We take over other people’s IT for a living, so we see what gets left behind. These are the questions that come up most, answered properly, with the numbers where we have them.
It is payment diversion fraud, timed for late on a Friday when a property completion is due and everyone wants to be out the door. The attacker has usually been reading the email thread for weeks. The control that stops it is a verbal check against a phone number you already held, never one taken from the email.
Ours is £42, £55 or £72 per user per month excluding VAT, depending on how much security sits in it. Almost nobody in this industry publishes a figure, so any industry average you are quoted is a guess. Here is ours, and what moves it.
Revoke the active sessions, then change the password, then check the mailbox rules. That order matters: changing a password on its own does not sign somebody out of a session they already hold, and the mailbox rule is what has been hiding this from you.
Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.
Probably not, not without some work first. Assessment accounts created on or after 27 April 2026 are marked against Requirements for IT Infrastructure v3.3, and multi-factor authentication is now mandatory on every cloud service that offers it. Miss it on one service and you fail the whole assessment.
Ring the number below and you get Tom, the owner. If it's a five minute answer you'll get it on the phone, and there's no expectation of anything after that.