<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Foxcube IT Blog - IT advice for UK small businesses]]></title><description><![CDATA[Practical IT support advice for small businesses in Nottingham and across the UK. Managed IT, cyber security, Microsoft 365 and more.]]></description><link>https://blog.foxcube.co.uk</link><image><url>https://cdn.hashnode.com/uploads/logos/6a157685da253d50d49ab6fc/f2cee38d-d70c-4dfa-9621-ee826933feae.png</url><title>Foxcube IT Blog - IT advice for UK small businesses</title><link>https://blog.foxcube.co.uk</link></image><generator>RSS for Node</generator><lastBuildDate>Mon, 07 Sep 2026 09:46:39 GMT</lastBuildDate><atom:link href="https://blog.foxcube.co.uk/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[The phishing email that knows your manager's name: why AI has changed the game]]></title><description><![CDATA[For years, spotting a phishing email was almost a party trick. Dodgy spelling, a greeting that got your name wrong, a link that obviously went nowhere near your bank. We all learned the tells.
That er]]></description><link>https://blog.foxcube.co.uk/the-phishing-email-that-knows-your-manager-s-name-why-ai-has-changed-the-game</link><guid isPermaLink="true">https://blog.foxcube.co.uk/the-phishing-email-that-knows-your-manager-s-name-why-ai-has-changed-the-game</guid><category><![CDATA[phishing]]></category><category><![CDATA[#PhishingAttacks ]]></category><category><![CDATA[email]]></category><dc:creator><![CDATA[adamhfoxy]]></dc:creator><pubDate>Fri, 26 Jun 2026 12:29:51 GMT</pubDate><content:encoded><![CDATA[<p>For years, spotting a phishing email was almost a party trick. Dodgy spelling, a greeting that got your name wrong, a link that obviously went nowhere near your bank. We all learned the tells.</p>
<p>That era is over.</p>
<p>Attackers now use the same generative AI tools the rest of us do, and they use them to write clean, fluent, convincing emails at scale. The message that references your actual manager by name, in their actual writing style, about a real project? That's not a coincidence anymore. The UK's National Cyber Security Centre has warned that criminals are using automation and AI to run these campaigns across thousands of targets at once, and that ransomware, which very often starts with a single phishing email, remains the most dangerous threat facing UK businesses.</p>
<p>It's working. As we covered in our breakdown of the government's latest Cyber Security Breaches Survey, more than four in ten UK businesses (43%) were hit by a cyber attack or breach in the past year, and phishing is behind the large majority of successful breaches.</p>
<p><strong>The new tricks, beyond email</strong></p>
<p>It isn't just text anymore. The same tools that write a convincing email can clone a voice from a few seconds of audio, or generate a passable video likeness. "Vishing" (a phone call that sounds like your finance director asking for an urgent transfer) is no longer science fiction. The defining feature of this new wave is that it removes the giveaways we were all trained to look for.</p>
<p><strong>Why smaller businesses are squarely in the firing line</strong></p>
<p>There's a comforting myth that hackers only go after big names. The opposite is true. Automated, AI-assisted attacks don't hand-pick victims; they go wide and hit whoever's least defended. Smaller firms tend to have thinner defences, which makes them the easy win.</p>
<p>It doesn't help that the basics are often missing. Research from BT found that around two in five small businesses haven't given their staff any cyber training at all. When the email is this convincing, an untrained team doesn't stand much of a chance.</p>
<p><strong>What actually stops it</strong></p>
<p>The reassuring news is that the defences haven't changed nearly as much as the attacks have. A few layers, applied consistently, stop the overwhelming majority of this:</p>
<ul>
<li><p><strong>Multi-factor authentication everywhere.</strong> Even if someone hands over a password, MFA blocks most account takeovers cold.</p>
</li>
<li><p><strong>Email filtering that catches the obvious before it lands.</strong> Fewer suspicious messages reaching inboxes means fewer chances to slip up.</p>
</li>
<li><p><strong>A simple "verify by a second channel" habit.</strong> Any unexpected request to move money or share data gets confirmed by phone or in person, never by replying to the message. This is the single best defence against the voice and video tricks.</p>
</li>
<li><p><strong>Staff who know what to look for.</strong> Not a one-off lecture, but a steady awareness that this is normal now.</p>
</li>
<li><p><strong>Monitored devices and accounts</strong>, so that if something does get through, it's caught fast. <strong>Where we fit in</strong></p>
</li>
</ul>
<p>At Foxcube, most of this runs by default. We patch, we enforce MFA, we filter, and we monitor, quietly, in the background, so that the bulk of these attacks never reach your team in the first place. And when something genuinely needs a human eye, you've got UK engineers who'll pick up the phone.</p>
<p>The attacks have got smarter. Your defences should keep pace. If you're not confident yours have, let's have a chat. Call <strong>0115 732 3060</strong> or email <strong><a href="mailto:hello@foxcube.co.uk">hello@foxcube.co.uk</a></strong>.</p>
]]></content:encoded></item><item><title><![CDATA[Still on Windows 10? You're more exposed than you think]]></title><description><![CDATA[If any machine in your business is still running Windows 10, here's the uncomfortable truth: unless it's enrolled in Microsoft's paid Extended Security Updates programme, it hasn't had a security patc]]></description><link>https://blog.foxcube.co.uk/still-on-windows-10-you-re-more-exposed-than-you-think</link><guid isPermaLink="true">https://blog.foxcube.co.uk/still-on-windows-10-you-re-more-exposed-than-you-think</guid><category><![CDATA[business productivity]]></category><category><![CDATA[endpoint security]]></category><category><![CDATA[patching]]></category><category><![CDATA[Windows 10]]></category><category><![CDATA[end-of-life]]></category><category><![CDATA[Nottingham]]></category><dc:creator><![CDATA[adamhfoxy]]></dc:creator><pubDate>Sun, 14 Jun 2026 06:34:58 GMT</pubDate><content:encoded><![CDATA[<p>If any machine in your business is still running Windows 10, here's the uncomfortable truth: unless it's enrolled in Microsoft's paid Extended Security Updates programme, it hasn't had a security patch since <strong>14 October 2025</strong>. Every vulnerability discovered since then is sitting open.</p>
<p>That's not scaremongering. It's just how end of support works.</p>
<p><strong>What "end of support" actually means</strong></p>
<p>On 14 October 2025, Windows 10 reached end of support. Microsoft didn't switch the machines off; they still boot, still run your software. What stopped is the security updates: no more monthly patches for newly discovered flaws. And since attackers actively hunt for exactly these unpatched systems, every month that passes makes a Windows 10 machine a softer target. It's the same "path of least resistance" problem we wrote about in our breakdown of last year's cyber attack figures.</p>
<p><strong>The one important caveat: Extended Security Updates (ESU)</strong></p>
<p>There is a safety net, and it's worth knowing about. Microsoft's ESU programme lets you keep receiving critical and important security patches after end of support, for a price, and only for a while. If your Windows 10 machines are on ESU, they're still being patched and you're in a far better position. If they're not, they're exposed.</p>
<p>Be clear about what ESU is, though. It delivers critical and important security fixes only: no new features, no performance improvements, and no general technical support from Microsoft. It's a bridge, not a destination.</p>
<p><strong>The dates and the real costs</strong></p>
<p>For businesses, ESU is bought per device, per year, through volume licensing or a Microsoft partner, and the price <strong>doubles every year</strong> to push you towards upgrading:</p>
<table>
<thead>
<tr>
<th>ESU year</th>
<th>Coverage period</th>
<th>Approx. cost per device</th>
</tr>
</thead>
<tbody><tr>
<td>Year 1</td>
<td>15 Oct 2025 to 13 Oct 2026</td>
<td><del>$61 (</del>£48)</td>
</tr>
<tr>
<td>Year 2</td>
<td>14 Oct 2026 to 12 Oct 2027</td>
<td><del>$122 (</del>£96)</td>
</tr>
<tr>
<td>Year 3</td>
<td>13 Oct 2027 to Oct 2028</td>
<td><del>$244 (</del>£193)</td>
</tr>
</tbody></table>
<p>That's roughly <strong>£337 per device</strong> over the full three years, and Year 3 is the end of the road. There is no Year 4; Windows 10 security updates stop permanently in October 2028. (Exact pricing comes through your reseller or CSP and excludes VAT.)</p>
<p>Two catches worth flagging. First, it's <strong>cumulative</strong>: you can't skip Year 1 and simply buy Year 2. Enrol late and you pay for the earlier year too. Second, the <strong>consumer</strong> version of ESU (the free/low-cost home option) only runs for one year, to 13 October 2026, and isn't built for a managed business fleet.</p>
<p><strong>Why this October is the real cliff</strong></p>
<p>We're currently in Year 1. The pressure point is <strong>October 2026</strong>: consumer ESU ends entirely, and business ESU doubles to around £96 per device.</p>
<p>Put numbers on it. If you've got fifteen Windows 10 machines, the cost of standing still jumps from roughly <strong>£720 this year to about £1,445 next year</strong>, for security patches alone, on machines that are otherwise frozen in time. Across the full three years that's nearly <strong>£5,000</strong> to keep fifteen ageing PCs on life support, money that, in a lot of cases, would go a long way towards replacing or upgrading them.</p>
<p><strong>The honest answer: ESU buys time, it doesn't fix the problem</strong></p>
<p>For most businesses, the right move is to get onto Windows 11. Many existing machines will upgrade for free if they meet the hardware requirements: TPM 2.0, Secure Boot and a supported processor. Some older machines won't qualify, and for those the real cost isn't ESU, it's replacement. Either way, that decision is far better made on a planned roadmap than under pressure the week a machine gets hit.</p>
<p>There's a compliance angle too. Running an unsupported operating system can quietly undermine your security obligations; it's the sort of thing that fails a Cyber Essentials assessment and sits awkwardly against the data protection duties we wrote about ahead of the 19 June deadline. "We were still on Windows 10" is not a sentence you want to be explaining to a client, an insurer, or the Information Commission.</p>
<p><strong>What we'd do for you</strong></p>
<p>This is squarely an MSP job, and one we handle end to end. We'll audit every machine and tell you which can move straight to Windows 11, which need ESU as a short bridge, and which are genuinely due for replacement. We'll enrol the stragglers so nothing sits exposed in the meantime, and plan the migration around your business, all on one flat monthly price, no surprises.</p>
<p>If you're not sure how many Windows 10 machines you've still got, or whether they're even patched, that's exactly what our free IT assessment is for. Call <strong>0115 732 3060</strong> or email <strong><a href="mailto:hello@foxcube.co.uk">hello@foxcube.co.uk</a></strong>.</p>
]]></content:encoded></item><item><title><![CDATA[The Data Deadline Every UK Business Needs to Know About]]></title><description><![CDATA[The Data Deadline Every UK Business Needs to Know About
There's a date coming up that most small businesses haven't heard of, let alone prepared for: 19 June 2026.
Under the Data (Use and Access) Act ]]></description><link>https://blog.foxcube.co.uk/data-use-access-act-2026-small-business-guide</link><guid isPermaLink="true">https://blog.foxcube.co.uk/data-use-access-act-2026-small-business-guide</guid><category><![CDATA[Data Protection]]></category><category><![CDATA[UKLaw]]></category><category><![CDATA[Small business]]></category><category><![CDATA[#gdpr]]></category><category><![CDATA[compliance ]]></category><category><![CDATA[Nottingham]]></category><dc:creator><![CDATA[adamhfoxy]]></dc:creator><pubDate>Wed, 03 Jun 2026 09:30:00 GMT</pubDate><content:encoded><![CDATA[<h1>The Data Deadline Every UK Business Needs to Know About</h1>
<p>There's a date coming up that most small businesses haven't heard of, let alone prepared for: <strong>19 June 2026</strong>.</p>
<p>Under the Data (Use and Access) Act 2025 - the UK's updated data protection framework - all UK businesses that handle personal data must have a formal internal complaints procedure in place by this date.</p>
<p>If you've got a contact form on your website, a client database, or a mailing list of any kind, this applies to you.</p>
<p>Here's what you need to know - in plain English, without the legal jargon.</p>
<hr />
<h2>What is the Data (Use and Access) Act 2025?</h2>
<p>The Data (Use and Access) Act 2025 (usually shortened to DUAA) received Royal Assent on 19 June 2025. It's the UK Government's update to data protection law following Brexit - amending, but not replacing, UK GDPR and the Data Protection Act 2018.</p>
<p>The stated goal is to reduce red tape for businesses while keeping individual data rights protected. For most small businesses, the majority of the changes are either irrelevant or quietly beneficial less bureaucracy around legitimate interests, more flexibility on data subject access requests, and clearer guidance on automated decision-making.</p>
<p>But there are a few things that require action. The most time-sensitive is the complaints procedure requirement.</p>
<hr />
<h2>What changes on 19 June 2026?</h2>
<p>From 19 June 2026, individuals gain an express statutory right to complain directly to your organisation about how you've handled their personal data before going to the Information Commissioner's Office (ICO).</p>
<p>This means you need a formal internal process for receiving and responding to those complaints. Specifically:</p>
<ul>
<li>A way for people to submit a data protection complaint to you directly</li>
<li>A commitment to acknowledge complaints within a reasonable timeframe (30 days is the practical standard)</li>
<li>An investigation process</li>
<li>A written response explaining the outcome</li>
<li>A record of complaints received and how they were resolved</li>
</ul>
<p>The ICO has confirmed it will take a measured approach to enforcement during the transition period but compliance should be treated as an immediate priority, not something to revisit later in the year.</p>
<hr />
<h2>Do I need to publish a complaints policy?</h2>
<p>No, there's no requirement to publish your internal complaints procedure publicly. It's an internal document.</p>
<p>What you do need to do is update your <strong>privacy notice</strong> to tell people they have the right to raise a data protection complaint directly with you, and how to do it. A single email address is sufficient as a complaints route.</p>
<hr />
<h2>What else has already changed?</h2>
<p>The 19 June 2026 deadline is the most urgent item, but several other DUAA provisions came into force on 5 February 2026. The ones most relevant to small businesses:</p>
<p><strong>Cookie consent flexibility</strong>
For certain analytics tools, the strict requirement for prior consent has been relaxed slightly. However, the ICO has simultaneously increased the maximum fines for cookie violations to align with UK GDPR levels up to £17.5 million or 4% of global turnover, up from the previous £500,000 cap. The message: more flexibility, but higher stakes if you get it wrong.</p>
<p><strong>Data subject access requests (DSARs)</strong>
If someone asks to see the data you hold about them, you now only need to conduct a "reasonable and proportionate" search rather than an exhaustive one. You can also pause the 30-day clock while waiting for the individual to clarify their request. Practically useful for small businesses that receive complex DSARs.</p>
<p><strong>Legitimate interests</strong>
A new "recognised legitimate interests" basis has been introduced for specific activities like national security and crime prevention largely irrelevant for most SMEs, but it signals a broader direction of travel towards making data protection less burdensome for businesses.</p>
<hr />
<h2>What does this mean for your privacy policy?</h2>
<p>If your privacy policy was written before June 2025, it almost certainly doesn't mention the right to complain directly to you. You need to add this.</p>
<p>Your updated privacy policy should include:</p>
<ul>
<li>How people can submit a data protection complaint directly to your organisation (email address)</li>
<li>A commitment to acknowledge within 30 days</li>
<li>Their ongoing right to escalate to the ICO if they're not satisfied with your response</li>
</ul>
<p>If you're a Foxcube IT client, your managed IT support plan includes a review of your data protection documentation on request. If you're not a client and would like a second pair of eyes on your privacy policy, get in touch.</p>
<hr />
<h2>The practical checklist</h2>
<p>Here's what a small business needs to do before 19 June 2026:</p>
<p><strong>1. Write an internal complaints procedure</strong>
A short document (one or two pages) covering: how complaints are received, who's responsible, how they're acknowledged and investigated, how responses are communicated, and how complaints are recorded. Keep it simple this doesn't need to be a legal document.</p>
<p><strong>2. Update your privacy notice</strong>
Add a section explaining that individuals can complain directly to you about data protection matters, with an email address and a note that they can escalate to the ICO if unsatisfied.</p>
<p><strong>3. Make sure someone owns it</strong>
In a small business, data protection complaints are usually the responsibility of the owner or a nominated director. Make sure that's clearly defined internally even if it's just a line in the procedure document.</p>
<p><strong>4. Train your team</strong>
If you have staff, they need to know what to do if a data protection complaint comes in. This doesn't need to be a formal training session, a five-minute conversation and a copy of the procedure is sufficient for most small businesses.</p>
<hr />
<h2>The bigger picture</h2>
<p>The DUAA is broadly good news for small businesses. It doesn't add significant new obligations on top of UK GDPR in fact it reduces several. The complaints procedure requirement is the main new action item, and for most small businesses it's a one-off task that takes an afternoon.</p>
<p>The businesses that will get caught out are the ones that do nothing. The ICO has expanded powers under the new Act, and the information landscape is shifting clients, prospects and insurers are increasingly asking questions about data protection practices.</p>
<p>Getting this sorted now puts you ahead of the vast majority of small businesses, and costs nothing but a bit of time.</p>
<hr />
<h2>Need help?</h2>
<p>If you're a small business in Nottingham or across the UK and you're not sure whether your data protection practices are up to date, we're happy to take a look as part of our free IT assessment.</p>
<p><a href="https://foxcube.co.uk/#contact">Book a free IT assessment →</a></p>
<hr />
<p><em>Sources: Data (Use and Access) Act 2025; ICO guidance on DUAA complaints procedure; Mayer Brown, Farrer &amp; Co, Michelmores legal analysis; CMS Law DUAA update May 2026.</em></p>
<p><em>This article is for general information purposes only and does not constitute legal advice. For specific legal guidance on data protection compliance, consult a qualified solicitor.</em></p>
]]></content:encoded></item><item><title><![CDATA[43% of UK Businesses Were Hit by a Cyber Attack Last Year. Is Yours Next?]]></title><description><![CDATA[43% of UK Businesses Were Hit by a Cyber Attack Last Year. Is Yours Next?
The UK Government's Cyber Security Breaches Survey 2025/2026 landed last month. The headline figure — 43% of UK businesses suf]]></description><link>https://blog.foxcube.co.uk/uk-cyber-attacks-small-business-2026</link><guid isPermaLink="true">https://blog.foxcube.co.uk/uk-cyber-attacks-small-business-2026</guid><category><![CDATA[cyber security]]></category><category><![CDATA[Small business]]></category><category><![CDATA[UK]]></category><category><![CDATA[ransomware]]></category><category><![CDATA[Nottingham]]></category><dc:creator><![CDATA[adamhfoxy]]></dc:creator><pubDate>Tue, 26 May 2026 10:50:21 GMT</pubDate><content:encoded><![CDATA[<h1>43% of UK Businesses Were Hit by a Cyber Attack Last Year. Is Yours Next?</h1>
<p>The UK Government's Cyber Security Breaches Survey 2025/2026 landed last month. The headline figure — 43% of UK businesses suffered a cyber attack or breach in the past 12 months — sounds alarming. But the detail behind it is more alarming still.</p>
<p>We've broken it down in plain English, without the jargon, so you can understand what it actually means for your business.</p>
<hr />
<h2>The numbers you need to know</h2>
<p><strong>43% of UK businesses</strong> experienced a cyber breach or attack in the past year. That's roughly 612,000 businesses. For context, that's not 43% of large enterprises with dedicated security teams — that's businesses of all sizes, including yours.</p>
<p><strong>50% of small businesses</strong> (10–49 employees) reported at least one breach or attack. If your business has fewer than 50 people, you're statistically more likely than not to have been targeted.</p>
<p><strong>Phishing is still the dominant attack method</strong>, accounting for the vast majority of incidents. An employee receives an email that looks legitimate, clicks a link, enters their credentials — and that's it. Game over.</p>
<p><strong>The average cost of a cyber attack for a small UK business is now £3,398</strong>. That's the direct cost. Add downtime, lost productivity, reputational damage and the cost of fixing the problem, and the real figure is considerably higher.</p>
<p><strong>28% of UK SMEs say a single attack could put them out of business entirely.</strong></p>
<hr />
<h2>The M&amp;S, Co-op and Harrods wake-up call</h2>
<p>If you need a more vivid illustration, look no further than what happened to three of the UK's best-known retailers this spring. Marks &amp; Spencer, Co-op and Harrods all suffered significant ransomware incidents within weeks of each other. M&amp;S alone reported disruption to online orders and systems that cost them tens of millions.</p>
<p>These aren't businesses that skimped on IT. They have dedicated security teams, enterprise budgets and years of experience.</p>
<p>If it can happen to them, it can happen to a ten-person professional services firm in Nottingham.</p>
<p>The difference is that large organisations can absorb the blow. Most small businesses cannot.</p>
<hr />
<h2>Why small businesses are the target</h2>
<p>There's a common misconception that cyber criminals are only interested in large, high-value targets. The reality is the opposite.</p>
<p>Automated tools scan thousands of businesses simultaneously looking for the path of least resistance. Small businesses consistently represent that path — fewer security controls, less staff training, and often no dedicated IT support at all.</p>
<p><strong>96% of UK businesses that suffer a cyber attack are small or medium-sized.</strong> Not because attackers specifically want them — but because they're easier to breach.</p>
<p>Criminals aren't after your data specifically. They're after access, credentials, and the ability to encrypt your systems and demand a ransom. A small business is just as valuable a target for ransomware as a large one, if its backups aren't working and its owner is desperate to get their files back.</p>
<hr />
<h2>The new compliance pressure: 19 June 2026</h2>
<p>Here's a date your business needs in the diary: <strong>19 June 2026</strong>.</p>
<p>Under the Data (Use and Access) Act 2025 — the UK's updated data protection framework which received Royal Assent last year — all UK businesses must have a formal internal process for handling data protection complaints in place by this date.</p>
<p>The Act also significantly increases the maximum fines for serious data breaches under PECR (the rules governing electronic communications and marketing), bringing them in line with UK GDPR levels — up to £17.5 million or 4% of global turnover.</p>
<p>This isn't theoretical. The Information Commission (the successor to the ICO under the new Act) has expanded powers and is actively enforcing. A data breach that previously might have resulted in a warning could now result in a substantial fine.</p>
<hr />
<h2>What actually works</h2>
<p>The good news is that the vast majority of successful cyber attacks exploit basic, fixable weaknesses. The NCSC's own research suggests that <strong>97% of successful attacks could have been prevented</strong> with modern, properly configured security controls.</p>
<p>Here's what makes the biggest difference:</p>
<p><strong>Multi-factor authentication (MFA)</strong> — Requiring a second form of verification to log in blocks the majority of credential-based attacks. If someone steals your password, MFA means they still can't get in. This is the single highest-impact control you can put in place and it costs almost nothing.</p>
<p><strong>Staff awareness</strong> — Most breaches start with a human click. Regular, practical training on how to spot phishing emails dramatically reduces the risk. This doesn't need to be expensive or time-consuming — even a 30-minute session once a quarter makes a measurable difference.</p>
<p><strong>Patching and updates</strong> — Unpatched software is one of the most common attack vectors. Keeping operating systems and applications up to date closes the doors that attackers rely on. Managed IT support handles this automatically.</p>
<p><strong>Working backups</strong> — If the worst happens and your systems are encrypted by ransomware, a recent, tested backup is the difference between a bad day and a business-ending one. The key word is <em>tested</em> — backups that haven't been verified don't count.</p>
<p><strong>Endpoint protection</strong> — Basic antivirus is no longer sufficient. Modern Endpoint Detection and Response (EDR) tools monitor device behaviour in real time and can catch threats that traditional antivirus misses.</p>
<hr />
<h2>Where Cyber Essentials fits in</h2>
<p>Cyber Essentials is the UK Government-backed certification scheme that covers the five most important technical controls — secure configuration, access control, software updates, malware protection and firewalls. It's been shown to prevent around 80% of common cyber attacks.</p>
<p>It's also increasingly required by clients and public sector procurement — particularly if you're tendering for government contracts or working with regulated industries like legal, financial services or healthcare.</p>
<p>At Foxcube IT, we guide businesses through the Cyber Essentials process as part of our managed IT support — helping you understand what's required, get the controls in place, and work towards certification.</p>
<hr />
<h2>The honest reality for small businesses in Nottingham</h2>
<p>We work with small businesses across Nottingham, and the pattern we see is consistent: most businesses know they should be doing more on cyber security, but it keeps getting deprioritised because there are always more urgent things to deal with.</p>
<p>That's completely understandable. It's also exactly why 43% of businesses got hit last year.</p>
<p>The businesses that don't get hit aren't necessarily more technically sophisticated. They're the ones that have taken a handful of basic, consistent steps — MFA, patching, backups, training — and maintained them. That's it.</p>
<p>If you're not sure where your business stands, or you want an honest view of what your current setup is missing, we offer a free IT assessment. No pressure, no obligation — just a straightforward conversation about what you've got and what, if anything, needs attention.</p>
<hr />
<h2>What to do next</h2>
<ol>
<li><p><strong>Check whether MFA is enabled</strong> on your Microsoft 365 accounts, email and any cloud services your team uses. If it's not, switch it on today.</p>
</li>
<li><p><strong>Check your backups</strong> — when were they last tested? Do you actually know you could restore from them?</p>
</li>
<li><p><strong>Talk to your team</strong> about phishing. Show them what a suspicious email looks like. It takes ten minutes and it works.</p>
</li>
<li><p><strong>Get a free assessment</strong> from Foxcube IT — we'll tell you honestly where your gaps are and what they'd cost to fix.</p>
</li>
</ol>
<p><a href="https://foxcube.co.uk/#contact">Get a free IT assessment →</a></p>
<hr />
<p><em>Foxcube IT provides managed IT support for small businesses across Nottingham, Nottinghamshire and the UK. We offer flat-rate plans with no contracts, onsite visits where needed, and a team that genuinely knows your setup.</em></p>
<p><em>Sources: UK Government Cyber Security Breaches Survey 2025/2026 (DSIT &amp; Home Office); StationX Small Business Cybersecurity Statistics 2026; NCSC Small Business Guide; Data (Use and Access) Act 2025.</em></p>
]]></content:encoded></item></channel></rss>