Tag: the unite group

  • Windows Server 2016 Support Ends January 2027: Is Your North East Business Ready?

    Windows Server 2016 Support Ends January 2027: Is Your North East Business Ready?

    If you still rely on Windows Server 2016, you now have a clear deadline. Windows Server 2016 end of support is 12 January 2027. After that, Microsoft stops providing regular security updates, which means any new vulnerability stays open on any server you have left on 2016.

    For a lot of North East SMEs, those servers are quietly running the things that matter most: line-of-business applications, shared drives, account systems and databases. Leaving them on an unsupported platform is not just a technical risk, it is a business risk. This article explains what Windows Server 2016 end of support actually means, how to check where you stand, and the practical routes to modernise before the 2027 cut-off.

    What Windows Server 2016 end of support actually means

    Microsoft gives its server products two main phases of support: mainstream support with feature updates, and extended support focused on security fixes. For Windows Server 2016, mainstream support ended in January 2022 and extended support ends on 12 January 2027. After that point, no regular security patches are released for most customers.

    When a platform goes out of support:

    • Newly discovered vulnerabilities may never be patched.
    • Security and compliance frameworks expect you to be on supported software, or to have a clear plan to move.
    • Third-party vendors may stop certifying their applications on that version.
    • You may be able to use paid Extended Security Updates (ESU) as a short-term bridge, but these are designed as temporary cover while you migrate, not a long-term plan.

    For many SMEs in and around Newcastle, Gateshead, North Tyneside and County Durham, the practical route is to upgrade or migrate away from Windows Server 2016 over the next 12–18 months, rather than waiting until late 2026.

    Why this deadline matters for North East SMEs

    If your servers sit in a cupboard or a small comms room, it is easy to ignore them while they just ‘keep working’. The 2027 end of support date forces a different question: if this server failed tomorrow or was compromised, what part of the business would stop?

    Typical impacts when legacy servers are left too long include:

    • Prolonged downtime while ageing hardware and software are coaxed back to life.
    • Higher recovery costs, because modern backup and disaster recovery was never set up properly on older platforms.
    • Audit and insurance pressure, where unsupported systems are flagged as a material cyber risk.

    The good news is that there is enough time to move away from Windows Server 2016 in a controlled way, rather than rushing a migration in late 2026.

    Step 1: Get a clear picture of your current servers

    Before deciding what to do next, you need an accurate inventory. For most SMEs, that means answering four simple questions.

    1) Which servers are still running Windows Server 2016?

    List physical and virtual machines, including anything hosted in a local data centre or colocation facility. Note their roles, such as file server, domain controller, application server or SQL database host.

    2) What does each server actually support?

    Map servers to business functions, such as:

    • Finance and accounts
    • Line-of-business or industry-specific apps
    • File storage and printing
    • Identity and authentication (Active Directory)

    3) Who depends on these systems?

    Identify departments, sites and external partners that rely on those services so you can prioritise high-impact workloads.

    4) How critical is each workload?

    Group them into:

    • Tier 1: Cannot be down during working hours
    • Tier 2: Can tolerate short, planned downtime
    • Tier 3: Legacy, rarely used or candidates for retirement

    If you already work with an IT partner, ask them to produce this view as part of a Windows Server 2016 review. This is typically covered under an ongoing support arrangement like Managed IT Services.

    Step 2: Choose your direction, upgrade, move to cloud, or retire

    Once you know what is running on Windows Server 2016, you can decide the best path for each workload. In practice, most North East businesses use a mix of three approaches.

    Option A: Upgrade to a newer on-premise Windows Server

    If you still need a local server at your office or data centre, upgrading to a newer long-term support version of Windows Server keeps a familiar model with a more modern foundation.

    This is usually suitable where:

    • You have on-site hardware that still has life left and is supported.
    • Regulations or application requirements mean the server must stay on-premise.
    • Latency-sensitive systems need to sit close to machinery or local infrastructure.

    The trade-off is that you remain responsible for hardware, power, cooling and physical security. Treat the upgrade as a chance to tidy up and standardise, not just lift-and-shift an untidy setup onto a newer operating system.

    Option B: Migrate workloads to cloud or hosted platforms

    For many SMEs, Windows Server 2016 end of support is a natural trigger to move parts of the stack to:

    • Hosted applications, such as SaaS replacements for on-premise systems
    • Cloud infrastructure, where servers are virtual rather than physical
    • Modern file storage backed by Microsoft 365 and SharePoint for collaboration

    This route reduces hardware and patching overhead, but it needs careful planning around identity, security, connectivity and backup so you do not simply move risk elsewhere. If you are weighing cloud options locally, Unite’s guide to business cloud solutions in Newcastle and the North East is a helpful starting point.

    Option C: Retire unused or low-value workloads

    Almost every server estate contains at least one system that nobody really needs any more. When you find those on Windows Server 2016, the simplest option is often to retire them completely.

    That might mean archiving data for compliance, exporting reports or consolidating functions into newer systems. Removing unused servers reduces your attack surface and simplifies what you need to support.

    Step 3: Build a realistic migration plan to 2027

    Once you have grouped workloads into upgrade, migrate or retire, you can put timelines against them. A practical plan usually includes:

    Prioritised phases
    Tackle high-impact systems first, such as finance and core line-of-business apps, especially if they sit on older hardware.

    Testing time
    Allow for test environments where upgrades or migrations can run without disrupting live users.

    Communication with staff
    Let teams know when systems will be offline and what will change, especially if new logins or ways of working are involved.

    Fallback and backup
    Ensure backups are recent, tested and usable before making any major change to a Windows Server 2016 environment. If you need to tighten this up, Unite’s article on IT disaster recovery strategy and business continuity is worth a read.

    Rather than one big ‘server replacement project’, treat this as a series of smaller, manageable changes over the next 12–18 months.

    Step 4: Reduce risk while you transition off Windows Server 2016

    You may not be able to move everything overnight, so it is important to reduce risk on any Windows Server 2016 systems that will be around for a while.

    Practical measures include:

    • Tightening access to management interfaces and remote access
    • Ensuring endpoint protection is up to date and monitored
    • Segmenting older servers on the network so they are less exposed
    • Improving backup and disaster recovery arrangements so that if something goes wrong, you can recover quickly

    These are not a substitute for moving away from an unsupported platform, but they can reduce exposure while projects are in flight. If you are also working towards a recognised baseline, Cyber Essentials can help structure the fundamentals, including patch management and secure configuration.

    How a local partner can help North East businesses prepare

    For many organisations, the hardest part of dealing with Windows Server 2016 end of support is finding the time and internal expertise. A local managed IT and cyber security partner can:

    • Audit your current server estate and map business impact
    • Advise on whether on-premise upgrades, cloud options or hybrids make most sense
    • Plan migrations to minimise downtime for staff and customers
    • Build backup and disaster recovery plans around your most important systems

    Unite supports North East SMEs with practical IT planning and delivery that fits how teams actually work, whether that’s modernising on-premise infrastructure, improving resilience, or moving the right workloads into the cloud. This is typically delivered through ongoing support via Managed IT Services and Microsoft environment management via Microsoft 365 services.

    Next steps if you are still on Windows Server 2016

    Windows Server 2016 will continue to run after January 2027, but running critical systems on an unsupported platform leaves your organisation exposed in ways that are increasingly hard to justify.

    A sensible next move is to:

    • Confirm exactly where you are still using Windows Server 2016
    • Prioritise servers by business impact and technical risk
    • Decide which workloads to upgrade, move to cloud or retire
    • Put a phased plan in place to complete the work well before the 2027 deadline

    If you want structured help rather than trying to untangle this on your own, a managed IT partner can handle the planning and delivery.

    Talk to Unite about a Windows Server 2016 end of support review. You’ll get a clear map of your current servers, practical recommendations for upgrade or migration, and help turning that into a timeline that fits your budget and business priorities.
    Contact Unite

  • Safer Internet Day 2026: Promoting AI Safety and Cyber Awareness at Work

    Safer Internet Day 2026: Promoting AI Safety and Cyber Awareness at Work

    Safer Internet Day 2026 is a good moment to reset how your organisation handles AI use and cyber awareness at work. This year’s theme is about making safer choices with ‘smart tech’, which is exactly where most day-to-day risk sits: what people share, click, download, approve, or trust too quickly. Done well, a simple awareness push in February can lead to clearer rules, better habits, and fewer avoidable incidents.

    Why Safer Internet Day 2026 matters for UK workplaces

    Safer Internet Day 2026 takes place on 10 February 2026. The campaign is often associated with schools and young people, but the theme is just as relevant in the workplace, especially as AI tools become part of everyday tasks.

    Many organisations now have AI in the mix somewhere, whether that’s built into productivity tools or used for drafting, summarising, and quick research. That can save time, but it can also introduce risk if staff share sensitive information, accept outputs at face value, or use unapproved tools without realising what happens to the data.

    Safer Internet Day gives you a simple, time-boxed way to:

    • refresh expectations for safe AI use without making it feel heavy or technical
    • connect AI habits to the cyber basics your business already relies on
    • remind people that security is a shared responsibility, not ‘just an IT thing’

    Turn the theme into simple AI safety rules people will actually follow

    If you want this to stick, keep it short and practical. These four principles usually cover most situations.

    1) Know the tool

    Be clear which AI tools are approved for work use and which are not. Not all tools handle information in the same way, and ‘I didn’t know’ is a common reason mistakes happen.

    If your organisation runs on Microsoft 365, it helps to align this with how accounts, permissions and sharing are managed day to day. Unite can support that setup through their Microsoft 365 services.

    2) Protect the data

    Set a plain-English rule that removes guesswork. For example:

    • don’t paste personal data, payment details, or confidential client information into public AI tools
    • treat anything you wouldn’t send outside the business as ‘not safe to share’

    If you use enterprise tools with tighter controls, spell out what is allowed and what is not, in a way people can apply in the moment.

    3) Check before you trust

    AI outputs are useful drafts, not guaranteed truth. Encourage staff to sense-check anything customer-facing or decision-critical, such as prices, policies, dates, technical instructions, or compliance-related wording.

    A simple habit helps: if it matters, verify it before you send it.

    4) Stay within your policies

    AI use should sit inside the same expectations you already have around acceptable use, information security, and data handling. The aim is not to ban AI, it’s to put guard rails in place so people can use it safely.

    Simple Safer Internet Day activities your team can run

    You don’t need a big programme. A few focused actions are usually enough to change behaviour.

    A short ‘AI and data’ toolbox talk (20 to 30 minutes)

    Cover:

    • what Safer Internet Day is and why you’re marking it
    • where AI is currently used in your business (including informal use)
    • your top three ‘do’ and ‘don’t’ rules for AI and data
    • a refresher on phishing and suspicious requests (because most incidents still start with a message that looks normal)

    Real-world scenario practice (10 minutes)

    Give staff a few realistic situations and ask, ‘What would you do?’ For example:

    • someone pastes a client spreadsheet into a public AI chatbot to ‘summarise it quickly’
    • a draft customer email written with AI includes outdated pricing
    • an email claims to be from a supplier and asks the user to ‘re-verify’ their login details

    The goal is to reinforce safe defaults: pause, check, ask, and report.

    A quick account and policy health-check

    Use the day as a reason to confirm the basics are in place:

    • multi-factor authentication where available
    • password and access expectations (especially for admin accounts)
    • a clear reporting route when something looks suspicious
    • a known place to find policies, so people are not guessing

    If you want a recognised baseline for core controls, Cyber Essentials is built around the fundamentals that reduce common cyber risks. Unite supports businesses through this via their Cyber Essentials service.

    Put ‘guard rails’ around AI use without slowing people down

    A good AI policy doesn’t need to be long. It needs to answer the real questions people face at work.

    A practical workplace AI policy usually covers:

    • where AI is encouraged (drafting, summarising, brainstorming) and where it is not
    • what data must never be shared with external tools
    • accountability, meaning staff remain responsible for what they submit and send
    • transparency, meaning when AI use should be disclosed internally or to clients
    • escalation, meaning who to contact if someone suspects misuse or a security issue

    Keep it short, repeat it often, and make it easy to follow.

    Linking AI safety with wider cyber awareness

    AI safety sits alongside cyber security basics, it doesn’t replace them. Good habits around emails, links, access, and data handling still do most of the heavy lifting.

    The most useful message for teams is simple: the safer you are with everyday actions, the less likely a small mistake becomes a bigger incident. 

    Not sure where to start? Book a short conversation with the Unite team about AI safety and cyber security in your business. We can help you review your current setup, prioritise practical changes and support your team so safer choices become the default. You can reach the team via Unite’s contact page.

  • Identity Threat Detection (ITDR): The Cybersecurity Shift Your Business Cannot Ignore

    Identity Threat Detection (ITDR): The Cybersecurity Shift Your Business Cannot Ignore

    Identity threat detection is about spotting and stopping attacks that target user accounts rather than the perimeter. Instead of only watching firewalls and antivirus, IT teams focus on unusual sign-ins, suspicious use of permissions and signs that someone is abusing a real account. For SMEs, that shift matters because many modern attacks start with stolen or misused credentials, not fancy malware.

    For a small or mid-sized business, this is good news as well as a warning. You do not need a giant security budget to improve your position. You do need to treat identities as the new perimeter, use identity threat detection tools where they fit, and make sure your Microsoft 365, VPN and line-of-business apps are not running on blind trust. If you want a stronger baseline first, Unite can also help you tighten the fundamentals through Cyber Essentials certification support.

    What identity threat detection actually is

    Identity threat detection and response, often shortened to ITDR, adds a security layer on top of your existing identity and access management. Where traditional IAM focuses on who can log in and what they can reach, ITDR watches how those identities behave and flags activity that looks risky.

    For an SME that usually means three things in practice:

    • Monitoring sign-ins for patterns that do not make sense, such as impossible travel, unusual locations or brand-new devices.
    • Watching how privileged accounts are used, especially admin and finance roles.
    • Linking identity signals with your other security tools, so you can respond quickly when something looks wrong.

    You may already have some ITDR-style capability in tools such as Microsoft Entra ID Protection, security add-ons for Microsoft 365 or your SIEM. The shift is less about buying yet another product and more about treating identity data as a primary signal rather than an afterthought. If you are unsure what you already have switched on, Unite can help you review your Microsoft tenancy and security setup via their Microsoft 365 services.

    Why identities are now your real perimeter

    Most security conversations used to revolve around keeping people ‘outside the network’. Firewalls, VPNs and antivirus still matter, but they assume you can tell inside from outside. With cloud services, remote work and personal devices, that boundary has blurred. Many vendors now describe identity as the new perimeter because attackers increasingly aim to sign in as a real user instead of breaking down the door.

    Industry breach reports back this up. Verizon’s 2024 Data Breach Investigations Report found that the human element, including stolen credentials and phishing, played a part in roughly two-thirds of breaches they analysed. A single compromised Microsoft 365 account can give an attacker access to email, files, Teams chats and sometimes finance systems in one go. If you want a practical view of the risks inside Microsoft 365 specifically, Unite’s piece on protecting Microsoft 365 identities and environments is a useful companion read.

    For a growing SME that relies on cloud platforms, that has a few clear implications:

    • Passwords, MFA and sign-in policies are now front-line security controls, not ‘IT admin settings’.
    • Admin accounts and service accounts carry far more risk than their small number suggests.
    • You need a way to spot and investigate odd behaviour around identities before it turns into a serious incident.

    That is where identity threat detection fits. If you are still in the stage of getting MFA applied consistently, Unite’s explainer on why MFA matters for business security can help you frame the change internally.

    How identity threat detection works day to day

    Identity threat detection does not replace your existing security tools. Instead, it pulls together identity-related signals and helps you focus on the events that matter. Typical capabilities include:

    1. Risk-based sign-in monitoring

    ITDR tools score sign-ins based on factors such as location, device health, user history and known attack techniques. High-risk attempts can be blocked, forced through extra checks or flagged for review.

    For example, if an account that usually logs in from Tyneside on a managed laptop suddenly appears from a new device in another country, that should create a visible alert. You do not have to inspect every login manually, the system brings you the outliers.

    2. Privileged identity monitoring

    Administrator accounts, finance systems and line-of-business apps with wide access are prime targets. Identity threat detection watches for:

    • New admin roles being granted unexpectedly
    • Changes to MFA or security settings on key accounts
    • Bulk actions such as large mailbox rule changes or permission grants

    The aim is not to block your IT team from doing their job. It is to make sure high-impact changes leave a clear trail and trigger checks when they look unusual.

    3. Lateral movement and misuse of access

    Once attackers have a foothold, they often try to move sideways by reusing tokens, abusing service accounts or granting themselves persistent access. ITDR helps you see patterns such as:

    • One account authenticating to many resources it never used before
    • Service accounts being used from odd locations or devices
    • Repeated attempts to access sensitive apps without success

    This identity-centred view pairs well with endpoint protection and network monitoring. Together they tell a fuller story of what is happening.

    Do SMEs really need identity threat detection?

    It is reasonable for a business owner or FD to ask whether identity threat detection is ‘overkill’ for a 50- or 150-user organisation. The honest answer depends on how you work rather than your headcount. Identity threat detection is worth serious consideration if:

    • You rely heavily on cloud platforms such as Microsoft 365, Teams and cloud accounting.
    • Staff work from multiple locations or devices and you do not control every laptop and phone.
    • You handle sensitive data, financial, personal or commercially valuable, that would be attractive to an attacker.
    • You are working towards Cyber Essentials, cyber insurance or other assurance for customers.

    In those contexts, a basic username-and-password model with occasional MFA is no longer enough. Attackers use automated tools to test breached credentials, send convincing phishing emails and probe legacy sign-in methods that bypass your stronger controls.

    The goal is not to chase every new security trend. It is to recognise that identities, not just devices, are now central to how your staff reach systems and data. Watching that layer closely is a practical, modern way to reduce risk.

    Getting started with identity threat detection in a small business

    You do not need to jump straight to a full ITDR platform to benefit from identity-centred security. For many SMEs, sensible first steps look like this:

    1. Strengthen your identity basics

    Before you think about detection, make sure the foundations are in place:

    • Enforce multi-factor authentication on all accounts where possible.
    • Close off legacy sign-in methods such as basic authentication that bypass MFA.
    • Use conditional access rules so sensitive apps are only reachable from compliant devices and appropriate locations.

    These basics support any later move into ITDR and already block many opportunistic attacks.

    2. Turn on and tune built-in identity protections

    If you use Microsoft 365 or Azure, you may already have access to risk-based sign-in and identity protection features through Microsoft Entra ID and related tools. Work with your IT partner to:

    • Review what identity risk signals you are already licensed for.
    • Enable core alerts for risky sign-ins and risky users.
    • Agree how those alerts are triaged, investigated and closed.

    The aim is a short, meaningful list of alerts that someone genuinely owns, not a flood of noise.

    3. Decide who is responsible for watching identities

    Identity threat detection does not help if nobody looks at the results. Clarify:

    • Who receives alerts about risky sign-ins or suspicious changes.
    • What counts as a routine event versus something that should be escalated.
    • How incidents are documented and fed into your wider cyber security and business continuity plans.

    For many North East SMEs, this responsibility sits best with a managed IT or cyber security partner that can monitor signals and bring deeper expertise when something looks serious. This is typically covered within an ongoing support model, such as Managed IT Services.

    Where ITDR sits alongside your existing cyber security

    Identity threat detection is one part of a wider cyber security picture, not a silver bullet. For a typical SME, a balanced approach still includes:

    • Basic hygiene such as patching, endpoint protection and secure backups.
    • User awareness training and phishing simulations so staff recognise social engineering.
    • Clear joiner, mover and leaver processes so accounts are created, changed and removed promptly.
    • Frameworks such as Cyber Essentials to provide structure and external assurance.

    Think of ITDR as the layer that helps you spot when those controls are being probed or bypassed through your identities. For a business that already has the basics in place, it is a natural next step rather than a luxury.

    Unite’s teams already work with identity signals through Microsoft 365, endpoint tooling and wider monitoring. Bringing those signals together, and making identities a first-class security concern, is how you move from ‘we have MFA’ to ‘we can see when someone is trying to work around it’.

    Next steps

    Identity threat detection is not only for global enterprises. For SMEs that rely on cloud services, remote work and flexible access, it is a practical way to reduce the risk that a single compromised account derails operations.

    By strengthening your identity basics, switching on the protections you already own and deciding who watches those signals, you can start benefiting from this shift without turning your business into a security lab. If you want help reviewing your current Microsoft 365 setup, tightening access controls, and aligning your security approach with Cyber Essentials, speak to the Unite team. 

    Start here: Contact Unite.

  • Achieving Cyber Essentials Certification: Step-by-Step Guide for SMEs

    Achieving Cyber Essentials Certification: Step-by-Step Guide for SMEs

    If you already know that Cyber Essentials is on your to-do list, the next question is simple: how to get Cyber Essentials in a way that’s realistic for your team. This guide gives you clear Cyber Essentials certification steps from start to finish. It focuses on the practical Cyber Essentials process for small business owners who want to pass first time, win or keep contracts, and avoid turning the self-assessment into a stressful box-ticking exercise.

    Whether you’re based in Newcastle, across the North East, or anywhere in the UK, we’ll walk you through preparation, scope, controls, the questionnaire, submission and renewal, with plain-English tips on where SMEs usually trip up and where Unite can help.

    Step 1: Get clear on why you’re doing Cyber Essentials

    Before you start any work, you need a simple answer to one question: why are you investing in Cyber Essentials now?

    Common reasons include:

    • A client, framework or tender requires Cyber Essentials
    • You want a recognised baseline to prove you take security seriously
    • You’re planning to grow into supply chains that expect it

    This answer matters because it influences:

    • Whether you start with standard Cyber Essentials or plan for Cyber Essentials Plus later
    • How wide your Cyber Essentials scope definition should be
    • How much time and budget you allocate

    At this stage, you don’t need to dive into the technical detail. You just need a clear business driver and a named person who’ll own the project.

    Step 2: Define scope and gather the essentials

    The next part of how to get Cyber Essentials is understanding what’ll fall under the certificate. This is the most important early decision and a common place where SMEs make life harder than it needs to be.

    2.1 Decide what’s in scope

    Scope is about which parts of your organisation and which systems are covered. You’ll need to decide, for example:

    • Are all locations in scope, or just head office and a satellite office?
    • Are home workers and their devices included?
    • Are all cloud services in scope, or only those used for sensitive data?

    Good Cyber Essentials scope definition balances realism and value. You’ve got to cover all systems that handle business data, but you don’t need to include every historic server that no one uses.

    Real-world example:
    A Newcastle accountancy practice initially tried to include every device anyone had ever touched. They ended up with 47 items on their asset list, including three laptops gathering dust in a cupboard and a server that hadn’t been switched on in two years. After a sensible scope review, they trimmed it down to 18 active devices and passed first time.

    2.2 Make a simple asset list

    Create a basic list of:

    • Users and roles
    • Laptops, desktops and tablets
    • Servers, including any on-site kit
    • Cloud services such as Microsoft 365, line-of-business systems and file storage
    • Firewalls and routers, both on-site and in the cloud

    This list will drive your Cyber Essentials checklist UK and help you avoid scrambling for information when you tackle the questionnaire.

    Step 3: Fix the basics in the five control areas

    Cyber Essentials focuses on a small number of technical controls. You don’t need to be an expert, but you do need to show that the basics are in place across your scoped environment. This is the heart of the Cyber Essentials process for small business.

    A practical way to approach this is to work through each area in turn and record what you change.

    3.1 Firewalls and internet gateways

    What you’ll need to check:

    • Confirm that all internet connections, including home-worker routers where in scope, are protected by a firewall
    • Remove unused open ports and risky rules
    • Disable default admin accounts and change default passwords

    Where businesses often trip up:
    They forget about older routers, guest Wi-Fi networks or direct connections into equipment like printers. One Gateshead professional services firm discovered they’d completely overlooked a printer with its own internet connection, that one device nearly scuppered their entire assessment.

    3.2 Secure configuration

    Here you focus on settings on devices and systems, for example:

    • Remove or disable unused software and services
    • Apply standard secure builds or configuration templates where possible
    • Turn on built-in security features such as device encryption

    Where businesses often trip up:
    Leaving devices with factory settings, or allowing users to run as local administrators when there’s no need. It’s surprisingly common, and surprisingly easy to fix once you know to look for it.

    3.3 User access control

    You need to show that accounts and access are managed properly:

    • Use named, individual accounts, not shared logins
    • Grant the minimum access needed for each role
    • Review who has administrator rights and reduce them where possible

    Where businesses often trip up:
    Old accounts that were never removed when staff left. We’ve seen businesses with “John-Sales-2019” accounts still active three years after John moved to a competitor. A quick audit usually finds half a dozen of these.

    3.4 Malware protection

    This is about preventing malicious software from running:

    • Ensure supported anti-malware is installed and updating on all in-scope devices
    • Turn on real-time scanning for files and downloads
    • Remove unsupported operating systems that can’t be protected properly

    Where businesses often trip up:
    Devices that are rarely connected to the network and therefore miss updates. That laptop your MD uses twice a year for site visits? It’s probably three years behind on definitions.

    3.5 Security update management

    You need to show that systems are kept up to date:

    • Turn on automatic updates where practical
    • Apply critical and high-risk patches within the timelines set by the scheme
    • Keep an eye on end-of-support dates and plan to replace unsupported systems

    If you document the work you do in these five areas, you’ll find the later Cyber Essentials self-assessment questionnaire help much easier, because you’re not answering from memory.

    Step 4: Complete the self-assessment questionnaire

    Once you’ve worked through the technical controls, you’re ready for the self-assessment. This is where many SMEs start searching for how to pass Cyber Essentials first time, and with good reason. The questionnaire isn’t difficult, but it’s detailed.

    4.1 Set up with a certification body

    You’ll need to:

    • Choose a certification body and create an account
    • Confirm your chosen scope
    • Choose standard Cyber Essentials first, or plan for Cyber Essentials Plus later

    Working with a partner that offers Cyber Essentials support North East or in your region can make this smoother, especially if you’re short on internal technical resource.

    4.2 Answer carefully and consistently

    Tips for completing the questionnaire:

    • Work through it with your asset list and configuration notes to hand
    • Answer honestly and consistently, conflicting answers are a red flag
    • Use the comments boxes to explain any edge cases or transitional situations

    If you’ve followed your own Cyber Essentials checklist UK as you prepared, most questions should now be a case of describing what you’ve already done.

    Real-world example:
    A North East manufacturing business rushed their first questionnaire and gave contradictory answers about their firewall setup. They said “yes” to having a firewall in section 2, then described a configuration in section 4 that wouldn’t have been possible with that firewall. The assessor spotted it immediately. They had to resubmit with a proper explanation, adding two weeks to their timeline when they were up against a tender deadline.

    Step 5: Deal with feedback and achieve certification

    After submitting the self-assessment, the assessor will review your answers. At this stage you’ll either:

    • Be issued with your certificate, or
    • Receive feedback with items you must fix before you can pass

    Many SMEs pass on the second attempt, which is normal. The important part is to respond quickly to feedback. This is where a partner who offers Cyber Essentials certification steps support can walk you through what needs changing and how to evidence it.

    How long does Cyber Essentials certification last?

    A common question is how long does Cyber Essentials certification last. The answer is that the certificate is valid for 12 months. After that you need to complete a new assessment and go through the Cyber Essentials renewal process.

    Standard Cyber Essentials is an annual cycle. Cyber Essentials Plus involves an additional technical audit, but follows the same renewal pattern.

    Step 6: Plan for renewal and keep it manageable

    Once you’ve got your first certificate, the next piece of how to get Cyber Essentials is actually how to keep it.

    Practical steps:

    • Put a reminder in your calendar around nine months after the award date
    • Keep a simple record of changes, for example, new systems or major updates
    • Review your five control areas every quarter so you’re not rushing at renewal

    Treating the controls as part of normal IT and security management, rather than a once-a-year project, makes each renewal lighter and improves your overall security posture.

    Common reasons SMEs fail Cyber Essentials first time

    A lot of organisations search for how to pass Cyber Essentials first time because they’ve heard stories of failed attempts. Typical issues include:

    • Scope that’s too vague or too wide, which creates confusion
    • Devices on unsupported operating systems
    • Old user accounts that haven’t been removed
    • Firewalls or routers left with default settings and credentials
    • Incomplete records of where data is stored or which services are in scope

    None of this is unfixable, but it’s much easier to tackle ahead of submission. A short readiness review with a partner can pick up most of these issues early.

    A simple Cyber Essentials checklist for SMEs

    To recap the Cyber Essentials certification steps, here’s a short checklist you can keep:

    1. Confirm why you’re doing Cyber Essentials and who owns it
    2. Define scope: locations, users, devices and cloud services
    3. Create a basic asset list and keep it up to date
    4. Work through each of the five control areas and record what you change
    5. Choose a certification body and complete the self-assessment carefully
    6. Fix any issues raised and resubmit if needed
    7. Note your renewal date and plan for the next cycle

    If you follow this flow, you should find that Cyber Essentials requirements explained in the official guidance feel far less daunting, because you’ll have a plan and evidence ready.

    FAQs: Cyber Essentials process and timing

    1. How long does Cyber Essentials take for a small business?

    For most SMEs, plan for four–eight weeks from decision to certificate. The main work is in preparing your environment and gathering information. Once you submit, the assessment itself is usually quite quick.

    2. Do we need Cyber Essentials Plus straight away?

    Not always. Many businesses start with standard Cyber Essentials, then move to Plus later when clients or contracts require it. You can treat Plus as an additional layer once you’re comfortable with the basics.

    3. How often do we need to renew?

    You need to renew every 12 months. That’s why it’s important to build the controls into day-to-day IT management, rather than rushing once a year.

    4. Can a very small business achieve Cyber Essentials?

    Yes. The scheme is specifically designed to be achievable for small organisations, as long as you’re willing to tidy up devices, accounts and basic configuration.

    5. Can we get help with the Cyber Essentials self-assessment questionnaire?

    Yes. Many providers, including Unite, offer Cyber Essentials self-assessment questionnaire help, where an engineer walks through questions with you and explains what’s being asked in plain English.

    6. Does Cyber Essentials cover our suppliers as well?

    Cyber Essentials focuses on your own systems, although many organisations use it as a baseline when assessing suppliers. For suppliers, you can ask for their own certificate or wider assurance.

    7. What’s the difference between Cyber Essentials and Cyber Essentials Plus?

    At a high level, standard Cyber Essentials is a self-assessment, while Cyber Essentials Plus adds an independent technical audit. If you’re unsure which route to take, a short discovery call can help you decide.

    Not sure where to start? Get a Cyber Essentials readiness review

    If you know you need Cyber Essentials, but you’re not sure how to turn the requirements into a concrete plan, Unite can help. Whether you’re in Newcastle, the North East or beyond, we can provide:

    • A short readiness review that checks your current position against the controls
    • Help to define a sensible scope for your first certificate
    • Support with remediation, configuration and the self-assessment
    • Ongoing assistance with the Cyber Essentials renewal process so each year is easier than the last

    We’ve helped dozens of North East businesses through Cyber Essentials from tiny startups to established firms with complex environments. We know where the trip-ups are, and we know how to explain things without drowning you in jargon.


    Book a Cyber Essentials readiness review and we’ll walk you through the exact steps to certification, in language your team can understand. Local support, practical guidance, no unnecessary complexity.

  • Business Broadband vs Leased Lines: Choosing the Right Internet for Your SME

    Business Broadband vs Leased Lines: Choosing the Right Internet for Your SME

    If you’re choosing between business broadband and a leased line, the key question is simple: how critical is your internet connection to daily operations? For many smaller organisations, good business broadband is enough. Once phones, Microsoft Teams, cloud applications and remote work become central, a leased line (a form of dedicated internet access for business) starts to look less like a luxury and more like insurance.

    This guide explains leased line vs business broadband in straightforward terms so you can decide based on risk and growth, rather than on headline speed alone.

    Business broadband vs leased line: the quick comparison

    FeatureBusiness broadbandLeased line (dedicated internet)
    Connection typeShared with other users (contended)Dedicated to your business only (uncontended)
    Speed“Up to” speeds, can drop at busy timesGuaranteed upload and download speeds
    SymmetryAsymmetric broadband (faster download than upload)Symmetric, same upload and download speed
    SLAsBasic business SLAStrong SLA (uptime and fix time commitments)
    ReliabilityGenerally good, can be affected by local congestionHigh, designed for mission-critical services
    Best forSmaller teams, email, browsing, light SaaSVoIP, contact centres, heavy cloud use, remote desktop
    Typical costLower monthly costHigher monthly cost

    A useful way to think about it:

    • Business broadband is like a well-managed public road, usually fine, but busy at rush hour.
    • A leased line is your own private lane that nobody else can use.

    What business broadband actually gives you

    With business broadband, you’re usually on FTTC or FTTP over shared local infrastructure. You get more stability than a home line, but you still share capacity with other users on the same cabinet or exchange.

    In practice, that means:

    • Contended bandwidth, you share the available capacity with other customers
    • Advertised “up to” speeds, rather than guaranteed performance
    • Asymmetric broadband, for example 100 Mbps down and 20 Mbps up
    • Business features such as static IP addresses, better routers and a dedicated support line

    For many SMEs this is perfectly adequate. If you’ve got a single office, a modest team and most of your day is spent in web applications, email and cloud storage, well-configured business broadband for VoIP and day-to-day work can offer very good value.

    Broadband is usually enough when:

    • You’ve got fewer than around 15–20 users on one site
    • You’re not running a high-volume phone or contact centre
    • You’re not uploading large video or CAD files all day
    • A slow period is inconvenient, but doesn’t stop the business operating

    If that’s your situation, it often makes more sense to improve Wi-Fi coverage, router configuration and basic security before considering a leased line.

    What a leased line changes

    A leased line is a dedicated fibre circuit from your premises into your provider’s network. It’s a classic example of dedicated internet access for business. No other customer uses that circuit.

    Compared with standard broadband, it offers three main differences:

    Uncontended bandwidth

    You’re not sharing capacity with other premises in the area.

    Symmetric speeds

    If you buy 200 Mbps, you get 200 Mbps down and 200 Mbps up. This is particularly important for VoIP, Teams and remote access.

    Stronger SLAs

    A typical leased line SLA vs broadband SLA will include clear uptime guarantees, target fix times and better escalation paths.

    A leased line tends to make sense when:

    • You’ve got 20 or more users regularly online at once
    • Phones and cloud phone systems are central to sales or customer service
    • Remote workers live in VPNs or remote desktops throughout the day
    • Outages or poor performance have obvious financial or reputational costs

    In these cases, connectivity moves from being an IT cost to being business-critical infrastructure.

    The real-world difference between leased line and broadband

    The difference between leased line and broadband isn’t just a line in a contract. It’s how your working day feels.

    On business broadband, performance rises and falls as everyone in your area logs on and off. You might be fine for most of the day, then hit choppy Teams calls at 9.30 am and 4 pm when many people are on video.

    On a leased line, performance is more predictable. Your capacity isn’t affected by your neighbours. This is why a fibre leased line vs fibre broadband can feel very different, even when the advertised speeds appear similar.

    Signs that your current broadband might be the bottleneck include:

    • Regular “robotic” or broken-up calls on VoIP
    • Teams or Zoom meetings where video freezes or drops
    • Uploads that are very slow even when downloads appear fine
    • Staff complaining at the same times every day

    If these patterns keep returning, and you’ve already improved Wi-Fi and router settings, it’s worth looking seriously at leased line vs business broadband instead of assuming it’s “just one of those things”.

    Cost and risk: more than “how much per month?”

    On paper, the leased line cost for small business will almost always be higher than broadband. The more useful question is:

    “What does it cost us if the internet is down for half a day?”

    For some organisations, the answer is “not much”, they can adapt and manage. For others, half a day offline means missed orders, unhappy customers, broken SLAs and staff who can’t do their jobs.

    In broad terms:

    • Business broadband is cheaper, often on 12–24 month terms, with “best effort” speeds and limited compensation
    • A leased line is more expensive, usually on 36-month terms, with defined uptime and fix time commitments

    If a single outage would cost more than a couple of months of leased line fees, it becomes easier to see why some businesses view a leased line as risk management rather than a nice-to-have.

    A simple way to decide

    You don’t need a spreadsheet of acronyms to decide between business broadband vs leased line. This quick framework can help.

    Broadband is probably enough if:

    • You’re a small, single-site office
    • You’re not running a heavy contact centre
    • Teams and VoIP work well most of the time
    • Downtime is frustrating, but doesn’t shut the business

    A leased line is worth serious consideration if:

    • Calls and cloud phone systems are central to how you serve customers
    • You rely heavily on cloud applications and remote access
    • You’re planning to grow headcount or open new sites
    • Clients expect strong uptime and defined response times
    • You’ve already improved Wi-Fi and router setups and still see issues

    If you sit in the middle, it’s often worth asking a provider to review your current setup and usage before you commit either way.

    Common mistakes when comparing options

    There are a few common traps when people weigh up business broadband vs leased line.

    Choosing by headline speed only

    A “1 Gbps” contended broadband service doesn’t guarantee smooth calls if everyone else nearby is busy. A lower-speed dedicated internet access for business line can behave better in practice.

    Ignoring upload speeds

    Uploads power calls, video, backups and file sharing. The asymmetric broadband model (fast downloads and slower uploads) is where smaller offices often begin to struggle as they grow.

    Assuming one line is enough for ever

    Whether you stick with broadband or move to a leased line, there comes a point where you also want a backup, such as a second broadband service or 4G/5G failover, especially if you can’t easily trade without connectivity.

    FAQs: business broadband vs leased lines

    1. Is a leased line always faster than business broadband?

    Not always. You can buy similar headline speeds on both. The benefit of a leased line is that those speeds are guaranteed and uncontended, rather than “up to”.

    2. Do we need a leased line for VoIP and cloud phone systems?

    Smaller teams can run VoIP on good business broadband. If phones are mission-critical, such as a support desk or sales floor, a leased line gives you more predictable quality and capacity.

    3. How long does a leased line take to install?

    Broadband can often be live within days. A leased line can take several weeks to a few months, depending on surveys, permissions and engineering work.

    4. Can we start on broadband and upgrade later?

    Yes. Many organisations begin with broadband and move to a leased line once they add more users, open new locations or rely more heavily on cloud services.

    5. Is a leased line more secure?

    It’s more predictable and easier to manage, but not automatically more secure. Security still depends on your firewalls, configuration and policies, whichever service you choose.

    6. How do we know what speed we need?

    That depends on user numbers, the tools you use and your plans for growth. A good provider will size the service (whether broadband or dedicated internet access for business) based on real usage rather than simply offering the highest speed.

    7. Should we ever have both broadband and a leased line?

    Yes. Some businesses run a leased line as their primary link and keep business broadband or 4G/5G as a backup, so they’ve got a way to stay online if the primary connection fails.

    Not sure which way to go? Get a plain-English connectivity review

    Choosing between a leased line vs business broadband is really about matching connectivity to how your business works today and where it’s heading in the next few years.

    If you’d like a view that’s clear and practical, you can ask Unite for a short connectivity review. Whether you’re in Newcastle, the North East or beyond, we’ll look at:

    • How you’re using phones, Teams and cloud applications now
    • Where performance or reliability is already under strain
    • Whether smarter business broadband, a leased line, or a mix of both is the right move

    We’re not here to push the most expensive option, we’re here to help you make the right call for your business.


    Book a quick connectivity review and we’ll help you decide whether you truly need a leased line, or whether better broadband and setup will do the job. Local support, honest advice, no nonsense.

  • How SD-WAN and Backup Connections Keep Your Business Online

    How SD-WAN and Backup Connections Keep Your Business Online

    If your phones, tills or cloud systems stop when the internet drops, you’re exactly the sort of organisation that can benefit from SD-WAN. In simple terms, SD-WAN lets you use more than one internet connection intelligently, so if one link fails or slows, traffic moves to another with minimal disruption. Combine that with sensible business internet backup solutions and you get something close to always-on internet for business, without enterprise-sized complexity.

    This guide explains what SD-WAN looks like in real life for SMEs across the North East and beyond, and how it keeps VoIP, card payments, Microsoft Teams and booking systems running when your main connection isn’t behaving.

    Why “always-on” matters more than ever

    For many SMEs, losing internet is no longer just an inconvenience. It can mean:

    • Phones going straight to voicemail
    • Card machines and EPOS systems refusing payments
    • Microsoft Teams calls dropping in the middle of client meetings
    • Cloud CRM, case management or booking systems becoming unreachable

    If you rely on connectivity resilience for cloud phone systems, remote staff or online bookings, you can’t afford to rely on a single, fragile connection. That’s why more organisations are looking at SD-WAN benefits for SMEs and backup links such as 4G failover for business broadband.

    What is SD-WAN in plain English?

    Traditional WANs were built around private circuits and complex routers in each site. SD-WAN or Software Defined Wide Area Networking is a more flexible way to manage connectivity.

    For small business customers in the UK, the basic idea is:

    • You’ve got two or more connections at a site (for example, fibre broadband and 4G)
    • An SD-WAN device or service sits in front of them
    • It constantly monitors the quality of each connection
    • It sends different types of traffic over the best available path

    You can think of it as a smart traffic controller. Instead of all traffic going through one road until it fails, SD-WAN watches all the roads and routes traffic based on current conditions.

    This is where it differs from SD-WAN vs traditional WAN approaches. Traditional WAN relies on fixed routing and manual changes. SD-WAN understands your applications and adapts dynamically.

    Some businesses already use a dual WAN router for small business to connect two internet lines. That’s a good start, but SD-WAN typically does more:

    • It looks at quality, not just “up or down” if one line is technically up but jittery, voice and video can be moved to the better line
    • It can send some traffic over both links at once, improving throughput and resilience
    • It can prioritise critical traffic such as network redundancy for VoIP or cloud apps, while using spare capacity for less time-sensitive tasks

    In other words, a dual WAN router sees two pipes. SD-WAN sees the behaviour of those pipes and your applications, then uses both intelligently.

    You might have, for example:

    • A primary connection, such as fibre or a leased line, used for most traffic
    • A secondary broadband line
    • A 4G failover for business broadband SIM as a last resort

    With SD-WAN and sensible design, all three can play a role.

    Backup connections: what your options look like

    If you want always-on internet for business, you need at least one backup option. SD-WAN then helps you make the most of it.

    Typical combinations include:

    Second broadband line

    A straightforward choice is a second broadband circuit from a different provider. Benefits include:

    • Extra capacity for busy periods
    • A separate path if one provider has an issue

    With SD-WAN, you can use both actively, not just keep one idle for emergencies.

    4G or 5G backup

    A 4G/5G router or SIM can act as a “last line of defence” when fixed lines fail. This is especially useful for:

    • Shops and venues that must keep taking card payments
    • Sites where quick fixes are hard, such as remote locations

    The key phrase here is 4G failover for business broadband. SD-WAN can detect a fixed line problem and move key traffic to 4G automatically so tills and phones keep working.

    SD-WAN and leased lines

    Larger or more critical sites might pair SD-WAN and leased lines. For example:

    In this setup, SD-WAN keeps core services on the leased line under normal conditions, but still has options when there’s an outage or maintenance.

    Real-life examples: how SD-WAN keeps things running

    To make this less abstract, here are two simple scenarios.

    Example 1: Single-site venue with phones and tills

    A busy restaurant and bar has:

    • Cloud EPOS and stock system
    • Card machines that need live authorisation
    • A small cloud phone system for bookings
    • A main broadband line and a 4G router

    Without SD-WAN:

    When the broadband drops, tills and phones stop working. Staff scramble to reboot routers and ring support. The 4G router is sitting there, but switching over is manual and messy. Customers get frustrated. Tables go unserved. Orders pile up.

    With SD-WAN and proper business internet backup solutions:

    The SD-WAN device sees that broadband is down or unstable. It automatically moves payment and voice traffic onto 4G. Calls still come in, and card payments still process, even if speeds are lower.

    Customers barely notice. Staff focus on serving, not troubleshooting. Business carries on.

    Example 2: Multi-site professional services firm

    A regional firm has:

    • Three offices connected to central cloud systems
    • Heavy use of Microsoft Teams for internal and client meetings
    • A SD-WAN managed service provider looking after their network

    At one office, the main connection begins to show high delays. Without SD-WAN, this would mean poor calls and sluggish access to files.

    With SD-WAN:

    The system detects the quality issue. It routes failover internet for Microsoft Teams sessions and VoIP calls onto the better performing link. Less critical traffic, such as large downloads, waits or uses the weaker line.

    Again, users see some slight variation, but video and voice keep working. Client meetings don’t get interrupted. Productivity stays on track.

    Is SD-WAN right for your organisation?

    Not every organisation needs SD-WAN for small business today. It’s worth looking at SD-WAN when:

    • A single outage has a clear financial impact
    • You already pay for more than one connection but only use one effectively
    • You operate more than one site, or have important branch offices
    • You’re serious about connectivity resilience for cloud phone systems and critical apps

    On the other hand, if you’re a very small office on a tight budget, it may be enough to start with:

    • One solid business broadband connection
    • A basic backup option such as 4G
    • Good routers and simple failover rules

    The important part is to plan for resilience early, rather than waiting for a painful incident.

    FAQs: SD-WAN and backup internet for SMEs

    1. Is SD-WAN only for large enterprises?

    No. Many vendors now offer SD-WAN for small business with simpler pricing and deployment. It’s particularly helpful for SMEs with multiple sites or critical cloud services.

    2. What do we need in place to use SD-WAN?

    At minimum, you need two or more connections (such as broadband and 4G), plus an SD-WAN device or service at each key site. Your provider will usually supply and manage the equipment.

    3. How is SD-WAN different from a dual WAN router?

    A basic dual WAN router can fail over when a link goes down. SD-WAN goes further by monitoring quality, prioritising applications and using all available paths more intelligently.

    4. Do we need both SD-WAN and leased lines?

    Not always. Some SMEs use SD-WAN over two broadband lines. Others pair SD-WAN and leased lines for their most critical sites. The right design depends on how much risk you’re trying to reduce.

    5. Will our staff notice anything when failover happens?

    If SD-WAN is set up well, most failover events should be invisible or feel like a brief pause, especially for voice, video and web apps. That’s the main goal.

    6. Which applications benefit most from SD-WAN?

    Real-time services such as VoIP, cloud phone systems, Microsoft Teams and other collaboration tools benefit the most, along with cloud line-of-business systems that staff use all day.

    7. Do we need in-house expertise to run SD-WAN?

    Not necessarily. Many organisations work with an SD-WAN managed service provider who designs, monitors and maintains the solution, so internal teams focus on users and applications.

    Not sure where to start? Get a resilience and SD-WAN review

    If you’re worried about outages, dropped calls or card machines failing at busy times, it may be time to look at SD-WAN and backup connectivity.

    Whether you’re based in Newcastle, across the North East, or elsewhere in the UK, Unite can help you:

    • Review your current connectivity and risks
    • Identify suitable business internet backup solutions, such as second lines and 4G failover for business broadband
    • Design a simple SD-WAN rollout, starting with your most critical sites
    • Manage and monitor the service so you don’t need specialist skills in-house

    We’re not here to sell you the most complicated solution. We’re here to help you stay online when it matters most.


    Book a connectivity resilience review and we’ll show you how SD-WAN and backup connections can keep your business online, even when your main link doesn’t behave. Local support, practical solutions, no complexity for complexity’s sake.

  • On-Premise vs Cloud Phone Systems: Which Is Right for Your Business?

    On-Premise vs Cloud Phone Systems: Which Is Right for Your Business?

    The Unite Group

    If you’re choosing between an on-premise vs cloud phone system, you’re really deciding how much control you want to keep in your own comms room and how much you want a provider to handle for you. For some UK SMEs, an upgraded on-premise PBX still makes sense. For many others, a hosted or cloud-based system now offers better flexibility, lower risk and a smoother path to hybrid working. This guide walks through the key decision factors, gives a simple small business phone system comparison, and helps you decide which way you should lean. 

    The basics: what are you actually comparing?

    Before you dive into cost and features, it helps to be clear about what we mean by each option.

    On-premise phone system

    An on-premise system usually means:

    • You’ve got a physical PBX box or server on your site
    • Handsets and local lines plug into that box
    • You or your IT provider maintain the hardware and software

    This is the traditional phone system vs VoIP picture many businesses still have in place, especially where they’ve used the same supplier for many years.

    Cloud or hosted phone system

    A cloud phone platform means:

    • The call handling brain lives in a secure data centre, not in your office
    • Handsets, softphones and apps connect over the internet
    • Your provider is responsible for upgrades, resilience and capacity

    This covers hosted vs on-premise phone system setups and what people often call hosted VoIP. There’s no PBX box on site, only network equipment and handsets.

    Decision factor 1: Cost today and over five years

    The cost of on-premise vs cloud phone system can look very different depending on whether you focus on upfront spend or ongoing value.

    On-premise cost pattern

    You typically see:

    • Larger upfront capital spend for hardware, licences and installation
    • Lower monthly fees, often line rental and support only
    • Occasional extra costs for upgrades, cards, modules or expansion

    This can appeal if you like to own equipment outright, but it does mean you carry the risk of that kit ageing or becoming difficult to support.

    Cloud cost pattern

    Cloud-based systems tend to be:

    • Subscription based, per user per month
    • Lower upfront cost, mostly handsets or headsets and set-up time
    • Easier to scale up and down by changing licence counts

    If you’re weighing business phone system upgrade options, it can help to sketch a simple five-year view of both patterns rather than only comparing first-year costs.

    Leans on-premise if:
    You prefer capital spend and your system is stable, with little expected change in users or sites.

    Leans cloud if:
    You want predictable monthly costs and expect to grow, shrink or move sites during the next few years.

    Decision factor 2: Control, customisation and responsibility

    A central part of the on-premise vs cloud PBX decision is how much control you want and how much responsibility you’re happy to hand over.

    On-premise control

    With on-premise equipment you usually have:

    • Full control of the hardware and software in your building
    • The ability to integrate specialised hardware for example, legacy door entry systems or analogue lines
    • Responsibility for resilience, upgrades and power

    This level of control can be helpful in complex environments, but it also means you must plan for failure and maintenance yourself.

    Cloud control

    With a hosted system, you:

    • Control numbers, users, call flows and basic features through a web portal
    • Don’t need to worry about server operating systems, physical cards or local power issues
    • Rely on the provider for resilience and upgrades

    Modern platforms give a high degree of logical control while removing the need to nurse physical equipment.

    Leans on-premise if:
    You’ve got specific hardware integrations on site that are hard to move and an IT team that’s comfortable owning telephony infrastructure.

    Leans cloud if:
    You want control over how calls are routed and handled, but don’t want to run phone servers and hardware.

    Decision factor 3: Flexibility and remote work

    One of the main advantages of cloud phone systems is how easily they support remote and hybrid work.

    On-premise and remote work

    An on-premise PBX can support remote users, but it often involves:

    • VPN access or site-to-site links
    • Extra configuration and security considerations
    • Limited flexibility if staff are moving around regularly

    It can be done well, but it’s usually more complex and relies heavily on your network design.

    Cloud and remote work

    A cloud phone system for small business UK users will normally offer:

    • Softphone apps for laptops and mobiles
    • Built-in support for users working from home or on the move
    • Easier routing rules for time of day, location and team membership

    If supporting a phone system for hybrid workforce use is a priority, cloud-based options are usually ahead from day one.

    Real-world example:
    A marketing agency with 12 staff moved to a cloud-based phone system when they adopted flexible working. Now their account managers take client calls seamlessly whether they’re in the Newcastle office, working from home, or meeting clients on site. With their old on-premise system, remote calls meant fumbling with VPN connections and call forwarding, now it just works.

    Leans on-premise if:
    Most users work from fixed desks, in one or two sites, and you don’t expect this to change.

    Leans cloud if:
    You’ve got a mix of office, home and field-based staff and want phone access to feel the same wherever they are.

    Decision factor 4: Reliability and business continuity

    Both on-premise and cloud solutions can be highly reliable, but they handle physical failures in different ways.

    On-premise reliability

    An on-premise PBX is tightly connected to your building. It usually works well as long as:

    • Local power is stable
    • Local network hardware is healthy
    • Inbound lines into the building are working

    If there’s a power cut, building issue or major local line fault, calls may be affected until that’s fixed.

    Cloud reliability

    In a cloud model:

    • The core phone platform is in resilient data centres with backup power and multiple links
    • Your handsets and apps reach that platform over internet connections
    • If your site has an issue, calls can still route to mobiles, other locations or voicemail

    When you consider business phone system upgrade options, it’s worth looking at how each approach behaves during a power cut, fire alarm or local outage.

    Real-world example:
    A professional services firm in Gateshead experienced a power outage during a January storm. Their cloud-based phone system automatically diverted calls to their staff’s mobiles and their second office. Clients got through first time, every time. With their previous on-premise system, similar outages meant a “closed for business” experience until power returned.

    Leans on-premise if:
    You’ve got very strong local resilience and line diversity already in place and your building is the only place where calls ever need to land.

    Leans cloud if:
    You want calls to be able to move quickly to mobiles, home workers or other offices if something happens at your main site.

    Decision factor 5: Future-proofing and ISDN replacement

    Many UK businesses are still running ISDN-based systems that are approaching end of life. If you need to replace ISDN phone system with VoIP, you’ve got a natural trigger point to decide whether to invest again on site or move to a hosted model.

    Moving from PBX to cloud phone

    If you’re already planning a significant upgrade, moving from PBX to cloud phone can give you:

    • A cleaner path away from legacy lines and cards
    • Easier integration with collaboration tools and CRMs
    • The option to unify numbers and presence with solutions such as Teams calling

    If you stay on-premise, you may still modernise with SIP trunks and IP handsets, but you’ll continue to own and manage more of the physical infrastructure.

    Leans on-premise if:
    You’ve recently invested in on-premise kit and it still has a long support life ahead, or compliance demands that certain functions remain fully on site.

    Leans cloud if:
    You’re planning a major change anyway and want to avoid another big hardware replacement cycle in a few years.

    Decision factor 6: Experience for customers and staff

    From your customers’ point of view, the phone experience matters more than the technology behind it. Both on-premise and cloud can deliver a professional experience, but ease of change can differ.

    With on-premise systems, you may need engineer time or on-site visits to:

    • Change IVR menus
    • Add new call queues or hunt groups
    • Introduce seasonal messages or routing rules

    With hosted platforms, these changes are usually made in a web portal, often by internal admins without needing a visit.

    For staff, pros and cons of hosted VoIP include:

    • The ability to take calls on different devices
    • Better integration with address books, CRMs and collaboration tools
    • New features arriving through regular platform updates

    If you want to experiment with new ways of working for example, blending calls and chat or routing calls to a phone system for hybrid workforce in a new department, it’s often easier to pilot on a cloud platform.

    Simple decision guide: which way should you lean?

    Use this as a quick small business phone system comparison for direction.

    You may lean towards on-premise if:

    • You’ve got a single main site and most staff work there all the time
    • You’ve got very specific on-site integrations that are difficult to move
    • You’ve already invested in modern on-premise kit and simply need minor changes
    • You’ve got internal IT resources who are comfortable managing telephony hardware

    You may lean towards cloud or hosted if:

    • You’re planning to replace ISDN phone system with VoIP in the near future
    • You want simpler support for hybrid and remote workers
    • You prefer a subscription model and don’t want to own phone servers
    • You want faster access to new features and integrations

    In many cases there’s also a sensible hybrid path, where you keep some on-premise elements for specific needs, and add hosted VoIP for new sites or teams. A partner that understands both models can help you take a phased approach rather than a big-bang change.

    FAQs: on-premise vs cloud phone system

    1. Is a cloud phone platform always cheaper than on-premise?

    Not always. Over five years, cloud often works out cost-effective for growing teams because you can adjust licences. In stable environments with little change, an on-premise system can still be competitive, especially if it’s already in place.

    2. Can we keep our existing numbers if we move to cloud?

    In most cases yes, numbers can be ported from your current provider to a hosted solution. Your partner should plan number porting carefully as part of the migration.

    3. Is call quality better on-premise or in the cloud?

    Call quality depends mainly on connectivity and configuration. Hosted systems can deliver excellent quality as long as you’ve got suitable internet connections and quality of service on your network.

    4. How long does it take to move from PBX to a cloud platform?

    It varies by size and complexity. Smaller businesses can often move in a matter of weeks. Larger or multi-site organisations may take longer, especially if they want a phased transition.

    5. What happens if the internet goes down with a cloud-based system?

    Calls can usually be diverted to mobiles, other offices or voicemail until service is restored. Many organisations combine cloud telephony with resilient connectivity so that full outages are rare.

    6. Can we integrate phones with Microsoft Teams or our CRM?

    Cloud-based platforms usually have an easier time integrating with tools such as Teams and common CRMs. On-premise systems may be able to integrate, but often require more bespoke work.

    7. Can we start small with cloud and move more users later?

    Yes. Many SMEs start with a pilot group or a single site, then extend cloud telephony as confidence grows and on-premise kit reaches the end of its life.

    Not sure which route to take? Get a phone system comparison session

    Choosing between on-premise vs cloud phone system options doesn’t have to be an all-or-nothing decision. The right answer depends on your sites, staff, existing kit and growth plans.

    Whether you’re based in Newcastle, across the North East, or elsewhere in the UK, Unite can help you:

    • Review your current system and contracts
    • Map out business phone system upgrade options, including hybrid approaches
    • Compare practical pros and cons for your specific environment
    • Plan a low-risk move, whether that’s refreshing on-premise kit, moving from PBX to cloud phone, or a mix of both

    We’re not here to push you towards the most expensive option. We’re here to help you find what actually works for your business.


    Book a short phone system comparison session and we’ll help you decide whether to stay on-premise, move to the cloud, or take a phased hybrid approach that fits your business. Local expertise, honest advice, no tech jargon.

  • Cyber Essentials Certification Body: What You Need to Know 

    Cyber Essentials Certification Body: What You Need to Know 

    Unite group meeting

    What Is a Cyber Essentials Certification Body? 

     

    A Cyber Essentials Certification Body is an accredited organisation that has been officially approved to assess, support and certify businesses against the UK Government-backed Cyber Essentials scheme. This certification is designed to help businesses of all sizes protect themselves from the most common and disruptive forms of cyberattacks. 

    At The Unite Group, we’re proud to act as an in-house certification body, helping businesses across the UK gain Cyber Essentials and Cyber Essentials Plus certifications quickly, confidently, and with ongoing support. 

    Why Cyber Essentials Matters 

    Cyber Essentials is not just a piece of paper; it’s a formal recognition that your business takes cyber security seriously. Certification means you’ve implemented key security controls to safeguard your organisation from 80% of common cyber threats, and therefore, you benefit from protections such as:

    • Malware 
    • Ransomware 
    • Phishing attacks 
    • Data breaches 

    Therefore, achieving certification also unlocks new opportunities for your business. Many government and MOD contracts now require certification as a minimum. It’s not just about security – it’s about staying competitive. 

    The Unite Group as a Certification Body 

    What sets The Unite Group apart is that we are not just consultants. As an official Cyber Essentials Certification Body, we offer: 

    • In-house assessors to guide you through every step 
    • Pre-assessment audits and gap analysis 
    • Hands-on support to implement required changes 
    • Straightforward certification process with minimal disruption 

    Since we offer IT support and cyber security under one roof, our clients don’t need to juggle multiple providers. As a result, IT management is simplified, and stress is significantly reduced. We’re your one-stop-shop for compliance, protection and peace of mind. 

    Real Businesses, Real Results 

    Furthermore, we’ve recently helped several companies achieve their Cyber Essentials certifications. Consequently, they have strengthened their cyber security posture, including:

    Preferred Management 

    Preferred Management turned to The Unite Group to renew their Cyber Essentials certification. With our help, they were able to demonstrate a strong cyber posture, reassuring their own clients that their data and systems are safe. 

    MRM Solutions 

    MRM Solutions needed a straightforward, guided route to compliance. Our assessors conducted a full review, supported remediation steps and successfully issued their renewed certificate, all without interrupting daily operations. 

    Sapphire HR 

    As a growing HR firm handling sensitive employee data, Sapphire HR needed to reinforce their cyber security. Our in-house team walked them through the Cyber Essentials framework and secured their renewed certification. Boosting client confidence and reinforcing their professional standards. 

    These stories highlight the real-world impact of choosing the right certification body: a smooth process, minimal downtime, and total support. 

    Cyber Essentials vs Cyber Essentials Plus 

    Many businesses start with the basic Cyber Essentials certification, which is a self-assessment verified by our team. For higher-risk organisations or those handling sensitive data, Cyber Essentials Plus offers a more in-depth review, and as a result, it includes:

    • Internal vulnerability scans 
    • External penetration testing 
    • Hands-on verification by an assessor 

    Both levels are available through The Unite Group. Whether you’re just starting with the scheme or moving up to Cyber Essentials Plus, we provide practical advice and technical assistance. In addition, we support you at every stage to ensure a smooth experience.

    The Certification Process: What to Expect 

    1. Initial Consultation 
      We assess your readiness and determine which level of certification is best suited to your business. 
    1. Gap Analysis 
      Our team identifies any weaknesses or missing controls to address before assessment. 
    1. Remediation Support 
      If any improvements are needed, we proactively implement the necessary technical fixes to ensure your systems meet certification standards.
    1. Formal Assessment 
      We review your policies, controls, and technical setup against the Cyber Essentials framework. 
    1. Certification 
      Once approved, your certificate is issued and your business listed on the official NCSC directory. 

    Why Choose Unite? 

    When you work with The Unite Group, not only are you getting a Cyber Essentials Certification Body, but also a reliable partner. Moreover, we understand that cyber security can feel overwhelming, especially for small and medium businesses. Therefore, our approach is designed to make the process straightforward and supportive:

    • Human – No bots, no jargon. You deal with real experts. 
    • Helpful – We work with your team, not just assess them. 
    • Holistic – As IT support specialists, we look at your infrastructure as a whole. 

    Ready to Get Certified? 

    Whether your business needs Cyber Essentials certification or is considering an upgrade to Cyber Essentials Plus, The Unite Group can make the process fast, clear, and stress-free. Furthermore, we provide guidance at every step to ensure a seamless experience.

    • Trusted Cyber Essentials Certification Body 
    • Proven Track Record With UK Businesses 
    • Friendly Experts You Can Rely On 

    Start Your Journey Today 
    Protect your business. Build client trust. Open up new opportunities. 

    Explore our Cyber Essentials service, or contact us today to book a free discovery call. 

  • Why Your Business Needs a Reliable IT Support Service

    Why Your Business Needs a Reliable IT Support Service

    Unite group employee working on a computer at a desk

    Whether you’re a small business or a growing enterprise, the right IT support service can keep your operations running smoothly. In addition, it boosts productivity and protects you from costly downtime.

    At The Unite Group, we believe technology should enable your business, not hold it back. Our IT support service combines proactive maintenance, cyber security, helpdesk support and strategic guidance. Giving you peace of mind and allowing you to focus on what you do best.

    What Makes a Good IT Support Service

    A robust IT support service should go beyond just fixing problems. It should prevent them. Today’s leading IT support providers, also known as Managed Service Providers (MSPs), offer comprehensive services. For example, these services include:

    • 24/7 remote monitoring and maintenance.  
    • Helpdesk support and incident resolution through phone or email.
    • Cyber security and compliance support — firewalls, patch management, backups, and more.  
    • cloud and infrastructure management — including hosted phone systems, WiFi, and remote working support is included.
    • Scalable support plans that grow with your business, replacing unpredictable IT costs with fixed fees.  

    This proactive, all‑in‑one approach is a significant departure from the reactive “call when something breaks” model of traditional IT support.

    The Unite Group’s IT Support Service: What You Get

    At The Unite Group, our IT support service is designed to be complete, flexible and user-focused. Here’s how we deliver real value to our clients:

    1. Proactive Monitoring & MaintenanceUsing industry-standard remote monitoring tools (RMM), we monitor your systems 24/7. This proactive approach allows us to detect issues, outdated software, potential security risks, and performance bottlenecks before they disrupt your business.

    2.Need help fast? Fortunately, our helpdesk team is always ready to assist. Whether it’s a password reset, software glitch, or network fault, your ticket is promptly logged, prioritised, and resolved remotely. Additionally, users get direct access to skilled engineers, not bots, ensuring fast and effective support every time.

    3. Cyber Security and Compliance
    With increasing cyber threats and regulatory requirements, security isn’t optional. We include managed cyber defences: firewalls, patching, backup, access control and support compliance frameworks like Cyber Essentials.

    4. Cloud & Communications Management
    From cloud‑based software to hosted phone systems and public WiFi packages, we manage the tech that keeps teams connected wherever they work. It’s ideal for remote and hybrid working environments.

    5. Scalable, Predictable Pricing
    Our service plans are designed to scale with your business. Whether you’re a small team or expanding across multiple sites, you benefit from a fixed monthly cost that eliminates surprise bills and aids budget planning.

    6. Strategic IT Guidance
    We don’t just fix problems; we help shape your technology roadmap. As your business evolves, we advise on scalability, future‑proof solutions and technology investments that match your growth plans.

    The Benefits You’ll See

    Here’s how a managed IT support service from The Unite Group can positively impact your business:

    • Fewer disruptions & downtime – proactive maintenance catches problems early.
    • Lower IT costs – predictable pricing and fewer emergency fixes.
    • Improved security & compliance – regular updates, backups and adherence to recognised standards.
    • Access to specialist knowledge – multiple IT disciplines under one roof without hiring separate staff.
    • Flexibility to scale – adding users or services is simple as you grow.
    • Peace of mind – tech handled by experts, so you can focus on business growth.

    Who Benefits Most?

    Specifically, while any business can benefit from a robust IT support service, it’s particularly valuable for:

    • Small to medium-sized enterprises without in-house IT teams.
    • Businesses using hybrid or remote working models.
    • Organisations handling sensitive data and needing compliance.
    • Growing firms needing scalable IT infrastructure without unpredictable costs.

    Why Waiting Is Risky

    Managing IT internally or relying on a break/fix model can leave you exposed. As a result, delayed updates, missed security patches, or inconsistent support can lead to downtime, data breaches, regulatory issues, and loss of client trust. By contrast, a modern IT service continuously monitors, secures, and optimises your technology.

    Ready to Upgrade Your IT Support?

    Therefore, if you’re tired of patchy support, unexpected costs, or security worries, it might be time to switch to a professional IT support service.

    At The Unite Group, we’re ready to be your technology partner. Providing managed IT support tailored to your needs, with hands-on service, reliable systems and peace of mind. From setup and migration to ongoing support and strategic planning, we’ve got your tech covered.

    Explore our Managed IT Services and IT Support Service

    Contact us today to arrange a consultation and discover how a smarter, simpler IT support solution can transform your business.

  • Cyber Essentials Service: Why It’s a Must‑Have for Your Business

    Cyber Essentials Service: Why It’s a Must‑Have for Your Business

    A Unite Group employee working at a desk on a computer

    In a world where cyber threats evolve constantly, a simple security framework can make all the difference. That’s where a Cyber Essentials service comes in. A foundational certification that helps businesses defend against the most common online attacks. Provided by trusted experts like The Unite Group, a Cyber Essentials service isn’t just about ticking boxes. It’s about building genuine resilience, protecting data, and giving clients confidence.

    What Is the Cyber Essentials Scheme?

    Cyber Essentials is a UK Government‑backed, industry‑supported certification scheme that defines a set of basic cyber security controls every organisation should have. It covers five critical areas: firewalls and routers, secure configuration, access control, malware protection, and up‑to‑date software patch management. 

    By meeting these standards, businesses can significantly reduce their exposure to common cyber threats. Such as phishing, ransomware and unauthorised access protecting both internal systems and customer data.

    Why a Cyber Essentials Service Is More Than a Certificate

    Real Risk Reduction

    The core value of Cyber Essentials is practical protection. Rather than relying on complex, expensive defences, the certification ensures that essential safeguards are in place. The kind that actually block everyday cyber attacks before they happen. 

    Boost Credibility & Win Business

    In today’s market, clients and suppliers expect proof of good cyber hygiene. Being Cyber Essentials certified demonstrates that you treat data security seriously. Making your business more trustworthy and often opening doors to new contracts, including government tenders. 

    Insurance & Regulatory Benefits

    Many insurers view Cyber Essentials as a sign of reduced risk, which can lead to lower premiums or better coverage. Likewise, certification supports compliance with data protection laws and helps safeguard personal data.

    Foundation for Growth & Compliance

    Cyber Essentials is just the beginning. Once the basic controls are in place, businesses can build on them. Adding advanced security tools, formal risk processes, or moving towards higher standards like ISO‑certification. A strong foundation makes future upgrades smoother.

     

    How The Unite Group’s Cyber Essentials Service Works

    Implementing Cyber Essentials doesn’t have to be complicated or time-consuming. At The Unite Group, we offer a full-service package designed to take the stress out of cyber security:

    Initial audit & gap analysis: 

    We start by reviewing your existing systems and policies to determine what needs updating. 

    Technical updates: 

    From firewall settings and secure configurations to malware defences and patch management, we ensure all five control areas meet the required standards. 

    User access control & configuration management: 

    We set up secure access protocols, remove unnecessary privileges, and enforce strong password and access practices. 

    Certification submission & follow-up: 

    Once everything is in place, we handle the application process on your behalf — whether for standard Cyber Essentials or the more rigorous Cyber Essentials Plus, which includes external technical audits. 

    Ongoing support: 

    Cyber threats evolve, so we offer ongoing monitoring, support and renewal services ensuring you stay protected long after certification. 

    Who Benefits from a Cyber Essentials Service?

    Whether you’re a small start-up or a well-established enterprise, Cyber Essentials is designed for businesses of every size. If your organisation handles customer data, financial records, or even basic email and operations online, this certification gives you solid protection. 

    For small and medium‑sized businesses especially, a Cyber Essentials service offers “big business” security without the cost and complexity of a full-scale security department something that can make a huge difference when resources are limited. 

    Real‑World Impact

    Clients who adopt Cyber Essentials often see fewer security incidents, lower risk exposure, and greater peace of mind. For many, certification has helped them win new contracts, reassure clients about data security, and reduce cybersecurity insurance costs. These benefits add up and can even safeguard a business from potentially devastating losses. 

    At The Unite Group, we’ve supported numerous clients from small SMEs to larger enterprises through their certification journey. Many tell us that the process is simpler and more rewarding than they expected, and that the resulting protection was worth every step.

    Take the Next Step Toward Security

    If you haven’t yet considered a Cyber Essentials service, now is a great time. Cyber threats aren’t going away but with the right basics in place, you can dramatically reduce your risk.

    At The Unite Group, we’re ready to guide you through the full process, manage the technical work, and help you achieve certification with confidence. Let us take cyber security off your to-do list, so you can focus on what matters: growing your business.

    Contact us today and ask how our Cyber Essentials service can protect your organisation.