Category: Business IT

  • How Social Engineering Turns a Trusted Identity Into Payment Fraud

    How Social Engineering Turns a Trusted Identity Into Payment Fraud

    The most dangerous part of an online scam is often not the technology. It is the relationship the criminal constructs before asking for money or information.

    On 11 September 2026, Reuters reported that South Africa had agreed to extradite six alleged members of the Black Axe network to the United States. US authorities accuse them of wire fraud and money laundering connected to online romance scams that allegedly defrauded more than 100 victims. The accusations will still need to be tested through the legal process. Reuters’ report provides the case details.

    Romance scams and business payment fraud are not identical. The useful connection is the method: establish credibility, control communication, create urgency and convert trust into a transaction.

    A believable identity is not proof

    Criminals can assemble a persuasive profile from public websites, social media and leaked data. They may know a director’s name, the company’s suppliers and which employee processes payments.

    They can also compromise a real mailbox or messaging account. A message coming from the correct address therefore does not always mean the legitimate owner sent it.

    Staff should judge high-risk requests through an agreed process, not through confidence in the sender’s writing style or profile photograph.

    Slow down the transaction

    Social engineering often uses urgency: a payment must happen before close of business, the supplier’s bank account has suddenly changed, or an executive is “in a meeting” and cannot take a call.

    The business needs rules that remain in force when someone applies pressure. Require independent verification for:

    • New or changed banking details
    • Unusual payment destinations
    • Confidential payroll or customer records
    • MFA codes or login approvals
    • Requests to install remote-access software
    • Exceptions to normal approval limits

    Do not verify using the phone number supplied in the suspicious message. Use a trusted number already recorded in the accounting system, contract or official directory.

    Separate request, approval and payment

    Where practical, one person should not be able to receive a request, change supplier details and release the payment alone. Dual approval creates a second opportunity to notice an inconsistency.

    Record who confirmed the change, which number was called and when approval occurred. A clear audit trail helps staff follow the rule consistently rather than relying on memory.

    Protect the communication accounts

    Process controls work best with secure accounts. Enable multifactor authentication, use separate administrator accounts, remove former employees promptly and investigate unexpected forwarding rules or login alerts.

    Train employees to report mistakes immediately. If someone approved a suspicious login or sent information, a fast report gives administrators a better chance to revoke sessions and limit damage. Punishing the first person who reports a mistake teaches everyone else to hide the next incident.

    Respond quickly to suspected fraud

    Contact the bank immediately through an official channel, preserve messages and transaction information, and involve the IT provider to check whether email or other accounts were compromised. Obtain appropriate legal, insurance and law-enforcement guidance for the circumstances.

    RandTech IT helps South African SMEs secure Microsoft 365, investigate suspicious access and implement practical security-awareness procedures. Trust is essential to business, but payments and confidential data need verification that does not depend on trust alone.

  • Cloud Services Still Need a Business Continuity Plan

    Cloud Services Still Need a Business Continuity Plan

    The debate concerns national infrastructure and development policy, but it also highlights a simpler lesson for small businesses: “it is in the cloud” does not mean every dependency has disappeared.

    The Associated Press reported on 5 September that South Africa hosts a substantial portion of Africa’s data-centre capacity and that campaigners are challenging further hyperscale expansion. Reuters had previously reported approval and objections around proposed Equinix facilities in Cape Town on 28 July 2026.

    For an SME in Johannesburg, the immediate risk is usually not the hyperscale facility. It is the fibre line, router, office power, DNS, user account or laptop between the employee and the service.

    Map the full chain

    Ask what is required for staff to open email, process an order or help a customer.

    The chain may include:

    • Electricity to the office and network cabinet
    • Fibre or fixed-wireless connectivity
    • Router, firewall, switches and Wi-Fi access points
    • Microsoft 365 or another cloud provider
    • Multifactor authentication on an employee’s phone
    • A working, updated laptop
    • Access to files and passwords

    A highly resilient cloud platform cannot compensate for a router that switches off two minutes into an outage.

    Add connectivity failover carefully

    An LTE or 5G connection can keep essential users online when fibre fails, but only if it is configured and tested in advance. Confirm signal quality, data limits, network coverage and whether the router changes connections automatically.

    Failover should prioritise essential services. A software update or cloud backup can consume mobile data while accounts staff are trying to process payments. Appropriate firewall and traffic rules can preserve the link for email, voice and critical applications.

    Size backup power for the network

    Keeping laptops charged does not help when the fibre terminal, router and switch have no power. Identify every network component that must remain on, measure its load and set a realistic runtime objective.

    A UPS battery also degrades. Test it under load and replace it based on condition, not merely age or a green indicator light.

    Prepare a degraded way of working

    Business continuity is not always full restoration. It may mean allowing a smaller group to continue essential work while the main connection is repaired.

    Document who needs priority access, which phone hotspot may be used, how incoming calls are handled, and which files can be securely available offline. Avoid copying uncontrolled customer data onto personal devices as an emergency shortcut.

    Test the plan

    Disconnect the primary internet connection during a controlled window and observe what happens. Can users still authenticate? Does Teams calling work? Can the business reach cloud accounting and retrieve key documents? Record the gaps and repeat the test after remediation.

    RandTech IT helps Johannesburg businesses design and test internet failover, office-network UPS protection and Microsoft 365 continuity. The cloud removes many local server risks, but resilience still depends on the last kilometre—and on a plan that has been proved before the outage.

  • Windows 11 Bluetooth Problems: Fix the Cause Before Replacing Hardware

    Windows 11 Bluetooth Problems: Fix the Cause Before Replacing Hardware

    A wireless headset that stutters, a mouse that disconnects or a laptop that shows the wrong Bluetooth status can quickly become a daily frustration. The tempting response is to replace the accessory—or blame the entire computer.

    Microsoft is now testing several Windows 11 Bluetooth fixes, including improvements for inaccurate connection reporting, random disconnections, audio behaviour and some controllers. The changes appeared in a preview build reported on 12 September 2026. Because the fixes are still in preview, they should not be treated as a universal solution or installed casually on important business PCs. Windows Central’s report summarises the affected behaviours.

    First identify the pattern

    Good troubleshooting begins by describing exactly what fails.

    Does the problem affect one headset or every Bluetooth device? Does it happen only during Teams calls, after the laptop wakes from sleep or when connected to a docking station? Does the same headset work correctly with a phone?

    These observations separate four broad causes: the accessory, the computer’s Bluetooth hardware, drivers and Windows, or radio interference.

    Complete supported updates

    Install normal released Windows updates and manufacturer-approved driver or firmware updates. Restart the PC afterwards; shutdown and fast-start behaviour do not always produce the same clean reload.

    Avoid downloading drivers from random “driver update” websites. Use Windows Update, the laptop manufacturer’s support page or the hardware vendor’s official utility. An incorrect driver can make the problem less predictable and introduce security risk.

    Remove simple environmental causes

    Bluetooth and 2.4 GHz Wi-Fi share crowded radio space. USB 3 devices, hubs and poorly shielded cables can also contribute to interference.

    Test close to the computer, move wireless dongles away from USB hubs, temporarily disconnect unnecessary USB devices and compare performance on a different desk. If the issue occurs only in one physical location, replacing the headset may change nothing.

    Check power and application behaviour

    A laptop may reduce power to wireless hardware to save battery. The problem can therefore appear after sleep or only when unplugged.

    Also test outside the affected application. If music plays correctly but audio fails in Teams, confirm the selected speaker and microphone, Teams updates and whether another application has taken control of the device.

    Forget and re-pair the device only after recording any required PIN or configuration. Re-pairing can clear a damaged relationship, but repeated pairing without diagnosis merely resets the symptom.

    When hardware repair is justified

    Suspect the accessory when it fails with several computers or phones. Suspect the laptop when multiple known-good devices fail on that machine, especially if Wi-Fi problems or physical damage appeared at the same time.

    A technician can test with a known-good USB Bluetooth adapter. If the external adapter works reliably, the internal module, antenna, driver or motherboard connection deserves closer inspection.

    PC Warehouse diagnoses Windows, driver and hardware faults in Randburg before recommending replacement. RandTech IT can standardise headsets, drivers and meeting configurations across a business fleet.

    Do not spend money until you know which component is failing. A disciplined test can reveal whether the correct fix is a released update, a driver repair, a new dongle, a replacement headset or work on the laptop itself.

  • September 2026 Windows Update: What Businesses Must Do Now

    September 2026 Windows Update: What Businesses Must Do Now

    Microsoft’s September 2026 security release deserves more attention than an ordinary monthly update. Published on 8 September, it addresses an exceptional number of vulnerabilities across Windows and other Microsoft products. Technical analyses count roughly 970 Microsoft vulnerabilities, with two already known to be exploited; totals vary slightly depending on how products and CVEs are counted.

    For a South African SME, the important question is not whether the headline says 972 or 974. It is whether every supported business computer receives the right updates, restarts successfully and continues to run the applications on which staff depend.

    Why this update matters

    Security updates close weaknesses that attackers can use for activities such as running code, gaining higher privileges or bypassing protections. Once a vulnerability and its fix become public, criminals can study the change and look for organisations that have not yet patched.

    Microsoft’s Windows message centre confirms that the September security update is available for supported Windows versions. Rapid7’s technical review records the unusually large release and the known exploitation status.

    Installing promptly matters, but “promptly” should still be controlled. Applying a large update to every device simultaneously can turn one compatibility problem into a company-wide interruption.

    Use a staged deployment

    A small business does not need enterprise-scale infrastructure to patch sensibly. Start with one or two representative PCs: an ordinary office workstation, a laptop used remotely and, where relevant, a machine running specialist software.

    Check that the pilot devices can:

    • Start and sign in normally
    • Connect to printers, scanners and shared folders
    • Open Outlook, Teams and Microsoft 365 apps
    • Run accounting, payroll and industry software
    • Use VPN and remote-access tools
    • Complete endpoint-security scans
    • Restart without requesting an unavailable BitLocker key

    If the pilot is healthy, deploy to the remaining devices in manageable groups.

    Confirm the update actually installed

    Clicking “Check for updates” is not proof of completion. A computer may have insufficient free space, a damaged Windows Update component, a pending restart or an unsupported Windows version.

    After deployment, record the Windows version, installed update and last successful update date. Investigate devices that have stopped checking in or repeatedly roll back an update. They are often the machines most exposed when a vulnerability is actively exploited.

    Prepare for recovery before restarting

    Before major maintenance, verify that important files are backed up and that BitLocker recovery information can be retrieved. Firmware and security-related changes can occasionally trigger a recovery prompt. The right moment to discover that nobody has the key is before the restart, not while an employee is locked out.

    Keep a rollback and support plan for business-critical machines. Do not erase or reinstall a device merely because one update fails; preserve data and diagnose the cause first.

    Patching is an ongoing service, not a monthly click

    The size of September’s release is a useful reminder that patch management includes inventory, testing, deployment, monitoring and evidence. Antivirus cannot protect an unpatched operating system from every known weakness.

    RandTech IT helps Johannesburg SMEs monitor Windows updates, test critical changes and remediate computers that have fallen behind. If you are unsure whether every company PC installed September’s security fixes, arrange a patch-health review before the gap becomes an incident.

  • Windows 11 26H2: A Business Upgrade Guide

    Windows 11 26H2: A Business Upgrade Guide

    Windows 11 version 26H2 has moved into Microsoft’s Release Preview Channel, bringing the next annual Windows feature update close enough for businesses to begin preparation.

    This does not mean every employee should install a preview build. Release Preview is still a testing stage. It means IT providers and software vendors can now validate the near-final update against real business workloads before general deployment.

    Microsoft announced Release Preview availability on 27 August 2026 and says 26H2 uses the shared servicing model of recent Windows 11 releases. For eligible PCs already on a recent version, the eventual update should be lighter than a full operating-system replacement. See Microsoft’s 26H2 Release Preview announcement.

    Do not install previews on production computers

    A production PC is one whose failure would interrupt normal work. Accounts, reception, claims and management laptops are poor places to test unfinished software.

    Use a spare machine or a controlled IT test device that resembles the company’s normal hardware. Back it up, document its applications and confirm that it can be restored.

    What businesses should test

    The Windows desktop may look familiar after the upgrade while a small compatibility issue breaks an essential workflow. Test the work, not merely the login screen.

    Check:

    • Accounting, payroll and line-of-business applications
    • Outlook profiles, shared mailboxes and add-ins
    • Teams audio, cameras and meeting-room equipment
    • Printers, scanners, label printers and signature pads
    • VPN, remote desktop and support agents
    • Endpoint protection, backup and encryption software
    • Network drives and SharePoint synchronisation
    • Sleep, docking stations and multiple monitors

    Record the exact software and driver versions. “It worked on my laptop” is not a rollout plan when the finance team uses different printers and add-ins.

    Check device eligibility and health

    An eligible Windows 11 PC can still be a poor upgrade candidate if it is short of storage, already unstable or using outdated firmware. Review free disk space, Windows Update health, BIOS/UEFI updates, TPM and Secure Boot status, drive health and BitLocker recovery-key availability.

    Do not bypass Microsoft’s hardware requirements on critical business PCs simply to force the newest version. Unsupported configurations can create security, update and support problems later.

    Build a staged rollout

    Start with an IT test device, then a small pilot group of users who can report problems clearly. Expand by department only after the pilot has completed normal work for an agreed period.

    Plan maintenance windows and make sure urgent support is available after the first production rollout. Keep senior decision-makers informed about genuine blockers rather than treating every cosmetic change as a reason to delay indefinitely.

    Upgrade readiness is also replacement planning

    The inventory may reveal computers that are technically compatible but no longer economical to maintain. A slow machine with a healthy processor may benefit from RAM or an SSD; an unreliable device with battery, hinge and motherboard problems may be better replaced.

    RandTech IT can assess a business’s Windows fleet, test 26H2 compatibility and manage a staged deployment. PC Warehouse can diagnose and upgrade suitable machines or provide correctly specified replacements.

    Prepare now, but wait for the supported general release before normal business deployment. A short pilot protects far more time than an untested company-wide click.

  • Why a Slow PC May Need an SSD, Not Replacement

    Why a Slow PC May Need an SSD, Not Replacement

    Why a Slow PC May Need an SSD, Not Replacement

    A computer that takes several minutes to start, freezes while opening applications and becomes unresponsive during updates may appear to have reached the end of its life.

    In many cases, the real bottleneck is an old mechanical hard drive.

    Replacing that drive with a solid-state drive can dramatically improve startup times, application loading and everyday responsiveness. For a suitable computer, an SSD upgrade can provide several more years of useful service at a fraction of the cost of replacement.

    Why traditional hard drives feel slow

    A mechanical hard disk stores information on spinning platters and uses a moving read-and-write head to access it. This design works well for inexpensive bulk storage, but it is relatively slow when Windows needs to access thousands of small files.

    A solid-state drive has no moving parts. It can retrieve information far more quickly, which is particularly noticeable when:

    • Windows starts
    • Outlook opens
    • Applications launch
    • Updates install
    • Files are searched
    • Several tasks run simultaneously

    An SSD will not turn every old PC into a high-performance workstation, but it can remove one of the most common performance bottlenecks.

    Signs the hard drive may be the problem

    Possible indicators include:

    • Disk usage repeatedly reaching 100%
    • Extremely slow startup
    • Delays when opening folders
    • Freezing during Windows updates
    • Clicking or unusual mechanical sounds
    • File errors or corrupted data
    • Applications becoming unresponsive while the disk is busy

    A failing hard drive is more than a performance problem. It can also become a data-recovery emergency, so unusual sounds and file errors should be investigated promptly.

    When an SSD upgrade makes sense

    An upgrade is usually worth considering when:

    • The processor still meets the user’s needs
    • The computer has enough RAM or can be upgraded
    • The motherboard, screen and hinges are healthy
    • The machine supports the required operating system
    • The total upgrade cost is well below replacement cost
    • The device is otherwise reliable

    A good-quality business laptop with an older hard drive may be a better upgrade candidate than a low-cost new laptop with weaker construction.

    When an SSD will not solve the problem

    Storage is only one component.

    An SSD cannot repair a damaged motherboard, overheating processor, broken hinge or unsuitable amount of RAM. It also cannot make an unsupported computer appropriate for critical business use indefinitely.

    Before approving an upgrade, a technician should evaluate the complete device, including:

    • Drive health
    • RAM usage
    • Processor performance
    • Cooling system
    • Battery condition
    • Windows compatibility
    • Physical condition
    • Backup status

    This prevents customers from spending money on one improvement when several expensive repairs are approaching.

    Cloning versus a clean installation

    An existing hard drive can sometimes be cloned onto the SSD, preserving Windows, applications and settings. This is convenient when the current installation is healthy.

    A clean Windows installation may be preferable when the old system contains corruption, unwanted software or years of accumulated problems. User data must be backed up and verified before either process begins.

    The correct method depends on the condition of the original drive and the customer’s software requirements.

    Diagnose before replacing

    PC Warehouse and RandTech IT provide computer diagnostics, SSD upgrades, data migration and replacement advice in Randburg and Johannesburg.

    We assess the complete machine and explain whether repair, upgrade or replacement offers the best value. If the device is worth saving, an SSD can be one of the most noticeable upgrades available.

    Before replacing a frustratingly slow computer, have it tested. The machine may not be finished—it may simply be waiting for its slowest component to be replaced.

  • Business Email Compromise: The Invoice Scam Targeting SMEs

    Business Email Compromise: The Invoice Scam Targeting SMEs

    Business Email Compromise: The Invoice Scam Targeting SMEs

    A supplier sends an email advising that its banking details have changed. The address appears correct, the invoice looks familiar and the message refers to a genuine project.

    The accounts department processes the payment. Days later, the real supplier asks why the account remains unpaid.

    This is business email compromise, commonly abbreviated to BEC. It is one of the most financially damaging forms of cybercrime because it exploits trusted relationships and normal business processes rather than relying only on malicious attachments.

    How the scam works

    Criminals may use several methods.

    They can register a domain that closely resembles the supplier’s real address. They may compromise the supplier’s mailbox and send messages from the genuine account. In other cases, they access the customer’s email and monitor correspondence until the correct moment to insert fraudulent payment instructions.

    Because the criminals have observed real conversations, they may know:

    • The supplier’s name
    • Which employee handles payments
    • The expected invoice amount
    • The project being discussed
    • When payment is due
    • The wording normally used in emails

    The message can therefore look completely legitimate.

    Why antivirus may not stop it

    A BEC message may contain no virus, malicious attachment or obvious phishing link. It may simply provide different banking details on a modified invoice.

    Traditional antivirus has little to detect. The most effective control is a combination of account security and a strong payment-verification process.

    Warning signs to watch for

    Treat these situations with caution:

    • New banking details
    • An unexpected request for urgent payment
    • Pressure to keep the transaction confidential
    • A subtle change in the sender’s domain
    • A reply-to address that differs from the sender
    • An invoice that looks slightly different
    • A request to bypass normal approval
    • Unusual timing or writing style
    • Claims that the supplier’s phone is unavailable

    A correct-looking email address is not absolute proof. A genuine mailbox may be compromised.

    Verify through an independent channel

    Every bank-detail change should be verified using contact information already held by the business.

    Do not phone the number included on the new invoice or in the suspicious email. Retrieve the supplier’s established number from your accounting records, original agreement or trusted website.

    The person verifying the change should record:

    • Who was contacted
    • Which trusted number was used
    • Who confirmed the details
    • The date and time
    • Whether a second person approved the payment

    The same procedure should apply to executives and long-standing suppliers. Familiarity is exactly what the criminal is exploiting.

    Secure the email environment

    Businesses should also:

    • Enable multifactor authentication
    • Protect administrator accounts
    • Review suspicious mailbox rules
    • Remove access belonging to former employees
    • Configure domain-authentication protections
    • Monitor unusual logins
    • Train finance staff using realistic examples
    • Use dual approval for significant payments

    If fraud is discovered, immediately contact the bank, IT provider and appropriate authorities. Speed may affect whether funds can be traced or frozen.

    RandTech IT helps South African SMEs secure Microsoft 365, investigate suspicious mailbox activity and implement practical anti-phishing controls.

    A professional-looking invoice is not proof of authenticity. When banking details change, pause the payment and verify the request independently. A two-minute phone call can prevent a loss that takes months—or longer—to resolve.

    Reference: INTERPOL guidance on business email compromise

  • POPIA and AI: Can Staff Paste Client Data Into ChatGPT?

    POPIA and AI: Can Staff Paste Client Data Into ChatGPT?

    POPIA and AI: Can Staff Paste Client Data Into ChatGPT?

    Employees are increasingly using ChatGPT, Microsoft Copilot, Claude and other generative-AI tools to summarise documents, draft correspondence and analyse information.

    The productivity benefits can be substantial. The risk appears when staff paste client records, identity documents, contracts, financial information or confidential company data into an AI service without understanding where that information goes.

    Under South Africa’s Protection of Personal Information Act, a business remains responsible for personal information under its control. Using a convenient AI tool does not remove that responsibility.

    What information should concern businesses?

    Potentially sensitive prompts may contain:

    • Customer names and identity numbers
    • Contact and address information
    • Medical or insurance information
    • Banking and payment details
    • Employee disciplinary records
    • Contracts and legal correspondence
    • Passwords or security configurations
    • Confidential pricing and proposals
    • Proprietary source code
    • Information received under a non-disclosure agreement

    Even when a task seems harmless, the surrounding document may contain far more information than the employee intended to share.

    Is using AI automatically a POPIA violation?

    No. AI use is not automatically unlawful, and the answer depends on the service, configuration, contract, purpose and information involved.

    However, the business should establish whether it has a lawful basis for processing the data, whether the use is compatible with the original purpose, whether adequate security safeguards exist and whether information may be processed outside South Africa.

    The organisation must also consider contractual confidentiality—not only POPIA. A client agreement may prohibit disclosure to an unapproved third party even if the information does not meet a narrow definition of personal information.

    Consumer and enterprise AI are not identical

    AI products may offer different privacy and data-handling terms depending on the plan being used.

    An enterprise service configured through an approved company tenant may provide stronger controls than an employee’s personal free account. Features can include administrative management, access controls, contractual protections and limitations on using business data for model training.

    That does not mean every enterprise AI prompt is automatically safe. The business must still control access, minimise information and configure the service correctly.

    Adopt a simple staff rule

    Until a tool has been formally approved, employees should not paste personal, confidential or client-identifiable information into it.

    Where AI assistance is appropriate, staff can often remove or replace sensitive information. For example:

    • Replace names with “Client A”
    • Remove identity and account numbers
    • Exclude signatures and contact details
    • Summarise the relevant facts instead of uploading the full file
    • Use fictional figures when testing a calculation
    • Paste only the paragraph needed for editing

    Redaction should be performed before information reaches the AI tool.

    What should an AI policy include?

    A practical workplace AI policy should define:

    • Approved tools and accounts
    • Prohibited information
    • When redaction is required
    • Who may upload documents
    • Human review requirements
    • Rules for generated legal, financial or technical advice
    • Retention and record-keeping
    • Incident reporting
    • Approval for new AI services

    Staff also need short, realistic training. A policy hidden in a folder will not change daily behaviour.

    Use AI deliberately

    RandTech IT helps South African businesses assess AI tools, secure Microsoft 365 environments and develop practical usage policies that balance productivity with privacy.

    Generative AI can be enormously useful, but convenience should not bypass client confidentiality. Before pasting business information into an AI prompt, employees should ask: is this tool approved, is this data necessary, and can the request be completed without identifying the person?

    For formal compliance decisions, businesses should also obtain advice from a qualified privacy or legal professional.

    Reference: South African Information Regulator

  • How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    How Often Should a Business Test Its Backups?

    A business should test important file restores at least quarterly and conduct a broader recovery exercise at least once a year. Higher-risk businesses may need monthly restore tests and more frequent disaster-recovery exercises.

    There is no universal schedule for every organisation. The correct frequency depends on how quickly information changes, how costly downtime would be and whether the business handles regulated or highly sensitive data.

    The central principle is simple: a successful backup notification does not prove that the business can recover.

    Why backups fail when they are needed

    A backup job may display a green status while still failing to protect the information the business considers critical.

    Common problems include:

    • Important folders were never selected
    • A new server or SharePoint site was not added
    • Backup credentials expired
    • Storage reached its capacity
    • Files were already corrupted before being copied
    • The backup is encrypted by the same ransomware
    • Nobody knows the recovery password
    • Restore instructions are outdated
    • The available internet connection is too slow for timely recovery

    These problems are often discovered only when someone urgently needs the data.

    Use more than one type of test

    Backup testing should happen at several levels.

    Monthly automated review

    An IT provider should review failed jobs, warnings, storage capacity and devices that have stopped reporting. This is monitoring rather than a complete recovery test, but it catches obvious problems early.

    Quarterly sample restores

    Restore several representative items, such as:

    • An email
    • A OneDrive folder
    • A SharePoint document
    • An accounting-data file
    • A folder from a server
    • Data belonging to a former employee

    Confirm that the restored information opens correctly and that its permissions and dates are usable.

    Annual recovery exercise

    At least once a year, simulate a more serious outage. Assume a server, primary storage system or Microsoft 365 administrator account is unavailable.

    Measure how long it takes to rebuild access and restore priority services. The exercise should expose unclear responsibilities, missing passwords and unrealistic recovery expectations.

    Businesses that cannot tolerate several hours of downtime should test more frequently.

    Define what must return first

    Not every file has the same operational value.

    An architectural practice may prioritise active project files. A brokerage may need client records, policy documents and email. A retailer may need point-of-sale data and supplier information.

    Your recovery plan should identify:

    • The most critical systems
    • The order in which they must be restored
    • The maximum acceptable data loss
    • The maximum acceptable downtime
    • Who can authorise a recovery
    • Where passwords and encryption keys are stored
    • How staff will work during the outage

    A test should measure performance against these requirements.

    Test Microsoft 365 as well

    Many SMEs back up a local server but overlook Exchange Online, OneDrive, SharePoint and Teams.

    Microsoft provides resilient infrastructure and native recovery tools, but businesses should understand their configuration and recovery limits. Independent Microsoft 365 backup can provide another recovery layer, particularly where deletion or compromise is discovered late.

    Testing should include the restoration of individual cloud files, folders and emails.

    Record and improve every test

    Document what was restored, how long it took and which problems occurred. Assign corrective actions and repeat failed tests.

    RandTech IT helps South African businesses implement monitored backups, test Microsoft 365 and local-data recovery, and create practical disaster-recovery plans.

    If your business has never completed a recorded restore test, you do not yet know whether you have a working backup. Schedule the test before a real emergency sets the deadline for you.

    Source: CISA’s ransomware and backup guidance

  • Is Microsoft Defender Enough for a Small Business?

    Is Microsoft Defender Enough for a Small Business?

    Is Microsoft Defender Enough for a Small Business?

    Microsoft Defender Antivirus is included with modern Windows computers and provides credible protection against many common threats. For a home user or a very small business with basic requirements, that makes it a useful security foundation.

    The important word, however, is foundation.

    Cybersecurity involves far more than scanning downloaded files for viruses. A business must also protect email accounts, administrator credentials, cloud data, remote access, backups and the devices employees use outside the office.

    Microsoft Defender Antivirus can form part of that protection, but the free built-in component should not be mistaken for a complete managed security service.

    What Microsoft Defender Antivirus does

    The antivirus component built into Windows can detect and block many forms of malware, suspicious files and potentially unwanted applications. It receives threat-intelligence and security updates through Microsoft.

    It also works with Windows security features such as:

    • Firewall protection
    • SmartScreen reputation checks
    • Tamper protection
    • Controlled folder access
    • Cloud-delivered protection
    • Secure Boot
    • Device encryption and BitLocker

    The effectiveness of these controls depends on whether they are enabled, correctly configured and monitored.

    A security feature that has been disabled for six months provides little protection, even if its icon still appears in Windows.

    Antivirus cannot solve every security problem

    Many modern attacks do not begin with a traditional virus.

    A criminal may steal a Microsoft 365 password through a fake login page, convince an employee to approve an MFA request or compromise a supplier’s genuine email account. An accounts employee could then receive a convincing request to pay an invoice into a different bank account.

    Antivirus may have nothing malicious to scan in these situations.

    It also cannot independently ensure that:

    • Backups are completing successfully
    • Deleted Microsoft 365 data can be restored
    • Former employees no longer have access
    • Shared administrator passwords have been eliminated
    • Suspicious mailbox-forwarding rules are detected
    • Computers receive patches on time
    • Staff verify payment-detail changes
    • An incident-response plan exists

    These protections require additional technology, configuration and human procedures.

    Defender Antivirus and Defender for Business are different

    Microsoft uses the Defender name across several products, which can cause confusion.

    Microsoft Defender Antivirus is the endpoint antivirus included with Windows. Microsoft Defender for Business adds business-focused endpoint detection, investigation and management capabilities and is included with certain Microsoft 365 subscriptions or available separately.

    A managed endpoint platform can provide central visibility across company computers. It helps an IT provider identify vulnerable devices, investigate alerts and respond when suspicious behaviour appears.

    Simply seeing “Microsoft Defender is on” does not establish that the device is centrally monitored.

    Small businesses need layered protection

    A sensible SME security baseline should include:

    • Centrally managed endpoint protection
    • Multifactor authentication
    • Separate administrator accounts
    • Microsoft 365 security monitoring
    • Prompt Windows and application patching
    • Independent backups
    • Regular recovery testing
    • Email and phishing controls
    • Staff awareness training
    • A documented incident-response process

    The correct combination depends on the business’s information, regulatory responsibilities and tolerance for downtime.

    Start with an assessment

    Installing multiple security products without a plan can cause conflicts while leaving important gaps untouched.

    RandTech IT helps South African SMEs assess Microsoft Defender, Microsoft 365, endpoints, backups and identity controls. We can determine whether built-in protection is appropriate, whether Defender for Business or another managed endpoint platform is required, and which security gaps need priority.

    Microsoft Defender is a strong starting point. For a business holding customer information and relying on its computers every day, it should be one part of a monitored, layered security strategy—not the entire strategy.

    Source: Microsoft Defender for Business documentation