Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
RESEARCH 11 JUL 2026 · 3 MIN

A year of findings: what changed in 2025

Across the businesses we checked this year, three things moved. Multi-factor sign-in rose sharply, backup testing barely budged, and suppliers overtook devices as the weak point.

SARA MITCHELL · RESEARCH
SHARE LinkedIn X Email
RESEARCH cover image

This is not a survey with a headline percentage; it is what we saw across the businesses we actually worked with over the year, and we would rather be honest than precise. The clearest good-news trend was multi-factor sign-in. Where a couple of years ago it was the exception, it is now something most of the businesses we check have turned on for at least their email, often because a bank or an insurer nudged them into it. That is real progress and worth naming.

The stubborn one is backup testing. Nearly everyone has a backup; hardly anyone has ever restored from it. That number moved almost not at all this year, which tells us the message ‘have a backup’ has landed and the message ‘prove it works’ has not. It remains the gap most likely to turn a bad day into a lost business, and it is the cheapest of all to close.

The shift that surprised us was where the risk now sits. For years the weak point was the device - the unpatched laptop, the shared password, the phone with no lock. Those have genuinely improved. What has not kept pace is the supplier: the bookkeeper, the booking platform, the outsourced payroll. More of the incidents we saw this year traced back to something a third party held or did, not to the business's own kit.

None of this is cause for alarm, and it is certainly not a reason to buy more products. It is a reason to spend attention where the risk actually moved. If you did one thing off the back of a year of findings, restore a backup on purpose and write down that it worked. If you did two, ask your key suppliers the plain questions about what they hold and how fast they would tell you if it went wrong.

WHAT TO DO
  • ✓If MFA is only on your email, extend it to banking, payroll and cloud storage.
  • ✓Restore one backup on purpose this quarter and record that it worked.
  • ✓List your suppliers who touch data and ask each what they hold and their breach timeline.
  • ✓Stop buying tools to fix habits - book the time instead.