Tag: the unite group

  • Microsoft Agent 365: A Governance Starter Pack for Copilot Agents

    Microsoft Agent 365: A Governance Starter Pack for Copilot Agents

    Copilot Agents governance relies on four key controls. First, decide who can create agents. Next, define what data agents can use. Then, control who can share them. Finally, limit what they can do externally. Get those four right and Microsoft Agent 365 becomes a useful productivity layer for your business. Skip them and you create a quiet new oversharing surface that sits on top of all the data your tenant has accumulated since 2018.

    Agent 365 reached general availability on 1 May 2026, and Microsoft’s Copilot data loss prevention for web search is rolling out worldwide through June 2026. That makes June the right month to set the rules, before staff start building agents at scale and the first ungoverned one shows up in a client meeting.

    What changed with Microsoft Agent 365

    Microsoft Agent 365 brings agents into the same identity, security and management plane as users. Agents can hold their own identity and use specific data sources. In addition, they can perform actions across Microsoft 365 and selected third-party systems. However, organisations should govern them with the same controls they use for human accounts.

    For an SME already using Microsoft 365 Copilot, this is the point where AI moves from a chat feature to something staff can build with. Copilot Studio lets users assemble agents that summarise weekly inboxes, route customer queries, draft proposals from templates, or trawl SharePoint for an answer. The hard part is no longer building. It is governing.

    The four Copilot Agents governance controls every business should set this month

    A workable Copilot Agents governance starter pack is four decisions made in writing and enforced in the tenant. Configure them in the Microsoft 365 admin centre, Copilot Studio settings and Microsoft Purview.

    ControlWhat it doesWhere it lives
    1. Who can create agentsRestricts agent authoring to named users or a security groupCopilot Studio settings
    2. What data agents can ground inLimits which SharePoint sites, OneDrive locations or external sources an agent can useSensitivity labels and agent configuration
    3. Who agents can be shared withControls internal-only, by-team, or cross-tenant sharingMicrosoft 365 admin and Copilot Studio
    4. What agents can do externallyDLP rules that prevent sensitive data leaving the tenant via web search or third-party connectorsMicrosoft Purview DLP for Copilot

    That is the starter pack. It is not the end of governance, but it is the floor.

    Control 1: Who can create agents

    The default is rarely the answer. If everyone with a Microsoft 365 licence can build agents, agents will appear faster than your IT team can track them. The sensible starting position is to restrict authoring to a named group, typically IT plus a handful of trained power users, and review quarterly.

    When a team wants their own agent, the group helps them build it. That keeps the oversight loop in place without turning IT into a bottleneck.

    Control 2: What data agents can ground in

    This control sits on top of the work you have already done with Microsoft Purview. If your sensitivity labels are healthy, your agents inherit the protection automatically. If they are not, agents will happily pull from any SharePoint site they can reach.

    Next, walk through the same logic from our Microsoft Purview starter pack. Then, make sure you apply labels before turning agents loose. Without that base layer, the next control gets harder.

    Control 3: Who agents can be shared with

    Agents can be shared inside a team, across the tenant, or with external organisations. Each step outward changes the risk profile. Tenant administrators in Agent 365 can now govern who is allowed to share agents created in Copilot. Set the default to internal-only, require approval for external sharing, and audit external-shared agents monthly.

    Take particular care with agents that touch customer or finance data. Those should not be shareable outside the team that owns them without a named approver.

    Control 4: What agents can do externally

    The June 2026 rollout of Copilot DLP for web search is the new control here. It prevents sensitive data from being included in prompts that hit web search, while still letting the agent ground its response in internal data sources. Microsoft documents this in their Copilot blueprint for oversharing.

    Set DLP rules for the data classes you already protect in email and Teams: customer records, financial data, payroll, anything regulated. The same rules now apply to agent web actions.

    How this connects to what you already have

    If your business has worked through the AI readiness check and rolled out Copilot, Agent 365 is the next layer. The Purview labels, conditional access policies and AI acceptable-use guidance you put in place earlier this year still apply. Agent 365 extends them; it does not replace them.

    For businesses that have not started yet, the order matters. Labels and DLP first. Copilot second. Agents third. Skipping ahead means governing agents on top of an unlabelled tenant, which is the situation Microsoft’s own guidance describes as the oversharing problem.

    A short readiness check

    Three questions to ask before you let agents into the business at scale:

    • Have we restricted who can author agents in our tenant?
    • Are our SharePoint sites labelled with sensitivity that agents will respect?
    • Do we have DLP rules that apply to Copilot web search as well as email and Teams?

    If two of the three answers are no, get the controls in place this month.

    Set the rules before staff build the agents

    Microsoft Agent 365 is moving fast. The right time to govern it is before staff start shipping agents into business processes, not after. The four controls above take a working day to set up and a quarterly review to maintain.

    If you would like us to audit which agents already exist in your tenant, configure the four-control starter pack and check your Purview foundation, book a Copilot Agents governance review and we will produce a one-page agent inventory and a setup plan tailored to your Microsoft 365 estate.

  • BYOD Without the Backlash: A Practical Intune Setup for UK Businesses in 2026

    BYOD Without the Backlash: A Practical Intune Setup for UK Businesses in 2026

    Bring your own device is already happening at most UK SMEs. Staff read work email on personal phones, join Teams calls from the car, and check Outlook on the same handset they use for everything else. The question is rarely whether to allow it. It is how to bring those phones under sensible control without staff feeling like the company has taken over their personal property.

    Mobile device management for small business in 2026 is no longer the heavy enrolment model people remember from a decade ago. Microsoft Intune supports an app-protection-only mode that controls company data inside Outlook, Teams and other work apps, without touching personal photos, texts, apps or location. That is the part most staff worry about. However, you can remove that concern from day one.

    Most BYOD rollouts stall on three questions

    Three questions come up the moment IT mentions managing personal phones. Can my employer see my photos. Can they see my texts, can they wipe my phone if I leave. Those questions are reasonable, and the answer to all three depends on which type of management the business chooses to deploy.

    Get that distinction wrong and the rollout stalls before the first device is enrolled. Get it right and most of the resistance disappears.

    Two ways to do mobile device management for small business

    Intune offers two broad approaches.

    ModelWhat it doesWhat staff see
    Full device enrolment (MDM)Manages the entire device, including settings, apps and policies. Can wipe the full device.A managed device with company control over the OS layer.
    App protection policies (MAM)Manages only the work apps and company data inside them. Cannot see personal apps, photos or texts. Cannot wipe personal data.A normal personal phone with a few work apps that follow company rules inside themselves.

    For most UK SMEs, app protection only is enough. It blocks copy-paste from Outlook to a personal WhatsApp, requires a PIN to open the work apps, encrypts company data on the device, and lets the business wipe only the work data if the phone is lost or the employee leaves. The personal half of the phone stays untouched.

    Full enrolment makes sense for company-owned devices, particularly where Cyber Essentials evidence or regulated data is involved. For staff-owned phones, app protection usually delivers what the Cyber Essentials v3.3 update asks for, without the personal-property concern.

    A working BYOD policy fits on two pages

    A workable BYOD policy fits on two pages and answers the questions staff are actually asking. The points that matter:

    • Which devices are allowed (modern iOS and Android with current OS versions).
    • Which work apps are covered (Outlook, Teams, OneDrive, the rest of Microsoft 365).
    • What the business can and cannot see on the device.
    • What happens when someone leaves (company data wiped, personal data untouched).
    • What happens if the device is lost (the same).
    • Who pays for what (data plan, repairs, replacement).

    The policy is written for staff to read, not for lawyers to refer to. If staff cannot summarise it back to you in a sentence, it is too long.

    A four-step Intune rollout

    A practical sequence for an SME on Microsoft 365 Business Premium:

    1. Inventory. List who needs work apps on a phone, on what device, with what OS version.
    2. Policy. Configure app protection policies for Outlook, Teams and OneDrive: PIN required, copy-paste restricted to work apps, encryption enforced, selective wipe on leaver.
    3. Pilot. Enrol three to five willing staff first. Iron out the OS prompts and the PIN experience before the wider rollout.
    4. Communicate. Send the two-page BYOD policy with a five-bullet summary of what changes and what does not. The we cannot see your photos line goes first.

    The technical work is rarely the slow part. The communication is.

    Where this sits next to your other controls

    App protection on phones complements the controls you already have on laptops and Microsoft 365. Conditional access policies, the Microsoft Purview information protection foundation and Zero Trust principles all rely on knowing what device is making a request and what data lives on it. Without mobile management, the phone is the gap. With app protection, the phone joins the rest of the estate.

    However, for Cyber Essentials, assessors want to see that staff protect company data on their phones, not that the business controls the entire device. App protection meets the bar, and aligns with NCSC mobile device guidance.

    What it looks like once it is live

    A staff member loses a phone on the train. The business issues a selective wipe of the work apps from the Intune portal. Within minutes, IT can remove the work mailbox, Teams chats and OneDrive cache while leaving the staff member’s photos, contacts and personal apps untouched. They report the loss to the carrier and pick up a replacement on the weekend.

    That is the model staff can live with. It is also the model that closes the most realistic mobile risk most businesses are carrying.

    Roll it out without the politics

    Mobile device management does not have to be a fight. With app-protection-only policies, a short BYOD policy and a clear staff briefing, most businesses land Intune in a fortnight without losing goodwill.

    If you would like a second pair of eyes on your Microsoft 365 setup before you roll BYOD out, get in touch and we will walk through what your existing licence already covers, where the policy gaps sit, and what a sensible rollout looks like for your team size.

  • Retention Is Not Backup: Where Microsoft 365 Stops and Backup Starts

    Retention Is Not Backup: Where Microsoft 365 Stops and Backup Starts

    Microsoft 365 backup is not bundled into any Microsoft 365 subscription. However, Microsoft bundles retention instead: it holds deleted items for a defined window, replicates data across data centres, and protects the platform from its own failures. None of that is the same as backup. If a user empties a deleted-items folder, ransomware encrypts SharePoint files, or an admin deletes the wrong site collection, retention alone may not be enough to bring the data back.

    Microsoft does sell a first-party backup product called Microsoft 365 Backup, launched in 2024 and priced per gigabyte stored per month. Most UK SMEs we work with use a third-party backup tool instead because the per-GB pricing scales unpredictably and the feature set is narrower than the established backup market. Either way, the gap below is real: retention by itself does not give you point-in-time recovery.

    Where the confusion comes from

    Microsoft publishes a shared-responsibility model that splits ownership between platform and customer. Microsoft owns availability and infrastructure. The customer owns the data, the configuration, and the recovery of that data when something goes wrong on the customer’s side.

    Most businesses read “the cloud” as “they handle backup”. They do not.

    Retention vs backup

    Retention is a holding pattern for items that have been deleted or modified, kept for a defined period inside Microsoft 365. Backup is an independent copy of your data, stored outside the live platform, that can be restored to a point in time.

    The difference matters when something larger than a single deletion goes wrong.

    ScenarioRetention covers itBackup covers it
    User deletes a single emailYes, within retention windowYes
    User empties deleted itemsSometimes, depending on policyYes
    Ransomware encrypts OneDrive filesLimited, version history may helpYes
    Admin deletes a SharePoint siteLimited, 93-day recovery windowYes
    Departing employee mailbox archivedYes, with policy in placeYes
    Restore to a specific point in timeNoYes
    Restore Teams chat historyLimitedYes
    Recover after a full tenant compromiseNoYes

    Retention buys you a window. Backup gives you a copy.

    What Microsoft does and does not back up

    Microsoft replicates your data across multiple data centres for availability. That protects against hardware failure and regional outages. It does not protect against data your business has deleted, encrypted or corrupted.

    The native recycle bins and retention policies are useful, and you should configure them. They are not designed to replace a backup. They will not help you restore last Tuesday’s version of a SharePoint site, roll Teams back to a known clean state after a ransomware event, or recover a mailbox after a long-deleted account has aged out of retention.

    The NCSC Small Business Guide on backing up data is unambiguous on the principle: keep an independent copy of important data, and test that you can restore it.

    Where Microsoft 365 Backup the product sits

    Microsoft launched Microsoft 365 Backup in 2024 as its own paid backup product and built it directly into the Microsoft admin centre. In addition, it covers Exchange, OneDrive and SharePoint, restores items and full sites, and bills storage per gigabyte each month on top of the existing subscription.

    Two trade-offs decide whether it suits a UK SME. First, the per-GB pricing is unpredictable for businesses with growing storage estates, where third-party tools usually price per user. Second, the backups sit inside the same Microsoft tenant boundary as the live data, which keeps things convenient but means the backup is not stored outside the blast radius of a major tenant-level incident. Neither trade-off is a deal-breaker. Both are worth knowing before you choose.

    What good Microsoft 365 backup looks like

    A real Microsoft 365 backup covers Exchange Online, OneDrive, SharePoint and Teams, retains data for a period that suits your business, and supports point-in-time restore at item, folder and site level.

    Three operational details separate good from average.

    Restore granularity

    Can you restore a single email, a specific OneDrive folder, or a SharePoint site as it was on a Tuesday last month? If the answer is “we can restore the whole mailbox”, that is not enough for most real incidents.

    Test restores

    You cannot trust a backup until you have restored it successfully. Test restores at least quarterly on a sample of data.

    Independent credentials and storage

    The backup admin account should not share credentials with day-to-day Microsoft 365 admins, and backup data should sit outside the same blast radius as the live tenant. This is the test Microsoft 365 Backup the product does not pass on its own; a third-party tool with separate storage usually does.

    This is the same principle we applied in our ransomware downtime guide and our incident response plan template. Backup is the layer that turns a bad week into a recoverable one.

    When retention is enough

    For some SMEs, retention covers most realistic scenarios. A small team with limited turnover, no regulated data, a stable Microsoft 365 footprint and a clear retention policy may not need third-party backup as a day-one priority.

    That changes quickly. Once a business takes on regulated data, hits 20+ users, holds anything an attacker would consider valuable, or carries client contracts that require a documented recovery plan, retention alone becomes a thin layer to rely on.

    A short readiness check

    Three questions to ask:

    • If a user deleted everything in their OneDrive a year ago, could we restore it today?
    • If ransomware encrypted our SharePoint sites tomorrow, what would we use to restore them?
    • When did we last test a restore on a non-trivial item?

    If the answers are “probably not”, “I am not sure”, and “we have not”, retention is doing the work that backup should be doing.

    Close the gap before you need to use it

    Microsoft 365 retention is a useful tool. It is not a recovery strategy. The businesses we see recovering well from ransomware, mass deletion and account compromise are the ones that closed this gap before they needed to.

    If you would like us to check what your current Microsoft 365 setup can restore, book a Microsoft 365 backup gap assessment and we will produce a one-page recovery map covering Exchange, OneDrive, SharePoint and Teams.

  • PSTN Price Hike on 1 July 2026: Why UK Businesses Should Migrate Before Legacy Lines Double

    PSTN Price Hike on 1 July 2026: Why UK Businesses Should Migrate Before Legacy Lines Double

    The PSTN price increase in 2026 lands hardest on 1 July, when Openreach’s wholesale rental on legacy voice-only PSTN linesrises by a further 40% on top of April’s 20% rise. A third rise of 40% follows on 1 October. By the autumn, the published Openreach pricing path has roughly doubled the cost of a voice-only line compared with early 2025.

    Openreach is running a free PSTN migration offer for voice-only lines placed between 8 June and 31 October 2026, on the condition that migrations complete within 30 days of the offer closing. That makes June the practical decision month for most UK SMEs still sitting on legacy lines.

    Below: what changes on 1 July, who the Openreach offer covers, what to check before you migrate, and why waiting for the January 2027 switch-off is now the most expensive option on the table.

    The PSTN price increase comes in three rises across 2026

    Three rises are scheduled across 2026. Openreach has published a phased increase in legacy line rental to reflect rising maintenance costs on a network being retired.

    DateIncreaseCumulative effect
    1 April 2026+20%1.20x
    1 July 2026+40%1.68x
    1 October 2026+40%2.35x

    By the time the October rise lands, a voice-only PSTN line will cost more than double what it cost in early 2025. None of that is optional and none of it is reversible. It is the published Openreach pricing path until the network is switched off.

    The Openreach free PSTN migration window

    Openreach’s free migration offer covers voice-only PSTN lines and is available for migrations placed between 8 June and 31 October 2026. The migration itself must complete within 30 days of the closing date. For a UK SME with one or two analogue lines used only for voice, this is a clean path off the network at no Openreach cost.

    The offer is narrower than it first sounds. It does not cover multi-line setups with broadband bonded to the same circuit, lines used for ADSL or FTTC alongside voice, or lines feeding alarms, lift telephones, door entry systems or card terminals. Those need a proper migration plan, not a swap of provider.

    Our ISDN switch-off checklist covers the device-by-device audit most businesses skip and then regret on cutover day.

    What you migrate to

    For a business voice line, the natural replacement is a cloud-hosted phone system running over your existing broadband, or over a SoGEA line if the circuit has been doing both voice and data. A SoGEA broadband connection gives you the same physical link without the underlying voice path, which removes the PSTN cost entirely.

    Most SMEs migrating now also bring in unified communications, so calling, chat and meetings sit on one platform. That is a bigger decision than a like-for-like line swap, and it should not be made under deadline pressure. Starting in June gives you the room to make it properly.

    What about the January 2027 deadline?

    The national PSTN switch-off date is 31 January 2027. Industry coverage of the migration phase reports engineering capacity is already tightening. More than 500,000 UK businesses are still on legacy lines. The closer to the deadline you migrate, the longer you wait for an engineer and the more months you pay an inflated line rental while you wait.

    Waiting also rules out the free migration offer, which closes at the end of October 2026.

    Two patterns we see across the North East

    The first is professional services and clinics with a single back-of-house line that nobody has thought about in a decade. Those are the cleanest candidates for the Openreach offer.

    The second is older industrial and hospitality sites with mixed services on the same site: alarm dialler, lift line, card terminal, ordering line. Those sites need a migration plan rather than a phone call to a provider. Get the audit done early.

    What to do this month

    A practical sequence for June 2026:

    1. List every line at every site, including alarms, lifts, door entry and card terminals.
    2. Check each line’s contract type and whether it is voice-only or carrying broadband.
    3. Identify which lines are eligible for the free Openreach migration and which need replacement hardware.
    4. Choose a replacement: hosted phone system, SoGEA plus VoIP, or a full unified communications platform.
    5. Schedule the cutover before October to stay inside the offer window.

    If that list looks heavier than expected, that is normal. Most businesses underestimate how many devices quietly depend on a line until they walk the site.

    Plan the migration before the July price rise

    The 1 July rise is the second of three. The Openreach free migration window closes on 31 October. Waiting beyond the autumn means paying more for a line you will need to replace anyway, on a tighter timetable, with less engineering capacity available.

    If you would like us to audit your lines and check which qualify for the free Openreach migration, book a phone system migration audit and we will produce a one-page switch plan with eligible lines, replacement options and a cutover date that beats the next price rise.

  • Microsoft Agent 365: A Governance Starter Pack for Copilot Agents

    Microsoft Agent 365: A Governance Starter Pack for Copilot Agents

    Four key controls govern Copilot Agents: who can create agents, what data they can access, who can share them, and what actions they can perform externally. Get those four right and Microsoft Agent 365 becomes a useful productivity layer for your business. However, without those controls, you create a quiet new oversharing surface that sits on top of all the data your tenant has accumulated since 2018.

    Agent 365 reached general availability on 1 May 2026, and Microsoft’s Copilot data loss prevention for web search is rolling out worldwide through June 2026. For this reason, June is the right time to set the rules. Once staff start building agents at scale, governance becomes much harder to apply consistently.

    What changed with Microsoft Agent 365

    Microsoft Agent 365 brings agents into the same identity, security and management plane as users. Organisations can give Agents their own identity, assign them to specific data sources, enable them to perform actions across Microsoft 365 and selected third-party systems, and govern them using the same controls as human accounts.

    For an SME already using Microsoft 365 Copilot, this is the point where AI moves from a chat feature to something staff can build with. Copilot Studio lets users assemble agents that summarise weekly inboxes, route customer queries, draft proposals from templates, or trawl SharePoint for an answer. The hard part is no longer building. It is governing.

    The four Copilot Agents governance controls every business should set this month

    A workable Copilot Agents governance starter pack starts with four decisions that organisations document and enforce within the tenant. Configure them in the Microsoft 365 admin centre, Copilot Studio settings and Microsoft Purview.

    ControlWhat it doesWhere it lives
    1. Who can create agentsRestricts agent authoring to named users or a security groupCopilot Studio settings
    2. What data agents can ground inLimits which SharePoint sites, OneDrive locations or external sources an agent can useSensitivity labels and agent configuration
    3. Who agents can be shared withControls internal-only, by-team, or cross-tenant sharingMicrosoft 365 admin and Copilot Studio
    4. What agents can do externallyDLP rules that prevent sensitive data leaving the tenant via web search or third-party connectorsMicrosoft Purview DLP for Copilot

    That is the starter pack. However, it is not the end of governance; it is the floor.

    Control 1: Who can create agents

    The default is rarely the answer. If everyone with a Microsoft 365 licence can build agents, they will appear quickly. As a result, your IT team may struggle to track them. Therefore, organisations should start by restricting authoring to a named group, typically IT and a small number of trained power users, before reviewing access quarterly.

    When a team wants their own agent, the group helps them build it. That keeps the oversight loop in place without turning IT into a bottleneck.

    Control 2: What data agents can ground in

    This control sits on top of the work you have already done with Microsoft Purview. When your sensitivity labels are healthy, agents inherit the protection automatically. However, if those labels are weak or inconsistent, agents can pull from any SharePoint site they can reach.

    Walk through the same logic we laid out in our Microsoft Purview starter pack and make sure labels are applied before turning agents loose. Without that base layer, the next control gets harder.

    Control 3: Who agents can be shared with

    Agents can be shared inside a team, across the tenant, or with external organisations. Each step outward changes the risk profile. Tenant administrators in Agent 365 can now govern who is allowed to share agents created in Copilot. Set the default to internal-only, require approval for external sharing, and audit external-shared agents monthly.

    Take particular care with agents that touch customer or finance data. Those should not be shareable outside the team that owns them without a named approver.

    Control 4: What agents can do externally

    The June 2026 rollout of Copilot DLP for web search is the new control here. As a result, it prevents sensitive data from being included in prompts that hit web search. At the same time, it still allows the agent to ground its responses in internal data sources. Microsoft documents this in their Copilot blueprint for oversharing.

    Set DLP rules for the data classes you already protect in email and Teams: customer records, financial data, payroll, anything regulated. The same rules now apply to agent web actions.

    How this connects to what you already have

    If your business has worked through the AI readiness check and rolled out Copilot, Agent 365 is the next layer. Furthermore, the Purview labels, conditional access policies and AI acceptable-use guidance you put in place earlier this year still apply. Agent 365 extends them; it does not replace them.

    For businesses that have not started yet, the order matters. Labels and DLP first. Copilot second. Agents third. Skipping ahead means governing agents on top of an unlabelled tenant, which is the situation Microsoft’s own guidance describes as the oversharing problem.

    A short readiness check

    Three questions to ask before you let agents into the business at scale:

    • Have we restricted who can author agents in our tenant?
    • Are our SharePoint sites labelled with sensitivity that agents will respect?
    • Do we have DLP rules that apply to Copilot web search as well as email and Teams?

    If two of the three answers are no, get the controls in place this month.

    Set the rules before staff build the agents

    Microsoft Agent 365 is moving fast. Therefore, organisations should govern Copilot Agents before staff start shipping them into business processes, not afterwards. The four controls above take a working day to set up and a quarterly review to maintain.

    If you would like us to audit which agents already exist in your tenant, configure the four-control starter pack and check your Purview foundation, book a Copilot Agents governance review and we will produce a one-page agent inventory and a setup plan tailored to your Microsoft 365 estate.

  • Out of Office, Out of Pocket: How UK Businesses Stop BEC and Invoice Fraud This Summer

    Out of Office, Out of Pocket: How UK Businesses Stop BEC and Invoice Fraud This Summer

    Invoice fraud prevention is a seasonal problem for most UK SMEs, and the worst season is summer. Two of the three approvers are out, one new starter is covering the inbox, and the finance lead’s out-of-office reply tells anyone who emails that they are walking the Camino until late August. June through August is when invoice fraud lands. It lands because the people who would normally spot it are not in the building.

    Invoice fraud prevention is less about new tools and more about closing the seasonal gaps in how your business approves changes when senior staff are away. The five controls below take less than a week to put in place and cover the most common scams we see hitting UK businesses through the summer holiday window.

    Why invoice fraud prevention gets harder in summer

    In the UK Cyber Security Breaches Survey 2025/26, phishing was the most disruptive type of incident for most businesses that experienced one. The technique itself is not seasonal. The success rate is.

    When the finance director is on a beach in Crete, an email from “the finance director” asking the bookkeeper to authorise an urgent supplier bank-detail change carries more weight, not less. The bookkeeper cannot easily check. The MD who would normally be CC’d is also away. The supplier has been a real supplier for years. The bank account change is the only thing that has moved, and that is the part nobody notices.

    This is the operational reality criminals are betting on, and they are right often enough to keep doing it.

    Control 1: A deputy matrix that covers approvals

    Most businesses have an out-of-office system for replying to emails. Few have one for approvals. Build a one-page deputy matrix before staff start booking holiday. Three columns: the action that needs approval, the primary approver, the named deputy.

    Cover at minimum:

    • Supplier bank-detail changes
    • New supplier setup
    • Payments above a defined threshold
    • Payroll changes
    • Refunds above a threshold

    The matrix lives in finance, in HR and in your shared drive. Every approver knows who their deputy is, in writing, before the first holiday week. Adapting the 30-second social engineering script we published in May gives the deputy a working escalation pattern when something feels wrong.

    Control 2: Out-of-office replies that do not leak

    The default out-of-office reply tells the world the sender is away, for how long, who is covering, and often where they are. That is enough for a convincing impersonation attempt.

    A safer pattern says only what the recipient needs to know: that the message has been received, when a reply can be expected, and a generic team inbox or covering colleague for urgent matters. No travel details, or external phone numbers and no private mobile.

    The same rule applies to LinkedIn updates and team-wide announcements. Holiday plans do not need to be public.

    Control 3: A callback rule for any bank-detail change

    This is the single highest-impact control on the list. Any change to supplier banking details triggers a callback to a known phone number for that supplier, never to the number in the latest email signature. The known number lives in your purchase ledger, not in the email thread requesting the change.

    If the supplier cannot be reached, the change waits. The cultural piece matters as much as the rule: nobody gets blamed for delaying a payment to verify it. That is the no-shame part. Once it is in the cyber incident response plan and the team knows it applies to everyone including the MD, the rule holds.

    Control 4: Conditional access for travel windows

    If your team uses Microsoft 365 and your licences include conditional access, you can tighten sign-in rules during defined travel windows. Block sign-ins from countries staff are not in, require a fresh MFA prompt from new locations, and flag impossible-travel events for review.

    This sits naturally next to the controls described in our Cyber Essentials v3.3 guide. It is also the control that catches account takeover attempts before they reach finance at all.

    Control 5: A short briefing for the team

    Before the holiday season starts, send a five-bullet email to the people who handle money and inboxes. Cover the deputy matrix, the OOO rule, the callback rule, and the two scams to expect: a bank-detail change for a real supplier, and a same-day urgent payment request from a senior approver who is travelling.

    The briefing does not need to be long. It does need to be in writing, so the team can point to it when they apply the rules.

    What this looks like by mid-July

    A business that has done the five controls above answers a different question in August. Instead of “did we just send GBP18,000 to the wrong account”, the question becomes “should we approve this change today or wait for our finance lead to confirm on Monday”. That is the same conversation, with one difference. The money is still in the account.

    If you would like us to walk through your summer cover and tighten the gaps, book a 30-minute summer-readiness review and we will produce a deputy matrix, a callback rule and conditional access settings tailored to your business before the July rota change.

  • AI Governance: The 10-Point Policy You Need Before Staff Use AI Tools at Work

    AI Governance: The 10-Point Policy You Need Before Staff Use AI Tools at Work

    Your staff are already using AI tools. Whether it is ChatGPT for drafting emails, an AI image generator for social media, or a browser extension that summarises documents, generative AI has entered most workplaces without a formal decision being made about it. The question is not whether your team uses AI. It is whether you have any control over how they use it, what data they put into it, and what risks that creates for your business. Consulting an AI governance policy SME can help ensure you manage these challenges effectively.

    Most SMEs do not have an AI policy. They do not need a 30-page governance framework either. What they need is a clear, practical set of rules that staff understand and that protects the business from the most common risks: data leakage, compliance failures, reputational damage and over-reliance on unverified outputs.

    Here are ten points that cover what most SMEs need.

    The 10-Point AI Acceptable Use Policy

    1. Name the tools that are approved.

    List the AI tools your business sanctions for work use. If you use Microsoft 365 Copilot or another enterprise AI product, make it clear that this is the approved option. Unapproved tools should require sign-off before use.

    2. No sensitive data in public AI tools.

    Staff must not enter client data, financial information, employee records, passwords, contract details or any personally identifiable information into public AI tools like ChatGPT, Gemini or Claude. These tools may store or use inputs for training unless enterprise agreements say otherwise.

    3. All AI-generated content must be reviewed before use.

    AI outputs can contain factual errors, fabricated references, outdated information or biased language. Any content generated by AI that will be sent externally, published, or used in a decision must be reviewed and verified by a human before it goes out.

    4. AI must not be used for regulated decisions.

    Do not use AI to make hiring decisions, assess employee performance, approve financial transactions or take any action that has legal or regulatory implications without explicit senior approval and legal review.

    5. Declare AI use when required.

    If a client, regulator or procurement process asks whether AI was used in producing work, staff must answer honestly. Misrepresenting AI-generated work as entirely human-produced creates reputational and contractual risk.

    6. Do not install AI browser extensions or plugins without IT approval.

    Many AI tools operate as browser extensions that can read page content, access email, and interact with cloud applications. These should go through the same approval process as any other software installation. This connects directly to your shadow IT controls.

    7. Log AI tool usage for compliance.

    Maintain a simple register of which AI tools are used, by whom, and for what purpose. This does not need to be complex. A shared spreadsheet reviewed quarterly is enough to maintain visibility.

    8. Review supplier AI use.

    If your suppliers or subcontractors use AI to process your data or deliver services, understand what tools they use and what data they access. Include AI use in your supplier security questionnaire.

    9. Train staff on AI risks.

    Include a short AI safety module in your security awareness programme. Staff should understand the data leakage risk, the accuracy limitations, and the importance of not trusting AI outputs without verification. If you use managed security awareness training, discuss adding AI-specific scenarios with your provider.

    10. Review the policy every six months.

    AI tools and capabilities change fast. A policy written today may not cover the tools your team is using in six months. Build in a scheduled review rather than treating it as a one-off document.

    Why This Matters Even If You Do Not Sell AI Services

    This is not about whether your business offers AI products. It is about whether your staff use AI tools in the course of their work, and the answer is almost certainly yes. Without a policy, you have no visibility into what data is leaving your organisation, no standard for quality control on AI-generated outputs, and no defence if something goes wrong.

    The NCSC’s AI threat assessment highlights that AI is accelerating the speed and sophistication of cyber attacks, including phishing and social engineering. But the internal risk, staff pasting sensitive data into public AI tools, is just as real and far more common.

    Make It Simple, Make It Visible

    Print the 10 points. Pin them in the office. Include them in your onboarding pack. Refer to them in team meetings. A policy only works if people know it exists and understand why it matters.

    If you want help drafting an AI acceptable use policy tailored to your business, or you want to review how AI tools interact with your Microsoft 365 environmentcontact The Unite Group. We will help you put practical guardrails in place without slowing your team down.

  • Microsoft Purview Starter Pack: 3 Labels, 2 DLP Rules and a Monthly Audit Routine

    Microsoft Purview Starter Pack: 3 Labels, 2 DLP Rules and a Monthly Audit Routine

    Most SMEs have no data classification in place. Microsoft Purview for SMEs can provide essential tools to address these challenges. Files sit in SharePoint and OneDrive with no labels, no restrictions on sharing, and no visibility into what is leaving the organisation. When someone accidentally shares a client contract via a public link, or emails a spreadsheet of employee salary data to the wrong address, there is nothing in place to prevent it or even flag it.

    Microsoft Purview provides sensitivity labels and data loss prevention (DLP) rules inside Microsoft 365. If you have a Business Premium or E3 licence, you already have access to the core features. The problem is that most SMEs never configure them because the documentation is designed for enterprise compliance teams, not for a business with 30 users and no dedicated IT security function.

    This article gives you a realistic starter configuration: three sensitivity labels, two DLP rules, and a monthly audit routine that an SME can deploy and maintain without a compliance department.

    Three Sensitivity Labels to Start With

    Sensitivity labels classify your data by how sensitive it is. Once applied, labels can enforce protections such as encryption, watermarks, and sharing restrictions. Start with three labels. You can add more later, but three covers 90% of SME needs without confusing users.

    Public. Content that can be shared externally without restriction. Marketing materials, published blog posts, public-facing documents. No encryption, no restrictions. A footer reading “Public” provides a visual marker.

    Internal. Content intended for internal use only. Meeting notes, internal policies, project documents, staff communications. No encryption (this avoids friction), but a footer reading “Internal Use Only” reminds staff not to share externally. This should be the default label applied to all new documents automatically, so nothing is created without classification.

    Confidential. Content that would cause harm if shared externally. Client contracts, financial data, employee records, supplier pricing, legal correspondence. Apply encryption so only authorised users can open the file. Add a header and footer reading “Confidential.” Restrict external sharing.

    Publish these labels through a label policy in the Purview portal and set “Internal” as the default. Users can upgrade to “Confidential” when needed, but nothing is ever created unlabelled.

    Two DLP Rules That Prevent the Worst Outcomes

    DLP rules monitor for sensitive information leaving the organisation and either warn the user, block the action, or notify an administrator. Start with two rules that cover the highest-risk scenarios.

    Rule 1: Block external sharing of Confidential files. When a user tries to share a file labelled “Confidential” via a public SharePoint link, external email, or OneDrive sharing, the DLP rule blocks the action and shows a policy tip explaining why. This single rule prevents the most common accidental data exposure.

    Rule 2: Warn on sensitive data in email. Configure a DLP rule that detects common sensitive data types in outbound email: National Insurance numbers, credit card numbers, and bank account details. Instead of blocking, show a policy tip that asks the user to confirm they intend to send this externally. This catches accidental disclosures without blocking legitimate business communication.

    Run both rules in audit mode for the first two weeks. Review the matches, check for false positives, and adjust before switching to enforcement. This avoids disrupting your team with unexpected blocks.

    A Monthly Audit Routine

    Labels and DLP rules only work if someone checks they are being used correctly. Set a monthly 30-minute review.

    Check the data classification dashboard in Purview. How much content is labelled? How much is unlabelled? If the unlabelled percentage is growing, your default label policy may not be applied correctly, or new content is being created outside the scope.

    Review DLP incident reports. How many policy matches occurred? Were they genuine risks or false positives? Adjust rules if a specific file type or workflow is generating excessive alerts.

    Check for label downgrades. If users are routinely changing files from “Confidential” to “Internal” or “Public,” investigate why. It may indicate the label is being applied too broadly by auto-labelling, or that users are bypassing protections for convenience.

    How This Supports Copilot and Compliance

    If your business uses or plans to use Microsoft 365 Copilot, sensitivity labels become essential. Copilot surfaces content based on user permissions. Labels add a classification layer that tells Copilot (and DLP) how sensitive that content is, regardless of who has permission to access it.

    For compliance, labels provide an auditable record of how data is classified, who accessed it, and what protections were applied. This supports cyber insurance evidence requirements and demonstrates proportionate data handling if a regulator asks.

    Make It Part of Your Security Programme

    If you have Microsoft 365 Business Premium or E3 and have never configured sensitivity labels or DLP, the features are sitting unused in your subscription. Contact The Unite Group and we will set up your starter labels, configure DLP rules for your environment, publish the label policy, and show your team how to use them, all as part of your managed Microsoft 365 service.

  • Social Engineering in 2026: A 30-Second Script Your Team Can Use Today

    Social Engineering in 2026: A 30-Second Script Your Team Can Use Today

    The phishing email is no longer the only threat your team needs to worry about. The reality is that social engineering UK business threats are rapidly evolving. Social engineering attacks in 2026 are multi-channel: they start with a Teams message, follow up with a phone call from a spoofed number, and close with an email that references both previous contacts. The grammar is flawless. The caller sounds like someone your team recognises. The request feels urgent but reasonable.

    Vishing (voice phishing) volumes surged over 440% between 2024 and 2025. IT helpdesks are the primary target in 42% of attacks. Finance departments account for over 30% of successful breaches. These are not mass-blast campaigns. They are targeted, researched and designed to exploit the way your team naturally responds to authority and urgency. Technical controls help, but they cannot catch a convincing phone call. What your team needs is a simple, repeatable process they can follow when something feels off. That process is three words: Stop, Verify, Escalate.

    The 30-Second Script

    This script works for reception staff, finance teams, office managers, anyone who handles incoming requests by phone, email or Teams.

    Stop. Pause before acting on any request that involves money, credentials, access changes or sensitive information. Urgency is the attacker’s primary tool. A legitimate request can wait 60 seconds.

    Verify. Contact the person who supposedly made the request using a known, trusted channel. Do not reply to the email, return the call to the number displayed, or respond to the Teams message. Instead, look up the person’s number independently and call them directly. If they confirm the request, proceed. If they do not, you have just prevented an attack.

    Escalate. If you cannot verify the request, or if the caller pressures you not to check, escalate to your line manager or IT team immediately. No legitimate colleague or supplier will object to a verification step. Resistance to verification is itself a red flag.

    Print this script. Pin it next to every phone. Include it in your onboarding pack. The value is in its simplicity: three steps that any member of staff can follow without needing technical knowledge.

    What Multi-Channel Attacks Look Like

    Understanding the pattern helps your team recognise it. Here is how a typical multi-channel social engineering attack unfolds in 2026.

    Stage one: the setup. Your finance officer receives a Teams message from what appears to be the managing director’s account. The message says: “I need you to process a payment urgently. I will call you in five minutes to explain.” The message references a real project or client name, which the attacker found on LinkedIn or the company website.

    Stage two: the call. Five minutes later, a phone call arrives. The caller ID shows the managing director’s mobile number (spoofed). The voice sounds plausible. The caller explains that a supplier payment needs processing today to avoid a penalty. They provide bank details and ask for immediate action.

    Stage three: the follow-up. An email arrives from a slightly misspelled domain confirming the bank details “for your records.” The email includes a PDF invoice that looks legitimate. At every stage, the attack builds credibility by referencing the previous contact. Each touchpoint makes the next one harder to question. The entire sequence takes under 15 minutes.

    The Stop, Verify, Escalate script breaks this chain at stage one. The finance officer pauses, calls the managing director on their known mobile number, and discovers they never sent the Teams message.

    Where to Apply the Script

    The script applies to any request that involves transferring money or changing bank details, resetting passwords or MFA, granting system access or sharing login credentials, sending sensitive files or client data externally, and making urgent changes to payroll or supplier records.

    For payment and bank detail changes specifically, add a standing rule: no bank detail change is processed without a verbal confirmation from a known contact at the requesting organisation. This single control blocks the majority of business email compromise attacks.

    Building a No-Blame Culture

    The script only works if staff feel safe using it. If someone verifies a request and it turns out to be legitimate, they should never be criticised for checking. If someone escalates a suspicious call that turns out to be genuine, they should be thanked.

    Attackers exploit hierarchy. A junior staff member is less likely to question a request that appears to come from a director. Make it explicit: everyone in the business has permission to verify any request, regardless of who it appears to come from. Include this in your security awareness training and reinforce it in team meetings.

    Make It Part of Your Security Programme

    The script is a starting point. For ongoing protection, pair it with regular security awareness training that includes simulated phishing and vishing exercises. Test your team with realistic scenarios so that Stop, Verify, Escalate becomes a reflex rather than something they have to remember under pressure.

    If you want help rolling out the script, training your team, or setting up simulated exercises, contact The Unite Group. We deliver managed cyber security services across the North East, and staff training is a core part of how we protect your business.

  • AI Readiness Check: The Infrastructure Gaps Stopping SMEs from Using AI Properly

    AI Readiness Check: The Infrastructure Gaps Stopping SMEs from Using AI Properly

    Most businesses that try AI tools hit the same problem. The tools themselves are ready. The infrastructure underneath them is not. Microsoft Copilot is powerful, but it is only as useful as the data, permissions and device estate it sits on top of.If your business has not secured its identities, cleaned up overshared permissions, managed its devices, or classified its data, AI will either underperform or actively create risk.

    This is the gap that sits between buying a Copilot licence and actually getting value from it. AI readiness is not about adopting new technology. It is about getting your existing foundations in order so that new technology works properly when you turn it on.

    The Six Infrastructure Gaps That Block AI

    1. Identity and access.

    AI tools like Copilot operate under the identity of the user. If MFA is not enforced across all accounts, a compromised identity gives an attacker the same AI-powered access the user had. If admin accounts lack MFA, the exposure is even greater. Passkeys and phishing-resistant authentication add a further layer that AI-era threats require.

    2. Permissions and sharing.

    Copilot surfaces everything the user has permission to access. In most businesses, permissions have drifted over years of staff changes, project sharing, and “Everyone in the organisation” links that were never revoked. The result is Copilot exposing content that users were never meant to see, from HR files to financial data. Fixing permissions is the single most important AI readiness task.

    3. Data classification.

    Without sensitivity labels, all data is treated equally. Copilot cannot distinguish between a public marketing brief and a confidential client contract unless labels tell it the difference. Deploying even a basic three-label taxonomy (Public, Internal, Confidential) gives AI and DLP tools the classification layer they need to behave appropriately.

    4. Device currency and management.

    AI features in Microsoft 365 require current operating systems and supported hardware. Devices running Windows 10 past end of support miss security updates and may not support the latest Microsoft 365 app features. Unmanaged devices, those not enrolled in Intune or equivalent, create blind spots where AI tools operate without the compliance policies your managed estate enforces.

    5. Licensing alignment.

    Not every user needs a Copilot licence. Not every user needs Business Premium. A business paying for 30 Copilot licences when only 10 people use the features daily is wasting money. Equally, users on Business Basic licences miss security features (Intune, Entra ID P1, Defender) that AI deployment assumes are in place. A licence audit that matches the right plan to the right role is a prerequisite, not an afterthought.

    6. Backup and recovery.

    AI accelerates productivity, which means your business creates, shares and modifies more data faster than before. If your backup and recovery strategydoes not cover the full Microsoft 365 estate (Exchange, OneDrive, SharePoint, Teams), you are accumulating more unprotected data at a faster rate. AI amplifies the consequences of not having proper backups.

    The Readiness Checklist

    Before deploying AI tools, confirm each of these:

    Your business enforces MFA on every account with no exceptions. Your team has audited SharePoint and OneDrive permissions and removed oversharing. Sensitivity labels are deployed and a default label is applied to all new content. All devices are managed, patched and running a supported operating system. Licences are matched to user roles and needs. Your Microsoft 365 backup covers all workloads, and your team has tested it within the last quarter.

    If any of these are incomplete, fix them first. Deploying AI on top of weak foundations does not just limit the value. It amplifies the risk. Copilot can surface restricted files, operate on unsecured devices, and generate content from data your business has not backed up.

    Legacy Infrastructure Is the Real Blocker

    Businesses often treat AI readiness as a conversation about buying new tools. In practice, the blocker is almost always the infrastructure that already exists. Many businesses rely on servers approaching end of life, unmanaged device fleets, organic permission structures that nobody has reviewed in years, and licensing models originally built for smaller teams.

    These are not AI problems. They are IT management problems that AI makes visible and urgent. A business that fixes them gets value from AI immediately. A business that ignores them will spend money on Copilot licences and wonder why the return never materialises.

    Get an AI Readiness Assessment

    If you want to deploy AI tools confidently, start with the foundations. Contact The Unite Group for an AI readiness assessment. We will audit your identity controls, permissions, device estate, data classification, licensing and backup coverage, then give you a clear, prioritised plan to close the gaps before you switch anything on. All of this is part of our managed IT and cyber security service.