Insights from Fifosys

Clear thinking for better technology decisions.

Practical insight on managed IT, cyber security, AI, Microsoft 365 and the technology decisions facing UK organisations.

More insights

Explore the latest thinking.

There are no articles under this topic in the posts currently loaded.

The latest articles could not be loaded. The standard Squarespace blog feed has been restored below.

Before You Roll Out AI Tools, Fix Your Permissions

AI tools can only work with the access and data environment you give them. Before rollout, review permissions, sharing links and ownership so old access problems do not become fast, searchable ones.

Read More

Your IT manager doesn't need replacing - they need backup

Your IT manager knows the business better than an external provider ever could, and co-managed IT gives them the capacity, specialist support and reliable cover to do more with that knowledge, without handing over control.

Read More

Unpacking the GTA 6 Leak: What Can Businesses Learn from Cyberleek?

GTA 6 has leaked again, with Cyberleek publishing apparent work-in-progress footage and a map ahead of Rockstar's official showcase. We look at what is confirmed, what remains uncertain, and the practical cyber security lessons for UK businesses.

Read More

What Is an MSP? A Practical Guide for UK Businesses

A managed service provider can act as your IT department or strengthen the team you already have. This practical guide explains how MSPs work, the benefits for UK businesses, what to look for in a provider, and why clear responsibilities matter in a co-managed relationship.

Read More

What Changed in AI This Week? Claude Cowork in Chrome, ChatGPT Business Pricing, UK Ads and Cyber AI

Claude Cowork moves into Chrome, ChatGPT Business introduces premium seats, and ChatGPT ads arrive in the UK. We unpack this week’s most important AI developments, including new compliance controls and advanced cyber models, and explain what they mean for business costs, security and governance.

Read More

MFA Isn’t the End Game: Why Businesses Need to Start Thinking About Passkeys

MFA has been the sensible answer to a clear problem: passwords aren’t enough. But attackers have adapted, and now one-time codes can be intercepted, fake sign-in pages can relay credentials in real time, and push notifications can be abused.

Passkeys offer a more phishing-resistant alternative, without making security more frustrating for users. So, what are they, how do they work, and what should UK businesses do now?

Read More

What Changed in AI This Week? GPT-5.6, Rogue AI Agents, Claude in Slack and the EU AI Act

AI agents went beyond their instructions during UK security tests, while OpenAI updated GPT-5.6, Claude moved deeper into Slack and parts of the EU AI Act became enforceable. Here’s what this week’s developments mean for businesses.

Read More

Claude Chats Appearing in Google: What Does That Teach us About AI Privacy?

Some publicly shared Claude chats have appeared in search results, raising a useful reminder that AI privacy is so much more than ‘just an IT issue’. Here’s what SMEs and mid-market organisations should learn from it.

Read More
OpenAI, ChatGPT, AI, AI Security, AI Governance, Cyber Security Jordan Stewart OpenAI, ChatGPT, AI, AI Security, AI Governance, Cyber Security Jordan Stewart

OpenAI’s AI Agent Escaped Its Sandbox. Here’s What Businesses Should Actually Take From It

Last week, we saw headlines on how “AI escaped”. We sat down with CTO James Moss, to understand what happened in OpenAI going rogue, the takeaways for businesses, and whether the robot uprising really is on the way.

Read More

Cyber Resilience in 2026: What UK SMEs Should Take From the New Government Pledge

Cyber resilience is moving from “something IT handles” to a board-level business discipline. The government’s July 2026 Cyber Resilience Pledge is aimed at larger organisations, but the practical message applies neatly to UK SMEs: know who owns cyber risk, use the free tools available, and make supply-chain security less vague.

Read More

What Should a Modern IT Partner Actually Be Responsible For?

A modern IT partner should be responsible for keeping core systems supported, secure, visible, resilient and aligned with the direction of the business. That includes responsive day-to-day support, proactive monitoring, cyber security, backup and recovery planning, supplier management, technology roadmapping, compliance support, and clear communication with leadership.

In short: they should help you deal with today’s issues, prevent tomorrow’s avoidable ones, and make better decisions about what comes next. Not a small job, then.

Read More

Your Backups Are Not a Recovery Plan

Backups are one of those things every business knows it should have.

They sit quietly in the background, reassuring everyone that if the worst happens, the data is safe and the business can carry on. But a backup is only useful if it can actually be restored.

That is why backup testing matters. It turns “we think we’re covered” into “we know what we can recover, how quickly, and what still needs fixing.” In the middle of a ransomware attack, cloud outage, accidental deletion, or failed migration, that difference becomes very real.

Read More

Microsoft 365 Changes Coming in 2026: Key Teams, SharePoint and Licensing Updates for IT Admins

Several important Microsoft 365 changes are arriving in 2026, from the retirement of Teams Live Events to licensing and governance updates across SharePoint, OneDrive, Purview and Entra. This guide explains what organisations should prepare for and where to focus their attention.

Read More

XDR vs MDR: What’s the Difference, and Which One Does Your Business Need?

Confused by XDR vs MDR? Here’s what UK SMEs and mid-market organisations need to know about modern threat detection, why endpoint security alone is no longer enough, and how broader visibility plus managed response can help reduce blind spots across email, cloud, identity, endpoint, and network environments.

Read More

The CISA GitHub Leak Is a Mess. But It’s Also Very Familiar

A major credential leak linked to the US cybersecurity agency CISA has exposed a problem most businesses are far more vulnerable to than they realise. From forgotten API keys to overprivileged supplier access, exposed credentials have become a normal part of modern IT environments. Here’s what UK SMEs and mid-market organisations should actually be paying attention to.

Read More
Cyber Attack, Cyber Resilience, Cyber Security Jordan Stewart Cyber Attack, Cyber Resilience, Cyber Security Jordan Stewart

When Supply Chain Attacks Become a Competition: What UK Businesses Need to Pay Attention to

A new threat advisory issued in May 2026 warns of increased risk around software supply chain compromise, including underground activity that appears to reward scale and downstream impact. For UK SMEs and mid-market organisations, the takeaway is not panic. It is a reminder that modern cyber risk does not always start inside your business.

Read More

Locking the Door: A Simple Cyber Hygiene Checklist for 2026

Cyber security doesn’t always come down to complex tools or advanced threats. More often, it’s the basics that make the biggest difference.

Following the UK government’s “lock the door” campaign, we’ve pulled together a simple cyber hygiene checklist to help organisations sense-check their current approach, from patching and access control to visibility and response.

Read More

The Five Assumptions That Lead to Breaches

Cyber incidents aren’t always the result of sophisticated attacks. More often, they stem from everyday assumptions about how systems work, where responsibility sits, and who is actually at risk.

With around half of UK SMEs experiencing a breach or attack in the past year, it’s clear that those assumptions don’t always hold up. In this blog, we explore five common beliefs that continue to catch organisations out, and why they’re worth challenging.

Read More
Phishing, Cyber Resilience, Cyber Security Jordan Stewart Phishing, Cyber Resilience, Cyber Security Jordan Stewart

Don’t Be Fooled: 5 Phishing Tactics to Watch Out for (And How to Spot Them)

April Fools’ Day is built on harmless deception, but phishing attacks are anything but. While prank emails might raise a smile, malicious ones are designed to catch you off guard and exploit trust, urgency or familiarity.

In this blog, we break down five common phishing tactics still catching people out in 2026, and what to look for before you click.

Read More