Fincomp Services Ltd

Fincomp Services Ltd Specialising in providing IT support for micro businesses and offering a range of cloud-based service

31/07/2026

Your team is using AI right now, whether you have a policy on it or not.

ChatGPT, Gemini, Copilot, Claude, and a dozen niche business tools are in the workflow of someone in your business this week. These tools learn from what you type, sometimes retain it for training, and live outside whatever data security setup you've built for the rest of the business.

Without a written policy, you have no way to know what client data is being pasted into prompts, which business decisions are being made with AI assistance, or how your insurance views any of it if something goes wrong.

An AI Acceptable Use Policy doesn't have to be 30 pages. A one-page version covers the essentials: which tools are approved, what data is forbidden as input, what disclosure rules apply to AI-generated work, and who reviews AI output before it goes to a client.

If you want a full AI Acceptable Use Policy template to implement in your business, comment below with "AI Policy" and we'll send it to you.

Deleted a OneDrive file lately and gone looking for it in your Recycle Bin?Surprise. It's not there.Since May, files you...
31/07/2026

Deleted a OneDrive file lately and gone looking for it in your Recycle Bin?

Surprise. It's not there.

Since May, files you delete from OneDrive or SharePoint in the cloud don't show up in your local Recycle Bin or Trash any more.

They get pulled straight off your device. The only place to get them back is the OneDrive or SharePoint recycle bin on the web.
Here's how:

- Go to onedrive.com or your SharePoint site
- Click "Recycle bin" in the left menu
- Right-click the file and hit "Restore"

You've usually got 30 days before it drops into the second-stage recycle bin (bet you didn't know that one existed). Then another 93 days or so in there, depending on how your org's set up.

After about 123 days? Gone for good.

P.S. Worth telling your team this one before someone panics thinking they've lost a week's work.

P.P.S If you're not sure if you have a backup or would like someone to check let me know.

30/07/2026

Smishing is text message phishing, and it's now more effective at reaching people than email phishing.

The reason is mechanical. Most businesses spent the last decade hardening their email gateways and training people on suspicious links. Almost nobody applied the same effort to text messages. The result is a channel where employees still tap first and think later.

The patterns repeat: a "delivery failed" message with a link asking for login credentials, a "this is your CEO" text from a number nobody recognises asking for gift cards or a wire, a fake account-lockout message that looks identical to a real bank alert, and a "hey, I'm in a meeting, can you help me with something quick?" text impersonating a senior person.

These work because texts feel personal in a way email doesn't. They land on the same screen where your spouse, your kids, and your coworkers reach you, which makes the brain default to trusting them. That's the entire attack.

The rules to give your team:

1. No business decision happens over text. That includes wire transfers, vendor changes, payroll changes, gift card requests, and password resets.
2. If a text claims to be from a coworker, verify through a different channel before responding. A 30-second Slack message or phone call kills most of these attacks.
3. Never click a login link inside a text. Open the app or website directly.
4. Forward suspected smishing to 7726 (which spells SPAM on a phone keypad). Carriers use it to block the source.

Smishing works when the response happens before the thinking. Train your team to slow down, and most of these attacks dead-end before the attacker has time to react.

Signed up for a load of AI tools over the last 18 months and not looked at them since?You're probably burning money.A Ma...
29/07/2026

Signed up for a load of AI tools over the last 18 months and not looked at them since?

You're probably burning money.

A March audit of 102 small businesses found 87% were wasting money on their AI subscriptions. Median waste? $18,000 a year. Per business.

Most owners end up in the same spot. You got ChatGPT. Then Claude. Then a transcription tool. Then a note-taker. Then a writing assistant. And now half of them do the same job as the other half.

Three signs your AI pile needs a clear-out:

▶️ You're paying for two tools that do the same thing

▶️ Your team quietly stopped using something you're still paying for

▶️ You can't explain, quickly, what any one tool actually gets you

While you're in there, check the security bit too:

✅ Make sure every tool's on a business plan with a "Do Not Train" clause. Consumer plans feed your data straight into the model.

✅ Pull access for anyone who's left. AI tools always get forgotten at offboarding.

✅ Check what's plugged into your Microsoft 365 or Google Workspace. These tools often have access to your email and files you never realised you'd handed over.

Worth an hour of your time. Probably worth a fair bit more than that.

When did you last actually audit your AI stack?

29/07/2026

Your salesperson stops at a coffee shop between meetings. They set up at a table, open their laptop, order a drink, and walk back to the counter when their name is called. The laptop is unattended for 90 seconds. That's enough time for someone to ruin your business week.

The attacker doesn't need to be sophisticated. A £40 USB device called a "Rubber Ducky" plugs in and looks like a keyboard to the computer. It runs pre-loaded keystrokes faster than any human can type. In 90 seconds it can open a terminal, download a remote access tool, install it, and disable the screen lock notification, all without a click from your salesperson.

When your salesperson comes back to the table, the laptop looks the same as they left it. The next time they connect to your office network, the attacker has a path in.

This kind of attack has been demonstrated at every major security conference for the last 10 years. The hardware is cheaper now than it was then.

The defense is straightforward.

- Set every laptop to lock automatically after 30 seconds of inactivity, and train your team that any unattended laptop gets locked first.
- Disable USB device auto-execute across your fleet. On Windows, that's the "AutoPlay" setting plus USB device blocking in Group Policy or Intune.
- Use endpoint detection and response (EDR) software that flags new processes, persistence mechanisms, and suspicious network connections within seconds of installation.
- For people who travel often, give them USB data blockers (small adapters that allow charging but block data transfer) for airports and coffee shops.

Physical security still matters even though most of your defenses sit in software. Don't let the five steps from your laptop to the counter at the coffee shop be the weakest part.

27/07/2026

When an employee leaves your business, the security gap is usually bigger than you'd guess.

A typical 25-person business has dozens of cloud accounts per employee.

Email, payroll, file storage, CRM, accounting, internal tools, and third-party SaaS subscriptions.

When the employee leaves, every one of those accounts should be disabled, but in most businesses only the obvious ones (email, computer login) get touched.

The rest sit dormant for months or years, still with the employee's credentials, still accessible if those credentials were ever leaked in a breach.

That's how a fired employee from 18 months ago becomes the entry point for next year's breach.

The fix is a written offboarding checklist that includes every account, not just the obvious ones.

- Day of departure: disable email, computer login, VPN, and any single-sign-on (SSO) accounts that gate everything else.
- Within 48 hours: revoke access on every SaaS tool by checking the actual admin panel of each.
- Within 7 days: change shared credentials the employee knew
- Within 30 days: do a "did we miss anything" review with someone who worked closely with the employee.

Without a checklist, "what did this person have access to?" is impossible to answer in a few months.

On May 7, 2026, an Amazon Web Services data center overheated and took out an entire availability zone in US-East-1, AWS...
26/07/2026

On May 7, 2026, an Amazon Web Services data center overheated and took out an entire availability zone in US-East-1, AWS's most popular region. Several core AWS services went down, and any business application hosted in that zone was unreachable for hours.

Cloud outages happen to every major provider, not just AWS. Azure, Google Cloud, Cloudflare, Microsoft 365, Salesforce, and Slack have all gone down long enough to break a business day in the last three years.

If your business loses meaningful money during downtime, you need a "the cloud is down" plan. The plan has three parts.

A dependency map. Every critical workflow in your business should be mapped to the SaaS or cloud service it depends on. Your accountant uses QuickBooks Online, which runs on AWS. Your sales team uses HubSpot, which also runs on AWS. Your phones might be VoIP, which depends on a carrier you've never named. The map doesn't need to be pretty, but it does need to exist.

An out-of-band communications path. Phone numbers for your key vendors, your insurance broker, your IT provider, and a contact for every team lead. This list lives on paper or on a phone that doesn't depend on your office network. Use the same list from your incident response plan.

A decision tree for what stops and what continues. Some work has to keep happening even when systems are down (taking orders, handling client emergencies). Other work can wait. Pre-decide which is which, so that conversation isn't happening for the first time during an outage.

Test the plan once a year. Turn off access to one major SaaS tool for an afternoon and watch what your team does. Whatever you learn from the dry run is cheaper than learning it for real.


Overheating at a single data center has been identified as the cause of the AWS outage, which impacted customers such as Coinbase

In May 2026, hackers breached Instructure, the company behind the Canvas learning platform used by thousands of schools ...
24/07/2026

In May 2026, hackers breached Instructure, the company behind the Canvas learning platform used by thousands of schools and universities. The attackers claimed data on 275 million users across more than 9,000 institutions.

That breach didn't just affect Instructure. Every one of those 9,000 institutions now has to deal with breach notification laws in every state where any of its affected users live. That means 50 different timelines, penalty structures, and disclosure requirements to track.

Your business probably isn't running Canvas. What happens to Instructure's customers, though, is the same thing that happens to your business when one of your vendors gets breached. You are responsible for notifying your customers under your state's law, often within 60 days, sometimes less. You don't get to wait for the vendor to handle it.

The work to do this week. Pull your list of SaaS vendors (the one you built from the SaaS audit). For each vendor that holds customer data, write down what data they hold and which state's law applies to each of your customers. Then call your cyber insurance broker and ask for the breach notification playbook your policy entitles you to. If they don't have one, that's worth knowing right now, not during an incident.

A vendor breach becomes your legal problem the day they tell you about it. The preparation has to happen earlier.


The criminal extortion group ShinyHunters breached Instructure last week. The hackers, who have also attacked individual universities, demanded the ed-tech giant pay up or face a data leak.

23/07/2026

The old rules about strong passwords are out of date.

For years the standard advice was eight characters, mix uppercase and lowercase, throw in a number and a symbol. NIST, CISA, and Microsoft's own identity team all moved off that advice years ago. The current recommendation is simpler and stronger. Use long passwords or passphrases, and stop forcing your team to rotate them on a schedule.

The math is straightforward. Modern password-cracking hardware can guess a complex 8-character password in less than an hour. A 16-character passphrase made of common words takes centuries against the same hardware. Length wins because every extra character multiplies the work an attacker has to do, while complexity adds only modest barriers.

The policy update for your business is short. Set a minimum of 14 characters for general accounts and 16 or more for admin or sensitive ones. Mandatory rotation creates more weak passwords than it prevents, so stop forcing it. Required complexity rules tend to push people toward simpler, less secure patterns, so drop those too. Block any password that appears in known breach databases, and require MFA on every account that supports it.

If your business is still using 8-character passwords with quarterly rotation, you're following the rules from 2010. The new rules are easier on your team and harder on attackers.

In May 2026, Intuit announced it would lay off around 3,000 employees to refocus the company on AI.Intuit owns QuickBook...
22/07/2026

In May 2026, Intuit announced it would lay off around 3,000 employees to refocus the company on AI.

Intuit owns QuickBooks, TurboTax, Mailchimp, and Credit Karma. Most small businesses use at least one of these. The layoffs are part of a bigger pattern across the tech industry, where companies built around traditional software are rebuilding around AI products. Small business tools are next in line.

Four things to expect over the next 18 months:

1. Product changes. Familiar features get replaced or buried inside AI-first workflows. The QuickBooks you use in 2027 probably won't look like the one you use today.
2. Support friction. Fewer humans on the support line means longer queues and more chatbot-first triage. Get to know your account manager's direct line before you need it.
3. Pricing changes. AI features get bundled into higher tiers, and the base tier loses ground. Expect a renewal call where the rep asks "have you seen our new AI plan?"
4. Data going somewhere new. Your accounting, payroll, and marketing data is the fuel for the new AI features. Check the privacy and data-use settings on each Intuit product you use, and find out what's opted in by default.

Stay on Intuit if it works for you. Just spend the next 18 months auditing what you're paying for, where your data goes, and who answers your calls when something breaks.


In a memo to employees, CEO Sasan Goodarzi said the layoffs are meant to reduce complexity, simplify the company's corporate structure, and deliver better AI products.

Address

Twickenham

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+442080997301

Alerts

Be the first to know and let us send you an email when Fincomp Services Ltd posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share