Tag: protect your business

  • BYOD Without the Backlash: A Practical Intune Setup for UK Businesses in 2026

    BYOD Without the Backlash: A Practical Intune Setup for UK Businesses in 2026

    Bring your own device is already happening at most UK SMEs. Staff read work email on personal phones, join Teams calls from the car, and check Outlook on the same handset they use for everything else. The question is rarely whether to allow it. It is how to bring those phones under sensible control without staff feeling like the company has taken over their personal property.

    Mobile device management for small business in 2026 is no longer the heavy enrolment model people remember from a decade ago. Microsoft Intune supports an app-protection-only mode that controls company data inside Outlook, Teams and other work apps, without touching personal photos, texts, apps or location. That is the part most staff worry about. However, you can remove that concern from day one.

    Most BYOD rollouts stall on three questions

    Three questions come up the moment IT mentions managing personal phones. Can my employer see my photos. Can they see my texts, can they wipe my phone if I leave. Those questions are reasonable, and the answer to all three depends on which type of management the business chooses to deploy.

    Get that distinction wrong and the rollout stalls before the first device is enrolled. Get it right and most of the resistance disappears.

    Two ways to do mobile device management for small business

    Intune offers two broad approaches.

    ModelWhat it doesWhat staff see
    Full device enrolment (MDM)Manages the entire device, including settings, apps and policies. Can wipe the full device.A managed device with company control over the OS layer.
    App protection policies (MAM)Manages only the work apps and company data inside them. Cannot see personal apps, photos or texts. Cannot wipe personal data.A normal personal phone with a few work apps that follow company rules inside themselves.

    For most UK SMEs, app protection only is enough. It blocks copy-paste from Outlook to a personal WhatsApp, requires a PIN to open the work apps, encrypts company data on the device, and lets the business wipe only the work data if the phone is lost or the employee leaves. The personal half of the phone stays untouched.

    Full enrolment makes sense for company-owned devices, particularly where Cyber Essentials evidence or regulated data is involved. For staff-owned phones, app protection usually delivers what the Cyber Essentials v3.3 update asks for, without the personal-property concern.

    A working BYOD policy fits on two pages

    A workable BYOD policy fits on two pages and answers the questions staff are actually asking. The points that matter:

    • Which devices are allowed (modern iOS and Android with current OS versions).
    • Which work apps are covered (Outlook, Teams, OneDrive, the rest of Microsoft 365).
    • What the business can and cannot see on the device.
    • What happens when someone leaves (company data wiped, personal data untouched).
    • What happens if the device is lost (the same).
    • Who pays for what (data plan, repairs, replacement).

    The policy is written for staff to read, not for lawyers to refer to. If staff cannot summarise it back to you in a sentence, it is too long.

    A four-step Intune rollout

    A practical sequence for an SME on Microsoft 365 Business Premium:

    1. Inventory. List who needs work apps on a phone, on what device, with what OS version.
    2. Policy. Configure app protection policies for Outlook, Teams and OneDrive: PIN required, copy-paste restricted to work apps, encryption enforced, selective wipe on leaver.
    3. Pilot. Enrol three to five willing staff first. Iron out the OS prompts and the PIN experience before the wider rollout.
    4. Communicate. Send the two-page BYOD policy with a five-bullet summary of what changes and what does not. The we cannot see your photos line goes first.

    The technical work is rarely the slow part. The communication is.

    Where this sits next to your other controls

    App protection on phones complements the controls you already have on laptops and Microsoft 365. Conditional access policies, the Microsoft Purview information protection foundation and Zero Trust principles all rely on knowing what device is making a request and what data lives on it. Without mobile management, the phone is the gap. With app protection, the phone joins the rest of the estate.

    However, for Cyber Essentials, assessors want to see that staff protect company data on their phones, not that the business controls the entire device. App protection meets the bar, and aligns with NCSC mobile device guidance.

    What it looks like once it is live

    A staff member loses a phone on the train. The business issues a selective wipe of the work apps from the Intune portal. Within minutes, IT can remove the work mailbox, Teams chats and OneDrive cache while leaving the staff member’s photos, contacts and personal apps untouched. They report the loss to the carrier and pick up a replacement on the weekend.

    That is the model staff can live with. It is also the model that closes the most realistic mobile risk most businesses are carrying.

    Roll it out without the politics

    Mobile device management does not have to be a fight. With app-protection-only policies, a short BYOD policy and a clear staff briefing, most businesses land Intune in a fortnight without losing goodwill.

    If you would like a second pair of eyes on your Microsoft 365 setup before you roll BYOD out, get in touch and we will walk through what your existing licence already covers, where the policy gaps sit, and what a sensible rollout looks like for your team size.

  • Out of Office, Out of Pocket: How UK Businesses Stop BEC and Invoice Fraud This Summer

    Out of Office, Out of Pocket: How UK Businesses Stop BEC and Invoice Fraud This Summer

    Invoice fraud prevention is a seasonal problem for most UK SMEs, and the worst season is summer. Two of the three approvers are out, one new starter is covering the inbox, and the finance lead’s out-of-office reply tells anyone who emails that they are walking the Camino until late August. June through August is when invoice fraud lands. It lands because the people who would normally spot it are not in the building.

    Invoice fraud prevention is less about new tools and more about closing the seasonal gaps in how your business approves changes when senior staff are away. The five controls below take less than a week to put in place and cover the most common scams we see hitting UK businesses through the summer holiday window.

    Why invoice fraud prevention gets harder in summer

    In the UK Cyber Security Breaches Survey 2025/26, phishing was the most disruptive type of incident for most businesses that experienced one. The technique itself is not seasonal. The success rate is.

    When the finance director is on a beach in Crete, an email from “the finance director” asking the bookkeeper to authorise an urgent supplier bank-detail change carries more weight, not less. The bookkeeper cannot easily check. The MD who would normally be CC’d is also away. The supplier has been a real supplier for years. The bank account change is the only thing that has moved, and that is the part nobody notices.

    This is the operational reality criminals are betting on, and they are right often enough to keep doing it.

    Control 1: A deputy matrix that covers approvals

    Most businesses have an out-of-office system for replying to emails. Few have one for approvals. Build a one-page deputy matrix before staff start booking holiday. Three columns: the action that needs approval, the primary approver, the named deputy.

    Cover at minimum:

    • Supplier bank-detail changes
    • New supplier setup
    • Payments above a defined threshold
    • Payroll changes
    • Refunds above a threshold

    The matrix lives in finance, in HR and in your shared drive. Every approver knows who their deputy is, in writing, before the first holiday week. Adapting the 30-second social engineering script we published in May gives the deputy a working escalation pattern when something feels wrong.

    Control 2: Out-of-office replies that do not leak

    The default out-of-office reply tells the world the sender is away, for how long, who is covering, and often where they are. That is enough for a convincing impersonation attempt.

    A safer pattern says only what the recipient needs to know: that the message has been received, when a reply can be expected, and a generic team inbox or covering colleague for urgent matters. No travel details, or external phone numbers and no private mobile.

    The same rule applies to LinkedIn updates and team-wide announcements. Holiday plans do not need to be public.

    Control 3: A callback rule for any bank-detail change

    This is the single highest-impact control on the list. Any change to supplier banking details triggers a callback to a known phone number for that supplier, never to the number in the latest email signature. The known number lives in your purchase ledger, not in the email thread requesting the change.

    If the supplier cannot be reached, the change waits. The cultural piece matters as much as the rule: nobody gets blamed for delaying a payment to verify it. That is the no-shame part. Once it is in the cyber incident response plan and the team knows it applies to everyone including the MD, the rule holds.

    Control 4: Conditional access for travel windows

    If your team uses Microsoft 365 and your licences include conditional access, you can tighten sign-in rules during defined travel windows. Block sign-ins from countries staff are not in, require a fresh MFA prompt from new locations, and flag impossible-travel events for review.

    This sits naturally next to the controls described in our Cyber Essentials v3.3 guide. It is also the control that catches account takeover attempts before they reach finance at all.

    Control 5: A short briefing for the team

    Before the holiday season starts, send a five-bullet email to the people who handle money and inboxes. Cover the deputy matrix, the OOO rule, the callback rule, and the two scams to expect: a bank-detail change for a real supplier, and a same-day urgent payment request from a senior approver who is travelling.

    The briefing does not need to be long. It does need to be in writing, so the team can point to it when they apply the rules.

    What this looks like by mid-July

    A business that has done the five controls above answers a different question in August. Instead of “did we just send GBP18,000 to the wrong account”, the question becomes “should we approve this change today or wait for our finance lead to confirm on Monday”. That is the same conversation, with one difference. The money is still in the account.

    If you would like us to walk through your summer cover and tighten the gaps, book a 30-minute summer-readiness review and we will produce a deputy matrix, a callback rule and conditional access settings tailored to your business before the July rota change.

  • Social Engineering in 2026: A 30-Second Script Your Team Can Use Today

    Social Engineering in 2026: A 30-Second Script Your Team Can Use Today

    The phishing email is no longer the only threat your team needs to worry about. The reality is that social engineering UK business threats are rapidly evolving. Social engineering attacks in 2026 are multi-channel: they start with a Teams message, follow up with a phone call from a spoofed number, and close with an email that references both previous contacts. The grammar is flawless. The caller sounds like someone your team recognises. The request feels urgent but reasonable.

    Vishing (voice phishing) volumes surged over 440% between 2024 and 2025. IT helpdesks are the primary target in 42% of attacks. Finance departments account for over 30% of successful breaches. These are not mass-blast campaigns. They are targeted, researched and designed to exploit the way your team naturally responds to authority and urgency. Technical controls help, but they cannot catch a convincing phone call. What your team needs is a simple, repeatable process they can follow when something feels off. That process is three words: Stop, Verify, Escalate.

    The 30-Second Script

    This script works for reception staff, finance teams, office managers, anyone who handles incoming requests by phone, email or Teams.

    Stop. Pause before acting on any request that involves money, credentials, access changes or sensitive information. Urgency is the attacker’s primary tool. A legitimate request can wait 60 seconds.

    Verify. Contact the person who supposedly made the request using a known, trusted channel. Do not reply to the email, return the call to the number displayed, or respond to the Teams message. Instead, look up the person’s number independently and call them directly. If they confirm the request, proceed. If they do not, you have just prevented an attack.

    Escalate. If you cannot verify the request, or if the caller pressures you not to check, escalate to your line manager or IT team immediately. No legitimate colleague or supplier will object to a verification step. Resistance to verification is itself a red flag.

    Print this script. Pin it next to every phone. Include it in your onboarding pack. The value is in its simplicity: three steps that any member of staff can follow without needing technical knowledge.

    What Multi-Channel Attacks Look Like

    Understanding the pattern helps your team recognise it. Here is how a typical multi-channel social engineering attack unfolds in 2026.

    Stage one: the setup. Your finance officer receives a Teams message from what appears to be the managing director’s account. The message says: “I need you to process a payment urgently. I will call you in five minutes to explain.” The message references a real project or client name, which the attacker found on LinkedIn or the company website.

    Stage two: the call. Five minutes later, a phone call arrives. The caller ID shows the managing director’s mobile number (spoofed). The voice sounds plausible. The caller explains that a supplier payment needs processing today to avoid a penalty. They provide bank details and ask for immediate action.

    Stage three: the follow-up. An email arrives from a slightly misspelled domain confirming the bank details “for your records.” The email includes a PDF invoice that looks legitimate. At every stage, the attack builds credibility by referencing the previous contact. Each touchpoint makes the next one harder to question. The entire sequence takes under 15 minutes.

    The Stop, Verify, Escalate script breaks this chain at stage one. The finance officer pauses, calls the managing director on their known mobile number, and discovers they never sent the Teams message.

    Where to Apply the Script

    The script applies to any request that involves transferring money or changing bank details, resetting passwords or MFA, granting system access or sharing login credentials, sending sensitive files or client data externally, and making urgent changes to payroll or supplier records.

    For payment and bank detail changes specifically, add a standing rule: no bank detail change is processed without a verbal confirmation from a known contact at the requesting organisation. This single control blocks the majority of business email compromise attacks.

    Building a No-Blame Culture

    The script only works if staff feel safe using it. If someone verifies a request and it turns out to be legitimate, they should never be criticised for checking. If someone escalates a suspicious call that turns out to be genuine, they should be thanked.

    Attackers exploit hierarchy. A junior staff member is less likely to question a request that appears to come from a director. Make it explicit: everyone in the business has permission to verify any request, regardless of who it appears to come from. Include this in your security awareness training and reinforce it in team meetings.

    Make It Part of Your Security Programme

    The script is a starting point. For ongoing protection, pair it with regular security awareness training that includes simulated phishing and vishing exercises. Test your team with realistic scenarios so that Stop, Verify, Escalate becomes a reflex rather than something they have to remember under pressure.

    If you want help rolling out the script, training your team, or setting up simulated exercises, contact The Unite Group. We deliver managed cyber security services across the North East, and staff training is a core part of how we protect your business.

  • AI Readiness Check: The Infrastructure Gaps Stopping SMEs from Using AI Properly

    AI Readiness Check: The Infrastructure Gaps Stopping SMEs from Using AI Properly

    Most businesses that try AI tools hit the same problem. The tools themselves are ready. The infrastructure underneath them is not. Microsoft Copilot is powerful, but it is only as useful as the data, permissions and device estate it sits on top of.If your business has not secured its identities, cleaned up overshared permissions, managed its devices, or classified its data, AI will either underperform or actively create risk.

    This is the gap that sits between buying a Copilot licence and actually getting value from it. AI readiness is not about adopting new technology. It is about getting your existing foundations in order so that new technology works properly when you turn it on.

    The Six Infrastructure Gaps That Block AI

    1. Identity and access.

    AI tools like Copilot operate under the identity of the user. If MFA is not enforced across all accounts, a compromised identity gives an attacker the same AI-powered access the user had. If admin accounts lack MFA, the exposure is even greater. Passkeys and phishing-resistant authentication add a further layer that AI-era threats require.

    2. Permissions and sharing.

    Copilot surfaces everything the user has permission to access. In most businesses, permissions have drifted over years of staff changes, project sharing, and “Everyone in the organisation” links that were never revoked. The result is Copilot exposing content that users were never meant to see, from HR files to financial data. Fixing permissions is the single most important AI readiness task.

    3. Data classification.

    Without sensitivity labels, all data is treated equally. Copilot cannot distinguish between a public marketing brief and a confidential client contract unless labels tell it the difference. Deploying even a basic three-label taxonomy (Public, Internal, Confidential) gives AI and DLP tools the classification layer they need to behave appropriately.

    4. Device currency and management.

    AI features in Microsoft 365 require current operating systems and supported hardware. Devices running Windows 10 past end of support miss security updates and may not support the latest Microsoft 365 app features. Unmanaged devices, those not enrolled in Intune or equivalent, create blind spots where AI tools operate without the compliance policies your managed estate enforces.

    5. Licensing alignment.

    Not every user needs a Copilot licence. Not every user needs Business Premium. A business paying for 30 Copilot licences when only 10 people use the features daily is wasting money. Equally, users on Business Basic licences miss security features (Intune, Entra ID P1, Defender) that AI deployment assumes are in place. A licence audit that matches the right plan to the right role is a prerequisite, not an afterthought.

    6. Backup and recovery.

    AI accelerates productivity, which means your business creates, shares and modifies more data faster than before. If your backup and recovery strategydoes not cover the full Microsoft 365 estate (Exchange, OneDrive, SharePoint, Teams), you are accumulating more unprotected data at a faster rate. AI amplifies the consequences of not having proper backups.

    The Readiness Checklist

    Before deploying AI tools, confirm each of these:

    Your business enforces MFA on every account with no exceptions. Your team has audited SharePoint and OneDrive permissions and removed oversharing. Sensitivity labels are deployed and a default label is applied to all new content. All devices are managed, patched and running a supported operating system. Licences are matched to user roles and needs. Your Microsoft 365 backup covers all workloads, and your team has tested it within the last quarter.

    If any of these are incomplete, fix them first. Deploying AI on top of weak foundations does not just limit the value. It amplifies the risk. Copilot can surface restricted files, operate on unsecured devices, and generate content from data your business has not backed up.

    Legacy Infrastructure Is the Real Blocker

    Businesses often treat AI readiness as a conversation about buying new tools. In practice, the blocker is almost always the infrastructure that already exists. Many businesses rely on servers approaching end of life, unmanaged device fleets, organic permission structures that nobody has reviewed in years, and licensing models originally built for smaller teams.

    These are not AI problems. They are IT management problems that AI makes visible and urgent. A business that fixes them gets value from AI immediately. A business that ignores them will spend money on Copilot licences and wonder why the return never materialises.

    Get an AI Readiness Assessment

    If you want to deploy AI tools confidently, start with the foundations. Contact The Unite Group for an AI readiness assessment. We will audit your identity controls, permissions, device estate, data classification, licensing and backup coverage, then give you a clear, prioritised plan to close the gaps before you switch anything on. All of this is part of our managed IT and cyber security service.

  • Cyber Essentials v3.3: What Changed and How to Pass First Time

    Cyber Essentials v3.3: What Changed and How to Pass First Time

    Cyber Essentials v3.3 took effect on 27 April 2026. All new assessment accounts created after that date use the updated requirements and the new Danzell question set. If your certification is due for renewal or you are certifying for the first time, v3.3 now applies to your assessment.

    The core scheme has not changed. It still tests the same five control themes: firewalls, secure configuration, user access control, malware protection, and security update management. The updated version marks certain areas more strictly, changes how cloud services are scoped, and introduces clearer automatic failure triggers. The businesses that understand these changes pass first time. The ones that assume last year’s answers still work are the ones that fail. It is crucial to keep up to date with Cyber Essentials v3.3 compliance requirements.

    The Three Changes That Matter Most

    1. MFA is now a hard fail. Cyber Essentials has included multi-factor authentication for several years, but v3.3 now marks it more strictly. If a cloud service supports MFA and you have not enabled it for all users, you automatically fail. No discussion, no mitigation, no partial credit. Adhering to Cyber Essentials version 3.3 is mandatory in this respect.

    This applies regardless of whether MFA is free, bundled with the service, or only available as a paid add-on. If the option exists and you have not switched it on, the assessment stops there. Cyber Essentials v3.3 no longer accepts IP allowlisting as a form of multi-factor authentication.

    The practical impact is significant. Most businesses have MFA enforced on their main platforms, Microsoft 365, for example, but have not enabled it on every cloud service they use. Project management tools, accounting software, CRM platforms, HR systems, social media accounts used for business, and even free-tier SaaS tools all count. Being thorough is now an integral part of the Cyber Essentials v3.3 requirements.

    2. Cloud services cannot be excluded from scope. For the first time, v3.3 includes a formal definition of a cloud service: an on-demand, scalable service hosted on shared infrastructure, accessible via the internet, accessed via an account, and used to store or process organisational data. This update is outlined clearly in the Cyber Essentials v3.3 documentation.

    If your business uses it and company data flows through it, it is in scope. Microsoft 365, Google Workspace, your CRM, your accounting platform, your file sharing tools, your HR system. Previous versions allowed some ambiguity that let businesses argue certain services were out of scope. That argument no longer holds. The new Cyber Essentials v3.3 designation closes these gaps.

    What This Means in Practice

    The practical step is to build a cloud service inventory before your assessment. List every service accessed with a business email or company account. For each one, confirm that MFA is enabled, that access controls are appropriate, and that the service is included in your scope statement as required by Cyber Essentials v3.3, ensuring no service is missed.

    3. The 14-day patching rule is now an auto-fail. High-risk and critical security updates, those with a CVSS v3 base score of 7 or above, must be applied within 14 days of release. Two new auto-fail questions, A6.4 and A6.5, mean that failure to meet this requirement results in an automatic assessment failure. These specifics stem from the new Cyber Essentials v3.3 guidance.

    This applies across all devices and software in scope: operating systems, firmware, browsers, plugins and applications. If your patching process is informal or relies on users accepting update prompts, you need a structured approach before your assessment. A managed IT provider with centralised patch management can enforce this consistently. Maintaining Cyber Essentials v3.3 patching standards gives your organisation the best chance at passing.

    What Catches Businesses Out

    Beyond the three headline changes, several areas consistently trip up businesses. Many common issues stem from misinterpreting Cyber Essentials v3.3 scope and requirements.

    Scope that excludes end-user devices. A scope that does not include laptops, desktops, tablets or phones used to access organisational data is not acceptable under v3.3. If your staff use devices to access business email, files or cloud services, those devices are in scope. This includes BYOD arrangements where personal devices access company systems—a non-compliance with Cyber Essentials v3.3.

    Social media accounts. Cyber Essentials v3.3 treats business social media accounts, including LinkedIn, Facebook and X, as cloud services. If your marketing team logs into these accounts with a business email, you must enable MFA to protect your assessment. The rules were clarified in Cyber Essentials v3.3, so businesses must review every account accordingly.

    Unsupported operating systems. Devices running operating systems past end of support, including Windows 10 without ESU, fail the secure configuration and patching requirements. If your estate includes machines that you cannot patch, you need to upgrade them, replace them, or formally exclude them from scope with documented network segregation. Cyber Essentials v3.3 helps you handle these systems properly.

    Admin account hygiene. Assessors check whether you enforce MFA on administrator accounts, limit admin privileges to the people who need them, and use separate admin and standard accounts. Shared admin accounts without MFA are a common failure point. These rules are specifically included in the Cyber Essentials v3.3 assessment process.

    Incomplete evidence. Even when the right controls are in place, businesses can struggle to prove it during assessment. Screenshots, policy records, patch reports, MFA settings and scope details all need to be clear, current and consistent. If the evidence does not match the answers given in the assessment, it can delay certification or lead to follow-up questions.

    How to Prepare for a v3.3 Assessment

    Start with three exercises. First, build your cloud service inventory and confirm MFA status on every service. Second, run a patching audit to confirm you can evidence 14-day compliance for critical updates. Third, review your scope statement to ensure it covers all devices and cloud services that handle organisational data. These actions are vital for Cyber Essentials v3.3 readiness.

    If you hold Cyber Essentials certification through Unite, we review your environment against v3.3 requirements before your assessment begins. If you are certifying for the first time, we run a readiness check that identifies gaps and helps you close them before your assessment account is created. This process is central to a successful Cyber Essentials version 3.3 certification journey.

    As an IASME certification body, The Unite Group assesses businesses against the Cyber Essentials scheme directly. We understand how assessors interpret the requirements because we are the assessors. If your renewal is coming up or you want to certify for the first time under v3.3, contact us for a readiness review. Make sure you are fully prepared for Cyber Essentials v3.3 assessment changes.

  • Windows 10 in 2026: ESU vs Upgrade vs Replace for UK SMEs

    Windows 10 in 2026: ESU vs Upgrade vs Replace for UK SMEs

    Windows 10 reached its end of support on 14 October 2025, but many organisations are already planning for Windows 10 end of support 2026 as they consider their next steps. Microsoft no longer provides free security updates for any Windows 10 device. If your business still has machines running Windows 10, you have three options: pay for Extended Security Updates (ESU) as a temporary measure, upgrade eligible machines to Windows 11, or replace hardware that cannot make the jump. Doing nothing means running unpatched systems that become more vulnerable with every month that passes.

    What Extended Security Updates Actually Give You

    ESU is a paid subscription that continues delivering critical and important security patches for Windows 10 devices after end of support. It does not include new features, design changes, or general technical support. It is a security-only stopgap.

    Year 1 (October 2025 to October 2026) costs approximately £60 per device. Year 2 doubles to around £120 per device. In year 3 doubles again to around £240. You cannot skip years, so if you start in Year 2, you must pay for Year 1 as well. The total three-year cost per device reaches roughly £420.

    Devices must be running Windows 10 version 22H2 to qualify. Earlier versions need updating before ESU can be activated.

    ESU makes sense for businesses with a small number of devices that cannot yet be upgraded, typically because of legacy software dependencies or a hardware refresh cycle that extends into 2027. It buys time. It does not solve the underlying problem.

    When Upgrading to Windows 11 Is the Right Move

    If a device meets Windows 11’s hardware requirements, upgrading is free for licensed Windows 10 users and is the most cost-effective long-term option.

    The key hardware requirements are a TPM 2.0 chip, Secure Boot capability, and a supported processor. Most business laptops and desktops purchased from 2019 onwards meet these requirements. Machines older than that typically do not.

    To check your estate, run the Microsoft PC Health Check tool on each device or use a centralised tool like Intune to assess compatibility across all machines at once. This gives you a clear picture of how many devices can upgrade in place and how many cannot.

    Upgrading in place preserves applications, files and settings. For most users, the transition is straightforward, but testing any specialist or line-of-business software against Windows 11 before rolling out across the team is worth the time.

    When Replacement Is the Only Practical Option

    If a device fails the Windows 11 compatibility check, particularly on the processor or TPM requirement, it cannot be upgraded. ESU extends its life temporarily, but you are paying £60+ per year per device for a machine that is already at the end of its useful life.

    For devices over five years old, replacement is usually more cost-effective than ESU once you factor in declining performance, battery degradation, increased failure rates and the cumulative ESU cost. A new business laptop running Windows 11 Pro costs roughly £400 to £700 depending on specification.

    Replacement does not have to happen all at once. A phased approach, replacing the oldest or most critical machines first and scheduling the rest across two or three quarters, spreads the cost and reduces disruption.

    A Simple Decision Framework

    For each Windows 10 device in your business, ask three questions.

    Can it run Windows 11? Check hardware compatibility. If yes, schedule the upgrade. If no, move to the next question.

    Does it run software that requires Windows 10? If yes, ESU buys time while you work with the software vendor on Windows 11 compatibility. If no, move to the next question.

    Is the device less than four years old and performing well? If yes, ESU for one year while you plan a phased replacement may make sense. If no, replace it.

    What Happens If You Do Nothing

    After October 2026, ESU Year 1 expires and consumer devices stop receiving any patches at all. Businesses on the enterprise ESU programme can extend to October 2028, but at escalating cost.

    Running unpatched Windows 10 devices creates real risk. New vulnerabilities discovered after your ESU coverage ends will not be fixed. Attackers specifically target end-of-life operating systems because they know patches are not coming. Cyber insurers ask about operating system currency during underwriting, and unpatched devices may affect your coverage.

    The Windows Server 2016 end of support deadline in January 2027 creates a similar pressure point for server infrastructure. If your business has both ageing desktops and ageing servers, planning both transitions together is more efficient.

    Get a Device Estate Audit

    If you are not sure which devices can upgrade, which need replacing, and how to plan the rollout without disrupting your team, contact The Unite Group for a device estate audit. We will assess every machine, recommend the right path for each, handle procurement for any replacements, and deliver them configured and ready to use as part of your managed IT services.

  • Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For

    Cyber Insurance Renewal 2026: The Evidence Your Insurer Will Ask For

    If your cyber insurance renewal is approaching, the application will look different from last time. Insurers have moved beyond generic questionnaires.They now ask detailed questions about your security controls. They also expect clear proof that these controls are active, enforced, and tested. A verbal confirmation that you “have MFA” is no longer enough.

    For SMEs, this shift can feel overwhelming. The questions reference tools and processes that your team may not manage directly, and assembling the evidence often falls between your IT provider and your internal admin with no clear owner. The result is a last-minute scramble, higher premiums, or in some cases, declined coverage.

    This blog explains what UK cyber insurers ask for in 2026. It also outlines the evidence needed for each requirement and how to build a proof pack before your renewal.

    What Insurers Are Asking For in 2026

    Underwriting has become technical. Carrier applications and renewal questionnaires now routinely cover six areas, and they want evidence for each.

    Multi-factor authentication. Insurers want to see MFA enforced on email, remote access, VPN and all administrative accounts. Partial coverage (MFA on email but not on remote desktop, for example) is specifically flagged. Microsoft reports that MFA blocks over 99% of account compromise attacks, which is why it tops every insurer’s checklist.

    Endpoint detection and response. Traditional antivirus no longer satisfies underwriters. They expect EDR or managed detection and response running on all endpoints, with evidence of 24/7 monitoring and active response capability. If you use Huntress Managed EDR, your provider dashboard shows deployment coverage, alert history and response timelines, all of which map directly to what insurers ask for.

    Backup and recovery. Insurers ask if you have backups in place, whether you keep them isolated or immutable so ransomware cannot encrypt them, and if you test restores regularly. If you have never tested a backup, insurers will not consider it reliable.

    Incident response plan. A written incident response plan with named contacts, defined escalation steps and evidence that it has been tested (even a simple tabletop exercise) is now a standard underwriting requirement. Insurers often ask for the date of the last test and any remediation actions that followed.

    Security awareness training. Insurers want evidence that staff receive regular training and that phishing simulations are part of the programme. A single annual session no longer satisfies most carriers. Managed security awareness training with monthly modules and automated reporting gives you exactly the documentation they expect.

    Patching and vulnerability management. Carriers ask about your patching cadence for critical vulnerabilities. Insurers expect you to apply critical patches within 14 to 30 days. They also expect you to remove end-of-life software or carry out a formal risk assessment.

    How to Build the Evidence Pack

    Start assembling documentation 60 to 90 days before your renewal date. Rushing this in the final week leads to gaps, and gaps lead to follow-up questions, higher premiums or declined coverage.

    For each of the six areas above, prepare a simple evidence file. This should include screenshots of MFA policies and EDR deployment reports. It should also cover backup test logs with dates and a copy of your incident response plan. Include training reports, phishing simulation results, and patch management reports showing update frequency.

    If your IT provider manages these controls for you, ask them to compile this pack as part of their service. A good managed IT provider should be able to produce most of this from their existing dashboards and reporting tools.

    Does Cyber Essentials Help with Insurance?

    Yes. Holding Cyber Essentials certification demonstrates that your business meets a government-backed baseline of security controls. Many UK insurers recognise it as a positive signal during underwriting, and some specifically ask whether you hold it.

    Cyber Essentials does not replace the evidence pack, but it covers key areas such as access control, patching, malware protection, and secure configuration. It also gives insurers confidence that these basics are formally verified rather than self-declared.

    The Cost of Getting This Wrong

    Businesses that cannot provide adequate evidence at renewal face three outcomes: significantly higher premiums, reduced coverage with broader exclusions, or outright refusal. In a market where the Cyber Security and Resilience Bill is increasing regulatory expectations across supply chains, having your insurance declined creates a compounding problem.

    The controls insurers ask about are the same controls that protect your business from the incidents insurance is designed to cover. Investing in them reduces your premium and reduces your risk at the same time.

    Get Your Evidence Pack Ready Before Renewal

    If your renewal is coming up and you are not sure whether your current setup meets insurer expectations, contact The Unite Group for an insurance readiness audit. We deliver every control insurers ask about, from managed EDR and security awareness training to backup management and incident response support, and we can assemble your evidence pack as part of our managed IT service.

  • 2G Switch-Off: Why UK Businesses Should Start a Device Audit Now

    2G Switch-Off: Why UK Businesses Should Start a Device Audit Now

    UK mobile network operators will switch off their 2G networks between 2029 and 2033. The 3G switch-off is already nearly complete, with most operators finishing by early 2026. DSIT published formal guidance on 24 March 2026 confirming the timeline and urging businesses to identify affected devices well ahead of the shutdown.

    The deadline feels distant, but the audit should not wait. Many SMEs have devices, SIMs and connected equipment running on 2G that they are not aware of. The businesses that identify these now have time to plan upgrades on their own terms.

    The ones that leave it until the final year face the same last-minute scramble the PSTN switch-off is already creating.

    Why 2G Matters More Than You Think

    Most smartphones sold in the last five years support 4G and 5G. For handsets, the switch- off will be invisible to most users. The problem sits with older devices and connected equipment that was never designed to move beyond 2G.

    Business mobiles issued three or four years ago to warehouse staff, drivers or site workers may still be basic feature phones running on 2G. Company-issued handsets are often replaced less frequently than personal phones, particularly for roles where a smartphone is not needed.

    Beyond handsets, many businesses have equipment that connects over 2G without anyone thinking about it. Vehicle trackers in fleet vans, IoT sensors for temperature monitoring, alarm communicators that fall back to 2G when broadband fails, agricultural monitoring devices, personal safety alarms, and older EPOS terminals with SIM-based connectivity all potentially rely on 2G.

    What to Audit in Your Business

    Walk through your operations and identify every device that uses a mobile connection. The categories most SMEs miss are listed here.

    Staff handsets. Check whether any company-issued phones are 2G-only. Look for “2G” or “E” on the signal indicator. If the phone never shows “4G” or “5G”, it will stop working when 2G is switched off.

    Vehicle and fleet trackers. GPS tracking devices in vans, trucks or company vehicles often use 2G to transmit location data. Check with your tracking provider whether the hardware supports 4G.

    Alarm systems. Some intruder and fire alarm communicators use 2G SIMs as a backup path when the primary broadband connection fails. This is separate from the ISDN/PSTN switch-off issue, which affects landline-connected alarms. Check with your alarm monitoring provider.

    IoT and environmental sensors. Temperature monitors in cold storage, water leak sensors, air quality monitors and similar connected devices may use 2G or 3G SIMs. These are often installed once and forgotten until they stop reporting.

    Personal safety devices. Lone worker alarms and personal safety pendants used by staff working remotely or in high-risk environments may depend on 2G to contact monitoring centres.

    Payment terminals. Older mobile card machines with SIM-based connectivity may still fall back to 2G in areas with weak 4G coverage.

    The Timeline and What It Means

    The government’s confirmed timeline is 2029 to 2033 for 2G switch-off across all operators. Each network will set its own schedule within that window. VMO2 withdrew 2G roaming services in October 2025 and completed its 3G switch-off by early 2026. Other operators are expected to publish their 2G timelines during 2026 and 2027.

    For businesses, the practical implication is straightforward. Devices purchased or installed today should support 4G at minimum. Any procurement decisions made from now on should exclude 2G-only equipment. And existing 2G devices should be catalogued so they can be replaced in phases rather than all at once under deadline pressure.

    Start the Audit Before It Becomes Urgent

    The ISDN switch-off has shown what happens when businesses delay infrastructure migration. Engineers become scarce, equipment availability tightens, and costs increase. The 2G timeline is longer, but the principle is the same: businesses that act early have more options and lower costs.

    If you need help auditing your mobile estate, identifying 2G-dependent devices, or planning replacements, contact The Unite Group. We manage business communications and connectivity across the North East, and we can assess your device fleet alongside your broader telecoms infrastructure.

  • How to Create a Cyber Incident Response Plan for Your SME

    How to Create a Cyber Incident Response Plan for Your SME

    Most small businesses know a cyber attack could happen to them. Far fewer have a written plan for what to do when it does.

    The result is predictable. When something goes wrong, whether it is a ransomware notification, a compromised email account, or unusual activity on the network, there is confusion. Who makes the call? Do you know who contacts the IT provider? Who tells customers? Decisions get made under pressure, and the wrong ones make the damage worse.

    A cyber incident response plan does not require a dedicated security team or a 50-page document. It needs to answer a handful of critical questions in advance so your business can respond quickly, limit damage and recover faster. Here is how to build one.

    What Counts as a Cyber Incident

    Before building a plan, define what triggers it. A cyber incident is any event that threatens the confidentiality, integrity or availability of your systems or data.

    Obvious examples include ransomware encryption, unauthorised access to email accounts, data breaches and phishing attacks that result in credential theft. Less obvious ones include a staff member losing an unencrypted laptop, finding unexpected admin accounts on your network, or discovering that someone has been forwarding company emails to a personal address.

    Your plan does not need to cover every scenario in detail. It needs to make clear that when something looks wrong, there is a defined process to follow rather than a scramble.

    The Five Steps Your Plan Should Cover

    A practical incident response plan follows five stages: prepare, identify, contain, recover and learn.

    1. Prepare. Assign roles before anything happens. Do you have a primary contact for your IT provider? Is it clear who has authority to shut down systems if needed? Who handles communication with customers or regulators? Write these names, phone numbers and responsibilities down. If one person is unavailable, name a backup.

    2. Identify. Define how incidents get reported internally. A simple rule works: if someone sees anything suspicious, they report it to a named person immediately, no judgement. That person contacts your IT provider or internal IT lead to assess whether it is a genuine incident. Speed matters here. The average attacker dwell time inside a compromised environment is 90 to 120 days.

    3. Contain. Once an incident is confirmed, the priority is stopping it from spreading. This might mean isolating an affected machine from the network, disabling a compromised account, or temporarily shutting down a system. Your IT provider should be leading this, but your plan should make clear who authorises these decisions internally.

    4. Recover. Restore affected systems from clean backups. Reset credentials. Verify that the threat has been fully removed before bringing systems back online. Document what happened and when.

    5. Learn. After recovery, review what went wrong, what went well and what needs to change. Update the plan based on what you learned. This step is the one most businesses skip, and it is the one that prevents the same thing happening again.

    Reporting Requirements Are Tightening

    Under the Cyber Security and Resilience Bill progressing through Parliament, organisations in scope will need to report cyber incidents within 24 hours, with a full report within 72 hours. Even if your business is not directly in scope, larger clients may require evidence that you have a documented incident response process as part of supply chain assurance.

    Having a plan already in place puts you ahead of the curve.

    Keep It Short, Test It Regularly

    The best incident response plans are short enough that people actually read them. One to two pages covering roles, contact details, the five steps and any specific instructions for your IT setup.

    Print a copy and keep it somewhere accessible. If your systems are encrypted by ransomware, a plan saved only on the network is useless.

    Test the plan at least once a year. Run a tabletop exercise: describe a scenario and talk through who does what. You will quickly find gaps, whether that is an out-of-date phone number, an unclear decision point or a step that nobody actually knows how to execute.

    You Do Not Have to Build This Alone

    If you want help creating an incident response plan that fits your business, or you want to make sure your current setup can detect and contain threats quickly, speak to The Unite Group about a managed security review. We work with SMEs across the North East to build practical, proportionate security processes backed by 24/7 monitoring and rapid response tools.

  • What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    What Happens When a Cyber Threat Hits Your Business? Inside Huntress Managed EDR 

    Most businesses understand that antivirus is no longer enough. Fewer understand what happens next. Managed endpoint detection and response (EDR) monitors every laptop, desktop and server in your business for suspicious activity, then detects, investigates and responds to threats before they cause damage. The difference between EDR and antivirus is not just what it catches. It is what happens after it catches it. 

    At The Unite Group, we deliver managed EDR through our partnership with Huntress. This article shows you what that looks like in practice, what the technology does, who is watching, and what happens when it finds something.

    The Team Behind the Screen 

    Former intelligence agency experts founded Huntress, and multiple specialist teams now run its Security Operations Centre. These include security analysts who investigate alerts, threat hunters who proactively search for hidden compromises, detection engineers who build and refine the rules that catch threats, threat intelligence researchers who track emerging attack techniques, and a dedicated threat response team that handles serious incidents. 

    This is not an automated system that sends you an email and hopes you know what to do. It is a team of people watching your environment around the clock, backed by tooling that monitors millions of endpoints globally. The threat intelligence from that scale feeds directly into the detection rules applied to your business, meaning you benefit from patterns spotted across thousands of other organisations. 

    What Huntress EDR Actually Detects 

    Traditional antivirus uses signature-based detection: it recognises known malware and blocks it. That is still important, but it cannot keep up with the volume of new threats created daily. EDR takes a different approach, monitoring behaviour rather than matching signatures. 

    Huntress looks for specific threat patterns across your endpoints. These include malicious process behaviour, where a legitimate application starts doing something it should not. Persistent footholds, where an attacker installs a secondary remote management tool to maintain access even after the obvious threat is removed. Ransomware canaries, which act as early warning tripwires that detect encryption activity before it spreads across your network. And open port detection, which identifies ports left open either accidentally or intentionally that could expose your systems. 

    The typical threat actor remains undetected inside a business environment for 90 to 120 days, quietly gathering information and preparing for a larger attack. EDR reduces that dwell time dramatically by identifying abnormal activity early and triggering a response in minutes rather than months. 

    Eight Minutes from Detection to Action 

    Speed matters because the gap between detection and response is where damage happens. Huntress operates with an average mean time to respond of eight minutes. That covers the entire cycle: detection, investigation, remediation and reporting. 

    When something suspicious is identified, the SOC team investigates immediately. If it is a genuine threat, they act. That typically means isolating the affected machine from the network so the threat cannot spread, killing malicious processes, removing persistent footholds, and providing clear guidance on cleanup and recovery. If backup systems are in place, they coordinate with those too, minimising downtime and data loss. 

    The system is 99.3% accurate in identifying real threats. That matters because false positives waste time and erode trust. If every alert turns out to be nothing, people stop paying attention. Huntress’s accuracy rate means that when an alert comes through, it is almost always something that genuinely needs addressing. 

    What You See as a Business Owner 

    You do not need to become a security expert to benefit from managed EDR. When a threat is detected and handled, you receive a clear report explaining what happened, what action was taken, and whether anything further is needed from your side. 

    Monthly reporting shows you what was detected, how your environment is performing, and whether any patterns need attention. This is useful not just for your own awareness but for demonstrating to clients, insurers and auditors that your business has active, continuous security monitoring in place. Cyber insurers increasingly expect evidence of EDR coverage, and having a managed service with documented response data strengthens your position at renewal. 

    How Managed EDR Fits with Everything Else 

    EDR is not a replacement for the rest of your security stack. It works alongside antivirus, multi-factor authentication, email filtering, and security awareness training. Think of it as the safety net: when something gets past the first layers of defence, EDR catches it and responds before it becomes a breach. 

    It also pairs directly with incident response planning. If you have a documented response plan, EDR provides the detection and containment steps that feed into it. If you do not have a plan yet, managed EDR gives you a level of protection while you build one. 

    For businesses that already hold Cyber Essentials certification, EDR is the logical next step. Cyber Essentials covers the baseline controls. EDR provides ongoing, active monitoring that Cyber Essentials does not require but that modern threats increasingly demand. 

    Is Managed EDR Right for Your Business? 

    If your team uses laptops, connects remotely, handles sensitive data, or operates in a sector where cyber insurance or compliance matters, managed EDR is worth considering. Huntress is not just for large businesses. It was built specifically for small and mid-sized organisations that do not have in-house security teams but still need enterprise-grade protection.

    The agent is lightweight and runs in the background without affecting device performance. Most users will not notice it once you install it. You can roll it out easily across your devices as part of your managed IT services.

    If you want to understand how managed EDR would work for your business, or you want to see what Huntress detects across your current environment, contact The Unite Group for a security assessment. We will review your setup, explain what managed EDR covers, and give you a clear recommendation.