Category: IT Support Blogs

Welcome to our IT Support Blogs page. Here at the Unite Group, we like to keep our clients and network up to date with the information that can help them in their business using our blog pages.

Here you will find blogs regarding IT infrastructure, how The Unite Group can support your business, and handy hints and tips to keep your IT safe and secure.

We have a team of experienced engineers ready on hand to provide you with the highest standard of service and solve any queries that you may have. Our engineers undergo continuous professional development to ensure they are always up to date with the latest technology.

  • Windows 10 in 2026: ESU vs Upgrade vs Replace for UK SMEs

    Windows 10 in 2026: ESU vs Upgrade vs Replace for UK SMEs

    Windows 10 reached its end of support on 14 October 2025, but many organisations are already planning for Windows 10 end of support 2026 as they consider their next steps. Microsoft no longer provides free security updates for any Windows 10 device. If your business still has machines running Windows 10, you have three options: pay for Extended Security Updates (ESU) as a temporary measure, upgrade eligible machines to Windows 11, or replace hardware that cannot make the jump. Doing nothing means running unpatched systems that become more vulnerable with every month that passes.

    What Extended Security Updates Actually Give You

    ESU is a paid subscription that continues delivering critical and important security patches for Windows 10 devices after end of support. It does not include new features, design changes, or general technical support. It is a security-only stopgap.

    Year 1 (October 2025 to October 2026) costs approximately £60 per device. Year 2 doubles to around £120 per device. In year 3 doubles again to around £240. You cannot skip years, so if you start in Year 2, you must pay for Year 1 as well. The total three-year cost per device reaches roughly £420.

    Devices must be running Windows 10 version 22H2 to qualify. Earlier versions need updating before ESU can be activated.

    ESU makes sense for businesses with a small number of devices that cannot yet be upgraded, typically because of legacy software dependencies or a hardware refresh cycle that extends into 2027. It buys time. It does not solve the underlying problem.

    When Upgrading to Windows 11 Is the Right Move

    If a device meets Windows 11’s hardware requirements, upgrading is free for licensed Windows 10 users and is the most cost-effective long-term option.

    The key hardware requirements are a TPM 2.0 chip, Secure Boot capability, and a supported processor. Most business laptops and desktops purchased from 2019 onwards meet these requirements. Machines older than that typically do not.

    To check your estate, run the Microsoft PC Health Check tool on each device or use a centralised tool like Intune to assess compatibility across all machines at once. This gives you a clear picture of how many devices can upgrade in place and how many cannot.

    Upgrading in place preserves applications, files and settings. For most users, the transition is straightforward, but testing any specialist or line-of-business software against Windows 11 before rolling out across the team is worth the time.

    When Replacement Is the Only Practical Option

    If a device fails the Windows 11 compatibility check, particularly on the processor or TPM requirement, it cannot be upgraded. ESU extends its life temporarily, but you are paying £60+ per year per device for a machine that is already at the end of its useful life.

    For devices over five years old, replacement is usually more cost-effective than ESU once you factor in declining performance, battery degradation, increased failure rates and the cumulative ESU cost. A new business laptop running Windows 11 Pro costs roughly £400 to £700 depending on specification.

    Replacement does not have to happen all at once. A phased approach, replacing the oldest or most critical machines first and scheduling the rest across two or three quarters, spreads the cost and reduces disruption.

    A Simple Decision Framework

    For each Windows 10 device in your business, ask three questions.

    Can it run Windows 11? Check hardware compatibility. If yes, schedule the upgrade. If no, move to the next question.

    Does it run software that requires Windows 10? If yes, ESU buys time while you work with the software vendor on Windows 11 compatibility. If no, move to the next question.

    Is the device less than four years old and performing well? If yes, ESU for one year while you plan a phased replacement may make sense. If no, replace it.

    What Happens If You Do Nothing

    After October 2026, ESU Year 1 expires and consumer devices stop receiving any patches at all. Businesses on the enterprise ESU programme can extend to October 2028, but at escalating cost.

    Running unpatched Windows 10 devices creates real risk. New vulnerabilities discovered after your ESU coverage ends will not be fixed. Attackers specifically target end-of-life operating systems because they know patches are not coming. Cyber insurers ask about operating system currency during underwriting, and unpatched devices may affect your coverage.

    The Windows Server 2016 end of support deadline in January 2027 creates a similar pressure point for server infrastructure. If your business has both ageing desktops and ageing servers, planning both transitions together is more efficient.

    Get a Device Estate Audit

    If you are not sure which devices can upgrade, which need replacing, and how to plan the rollout without disrupting your team, contact The Unite Group for a device estate audit. We will assess every machine, recommend the right path for each, handle procurement for any replacements, and deliver them configured and ready to use as part of your managed IT services.

  • 2G Switch-Off: Why UK Businesses Should Start a Device Audit Now

    2G Switch-Off: Why UK Businesses Should Start a Device Audit Now

    UK mobile network operators will switch off their 2G networks between 2029 and 2033. The 3G switch-off is already nearly complete, with most operators finishing by early 2026. DSIT published formal guidance on 24 March 2026 confirming the timeline and urging businesses to identify affected devices well ahead of the shutdown.

    The deadline feels distant, but the audit should not wait. Many SMEs have devices, SIMs and connected equipment running on 2G that they are not aware of. The businesses that identify these now have time to plan upgrades on their own terms.

    The ones that leave it until the final year face the same last-minute scramble the PSTN switch-off is already creating.

    Why 2G Matters More Than You Think

    Most smartphones sold in the last five years support 4G and 5G. For handsets, the switch- off will be invisible to most users. The problem sits with older devices and connected equipment that was never designed to move beyond 2G.

    Business mobiles issued three or four years ago to warehouse staff, drivers or site workers may still be basic feature phones running on 2G. Company-issued handsets are often replaced less frequently than personal phones, particularly for roles where a smartphone is not needed.

    Beyond handsets, many businesses have equipment that connects over 2G without anyone thinking about it. Vehicle trackers in fleet vans, IoT sensors for temperature monitoring, alarm communicators that fall back to 2G when broadband fails, agricultural monitoring devices, personal safety alarms, and older EPOS terminals with SIM-based connectivity all potentially rely on 2G.

    What to Audit in Your Business

    Walk through your operations and identify every device that uses a mobile connection. The categories most SMEs miss are listed here.

    Staff handsets. Check whether any company-issued phones are 2G-only. Look for “2G” or “E” on the signal indicator. If the phone never shows “4G” or “5G”, it will stop working when 2G is switched off.

    Vehicle and fleet trackers. GPS tracking devices in vans, trucks or company vehicles often use 2G to transmit location data. Check with your tracking provider whether the hardware supports 4G.

    Alarm systems. Some intruder and fire alarm communicators use 2G SIMs as a backup path when the primary broadband connection fails. This is separate from the ISDN/PSTN switch-off issue, which affects landline-connected alarms. Check with your alarm monitoring provider.

    IoT and environmental sensors. Temperature monitors in cold storage, water leak sensors, air quality monitors and similar connected devices may use 2G or 3G SIMs. These are often installed once and forgotten until they stop reporting.

    Personal safety devices. Lone worker alarms and personal safety pendants used by staff working remotely or in high-risk environments may depend on 2G to contact monitoring centres.

    Payment terminals. Older mobile card machines with SIM-based connectivity may still fall back to 2G in areas with weak 4G coverage.

    The Timeline and What It Means

    The government’s confirmed timeline is 2029 to 2033 for 2G switch-off across all operators. Each network will set its own schedule within that window. VMO2 withdrew 2G roaming services in October 2025 and completed its 3G switch-off by early 2026. Other operators are expected to publish their 2G timelines during 2026 and 2027.

    For businesses, the practical implication is straightforward. Devices purchased or installed today should support 4G at minimum. Any procurement decisions made from now on should exclude 2G-only equipment. And existing 2G devices should be catalogued so they can be replaced in phases rather than all at once under deadline pressure.

    Start the Audit Before It Becomes Urgent

    The ISDN switch-off has shown what happens when businesses delay infrastructure migration. Engineers become scarce, equipment availability tightens, and costs increase. The 2G timeline is longer, but the principle is the same: businesses that act early have more options and lower costs.

    If you need help auditing your mobile estate, identifying 2G-dependent devices, or planning replacements, contact The Unite Group. We manage business communications and connectivity across the North East, and we can assess your device fleet alongside your broader telecoms infrastructure.

  • 10 Power Automate Workflows Every SME Office Can Set Up This Quarter

    10 Power Automate Workflows Every SME Office Can Set Up This Quarter

    If your business uses Microsoft 365, you already have access to Power Automate. Most SMEs never touch it. The tool sits inside your existing subscription, capable of automating repetitive admin tasks that eat into your team’s working day, but nobody has time to explore what it actually does.

    Power Automate connects the Microsoft 365 apps your team already uses (Outlook, Teams, SharePoint, Excel, Forms) and lets you build automated workflows between them without writing code. An invoice arrives by email and the system routes it for approval automatically.A new starter joins and their onboarding checklist populates in Teams. A contract renewal date approaches and the account manager gets a reminder. These are not complex IT projects. Most take under an hour to set up using built-in templates. Here are ten that deliver immediate time savings for a typical SME office.

    Approvals That Do Not Live in Someone’s Inbox

    1. Expense approvals via Teams. When a staff member submits an expense (through a SharePoint list or Microsoft Form), Power Automate sends an approval request to their manager in Teams. The manager approves or rejects with one tap.The system logs the result automatically and sends the employee a confirmation email. No chasing, no lost receipts, no paper forms.

    2. Document sign-off. Upload a document to a specific SharePoint folder and Power Automate triggers an approval request to the designated reviewer. Once approved, the file moves to an “Approved” folder automatically. Useful for policies, proposals, marketing materials, or anything that needs a second pair of eyes before it goes out.

    3. Purchase order approvals. Route purchase requests through a defined approval chain based on value. Orders under a set threshold get approved by a team lead. Orders above it escalate to a director. The entire trail is logged in SharePoint.

    Onboarding and Off-boarding

    4. New starter onboarding checklist. When a new employee is added to your HR list (or a Microsoft Form is submitted by the hiring manager), Power Automate creates a task list in Planner or Teams with every onboarding step: equipment request, account setup, induction booking, policy acknowledgements. Each task is assigned to the relevant person with a due date.

    5. Leaver process trigger. When someone’s leaving date is entered, the flow notifies IT to schedule account deactivation, reminds their manager to reassign shared files, and sends HR a checklist for final paperwork. This reduces the risk of ex-employees retaining access to systems, which is a common security gap flagged during Cyber Essentials assessments.

    Finance and Admin Automation

    6. Invoice payment reminders. Connect Power Automate to an Excel tracker or SharePoint list of outstanding invoices. When a payment date arrives, the flow sends a polite reminder email to the client and posts a notification in your finance Teams channel. No more manually checking spreadsheets every morning.

    7. Contract renewal alerts. Store contract end dates in a SharePoint list. Power Automate sends an alert 90 days, 30 days and 7 days before each renewal, giving your team time to review terms, renegotiate or switch providers. This is especially useful for software licences, insurance policies and supplier agreements.

    Communication and Reporting

    8. Weekly team summary from Forms. Set up a recurring Microsoft Form for weekly updates (project status, blockers, wins). Power Automate collects responses every Friday and compiles them into a single Teams message or email to the manager. Replaces the meeting that could have been an email.

    9. Customer enquiry routing. When a contact form submission arrives (via Microsoft Forms or a connected web form), Power Automate sends it to the right person based on the enquiry type, logs it in a SharePoint list, and sends the customer an acknowledgement email within seconds.

    10. Teams channel notifications for key events. Set up Teams notifications for important activity across your M365 environment, such as large external file shares, SharePoint site membership changes, or critical Planner tasks becoming overdue.This keeps your team aware without relying on people checking dashboards.

    A Note on Governance

    Shadow flows can become a problem if everyone creates automations without oversight. Set clear ownership for each flow, document what it does and who maintains it, and review active flows quarterly. If a flow breaks or a staff member leaves, someone needs to know it exists. Your managed IT provider can help set up a governance framework alongside the automations themselves.

    Where to Start

    Pick one workflow that solves a real, daily frustration for your team. Set it up using a Power Automate template, test it, and let it run for two weeks. Once people see admin tasks disappearing, the appetite for more automation follows naturally.

  • How to Create a Cyber Incident Response Plan for Your SME

    How to Create a Cyber Incident Response Plan for Your SME

    Most small businesses know a cyber attack could happen to them. Far fewer have a written plan for what to do when it does.

    The result is predictable. When something goes wrong, whether it is a ransomware notification, a compromised email account, or unusual activity on the network, there is confusion. Who makes the call? Do you know who contacts the IT provider? Who tells customers? Decisions get made under pressure, and the wrong ones make the damage worse.

    A cyber incident response plan does not require a dedicated security team or a 50-page document. It needs to answer a handful of critical questions in advance so your business can respond quickly, limit damage and recover faster. Here is how to build one.

    What Counts as a Cyber Incident

    Before building a plan, define what triggers it. A cyber incident is any event that threatens the confidentiality, integrity or availability of your systems or data.

    Obvious examples include ransomware encryption, unauthorised access to email accounts, data breaches and phishing attacks that result in credential theft. Less obvious ones include a staff member losing an unencrypted laptop, finding unexpected admin accounts on your network, or discovering that someone has been forwarding company emails to a personal address.

    Your plan does not need to cover every scenario in detail. It needs to make clear that when something looks wrong, there is a defined process to follow rather than a scramble.

    The Five Steps Your Plan Should Cover

    A practical incident response plan follows five stages: prepare, identify, contain, recover and learn.

    1. Prepare. Assign roles before anything happens. Do you have a primary contact for your IT provider? Is it clear who has authority to shut down systems if needed? Who handles communication with customers or regulators? Write these names, phone numbers and responsibilities down. If one person is unavailable, name a backup.

    2. Identify. Define how incidents get reported internally. A simple rule works: if someone sees anything suspicious, they report it to a named person immediately, no judgement. That person contacts your IT provider or internal IT lead to assess whether it is a genuine incident. Speed matters here. The average attacker dwell time inside a compromised environment is 90 to 120 days.

    3. Contain. Once an incident is confirmed, the priority is stopping it from spreading. This might mean isolating an affected machine from the network, disabling a compromised account, or temporarily shutting down a system. Your IT provider should be leading this, but your plan should make clear who authorises these decisions internally.

    4. Recover. Restore affected systems from clean backups. Reset credentials. Verify that the threat has been fully removed before bringing systems back online. Document what happened and when.

    5. Learn. After recovery, review what went wrong, what went well and what needs to change. Update the plan based on what you learned. This step is the one most businesses skip, and it is the one that prevents the same thing happening again.

    Reporting Requirements Are Tightening

    Under the Cyber Security and Resilience Bill progressing through Parliament, organisations in scope will need to report cyber incidents within 24 hours, with a full report within 72 hours. Even if your business is not directly in scope, larger clients may require evidence that you have a documented incident response process as part of supply chain assurance.

    Having a plan already in place puts you ahead of the curve.

    Keep It Short, Test It Regularly

    The best incident response plans are short enough that people actually read them. One to two pages covering roles, contact details, the five steps and any specific instructions for your IT setup.

    Print a copy and keep it somewhere accessible. If your systems are encrypted by ransomware, a plan saved only on the network is useless.

    Test the plan at least once a year. Run a tabletop exercise: describe a scenario and talk through who does what. You will quickly find gaps, whether that is an out-of-date phone number, an unclear decision point or a step that nobody actually knows how to execute.

    You Do Not Have to Build This Alone

    If you want help creating an incident response plan that fits your business, or you want to make sure your current setup can detect and contain threats quickly, speak to The Unite Group about a managed security review. We work with SMEs across the North East to build practical, proportionate security processes backed by 24/7 monitoring and rapid response tools.

  • Phishing Attacks in 2026: What UK Businesses Still Get Wrong

    Phishing Attacks in 2026: What UK Businesses Still Get Wrong

    Phishing attacks remain the most common cause of cyber breaches in the UK. The government’s Cyber Security Breaches Survey found that 85% of businesses that experienced a breach identified phishing as the attack method. That figure has barely shifted in three years. What has changed is how the attacks look, how they arrive, and why email filters alone no longer catch them.

    For SMEs, the risk is straightforward. Phishing works because it targets people, not systems. And unless your team knows what to look for, a single click can give an attacker access to your email accounts, customer data or financial systems.

    Why Phishing Has Become Harder to Spot

    A few years ago, most phishing emails were easy to identify. Poor spelling, generic greetings, suspicious sender addresses. That is no longer the case.

    Attackers now use AI tools to generate phishing emails that match the tone, formatting and language of legitimate business communication. They research targets using LinkedIn, company websites and public data to craft messages that feel personal and relevant. A finance team member might receive what looks like a genuine invoice from a known supplier. A director might get a convincing request from what appears to be their bank.

    Beyond email, phishing has expanded into other channels. Voice phishing (vishing) uses phone calls, often spoofing real numbers, to pressure staff into sharing credentials or making payments. QR code phishing (quishing) embeds malicious links in printed materials or PDF attachments, bypassing email filtering entirely. SMS phishing (smishing) targets mobile devices where people tend to be less cautious.

    The Mistakes Businesses Keep Making

    Relying entirely on email filters. Filters catch a lot, but they are not infallible. AI-generated phishing emails are specifically designed to pass through automated detection. Filters should be a layer of defence, not the only one.

    Running training once a year. An annual awareness session does not change behaviour. Monthly, bite-sized training with simulated phishing tests is what actually builds recognition skills over time. Staff need to practise identifying threats in realistic conditions, not just sit through a slide deck.

    No clear process for reporting. If someone suspects a phishing email, do they know what to do? Many businesses have no defined process, and staff worry about looking foolish for flagging something that might be legitimate. A simple, blame-free reporting process catches threats faster and encourages vigilance.

    Assuming small businesses are not targeted. Attackers increasingly target SMEs because they tend to have weaker defences and less formal processes. Automated phishing campaigns do not discriminate by company size. If your email addresses are publicly listed, you are a target.

    What Actually Reduces Risk

    Effective phishing defence combines technical controls with regular staff training.

    On the technical side, ensure your email platform has modern anti-phishing protections enabled. If you use Microsoft 365, check that Safe Links and Safe Attachments are turned on. Make sure multi-factor authentication is active on every account, so that even if credentials are stolen, attackers cannot log in without a second factor.

    On the people side, invest in ongoing cyber security training that includes regular phishing simulations. This does not need to be time-consuming or expensive. Managed training platforms run automatically, track completion, and provide targeted follow-up for anyone who falls for a test. The data from simulations shows you exactly where your team’s weaknesses are.

    Create a clear internal process: if you receive a suspicious email, forward it to a designated address or flag it in your email client. Do not click, do not reply, do not forward it to colleagues to ask ‘does this look dodgy to you?’

    What to Do If Someone Clicks

    If a staff member clicks a phishing link or enters credentials on a suspicious page, act quickly. Change the affected passwords immediately. Check whether the compromised account has been used to send further phishing emails internally or to contacts. Review recent sign-in activity for anything unusual.

    If you work with a managed IT provider, report it to them straight away. Providers with proactive monitoring tools can isolate affected accounts and check for signs of deeper compromise before it spreads.

    The speed of response matters more than blame. Businesses that have a tested incident response process recover faster and limit damage. Businesses that do not often discover the breach weeks later, after significant harm has already been done.

    Phishing Prevention Starts with People

    Technical tools help, but phishing exploits human judgement. The businesses that handle it best are the ones where staff feel confident identifying threats and comfortable reporting them.

    If your team has not had structured phishing awareness training recently, or if you are unsure how your current defences measure up, talk to The Unite Group about managed security awareness training. We run phishing simulations and ongoing training programmes that fit around your team’s working day and give you clear data on where to focus.

  • ISDN Switch-Off Checklist: Every Device Your Business Needs to Migrate Before 2027

    ISDN Switch-Off Checklist: Every Device Your Business Needs to Migrate Before 2027

    All ISDN and PSTN services in the UK will be permanently switched off on 31 January 2027. An estimated six million businesses still rely on these legacy connections for phone systems, broadband or connected devices, and many have not started planning their migration. No new ISDN lines have been available since September 2023, Openreach is withdrawing remaining services region by region through 2026, and there will be no further extension.

    The replacement technology, VoIP and IP-based connectivity, is already well established and brings genuine improvements in flexibility, cost and reliability. But the transition is not as simple as swapping a handset. Businesses that only think about their phone system risk overlooking the alarms, payment terminals, lift phones and monitoring equipment that also depend on copper lines.

    At The Unite Group, we handle ISDN-to-IP migrations for businesses across the North East and beyond, covering phones, broadband and every connected device in between. This checklist is designed to help you audit your premises and identify everything that needs to move before the deadline.

    Your Room-by-Room Migration Checklist

    Walk through your premises and check every device that connects to a phone socket or ISDN line. Here is what to look for.

    Phone system

    If you are running a traditional PBX connected to ISDN30 or ISDN2 lines, it will stop working entirely. You need to move to a cloud-hosted phone system or, if your existing PBX supports it, add a SIP gateway to route calls over your broadband instead. Your existing phone numbers can be ported to the new system.

    Broadband

     If your internet connection runs over an ADSL line or FTTC broadband that depends on an active phone line, you will need to switch to SoGEA or FTTP (full fibre) where available. Check with your provider which options are available at your premises.

    Intruder alarm

    Many alarm systems use a phone line to call the monitoring centre when triggered. After the switch-off, that connection will not work. Contact your alarm provider to check whether your system is IP-compatible or needs replacing with one that communicates over broadband or 4G.

    Fire alarm

    Fire panel communicators that dial out over PSTN will fail. These need upgrading to IP-based or cellular communicators. Given the safety implications, this should be a priority rather than something left until the final months.

    Lift emergency phone

    Building regulations require lifts to have a working emergency phone. Most use an analogue phone line. After the switch-off, these need replacing with IP or GSM-based lift communicators. Speak to your lift maintenance provider about compatible options.

    Card payment terminals

    Older EPOS and card terminals that dial out over a phone line will stop processing payments. Most modern terminals use broadband or 4G connectivity, but if your terminal still has a phone cable connected, it needs replacing or upgrading.

    Fax machine

    If your business still uses fax (some legal and healthcare businesses do), physical fax machines connected to a phone line will stop working. Online fax services that send and receive via email are the practical replacement.

    Door entry and intercom systems

    Some door entry systems use phone lines to call internal extensions or mobile numbers. These need checking for IP compatibility.

    Building management systems (BMS) 

    HVAC monitoring, water treatment controls and similar systems sometimes phone home using analogue lines. Check with your building management provider.

    CCTV and remote monitoring

    Older CCTV systems that transmit footage via phone lines need upgrading to IP-based cameras and network video recorders.

    Telecare and health monitoring devices

    Pendant alarms and health monitoring equipment that use phone lines require urgent attention. BT has paused forced migrations for vulnerable customers, but replacement devices still need to be in place before the deadline.

    When to Start (and When It Gets Difficult)

    Migration is not something you can do in a week. A typical business needs to audit what it has, choose replacement solutions, order equipment, schedule installations and test everything. For most SMEs, the whole process takes two to four months when planned properly.

    As January 2027 approaches, demand for engineers, equipment and installation slots will spike. Businesses that leave it until the final quarter of 2026 risk delays, limited availability, and higher costs from providers under pressure to deliver.

    The sensible window for migration is now through the end of 2026. Starting earlier gives you time to test, resolve issues, and avoid the inevitable last-minute scramble.

    What Happens If You Miss the Deadline

    On 1 February 2027, every service still connected to the old copper phone network stops working. Phone lines go silent. Alarm systems lose their connection to monitoring centres. Card terminals stop processing payments. Broadband connections that depend on a phone line drop offline.

    There will be no extension. The infrastructure is being physically retired because it is too old and expensive to maintain. Ofcom reported a 45% increase in PSTN resilience incidents in 2024, underlining why the network is being replaced.

    Get a Free Migration Audit

    If you are not sure which devices in your business still rely on ISDN or PSTN, that is the first thing to find out. Contact The Unite Group for a free migration audit. We will walk through your setup, identify every affected device and service, and give you a clear plan for migrating everything before the deadline, including your phone system, broadband and connected equipment.

  • What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    Most businesses understand that antivirus is no longer enough. Fewer understand what happens next. Managed endpoint detection and response (EDR) monitors every laptop, desktop and server in your business for suspicious activity, then detects, investigates and responds to threats before they cause damage. The difference between EDR and antivirus is not just what it catches. It is what happens after it catches it. 

    At The Unite Group, we deliver managed EDR through our partnership with Huntress. This article shows you what that looks like in practice, what the technology does, who is watching, and what happens when it finds something.

    The Team Behind the Screen 

    Former intelligence agency experts founded Huntress, and multiple specialist teams now run its Security Operations Centre. These include security analysts who investigate alerts, threat hunters who proactively search for hidden compromises, detection engineers who build and refine the rules that catch threats, threat intelligence researchers who track emerging attack techniques, and a dedicated threat response team that handles serious incidents. 

    This is not an automated system that sends you an email and hopes you know what to do. It is a team of people watching your environment around the clock, backed by tooling that monitors millions of endpoints globally. The threat intelligence from that scale feeds directly into the detection rules applied to your business, meaning you benefit from patterns spotted across thousands of other organisations. 

    What Huntress EDR Actually Detects 

    Traditional antivirus uses signature-based detection: it recognises known malware and blocks it. That is still important, but it cannot keep up with the volume of new threats created daily. EDR takes a different approach, monitoring behaviour rather than matching signatures. 

    Huntress looks for specific threat patterns across your endpoints. These include malicious process behaviour, where a legitimate application starts doing something it should not. Persistent footholds, where an attacker installs a secondary remote management tool to maintain access even after the obvious threat is removed. Ransomware canaries, which act as early warning tripwires that detect encryption activity before it spreads across your network. And open port detection, which identifies ports left open either accidentally or intentionally that could expose your systems. 

    The typical threat actor remains undetected inside a business environment for 90 to 120 days, quietly gathering information and preparing for a larger attack. EDR reduces that dwell time dramatically by identifying abnormal activity early and triggering a response in minutes rather than months. 

    Eight Minutes from Detection to Action 

    Speed matters because the gap between detection and response is where damage happens. Huntress operates with an average mean time to respond of eight minutes. That covers the entire cycle: detection, investigation, remediation and reporting. 

    When something suspicious is identified, the SOC team investigates immediately. If it is a genuine threat, they act. That typically means isolating the affected machine from the network so the threat cannot spread, killing malicious processes, removing persistent footholds, and providing clear guidance on cleanup and recovery. If backup systems are in place, they coordinate with those too, minimising downtime and data loss. 

    The system is 99.3% accurate in identifying real threats. That matters because false positives waste time and erode trust. If every alert turns out to be nothing, people stop paying attention. Huntress’s accuracy rate means that when an alert comes through, it is almost always something that genuinely needs addressing. 

    What You See as a Business Owner 

    You do not need to become a security expert to benefit from managed EDR. When a threat is detected and handled, you receive a clear report explaining what happened, what action was taken, and whether anything further is needed from your side. 

    Monthly reporting shows you what was detected, how your environment is performing, and whether any patterns need attention. This is useful not just for your own awareness but for demonstrating to clients, insurers and auditors that your business has active, continuous security monitoring in place. Cyber insurers increasingly expect evidence of EDR coverage, and having a managed service with documented response data strengthens your position at renewal. 

    How Managed EDR Fits with Everything Else 

    EDR is not a replacement for the rest of your security stack. It works alongside antivirus, multi-factor authentication, email filtering, and security awareness training. Think of it as the safety net: when something gets past the first layers of defence, EDR catches it and responds before it becomes a breach. 

    It also pairs directly with incident response planning. If you have a documented response plan, EDR provides the detection and containment steps that feed into it. If you do not have a plan yet, managed EDR gives you a level of protection while you build one. 

    For businesses that already hold Cyber Essentials certification, EDR is the logical next step. Cyber Essentials covers the baseline controls. EDR provides ongoing, active monitoring that Cyber Essentials does not require but that modern threats increasingly demand. 

    Is Managed EDR Right for Your Business? 

    If your team uses laptops, connects remotely, handles sensitive data, or operates in a sector where cyber insurance or compliance matters, managed EDR is worth considering. Huntress is not just for large businesses. It was built specifically for small and mid-sized organisations that do not have in-house security teams but still need enterprise-grade protection.

    The agent is lightweight and runs in the background without affecting device performance. Most users will not notice it once you install it. You can roll it out easily across your devices as part of your managed IT services.

    If you want to understand how managed EDR would work for your business, or you want to see what Huntress detects across your current environment, contact The Unite Group for a security assessment. We will review your setup, explain what managed EDR covers, and give you a clear recommendation. 

  • What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    Most businesses understand that antivirus is no longer enough. Fewer understand what happens next. Managed endpoint detection and response (EDR) monitors every laptop, desktop and server in your business for suspicious activity, then detects, investigates and responds to threats before they cause damage. The difference between EDR and antivirus is not just what it catches. It is what happens after it catches it. 

    At The Unite Group, we deliver managed EDR through our partnership with Huntress. This article explains what that looks like in practice: what the technology does, who is watching, and what happens when something is found. 

    The Team Behind the Screen 

    Huntress was founded by former intelligence agency experts and operates a Security Operations Centre staffed by multiple specialist teams. These include security analysts who investigate alerts, threat hunters who proactively search for hidden compromises, detection engineers who build and refine the rules that catch threats, threat intelligence researchers who track emerging attack techniques, and a dedicated threat response team that handles serious incidents. 

    This is not an automated system that sends you an email and hopes you know what to do. It is a team of people watching your environment around the clock, backed by tooling that monitors millions of endpoints globally. The threat intelligence from that scale feeds directly into the detection rules applied to your business, meaning you benefit from patterns spotted across thousands of other organisations. 

    What Huntress EDR Actually Detects 

    Traditional antivirus uses signature-based detection: it recognises known malware and blocks it. That is still important, but it cannot keep up with the volume of new threats created daily. EDR takes a different approach, monitoring behaviour rather than matching signatures. 

    Huntress looks for specific threat patterns across your endpoints. These include malicious process behaviour, where a legitimate application starts doing something it should not. Persistent footholds, where an attacker installs a secondary remote management tool to maintain access even after the obvious threat is removed. Ransomware canaries, which act as early warning tripwires that detect encryption activity before it spreads across your network. And open port detection, which identifies ports left open either accidentally or intentionally that could expose your systems. 

    The typical threat actor remains undetected inside a business environment for 90 to 120 days, quietly gathering information and preparing for a larger attack. EDR reduces that dwell time dramatically by identifying abnormal activity early and triggering a response in minutes rather than months. 

    Eight Minutes from Detection to Action 

    Speed matters because the gap between detection and response is where damage happens. Huntress operates with an average mean time to respond of eight minutes. That covers the entire cycle: detection, investigation, remediation and reporting. 

    When something suspicious is identified, the SOC team investigates immediately. If it is a genuine threat, they act. That typically means isolating the affected machine from the network so the threat cannot spread, killing malicious processes, removing persistent footholds, and providing clear guidance on cleanup and recovery. If backup systems are in place, they coordinate with those too, minimising downtime and data loss. 

    The system is 99.3% accurate in identifying real threats. That matters because false positives waste time and erode trust. If every alert turns out to be nothing, people stop paying attention. Huntress’s accuracy rate means that when an alert comes through, it is almost always something that genuinely needs addressing. 

    What You See as a Business Owner 

    You do not need to become a security expert to benefit from managed EDR. When Huntress detects and handles a threat, you receive a clear report that explains what happened, what action it took, and whether you need to do anything else.

    Monthly reporting shows you what the system detected, how your environment is performing, and whether any patterns need attention. This is useful not just for your own awareness but for demonstrating to clients, insurers and auditors that your business has active, continuous security monitoring in place. Cyber insurers increasingly expect evidence of EDR coverage, and having a managed service with documented response data strengthens your position at renewal. 

    How Managed EDR Fits with Everything Else 

    EDR is not a replacement for the rest of your security stack. It works alongside antivirus, multi-factor authentication, email filtering, and security awareness training. Think of it as the safety net: when something gets past the first layers of defence, EDR catches it and responds before it becomes a breach. 

    It also pairs directly with incident response planning. If you have a documented response plan, EDR provides the detection and containment steps that feed into it. If you do not have a plan yet, managed EDR gives you a level of protection while you build one. 

    For businesses that already hold Cyber Essentials certification, EDR is the logical next step. Cyber Essentials covers the baseline controls. EDR provides ongoing, active monitoring that Cyber Essentials does not require but that modern threats increasingly demand. 

    Is Managed EDR Right for Your Business? 

    If your team uses laptops, connects remotely, handles sensitive data, or operates in a sector where cyber insurance or compliance matters, managed EDR is worth considering. Huntress is not just for large businesses. It was built specifically for small and mid-sized organisations that do not have in-house security teams but still need enterprise-grade protection.

    The agent is lightweight and runs in the background without affecting device performance. Most users will not notice it once you install it. You can deploy it easily across your devices as part of your managed IT services.

    If you want to understand how managed EDR would work for your business, or you want to see what Huntress detects across your current environment, contact The Unite Group for a security assessment. We will review your setup, explain what managed EDR covers, and give you a clear recommendation. 

  • What Is SoGEA Broadband and Why Is It Replacing Your Business Phone Line?

    What Is SoGEA Broadband and Why Is It Replacing Your Business Phone Line?

    SoGEA stands for Single Order Generic Ethernet Access. In plain English, it is broadband delivered over the same fibre-to-the-cabinet infrastructure your business probably already uses, but without requiring a traditional phone line. You get the internet connection without the landline rental you may no longer need. 

    If that sounds straightforward, it is. The reason it matters right now is the UK’s PSTN switch-off. By 31 January 2027, every traditional analogue and ISDN phone line in the country will be permanently disconnected. Businesses that currently get their broadband bundled with a phone line will need to move to a standalone broadband product. For most premises where full fibre is not yet available, SoGEA is that product. 

    How SoGEA Differs from Your Current Broadband 

    Most UK businesses currently use FTTC (Fibre to the Cabinet) broadband. This runs a fibre optic cable from the exchange to a green street cabinet, then copper from the cabinet to your premises. It requires an active phone line, even if you never make a call on it. 

    SoGEA uses exactly the same physical infrastructure, the same fibre to the cabinet and copper to the premises, but removes the phone line requirement. The connection is broadband-only. You get the same speeds (up to 80Mbps download, 20Mbps upload) without paying for a landline you do not use. 

    The practical differences are small but meaningful. There is no separate phone line rental charge, typically £15 to £25 per month that businesses can save. Installation is a single order rather than one for the phone line and another for broadband. And because there is one less service running over the copper, connections tend to be more stable with fewer fault points. 

    What Happens to Your Phone Calls 

    Moving to SoGEA does not mean giving up business phone calls. It means your calls will run over your broadband connection using VoIP (Voice over Internet Protocol) instead of an analogue phone line. 

    In practice, this means you can keep your existing business phone number. Your provider will port it to a cloud-hosted phone system that routes calls over the internet. The quality is typically better than traditional calls, and you gain features like call routing, voicemail to email, mobile app integration and the ability to take calls from anywhere. 

    If your business already uses a cloud phone system or Microsoft Teams for calling, SoGEA is a natural fit. You are already making calls over the internet; SoGEA simply removes the legacy phone line underneath your broadband that you are no longer using. 

    SoGEA vs FTTP: Which Should You Choose? 

    Full Fibre to the Premises (FTTP) delivers a fibre optic cable directly to your building, offering speeds of up to 1Gbps. It is faster, more reliable, and the future of UK connectivity. 

    However, FTTP is not yet available everywhere. Openreach’s full fibre rollout continues, but many business premises, particularly outside major city centres, do not have access yet. 

    Where FTTP is available, it is generally the better long-term choice. Where it is not, SoGEA is the practical next step. It future-proofs your broadband setup ahead of the PSTN switch-off while delivering reliable speeds for day-to-day business use including video calls, cloud software and payment systems. 

    Check with your communications provider to find out which options are available at your premises. 

    Do You Need a New Router?

     

    In most cases, yes. Your broadband provider will typically supply a new router configured for SoGEA. Even if your existing FTTC router is technically compatible, using the supplied equipment ensures the connection is set up correctly and avoids compatibility issues. 

    The changeover is straightforward. A standard SoGEA installation involves a single engineer visit, and most businesses experience minimal disruption during the switch. 

    Why You Should Act Before 2027 

    The PSTN switch-off is not a gradual process. On 31 January 2027, every service still running on the old copper phone network stops working. That includes phone lines, broadband services that depend on those lines, and any devices connected through them, from alarms to card machines. 

    Businesses that migrate early avoid the rush. As the deadline approaches, demand for installations, engineer visits, and equipment will increase sharply. Migrating now gives you time to test the new setup, train your team, and resolve any issues before they become urgent. 

    For a complete checklist of what needs migrating before the deadline, read our ISDN switch-off checklist

    If you are unsure whether your broadband setup is ready for the switch-off, contact The Unite Group. We will check what you currently have, confirm what is available at your premises, and make sure you are ready well ahead of the deadline. 

  • From Experimental to Essential: How UK SMEs Are Embracing AI in 2026

    From Experimental to Essential: How UK SMEs Are Embracing AI in 2026

    AI for SMEs has shifted from ‘something to try when we have time’ to a practical way to get more done with the same headcount. For UK SMEs, AI is now less about experiments and more about quietly handling admin, content and routine decision-making in the background. The real question is no longer whether to use AI, but how to use it in a way that fits your business, your data and your people.

    AI has moved from hype to everyday tool

    A few years ago, AI lived in pilot projects and side experiments. Someone in marketing tried a copy tool, someone in operations played with a bot, and everything stayed disconnected.

    By 2026, AI is becoming part of the normal toolkit for many SMEs. Staff are increasingly asking whether AI can help with a task in the same way they might ask whether a template already exists. The difference now is accessibility, you do not need a large IT project for basic productivity gains.

    That said, there is still a big gap between interest and results. The businesses that see consistent value tend to treat AI as a workflow improvement, not a novelty.

    Why AI has become more ‘essential’ for SMEs

    For most small and medium businesses, the pressure points are familiar: too many tasks, not enough people, and constant cost pressure. AI helps most when it does the unglamorous work well, such as:

    • taking on repetitive, rules-based tasks so people focus on judgement and relationships
    • speeding up document, email and content work that used to take much longer
    • helping teams find information faster and work more consistently

    The key shift is mindset. AI stops being a side project and becomes part of how you manage capacity, design roles, and decide where humans add the most value.

    How SMEs are actually using AI in 2026

    The most useful AI use in SMEs is usually practical and contained. A typical pattern looks like this.

    1) Admin and operations

    AI tools often start by supporting routine admin: drafting and polishing emails, summarising meeting notes, and producing first drafts of standard documents and reports. For small teams, even modest time saved here can create breathing room.

    If you are already on Microsoft 365, this is where Copilot-style features tend to land first, because they sit inside tools your team already uses. That is also why getting your Microsoft 365 environment configured properly matters before you encourage wider adoption.

    2) Customer communication

    Customer-facing teams use AI to turn rough notes into clearer updates, propose responses to common support queries, and help rewrite messages so they are easier to understand. The strongest results come when AI drafts and humans decide, staff stay in control of tone, judgement, and relationship cues.

    3) Marketing and content

    Marketing teams often adopt early: content outlines, repurposing talks into posts, and generating headline variations. Guardrails matter here. Without a clear voice and review process, AI-generated content becomes generic fast. With good briefs and human editing, it becomes a fast way to explore more ideas without increasing budget.

    4) Internal knowledge and support

    Some SMEs are starting to build internal ‘copilots’ on top of policy documents, procedures and handbooks. The goal is simple: reduce time spent hunting through folders, and reduce repeat questions to managers.

    This works best when your information is organised and access permissions make sense. If your SharePoint and file permissions are messy, AI can amplify that mess by making it easier to surface the wrong thing quickly.

    The new risks: skills, shadow AI and trust

    As AI becomes normal, the risks shift too. Most fall into three buckets.

    Skills and confidence

    If leaders and managers are not confident, AI adoption can swing between two extremes: blocking it entirely, or letting people use whatever they like without guidance. A more useful approach is to treat AI skills as part of normal digital literacy. Short training on real tasks usually beats long theory sessions.

    Shadow AI and data sprawl

    If you do not provide approved tools, employees will still experiment. That can create ‘shadow AI’, where sensitive information gets pasted into consumer tools without oversight. A practical response is to approve a small set of tools, set clear rules on what must never be shared, and provide safer organisation-managed options where possible.

    This is where baseline security and access controls are non-negotiable, especially MFA. If you need a simple internal explainer for staff, Unite’s guide on multi-factor authentication is a useful starting point.

    Quality and trust

    AI can sound confident and still be wrong. The simplest protection is cultural: treat AI like a helpful junior colleague. It can draft, summarise and suggest, but a human always reviews and signs off, especially for customer-facing work and anything financial, legal, or contractual.

    Turning AI from experiments into a practical plan

    If AI is going to be useful rather than noisy, it needs a basic plan. For a typical SME, that plan can be lightweight.

    1) Map where AI can genuinely help

    Ask each team:

    • which tasks feel repetitive or admin-heavy
    • where backlogs and delays are happening
    • where consistency is hard to maintain

    This usually reveals a handful of high-value use cases in operations, customer service, and marketing.

    2) Choose two or three priority workflows

    Rather than trying to ‘do AI everywhere’, pick a small set of workflows and define what good looks like. For example:

    • email and document drafting for client-facing roles
    • meeting notes and action capture for managers
    • internal knowledge search across policies and procedures

    3) Set simple guardrails

    A one-page policy can go a long way. Cover: approved tools, what data is off-limits, who reviews what, and how staff flag concerns. Keep it practical, so people actually use it.

    If you are already working towards more formal assurance, it also helps to align AI use with your wider security basics and governance. For some organisations, working towards Cyber Essentials is a useful way to tighten fundamentals at the same time.

    4) Support your team, not just your tools

    Tools alone rarely change much. The SMEs that get the most value from AI tend to run short demos on real tasks, encourage staff to share practical wins, and make it normal to say ‘I tried this and it did not work’. That is how you move from curiosity to reliable habits.

    A better way to think about AI in 2026

    A realistic aim is to make AI boring. Not flashy, not chaotic, not a separate ‘AI project’, just a small, stable part of how work gets done.

    When you treat AI like routine workflow improvement, the priorities become clearer: pick the right tools, sort your information, tighten access, and train people to use it responsibly. That is how you get the upside without the clutter.

    Want to make AI useful without adding risk or confusion? Start with the foundations: your Microsoft 365 setup, permissions, identity controls, and a clear ‘house view’ on how staff should use AI day-to-day. That is the difference between scattered experiments and steady, repeatable gains.