UK mobile network operators will switch off their 2G networks between 2029 and 2033. The 3G switch-off is already nearly complete, with most operators finishing by early 2026. DSIT published formal guidance on 24 March 2026 confirming the timeline and urging businesses to identify affected devices well ahead of the shutdown.
The deadline feels distant, but the audit should not wait. Many SMEs have devices, SIMs and connected equipment running on 2G that they are not aware of. The businesses that identify these now have time to plan upgrades on their own terms.
The ones that leave it until the final year face the same last-minute scramble the PSTN switch-off is already creating.
Why 2G Matters More Than You Think
Most smartphones sold in the last five years support 4G and 5G. For handsets, the switch- off will be invisible to most users. The problem sits with older devices and connected equipment that was never designed to move beyond 2G.
Business mobiles issued three or four years ago to warehouse staff, drivers or site workers may still be basic feature phones running on 2G. Company-issued handsets are often replaced less frequently than personal phones, particularly for roles where a smartphone is not needed.
Beyond handsets, many businesses have equipment that connects over 2G without anyone thinking about it. Vehicle trackers in fleet vans, IoT sensors for temperature monitoring, alarm communicators that fall back to 2G when broadband fails, agricultural monitoring devices, personal safety alarms, and older EPOS terminals with SIM-based connectivity all potentially rely on 2G.
What to Audit in Your Business
Walk through your operations and identify every device that uses a mobile connection. The categories most SMEs miss are listed here.
Staff handsets. Check whether any company-issued phones are 2G-only. Look for “2G” or “E” on the signal indicator. If the phone never shows “4G” or “5G”, it will stop working when 2G is switched off.
Vehicle and fleet trackers. GPS tracking devices in vans, trucks or company vehicles often use 2G to transmit location data. Check with your tracking provider whether the hardware supports 4G.
Alarm systems. Some intruder and fire alarm communicators use 2G SIMs as a backup path when the primary broadband connection fails. This is separate from the ISDN/PSTN switch-off issue, which affects landline-connected alarms. Check with your alarm monitoring provider.
IoT and environmental sensors. Temperature monitors in cold storage, water leak sensors, air quality monitors and similar connected devices may use 2G or 3G SIMs. These are often installed once and forgotten until they stop reporting.
Personal safety devices. Lone worker alarms and personal safety pendants used by staff working remotely or in high-risk environments may depend on 2G to contact monitoring centres.
Payment terminals. Older mobile card machines with SIM-based connectivity may still fall back to 2G in areas with weak 4G coverage.
The Timeline and What It Means
The government’s confirmed timeline is 2029 to 2033 for 2G switch-off across all operators. Each network will set its own schedule within that window. VMO2 withdrew 2G roaming services in October 2025 and completed its 3G switch-off by early 2026. Other operators are expected to publish their 2G timelines during 2026 and 2027.
For businesses, the practical implication is straightforward. Devices purchased or installed today should support 4G at minimum. Any procurement decisions made from now on should exclude 2G-only equipment. And existing 2G devices should be catalogued so they can be replaced in phases rather than all at once under deadline pressure.
Start the Audit Before It Becomes Urgent
The ISDN switch-off has shown what happens when businesses delay infrastructure migration. Engineers become scarce, equipment availability tightens, and costs increase. The 2G timeline is longer, but the principle is the same: businesses that act early have more options and lower costs.
If you need help auditing your mobile estate, identifying 2G-dependent devices, or planning replacements, contact The Unite Group. We manage business communications and connectivity across the North East, and we can assess your device fleet alongside your broader telecoms infrastructure.
If your business uses Microsoft 365, you already have access to Power Automate. Most SMEs never touch it. The tool sits inside your existing subscription, capable of automating repetitive admin tasks that eat into your team’s working day, but nobody has time to explore what it actually does.
Power Automate connects the Microsoft 365 apps your team already uses (Outlook, Teams, SharePoint, Excel, Forms) and lets you build automated workflows between them without writing code. An invoice arrives by email and the system routes it for approval automatically.A new starter joins and their onboarding checklist populates in Teams. A contract renewal date approaches and the account manager gets a reminder. These are not complex IT projects. Most take under an hour to set up using built-in templates. Here are ten that deliver immediate time savings for a typical SME office.
Approvals That Do Not Live in Someone’s Inbox
1. Expense approvals via Teams. When a staff member submits an expense (through a SharePoint list or Microsoft Form), Power Automate sends an approval request to their manager in Teams. The manager approves or rejects with one tap.The system logs the result automatically and sends the employee a confirmation email. No chasing, no lost receipts, no paper forms.
2. Document sign-off. Upload a document to a specific SharePoint folder and Power Automate triggers an approval request to the designated reviewer. Once approved, the file moves to an “Approved” folder automatically. Useful for policies, proposals, marketing materials, or anything that needs a second pair of eyes before it goes out.
3. Purchase order approvals. Route purchase requests through a defined approval chain based on value. Orders under a set threshold get approved by a team lead. Orders above it escalate to a director. The entire trail is logged in SharePoint.
Onboarding and Off-boarding
4. New starter onboarding checklist. When a new employee is added to your HR list (or a Microsoft Form is submitted by the hiring manager), Power Automate creates a task list in Planner or Teams with every onboarding step: equipment request, account setup, induction booking, policy acknowledgements. Each task is assigned to the relevant person with a due date.
5. Leaver process trigger. When someone’s leaving date is entered, the flow notifies IT to schedule account deactivation, reminds their manager to reassign shared files, and sends HR a checklist for final paperwork. This reduces the risk of ex-employees retaining access to systems, which is a common security gap flagged during Cyber Essentials assessments.
Finance and Admin Automation
6. Invoice payment reminders. Connect Power Automate to an Excel tracker or SharePoint list of outstanding invoices. When a payment date arrives, the flow sends a polite reminder email to the client and posts a notification in your finance Teams channel. No more manually checking spreadsheets every morning.
7. Contract renewal alerts. Store contract end dates in a SharePoint list. Power Automate sends an alert 90 days, 30 days and 7 days before each renewal, giving your team time to review terms, renegotiate or switch providers. This is especially useful for software licences, insurance policies and supplier agreements.
Communication and Reporting
8. Weekly team summary from Forms. Set up a recurring Microsoft Form for weekly updates (project status, blockers, wins). Power Automate collects responses every Friday and compiles them into a single Teams message or email to the manager. Replaces the meeting that could have been an email.
9. Customer enquiry routing. When a contact form submission arrives (via Microsoft Forms or a connected web form), Power Automate sends it to the right person based on the enquiry type, logs it in a SharePoint list, and sends the customer an acknowledgement email within seconds.
10. Teams channel notifications for key events. Set up Teams notifications for important activity across your M365 environment, such as large external file shares, SharePoint site membership changes, or critical Planner tasks becoming overdue.This keeps your team aware without relying on people checking dashboards.
A Note on Governance
Shadow flows can become a problem if everyone creates automations without oversight. Set clear ownership for each flow, document what it does and who maintains it, and review active flows quarterly. If a flow breaks or a staff member leaves, someone needs to know it exists. Your managed IT provider can help set up a governance framework alongside the automations themselves.
Where to Start
Pick one workflow that solves a real, daily frustration for your team. Set it up using a Power Automate template, test it, and let it run for two weeks. Once people see admin tasks disappearing, the appetite for more automation follows naturally.
Phishing attacks remain the most common cause of cyber breaches in the UK. The government’s Cyber Security Breaches Survey found that 85% of businesses that experienced a breach identified phishing as the attack method. That figure has barely shifted in three years. What has changed is how the attacks look, how they arrive, and why email filters alone no longer catch them.
For SMEs, the risk is straightforward. Phishing works because it targets people, not systems. And unless your team knows what to look for, a single click can give an attacker access to your email accounts, customer data or financial systems.
Why Phishing Has Become Harder to Spot
A few years ago, most phishing emails were easy to identify. Poor spelling, generic greetings, suspicious sender addresses. That is no longer the case.
Attackers now use AI tools to generate phishing emails that match the tone, formatting and language of legitimate business communication. They research targets using LinkedIn, company websites and public data to craft messages that feel personal and relevant. A finance team member might receive what looks like a genuine invoice from a known supplier. A director might get a convincing request from what appears to be their bank.
Beyond email, phishing has expanded into other channels. Voice phishing (vishing) uses phone calls, often spoofing real numbers, to pressure staff into sharing credentials or making payments. QR code phishing (quishing) embeds malicious links in printed materials or PDF attachments, bypassing email filtering entirely. SMS phishing (smishing) targets mobile devices where people tend to be less cautious.
The Mistakes Businesses Keep Making
Relying entirely on email filters. Filters catch a lot, but they are not infallible. AI-generated phishing emails are specifically designed to pass through automated detection. Filters should be a layer of defence, not the only one.
Running training once a year. An annual awareness session does not change behaviour. Monthly, bite-sized training with simulated phishing tests is what actually builds recognition skills over time. Staff need to practise identifying threats in realistic conditions, not just sit through a slide deck.
No clear process for reporting. If someone suspects a phishing email, do they know what to do? Many businesses have no defined process, and staff worry about looking foolish for flagging something that might be legitimate. A simple, blame-free reporting process catches threats faster and encourages vigilance.
Assuming small businesses are not targeted. Attackers increasingly target SMEs because they tend to have weaker defences and less formal processes. Automated phishing campaigns do not discriminate by company size. If your email addresses are publicly listed, you are a target.
What Actually Reduces Risk
Effective phishing defence combines technical controls with regular staff training.
On the technical side, ensure your email platform has modern anti-phishing protections enabled. If you use Microsoft 365, check that Safe Links and Safe Attachments are turned on. Make sure multi-factor authentication is active on every account, so that even if credentials are stolen, attackers cannot log in without a second factor.
On the people side, invest in ongoing cyber security training that includes regular phishing simulations. This does not need to be time-consuming or expensive. Managed training platforms run automatically, track completion, and provide targeted follow-up for anyone who falls for a test. The data from simulations shows you exactly where your team’s weaknesses are.
Create a clear internal process: if you receive a suspicious email, forward it to a designated address or flag it in your email client. Do not click, do not reply, do not forward it to colleagues to ask ‘does this look dodgy to you?’
What to Do If Someone Clicks
If a staff member clicks a phishing link or enters credentials on a suspicious page, act quickly. Change the affected passwords immediately. Check whether the compromised account has been used to send further phishing emails internally or to contacts. Review recent sign-in activity for anything unusual.
If you work with a managed IT provider, report it to them straight away. Providers with proactive monitoring tools can isolate affected accounts and check for signs of deeper compromise before it spreads.
The speed of response matters more than blame. Businesses that have a tested incident response process recover faster and limit damage. Businesses that do not often discover the breach weeks later, after significant harm has already been done.
Phishing Prevention Starts with People
Technical tools help, but phishing exploits human judgement. The businesses that handle it best are the ones where staff feel confident identifying threats and comfortable reporting them.
If your team has not had structured phishing awareness training recently, or if you are unsure how your current defences measure up, talk to The Unite Group about managed security awareness training. We run phishing simulations and ongoing training programmes that fit around your team’s working day and give you clear data on where to focus.
All ISDN and PSTN services in the UK will be permanently switched off on 31 January 2027. An estimated six million businesses still rely on these legacy connections for phone systems, broadband or connected devices, and many have not started planning their migration. No new ISDN lines have been available since September 2023, Openreach is withdrawing remaining services region by region through 2026, and there will be no further extension.
The replacement technology, VoIP and IP-based connectivity, is already well established and brings genuine improvements in flexibility, cost and reliability. But the transition is not as simple as swapping a handset. Businesses that only think about their phone system risk overlooking the alarms, payment terminals, lift phones and monitoring equipment that also depend on copper lines.
At The Unite Group, we handle ISDN-to-IP migrations for businesses across the North East and beyond, covering phones, broadband and every connected device in between. This checklist is designed to help you audit your premises and identify everything that needs to move before the deadline.
Your Room-by-Room Migration Checklist
Walk through your premises and check every device that connects to a phone socket or ISDN line. Here is what to look for.
Phone system
If you are running a traditional PBX connected to ISDN30 or ISDN2 lines, it will stop working entirely. You need to move to a cloud-hosted phone system or, if your existing PBX supports it, add a SIP gateway to route calls over your broadband instead. Your existing phone numbers can be ported to the new system.
Broadband
If your internet connection runs over an ADSL line or FTTC broadband that depends on an active phone line, you will need to switch to SoGEAor FTTP (full fibre) where available. Check with your provider which options are available at your premises.
Intruder alarm
Many alarm systems use a phone line to call the monitoring centre when triggered. After the switch-off, that connection will not work. Contact your alarm provider to check whether your system is IP-compatible or needs replacing with one that communicates over broadband or 4G.
Fire alarm
Fire panel communicators that dial out over PSTN will fail. These need upgrading to IP-based or cellular communicators. Given the safety implications, this should be a priority rather than something left until the final months.
Lift emergency phone
Building regulations require lifts to have a working emergency phone. Most use an analogue phone line. After the switch-off, these need replacing with IP or GSM-based lift communicators. Speak to your lift maintenance provider about compatible options.
Card payment terminals
Older EPOS and card terminals that dial out over a phone line will stop processing payments. Most modern terminals use broadband or 4G connectivity, but if your terminal still has a phone cable connected, it needs replacing or upgrading.
Fax machine
If your business still uses fax (some legal and healthcare businesses do), physical fax machines connected to a phone line will stop working. Online fax services that send and receive via email are the practical replacement.
Door entry and intercom systems
Some door entry systems use phone lines to call internal extensions or mobile numbers. These need checking for IP compatibility.
Building management systems (BMS)
HVAC monitoring, water treatment controls and similar systems sometimes phone home using analogue lines. Check with your building management provider.
CCTV and remote monitoring
Older CCTV systems that transmit footage via phone lines need upgrading to IP-based cameras and network video recorders.
Telecare and health monitoring devices
Pendant alarms and health monitoring equipment that use phone lines require urgent attention. BT has paused forced migrations for vulnerable customers, but replacement devices still need to be in place before the deadline.
When to Start (and When It Gets Difficult)
Migration is not something you can do in a week. A typical business needs to audit what it has, choose replacement solutions, order equipment, schedule installations and test everything. For most SMEs, the whole process takes two to four months when planned properly.
As January 2027 approaches, demand for engineers, equipment and installation slots will spike. Businesses that leave it until the final quarter of 2026 risk delays, limited availability, and higher costs from providers under pressure to deliver.
The sensible window for migration is now through the end of 2026. Starting earlier gives you time to test, resolve issues, and avoid the inevitable last-minute scramble.
What Happens If You Miss the Deadline
On 1 February 2027, every service still connected to the old copper phone network stops working. Phone lines go silent. Alarm systems lose their connection to monitoring centres. Card terminals stop processing payments. Broadband connections that depend on a phone line drop offline.
There will be no extension. The infrastructure is being physically retired because it is too old and expensive to maintain. Ofcom reported a 45% increase in PSTN resilience incidents in 2024, underlining why the network is being replaced.
Get a Free Migration Audit
If you are not sure which devices in your business still rely on ISDN or PSTN, that is the first thing to find out. Contact The Unite Group for a free migration audit. We will walk through your setup, identify every affected device and service, and give you a clear plan for migrating everything before the deadline, including your phone system, broadband and connected equipment.
The Cyber Security and Resilience Bill is the UK government’s most significant update to cyber legislation since the original NIS Regulations in 2018. It expands who must meet formal cyber security standards, tightens incident reporting timelines, and for the first time brings managed service providers under direct regulatory oversight. If your business uses an external IT provider or supplies services to larger organisations, this Bill will affect you.
The Bill passed its second reading in January 2026 and has been progressing through committee stage since February. While it primarily targets operators of essential services, data centres and MSPs, the ripple effect on SMEs through supply chain requirements is substantial.
What the Bill Actually Changes
Three things matter most for small and medium-sized businesses.
Managed service providers become regulated. An estimated 900 to 1,100 MSPs will come under direct ICO oversight. They will need to meet defined security standards and report incidents within prescribed timeframes. If your IT is managed externally, your provider will be held to higher standards, and you should be asking them how they are preparing.
Incident reporting gets stricter. Organisations in scope must report cyber incidents to their regulator and to the NCSC within 24 hours of becoming aware. A full report must follow within 72 hours. This replaces the slower, less consistent reporting that existed under the 2018 regulations.
Supply chain scrutiny increases. Regulated organisations will be required to assess and manage cyber risk across their suppliers. SMEs that supply goods or services to larger businesses can expect more cyber security clauses in contracts, assurance questionnaires and minimum securitystandards becoming routine.
How This Affects SMEs (Even If You Are Not Directly in Scope)
The Bill does not impose direct obligations on most small businesses. But the indirect effects are real.
Larger clients will start asking whether you hold Cyber Essentials certification, whether you have an incident response plan, and whether your data is properly protected. Businesses that cannot demonstrate reasonable cyber security measures risk losing contracts or being excluded from tender processes altogether.
The government has been clear that SMEs are not expected to invest in enterprise-grade tools. The expectation is proportionate: understand your risks, take reasonable steps to manage them, and be able to show evidence of both. Cyber Essentials, maintained access controls, regular patching and a tested incident response plan go a long way toward meeting that bar.
The Penalties Are Significant
For organisations directly in scope, fines can reach £17 million or 4% of global annual turnover, whichever is higher. For less severe breaches, the cap is £10 million or 2% of turnover. Regulators can also impose daily fines of up to £100,000 for ongoing non-compliance.
SMEs are unlikely to face fines directly under this Bill. But losing a contract because you cannot satisfy a client’s supply chain requirements has a similar financial impact at a smaller scale.
What You Should Do Now
You do not need to wait for the Bill to receive Royal Assent before acting. The direction is clear, and the expectations are already filtering into commercial contracts.
Start with a basic cyber security review. Identify what data your business holds and where it is stored. Check your backups and access controls. Make sure your multi-factor authentication is in place across all accounts. Consider whether Cyber Essentials certification would strengthen your position with clients.
If you use a managed IT provider, ask them directly how they are preparing for the new regulatory requirements. A good provider will already be working toward compliance. If they cannot answer that question clearly, it may be worth reviewing the relationship.
How This Connects to Your IT Provider
The Bill specifically names managed service providers as a new regulated category. This means your IT partner will face the same obligations as digital service providers: formal security standards, incident reporting duties and regulatory oversight by the ICO.
For businesses that already work with a proactive managed IT services provider, this should be reassuring. It raises the baseline across the industry and makes it harder for underqualified providers to operate without accountability.
At The Unite Group, we hold ISO 27001 certification and operate as an IASME-accredited Cyber Essentials certification body. We are already aligned with the standards the Bill is designed to enforce. If you want to understand how the Cyber Security and Resilience Bill affects your business or your current IT arrangements, speak to our team about a cyber security review and we will help you identify any gaps.
SoGEA stands for Single Order Generic Ethernet Access. In plain English, it is broadband delivered over the same fibre-to-the-cabinet infrastructure your business probably already uses, but without requiring a traditional phone line. You get the internet connection without the landline rental you may no longer need.
If that sounds straightforward, it is. The reason it matters right now is the UK’s PSTN switch-off. By 31 January 2027, every traditional analogue and ISDN phone line in the country will be permanently disconnected. Businesses that currently get their broadband bundled with a phone line will need to move to a standalone broadband product. For most premises where full fibre is not yet available, SoGEA is that product.
How SoGEA Differs from Your Current Broadband
Most UK businesses currently use FTTC (Fibre to the Cabinet) broadband. This runs a fibre optic cable from the exchange to a green street cabinet, then copper from the cabinet to your premises. It requires an active phone line, even if you never make a call on it.
SoGEA uses exactly the same physical infrastructure, the same fibre to the cabinet and copper to the premises, but removes the phone line requirement. The connection is broadband-only. You get the same speeds (up to 80Mbps download, 20Mbps upload) without paying for a landline you do not use.
The practical differences are small but meaningful. There is no separate phone line rental charge, typically £15 to £25 per month that businesses can save. Installation is a single order rather than one for the phone line and another for broadband. And because there is one less service running over the copper, connections tend to be more stable with fewer fault points.
What Happens to Your Phone Calls
Moving to SoGEA does not mean giving up business phone calls. It means your calls will run over your broadband connection using VoIP (Voice over Internet Protocol) instead of an analogue phone line.
In practice, this means you can keep your existing business phone number. Your provider will port it to a cloud-hosted phone system that routes calls over the internet. The quality is typically better than traditional calls, and you gain features like call routing, voicemail to email, mobile app integration and the ability to take calls from anywhere.
If your business already uses a cloud phone system or Microsoft Teams for calling, SoGEA is a natural fit. You are already making calls over the internet; SoGEA simply removes the legacy phone line underneath your broadband that you are no longer using.
SoGEA vs FTTP: Which Should You Choose?
Full Fibre to the Premises (FTTP) delivers a fibre optic cable directly to your building, offering speeds of up to 1Gbps. It is faster, more reliable, and the future of UK connectivity.
However, FTTP is not yet available everywhere. Openreach’s full fibre rollout continues, but many business premises, particularly outside major city centres, do not have access yet.
Where FTTP is available, it is generally the better long-term choice. Where it is not, SoGEA is the practical next step. It future-proofs your broadband setup ahead of the PSTN switch-off while delivering reliable speeds for day-to-day business use including video calls, cloud software and payment systems.
Check with your communications provider to find out which options are available at your premises.
Do You Need a New Router?
In most cases, yes. Your broadband provider will typically supply a new router configured for SoGEA. Even if your existing FTTC router is technically compatible, using the supplied equipment ensures the connection is set up correctly and avoids compatibility issues.
The changeover is straightforward. A standard SoGEA installation involves a single engineer visit, and most businesses experience minimal disruption during the switch.
Why You Should Act Before 2027
The PSTN switch-off is not a gradual process. On 31 January 2027, every service still running on the old copper phone network stops working. That includes phone lines, broadband services that depend on those lines, and any devices connected through them, from alarms to card machines.
Businesses that migrate early avoid the rush. As the deadline approaches, demand for installations, engineer visits, and equipment will increase sharply. Migrating now gives you time to test the new setup, train your team, and resolve any issues before they become urgent.
For a complete checklist of what needs migrating before the deadline, read our ISDN switch-off checklist.
If you are unsure whether your broadband setup is ready for the switch-off, contact The Unite Group. We will check what you currently have, confirm what is available at your premises, and make sure you are ready well ahead of the deadline.
AI for SMEs has shifted from ‘something to try when we have time’ to a practical way to get more done with the same headcount. For UK SMEs, AI is now less about experiments and more about quietly handling admin, content and routine decision-making in the background. The real question is no longer whether to use AI, but how to use it in a way that fits your business, your data and your people.
AI has moved from hype to everyday tool
A few years ago, AI lived in pilot projects and side experiments. Someone in marketing tried a copy tool, someone in operations played with a bot, and everything stayed disconnected.
By 2026, AI is becoming part of the normal toolkit for many SMEs. Staff are increasingly asking whether AI can help with a task in the same way they might ask whether a template already exists. The difference now is accessibility, you do not need a large IT project for basic productivity gains.
That said, there is still a big gap between interest and results. The businesses that see consistent value tend to treat AI as a workflow improvement, not a novelty.
Why AI has become more ‘essential’ for SMEs
For most small and medium businesses, the pressure points are familiar: too many tasks, not enough people, and constant cost pressure. AI helps most when it does the unglamorous work well, such as:
taking on repetitive, rules-based tasks so people focus on judgement and relationships
speeding up document, email and content work that used to take much longer
helping teams find information faster and work more consistently
The key shift is mindset. AI stops being a side project and becomes part of how you manage capacity, design roles, and decide where humans add the most value.
How SMEs are actually using AI in 2026
The most useful AI use in SMEs is usually practical and contained. A typical pattern looks like this.
1) Admin and operations
AI tools often start by supporting routine admin: drafting and polishing emails, summarising meeting notes, and producing first drafts of standard documents and reports. For small teams, even modest time saved here can create breathing room.
If you are already on Microsoft 365, this is where Copilot-style features tend to land first, because they sit inside tools your team already uses. That is also why getting your Microsoft 365 environment configured properly matters before you encourage wider adoption.
2) Customer communication
Customer-facing teams use AI to turn rough notes into clearer updates, propose responses to common support queries, and help rewrite messages so they are easier to understand. The strongest results come when AI drafts and humans decide, staff stay in control of tone, judgement, and relationship cues.
3) Marketing and content
Marketing teams often adopt early: content outlines, repurposing talks into posts, and generating headline variations. Guardrails matter here. Without a clear voice and review process, AI-generated content becomes generic fast. With good briefs and human editing, it becomes a fast way to explore more ideas without increasing budget.
4) Internal knowledge and support
Some SMEs are starting to build internal ‘copilots’ on top of policy documents, procedures and handbooks. The goal is simple: reduce time spent hunting through folders, and reduce repeat questions to managers.
This works best when your information is organised and access permissions make sense. If your SharePoint and file permissions are messy, AI can amplify that mess by making it easier to surface the wrong thing quickly.
The new risks: skills, shadow AI and trust
As AI becomes normal, the risks shift too. Most fall into three buckets.
Skills and confidence
If leaders and managers are not confident, AI adoption can swing between two extremes: blocking it entirely, or letting people use whatever they like without guidance. A more useful approach is to treat AI skills as part of normal digital literacy. Short training on real tasks usually beats long theory sessions.
Shadow AI and data sprawl
If you do not provide approved tools, employees will still experiment. That can create ‘shadow AI’, where sensitive information gets pasted into consumer tools without oversight. A practical response is to approve a small set of tools, set clear rules on what must never be shared, and provide safer organisation-managed options where possible.
This is where baseline security and access controls are non-negotiable, especially MFA. If you need a simple internal explainer for staff, Unite’s guide on multi-factor authentication is a useful starting point.
Quality and trust
AI can sound confident and still be wrong. The simplest protection is cultural: treat AI like a helpful junior colleague. It can draft, summarise and suggest, but a human always reviews and signs off, especially for customer-facing work and anything financial, legal, or contractual.
Turning AI from experiments into a practical plan
If AI is going to be useful rather than noisy, it needs a basic plan. For a typical SME, that plan can be lightweight.
1) Map where AI can genuinely help
Ask each team:
which tasks feel repetitive or admin-heavy
where backlogs and delays are happening
where consistency is hard to maintain
This usually reveals a handful of high-value use cases in operations, customer service, and marketing.
2) Choose two or three priority workflows
Rather than trying to ‘do AI everywhere’, pick a small set of workflows and define what good looks like. For example:
email and document drafting for client-facing roles
meeting notes and action capture for managers
internal knowledge search across policies and procedures
3) Set simple guardrails
A one-page policy can go a long way. Cover: approved tools, what data is off-limits, who reviews what, and how staff flag concerns. Keep it practical, so people actually use it.
If you are already working towards more formal assurance, it also helps to align AI use with your wider security basics and governance. For some organisations, working towards Cyber Essentials is a useful way to tighten fundamentals at the same time.
4) Support your team, not just your tools
Tools alone rarely change much. The SMEs that get the most value from AI tend to run short demos on real tasks, encourage staff to share practical wins, and make it normal to say ‘I tried this and it did not work’. That is how you move from curiosity to reliable habits.
A better way to think about AI in 2026
A realistic aim is to make AI boring. Not flashy, not chaotic, not a separate ‘AI project’, just a small, stable part of how work gets done.
When you treat AI like routine workflow improvement, the priorities become clearer: pick the right tools, sort your information, tighten access, and train people to use it responsibly. That is how you get the upside without the clutter.
Want to make AI useful without adding risk or confusion? Start with the foundations: your Microsoft 365 setup, permissions, identity controls, and a clear ‘house view’ on how staff should use AI day-to-day. That is the difference between scattered experiments and steady, repeatable gains.
Unified communications brings your calls, video meetings, messaging and sometimes contact centre tools into one joined-up platform, instead of spreading them across separate apps. For UK SMEs, that usually means fewer missed messages, smoother collaboration and one place to manage how people communicate with colleagues and customers. It is gaining traction now because it makes day-to-day work less chaotic, especially for hybrid teams, and it helps smaller organisations feel more responsive without adding extra layers of admin.
What unified communications actually means
At its simplest, unified communications (UC) means your main communication channels work together in one system rather than as separate tools. That usually includes:
phone calls and voicemail
video meetings
team chat and presence (who is available, busy, away)
file sharing and, in some cases, contact centre features
Instead of your phone system, meeting tool and chat app all being different products, unified communications connects them behind the scenes. You can move from a chat to a call, or from a call to a video meeting, without switching platforms or hunting for dial-in details.
For most SMEs, the biggest benefit is how it feels to use. Staff have one main place to go for conversations, whether they need a quick message, a call, or a client meeting. If you want a simple reference point for what UC can look like in practice, Unite have a plain-English overview here: Unified Communications.
Why SMEs are finally paying attention
Many SMEs have lived for years with a patchwork of tools, a legacy phone system, a separate video app, and email doing far too much heavy lifting. Changing it has often felt risky or unnecessary, especially if the phones still worked.
A few things have shifted that calculation:
Hybrid working has made reliable video, chat and calling non-negotiable.
Cloud phone systems have become easier to deploy and manage.
The UK’s move away from analogue phone lines is pushing businesses to rethink old telephony rather than patch it again. Openreach says the analogue network will be retired by 31 January 2027, and analogue lines have not been sold to new customers since September 2023.
Put together, more SMEs are asking a different question. Instead of ‘How do we replace our old phones?’, they are asking ‘If we are changing anyway, can we tidy up calls, meetings and messaging at the same time?’
How unified communications works in a typical SME
In practice, unified communications does not have to be a huge transformation project. It often looks like a handful of simple changes that staff notice quickly:
using one app on desktop and mobile for calls, meetings and chat
clicking to call from your CRM or helpdesk instead of dialling manually
seeing whether a colleague is available before you ring
starting with a chat, then escalating to a call or video meeting in one click
For many teams, the real gain is less friction. There is less time wasted copying numbers between systems, searching for meeting links, or leaving voicemails that never get picked up.
If your current phone set-up is already due a refresh, it is worth starting with the foundations. Unite’s overview of a modern Cloud Hosted Phone System is a good baseline for what most SMEs actually need.
Unified communications vs separate tools
It can help to look at the difference side by side.
Area
Separate tools approach
Unified communications approach
Phone system
Stand-alone desk phones, separate admin portal
Cloud calling inside your main collaboration platform
Video meetings
Separate app with different login
Launched from the same app you use for chat and calling
Team messaging
Email or separate chat app
Integrated chat with presence and file sharing
Contact details
Scattered across email, CRM and phone system
Centralised, often synced from your directory or CRM
Admin and security
Multiple portals and policies
One main platform with consistent access rules
The technology underneath is not always radically different. The big shift is that everything is connected and managed in one place, which is often a better fit for SMEs with limited IT capacity.
Why unified communications matters for customer experience
From a customer’s point of view, unified communications shows up as responsiveness and consistency. It becomes easier to:
route calls to the right person first time, even if they are remote
share a screen or document instantly when a conversation needs detail
follow up calls with clear written summaries and links
use call queues or shared voicemail so calls do not disappear when someone is off
That does not mean every SME needs a full contact centre platform. For many, basic call handling improvements plus joined-up calendars and presence already makes the business feel more professional.
Common worries SMEs have about unified communications
Even when the benefits are clear, leaders often have sensible concerns.
‘Will this be expensive or tie us into a long contract?’
Most modern UC platforms use per-user licensing. The cost depends on what you are replacing and how many separate tools you are currently paying for. In some cases, consolidating licences and retiring old services can make the overall spend easier to control, even if the “phone system” line item looks more visible than it used to.
‘Will my team find it confusing?’
If staff already use something like Microsoft Teams for meetings and chat, unified communications often feels like an extension rather than a brand new system. The difference is that calling becomes part of the same place people already work. Unite’s guide to Microsoft Teams Calling is a good example of how this typically lands for end users. Similarly, platforms like Cisco Webex bring enterprise-grade UC capabilities into SME-friendly packaging, often with smoother transitions for organisations moving from traditional PBX systems.
‘What if everything goes down at once?’
Consolidation can mean more eggs in one basket, so resilience planning matters. That might include mobile fallback options, call forwarding rules, and backup internet for key sites. If VoIP and Teams are business-critical for you, it is worth thinking about connectivity as part of the UC plan, not as a separate issue. Unite’s North East-focused guide on SD-WAN and backup internet explains the practical options without turning it into an enterprise-only conversation.
Signs your business is ready for unified communications
Not every organisation needs to rush into UC. However, a few patterns are strong signs it is worth serious consideration:
staff juggle between phone, email, chat and video apps to get simple tasks done
remote and office-based staff struggle to reach each other consistently
your phone system is approaching end of life, or the UK analogue switch-off is forcing change anyway
you already rely heavily on a collaboration platform, but calls still sit elsewhere
you spend more time managing tools and licences than improving how people communicate
If several of these feel familiar, unified communications is less a luxury and more a practical tidy-up.
Getting started without disrupting day-to-day work
A move to unified communications does not have to be “big bang”. Many SMEs take an incremental approach that keeps risk low:
Audit what you already have: list your tools for calling, meetings, messaging and file sharing, plus where they integrate with CRM or helpdesk systems.
Choose your primary platform: decide what becomes the main home for calls, meetings and chat.
Run a small pilot: start with one team, migrate their numbers, set up basic call flows, then tighten training based on real feedback.
Tidy up as you go: remove or downgrade old tools so you do not pay twice or confuse staff with overlapping systems.
The biggest success factor is internal communication. Clear expectations, simple how-to guides and a feedback loop make the shift feel manageable.
A smoother way to work, especially for smaller teams
Unified communications will not fix every communication problem on its own, but it removes everyday friction. For many UK SMEs, 2026 is the point where UC stops being a buzzword and becomes a straightforward decision, especially if you are already changing phone lines, improving hybrid working, or trying to tighten customer responsiveness.
If you want a second opinion before you commit, focus on a review that starts with your real call volumes, staffing patterns and current tools, not a generic package. If you are considering a move to unified communications, talk to Unite about simplifying calls, meetings and messaging into one joined-up platform. We can review your current set-up, map the cleanest migration route, and help you roll it out without disrupting the day job. Contact Unite
If you still rely on Windows Server 2016, you now have a clear deadline. Windows Server 2016 end of support is 12 January 2027. After that, Microsoft stops providing regular security updates, which means any new vulnerability stays open on any server you have left on 2016.
For a lot of North East SMEs, those servers are quietly running the things that matter most: line-of-business applications, shared drives, account systems and databases. Leaving them on an unsupported platform is not just a technical risk, it is a business risk. This article explains what Windows Server 2016 end of support actually means, how to check where you stand, and the practical routes to modernise before the 2027 cut-off.
What Windows Server 2016 end of support actually means
Microsoft gives its server products two main phases of support: mainstream support with feature updates, and extended support focused on security fixes. For Windows Server 2016, mainstream support ended in January 2022 and extended support ends on 12 January 2027. After that point, no regular security patches are released for most customers.
When a platform goes out of support:
Newly discovered vulnerabilities may never be patched.
Security and compliance frameworks expect you to be on supported software, or to have a clear plan to move.
Third-party vendors may stop certifying their applications on that version.
You may be able to use paid Extended Security Updates (ESU) as a short-term bridge, but these are designed as temporary cover while you migrate, not a long-term plan.
For many SMEs in and around Newcastle, Gateshead, North Tyneside and County Durham, the practical route is to upgrade or migrate away from Windows Server 2016 over the next 12–18 months, rather than waiting until late 2026.
Why this deadline matters for North East SMEs
If your servers sit in a cupboard or a small comms room, it is easy to ignore them while they just ‘keep working’. The 2027 end of support date forces a different question: if this server failed tomorrow or was compromised, what part of the business would stop?
Typical impacts when legacy servers are left too long include:
Prolonged downtime while ageing hardware and software are coaxed back to life.
Higher recovery costs, because modern backup and disaster recovery was never set up properly on older platforms.
Audit and insurance pressure, where unsupported systems are flagged as a material cyber risk.
The good news is that there is enough time to move away from Windows Server 2016 in a controlled way, rather than rushing a migration in late 2026.
Step 1: Get a clear picture of your current servers
Before deciding what to do next, you need an accurate inventory. For most SMEs, that means answering four simple questions.
1) Which servers are still running Windows Server 2016?
List physical and virtual machines, including anything hosted in a local data centre or colocation facility. Note their roles, such as file server, domain controller, application server or SQL database host.
2) What does each server actually support?
Map servers to business functions, such as:
Finance and accounts
Line-of-business or industry-specific apps
File storage and printing
Identity and authentication (Active Directory)
3) Who depends on these systems?
Identify departments, sites and external partners that rely on those services so you can prioritise high-impact workloads.
4) How critical is each workload?
Group them into:
Tier 1: Cannot be down during working hours
Tier 2: Can tolerate short, planned downtime
Tier 3: Legacy, rarely used or candidates for retirement
If you already work with an IT partner, ask them to produce this view as part of a Windows Server 2016 review. This is typically covered under an ongoing support arrangement like Managed IT Services.
Step 2: Choose your direction, upgrade, move to cloud, or retire
Once you know what is running on Windows Server 2016, you can decide the best path for each workload. In practice, most North East businesses use a mix of three approaches.
Option A: Upgrade to a newer on-premise Windows Server
If you still need a local server at your office or data centre, upgrading to a newer long-term support version of Windows Server keeps a familiar model with a more modern foundation.
This is usually suitable where:
You have on-site hardware that still has life left and is supported.
Regulations or application requirements mean the server must stay on-premise.
Latency-sensitive systems need to sit close to machinery or local infrastructure.
The trade-off is that you remain responsible for hardware, power, cooling and physical security. Treat the upgrade as a chance to tidy up and standardise, not just lift-and-shift an untidy setup onto a newer operating system.
Option B: Migrate workloads to cloud or hosted platforms
For many SMEs, Windows Server 2016 end of support is a natural trigger to move parts of the stack to:
Hosted applications, such as SaaS replacements for on-premise systems
Cloud infrastructure, where servers are virtual rather than physical
Modern file storage backed by Microsoft 365 and SharePoint for collaboration
This route reduces hardware and patching overhead, but it needs careful planning around identity, security, connectivity and backup so you do not simply move risk elsewhere. If you are weighing cloud options locally, Unite’s guide to business cloud solutions in Newcastle and the North East is a helpful starting point.
Option C: Retire unused or low-value workloads
Almost every server estate contains at least one system that nobody really needs any more. When you find those on Windows Server 2016, the simplest option is often to retire them completely.
That might mean archiving data for compliance, exporting reports or consolidating functions into newer systems. Removing unused servers reduces your attack surface and simplifies what you need to support.
Step 3: Build a realistic migration plan to 2027
Once you have grouped workloads into upgrade, migrate or retire, you can put timelines against them. A practical plan usually includes:
Prioritised phases Tackle high-impact systems first, such as finance and core line-of-business apps, especially if they sit on older hardware.
Testing time Allow for test environments where upgrades or migrations can run without disrupting live users.
Communication with staff Let teams know when systems will be offline and what will change, especially if new logins or ways of working are involved.
Fallback and backup Ensure backups are recent, tested and usable before making any major change to a Windows Server 2016 environment. If you need to tighten this up, Unite’s article on IT disaster recovery strategy and business continuity is worth a read.
Rather than one big ‘server replacement project’, treat this as a series of smaller, manageable changes over the next 12–18 months.
Step 4: Reduce risk while you transition off Windows Server 2016
You may not be able to move everything overnight, so it is important to reduce risk on any Windows Server 2016 systems that will be around for a while.
Practical measures include:
Tightening access to management interfaces and remote access
Ensuring endpoint protection is up to date and monitored
Segmenting older servers on the network so they are less exposed
Improving backup and disaster recovery arrangements so that if something goes wrong, you can recover quickly
These are not a substitute for moving away from an unsupported platform, but they can reduce exposure while projects are in flight. If you are also working towards a recognised baseline, Cyber Essentials can help structure the fundamentals, including patch management and secure configuration.
How a local partner can help North East businesses prepare
For many organisations, the hardest part of dealing with Windows Server 2016 end of support is finding the time and internal expertise. A local managed IT and cyber security partner can:
Audit your current server estate and map business impact
Advise on whether on-premise upgrades, cloud options or hybrids make most sense
Plan migrations to minimise downtime for staff and customers
Build backup and disaster recovery plans around your most important systems
Unite supports North East SMEs with practical IT planning and delivery that fits how teams actually work, whether that’s modernising on-premise infrastructure, improving resilience, or moving the right workloads into the cloud. This is typically delivered through ongoing support via Managed IT Services and Microsoft environment management via Microsoft 365 services.
Next steps if you are still on Windows Server 2016
Windows Server 2016 will continue to run after January 2027, but running critical systems on an unsupported platform leaves your organisation exposed in ways that are increasingly hard to justify.
A sensible next move is to:
Confirm exactly where you are still using Windows Server 2016
Prioritise servers by business impact and technical risk
Decide which workloads to upgrade, move to cloud or retire
Put a phased plan in place to complete the work well before the 2027 deadline
If you want structured help rather than trying to untangle this on your own, a managed IT partner can handle the planning and delivery.
Talk to Unite about a Windows Server 2016 end of support review. You’ll get a clear map of your current servers, practical recommendations for upgrade or migration, and help turning that into a timeline that fits your budget and business priorities. Contact Unite
Meta Description: Discover why MFA (Multi-Factor Authentication) is critical for business security in 2025. Learn how The Unite Group helps you implement robust MFA solutions across your organisation.
Protecting sensitive business data is no longer optional it’s essential. One of the most effective tools in your cyber security toolbox is MFA, or Multi-Factor Authentication. MFA adds a critical layer of protection that stops malicious attackers in their tracks, even if passwords are compromised.
At The Unite Group, we help businesses across the UK stay protected by implementing industry-standard security solutions, including MFA, as part of our managed IT services and cyber security packages. Here’s everything you need to know about why MFA matters and how we can help.
What Is MFA?
(Multi-Factor Authentication) is a security method that requires users to verify their identity through two or more factors before gaining access to a system or account. These factors fall into three categories:
Something you know (password or PIN)
Something you have (mobile phone or authentication app)
Something you are (biometric data like a fingerprint or face scan)
Using Multi Factor Authentication ensures that even if one factor (like a password) is compromised, access cannot be gained without the second or third.
Why MFA Matters More Than Ever in 2025
Cyber attacks are growing in complexity and phishing attacks are now more sophisticated than ever. With remote and hybrid working becoming the norm, protecting access to business systems is critical. Multi Factor Authentication significantly reduces the risk of unauthorised access, even when credentials are leaked or stolen.
Still not sure how MFA fits into your business? Here are just a few scenarios:
Email accounts: Protect against phishing by requiring MFA for Microsoft 365 or Google Workspace
Remote access: Secure VPN or RDP sessions with an extra layer of login protection
Cloud software: Add MFA to your CRM, file-sharing, or finance platforms
Admin access: Ensure only verified users can access sensitive server or IT infrastructure data
By integrating MFA across these systems, you create multiple roadblocks for cybercriminals. Protecting your company, your clients and your reputation.
Common MFA Misconceptions (And Why They’re Wrong)
“MFA is inconvenient for staff.” Actually, modern Multi Factor Authentication apps are user-friendly and quick. Most staff only need to verify once a day or when using a new device.
“Only large businesses need Multi Factor Authentication.” Small and medium businesses are often the biggest targets. Hackers assume SMEs have weaker defences. Prove them wrong with MFA.
“It’s expensive.” Many MFA tools are low-cost or free with your existing systems. The Unite Group can help you implement the right solution within budget.
Make Cyber Security a Culture, Not a Checkbox
Adopting Multi Factor Authentication is more than a compliance task, it’s a commitment to a secure business culture. It shows staff, customers and stakeholders that your business is taking proactive steps to stay protected in a digital-first world.
Ready to Strengthen Your Cyber Security?
Whether you’re looking to improve compliance, protect against phishing, or simply reduce risk, MFA is one of the smartest investments you can make in 2025.
At The Unite Group, we’re proud to support businesses across the UK with managed Multi Factor Authentication implementation as part of our IT support, Cyber Essentials certification and cyber security services.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.