Why lean IT teams must rethink cyber-security

Posted: 12th Mar 2026

As regulations such as NIS2 and DORA tighten and cyber-attacks grow more sophisticated, mid-sized UK organisations face enterprise-level expectations without enterprise-level resources.

In 2025, a UK-based organisation with about 20 users discovered that its “good enough” security wasn’t nearly enough. The company had relied solely on native Microsoft 365 protection, with managers assuming its small size made it an unlikely target.

They were wrong.

A security incident revealed that attackers had already infiltrated the organisation’s cloud environment, quietly creating suspicious mailbox rules to exfiltrate sensitive data without anyone noticing. Without dedicated security staff to monitor the environment, the breach went undetected until the damage was done.

View Full Article

Related Articles

Popular Articles

Many people assume that productivity relies on workers being physically present at work in order for...
AI is giving cybercriminals new speed and scale, but researchers say the technology could also becom...
Today, the Council gave its final green light on a new regulation aiming to streamline and simplify ...
Something shifted in late 2025 that I don't think our industry has fully reckoned with yet.  W...