<![CDATA[Blog]]> https://www.thesilvercloudbusiness.com/blog/rss Our Blog en Sat, 26 Sep 2026 07:56:40 +0000 Do you know where your business data is? https://www.thesilvercloudbusiness.com/blog/do-you-know-where-your-business-data-is https://www.thesilvercloudbusiness.com/blog/do-you-know-where-your-business-data-is <p>A lot of people are using AI these days; some people are even using it to help them with their work, but are staff using AI in your business with your knowledge or are they using it under the radar?  As we covered in last week's article, a lot of AI models use data to train on, what if a member of staff is using your company data and it's inadvertently being used to train AI which in turn could aid your competitors or leak your business data?</p> <p>I'm going to go down memory lane, bear with me; a few years ago, we took a frantic call from a business that had suffered a serious data leak. Not because of a hacker. Not because of ransomware. Not because someone inside the company was trying to do harm.</p> <p>It happened because a well-meaning member of staff wanted to carry on working from home. To make that easier, they uploaded company data into their own free personal Dropbox account. The intention was helpful. The outcome was catastrophic.</p> <p>The data was now outside the company’s control, outside any proper business agreement, and outside the terms intended for that domestic service. Worse still, it was not protected to the standard the business needed. The result was a major data loss, reputational damage, and a very painful lesson: convenience can be dangerous when it bypasses proper controls.</p> <h2>The same risk has a new name: AI</h2> <p>Fast forward to today and the same pattern is happening again. This time, the tool is not personal cloud storage. It is artificial intelligence.</p> <p>Staff are using AI tools to write emails, analyse spreadsheets, summarise documents, create proposals, polish reports, draft HR content, troubleshoot technical issues and speed up everyday work. In many cases, they are doing it with good intentions. They want to be faster. They want to be more productive. They want to help the business.</p> <p>But if they are pasting customer information, contracts, financial data, internal processes, technical details, passwords, source code, sales figures or strategy documents into tools the business has not approved, then your confidential information may already be leaving the building.</p> <h2>Helpful does not always mean safe</h2> <p>The danger is that many employees do not realise what happens after they type or upload information into an AI platform. Some tools may store prompts. Some may use submitted data to improve or train their models. Some may be operated outside the UK. Some may have terms that are suitable for personal experimentation, but not for handling sensitive business data.</p> <p>The risk is not always malicious. In fact, that is what makes it so dangerous. Your team may believe they are doing the right thing, while accidentally exposing commercially sensitive information to a system the business has not assessed, secured or approved.</p> <p>Imagine a member of staff asking a free AI tool to summarise a confidential client proposal. Or to rewrite a disciplinary letter. Or to analyse a spreadsheet containing customer records. Or to explain a technical configuration that reveals how your systems are built. In each case, the employee is not trying to leak data. But the data may still be exposed.</p> <h2>Shadow AI is the new shadow IT</h2> <p>For years, businesses have worried about shadow IT: staff signing up for apps, storage services or software without telling the company. AI has made that problem bigger, faster and harder to see. It takes seconds to open an AI tool in a browser. It takes seconds to paste in confidential information. And once that data has gone in, you may have no easy way to get it back.</p> <p>That creates serious questions for business owners:</p> <ul> <li>Do you know which AI tools your staff are using?</li> <li>Do your staff know what information they must never enter into AI?</li> <li>Have you checked the terms, privacy settings and data handling policies of those tools?</li> <li>Do you have an AI usage policy that is actually understood by your team?</li> <li>Can you prove that client, employee and business data is being handled properly?</li> <li>Is your data being processed whilst maintaining GDPR compliance?</li> <li>Is your business data being used to train the AI model which exposes it to the public domain?</li> </ul> <p>If the answer is “no” or “I’m not sure”, then this is not a future problem. It is a current risk.</p> <h2>AI needs rules, not guesswork</h2> <p>AI can be incredibly useful. Used properly, it can improve productivity, reduce admin, speed up research and help teams work smarter. The answer is not necessarily to ban AI completely. A ban often drives the behaviour underground, where it becomes even harder to manage.</p> <p>The better approach is to put proper controls in place. Decide which tools are approved. Set clear rules on what can and cannot be entered. Train staff using real-world examples. Review supplier terms. Configure business-grade services correctly. Monitor for risky behaviour. Make AI part of your cyber security and data protection strategy, not an uncontrolled side project.</p> <p>Most importantly, make sure your people understand the issue. In the same way that uploading business data to a free personal storage account can create a serious data breach, pasting business data into the wrong AI tool can expose information you are legally, commercially and morally responsible for protecting.</p> <h2>Be careful, try not to be too helpful when using AI tools</h2> <p>Let me ask you a simple question. "<strong>Would you like to improve this tool to help others?</strong>"  This sounds like an innocent question, and most people, by their very nature would think "yes, I want to help this tool improve for others" so they select yes, <strong>BUT</strong> what this question actually means is " we need your permission to use all the data you upload to train the AI model and it could expose your data to the world".  If the question were worded as the latter explaining the data will be exposed to the world, then everyone would select no, this is why they are very careful with how they word the question.  Be warned.</p> <h2>What does this mean for your business</h2> <p>If your staff are using AI without your knowledge, your business may already have a data protection problem waiting to surface. The good news is that this can be managed with the right policies, tools, training and technical controls. As your MSP, we can help you understand where AI is being used, identify the risks, put sensible guardrails in place and make sure your team can benefit from AI without putting your business data at risk.</p> <p> </p> <p>At the very least you should have an AI usage policy for the business just so staff know the business stance on using AI.</p> <p>If you need help, call us on <strong>01722 411999</strong>.</p> Wed, 23 Sep 2026 00:00:00 +0000 Are You Using AI or is AI Using You https://www.thesilvercloudbusiness.com/blog/are-you-using-ai-or-is-ai-using-you https://www.thesilvercloudbusiness.com/blog/are-you-using-ai-or-is-ai-using-you <h1>Be Careful What You Share with AI - How to Keep Your Business Data Safe</h1> <h2>Artificial intelligence can be a powerful productivity tool, but careless use can create serious data protection and commercial risks.</h2> <p>AI tools are becoming part of everyday business life. They can help draft documents, summarise information, analyse data and speed up routine tasks. Used well, they can save time and improve decision-making. Used carelessly, however, they can expose confidential information, customer data, intellectual property and commercially sensitive material.</p> <p>Many people do not realise that some AI services may use prompts, uploaded files, chat history or user feedback to improve their systems, depending on the provider’s terms and settings. That means information entered into an AI tool could leave the control of your organisation and create risks around confidentiality, data protection and regulatory compliance. The UK Information Commissioner’s Office states that organisations using AI must consider accountability, transparency, security and data minimisation when personal data is involved.</p> <h2>Why this matters</h2> <p>Business data is valuable. It may include client records, staff information, contracts, pricing, designs, financial forecasts, legal advice, tender submissions or incident reports. If this information is copied into an AI tool without proper safeguards, it could be retained by a third party, accessed outside your approved environment, or used in ways your organisation did not intend.</p> <p>The risk is not only commercial. If personal data is involved, an accidental disclosure could place the business in breach of data protection obligations. Regulators expect organisations to understand what data they process, why they process it, who can access it and how it is protected. AI does not remove those responsibilities; it can make them more complex.</p> <h2>Common mistakes businesses make with AI</h2> <ul> <li>Pasting confidential emails, contracts or reports into public AI tools.</li> <li>Uploading spreadsheets containing personal, financial or client information.</li> <li>Assuming that every AI product has the same privacy and retention settings.</li> <li>Allowing staff to use unapproved AI tools without guidance or training.</li> <li>Failing to check whether AI-generated outputs contain inaccurate, biased or confidential information.</li> <li>Using AI outputs in regulated decisions without human review and proper records.</li> </ul> <h2>Tips to keep your data safe</h2> <ol> <li><strong>Do not enter sensitive information into public AI tools.</strong> Treat prompts like external disclosures unless you have checked the provider’s contractual terms, privacy settings and data retention policy.</li> <li><strong>Use approved business accounts only.</strong> Enterprise AI tools often provide stronger controls than free consumer versions, including administration, access management and data protection settings.</li> <li><strong>Classify your data before using AI.</strong> Decide what data is public, internal, confidential or highly restricted, and set clear rules on what can and cannot be used with AI systems.</li> <li><strong>Remove or mask personal and confidential details.</strong> Where possible, anonymise, pseudonymise or summarise information before asking an AI tool to process it.</li> <li><strong>Check supplier terms carefully.</strong> Understand whether your data may be retained, reviewed, used for model training, transferred internationally or shared with subcontractors.</li> <li><strong>Carry out a risk assessment.</strong> For higher-risk uses, especially where personal data is involved, consider a Data Protection Impact Assessment and document the safeguards you have put in place.</li> <li><strong>Train your staff.</strong> Make AI awareness part of your cyber security and data protection training so employees understand the practical risks.</li> <li><strong>Review AI outputs before use.</strong> AI can produce convincing but incorrect information, so human checking remains essential.</li> <li><strong>Create an AI use policy.</strong> Set out approved tools, permitted uses, prohibited data types, escalation points and review processes.</li> </ol> <h2>AI should support your business, not expose it</h2> <p>The answer is not to avoid AI altogether. The answer is to use it deliberately, safely and with the right controls. Businesses that put clear rules in place now will be better positioned to benefit from AI while protecting customers, staff, intellectual property and reputation.</p> <p>If you are unsure whether your current AI use is safe, now is the time to review it. Speak to your IT, compliance or data protection adviser, check your contracts and make sure your team knows what information must never be placed into an AI system.</p> <h2>How does this affect my business</h2> <p>Every business using AI needs to understand what data is being entered, where that data goes, and whether the tool is suitable for the information being processed. A simple review of your AI use, staff guidance and supplier settings can reduce the risk of data leakage, protect your commercial position and help demonstrate that you are taking compliance seriously.</p> <p>If you would like help reviewing how your business uses AI safely, contact us on <strong>01722 411 999</strong>.</p> <p> </p> Wed, 16 Sep 2026 00:00:00 +0000 Bye bye Microsoft Publisher, it was nice knowing you https://www.thesilvercloudbusiness.com/blog/bye-bye-microsoft-publisher-it-was-nice-knowing-you https://www.thesilvercloudbusiness.com/blog/bye-bye-microsoft-publisher-it-was-nice-knowing-you <h2>Microsoft Publisher is retiring in October 2026. Here is what your business needs to know—and what to do before your .pub files become difficult to access.</h2> <p>For decades, Microsoft Publisher has been the familiar choice for newsletters, leaflets, brochures, labels, business cards and other desktop-publishing jobs. It has been straightforward, flexible and included with many versions of Microsoft Office. But all good things must come to an end.</p> <p>Microsoft has confirmed that Publisher will reach end of life in October 2026. <strong>Microsoft 365 subscribers can use Publisher until 1 October 2026, but will no longer be able to access the application after that date.</strong> Support for the perpetual version of Publisher ends on <strong>13 October 2026</strong>, alongside Office LTSC 2021 and Office 2021. The safest business deadline is therefore 1 October 2026: complete your migration before then rather than relying on an unsupported installation.</p> <p>After retirement, Microsoft 365 subscribers will not be able to open or edit Publisher files in Publisher. Your .pub files will not simply disappear, but keeping them without a supported way to use them creates a serious accessibility and continuity risk—particularly when an old price list, template, certificate or marketing item suddenly needs updating.</p> <h2>Why businesses should act now</h2> <p>Publisher files are often scattered across laptops, servers, archived user folders, OneDrive, SharePoint and Teams-connected document libraries. Some may be obvious; others may sit untouched for years until they are urgently needed. Waiting until the last minute makes it harder to identify an owner, choose the right destination format and check that the converted output still looks correct.</p> <ul> <li>Publisher will no longer be included with Microsoft 365 after the retirement date.</li> <li>Unsupported software will not receive the protection or technical support expected by a modern business.</li> <li>Complex layouts, fonts and graphics may not convert perfectly without review.</li> <li>Historic documents may need preserving, while working templates need an editable replacement.</li> <li>A rushed migration can lead to missing files, broken layouts and lost business information.</li> </ul> <h2>How to prepare: a practical Publisher retirement checklist</h2> <ol> <li><strong>Find every .pub file.</strong> Search PCs, file servers, network shares, OneDrive, SharePoint, Teams libraries, backups and archive locations.</li> <li><strong>Assign an owner.</strong> Record which person or department understands the purpose of each file.</li> <li><strong>Classify the content.</strong> Mark each publication as active, reusable, historic, duplicate, obsolete or subject to a retention requirement.</li> <li><strong>Choose the destination.</strong> Decide whether the file should become a PDF, Word document, PowerPoint presentation or a design rebuilt in another supported application.</li> <li><strong>Back up the originals.</strong> Preserve an untouched copy of important .pub files and any linked images, logos or fonts before conversion.</li> <li><strong>Convert in manageable batches.</strong> Start with business-critical and regularly updated material rather than attempting everything at once.</li> <li><strong>Check the result.</strong> Compare pages, text flow, fonts, images, hyperlinks, margins, print settings and accessibility with the original.</li> <li><strong>Test the new workflow.</strong> Confirm that the content owner can edit, save, share and print the replacement without Publisher.</li> <li><strong>Stop creating new Publisher files.</strong> Move new work to a supported platform now so the backlog does not continue to grow.</li> <li><strong>Set a completion date before 1 October 2026.</strong> Leave time for exceptions, redesign work and user training.</li> </ol> <h2>Which application should replace Publisher?</h2> <h3>PDF—for finished documents that only need to be viewed, shared or printed</h3> <p>PDF is usually the best preservation format for completed publications because it maintains the visual appearance and is widely supported. It is not, however, a practical master format where text, prices, dates or images must continue to change.</p> <ul> <li>Open the publication in Publisher.</li> <li>Select <strong>File > Save As</strong> and choose a destination folder.</li> <li>Select <strong>PDF</strong> as the file type and save it.</li> <li>Open the PDF and compare it with the original, including every page.</li> <li>Use an appropriate quality setting for online distribution, office printing or commercial print.</li> </ul> <h3>Microsoft Word—for text-led documents that need future editing</h3> <p>Word is well suited to notices, forms, letters, simple newsletters, labels and documents where written content matters more than free-form page design. Microsoft’s suggested editable route is to convert the Publisher file to PDF and then open that PDF in Word. Expect to tidy complex layouts and check graphics carefully.</p> <ul> <li>Export the Publisher file as a PDF.</li> <li>Open Microsoft Word.</li> <li>Select <strong>File > Open</strong> and choose the PDF.</li> <li>Accept the prompt that Word will convert the PDF into an editable document.</li> <li>Review page breaks, columns, text boxes, images, fonts and spacing.</li> <li>Save the result as a .docx file and test printing and sharing.</li> </ul> <h3>Microsoft PowerPoint—for posters, signs, flyers and visual layouts</h3> <p>PowerPoint provides flexible placement of text and images and can be a practical replacement for single-page or slide-like content. Rather than trusting an automatic conversion, rebuild a clean reusable template and validate its physical page size before printing.</p> <ul> <li>Create a presentation with the required page orientation and dimensions.</li> <li>Copy the approved wording and source images from the original publication.</li> <li>Rebuild the layout using editable PowerPoint objects.</li> <li>Add branding to the template or slide master where appropriate.</li> <li>Export a PDF and run a test print before approving the replacement.</li> </ul> <h3>Microsoft Designer or a specialist publishing tool—for highly visual work</h3> <p>Modern design tools may suit social graphics, promotional artwork and quick branded content, while layout-critical catalogues, complex brochures and commercial-print projects may justify a specialist desktop-publishing application. Test representative files before committing, confirm licensing and data-handling requirements, and retain the original assets used to create each publication.</p> <h2>Do not confuse preservation with migration</h2> <p>A PDF may successfully preserve the appearance of an old brochure, but it does not automatically give you an easy-to-edit replacement for next year’s brochure. For every file, ask two questions: <strong>Do we only need to view this?</strong> and <strong>Will we need to edit or reuse it?</strong> The answer determines both the target format and the amount of rebuilding required.</p> <h2>What does this mean for my business?</h2> <p>Publisher’s retirement is not just a software change; it is a data-discovery and business-continuity project. If you do not know where your .pub files are stored, who owns them or which ones remain operationally important, now is the time to find out.</p> <p><strong>The Silver Cloud Business can help.</strong> We can search your data repositories—including suitable PCs, servers and Microsoft 365 storage—for Publisher files, help you understand what is there, prioritise business-critical content and plan a controlled move to a supported product before it is too late.</p> <p><strong>Call The Silver Cloud Business on 01722 411999</strong> to discuss a Publisher discovery and migration review. We can help you turn an approaching deadline into a planned, documented transition—without leaving important business content stranded in an obsolete format.</p> Thu, 03 Sep 2026 00:00:00 +0000 Preparing Your Business for AI: An AI Readiness Guide https://www.thesilvercloudbusiness.com/blog/preparing-your-business-for-ai-an-ai-readiness-guide https://www.thesilvercloudbusiness.com/blog/preparing-your-business-for-ai-an-ai-readiness-guide <h2>A practical approach to adopting AI securely, responsibly and successfully across your organisation</h2> <p>Artificial intelligence can help staff work faster, improve customer service and make better use of the information a business already holds. However, adopting AI for everyone is not simply a matter of buying licences and switching the technology on. AI can search, summarise and combine information at a speed and scale that exposes weaknesses in permissions, data governance and working practices that may previously have gone unnoticed.</p> <p>A successful AI programme therefore starts with the business, its people and its data. The objective should be to create a controlled environment in which approved tools deliver measurable value without exposing confidential information, personal data, intellectual property or client records.</p> <h2>1. Establish leadership, ownership and acceptable use</h2> <p>Nominate a senior owner for AI and create a small steering group involving business leadership, IT, information security, data protection and representatives from the teams that will use AI. Define which outcomes matter, such as reducing administration, improving response times or helping staff find information, and agree how success will be measured.</p> <ul> <li>Publish an AI acceptable-use policy covering approved services, permitted data, human review and prohibited activities.</li> <li>Create a simple approval process for new AI tools, browser extensions, agents, connectors and integrations.</li> <li>Define accountable owners for each use case and record its purpose, data sources, users, supplier and risk rating.</li> <li>Set clear rules for customer-facing content, automated decisions and any use involving personal or sensitive information.</li> </ul> <h2>2. Discover and classify the information AI could access</h2> <p>Build an information map covering Microsoft 365, line-of-business systems, shared drives, cloud storage, email, collaboration platforms and archives. Identify where personal data, commercially sensitive material, HR records, financial information, credentials and client data are stored. Assign owners and retention requirements, remove redundant data and introduce sensitivity labels where appropriate.</p> <p><strong>Why this matters:</strong> an AI assistant may make information dramatically easier to find, but it does not correct an unsafe permissions model. Content that was technically accessible but difficult to discover can become available through a straightforward natural-language request.</p> <h2>3. Review permissions and reduce oversharing</h2> <p>Carry out a structured permissions audit before connecting AI to business data. Review SharePoint sites, Teams, OneDrive, shared mailboxes, network folders and business applications. Pay particular attention to organisation-wide access, “anyone” links, the “Everyone except external users” group, inherited or broken permissions, guest access, stale accounts and sites without an active owner.</p> <ul> <li>Apply least privilege: staff should have access only to information required for their role.</li> <li>Replace broad sharing links with named users or controlled groups.</li> <li>Review privileged roles, service accounts and third-party application permissions.</li> <li>Remove obsolete content and access left behind by former employees, suppliers or completed projects.</li> <li>Introduce recurring access reviews rather than treating remediation as a one-off exercise.</li> </ul> <h2>4. Assess every AI supplier and service</h2> <p>Do not assume that a free or inexpensive AI service is suitable for business use. The commercial model may depend on retaining prompts, uploaded files or conversation history and using them to improve services or train models.</p> <p>Even where an opt-out exists, it may depend on the account type, settings or contract. Staff accepting consumer terms on behalf of themselves can unintentionally disclose company or client information outside approved controls.</p> <p>For each supplier, establish in writing:</p> <ul> <li>Whether prompts, outputs and uploaded data are used for model training or service improvement.</li> <li>Where data is processed and stored, how long it is retained and how it can be deleted or exported.</li> <li>Whether administrators can control accounts, sharing, connectors, agents and audit logs.</li> <li>Which subprocessors are involved and what contractual, privacy and security assurances apply.</li> <li>How the service handles encryption, incident notification, business continuity and account termination.</li> <li>Whether the intended use requires a data protection impact assessment, contractual review or client approval.</li> </ul> <h2>5. Find and control shadow AI</h2> <p>Shadow AI occurs when employees adopt AI tools, agents, meeting assistants, browser extensions or personal accounts without the knowledge or approval of the business. This may already be happening before a formal AI project begins.</p> <p>Risks include uncontrolled data transfer, excessive application permissions, poor authentication, unrecorded automated actions, intellectual-property leakage and suppliers that cannot meet the organisation’s legal or contractual obligations.</p> <ul> <li>Survey staff in a constructive, non-punitive way to understand what they use and why.</li> <li>Review sign-ins, enterprise applications, OAuth consent, browser extensions, network or cloud-security logs and expense claims.</li> <li>Maintain an approved AI catalogue and give staff a quick route for requesting alternatives.</li> <li>Block or restrict high-risk services where proportionate, while explaining the approved options.</li> <li>Revoke unknown integrations and investigate any exposure of confidential or personal information.</li> </ul> <h2>6. Put technical guardrails around approved AI</h2> <p>Use business-grade services under centrally managed accounts. Enforce multi-factor authentication, conditional access, least-privilege administration and controlled app consent. Apply data loss prevention, sensitivity labels, retention controls, audit logging and alerting. Limit agents and connectors to approved systems, credentials and scopes; test what information they can retrieve and what actions they can take.</p> <p>Treat an autonomous or semi-autonomous agent as a privileged digital worker. Give it a named owner, a defined purpose, the minimum data and permissions required, spending or transaction limits where relevant, complete logging, and a reliable method to stop or revoke it.</p> <h2>7. Start with controlled, valuable use cases</h2> <p>Select a small pilot group and begin with repeatable tasks that have clear value and manageable risk: drafting routine communications, summarising approved documents, finding internal procedures or assisting with meeting notes. Establish a baseline, define expected benefits and monitor quality, time saved, adoption, support demand and incidents.</p> <p>Require human verification of outputs. AI can produce inaccurate, incomplete or fabricated answers, and plausible wording should never be mistaken for evidence. High-impact decisions, legal or financial advice, customer commitments, security changes and publication of sensitive material should remain subject to competent human approval.</p> <h2>8. Train staff and create safe working habits</h2> <p>Training should cover more than prompting. Staff need to understand information classification, approved tools, privacy, copyright and intellectual property, hallucinations, bias, social engineering, secure sharing and how to report a mistake. Use role-based examples and provide reusable prompt patterns that avoid unnecessary personal or confidential data.</p> <h2>9. Prepare for incidents and ongoing assurance</h2> <p>Update incident-response procedures to include accidental prompt disclosure, unsafe output, compromised AI accounts, malicious integrations, agent misbehaviour and supplier incidents. Staff should know whom to contact and should preserve the relevant prompt, output, tool, account and time without redistributing sensitive content.</p> <p>Review the AI register, permissions, suppliers, logs, policies, training needs and business benefits regularly. Terms, features and risks change quickly, so approval should never be permanent by default.</p> <h2>What does this mean for your business</h2> <p>AI readiness is not about preventing innovation. It is about making sure the organisation understands its information, chooses trustworthy services and gives staff a safe, productive route to use them. Before deploying AI to all staff, your business should consider the following steps:</p> <ol> <li>Appoint an AI owner and agree the outcomes you want to achieve.</li> <li>Discover and classify the data your organisation holds.</li> <li>Audit file, folder, site, mailbox and application permissions.</li> <li>Identify any AI services, agents or extensions already being used.</li> <li>Create an approved-tools list and an AI acceptable-use policy.</li> <li>Review supplier terms, privacy, training, retention and data-location commitments.</li> <li>Implement identity, data-protection, logging and application-control guardrails.</li> <li>Pilot a small number of low-risk, high-value use cases.</li> <li>Train staff to use AI safely and verify its outputs.</li> <li>Measure value, review risk and improve controls continuously.</li> </ol> <p><strong>The Silver Cloud Business can help.</strong> Our AI Readiness service can assess your Microsoft 365 and / or server environment, review permissions and data exposure, help to identify shadow AI, evaluate proposed platforms, develop practical policies and create a phased roadmap for secure adoption.</p> <p><strong>Call us on 01722 411 999</strong> to discuss an AI Readiness Assessment and make sure your organisation is ready to gain the benefits of AI without exposing the data it depends on.</p> <p> </p> Wed, 02 Sep 2026 00:00:00 +0000 Security threats are no longer just a “computer problem” https://www.thesilvercloudbusiness.com/blog/security-threats-are-no-longer-just-a-computer-problem https://www.thesilvercloudbusiness.com/blog/security-threats-are-no-longer-just-a-computer-problem <h2>Recent real-world vulnerabilities show why businesses need visibility across their entire infrastructure including cloud services, websites and mobile devices and not just their computers.</h2> <p>When people think about cybersecurity, they often picture a laptop with antivirus software, a server needing updates, or a firewall blocking suspicious traffic. Those things still matter, but the modern attack surface is much broader. Today, business systems depend on cloud identity platforms, website plugins and frameworks, smartphones, tablets and third-party services that sit outside the traditional office network.</p> <p>Three recent security stories make that point very clearly: a critical Microsoft Entra ID remote code execution vulnerability, a serious Elementor Pro WordPress plugin flaw that could allow attackers to upload executable code, and an Apple ImageIO issue fixed in the latest security updates for iPhone, iPad and macOS.</p> <p>Each one affects a different part of the technology stack, but together they underline the same message: anything connected to your business can become part of your cyber-attack surface risk.</p> <h2>1. Microsoft Entra ID: when the cloud identity layer is the target</h2> <p>Microsoft Entra ID, formerly known as Azure Active Directory, is at the heart of many organisations’ Microsoft 365 and Azure environments. It controls authentication, single sign-on, conditional access and access to cloud applications. That makes it a critical service: if identity is compromised, the knock-on impact can be significant.</p> <p>The vulnerability tracked as <strong>CVE-2026-69836</strong> was reported as a maximum-severity remote code execution issue in Microsoft Entra ID, caused by unsafe deserialization of untrusted data. Microsoft stated that the issue was mitigated server-side and that customers did not need to apply a traditional patch. Some early reporting described the flaw as exploited in the wild, but later reporting noted that Microsoft corrected the exploitation status to say it had not been exploited. Even with that clarification, the incident is a useful reminder that cloud services are not abstract or risk-free: they are software platforms, and they can contain serious vulnerabilities.</p> <p>For businesses, the lesson is not simply “Microsoft fixed it”. The more important lesson is that your cloud identity platform is now part of your security perimeter.</p> <p>This is why it is business critical to monitoring sign-ins, reviewing administrator activity, checking conditional access policies and keeping visibility of connected applications are all essential parts of modern IT security.</p> <h2>2. Elementor Pro for WordPress: when website code becomes the doorway</h2> <p>WordPress powers a huge number of business websites, and many of those sites rely on plugins to provide contact forms, page builders, booking systems, e-commerce tools and customer upload features. Elementor Pro is one of the most widely used premium WordPress plugins, and a recent vulnerability showed how a common website feature can become a serious security risk.</p> <p>The Elementor Pro vulnerability, tracked as <strong>CVE-2026-32475</strong>, affects versions up to and including 4.2.1 and was fixed in version 4.2.2. The flaw involved the Forms module’s File Upload field. In practical terms, an attacker could potentially use a specially crafted upload request to bypass file checks and place a PHP file into a public directory, creating a route to remote code execution on the website server.</p> <p>This is not just a WordPress administrator’s problem. A compromised website can be used to steal customer data, redirect visitors, host phishing pages, send malicious emails or damage your company’s reputation.</p> <p>Website frameworks, plugins and themes should therefore be treated as live business systems that need regular updates, monitoring and regular review, not as something that is “finished” once the site goes live.</p> <h2>3. Apple ImageIO: when a mobile device becomes the target</h2> <p>Mobile devices are now business devices. Staff use iPhones and iPads to access email, documents, Teams, cloud storage, authentication apps and customer information. That means a mobile vulnerability can quickly become a business vulnerability.</p> <p>Apple’s recent security updates addressed an ImageIO vulnerability, reported as <strong>CVE-2026-65346</strong>, where processing a maliciously crafted image could lead to arbitrary code execution. ImageIO is a system-level framework used to handle images across Apple platforms, so vulnerabilities in this area matter because images are processed by many everyday apps and services. Apple’s latest iOS, iPadOS and macOS updates included fixes for this issue, reinforcing the importance of keeping mobile devices updated rather than treating phones as separate from the business IT estate.</p> <p>The key point is simple: your mobile devices are endpoints too. If they access company email, cloud services, shared files or authentication systems, they need the same level of visibility and patch awareness as laptops and desktops.</p> <h2>The bigger picture: security now spans devices, cloud and code</h2> <p>These three examples show that exploitation risk is no longer limited to traditional computers. A business may be exposed through its cloud identity infrastructure, through the code running its website, or through the mobile devices staff use every day. Security therefore has to be broader than installing updates on office PCs. It needs asset visibility, update management, monitoring, alerting and a clear understanding of what is connected to your environment.</p> <p>For many businesses, the biggest risk is not knowing what is out there. Which devices are accessing your systems? Are staff phones up to date? Are laptops missing critical patches? Is your website running vulnerable plugins? Are cloud services being accessed from unexpected locations or unmanaged devices? These are the questions that need answers before a vulnerability becomes an incident.</p> <h2>What is CVE?</h2> <p>You may have noticed that each incident has an assigned CVE (Common Vulnerabilities and Exposures) number.  The Common Vulnerabilities and Exposures is a free, standardised directory and naming system for publicly known cyber-security flaws in both software and hardware. You can access the CVE site here <span style="text-decoration: underline;"><strong><a title="CVE website" href="https://www.cve.org" target="_blank">https://www.cve.org</a> </strong></span></p> <p>The CVE was created in 1999 and gives every security bug a unique ID so that security teams around the world can discuss and fix the exact same problem.  It serves as a critical, early-warning public utility that keeps digital devices, personal data, and infrastructure secure using the following:</p> <ul> <li><strong class="rQesXe MPyX" data-sfc-cp="" data-sfc-root="ep" data-complete="true" data-copy-service-computed-style="font-family: ">Secures Everyday Products:</strong> It forces companies to fix flaws in consumer tech like smartphones, routers, smart TVs, and medical devices.</li> <li class="Z1qcYe" data-sfc-cp="" data-sfc-root="ep" data-hveid="CAAICBAE" data-complete="true" data-processed="true" data-sae="" data-copy-service-computed-style="font-family: "><strong class="rQesXe MPyX" data-sfc-cp="" data-sfc-root="ep" data-complete="true" data-copy-service-computed-style="font-family: ">Prevents Massive Data Breaches:</strong> Patching CVEs protects large companies and banks, keeping your personal identity, passwords, and credit card data safe from hackers.</li> <li class="Z1qcYe" data-sfc-cp="" data-sfc-root="ep" data-hveid="CAAICBAH" data-complete="true" data-processed="true" data-sae="" data-copy-service-computed-style="font-family: "><strong class="rQesXe MPyX" data-sfc-cp="" data-sfc-root="ep" data-complete="true" data-copy-service-computed-style="font-family: ">Protects Critical Infrastructure:</strong> Governments use CVE data to secure vital public systems like power grids, water plants, and hospital networks.</li> <li class="Z1qcYe" data-sfc-cp="" data-sfc-root="ep" data-hveid="CAAICBAK" data-processed="true" data-sae="" data-complete="true" data-copy-service-computed-style="font-family: "><strong class="rQesXe MPyX" data-sfc-cp="" data-sfc-root="ep" data-complete="true" data-copy-service-computed-style="font-family: ">Empowers Smart Consumers:</strong> Anyone can search a product before buying it to see its security track record and check if the manufacturer fixes flaws quickly.</li> <li class="Z1qcYe" data-sfc-cp="" data-sfc-root="ep" data-hveid="CAAICBAN" data-complete="true" data-processed="true" data-sae="" data-copy-service-computed-style="font-family: "><strong class="rQesXe MPyX" data-sfc-cp="" data-sfc-root="ep" data-complete="true" data-copy-service-computed-style="font-family: ">Drives Automated Security:</strong> Cybersecurity tools built into home operating systems (like Windows Update or Apple iOS updates) use CVE data to download and install security fixes automatically.</li> </ul> <h2>What does this mean to your business?</h2> <p>It means cyber-security needs to cover more than the machines sitting on desks, you must think of every component in your infrastructure both physically in your business and much wider such as cloud services or web hosting solutions.   It is imperative to have oversight of your entire infrastructure, not just the physical equipment you can see and touch.</p> <p>The Silver Cloud Business provides remote monitoring and maintenance tools that can help businesses identify devices to ensure they are patched and secure, identify devices accessing the business’s environment, highlight systems that are out of date and alert when action is needed.</p> <p>If you would like help understanding your current exposure, improving visibility across your devices, or learning more about our managed IT and security services, please call us on <strong>01722 411999</strong>. We would be happy to offer practical advice and help you decide what level of protection is right for your business.</p> <p>If you still need convincing that there are threats everywhere, call us for a free comprehensive scan of your Microsoft 365 tenant including scanning your email to identify any threats lurking in your email store.  It is remarkable what our tools will find and it is also remarkable that these flaws are still there, waiting to be exploited.</p> <p>Getting started is simple. The scan is <strong>FREE</strong>, and the insights could prove invaluable and save your business from an embarrassing data leak.</p> Mon, 24 Aug 2026 00:00:00 +0000 The UK Government Cyber Resilience Pledge: What It Means for Businesses https://www.thesilvercloudbusiness.com/blog/the-uk-government-cyber-resilience-pledge-what-it-means-for-businesses https://www.thesilvercloudbusiness.com/blog/the-uk-government-cyber-resilience-pledge-what-it-means-for-businesses <p>A practical guide to the declaration, Cyber Essentials, Cyber Essentials Plus, costs and the right route for different business sizes.</p> <h2>What is the UK Government Cyber Resilience Pledge?</h2> <p>The UK Government Cyber Resilience Pledge is a voluntary public declaration for organisations that want to demonstrate a stronger commitment to cyber resilience. It was formally launched at 10 Downing Street on 7 July 2026 and asks organisations to commit to three practical actions: making cyber security a board-level responsibility, signing up to the National Cyber Security Centre Early Warning service, and improving Cyber Essentials coverage across their supply chains.</p> <p>The pledge is not a certification and it does not prove that a business is secure. Instead, it is a governance and accountability commitment. It tells customers, suppliers, regulators and investors that cyber risk is being treated as a business resilience issue, not just an IT problem.  Trust is such an important commodity in business and it is really important that businesses demonstrate that they treat their IT security seriously and demonstrate this to customers and suppliers. </p> <h2>What does the pledge involve?</h2> <p>Organisations that sign the pledge commit to the following:</p> <ol> <li><strong>Make cyber a board responsibility.</strong> This means implementing the Cyber Governance Code of Practice and ensuring all board members complete NCSC Cyber Governance Training within three months of signing and then annually.</li> <li><strong>Sign up to NCSC Early Warning.</strong> Organisations must register for the free Early Warning service within one month. This service alerts organisations to signs of potential compromise or malicious activity linked to their networks, domains or IP addresses.</li> <li><strong>Require Cyber Essentials across supply chains.</strong> Organisations must register for the Cyber Essentials Supplier Check Tool within two months, audit Cyber Essentials coverage across their supply chain, present the results to the board and take a risk-based approach to requiring certification from suppliers.</li> </ol> <p>Signatories are also expected to encourage the same actions within their own supply chains, publish the signed declaration on their website within two months, and provide an annual public update on the steps taken to deliver against the pledge.</p> <h2>What is the significance?</h2> <p>For larger organisations, the pledge creates a visible board-level commitment to cyber governance and supply-chain assurance. For smaller suppliers, the impact may be indirect but significant: if their customers sign the pledge, they may increasingly be asked to obtain Cyber Essentials as a condition of doing business.</p> <p>In practical terms, the pledge is likely to accelerate Cyber Essentials adoption across UK supply chains. It also raises expectations that boards should understand cyber risk, measure supplier assurance, and demonstrate that cyber resilience is part of business continuity planning.</p> <h2>Which businesses have already signed up?</h2> <p>The government has published a live list of organisations that have signed the Cyber Resilience Pledge. Early signatories include M&S, Microsoft UK, Vodafone Group, Deloitte LLP, Accenture UK Limited, Cloudflare, Aviva, Capgemini UK, Computacenter, ITV plc, London Stock Exchange Group, Mastercard Europe, Nationwide, Tesco PLC, Harrods, Whitbread and many cyber security and technology providers working towards adopting the Cyber Resilience Pledge including The Silver Cloud Business.</p> <p>The reasons for signing will vary by organisation, but the common business drivers are clear:</p> <ul> <li><strong>Reputation and trust:</strong> signing demonstrates that cyber resilience is taken seriously at board level.</li> <li><strong>Supply-chain leadership:</strong> large organisations can use the pledge to set expectations for suppliers and partners.</li> <li><strong>Customer assurance:</strong> public commitment can help reassure customers after a period of heightened cyber threat.</li> <li><strong>Procurement readiness:</strong> businesses working with government, regulated sectors or large enterprises can show alignment with the UK’s preferred cyber-security direction of travel.</li> <li><strong>Incident learning:</strong> organisations that have experienced or observed major cyber incidents may see the pledge as a way to demonstrate continuous improvement.</li> </ul> <p>Microsoft UK’s published comment around the launch positioned stronger board-level accountability and supply-chain security as ways for the UK to stay ahead as AI changes both cyber threats and defensive responses. That neatly captures the wider purpose of the pledge: it is about governance, resilience and shared responsibility across the economy.</p> <h2>What would a business need to do before declaring?</h2> <p>A sensible route to signing the pledge would look like this:</p> <ol> <li><strong>Board briefing:</strong> explain the pledge, confirm why the business wants to sign, and agree the intended scope.</li> <li><strong>Assign accountability:</strong> nominate a board-level owner for cyber risk and define reporting lines into the board.</li> <li><strong>Complete cyber-governance training:</strong> ensure all directors complete NCSC Cyber Governance Training within the pledge timescale.</li> <li><strong>Map current controls:</strong> assess existing policies, incident response, business continuity, supplier management, patching, identity protection, backups and monitoring.</li> <li><strong>Register for NCSC Early Warning:</strong> identify who will receive alerts, how they will be triaged, and how incidents will be escalated.</li> <li><strong>Register for the Cyber Essentials Supplier Check Tool:</strong> use it to understand supplier Cyber Essentials coverage.</li> <li><strong>Audit the supply chain:</strong> categorise suppliers by criticality, data access, network access and operational dependency.</li> <li><strong>Set supplier requirements:</strong> decide where Cyber Essentials, Cyber Essentials Plus or alternative assurance is required.</li> <li><strong>Prepare the declaration:</strong> have the Chair or CEO sign the pledge, publish it on the company website, and schedule an annual update.</li> </ol> <h2>How much does the pledge cost?</h2> <p>The pledge itself is voluntary and does not carry a government certification fee. However, businesses should budget for the practical work needed to meet the declaration commitments.</p> <p>The pledge areas can be broken down into the following fees and notes:</p> <ul> <li><strong>Pledge declaration - </strong>£0 government fee - Internal time to review, approve, sign and publish.</li> <li><strong>NCSC Early Warning - </strong>Free - Requires internal or managed-service time to monitor and respond to alerts.</li> <li><strong>Cyber-governance training - </strong>Free NCSC training - Board time should be planned and recorded.</li> <li><strong>Supplier audit - </strong>Internal time or consultancy - Cost depends on supplier volume and complexity.</li> <li><strong>Cyber Essentials - </strong>Typically around £320–£600 + VAT by organisation size - Assessment fee only; remediation or consultancy is extra.</li> <li><strong>Cyber Essentials Plus - </strong>Commonly from about £1,500 to £4,250+ VAT, sometimes more for complex environments - Includes independent technical testing after Cyber Essentials.</li> </ul> <h2>Cyber Resilience Pledge vs Cyber Essentials vs Cyber Essentials Plus</h2> <p><strong>Cyber Resilience Pledge</strong></p> <ul> <li><strong>Type -</strong> Voluntary public declaration</li> <li> <p><strong>Main purpose -</strong> Board accountability and supply-chain resilience</p> </li> <li> <p><strong>Assurance level -</strong> Commitment-based</p> </li> <li> <p><strong>Typical audience -</strong> Medium, large and enterprise organisations, especially those with supply chains</p> </li> <li> <p><strong>Validity -</strong> Ongoing public commitment with annual update expected</p> </li> <li><strong>Cost -</strong> No direct government fee, but implementation effort required</li> <li><strong>Best use -</strong> Showing leadership, governance maturity and supply-chain influence</li> </ul> <p><strong>Cyber Essentials</strong></p> <ul> <li><strong>Type -</strong> Government-backed certification</li> <li> <p><strong>Main purpose -</strong> Baseline technical controls</p> </li> <li> <p><strong>Assurance level -</strong> Self-assessment reviewed by an assessor</p> </li> <li> <p><strong>Typical audience -</strong> All organisations, especially SMEs and suppliers</p> </li> <li> <p><strong>Validity -</strong> 12 months</p> </li> <li><strong>Cost -</strong> Usually around £320–£600 + VAT depending on size</li> <li><strong>Best use -</strong>  Proving basic cyber hygiene</li> </ul> <p><strong>Cyber Essentials Plus</strong></p> <ul> <li><strong>Type -</strong> Government-backed certification with technical audit</li> <li> <p><strong>Main purpose -</strong> Independent validation that controls work in practice</p> </li> <li> <p><strong>Assurance level -</strong> External testing and verification</p> </li> <li> <p><strong>Typical audience -</strong> Higher-risk suppliers, regulated sectors, government supply chains and larger organisations</p> </li> <li> <p><strong>Validity -</strong> 12 months </p> </li> <li><strong>Cost -</strong> Usually several thousand pounds depending on size and complexity</li> <li><strong>Best use -</strong> Proving basic controls have been independently tested</li> </ul> <p> </p> <p>The key difference is that the pledge is a promise to govern and influence cyber resilience, while Cyber Essentials and Cyber Essentials Plus are certifications. In most cases, they should not be seen as alternatives. The pledge depends heavily on Cyber Essentials because one of its three core commitments is to drive Cyber Essentials through the supply chain.</p> <h2>Which route is best by business size?</h2> <p><strong>Small business</strong></p> <p>Cyber Essentials first. Consider the pledge only if customers ask for it or if the business wants to make a public governance commitment. Cyber Essentials gives the strongest value for money and is increasingly useful in tenders and supply-chain assurance.</p> <p><strong>SME</strong></p> <p>Cyber Essentials as a minimum; Cyber Essentials Plus if handling sensitive data, providing IT services, bidding for public-sector work or supporting larger customers. SMEs are often supply-chain targets. Certification gives clear evidence of baseline controls and can unlock commercial opportunities.</p> <p><strong>Medium organisation</strong></p> <p>Cyber Essentials Plus, plus consider signing the Cyber Resilience Pledge if the organisation has a board structure and meaningful supplier network. Medium organisations normally have enough operational complexity to justify independent technical validation and formal supplier assurance.</p> <p><strong>Enterprise organisation</strong></p> <p>All three: Cyber Resilience Pledge, Cyber Essentials, and Cyber Essentials Plus where appropriate across key business units or subsidiaries. Enterprises influence large supply chains, face higher regulatory and reputational exposure, and need both governance commitment and technical assurance.</p> <h2>What does this mean for my business?</h2> <p>For most businesses, the right starting point is Cyber Essentials. It is affordable, recognised and directly aligned with the government’s supply-chain direction. Cyber Essentials Plus is the stronger option where customers, contracts, risk profile or data sensitivity justify independent testing. The Cyber Resilience Pledge is most powerful for organisations with board-level governance and supplier influence, because it shows public leadership and commits the business to raising cyber standards beyond its own perimeter.</p> <p>The best outcome is not to treat these as competing options. A mature business should use Cyber Essentials to establish the baseline, Cyber Essentials Plus to validate it, and the Cyber Resilience Pledge to show leadership, accountability and supply-chain responsibility.</p> Wed, 12 Aug 2026 00:00:00 +0000