<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Saturday Cloud</title>
    <link>https://www.saturday-cloud.com/blog/</link>
    <atom:link href="https://www.saturday-cloud.com/feed.xml" rel="self" type="application/rss+xml" />
    <description>IT and cyber security advice for businesses of 5 to 60 people across South Wales, Cardiff and the South West. Written by Thomas Briscombe at Saturday Cloud.</description>
    <language>en-GB</language>
    <lastBuildDate>Fri, 28 Aug 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>What does IT support cost per user per month?</title>
      <link>https://www.saturday-cloud.com/blog/what-does-it-support-cost/</link>
      <guid isPermaLink="true">https://www.saturday-cloud.com/blog/what-does-it-support-cost/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Briscombe</dc:creator>
      <description>Ours is £42, £55 or £72 per user per month excluding VAT, depending on how much security sits in it. Almost nobody in this industry publishes a figure, so any industry average you are quoted is a guess. Here is ours, and what moves it.</description>
      <content:encoded>&amp;lt;p&amp;gt;Ours is £42, £55 or £72 per user per month excluding VAT, and the whole rate card is on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/pricing/&amp;quot;&amp;gt;the pricing page&amp;lt;/a&amp;gt; rather than behind a form.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is an unusual thing to publish, which is worth being straight about. Most providers in this industry will not give you a number without a meeting first, so if somebody quotes you an industry average for managed IT support, they have made it up or read it in a marketing report that made it up. There is no reliable published figure, because most of the market does not publish.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What do you get at each level?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Essential, £42 per user per month.&amp;lt;/strong&amp;gt; Unlimited remote and on site support, helpdesk 9am to 5pm Monday to Friday, NinjaOne remote monitoring and management, updates and patching, backup of Microsoft 365 email and files including testing that it restores, and starters, leavers and moves.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is IT support without the security layer, and we say plainly on the pricing page that most businesses need more than it. If the only thing protecting you is what came built into Microsoft 365, nobody is watching for a compromised account and nothing is catching the phishing email that gets through.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Secure, £55 per user per month.&amp;lt;/strong&amp;gt; Everything above, plus Bitdefender endpoint protection with Advanced Threat Security and 24 hour human monitoring behind it, Check Point advanced email security, DMARC domain protection, DefensX DNS and browser protection, vulnerability scanning and management, and security awareness training.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;This is the level most of our clients are on and the one we recommend. It is also the level that answers the questions an insurer or a client asks you.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Secure+, £72 per user per month.&amp;lt;/strong&amp;gt; Everything above, plus quarterly vCIO meetings, Cyber Essentials readiness and extended hours support. For businesses that want IT on the agenda rather than in the background.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What is not in the monthly fee?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;This is the part that decides whether a comparison between two providers means anything.&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Projects.&amp;lt;/strong&amp;gt; Migrations, office moves, server replacements. Scoped and quoted before anything starts. Day to day changes are included, and so is a handful of them at once.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Hardware.&amp;lt;/strong&amp;gt; We source and supply it based on what you actually need, so machines arrive built, licensed and on the right warranty.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Cyber Essentials certification.&amp;lt;/strong&amp;gt; The assessment fee and the work to get you through it, laid out in full at the start including what the certifying body charges.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Cloud, telecoms and connectivity.&amp;lt;/strong&amp;gt; Phone systems, broadband and mobile, priced separately as their own lines on the same invoice.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Backup beyond Microsoft 365.&amp;lt;/strong&amp;gt; Servers and on premises data are priced on how much there is to protect.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;What is not on that list matters as much as what is. There is no charge per ticket, no hourly rate for support, no call out fee, and no separate line for the monitoring tools.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Why does hourly billing cost more than it looks?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Because of what it does to behaviour.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A team that gets billed by the hour learns to put up with things. The printer that only works if you do it in a particular order, the laptop that takes four minutes to wake up, the shared drive nobody can find anything on. None of it is worth a phone call at £95 an hour, so nobody makes the call. Then a dozen small annoyances accumulate and one of them turns into a stoppage.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The other thing hourly billing does is make the invoice unpredictable, which for a business of 5 to 60 people is often the real complaint. You cannot budget for it and you cannot tell whether a big month means you had a bad month or your provider had a good one.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;A fixed fee changes who carries that risk. If something is badly built, it costs us to keep fixing it, so we have an interest in fixing it properly the first time.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;How do you compare two quotes properly?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Two proposals at very different prices are usually not describing the same service. Work through this list and they become comparable:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is endpoint protection included, and is a human watching it?&amp;lt;/strong&amp;gt; Antivirus on a machine and managed detection and response with a 24 hour team behind it are different products at different prices. Ask which one is in the number.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is email security included, beyond what Microsoft gives you?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is backup included, and has anyone tested a restore?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is security awareness training in there, or an extra?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;What are the support hours, and what happens outside them?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Is support genuinely unlimited, or is there a fair use clause with a number in it?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Who actually answers?&amp;lt;/strong&amp;gt; Ask how many people are in the team and whether first line is offshore.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;What is the onboarding cost and what does it cover?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;How long is the term, and what happens at the end of it?&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;If a provider will not answer those in writing, that is your answer.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What about the one off costs?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;There is an onboarding fee, tiered by the size of the business, and it is real work rather than an admin charge. Documenting an environment nobody has documented, fixing what is broken before it becomes our problem, getting the monitoring and security tools deployed. Sign for 36 months and we halve it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The minimum term is 12 months.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Is cheaper ever the right answer?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Sometimes, and we will tell you when.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;I sat with a business owner last year who knew his security was not where it should be and had been quoted something eye watering by somebody else. We went through the list together, most valuable to least valuable for his particular business, and I told him what I would not spend money on if I were in his seat. He looked surprised, which is fair enough, because usually the person on the other side of that table has a target to hit.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;He got to a genuinely good setup for a lot less than he had been quoted, and the things we left out he can add later if the business changes. He is still a client. That is roughly how I think it should work.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What to do next&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The full rate card, including what sits outside the monthly fee and the date it was last reviewed, is on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/pricing/&amp;quot;&amp;gt;the pricing page&amp;lt;/a&amp;gt;. What is actually covered day to day is on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/it-support/&amp;quot;&amp;gt;the IT support page&amp;lt;/a&amp;gt;, and the security detail is on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/cyber-security/&amp;quot;&amp;gt;the cyber security page&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you want a number for your business rather than a range, &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/contact/&amp;quot;&amp;gt;tell us how many people you have&amp;lt;/a&amp;gt; and you will get one. We will not ask to see your current bill first.&amp;lt;/p&amp;gt;
</content:encoded>
    </item>
    <item>
      <title>We think someone has access to our email. What do we do now?</title>
      <link>https://www.saturday-cloud.com/blog/someone-has-access-to-our-email/</link>
      <guid isPermaLink="true">https://www.saturday-cloud.com/blog/someone-has-access-to-our-email/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Briscombe</dc:creator>
      <description>Revoke the active sessions, then change the password, then check the mailbox rules. That order matters: changing a password on its own does not sign somebody out of a session they already hold, and the mailbox rule is what has been hiding this from you.</description>
      <content:encoded>&amp;lt;p&amp;gt;Do these three things, in this order, before anything else.&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Revoke the account’s active sessions.&amp;lt;/strong&amp;gt; In Microsoft 365 this is &amp;amp;quot;sign out of all sessions&amp;amp;quot; on the user, or disabling the account outright.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Change the password&amp;lt;/strong&amp;gt;, to something new, not a variation of the old one.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check the mailbox rules&amp;lt;/strong&amp;gt;, on that account and on any shared mailbox it can reach.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;The order is the part people get wrong. A password change on its own does not eject somebody who is already signed in, because the session they are holding was issued before you changed anything. Plenty of businesses have changed a password, felt relieved, and left the intruder exactly where they were.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Why do the mailbox rules matter so much?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Because they are how a compromise stays invisible.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Once somebody is in a mailbox, one of their first moves is to create a rule. Messages containing certain words get moved to a folder nobody opens, or marked as read, or forwarded outside the business. Then the account owner carries on as normal, seeing nothing unusual, while the interesting mail is filtered away before they reach it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Look for rules that move things to RSS Feeds, Conversation History, Archive or a folder with a single character as a name. Look for anything forwarding externally. Delete them, and write down what they said first.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;While you are in there, check the sent items and the deleted items. What has been sent from this account in the last month is the question that decides how bad this is.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What else needs checking?&amp;lt;/h2&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Look at the sign in logs.&amp;lt;/strong&amp;gt; Where has this account signed in from, and when. You are looking for locations and devices that make no sense.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check whether multi-factor authentication was on.&amp;lt;/strong&amp;gt; If it was not, switch it on now, for this account and every other one. If it was on and they got in anyway, somebody approved a prompt, which is a different conversation and a training one.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check for new app registrations or consents&amp;lt;/strong&amp;gt; granted from that account, because those survive a password change.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check the other accounts.&amp;lt;/strong&amp;gt; People reuse passwords. If this one leaked, assume others have.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Warn the people who deal with money.&amp;lt;/strong&amp;gt; Anybody who could act on a payment instruction needs to know today that a mailbox has been compromised, and that no bank details change gets actioned this week without a phone call to a number they already held.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Tell your clients if the account has been emailing them.&amp;lt;/strong&amp;gt; Awkward, and much less awkward than one of them paying an invoice that was not yours.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;h2&amp;gt;What was actually being aimed at?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Almost always money.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The pattern is consistent. Somebody gets into a mailbox, sets up the rule so nobody notices, and then reads. They are waiting for a transaction worth diverting: a completion, an invoice, a deposit, a payroll run. When it appears, an email arrives from a thread that is genuinely real, saying the bank details have changed.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is why the payments warning above is not an afterthought. It is the thing you are actually trying to prevent.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Occasionally it is something else. Access to a mailbox is a route into whatever that address can reset a password on, which is usually more than anybody realises.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Do you have to report it?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Possibly, and this is worth taking advice on rather than deciding for yourself.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If personal data has been accessed, a notifiable breach has to be reported to the ICO within 72 hours of you becoming aware. If you are regulated, your regulator will have its own requirement. Your insurer almost certainly has a notification period, and leaving it late can affect a claim. And if client data is involved you may need to tell them.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Four clocks, all starting from the moment somebody realises. That is the argument for having decided in advance who makes those calls, rather than working it out on the day.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;How do you stop it happening again?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Nobody enjoys this bit, and skipping it is how it happens twice.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Work out how they got in. It is usually a password entered on a convincing fake login page. Then fix the thing that made that enough: multi-factor authentication on every account with no exceptions, monitoring that would spot a mailbox rule being created, and email filtering ahead of the message arriving in the first place.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;And say to your team, plainly, that whoever clicked it is not in trouble. I mean that. The most expensive version of this is the one where somebody realises at half past four on a Friday and decides to see whether it sorts itself out over the weekend. A team that owns up in five minutes is worth more to you than a team that never clicks anything, and the second one does not exist.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;If you need somebody now&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Ring us on the number at the top of the page. If you are not a client we will still tell you what to do first, because the first hour matters more than who you buy support from.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;&amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/cyber-security/&amp;quot;&amp;gt;What we run for clients&amp;lt;/a&amp;gt; includes monitoring that flags exactly this, and &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/pricing/&amp;quot;&amp;gt;what it costs&amp;lt;/a&amp;gt; is published. If you want somebody to check whether this could be happening right now and nobody has noticed, &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/contact/&amp;quot;&amp;gt;that is a short conversation&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;
</content:encoded>
    </item>
    <item>
      <title>Will your cyber insurance actually pay out?</title>
      <link>https://www.saturday-cloud.com/blog/does-your-cyber-insurance-pay-out/</link>
      <guid isPermaLink="true">https://www.saturday-cloud.com/blog/does-your-cyber-insurance-pay-out/</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Briscombe</dc:creator>
      <description>Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.</description>
      <content:encoded>&amp;lt;p&amp;gt;Only if you were doing the things you said you were doing. That is the whole of it.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Your policy has a schedule, and the schedule lists what you told the insurer was in place when you took the cover out. If you have a breach, one of the first things an insurer does is check whether those things were true on the day. If one of them was not, the claim can be refused. Not reduced, refused.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;We are not insurance brokers and this is not advice on your policy. Your broker and the wording itself are the authority. What we can tell you is which line items on a typical schedule are the ones businesses get wrong.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What is usually on the schedule?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The list varies by insurer, and most of them include some version of:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;Multi-factor authentication on all remote access and all email accounts, and increasingly on all privileged accounts as well.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Security updates applied within a defined window, often fourteen or thirty days for critical ones.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Endpoint protection deployed on every device.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Backups taken at a stated frequency, with at least one copy separated from the main environment.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Security awareness training for staff, on a stated schedule.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;A documented incident response plan.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Sometimes a defined process for verifying changes to payment details.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Read as a list, none of that is unreasonable. Read as a set of warranties you have given, it is a set of things somebody will check line by line at the worst possible moment.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Which one catches people?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Multi-factor authentication, and specifically the word &amp;amp;quot;all&amp;amp;quot;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The declaration usually says all accounts, or all email accounts, or all remote access. What businesses actually have is multi-factor authentication on most accounts, with a handful of exceptions that were made years ago for practical reasons and never revisited. The shared mailbox. The account a piece of software signs in with. The director who found it annoying. The global administrator account somebody set up during a migration.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Every one of those is a gap between what the schedule says and what is true, and the second one is the one an attacker uses.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The other common one is training. &amp;amp;quot;Annual security awareness training&amp;amp;quot; is easy to agree to and easy to let slide in a busy year, and it is trivially checkable after the fact, because either there are records or there are not.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Why do so many businesses never read it?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Because there are a lot of hats to wear when you run a small business, and insurance is the one you put on for an afternoon each year.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Most small firms I talk to bought the policy, put it in a drawer, and assumed they were covered. That is a completely understandable thing to have done. It is also the reason the first time anybody reads the schedule properly is often after something has happened, which is the worst possible time to discover a mismatch.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;How do you check it in half an hour?&amp;lt;/h2&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Find the policy and open the schedule.&amp;lt;/strong&amp;gt; Not the summary at the front. The actual list of what you have warranted.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Go through it line by line with whoever handles your IT.&amp;lt;/strong&amp;gt; Ask for evidence rather than reassurance. &amp;amp;quot;Yes, MFA is on&amp;amp;quot; and &amp;amp;quot;here is the report showing every account with its status&amp;amp;quot; are different answers.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Write down anything that is not currently true.&amp;lt;/strong&amp;gt; That is your gap list, and it needs closing before renewal, not after a claim.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check the reporting obligations while you are in there.&amp;lt;/strong&amp;gt; Most policies require notification within a set period, and a delay can be its own problem.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;For most businesses that exercise produces two or three items, and most of them are configuration rather than money. Switching multi-factor authentication on is free.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;The bit worth saying plainly&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;The insurance is there to catch you when something goes wrong. It only works if the safety net you described to the insurer is the safety net you actually have.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That is also why this is worth doing even if you never claim. Every item on that schedule is something you would want to be true anyway. The policy just turns it into a list somebody else will check, which for a lot of businesses is what finally gets it done.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you want the evidence side of it handled properly, that is most of what our Secure level is for: multi-factor authentication enforced rather than requested, Bitdefender endpoint protection with 24 hour monitoring behind it, patching you can show a report for, and security awareness training included rather than bought separately. The full list and what it costs is on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/pricing/&amp;quot;&amp;gt;the pricing page&amp;lt;/a&amp;gt;, and the detail sits on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/cyber-security/&amp;quot;&amp;gt;the cyber security page&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Most of the same controls are also what &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/cyber-essentials/&amp;quot;&amp;gt;Cyber Essentials&amp;lt;/a&amp;gt; asks for, so if you are doing one you are most of the way through the other.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you would like somebody to sit down with your schedule and tell you which lines are currently true, &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/contact/&amp;quot;&amp;gt;get in touch&amp;lt;/a&amp;gt;. It is half an hour and you will know where you stand.&amp;lt;/p&amp;gt;
</content:encoded>
    </item>
    <item>
      <title>We certified last year. Will we pass Cyber Essentials renewal?</title>
      <link>https://www.saturday-cloud.com/blog/cyber-essentials-renewal-mfa/</link>
      <guid isPermaLink="true">https://www.saturday-cloud.com/blog/cyber-essentials-renewal-mfa/</guid>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Briscombe</dc:creator>
      <description>Probably not, not without some work first. Assessment accounts created on or after 27 April 2026 are marked against Requirements for IT Infrastructure v3.3, and multi-factor authentication is now mandatory on every cloud service that offers it. Miss it on one service and you fail the whole assessment.</description>
      <content:encoded>&amp;lt;p&amp;gt;The short answer is probably not, and the reason is one line in the requirements.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Cyber Essentials certificates last twelve months. When yours comes up you don’t renew the old assessment, you open a new one. If that new assessment account is created on or after 27 April 2026, it’s marked against Requirements for IT Infrastructure v3.3, which is a stricter document than the one you were marked against last year. Nobody writes to tell you. You log in expecting last year’s questions and get this year’s.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What changed in Cyber Essentials on 27 April 2026?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Multi-factor authentication became mandatory on every cloud service that offers it, and missing it on a single service is an automatic fail rather than a mark against you.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The same update leans harder on passwordless sign in and passkeys, gives cloud services a formal definition so there’s less argument about what sits in scope, and simplifies the scoping rules.&amp;lt;/p&amp;gt;
&amp;lt;p class=&amp;quot;stat__source&amp;quot;&amp;gt;Source: &amp;lt;a href=&amp;quot;https://iasme.co.uk/articles/upcoming-changes-to-the-cyber-essentials-scheme-april-2026-update/&amp;quot; rel=&amp;quot;noopener&amp;quot;&amp;gt;IASME, changes to the Cyber Essentials scheme, April 2026&amp;lt;/a&amp;gt;. IASME is the NCSC’s delivery partner for the scheme.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Assessment accounts opened before 27 April 2026 carry on against the previous version until that assessment closes. That’s the part that catches people, because it means the change doesn’t arrive on the day it’s announced. It arrives at renewal, months later, when you’ve stopped thinking about it.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Why does MFA fail so many renewals?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Because Microsoft 365 is the one everybody switched on years ago, and it’s the other nine services that nobody has looked at since the day they were set up.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The ones we find switched off, over and over:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt;
&amp;lt;li&amp;gt;The accounting package. Xero, Sage, QuickBooks, whichever it is.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The payroll portal, which is usually a separate login from accounting.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;File sharing that grew up outside Microsoft 365. Dropbox is the common one.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The CRM or practice management system.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The domain registrar and the hosting control panel, which between them can redirect your email.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The backup console. Worth thinking about what an attacker does first if they get into that one.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;The password manager, which is the account that opens every other account.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Remote access and support tools.&amp;lt;/li&amp;gt;
&amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;I’ll give you the version of this that still surprises me. We take over IT environments for a living, and some of the worst setups we walk into belong to businesses turning over £10m. Not startups counting pennies. Established, profitable, well run companies in every respect except this one. No MFA. Not patchy MFA, not MFA missing on a few accounts. None at all, and in some cases not even on the global admin account that controls the entire Microsoft tenant.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;That isn’t a budget decision, because switching MFA on is free. What’s happened is that years ago someone found the path of least resistance, nobody questioned it, and it became the business process.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;Which systems count as cloud services?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If your business reaches it over the internet, someone signs into it, and it holds business data, assume it’s in scope until somebody tells you otherwise.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The v3.3 definition exists precisely because this used to be arguable. The practical test that will save you an argument at assessment: if losing control of that login would be a bad day for the business, it’s in scope.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What does an automatic fail actually mean?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;It means there’s no partial credit. Cyber Essentials is a verified self-assessment, so you answer the questions and a board member signs a declaration that your answers are true. If MFA is missing on one service in scope, the honest answer to that question is no, and no is a fail regardless of how good everything else is.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The declaration itself has teeth now. Under the current version, a board member has to state that compliance is maintained through the certification period, not just that it was true on the day you submitted.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;How long before renewal should we start?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Six to eight weeks, and the time goes on finding things rather than fixing them.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Switching MFA on across a set of services you already have a list of is days of work, not weeks. Building that list is the slow part, and it’s slow because no single person in most businesses knows every system in use. What helps:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Find your renewal date first.&amp;lt;/strong&amp;gt; Everything else hangs off it.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Ask finance what the business pays for.&amp;lt;/strong&amp;gt; The card statement and the direct debits are a more honest inventory than anyone’s memory.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Ask each team what they log into.&amp;lt;/strong&amp;gt; You will find at least one system nobody in management knew existed.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check MFA on every one of them, including the admin accounts,&amp;lt;/strong&amp;gt; which are usually the ones exempted for convenience years ago.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Check nothing in scope is out of support,&amp;lt;/strong&amp;gt; because unsupported software is its own fail.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;h2&amp;gt;Is the certificate worth having if it’s a tick-box exercise?&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;Yes, and it is a tick-box exercise. Both things are true, and I say that as someone whose company gets clients certified.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The certificate tells you that on the day you were assessed, you met the controls. It doesn’t tell you whether somebody set up a forwarding rule on your finance inbox this morning. It doesn’t tell you whether a scheduled task has been sitting on your domain controller since 2019. We have found exactly that, on a network that had antivirus installed and scanning daily, because nobody was reading what it found.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;The thinking behind the scheme is still good. MFA, patching, endpoint protection, restricted admin access, a proper joiners and leavers process. If every UK SME did those five things consistently, the national picture would look dramatically different.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;So my actual view, in three lines:&amp;lt;/p&amp;gt;
&amp;lt;ol&amp;gt;
&amp;lt;li&amp;gt;If you need the badge for a contract, a tender or a regulator, get it. It isn’t hard, depending on how much technical debt you’re carrying.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;If you don’t need the badge, you still need the controls. Don’t wait for somebody to mandate what you should be doing anyway.&amp;lt;/li&amp;gt;
&amp;lt;li&amp;gt;Don’t treat the certificate as the finish line. You’ve got another 364 days to stay compliant, and the declaration you signed says you will.&amp;lt;/li&amp;gt;
&amp;lt;/ol&amp;gt;
&amp;lt;p&amp;gt;The badge was never the goal. The goal is the thing the badge is supposed to prove.&amp;lt;/p&amp;gt;
&amp;lt;h2&amp;gt;What to do next&amp;lt;/h2&amp;gt;
&amp;lt;p&amp;gt;If you’re certified already, find your renewal date and start the list. If you’re not, and a client or a tender has started asking, &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/cyber-essentials/&amp;quot;&amp;gt;the Cyber Essentials page&amp;lt;/a&amp;gt; sets out the five controls, both levels, and how we take businesses through it. What it costs to have us do it sits on &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/pricing/&amp;quot;&amp;gt;the pricing page&amp;lt;/a&amp;gt; alongside everything else, because we publish our rates.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;If you want a straight answer on whether your current setup would pass, &amp;lt;a href=&amp;quot;https://www.saturday-cloud.com/contact/&amp;quot;&amp;gt;ask us&amp;lt;/a&amp;gt;. It’s a short conversation and you’ll get a real answer, including if the answer is that you’re fine as you are.&amp;lt;/p&amp;gt;
</content:encoded>
    </item>
  </channel>
</rss>
