<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
  <title>IT Support World blog</title>
  <link>https://itsupportworld.co.uk/blog/</link>
  <atom:link href="https://itsupportworld.co.uk/blog/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Plain-English IT advice for UK businesses and home users, from the engineers at IT Support World, Richmond, London.</description>
  <language>en-gb</language>
  <lastBuildDate>Mon, 24 Aug 2026 15:38:38 GMT</lastBuildDate>
  <item>
    <title>Windows 10 is out of support — your options until October 2027, in plain English</title>
    <link>https://itsupportworld.co.uk/blog/windows-10-out-of-support-your-options.html</link>
    <guid isPermaLink="true">https://itsupportworld.co.uk/blog/windows-10-out-of-support-your-options.html</guid>
    <pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
    <category>Windows &amp; Devices</category>
    <description>Windows 10 stopped getting security fixes in October 2025, but Microsoft now offers extended updates until 12 October 2027. Here is who should take them, who should upgrade, and how to tell which your computer is.</description>
    <content:encoded><![CDATA[<p>Windows 10 reached the end of its supported life on <strong>14 October 2025</strong>. Since then, a Windows 10 computer that has not been enrolled in Microsoft&#39;s extended programme has had no security fixes at all — and that is the part that matters. &quot;Unsupported&quot; does not mean the computer stops working; it means that every newly discovered hole stays open.</p>
<p>The good news, and the reason for this post, is that the situation changed in 2026. Microsoft&#39;s consumer <strong>Extended Security Updates (ESU)</strong> programme, which originally ran for one year, now covers Windows 10 through to <strong>12 October 2027</strong>. That gives most people breathing room — provided they actually switch it on.</p>
<h2 id="first-find-out-what-you-have">First, find out what you have</h2>
<p>Press the Windows key, type <strong>winver</strong> and press Enter. A small window tells you the edition and version. If it says Windows 10, read on. If it says Windows 11, you are fine — close this and go and have a cup of tea.</p>
<p>Then, still on Windows 10, open <strong>Settings → Update &amp; Security → Windows Update</strong>. If you see a line offering to <strong>&quot;Enroll now&quot;</strong> in extended security updates, your computer is eligible and you have not done it yet.</p>
<h2 id="the-three-routes">The three routes</h2>
<h3 id="route-1-upgrade-to-windows-11-free-if-the-computer-qualifies">Route 1 — Upgrade to Windows 11 (free, if the computer qualifies)</h3>
<p>Windows 11 is a free upgrade for any Windows 10 computer that meets the hardware requirements. The requirement people trip over is a security chip called <strong>TPM 2.0</strong> and a reasonably recent processor; many machines from 2018 onwards qualify, many from before do not. Microsoft&#39;s own <strong>PC Health Check</strong> app (a free download) gives a yes or no.</p>
<p>If it says yes, this is the right answer for almost everyone: Windows 11 is supported for years to come and the upgrade keeps your files and programs. Take a backup first (our <a href="/blog/backup-3-2-1-rule-home.html">3-2-1 backup guide</a> explains how), then let Windows Update do it. Allow an hour and do not start it at 5 pm on a Friday.</p>
<h3 id="route-2-enrol-in-extended-security-updates-windows-10-stays-patched-until-october-2027">Route 2 — Enrol in Extended Security Updates (Windows 10 stays, patched until October 2027)</h3>
<p>If the computer cannot run Windows 11, or you simply are not ready, enrol in ESU. In the UK there are three ways to do it and all three give the same protection:</p>
<ul>
<li><strong>Free</strong>, if you sign in with a Microsoft account and allow Windows to back up your settings to that account.</li>
<li><strong>Free</strong>, by redeeming 1,000 Microsoft Rewards points.</li>
<li>A <strong>one-off payment</strong> (around £25 in the UK; Microsoft quotes 30 US dollars) — the route to take if you prefer to keep using a local account.</li>
</ul>
<p>One enrolment covers up to ten computers on the same Microsoft account, which is handy for a household. Enrolment is done from the Windows Update page mentioned above, and you can join at any time until the programme ends.</p>
<p>Businesses use a separate, paid ESU licence per device, and unlike the consumer version the price rises each year — which is Microsoft&#39;s polite way of saying &quot;please move&quot;.</p>
<h3 id="route-3-replace-the-computer">Route 3 — Replace the computer</h3>
<p>If the machine is more than about seven years old, struggling anyway, and cannot take Windows 11, the money is usually better spent on a replacement than on nursing it along. A modern laptop with 16 GB of memory and a solid-state drive will feel like a different world, and it will be supported until well into the 2030s. We can <a href="/hardware-supply.html">supply and set up</a> machines for both homes and businesses, and move everything across.</p>
<h2 id="what-we-recommend-by-situation">What we recommend, by situation</h2>
<div class="scroll-x"><table><thead><tr><th>Situation</th><th>Our advice</th></tr></thead><tbody><tr><td>Computer qualifies for Windows 11</td><td>Upgrade now; it is free and it ends the problem</td></tr><tr><td>Does not qualify, works well, used for email/web/documents</td><td>Enrol in ESU today, plan a replacement before October 2027</td></tr><tr><td>Does not qualify, slow, over 7 years old</td><td>Replace; do not spend money on the old one</td></tr><tr><td>Business with several Windows 10 PCs</td><td>Audit them all; upgrade what qualifies, licence ESU only as a bridge, budget replacements over the next 12 months</td></tr><tr><td>Runs specialist software that only works on Windows 10</td><td>Enrol in ESU, isolate the machine from email and web use, and talk to the software vendor about a path forward</td></tr></tbody></table></div>
<h2 id="two-things-people-get-wrong">Two things people get wrong</h2>
<p><strong>&quot;I have antivirus, so I am fine.&quot;</strong> Antivirus catches known bad files. It cannot patch a flaw in Windows itself, which is what the security updates do. Both are needed; neither replaces the other.</p>
<p><strong>&quot;I never click on anything dodgy.&quot;</strong> Unfortunately the most common route in is a website you would consider perfectly normal, or a document that arrives from someone whose own email was compromised. The whole point of updates is that they protect you from things you never see.</p>
<h2 id="for-businesses-this-is-now-a-compliance-question">For businesses: this is now a compliance question</h2>
<p>The 2026 update to Cyber Essentials (the UK government-backed baseline standard) requires that <strong>critical and high-risk updates are installed within 14 days</strong> of release, and that all software in scope is supported by its vendor. An unenrolled Windows 10 machine fails that test, which in turn can affect insurance and tenders. Our post on <a href="/blog/cyber-essentials-april-2026-what-changed.html">what changed in Cyber Essentials this year</a> covers the detail.</p>
<h2 id="the-short-version">The short version</h2>
<p>Check <strong>winver</strong>. If it is Windows 10, either upgrade to Windows 11 today or switch on extended updates today — both are free for most people — and put &quot;replace before October 2027&quot; in the diary. If you would rather someone did it for you, that is a thirty-minute job for us, remotely or on site.</p>
]]></content:encoded>
  </item>
  <item>
    <title>Phishing is still the number one threat to UK businesses — and it is beatable</title>
    <link>https://itsupportworld.co.uk/blog/phishing-still-number-one-threat-uk-businesses.html</link>
    <guid isPermaLink="true">https://itsupportworld.co.uk/blog/phishing-still-number-one-threat-uk-businesses.html</guid>
    <pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
    <category>Cyber Security</category>
    <description>The government's 2026 breaches survey found 43% of UK businesses were attacked in the past year, with phishing behind most of the damage. Here is what actually works against it, in order of effort.</description>
    <content:encoded><![CDATA[<p>Every year the Department for Science, Innovation and Technology publishes the Cyber Security Breaches Survey, and every year the headline is roughly the same: the attacks that hurt small and medium businesses are not clever. They are emails.</p>
<p>The 2025/26 edition, published on 30 April 2026, found that <strong>43% of UK businesses</strong> identified a cyber attack or breach in the previous twelve months — around 612,000 companies. Among small businesses (10–49 staff) the figure was 46%; among medium businesses (50–249 staff) it was 65%. <strong>Phishing</strong> was by far the most common attack, reported by 38% of all businesses, and it accounted for <strong>69% of the most disruptive breaches</strong>. Ransomware, the thing that makes the news, was reported by just 1%.</p>
<p>So if you run a business of 2 to 500 people, the threat you are most likely to face is a person being persuaded to click, type a password, approve a login, or pay an invoice. That is good news, because it is a problem you can do something about without a large budget.</p>
<h2 id="what-phishing-looks-like-in-2026">What phishing looks like in 2026</h2>
<p>The badly spelled email from a foreign prince is long gone. What lands in inboxes now is:</p>
<ul>
<li><strong>A login page that looks exactly like Microsoft 365 or Google Workspace.</strong> Often reached from a &quot;shared document&quot; or &quot;voicemail&quot; link. The page is a proxy: whatever you type, including the multi-factor code, goes straight to the attacker.</li>
<li><strong>Invoice redirection.</strong> The attacker has quietly been reading a real mailbox — yours or a supplier&#39;s — for weeks. When a genuine invoice is due, a follow-up email arrives with &quot;updated bank details&quot;. Nothing about it looks wrong because everything except the sort code is real.</li>
<li><strong>MFA fatigue.</strong> The attacker has the password and repeatedly triggers the approval prompt on someone&#39;s phone at 11 pm until they tap &quot;Approve&quot; to make it stop.</li>
<li><strong>The chief executive on the phone.</strong> Text messages or WhatsApp from &quot;the boss&quot; asking for gift cards, a quick transfer, or a change of payroll details. Increasingly, a convincing voice call.</li>
<li><strong>QR codes in emails and on posters</strong> that take the phone — which usually sits outside the company&#39;s security tools — to the fake login page.</li>
</ul>
<p>The common thread: the attack does not break technology, it borrows trust.</p>
<h2 id="what-works-in-order-of-effort">What works, in order of effort</h2>
<h3 id="s-1-multi-factor-authentication-on-everything-and-the-right-kind">1. Multi-factor authentication on everything — and the right kind</h3>
<p>If you do one thing, do this. A password alone is no longer a lock. But not all second factors are equal:</p>
<ul>
<li><strong>Text-message codes</strong> are better than nothing but can be intercepted or phished.</li>
<li><strong>App-based codes and push approvals</strong> are good, especially with &quot;number matching&quot; turned on, which defeats the MFA-fatigue trick.</li>
<li><strong>Passkeys and security keys</strong> (FIDO2) are the gold standard: they are tied to the real website, so a fake login page simply cannot use them. Microsoft 365 and Google Workspace both support them now, and the 2026 Cyber Essentials guidance points firmly in this direction.</li>
</ul>
<p>Since April 2026, Cyber Essentials requires MFA on <strong>all</strong> cloud services where it is available. If you want the certificate, this is no longer optional.</p>
<h3 id="s-2-make-the-fake-pages-harder-to-reach">2. Make the fake pages harder to reach</h3>
<p>Most modern email services can be tuned far beyond their defaults. Turning on the built-in protections — link scanning, attachment sandboxing, impersonation detection for your own senior names and your key suppliers — costs nothing extra in most Microsoft 365 Business Premium and Google Workspace tiers. It is the single most under-used setting we see.</p>
<p>Add <strong>SPF, DKIM and DMARC</strong> records to your domain. These stop criminals sending email that appears to come from <em>your</em> address, protecting your customers and suppliers and, in the process, your reputation. It is a DNS change, not a project.</p>
<h3 id="s-3-a-payment-rule-that-cannot-be-phished">3. A payment rule that cannot be phished</h3>
<p>Technology does not stop invoice fraud; a process does. Adopt one rule and write it down: <strong>any change to bank details is confirmed by phone, using a number you already had, before a penny moves.</strong> Not the number on the email. Not a reply to the email. Every finance team we have seen lose money to invoice redirection had no such rule; every one that has the rule has caught an attempt.</p>
<h3 id="s-4-training-that-is-short-regular-and-blame-free">4. Training that is short, regular and blame-free</h3>
<p>An annual hour of slides does not change behaviour. What does is a few minutes every month or two — a real example that arrived that week, what gave it away, what to do. Simulated phishing emails can help <em>if</em> they are used to teach rather than to catch people out. Someone who is embarrassed for clicking will not report the next one; someone who is thanked for reporting will.</p>
<p>Make reporting effortless: a &quot;Report&quot; button in the email client, or simply forward to a known address. Speed matters. The attacker&#39;s window closes the moment IT knows.</p>
<h3 id="s-5-limit-the-blast-radius">5. Limit the blast radius</h3>
<p>Assume, one day, someone will click. Then ask what the attacker gets:</p>
<ul>
<li>Does that person have administrator rights they do not need? Remove them.</li>
<li>Is there a shared mailbox with a password everyone knows? Replace it with proper delegated access.</li>
<li>Are old accounts for people who left still active? Disable them.</li>
<li>Is there a backup that a compromised account cannot delete? There must be — see our <a href="/blog/backup-3-2-1-rule-home.html">3-2-1 backup post</a> for the principle; the business version is the same idea with more zeros.</li>
</ul>
<h3 id="s-6-know-what-you-would-do">6. Know what you would do</h3>
<p>A one-page plan — who to call, how to reset every affected password, how to tell customers, whether you have cyber insurance and what its conditions are — turns a bad afternoon into a manageable one. Only 25% of businesses in the survey had a formal incident response plan (21% of micro businesses), which means most are working it out live, on the day.</p>
<h2 id="what-this-costs">What this costs</h2>
<p>Less than people expect. Steps 1, 2, 3 and 5 are mostly configuration of things already paid for, plus an engineer&#39;s time. Step 4 is a habit. Step 6 is a document. The survey found that most incidents cost businesses little or nothing in direct terms — which sounds reassuring until you are the exception with a redirected invoice, a locked mailbox and a weekend nobody got back. Set against that, it is a very small number.</p>
<p>If you would like us to look at your Microsoft 365 or Google Workspace tenancy and tell you which of these are already on, which are off, and how long the gap would take to close, that is a fixed-price piece of work and we will put the findings in writing. Start with our <a href="/business.html">cyber security</a> overview or just <a href="/contact.html">get in touch</a>.</p>
]]></content:encoded>
  </item>
  <item>
    <title>The landline switch-off is 31 January 2027 — the checklist every small business needs now</title>
    <link>https://itsupportworld.co.uk/blog/landline-switch-off-2027-business-checklist.html</link>
    <guid isPermaLink="true">https://itsupportworld.co.uk/blog/landline-switch-off-2027-business-checklist.html</guid>
    <pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
    <category>Phones &amp; VoIP</category>
    <description>Openreach turns off the old analogue phone network on 31 January 2027. Here is what stops working, what it will cost you to wait, and a plain checklist to get your business across in good time.</description>
    <content:encoded><![CDATA[<p>If your business still has a traditional phone line, a fax, a card terminal plugged into a phone socket, or an alarm that &quot;dials out&quot;, this affects you. The analogue public switched telephone network (PSTN) — the copper phone network the UK has used for more than a century — is being switched off on <strong>31 January 2027</strong>. That date was pushed back once already (from December 2025) and Openreach has been clear there will not be another delay.</p>
<p>This is not a scare story and it is not a sales pitch for a shiny new system. It is a fixed engineering deadline, and the sooner you deal with it the cheaper and calmer it is.</p>
<h2 id="what-is-actually-being-switched-off">What is actually being switched off</h2>
<p>Two things are going:</p>
<ul>
<li><strong>PSTN</strong> — the analogue voice network your phone number has historically lived on.</li>
<li><strong>ISDN</strong> — the digital lines (ISDN2 and ISDN30) that many offices used for their phone systems.</li>
</ul>
<p>Everything that used to ride on those lines moves to an internet-based (all-IP) service instead. Your broadband will still work, but the voice part of the line disappears. Openreach stopped selling new analogue lines back in 2023 (the &quot;stop-sell&quot;), so anything you have now is legacy kit living on borrowed time.</p>
<h2 id="why-waiting-costs-money">Why waiting costs money</h2>
<p>In February 2026 Openreach reported that around <strong>2.8 million lines</strong> still had to migrate, more than <strong>500,000</strong> of them serving business premises. To push the stragglers along, the wholesale rental for the old products is being increased in three steps during 2026 — in <strong>April</strong>, <strong>July</strong> and a final rise on <strong>1 October 2026</strong>. Your provider passes those costs on. In other words, a line you keep until the last minute costs noticeably more every quarter, and then simply stops.</p>
<p>There is a second, quieter cost: engineer availability. Everybody who has not moved will be trying to book installations in the same few weeks. Book now and you pick the date; book in January and you take what is left.</p>
<h2 id="what-stops-working-on-the-day">What stops working on the day</h2>
<p>The obvious one is the desk phone plugged straight into the wall socket. The less obvious ones are the things nobody thinks about until they are silent:</p>
<div class="scroll-x"><table><thead><tr><th>Equipment</th><th>Typical problem</th><th>What to do</th></tr></thead><tbody><tr><td>Intruder or fire alarm with a dial-out panel</td><td>Stops reporting to the monitoring centre</td><td>Ask your alarm company for an IP or 4G communicator</td></tr><tr><td>Card payment terminal (PDQ) on a phone socket</td><td>Cannot authorise payments</td><td>Move to a Wi-Fi, Ethernet or 4G terminal</td></tr><tr><td>Fax machine</td><td>No dial tone</td><td>Switch to email-to-fax, or retire it</td></tr><tr><td>Lift emergency phone</td><td>Trapped-passenger line goes dead — a safety issue</td><td>Lift maintainer must fit a digital or GSM unit</td></tr><tr><td>Door entry / gate intercom</td><td>Cannot call out</td><td>Replace with an IP or SIM-based intercom</td></tr><tr><td>Franking machine, older CCTV DVRs, telecare pendants</td><td>Silent failures</td><td>Check each one with the supplier</td></tr><tr><td>Analogue phone system (PBX) on ISDN</td><td>Whole system loses its lines</td><td>Move to a hosted VoIP system, or add a SIP gateway</td></tr></tbody></table></div>
<p>The trap is that most of these will fail <strong>silently</strong>. Nothing beeps, nothing flashes; they just stop reporting. That is why the first job on the checklist is an inventory, not a purchase.</p>
<h2 id="the-checklist">The checklist</h2>
<ol>
<li><strong>List every socket and every device.</strong> Walk the building. Note everything plugged into a phone socket, and every device that &quot;phones home&quot; — alarms, lifts, terminals, intercoms, meters. Photograph labels.</li>
<li><strong>Find out what you actually pay for.</strong> Your phone bill will list the lines (they may be called WLR, PSTN, analogue, ISDN2e or ISDN30). Many businesses discover lines they forgot existed and have been paying for since a previous tenant.</li>
<li><strong>Decide where the voice service goes.</strong> For almost every business of 2–500 people the answer is a hosted VoIP system: your numbers move to the cloud, calls run over your broadband, and the handsets (or an app on your mobile) connect over the network. There is no box in the cupboard to maintain.</li>
<li><strong>Check the broadband can carry it.</strong> A good VoIP call needs roughly 100 kbit/s in each direction with low jitter. Almost any fibre connection is fine; a congested or ageing ADSL line may not be. We test this before we quote, never after.</li>
<li><strong>Keep your numbers.</strong> Numbers are ported, not lost. Do not cancel the old line yourself — cancel it and the number can go with it. The new provider ports first; the old service is ceased afterwards.</li>
<li><strong>Sort the special devices.</strong> Alarm, lift and payment kit is handled by the company that maintains it. Give them the date and ask in writing what they will fit. Get the answer before you book the voice migration so both happen in the right order.</li>
<li><strong>Plan for power cuts.</strong> An old analogue phone kept working when the electricity failed. VoIP does not, unless the router and phone have battery backup. Ofcom requires providers to offer a solution for customers who rely on the line for emergency calls; for a business a small UPS on the router is the usual answer.</li>
<li><strong>Train the team for ten minutes.</strong> New handsets and apps behave slightly differently — transfers, voicemail, out-of-hours rules. Ten minutes on the day saves a week of grumbling.</li>
</ol>
<h2 id="what-a-well-run-migration-looks-like">What a well-run migration looks like</h2>
<p>From the customer&#39;s side it is dull, which is the point. Numbers are ported on a chosen day (usually mid-morning, mid-week, so any issue is found while support desks are fully staffed). Handsets have been on desks and tested for a few days beforehand. The old line is ceased a week or two later, once everyone is sure nothing else was hanging off it. The alarm and payment terminal were switched earlier, independently, so nothing depends on everything happening at once.</p>
<p>If a supplier proposes doing all of it on the same afternoon, ask why.</p>
<h2 id="home-users-are-affected-too">Home users are affected too</h2>
<p>The same switch-off applies to home phones. If you or an older relative relies on a landline — especially with a telecare pendant or a phone-line alarm — the provider should be moving you to a digital voice service and must take extra care with vulnerable customers. We wrote about that separately for <a href="/home-users.html">home users</a>; the short version is that the handset usually plugs into the back of the router instead of the wall.</p>
<h2 id="the-honest-summary">The honest summary</h2>
<p>You do not need the most expensive system, and you do not need it today. You do need to know what is on your lines, and you need a date in the diary well before January. The businesses that find the switch-off painful are the ones who discover their alarm or card machine was on an analogue line the morning after it stopped.</p>
<p>If you would like an engineer to do the inventory with you and tell you plainly what needs to change — and what does not — that is exactly the kind of conversation we are set up for. See our <a href="/voip.html">VoIP and landline switch-over</a> page for how we approach it.</p>
]]></content:encoded>
  </item>
  <item>
    <title>Cyber Essentials changed in April 2026 — MFA everywhere, 14-day patching and what it means for your certificate</title>
    <link>https://itsupportworld.co.uk/blog/cyber-essentials-april-2026-what-changed.html</link>
    <guid isPermaLink="true">https://itsupportworld.co.uk/blog/cyber-essentials-april-2026-what-changed.html</guid>
    <pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
    <category>Cyber Security</category>
    <description>The &quot;Danzell&quot; question set took effect on 26 April 2026. Two new automatic-fail questions and mandatory MFA on every cloud service catch out businesses that passed comfortably last year. A plain-English guide to the changes.</description>
    <content:encoded><![CDATA[<p>Cyber Essentials is the UK government-backed scheme that certifies a business has the basic controls in place to stop the common, opportunistic attacks. It is run by the National Cyber Security Centre (NCSC) with IASME as the delivery partner, and increasingly it is a condition of public-sector contracts, supply-chain questionnaires and cyber insurance.</p>
<p>Each year the question set is updated and given a name. The current one, <strong>Danzell</strong>, was published on 13 February 2026 and applies to every assessment account created on or after <strong>26 April 2026</strong>. Businesses that already had an assessment account open on that date were given six months to move across, so from late October 2026 everyone is on the new rules.</p>
<p>Most of the changes are tightening rather than new territory. Two of them, though, are now <strong>automatic fails</strong> — you answer &quot;no&quot; and the assessment stops — and they are the ones catching people out.</p>
<h2 id="change-1-mfa-is-mandatory-on-all-cloud-services">Change 1: MFA is mandatory on all cloud services</h2>
<p>Previously, multi-factor authentication was required for administrator accounts and strongly expected elsewhere. Under Danzell it is required for <strong>every user on every cloud service where the service offers it</strong> — Microsoft 365, Google Workspace, Xero, Sage, your CRM, your VoIP portal, your backup console, the lot. Answer &quot;no&quot; for any of them and it is a fail.</p>
<p>Two practical points:</p>
<ul>
<li>&quot;Where it is available&quot; is not an escape hatch. Almost every business cloud service offers MFA now; the assessor will expect you to have turned it on, not to argue that it is optional.</li>
<li>The guidance now explicitly encourages <strong>passwordless methods such as passkeys</strong> as the preferred approach. They are also the only kind of second factor that a fake login page cannot capture, which we covered in our post on <a href="/blog/phishing-still-number-one-threat-uk-businesses.html">phishing</a>.</li>
</ul>
<h2 id="change-2-critical-and-high-risk-updates-within-14-days-twice">Change 2: critical and high-risk updates within 14 days — twice</h2>
<p>There are now two separate auto-fail questions on patching:</p>
<ol>
<li>Are <strong>operating system and firmware</strong> updates rated critical or high-risk installed within 14 days of release?</li>
<li>Are <strong>application</strong> updates rated critical or high-risk installed within 14 days of release?</li>
</ol>
<p>The 14-day rule itself is not new. What is new is that it is asked as a hard yes/no, twice, and that firmware — routers, firewalls, switches, wireless access points — is called out explicitly. The box in the comms cupboard that nobody has logged into since 2021 is now a certification problem, not just a security one.</p>
<p>It follows that every device and piece of software in scope must still be <strong>supported by its vendor</strong>. A Windows 10 computer that has not been enrolled for extended updates is unsupported and fails the test outright; our <a href="/blog/windows-10-out-of-support-your-options.html">Windows 10 post</a> explains the fix.</p>
<h2 id="change-3-scope-has-to-be-honest-and-complete">Change 3: scope has to be honest and complete</h2>
<p>Danzell removes the old character limit on the scope description and requires you to state clearly what is <strong>out of scope</strong> and why, and which legal entity is being certified. Cloud services are now formally defined and cannot be excluded — if your staff log into it, it is in.</p>
<p>Larger organisations can have <strong>individual certificates for each legal entity</strong> inside a group scope, which tidies up a long-standing awkwardness for groups of companies.</p>
<h2 id="change-4-no-quiet-tidying-up-before-the-plus-audit">Change 4: no quiet tidying-up before the Plus audit</h2>
<p>For Cyber Essentials <strong>Plus</strong> (the audited version):</p>
<ul>
<li>Your self-assessment answers are <strong>locked before testing begins</strong>, so they cannot be adjusted once the auditor starts finding things.</li>
<li>Retests draw a <strong>new sample of devices</strong>, so fixing only the machines the auditor looked at last time does not work.</li>
<li>&quot;Point in time&quot; now formally means the date the certificate is issued.</li>
</ul>
<h2 id="what-has-not-changed">What has not changed</h2>
<p>The five control areas are the same: firewalls, secure configuration, user access control, malware protection, and security update management. The scheme still costs a few hundred pounds for the basic certificate (the exact fee depends on your size and the certification body) and a Plus audit on top of that. Certificates still last twelve months.</p>
<h2 id="a-short-readiness-checklist">A short readiness checklist</h2>
<ul>
<li>MFA on, for everyone, on every cloud service — preferably passkeys or app-based with number matching.</li>
<li>A list of every device, including firmware on network kit, with an owner and an update process that meets 14 days.</li>
<li>No unsupported software or operating systems in scope (or a documented, segregated exception that the assessor will accept).</li>
<li>Local administrator rights removed from day-to-day accounts.</li>
<li>A written scope: what is in, what is out, why, and which company it is.</li>
<li>Malware protection and automatic updates verified on every laptop, including the ones that live at home.</li>
</ul>
<h2 id="where-businesses-actually-fail">Where businesses actually fail</h2>
<p>In our experience it is rarely the firewall. It is the three staff who &quot;prefer not to have the app on their personal phone&quot;, the accountancy package whose MFA was never switched on because it lives on one person&#39;s desktop, the switch that has never had a firmware update, and the two laptops from the old office that still work and are still on Windows 10. Each is a five-minute conversation now and an automatic fail in the assessment.</p>
<p>If you would like a pre-assessment — we go through the Danzell questions with you, fix the obvious gaps and tell you honestly whether you would pass — that is a fixed-price piece of work, and it is far cheaper than a failed assessment and a resubmission. See our <a href="/it-support.html">managed IT support</a> page or <a href="/contact.html">get in touch</a>.</p>
]]></content:encoded>
  </item>
  <item>
    <title>The 3-2-1 backup rule — and why &quot;it's in the cloud&quot; is not a backup</title>
    <link>https://itsupportworld.co.uk/blog/backup-3-2-1-rule-home.html</link>
    <guid isPermaLink="true">https://itsupportworld.co.uk/blog/backup-3-2-1-rule-home.html</guid>
    <pubDate>Mon, 24 Aug 2026 09:00:00 GMT</pubDate>
    <category>Backups &amp; Data</category>
    <description>Photos, documents and twenty years of email can vanish in an afternoon — a dropped laptop, a wrong click, a ransom note. The 3-2-1 rule is the simplest way to make sure they come back. Here it is in plain English, with what to actually buy.</description>
    <content:encoded><![CDATA[<p>We do a lot of data recovery. Some of it is heroic — a drive that clicks, a phone that went through the wash. Most of it is heartbreakingly ordinary: the laptop was stolen, the only copy of the wedding photos was on it, and nobody had ever thought about a backup because nothing had gone wrong before.</p>
<p>The rule below takes ten minutes to set up and costs less than a takeaway a month. It is the same rule we use for businesses; the numbers are just smaller.</p>
<h2 id="the-rule">The rule</h2>
<p>Keep <strong>3</strong> copies of anything you care about, on <strong>2</strong> different kinds of storage, with <strong>1</strong> copy somewhere else.</p>
<ul>
<li><strong>Three copies</strong>: the original plus two backups. One backup can fail or be out of date at the exact moment you need it — it happens more than you would think.</li>
<li><strong>Two kinds of storage</strong>: for instance the computer&#39;s own drive plus an external drive, or the computer plus a cloud service. Two copies on the same physical drive are one copy with extra steps.</li>
<li><strong>One off-site</strong>: if the house floods, or a burglar takes the laptop <em>and</em> the drive sitting next to it, the copy that survives is the one that was somewhere else — usually a cloud service, sometimes a drive at a relative&#39;s house.</li>
</ul>
<h2 id="why-sync-is-not-backup">Why sync is not backup</h2>
<p>This is the misunderstanding that catches most people. OneDrive, Google Drive, iCloud Drive and Dropbox are <strong>sync</strong> services: they make the same set of files appear on all your devices. That is genuinely useful, and the files are stored on the provider&#39;s servers, so a stolen laptop does not lose them. But sync copies mistakes just as faithfully as it copies photos:</p>
<ul>
<li>Delete a folder by accident and it is deleted everywhere within seconds.</li>
<li>Ransomware scrambles your files, and the scrambled versions sync up and replace the good ones.</li>
<li>A child &quot;tidies&quot; the photo library on the tablet; the tidy-up syncs to the computer.</li>
</ul>
<p>Most of these services keep a recycle bin or version history for a limited time (typically 30 days), which will save you if you notice quickly. They will not save you if you notice in three months, and they are not designed to restore a whole computer.</p>
<p>A <strong>backup</strong>, by contrast, is a separate copy that the computer writes <em>to</em> and does not automatically change when you change the original. That is the copy that gives you a way back.</p>
<h2 id="what-we-actually-recommend-for-a-home">What we actually recommend for a home</h2>
<h3 id="copy-1-the-computer-itself">Copy 1 — the computer itself</h3>
<p>Keep the things you care about in the normal places (Documents, Pictures, Desktop), not scattered across old drives and downloads folders. You cannot back up what you cannot find.</p>
<h3 id="copy-2-an-external-drive-with-the-built-in-backup-tool">Copy 2 — an external drive with the built-in backup tool</h3>
<p>Both Windows and macOS include a perfectly good backup program, and both are switched off until you plug in a drive and say yes.</p>
<ul>
<li><strong>Windows</strong>: plug in an external drive, open <strong>Settings → Update &amp; Security → Backup</strong> (Windows 10) or search for <strong>File History</strong> (Windows 11), and turn it on. It keeps versions of your files as they change, so you can go back to last Tuesday&#39;s copy of a document.</li>
<li><strong>Mac</strong>: plug in the drive, and macOS will offer <strong>Time Machine</strong>. Say yes. It backs up everything, hourly, and restoring a whole Mac from it is a one-screen job.</li>
</ul>
<p>A 2 TB external drive costs roughly the price of a family cinema trip and is enough for most households. Leave it plugged in if it is a desktop; if it is a laptop, plug it in once a week and let it run while you make dinner. Put a reminder in your phone — this is the step people forget.</p>
<h3 id="copy-3-off-site-automatic">Copy 3 — off-site, automatic</h3>
<p>For the off-site copy, use a <strong>cloud backup</strong> service (not a sync service — the distinction above) or, for the more technical, a second drive that lives at another address and is swapped monthly. Cloud backup services quietly copy your files overnight and keep old versions for months or years. The subscription is typically a few pounds a month for unlimited storage from one computer; we can recommend one when we set it up, and we have no commission arrangement with any of them.</p>
<p>If you already pay for Microsoft 365 or Google One, the extra storage that comes with it <em>can</em> serve as the off-site copy for the files that live in OneDrive or Drive — as long as you understand you are relying on that 30-day safety net and keep Copy 2 for anything older.</p>
<h3 id="phones">Phones</h3>
<p>Phone photos are the single most-lost category. Turn on <strong>iCloud Photos</strong> (iPhone) or <strong>Google Photos backup</strong> (Android) and check it is actually running — open the app and look for the &quot;backed up&quot; tick. Then make sure those photos also reach the computer, so they are included in Copies 2 and 3. A phone backup alone is one copy, on one company&#39;s servers, tied to one account you could be locked out of.</p>
<h2 id="test-it-once">Test it, once</h2>
<p>A backup nobody has restored from is a hope, not a plan. Once it has been running for a week, pick a file, delete it (or rename it), and get it back from the backup. It takes two minutes and it is the difference between knowing and assuming. Do it again every few months, and after any big change — new computer, new drive, new service.</p>
<h2 id="when-you-need-us">When you need us</h2>
<p>If a drive has already failed, <strong>stop using it</strong>. Every extra minute a failing drive spins reduces the chance of recovery, and &quot;let me just try one more thing&quot; is how recoverable drives become unrecoverable. Our <a href="/data-recovery.html">data recovery</a> service starts with an honest assessment — what is recoverable and what it would cost — before you commit to anything.</p>
<p>And if you would rather someone came and set all of the above up — drive, cloud, phones, the restore test, and a one-page sheet explaining what happens where — that is a single visit, and we will label the drive so you never have to remember which one it is.</p>
]]></content:encoded>
  </item>
</channel>
</rss>
