Clear thinking for better technology decisions.
Practical insight on managed IT, cyber security, AI, Microsoft 365 and the technology decisions facing UK organisations.
What’s changing, and what it means for your business.
Our newest guidance, analysis and practical thinking for business and IT leaders.
Explore the latest thinking.
There are no articles under this topic in the posts currently loaded.
The latest articles could not be loaded. The standard Squarespace blog feed has been restored below.
Turn useful insight into practical next steps.
Explore how Fifosys supports organisations with managed IT, cyber security and the technology decisions that shape what comes next.
Cyber Resilience in 2026: What UK SMEs Should Take From the New Government Pledge
Cyber resilience is moving from “something IT handles” to a board-level business discipline. The government’s July 2026 Cyber Resilience Pledge is aimed at larger organisations, but the practical message applies neatly to UK SMEs: know who owns cyber risk, use the free tools available, and make supply-chain security less vague.
What Should a Modern IT Partner Actually Be Responsible For?
A modern IT partner should be responsible for keeping core systems supported, secure, visible, resilient and aligned with the direction of the business. That includes responsive day-to-day support, proactive monitoring, cyber security, backup and recovery planning, supplier management, technology roadmapping, compliance support, and clear communication with leadership.
In short: they should help you deal with today’s issues, prevent tomorrow’s avoidable ones, and make better decisions about what comes next. Not a small job, then.
What Changed in AI This Week: Claude Sonnet 5, Microsoft’s SMB Copilot Push, OpenAI Adoption Data and Google’s Agent Platform Moves
This week’s AI news was less about flashy demos and more about business reality: Claude Sonnet 5 sharpened the cost-performance race, Microsoft pushed Copilot further into SMB workflows, OpenAI showed ChatGPT usage deepening over time, and cautionary stories from Ford and Uber highlighted the need for governance, cost control and human expertise.
Your Backups Are Not a Recovery Plan
Backups are one of those things every business knows it should have.
They sit quietly in the background, reassuring everyone that if the worst happens, the data is safe and the business can carry on. But a backup is only useful if it can actually be restored.
That is why backup testing matters. It turns “we think we’re covered” into “we know what we can recover, how quickly, and what still needs fixing.” In the middle of a ransomware attack, cloud outage, accidental deletion, or failed migration, that difference becomes very real.
Unpacking Microsoft’s MFA Push: An Operations Check for Your Business
Microsoft’s MFA enforcement is not just another login tweak. For UK SMEs and mid-market organisations, it is a useful prompt to review admin access, legacy accounts, automations, and whether Microsoft 365 is being actively managed or simply inherited.
Disruption Doesn’t Ask for Notice: What April’s Tube Strikes May Reveal About Your Infrastructure
Disruption doesn’t wait for a convenient moment. And this week’s tube strikes offered a useful reminder of that.
For many organisations, it forced an immediate shift to fully remote working, putting infrastructure, access, and collaboration tools under pressure in a way that planned hybrid setups rarely do. In this blog, we explore what moments like this reveal, and how to sense-check whether your environment is built to cope.
The Five Assumptions That Lead to Breaches
Cyber incidents aren’t always the result of sophisticated attacks. More often, they stem from everyday assumptions about how systems work, where responsibility sits, and who is actually at risk.
With around half of UK SMEs experiencing a breach or attack in the past year, it’s clear that those assumptions don’t always hold up. In this blog, we explore five common beliefs that continue to catch organisations out, and why they’re worth challenging.
What the Companies House Incident Reveals About Cyber Risk
Companies House is one of those systems most people assume simply works. It sits quietly in the background of the UK business environment, holding records for millions of companies and underpinning how organisations verify each other every day.
But recent reports of a vulnerability in the WebFiling system have raised serious questions about how secure that infrastructure really is. Beyond the technical issue itself, the incident highlights something broader: many of the systems businesses rely on sit outside their direct control.
When platforms like this experience problems, the consequences can ripple far beyond the organisation running them.
When Technology Stops the Game: Why Invisible Infrastructure Matters
A six-minute delay in the North London derby was a small disruption with very visible consequences. Tens of thousands waited. Millions watched. All because the technology, which is usually invisible, briefly stopped working. In this piece, we explore what that moment reveals about modern infrastructure and why reliability now underpins experiences far beyond the stadium.
Hybrid Work in 2026: Are Your Systems Still Built for 2021?
Hybrid work is no ‘temporary fix’. It’s the operating model for many UK businesses. But while ways of working have matured, much of the infrastructure behind them sometimes hasn’t. From legacy VPN dependence to collaboration sprawl and uneven identity controls, systems built in urgency are now showing their age. This piece explores whether your architecture is truly ready for sustained hybrid operations in 2026.
2025 in Review: The Cyber Incidents That Redefined Risk and Resilience
2025 was a defining year for cyber security. From major outages to supply-chain attacks, organisations were forced to confront systemic risk and the limits of assumed resilience. This review examines the cyber incidents that mattered and the lessons they hold for the year ahead.
The Rainbow Six Siege Breach and the Hidden Cost of Holiday Cyber Risk
The Christmas period is meant to be quiet, yet the Rainbow Six Siege breach shows how cyber incidents thrive when attention drops. As servers were taken offline and data integrity collapsed, the real story goes beyond gaming disruption, revealing the risks that always-on services face when attackers strike during holiday downtime.
What the November 2025 Cloudflare Outage Teaches Organisations About Resilience
Cloudflare suffered a major global outage on 18 November 2025 that disrupted websites, applications and core services for several hours. A routine internal configuration change triggered an unexpected file duplication that caused Cloudflare’s traffic proxy processes to crash and interrupt global connectivity. The incident revealed how dependent organisations are on single infrastructure providers and highlighted the need for stronger resilience planning, careful change control and clear visibility over internal configuration pipelines.
The True Cost of Not Investing in Security
When thieves broke into the Louvre Museum, the biggest shock wasn’t what they stole - it was how easily they did it. Yet, a password allegedly set to “Louvre” is what’s really exposed one of the world’s most secure institutions. The incident is a reminder that under-investment in cyber security doesn’t just risk data loss; it threatens trust, reputation and millions in avoidable cost.
Why Preparation Has Replaced Prevention
Another year is closing out, and once again, cyber security has dominated the agenda. From AI-powered attacks to boardroom accountability, 2025 has challenged every layer of digital resilience. As new threats rise and regulations tighten, UK organisations are learning that prevention alone isn’t enough, preparation and partnership now define true resilience.
When the Cloud Sneezes, the Internet Catches a Cold
When AWS went down on 20th October and half the internet froze, our Microsoft-based clients stayed online. This piece unpacks what really caused the outage, why single-provider setups are risky, and how thoughtful design and regular testing turn resilience from buzzword to reality.
Inside an Email Breach: The 16-Step Response Plan We Use at Fifosys
Over the past few months, we’ve seen a sharp rise in targeted email breaches across UK businesses - including our own clients. When an inbox is compromised, every second counts. This article walks through the exact 16-step plan we follow internally at Fifosys, and includes a download you can adapt for your own response process.
The Clock’s Ticking: What Windows 10 End-of-Life Means for You
Windows 10 support ends on 14 October 2025. That means no more security updates, and a greater risk the longer you delay. From upgrading to Windows 11 to exploring Extended Security Updates, here's what businesses need to know - and the options available to you.
Beyond the Tick Box: Building a Culture of Compliance
Having the right policies is one thing. Living by them is another. As regulators tighten expectations, compliance is no longer about passing an audit. It’s about creating a culture where security awareness, accountability, and good habits are part of everyday business.
When the Wheels Stop Turning: What the JLR Cyberattack and Heathrow Shutdown Teach UK Businesses
When Jaguar Land Rover and Heathrow Airport both ground to a halt in September 2025, the message was clear: cyberattacks don’t just take systems offline anymore. They stop business in its tracks. What can UK organisations learn from these incidents, and how can you prepare before it happens to you?