Onboard 365 LTD

Onboard 365 LTD At Onboard365 we offer reliable IT support and services for your business.

With a range of support options that can be tailored to you, whatever your IT needs we are here for you.

04/09/2026

If someone takes over your business page, they can scam your customers using your name. Turn on two-factor authentication for every social account. Stop sharing one login and use Business Manager so each person has their own access you can remove when they leave.

03/09/2026

If your guests, staff phones and work computers are all on the same wifi, they can all reach each other. One infected laptop sits right next to the machine running your accounts. Put guests and smart devices on separate networks. Most routers do this already.

In May 2026, Google launched a one-click tool that imports your team's Microsoft 365 user accounts directly into Google ...
09/08/2026

In May 2026, Google launched a one-click tool that imports your team's Microsoft 365 user accounts directly into Google Workspace.

The feature is built into the Workspace setup flow for very small and small businesses. It pulls user accounts from M365 in a single step, and a separate import handles the data behind those accounts (emails, calendars, contacts, and OneDrive files). What used to be a multi-day project with consultants now takes under an hour for a 25-person team.

The real story is the switching cost. For years, a small business that started on M365 was effectively locked in by the labor of moving off. That lock just got weaker, and it changes the conversation even if you have no plans to switch.

Your next Microsoft 365 renewal becomes a real negotiation. Price increases that used to feel unavoidable because the alternative was too much work now have a reasonable Plan B. Bring it up. The reps already know.

If you're paying for M365 features your team doesn't use (Premium licensing, Defender add-ons, Power Platform seats), the renewal is also the moment to right-size. You're probably paying for two or three tiers above what your team actually needs.

Whether you plan to switch or not, your negotiating position just improved. Use it.



arrow_back Back May 13, 2026 Small businesses can now seamlessly import users from Microsoft to Google Workspace Admin console Google Workspace Rapid Release Scheduled Release We’re excited to announce the beta release of a new, simplified way for very small and small-sized businesses to import th...

08/08/2026

Your primary work email is on every business card, contract, and website. It's also the first thing attackers look for when they're targeting your business.

Phishing crews scrape your company website and LinkedIn for the format and patterns of your email addresses. Once they have one address, they can guess the rest of your team's emails in seconds. That gives them targets for credential phishing, fake invoice scams, and CEO impersonation.

Email aliases reduce that exposure. An alias is an extra email address that delivers to the same inbox without exposing the real one. Microsoft 365 supports up to 400 aliases per mailbox. Google Workspace supports up to 30 per user. Both are free and built in.

A simple pattern that works for most small businesses:

- Use a public-facing alias for any address that lives on your website, business cards, and signup forms (info@, hello@, sales@). Keep your real email off public pages.
- Create vendor-specific aliases for major suppliers ([email protected], [email protected]). If one vendor leaks and you start seeing phishing on that alias, you know exactly which one.
- Use one tightly held internal email for sensitive operations like banking and payroll. That one stays off everything public.

If a phishing campaign hits one of your aliases tomorrow, you'll know which list you ended up on. You can shut that alias off without changing your main address.

A ransomware group called "The Gentlemen" is one of the fastest-growing names in cybercrime right now. You probably have...
07/08/2026

A ransomware group called "The Gentlemen" is one of the fastest-growing names in cybercrime right now. You probably haven't heard of them.

In April 2026, The Gentlemen accounted for roughly 10% of all logged ransomware attacks worldwide and climbed into the top three most active ransomware operations, alongside Qilin and DragonForce. One of their named victims that month was Adaptavist, an Atlassian platinum partner that serves thousands of business customers.

This shift matters because the names you might already know are out of the picture. LockBit, Conti, REvil, and Hive are all gone or rebranded after law enforcement crackdowns and infighting. The replacements use different aliases but the same tactics: phishing, credential theft, vulnerable VPN appliances, and unpatched servers. They encrypt your data and steal a copy to threaten you twice.

The good news is that the defense looks the same regardless of which group is hitting your industry. Five things work against all of them: patching CISA KEV systems within two weeks, MFA with number matching on internet-facing systems, immutable offsite backups that you actually test, security tools that watch for behavior instead of relying on known viruses, and phishing training that covers 2026 forms like QR codes, voice cloning, and fake CAPTCHA pages.

You can't keep up with which ransomware group is hot this month, and you don't have to. The defenses that work today will still work when The Gentlemen rebrand into something else next year.



Every Region Recorded Higher Attack Volumes in April In April 2026, global cyber-attack activity rebounded sharply following the brief moderation observed Global cyberattacks rose 10% in April 2026 as ransomware expanded and GenAI risks persisted. See key trends across sectors, regions, and industri...

06/08/2026

Most of the tools your team uses to get work done are probably not on your IT list.

Some examples: personal Dropbox accounts for client files, ChatGPT with confidential information pasted in, a Trello board the marketing team set up a year ago, a Notion workspace someone in operations runs from their phone. The name for all of this is shadow IT, and every business has more of it than you'd guess.

The risk shows up in two places. First, data that should live inside your business sits inside accounts you don't control and can't delete. When an employee leaves, the data stays where they put it. Second, none of those tools are configured with your security in mind. MFA settings are weak or off, and there's no data loss prevention, retention policy, or audit log to check when something goes wrong.

You don't need a top-down crackdown to fix this. Ask four questions in your next team meeting:

1. What software or web tool are you using this week that wasn't installed by IT?
2. Which one would slow your work down the most if it disappeared tomorrow?
3. Is any client or company data sitting in it?
4. Would you be embarrassed if it leaked in a breach?

Run the conversation as a fact-finding exercise. The helpful tools get sanctioned, the risky ones get replaced.

If you don't know what's running in your business, you can't protect it.

05/08/2026

Windows 10 hit end of life on October 14, 2025. Microsoft stopped sending free security updates that day.

Every new vulnerability discovered since then sits unpatched on every Windows 10 machine that isn't enrolled in Microsoft's paid Extended Security Updates program. The list grows every month. Attackers know exactly which versions of Windows have which holes, and they go after the easiest ones first.

If you still have Windows 10 machines in your business, you have three options.

Upgrade to Windows 11. Most computers made in the last 4 to 5 years can run it. The upgrade itself is free if your license is genuine. The main cost is the time to plan it. For most businesses this is the right answer.

Pay for Extended Security Updates. Microsoft sells ESU to businesses at $61 per device for year one. That price doubles in year two and again in year three. ESU keeps the patches coming, but the vulnerability count keeps climbing and you pay more each year to stay current.

Replace the hardware. If a computer can't run Windows 11, it's old enough that it was due for replacement anyway. The longer you wait, the more it costs you in lost productivity.

The one option that isn't on the list is keeping Windows 10 and hoping nothing happens.

04/08/2026

If someone asks whether your business has backups, you probably say yes. Disaster recovery is a different question.

A backup is a copy of your data. Disaster recovery is the plan that brings your business back to running condition after something goes wrong. The two get confused all the time, and the confusion costs real money when ransomware or a hardware failure hits.

A good backup setup follows the 3-2-1-1-0 rule: three copies of every important file, on two different types of storage, with one copy stored offsite, one copy that's immutable so ransomware can't encrypt it, and zero errors in your last test restore.

That last one is what most businesses skip. Untested backups are not backups.

They're an unverified promise.

Pick a normal file, an email, and a full server volume, then try to restore each one to a different location.

If the restore works, you have backups. If it doesn't, you have a problem you can fix today instead of during an attack.

Disaster recovery goes one layer further. It's the playbook for what your business does when it can't function. Things like which systems come back first, which people make decisions, which vendors get called, and how long each step is supposed to take. Without that playbook, even a working backup leaves you guessing during the worst week of your year.

In April 2026, ransomware hit Adaptavist, an Atlassian platinum partner that builds and supports tools for thousands of ...
03/08/2026

In April 2026, ransomware hit Adaptavist, an Atlassian platinum partner that builds and supports tools for thousands of business customers.

Adaptavist makes ScriptRunner and similar add-ons that plug into Atlassian products like Jira and Confluence. When attackers got into Adaptavist's systems, every customer connected to those tools was suddenly downstream of a breach they didn't cause.

This is the supply chain attack pattern. Your business doesn't have to be the target. It just has to share a vendor with the target.

Three things worth doing this month:

-Make a one-page list of every SaaS vendor your business depends on. Email, accounting, payroll, CRM, helpdesk, file storage, project management. The list is usually longer than you'd expect.
-For each vendor, find their security and breach notification page online. If you can't find it in five minutes, that's information worth knowing.
-For the top five vendors by data sensitivity, ask three questions in writing: do you have a current SOC 2 Type II report, what's your breach notification SLA, and how do you handle credentials inside your support tooling.

You can't control every vendor's security. Pick the ones that take it seriously.



: Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole

02/08/2026

Your incident response plan needs to live on paper, because the second you need it, your computers and email are the thing that's broken.

A one-page version beats nothing. The most important piece is the contact list, because those are the phone numbers you can't get to once your systems are down. Print this list and keep one copy at the office and one at home.

Six contacts to have on paper:

1. Your cyber insurance broker. They open the door to every other resource your policy covers. Save the after-hours line, not just the main number.
2. Your breach attorney. Not your business attorney. A specialist in cyber incidents. Their first job is to create legal privilege over the response.
3. Your incident response firm. If your insurance assigns one, save the IR firm's name and 24/7 line on this same page.
4. Your IT provider or MSP. Direct line for the senior engineer, not the front desk.
5. Law enforcement. FBI IC3 (1-800-CALL-FBI / ic3.gov) and your state cyber unit if you have one.
6. Two business lifelines. Your bank's fraud line and your payroll provider's emergency line. Both can freeze transactions if an attack is in progress.

Once ransomware locks your email and laptops, the only contact list you can reach is the one you printed.

Address

Unit 115a, The Mayford Centre
Woking
GU220PP

Opening Hours

Monday 9am - 5:30pm
Tuesday 9am - 5:30pm
Wednesday 9am - 5:30pm
Thursday 9am - 5:30pm
Friday 9am - 2pm

Telephone

+441483672610

Alerts

Be the first to know and let us send you an email when Onboard 365 LTD posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Onboard 365 LTD:

Shortcuts

Share