Scam alerts, practical guides and honest opinions - filtered to what’s relevant for you.
We found a 12-person practice 61 days from losing their web address with automatic renewal switched off.
Nothing to type, nothing to steal, nothing to phish. Where it's available today.
One deliberate restore, timed and written down, is the whole test.
August is when payment fraud works, because the person who would have questioned it is in Spain.
What do you hold, who else can see it, and how fast will you tell us if something goes wrong?
Payment approvals, out-of-office wording, device charging and who has the alarm code.
MFA coverage, backup testing and incident planning move the premium more than anything else.
Disable, convert the mailbox, move the files, collect the kit, log the date.
SIM swaps are rare but real. Move email and banking to an app or a passkey.
If your phone buzzes and you didn't ask it to, your password is already known.
Eleven things that cost nothing and close most of what we find.
Nobody wants one until the day someone leaves knowing the reception password.
Nine devices, no certificates, and still your liability until collected.
Updates, one restore check, one look at who has access. That's genuinely most of it.
Consent, deletion requests, and why “we asked at the time” isn't a record.
Reception, accounts, info@. Everyone knows it, nobody owns it, leavers keep it.
Old enquiries, ex-staff mailboxes and a shared drive from 2016.
January is when access sprawl starts. A ten-minute checklist stops it.
Fake networks, sign-in pages and the person reading your screen on the train.
Domain, email, second factor, backup, and one page for customers.