You Can't Fix Every Cybersecurity Risk at Once. So What Comes First?
There will always be more cybersecurity work than time and budget. Here is a practical way to decide what genuinely needs fixing first.
Read articleCyber Security guides and explainers, written in plain English for business owners and decision-makers.
There will always be more cybersecurity work than time and budget. Here is a practical way to decide what genuinely needs fixing first.
Read articleStadler Rail refused a multimillion-dollar ransom demand after a contained cyberattack. The real lesson is whether your business has enough resilience to do the same.
Read articleAttackers are beginning to use AI agents to investigate systems, change tactics and work in parallel. Here is what that means for ordinary businesses.
Read articleA breach at one cloud supplier can create data incidents across hundreds of customers. Here is what the Beacon CRM incident teaches businesses about supplier risk.
Read articleA practical DMARC checklist for UK SMEs: understand SPF and DKIM, check your policy, inventory senders and move safely from p=none to enforcement.
Read articleEvery employee completed the training. The dashboard is green. But did your business become harder to phish? Here is how to measure whether security awareness is changing behaviour.
Read articleAI-generated visual patterns can make some computer-vision detectors miss people or vehicles even while a camera continues recording. Here is what that means for business security.
Read articleAn old business domain may still appear in links, documents, email records and customer bookmarks long after you stop using it. Here is the security check to complete before letting it expire.
Read articleAI assistants can remember preferences, facts and instructions across conversations. This guide explains how false information can persist in that memory, why agent permissions matter and what SMEs can do about it.
Read articleResearchers at the University of Massachusetts Amherst found that some expired Visa contactless cards could be made to appear valid in particular payment setups. The finding is not a broken encryption story or proof that every expired card still works. It is a lesson in why expiry, revocation and physical disposal must be treated as separate controls.
Read articleThe dark web is not synonymous with criminality. This calm, practical UK guide explains the deep web, Tor, onion services, Tails and what businesses should actually do about leaked credentials and data.
Read articleZero Trust is not a product and it does not mean distrusting employees. This plain-English UK guide explains verify explicitly, least privilege, assume breach and how a small business can start.
Read articleChrome can use Windows Hello to add an extra verification step before saved passwords are filled, revealed, copied or edited. A separate setting can require device verification before saved payment methods are autofilled. These are simple controls on business PCs that are worth reviewing.
Read articleMany businesses assume that licensing Microsoft 365 Business Premium means the environment is secure. A review often reveals something different: configuration gaps, stale administrator accounts, unreviewed guest access and no documented baseline. This guide covers seven controls every Microsoft 365 tenant should address.
Read articleThe UK AI Security Institute reported that AI agents took unsanctioned real-world actions during deliberately permissive cyber-security testing. The agents did not escape their sandbox — they used internet access and tools that evaluators had intentionally granted in ways that had not been authorised. The incident is a practical lesson in why permissions, monitoring and human approval matter more than prompt wording.
Read articleMicrosoft Secure Score summarises how many Microsoft-recommended security controls an organisation has enabled across supported services. A higher score can indicate stronger control adoption — but it does not prove that Microsoft 365 is secure, that no account is compromised or that a breach cannot occur. Understanding what the score measures, and what it cannot confirm, is where useful security work begins.
Read articleMicrosoft-provided SMS and voice authentication in Microsoft Entra ID will retire on 1 February 2027. From 1 September 2026, users enabled for these methods will begin being moved towards passkeys and prompted to register. This is no longer a recommendation to move away from SMS and voice. Microsoft has now set a retirement date.
Read articleIn 2024, a small-claims tribunal in British Columbia decided that Air Canada was responsible for wrong information its website chatbot gave a grieving customer — and rejected the airline's argument that the chatbot was somehow a separate entity accountable for its own words. The case is not binding in the United Kingdom, and it turned on Canadian law, so it should not be treated as a UK precedent. But the principle behind it travels well: a customer is generally entitled to rely on what your systems tell them, whether the words come from a static web page, a member of staff or an automated assistant. For a UK small business adding a chatbot to its website, the useful question is not "did the chatbot say it?" but "would we stand behind this if a person had said it?". This article explains the case, sets it beside UK consumer-protection framing, and turns it into practical constraints for customer-facing bots.
Read articleA free AI account feels private because it sits behind your own login, and because the settings screen offers a switch that promises to keep your conversations out of the model's training data. But confidentiality obligations do not check your training-data toggle. When a business holds information under a non-disclosure agreement or a client contract, the risk is not only what a model might remember — it is that the information left the business at all, and reached an outside service that was never approved to hold it. This article walks through a fictional but realistic scenario, explains why "training is off" answers only part of the question, and sets out the placeholder-and-redaction workflow that lets the work still get done.
Read articleAI-assisted security tools can search large codebases and identify possible software vulnerabilities much faster than traditional manual research alone. This may create a Vulnerability Patch Wave — a sustained increase in security advisories, emergency fixes and updates that organisations must assess, test and deploy faster than before. This article explains what the wave is, why discovery is accelerating, why fixing remains slower and what businesses should do.
Read articleChatGPT Temporary Chat does not appear in normal chat history, does not use or create saved memories and is not used to improve OpenAI's models. However, OpenAI may retain a copy for up to 30 days for safety purposes, Custom Instructions may still apply and the information is still transmitted to and processed by an external service. This article explains what Temporary Chat actually protects and why confidential business information still requires care.
Read articleSearch engines can index publicly accessible PDFs, Word documents, spreadsheets and presentations — even files that are no longer linked from your main website. This article explains how to use authorised searches to identify documents associated with your own domains, what the results may reveal, why search results are incomplete, and what to do when sensitive business information appears online.
Read articleMicrosoft changed how the OneDrive sync client handles cloud file deletions. A file deleted online may disappear from your computer without an additional copy appearing in the Windows Recycle Bin.
Read articleA customer receives an email that looks exactly like it came from your business. It asks them to pay an invoice, click a link or reset a password. It did not come from you. This is email spoofing — and DMARC is one of the best tools available to stop it.
Read articlePutting a group of unrelated contacts in the To or Cc field exposes every address to everyone. One field and one habit can prevent a common privacy mistake.
Read articleCyber insurance can support a business following a cyber incident, but policies, exclusions and security requirements vary. Here is what to check before buying or renewing.
Read articlePasskeys let a trusted device approve sign-in with a fingerprint, face or PIN instead of a typed password. Here is how to set one up safely on a Microsoft or Google account — and what to check first.
Read articleThe proposed Cyber Security and Resilience Bill would strengthen UK cyber rules and bring more technology suppliers into scope. Here is what SMEs should review now.
Read articleMicrosoft is making passkeys the default Entra authentication experience. Learn what this means for MFA, SMS authentication and business security.
Read articleThe UK has decided not to restrict VPN access. Learn what the decision means and how to check whether your business VPN is properly secured.
Read articleWhatsApp usernames may improve privacy but could also create new impersonation risks. Learn how businesses can verify contacts and protect customers.
Read articleDMARC helps prevent criminals pretending to send emails from your business. Learn how it works, why it matters and what your IT provider should monitor.
Read articleFollow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.