Clear thinking for better technology decisions.
Practical insight on managed IT, cyber security, AI, Microsoft 365 and the technology decisions facing UK organisations.
What’s changing, and what it means for your business.
Our newest guidance, analysis and practical thinking for business and IT leaders.
Explore the latest thinking.
There are no articles under this topic in the posts currently loaded.
The latest articles could not be loaded. The standard Squarespace blog feed has been restored below.
Turn useful insight into practical next steps.
Explore how Fifosys supports organisations with managed IT, cyber security and the technology decisions that shape what comes next.
One phishing email and almost ten years of fallout: What the Manchester City story teaches every business about cyber risk
A phishing email reportedly opened the door to thousands of Manchester City documents, and almost a decade later, the consequences are still unfolding. Here’s what UK businesses should learn about email security, access, monitoring and incident response.
What UK Businesses Can Learn From the Revolut Data Breach
Revolut was not breached through its core systems. Criminals used a legitimate government email domain to request sensitive customer data. The incident is a useful warning for every business that relies on email and trusted relationships.
MFA Isn’t the End Game: Why Businesses Need to Start Thinking About Passkeys
MFA has been the sensible answer to a clear problem: passwords aren’t enough. But attackers have adapted, and now one-time codes can be intercepted, fake sign-in pages can relay credentials in real time, and push notifications can be abused.
Passkeys offer a more phishing-resistant alternative, without making security more frustrating for users. So, what are they, how do they work, and what should UK businesses do now?
Don’t Be Fooled: 5 Phishing Tactics to Watch Out for (And How to Spot Them)
April Fools’ Day is built on harmless deception, but phishing attacks are anything but. While prank emails might raise a smile, malicious ones are designed to catch you off guard and exploit trust, urgency or familiarity.
In this blog, we break down five common phishing tactics still catching people out in 2026, and what to look for before you click.
What Is DMARC? Why Domain Protection Matters in 2026
Email remains one of the most trusted channels in business, yet it is also one of the easiest to abuse. If your domain is not properly protected, it can be spoofed without your knowledge, putting your brand and clients at risk. In this piece, we break down what DMARC actually does, why so many organisations still misconfigure it, and why domain protection should be treated as a baseline control in 2026.
Is Your Email Filtering Hitting DMARC?
If someone sent an email pretending to be your CEO, would your systems catch it? Would your clients know the difference? Could you stop it? Email spoofing is one of the easiest ways for cybercriminals to impersonate your brand, trick your clients, and cause chaos in your business.
And it works. All too well.
Join us for a look at all things DMARC and learn how it can keep you (and your inbox) safe from malicious outsiders.
Phishing: What Is It and Why Does It Matter?
What is phishing, how can you spot a suspicious email and what should you do if you click the wrong link? We break down the warning signs, common tactics and practical steps businesses and employees can take to reduce the risk.