, the attacker has those too. In a zero trust environment, the stolen password alone is not enough. MFA blocks the login attempt. Conditional access flags the unfamiliar device or location. Even if the attacker gets past those layers, least-privilege access means they reach only what that specific role requires, not the entire business.

    Zero Trust Principles

    Strip away the frameworks and the jargon, and zero trust comes down to three things.

    Verify every access request

    Do not assume that because someone logged in this morning, they should still have access this afternoon. Instead, check who they are, what device they are using, where they are connecting from, and whether the access request makes sense.

    This is where multi-factor authentication becomes essential, but it goes beyond MFA into conditional access policies that evaluate context with every request.

    Give people only what they need

    This is least-privilege access. For example, if someone in marketing does not need access to the finance folder, they should not have it. Likewise, if an employee leaves or changes role, their permissions should be updated immediately rather than left open indefinitely. Most businesses discover they have far more shared access than they realised when they actually audit it.

    Assume a breach has already happened

    Design your systems as though an attacker is already inside. Segment access so that compromising one account does not hand over everything. Monitor for unusual behaviour, like a user logging in from two countries within an hour, or downloading thousands of files at midnight. This aligns with identity-based threat detection.

    Practical Steps for a Small Business

    You do not need a dedicated security operations centre to start applying zero trust. Here is where most SMEs should begin.

    Turn on conditional access in Microsoft 365

    If you have Microsoft 365 Business Premium, you already have the tools. Set up policies that require MFA, block sign-ins from risky locations, and ensure devices meet basic compliance standards before granting access.

    Audit your permissions

    Check who has access to what across SharePoint, OneDrive, Teams and any other shared systems. Remove access people no longer need. Set shared folders to restricted rather than open by default.

    Use separate admin accounts

    Anyone with administrative privileges should have a separate admin account that they only use for admin tasks. Day-to-day work should happen on a standard account. This limits the damage if a credential is compromised.

    Enable security defaults or conditional access policies

    Microsoft’s security defaults provide a baseline of zero trust controls at no extra cost. For more granular control, conditional access policies let you define specific rules based on user, device, location and risk level.

    Review access regularly

    Zero trust is not a one-time project. Schedule quarterly reviews of user permissions, admin accounts and access policies. When someone changes role or leaves the business, update their access on the same day.

    Require device compliance before granting access

    If you use Microsoft Intune (included with Business Premium), you can set policies that only allow access from devices that meet your security standards, such as having an up-to-date operating system, active antivirus and disk encryption enabled. A personal laptop that has not been patched in six months should not have the same access as a managed company device.

    Segment your network

    At a basic level, this means keeping your guest Wi-Fi separate from your business network. Visitors and personal devices should not sit on the same network as your servers, printers and business systems. Most modern routers support this, and it is one of the simplest ways to limit what an attacker can reach if they gain access through a less secure device.

    How Zero Trust Relates to Cyber Essentials

    If your business holds or is working toward Cyber Essentials certification, you are already aligned with some zero trust principles. Cyber Essentials requires access control, secure configuration and malware protection, all of which overlap with the zero trust model. Zero trust builds on that foundation. Where Cyber Essentials provides a baseline, zero trust extends it with continuous verification, conditional access and the assumption that no network location is inherently safe. The two work together, not in competition.

    Getting Started Without a Security Team

    Zero trust is a direction, not a destination. You do not need to implement everything at once. Start with MFA and conditional access. Audit your permissions. Enable basic monitoring. Each step reduces your attack surface. If you want help applying zero trust principles to your managed IT environment, speak to The Unite Group. We will review your current setup, identify the quick wins and build a practical roadmap that fits your business, not an enterprise framework.

  • What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    Most businesses understand that antivirus is no longer enough. Fewer understand what happens next. Managed endpoint detection and response (EDR) monitors every laptop, desktop and server in your business for suspicious activity, then detects, investigates and responds to threats before they cause damage. The difference between EDR and antivirus is not just what it catches. It is what happens after it catches it. 

    At The Unite Group, we deliver managed EDR through our partnership with Huntress. This article shows you what that looks like in practice, what the technology does, who is watching, and what happens when it finds something.

    The Team Behind the Screen 

    Former intelligence agency experts founded Huntress, and multiple specialist teams now run its Security Operations Centre. These include security analysts who investigate alerts, threat hunters who proactively search for hidden compromises, detection engineers who build and refine the rules that catch threats, threat intelligence researchers who track emerging attack techniques, and a dedicated threat response team that handles serious incidents. 

    This is not an automated system that sends you an email and hopes you know what to do. It is a team of people watching your environment around the clock, backed by tooling that monitors millions of endpoints globally. The threat intelligence from that scale feeds directly into the detection rules applied to your business, meaning you benefit from patterns spotted across thousands of other organisations. 

    What Huntress EDR Actually Detects 

    Traditional antivirus uses signature-based detection: it recognises known malware and blocks it. That is still important, but it cannot keep up with the volume of new threats created daily. EDR takes a different approach, monitoring behaviour rather than matching signatures. 

    Huntress looks for specific threat patterns across your endpoints. These include malicious process behaviour, where a legitimate application starts doing something it should not. Persistent footholds, where an attacker installs a secondary remote management tool to maintain access even after the obvious threat is removed. Ransomware canaries, which act as early warning tripwires that detect encryption activity before it spreads across your network. And open port detection, which identifies ports left open either accidentally or intentionally that could expose your systems. 

    The typical threat actor remains undetected inside a business environment for 90 to 120 days, quietly gathering information and preparing for a larger attack. EDR reduces that dwell time dramatically by identifying abnormal activity early and triggering a response in minutes rather than months. 

    Eight Minutes from Detection to Action 

    Speed matters because the gap between detection and response is where damage happens. Huntress operates with an average mean time to respond of eight minutes. That covers the entire cycle: detection, investigation, remediation and reporting. 

    When something suspicious is identified, the SOC team investigates immediately. If it is a genuine threat, they act. That typically means isolating the affected machine from the network so the threat cannot spread, killing malicious processes, removing persistent footholds, and providing clear guidance on cleanup and recovery. If backup systems are in place, they coordinate with those too, minimising downtime and data loss. 

    The system is 99.3% accurate in identifying real threats. That matters because false positives waste time and erode trust. If every alert turns out to be nothing, people stop paying attention. Huntress’s accuracy rate means that when an alert comes through, it is almost always something that genuinely needs addressing. 

    What You See as a Business Owner 

    You do not need to become a security expert to benefit from managed EDR. When a threat is detected and handled, you receive a clear report explaining what happened, what action was taken, and whether anything further is needed from your side. 

    Monthly reporting shows you what was detected, how your environment is performing, and whether any patterns need attention. This is useful not just for your own awareness but for demonstrating to clients, insurers and auditors that your business has active, continuous security monitoring in place. Cyber insurers increasingly expect evidence of EDR coverage, and having a managed service with documented response data strengthens your position at renewal. 

    How Managed EDR Fits with Everything Else 

    EDR is not a replacement for the rest of your security stack. It works alongside antivirus, multi-factor authentication, email filtering, and security awareness training. Think of it as the safety net: when something gets past the first layers of defence, EDR catches it and responds before it becomes a breach. 

    It also pairs directly with incident response planning. If you have a documented response plan, EDR provides the detection and containment steps that feed into it. If you do not have a plan yet, managed EDR gives you a level of protection while you build one. 

    For businesses that already hold Cyber Essentials certification, EDR is the logical next step. Cyber Essentials covers the baseline controls. EDR provides ongoing, active monitoring that Cyber Essentials does not require but that modern threats increasingly demand. 

    Is Managed EDR Right for Your Business? 

    If your team uses laptops, connects remotely, handles sensitive data, or operates in a sector where cyber insurance or compliance matters, managed EDR is worth considering. Huntress is not just for large businesses. It was built specifically for small and mid-sized organisations that do not have in-house security teams but still need enterprise-grade protection.

    The agent is lightweight and runs in the background without affecting device performance. Most users will not notice it once you install it. You can roll it out easily across your devices as part of your managed IT services.

    If you want to understand how managed EDR would work for your business, or you want to see what Huntress detects across your current environment, contact The Unite Group for a security assessment. We will review your setup, explain what managed EDR covers, and give you a clear recommendation. 

  • What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    Most businesses understand that antivirus is no longer enough. Fewer understand what happens next. Managed endpoint detection and response (EDR) monitors every laptop, desktop and server in your business for suspicious activity, then detects, investigates and responds to threats before they cause damage. The difference between EDR and antivirus is not just what it catches. It is what happens after it catches it. 

    At The Unite Group, we deliver managed EDR through our partnership with Huntress. This article explains what that looks like in practice: what the technology does, who is watching, and what happens when something is found. 

    The Team Behind the Screen 

    Huntress was founded by former intelligence agency experts and operates a Security Operations Centre staffed by multiple specialist teams. These include security analysts who investigate alerts, threat hunters who proactively search for hidden compromises, detection engineers who build and refine the rules that catch threats, threat intelligence researchers who track emerging attack techniques, and a dedicated threat response team that handles serious incidents. 

    This is not an automated system that sends you an email and hopes you know what to do. It is a team of people watching your environment around the clock, backed by tooling that monitors millions of endpoints globally. The threat intelligence from that scale feeds directly into the detection rules applied to your business, meaning you benefit from patterns spotted across thousands of other organisations. 

    What Huntress EDR Actually Detects 

    Traditional antivirus uses signature-based detection: it recognises known malware and blocks it. That is still important, but it cannot keep up with the volume of new threats created daily. EDR takes a different approach, monitoring behaviour rather than matching signatures. 

    Huntress looks for specific threat patterns across your endpoints. These include malicious process behaviour, where a legitimate application starts doing something it should not. Persistent footholds, where an attacker installs a secondary remote management tool to maintain access even after the obvious threat is removed. Ransomware canaries, which act as early warning tripwires that detect encryption activity before it spreads across your network. And open port detection, which identifies ports left open either accidentally or intentionally that could expose your systems. 

    The typical threat actor remains undetected inside a business environment for 90 to 120 days, quietly gathering information and preparing for a larger attack. EDR reduces that dwell time dramatically by identifying abnormal activity early and triggering a response in minutes rather than months. 

    Eight Minutes from Detection to Action 

    Speed matters because the gap between detection and response is where damage happens. Huntress operates with an average mean time to respond of eight minutes. That covers the entire cycle: detection, investigation, remediation and reporting. 

    When something suspicious is identified, the SOC team investigates immediately. If it is a genuine threat, they act. That typically means isolating the affected machine from the network so the threat cannot spread, killing malicious processes, removing persistent footholds, and providing clear guidance on cleanup and recovery. If backup systems are in place, they coordinate with those too, minimising downtime and data loss. 

    The system is 99.3% accurate in identifying real threats. That matters because false positives waste time and erode trust. If every alert turns out to be nothing, people stop paying attention. Huntress’s accuracy rate means that when an alert comes through, it is almost always something that genuinely needs addressing. 

    What You See as a Business Owner 

    You do not need to become a security expert to benefit from managed EDR. When Huntress detects and handles a threat, you receive a clear report that explains what happened, what action it took, and whether you need to do anything else.

    Monthly reporting shows you what the system detected, how your environment is performing, and whether any patterns need attention. This is useful not just for your own awareness but for demonstrating to clients, insurers and auditors that your business has active, continuous security monitoring in place. Cyber insurers increasingly expect evidence of EDR coverage, and having a managed service with documented response data strengthens your position at renewal. 

    How Managed EDR Fits with Everything Else 

    EDR is not a replacement for the rest of your security stack. It works alongside antivirus, multi-factor authentication, email filtering, and security awareness training. Think of it as the safety net: when something gets past the first layers of defence, EDR catches it and responds before it becomes a breach. 

    It also pairs directly with incident response planning. If you have a documented response plan, EDR provides the detection and containment steps that feed into it. If you do not have a plan yet, managed EDR gives you a level of protection while you build one. 

    For businesses that already hold Cyber Essentials certification, EDR is the logical next step. Cyber Essentials covers the baseline controls. EDR provides ongoing, active monitoring that Cyber Essentials does not require but that modern threats increasingly demand. 

    Is Managed EDR Right for Your Business? 

    If your team uses laptops, connects remotely, handles sensitive data, or operates in a sector where cyber insurance or compliance matters, managed EDR is worth considering. Huntress is not just for large businesses. It was built specifically for small and mid-sized organisations that do not have in-house security teams but still need enterprise-grade protection.

    The agent is lightweight and runs in the background without affecting device performance. Most users will not notice it once you install it. You can deploy it easily across your devices as part of your managed IT services.

    If you want to understand how managed EDR would work for your business, or you want to see what Huntress detects across your current environment, contact The Unite Group for a security assessment. We will review your setup, explain what managed EDR covers, and give you a clear recommendation. 

  • UK Cyber Security and Resilience Bill 2026: What It Means for SMEs and Their IT Suppliers 

    UK Cyber Security and Resilience Bill 2026: What It Means for SMEs and Their IT Suppliers 

    The Cyber Security and Resilience Bill is the UK government’s most significant update to cyber legislation since the original NIS Regulations in 2018. It expands who must meet formal cyber security standards, tightens incident reporting timelines, and for the first time brings managed service providers under direct regulatory oversight. If your business uses an external IT provider or supplies services to larger organisations, this Bill will affect you. 

    The Bill passed its second reading in January 2026 and has been progressing through committee stage since February. While it primarily targets operators of essential services, data centres and MSPs, the ripple effect on SMEs through supply chain requirements is substantial. 

    What the Bill Actually Changes 

    Three things matter most for small and medium-sized businesses. 

    Managed service providers become regulated. An estimated 900 to 1,100 MSPs will come under direct ICO oversight. They will need to meet defined security standards and report incidents within prescribed timeframes. If your IT is managed externally, your provider will be held to higher standards, and you should be asking them how they are preparing. 

    Incident reporting gets stricter. Organisations in scope must report cyber incidents to their regulator and to the NCSC within 24 hours of becoming aware. A full report must follow within 72 hours. This replaces the slower, less consistent reporting that existed under the 2018 regulations. 

    Supply chain scrutiny increases. Regulated organisations will be required to assess and manage cyber risk across their suppliers. SMEs that supply goods or services to larger businesses can expect more cyber security clauses in contracts, assurance questionnaires and minimum securitystandards becoming routine. 

    How This Affects SMEs (Even If You Are Not Directly in Scope) 

    The Bill does not impose direct obligations on most small businesses. But the indirect effects are real. 

    Larger clients will start asking whether you hold Cyber Essentials certification, whether you have an incident response plan, and whether your data is properly protected. Businesses that cannot demonstrate reasonable cyber security measures risk losing contracts or being excluded from tender processes altogether. 

    The government has been clear that SMEs are not expected to invest in enterprise-grade tools. The expectation is proportionate: understand your risks, take reasonable steps to manage them, and be able to show evidence of both. Cyber Essentials, maintained access controls, regular patching and a tested incident response plan go a long way toward meeting that bar. 

    The Penalties Are Significant 

    For organisations directly in scope, fines can reach £17 million or 4% of global annual turnover, whichever is higher. For less severe breaches, the cap is £10 million or 2% of turnover. Regulators can also impose daily fines of up to £100,000 for ongoing non-compliance. 

    SMEs are unlikely to face fines directly under this Bill. But losing a contract because you cannot satisfy a client’s supply chain requirements has a similar financial impact at a smaller scale. 

    What You Should Do Now 

    You do not need to wait for the Bill to receive Royal Assent before acting. The direction is clear, and the expectations are already filtering into commercial contracts. 

    Start with a basic cyber security review. Identify what data your business holds and where it is stored. Check your backups and access controls. Make sure your multi-factor authentication is in place across all accounts. Consider whether Cyber Essentials certification would strengthen your position with clients. 

    If you use a managed IT provider, ask them directly how they are preparing for the new regulatory requirements. A good provider will already be working toward compliance. If they cannot answer that question clearly, it may be worth reviewing the relationship. 

    How This Connects to Your IT Provider 

    The Bill specifically names managed service providers as a new regulated category. This means your IT partner will face the same obligations as digital service providers: formal security standards, incident reporting duties and regulatory oversight by the ICO. 

    For businesses that already work with a proactive managed IT services provider, this should be reassuring. It raises the baseline across the industry and makes it harder for underqualified providers to operate without accountability. 

    At The Unite Group, we hold ISO 27001 certification and operate as an IASME-accredited Cyber Essentials certification body. We are already aligned with the standards the Bill is designed to enforce. If you want to understand how the Cyber Security and Resilience Bill affects your business or your current IT arrangements, speak to our team about a cyber security review and we will help you identify any gaps.