Category: Business IT

  • How to Recognise AI-Generated Phishing Emails in 2026

    How to Recognise AI-Generated Phishing Emails in 2026

    How to Recognise AI-Generated Phishing Emails in 2026

    “Look for bad spelling” is no longer enough to protect a business from phishing.

    Generative AI can produce professional emails with correct grammar, convincing formatting and a tone that sounds like a supplier, manager or colleague. Criminals can combine AI with information from websites, LinkedIn profiles, data breaches and previous email compromises to create highly believable messages.

    INTERPOL’s 2026 African Cyberthreat Assessment says artificial intelligence is enabling cybercrime across Africa to become faster, more scalable and increasingly sophisticated.

    Employees therefore need to judge an email by its request and context—not simply by how well it is written.

    AI makes personalisation easier

    A criminal can quickly gather names, job titles, suppliers and current projects from public sources. AI can then turn that information into a message aimed at one specific employee.

    For example, an accounts user may receive a message appearing to come from a known supplier, explaining that its banking details have changed. A manager may receive a realistic Microsoft 365 login alert. An employee may hear a voice note that resembles an executive asking for an urgent payment.

    The individual details may be accurate even when the request is fraudulent.

    Warning signs still exist

    AI-generated phishing may be polished, but criminals still need the recipient to perform an action. Focus on that action.

    Be suspicious when a message requests:

    • An urgent or confidential payment
    • A change to supplier banking details
    • Login through an unexpected link
    • An MFA code or approval
    • Confidential customer or employee information
    • Installation of remote-access software
    • Purchase of vouchers or gift cards
    • Bypassing the normal approval process
    • Opening an unexpected shared document

    Urgency, secrecy and unusual procedure are stronger indicators than spelling mistakes.

    Check the sender carefully

    A displayed name can be copied easily. Examine the full email address and domain.

    Criminals may use a lookalike domain containing an extra letter, substituted character or different ending. An email may also come from a legitimate account that has been compromised, so a correct address is not absolute proof.

    Do not use the phone number or contact details included in the suspicious message to verify it. Use a number already held in your records or speak to the person directly.

    Treat login links with caution

    Fake Microsoft 365 pages can closely resemble the real sign-in screen. Some attacks also relay authentication in real time or attempt to trick users into approving an MFA request.

    Instead of clicking an unexpected email link, open the service through a saved bookmark or enter the known address manually. Never provide an MFA code to another person or approve a login you did not initiate.

    If a user enters credentials into a suspicious page, report it immediately. Quick action may allow administrators to reset the password, revoke active sessions and investigate before the account is used against customers or colleagues.

    Introduce a second-channel verification rule

    Every business should have a rule for high-risk requests:

    Changes to banking details, unusual payments and requests for confidential records must be confirmed through a second trusted channel.

    A phone call to a known number may feel inconvenient, but it can prevent a major loss. The verification process should apply regardless of whether the email appears to come from the CEO or a long-standing supplier.

    Technology and training must work together

    Email filtering, endpoint security and MFA remain important. However, no filter can guarantee that every well-crafted message will be blocked.

    RandTech IT helps South African businesses strengthen Microsoft 365 security, review suspicious email activity and train employees using realistic examples.

    The new rule is simple: do not trust an email because it looks professional. Verify the identity, request and procedure before money, passwords or sensitive information leave the business.

    Source: INTERPOL’s 2026 African Cyberthreat Assessment

  • ARM Laptops in South Africa: What Business Buyers Should Know

    ARM Laptops in South Africa: What Business Buyers Should Know

    ARM Laptops in South Africa: What Business Buyers Should Know

    A Windows laptop is no longer guaranteed to contain an Intel or AMD processor.

    A growing number of premium Windows devices now use ARM-based processors, particularly Qualcomm Snapdragon chips. These laptops often promise long battery life, low heat, quiet operation and built-in AI-processing capability.

    They can be excellent devices, but businesses should not buy them based on battery-life claims alone. The processor architecture can affect application, driver and peripheral compatibility.

    What is an ARM laptop?

    Most traditional Windows computers use the x64 processor architecture associated with Intel and AMD. ARM processors use a different architecture designed around power efficiency.

    ARM chips already dominate smartphones and tablets. Apple’s move to its own ARM-based M-series processors also demonstrated that the architecture can deliver strong laptop performance.

    Microsoft and its hardware partners are now expanding Windows on ARM through modern Snapdragon-powered Copilot+ PCs.

    Do normal Windows applications work?

    Many popular applications now offer native ARM versions. Others can run through Windows emulation, which translates traditional x86 or x64 software for the ARM processor.

    For mainstream browser, email, video-call and Microsoft 365 work, compatibility is increasingly good. Microsoft has invested heavily in its Prism emulation technology, while more developers are releasing ARM-native applications.

    The risk lies in specialist or older software.

    A program may install but perform poorly, while another may refuse to run. Applications that depend on particular drivers, low-level security components or uncommon hardware can present greater problems than ordinary productivity software.

    What should businesses test?

    Before standardising on ARM laptops, check:

    • Accounting and payroll applications
    • VPN and remote-access software
    • Endpoint security and monitoring agents
    • Printer and scanner drivers
    • Label printers and specialised USB devices
    • Document-management add-ins
    • Industry-specific applications
    • Legacy database clients
    • Microsoft Outlook add-ins
    • Backup and encryption tools

    A list stating that an application “supports Windows 11” is not enough. Confirm that the exact version supports Windows 11 on ARM.

    Who benefits most?

    ARM laptops can be a strong choice for executives, consultants and mobile staff who spend most of their time in Microsoft 365, web applications, Teams and cloud platforms.

    These users may benefit from:

    • Longer practical battery life
    • Instant or near-instant wake
    • Quiet operation
    • Lower heat output
    • Strong portability
    • Modern AI-assisted features

    They are less suitable where the user depends on specialist peripherals, legacy applications or technical tools that have not been tested on ARM.

    New hardware can still have software problems

    A premium laptop may appear faulty when the real problem is application compatibility or an incomplete software update.

    Microsoft has previously documented cases in which Teams and New Outlook could fail on certain freshly configured ARM devices until the relevant Microsoft Store updates were installed. This highlights the importance of completing Windows, driver and Store updates during setup.

    Reinstalling Windows or exchanging the laptop should not be the first response to every application failure.

    Buy for the workload—not the marketing label

    ARM is not automatically better or worse than Intel or AMD. It is a different platform with meaningful advantages and specific compatibility considerations.

    A business purchasing ten laptops should test one device with its real applications, printers, VPN, security software and shared mailboxes before completing the rollout.

    RandTech IT helps South African businesses compare laptops, verify software compatibility and configure new devices for Microsoft 365, security and data access.

    The right ARM laptop can be an excellent mobile business machine. The wrong one can become an expensive compatibility experiment. A short assessment before purchase is far cheaper than discovering a critical application does not work after deployment.

    Source: Microsoft’s Windows on ARM overview

  • New Outlook vs Classic Outlook: Which Is Better for Business?

    New Outlook vs Classic Outlook: Which Is Better for Business?

    New Outlook vs Classic Outlook: Which Is Better for Business?

    Microsoft is progressively moving Windows users towards New Outlook, but that does not mean every business should switch every employee immediately.

    New Outlook offers a modern interface and a more consistent experience across Outlook on the web and Windows. Classic Outlook remains the established desktop application used by organisations with complex mailbox configurations, legacy add-ins and specialised workflows.

    Microsoft says existing Classic Outlook installations will remain supported until at least 2029. Businesses therefore have time to evaluate the change instead of treating every upgrade prompt as an emergency.

    What New Outlook does well

    New Outlook provides a cleaner interface and receives many of Microsoft’s newest cloud-connected features. Users familiar with Outlook on the web may find the layout easier to understand.

    Potential benefits include:

    • A consistent experience between the browser and Windows application
    • Simplified account and settings management
    • Modern search and calendar features
    • Easier integration with Microsoft’s online services
    • Reduced dependence on some traditional local Outlook components
    • Ongoing feature development from Microsoft

    For users who mainly send email, manage a calendar and work with one or two straightforward mailboxes, New Outlook may be entirely suitable.

    Why some businesses still need Classic Outlook

    Classic Outlook has existed for decades and supports a wide range of mature business workflows.

    A business may need to remain on Classic Outlook where users rely on:

    • Legacy COM add-ins
    • Specialist accounting or document-management integrations
    • Complex shared-mailbox workflows
    • PST files and established archive processes
    • Advanced offline access
    • Custom forms, macros or automation
    • Features that are not yet equivalent in New Outlook

    Compatibility continues to improve, but an apparently small missing feature can have a large operational effect if it sits inside a daily process.

    Shared mailboxes need careful testing

    Many South African SMEs use shared mailboxes for accounts, claims, sales, support or general enquiries.

    Before migration, test how users open the mailbox, send from its address, search older messages, use categories and manage signatures or delegated calendars. Do not assume that a workflow behaves identically merely because the mailbox appears in both applications.

    Businesses with several large shared mailboxes should also review permissions and caching. In Classic Outlook, automatically caching multiple shared mailboxes can produce very large OST files, consume disk space and cause confusing “mailbox full” or synchronisation symptoms even when the server mailbox is not full.

    Can users switch between them?

    In many current installations, users can try New Outlook and return to Classic Outlook. Microsoft’s rollout phases and available controls depend on the Microsoft 365 licence and update channel.

    IT administrators should manage the transition centrally where possible. Allowing each user to switch independently can create inconsistent interfaces, duplicated support work and uncertainty about which features should be available.

    Test before standardising

    A sensible migration process should:

    1. Document important Outlook workflows and add-ins
    2. Select a small pilot group
    3. Test shared mailboxes, printing, search and offline access
    4. Confirm line-of-business integrations
    5. Train users on changed layouts
    6. Keep a controlled fallback path
    7. Expand deployment only after the pilot succeeds

    The best Outlook version is the one that supports the user’s real work reliably.

    RandTech IT helps businesses troubleshoot Outlook, optimise shared-mailbox configurations and plan controlled New Outlook deployments.

    If your staff are receiving prompts to change Outlook, do not click through blindly or block the change forever. Test the new application against your business processes, identify genuine compatibility gaps and move when the organisation is ready.

    Source: Microsoft’s New Outlook adoption guidance

  • What to Do After a Ransomware Attack: An SME Response Guide

    What to Do After a Ransomware Attack: An SME Response Guide

    What to Do After a Ransomware Attack: An SME Response Guide

    A ransomware incident rarely begins with a dramatic message appearing on every screen. The first warning may be a user unable to open a document, a shared folder containing strangely renamed files or a computer suddenly running unusual processes.

    What happens during the next hour can determine whether the incident affects one computer or spreads across the business.

    South African SMEs should have a simple ransomware response plan that employees and decision-makers can follow without improvising under pressure.

    1. Isolate affected devices

    Disconnect a suspected computer from wired and wireless networks as quickly as possible. Remove its network cable or disable Wi-Fi, but do not immediately erase, reset or reinstall it.

    If several devices show similar symptoms, disconnect affected network segments and shared storage where practical. The objective is to limit further encryption, data theft and movement between computers.

    Do not continue opening files to test whether they work. Every additional action may spread damage or overwrite useful evidence.

    2. Contact your IT and security provider

    Treat the event as a security incident rather than an ordinary computer fault.

    Your provider needs to determine:

    • Which users and devices are affected
    • Whether administrator credentials may be compromised
    • Whether files are still being encrypted
    • Whether Microsoft 365 or other cloud accounts were accessed
    • Whether data may have been stolen
    • Whether backups remain safe
    • How the attacker gained access

    Modern ransomware incidents may include data theft before encryption. Restoring files alone does not establish that the threat has been removed.

    3. Protect identities and administrative access

    If account compromise is suspected, passwords and sessions may need to be reset from a known-clean device. Administrative accounts, remote-access tools, VPN credentials and Microsoft 365 access should receive priority.

    Simply changing one employee’s password may be insufficient. Attackers sometimes create forwarding rules, add authentication methods or establish alternative accounts that allow them to return.

    Security changes should be coordinated carefully so the response team does not accidentally lose access to essential evidence or recovery systems.

    4. Preserve evidence

    Keep affected devices, ransom notes, suspicious emails, timestamps and security logs. Take photographs or screenshots where appropriate, but do not interact unnecessarily with malicious files.

    Evidence can help establish the entry point, scope of the incident and whether personal information was affected. This may also be important for cyber-insurance claims, regulatory obligations and law-enforcement reporting.

    Where personal information may have been compromised, the business should obtain appropriate POPIA and legal guidance regarding notification requirements.

    5. Verify backups before restoring

    Do not reconnect backup drives or begin restoring data until the environment has been assessed.

    A backup connected too early could also be encrypted or contaminated. The recovery team should confirm that the backup predates the attack, remains isolated and can be restored into a clean environment.

    Recovery should follow business priorities. Email, accounting, customer records and operational systems may need to be restored in a planned sequence.

    Should a business pay the ransom?

    Paying does not guarantee that criminals will provide a working decryption key, delete stolen information or avoid attacking again. Payment may also create legal, ethical and insurance complications.

    This decision should not be made impulsively. Obtain specialist incident-response, legal and insurance advice based on the exact circumstances.

    Prepare before the attack

    The best time to decide who disconnects systems, contacts the insurer and authorises recovery is before ransomware is discovered.

    RandTech IT helps SMEs implement managed endpoint protection, Microsoft 365 security, independent backups and tested incident-response procedures.

    If you suspect ransomware, stop using the affected device, disconnect it from the network and contact professional support immediately. Fast containment is far less expensive than allowing a single compromised computer to become a business-wide outage.

    Source: CISA StopRansomware Guide

  • Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Microsoft 365 stores business email, documents, Teams information and SharePoint data in highly resilient cloud infrastructure. That often creates the impression that everything in Microsoft 365 is automatically backed up forever.

    It is not quite that simple.

    Microsoft protects the availability and operation of its cloud platform, while your business remains responsible for how its users, administrators and connected applications handle company information. Deleted data may be recoverable for a limited period, but Microsoft 365 retention features should not automatically be treated as a complete independent backup system.

    Cloud storage and backup are different

    OneDrive synchronises files between a user’s computer and the cloud. SharePoint gives teams a central place to store and collaborate on documents. Exchange Online keeps business email accessible across devices.

    These services are built for productivity and availability. Backup has a different purpose: maintaining a separate recoverable copy of data in case the live information becomes unavailable, corrupted or deliberately removed.

    If a user deletes a synchronised folder, the deletion may be reflected across the environment. If an attacker compromises an administrator account, they may attempt to delete data or weaken retention settings. Malware can also encrypt files before the damaged versions synchronise to OneDrive or SharePoint.

    Microsoft 365 includes recycle bins, version history and retention capabilities, but each feature has rules, limits and configuration requirements.

    Common ways businesses lose Microsoft 365 data

    Data loss is not always caused by Microsoft suffering a major outage. More common causes include:

    • A staff member accidentally deleting a mailbox or folder
    • An employee leaving before important information is transferred
    • A compromised account deleting or manipulating data
    • Incorrect SharePoint permissions exposing files
    • Malware encrypting synchronised documents
    • An administrator changing a retention policy
    • A third-party application corrupting or deleting information
    • The business discovering a loss after the recovery window has passed

    A backup becomes particularly valuable when nobody notices the problem immediately.

    What should be protected?

    A Microsoft 365 backup strategy should account for the services the business actually uses. This may include:

    • Exchange Online mailboxes
    • Shared mailboxes
    • OneDrive accounts
    • SharePoint sites and document libraries
    • Teams files and associated SharePoint data
    • Contacts and calendars

    The system should also make it possible to restore individual items. Recovering one deleted email or folder should not require rebuilding an entire environment.

    Retention and backup solve different problems

    Retention policies are important for governance, compliance and controlling how long information is kept. They can help prevent permanent deletion during a defined retention period.

    Independent backup provides another recovery layer. It can preserve separate copies, offer longer recovery histories and reduce dependence on the state of the live Microsoft 365 tenant.

    Many businesses benefit from using both. Retention helps govern information inside Microsoft 365, while backup provides an additional route to recovery.

    A backup must be tested

    A dashboard showing successful backup jobs is reassuring, but it does not prove that the correct data can be restored quickly.

    Businesses should periodically test:

    • Restoring an individual email
    • Recovering a OneDrive folder
    • Restoring a SharePoint document and its previous version
    • Recovering data belonging to a former employee
    • Confirming who is authorised to initiate a restore
    • Measuring how long recovery takes

    These tests turn backup from a subscription into an operational recovery capability.

    RandTech IT helps South African businesses assess Microsoft 365 retention, implement independent cloud backup and test the recovery of Exchange, OneDrive and SharePoint information.

    Your data may be in Microsoft’s cloud, but it is still your business’s responsibility. A properly configured and tested backup ensures that one mistake, compromised account or late discovery does not become permanent data loss.

    Source: Microsoft 365 Backup documentation

  • Secure Boot Certificate Changes in 2026: Is Your PC Ready?

    Secure Boot Certificate Changes in 2026: Is Your PC Ready?

    Secure Boot Certificate Changes in 2026: Is Your PC Ready?

    Microsoft is replacing ageing Secure Boot certificates used by Windows computers, and the change is becoming an important maintenance issue in 2026.

    The original certificates began reaching expiry dates from June 2026. Microsoft has expanded the rollout of replacement certificates to eligible devices through Windows updates.

    For most people, certificate expiry does not mean that a computer will immediately refuse to start. However, devices that fail to receive the new certificates may eventually miss important protections and future boot-related security updates.

    What is Secure Boot?

    Secure Boot is a security feature built into modern computer firmware. It helps verify that trusted software is loading when the PC starts.

    This makes it harder for malicious software to insert itself before Windows and evade ordinary antivirus protection. Threats operating at this level can be particularly difficult to detect and remove because they begin running before many operating-system security controls.

    Secure Boot works with digital certificates that identify trusted boot components. Those certificates cannot remain unchanged forever, which is why Microsoft and computer manufacturers must transition devices to newer versions.

    Will affected computers stop working?

    In most cases, no immediate failure is expected solely because an older certificate reaches its expiry date.

    The greater concern is that an unmanaged or unhealthy computer may not receive the new certificate. Over time, that device could lack support for newer boot managers, revocation information and Secure Boot security improvements.

    This is especially relevant to computers with:

    • Windows updates disabled or repeatedly failing
    • Very old BIOS or UEFI firmware
    • Secure Boot disabled
    • Unusual boot configurations
    • Unsupported operating systems
    • Long periods without internet access
    • BitLocker enabled without securely stored recovery keys

    Some devices may restart an additional time while the certificate update is applied. A restart during maintenance should not automatically be treated as a hardware fault.

    Why businesses should take extra care

    Firmware and boot-security changes require more caution than an ordinary application update.

    If BitLocker protects the drive, a firmware or security change may occasionally cause Windows to request the recovery key. The key should therefore be verified and securely recorded before major firmware maintenance.

    Businesses should not discover during an urgent support call that nobody knows which Microsoft account or administrator profile holds the key.

    A managed health check should review the complete chain rather than only asking whether Secure Boot displays “On.” Relevant checks include:

    • Windows edition, version and update status
    • Secure Boot capability and current state
    • TPM status
    • BIOS or UEFI version
    • BitLocker encryption status
    • Recovery-key availability
    • Manufacturer firmware updates
    • Evidence that replacement certificates were deployed

    Avoid changing firmware settings blindly

    Users may find internet instructions telling them to enable Secure Boot, reset keys or change legacy boot settings. Applying these steps without checking the current configuration can leave a machine unable to boot.

    Older installations may use legacy BIOS mode or an incompatible disk layout. The correct remediation may require preparation inside Windows before firmware settings are changed.

    For business computers, servers and Hyper-V hosts, changes should be planned, documented and tested.

    Add Secure Boot to routine maintenance

    The 2026 certificate transition is a useful reminder that computer security extends beyond antivirus software. Firmware, encryption, recovery keys and operating-system updates all contribute to whether a device can be trusted and recovered.

    RandTech IT can inspect Windows update health, BIOS firmware, TPM, Secure Boot and BitLocker recovery readiness as part of a structured business PC health check.

    If your organisation has older PCs, manually configured machines or devices that frequently fail updates, arrange an assessment before a security maintenance issue becomes an outage.

    Source: Microsoft’s Secure Boot certificate-expiry guidance

  • RAM and SSD Prices Are Rising: Should You Upgrade or Replace?

    RAM and SSD Prices Are Rising: Should You Upgrade or Replace?

    RAM and SSD Prices Are Rising: Should You Upgrade or Replace?

    The cost of improving or replacing a computer is changing quickly as higher memory and storage prices reach South African retailers.

    Local industry reporting has described substantial increases in RAM and SSD costs, with some products doubling or tripling and certain DDR5 components rising sharply over a matter of months. Higher component costs eventually affect not only upgrades, but also new laptops and complete desktop computers.

    For consumers and SMEs, this makes one question more important than ever: is the current computer worth upgrading, or would replacement offer better value?

    Why RAM and SSD prices matter

    RAM allows a computer to keep more applications and browser tabs active without slowing down. An SSD stores Windows, applications and files, and is one of the most important factors affecting startup and loading speed.

    When these components become more expensive, quotations can change quickly. A price given several weeks ago may no longer reflect the supplier’s replacement cost.

    Businesses should expect shorter quotation-validity periods and may need to pay a deposit before volatile components are ordered. This is not simply a retailer increasing margins; it can reflect rapidly changing distributor pricing.

    When an upgrade still makes sense

    Despite price increases, an upgrade may remain much cheaper than replacing a good computer.

    An SSD upgrade can transform a machine that still uses an old mechanical hard drive. Additional RAM can improve multitasking, large spreadsheets, browser-heavy work and certain design applications.

    An upgrade is generally worth considering when:

    • The processor remains suitable for the user’s workload
    • The computer supports Windows 11
    • The motherboard, screen and chassis are in good condition
    • The battery or power supply is serviceable
    • The upgrade provides at least another two or three useful years
    • The total repair and upgrade cost is well below suitable replacement cost

    A business-grade computer may also be more worthwhile to repair than a newer but poorly built entry-level replacement.

    When replacement is the better decision

    Adding memory or faster storage cannot correct every limitation.

    Replacement may be preferable when the device has an unsupported processor, damaged hinges, a failing battery, unreliable motherboard and outdated connectivity at the same time. The same applies when several components must be replaced just to achieve basic reliability.

    Businesses must also consider downtime, warranty coverage and employee productivity. Saving money on an old computer is not good value if it continues interrupting work.

    Refurbished equipment can provide a middle option

    A professionally refurbished business laptop or desktop may offer better build quality than a new entry-level consumer model at a similar price.

    The important details are the device’s generation, condition, Windows 11 compatibility, SSD health, battery condition and warranty. “Refurbished” should not merely mean cleaned and resold.

    For some businesses, a mixed approach works best: upgrade the strongest existing computers, replace unreliable units and allocate quality refurbished devices to less demanding roles.

    Diagnose before spending

    Buying RAM based only on capacity can lead to compatibility problems. SSDs also differ by interface, size, performance and endurance. Before approving an upgrade, the computer should be inspected and its overall condition considered.

    PC Warehouse and RandTech IT can assess whether a slow computer needs repair, an SSD, more RAM or full replacement. We can also migrate data and configure replacement machines so users return to work with minimal disruption.

    With component prices changing rapidly, the smartest purchase is not automatically the cheapest upgrade or newest computer. It is the option that delivers the best reliable working life for the total cost.

    Source: MyBroadband’s report on South African PC component prices

  • Windows 10 and Microsoft 365 Deadlines: What Businesses Must Know

    Windows 10 and Microsoft 365 Deadlines: What Businesses Must Know

    Windows 10 and Microsoft 365 Deadlines: What Businesses Must Know

    Windows 10 reached the end of its standard support lifecycle on 14 October 2025, but many South African businesses still use it every day.

    A Windows 10 computer does not suddenly stop working after support ends. That is precisely why the risk can be easy to ignore. The machine may continue opening email, browsing the internet and running business software while gradually falling behind current security and compatibility requirements.

    Businesses now need to distinguish between three separate issues: Windows security support, Extended Security Updates and Microsoft 365 application support.

    What happened to normal Windows 10 support?

    Microsoft no longer provides ordinary free security updates, feature improvements or technical support for standard Windows 10 installations.

    Eligible devices can receive Extended Security Updates, commonly called ESU, for a limited period. ESU can be useful when a business needs additional time to replace specialist hardware or test important software.

    It should be treated as a transition measure—not as a permanent strategy for keeping ageing computers indefinitely.

    Microsoft 365 has a different timetable

    Microsoft has continued providing security updates for Microsoft 365 Apps running on Windows 10 for a transitional period.

    According to Microsoft’s current lifecycle guidance, Version 2608 is the final Microsoft 365 Apps feature version for Windows 10. Devices remaining on that operating system can continue receiving security updates for that version until 10 October 2028.

    This does not restore full Windows 10 support. It means the Office applications have their own temporary security-update arrangement while the underlying operating system remains outside normal support unless separately covered by ESU.

    Businesses should therefore avoid interpreting “Office still receives updates” as “the computer is fully supported.”

    Should you upgrade or replace the computer?

    Not every Windows 10 PC needs to be discarded.

    A device may support Windows 11 after firmware settings, TPM or Secure Boot configuration has been corrected. In other cases, the processor or security hardware may not meet Microsoft’s requirements.

    A proper assessment should check:

    • Processor and Windows 11 compatibility
    • TPM version and status
    • Secure Boot capability
    • Available RAM and storage
    • SSD health
    • BIOS or firmware updates
    • BitLocker recovery-key availability
    • Application and printer compatibility
    • Age and physical condition of the device

    A technically compatible PC may still be a poor upgrade candidate if its storage is failing, battery is unusable or performance no longer meets the user’s needs. Conversely, a good-quality business laptop with adequate hardware may need only configuration, an SSD or additional memory.

    Avoid unsupported upgrade shortcuts

    Various online methods can install Windows 11 on unsupported computers. They may work, but a business should understand the consequences before relying on them.

    Unsupported installations can introduce uncertainty around future updates, drivers and vendor support. That may be acceptable for a non-critical personal device, but it is a questionable foundation for payroll, accounting, customer service or regulated information.

    Build a controlled replacement plan

    Businesses should inventory their computers and classify them into four groups:

    1. Ready for a normal Windows 11 upgrade
    2. Upgradeable after configuration or hardware improvements
    3. Temporarily retained with ESU
    4. Due for replacement

    This prevents emergency purchasing and allows replacements to be budgeted by business priority.

    RandTech IT provides Windows compatibility assessments, upgrades, data migration and replacement-device planning for South African SMEs. If your business still has Windows 10 computers, now is the time to establish which machines can be upgraded safely and which have reached the end of their practical life.

    Sources: Microsoft’s Windows 10 lifecycle page and Microsoft 365 Apps support guidance

  • AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    Artificial intelligence is not only helping businesses automate work. It is also helping cybercriminals create convincing scams, analyse targets and launch attacks more efficiently.

    INTERPOL’s 2026 African Cyberthreat Assessment reports that artificial intelligence was involved in 55% of reported cybercrime across Africa. The assessment also identifies South Africa as a particularly significant ransomware target, accounting for 92% of detections in the African dataset cited by the report.

    These figures do not mean that 92% of every ransomware attack in Africa occurred in South Africa. They come from a specific threat-detection dataset. They do, however, reinforce what local businesses are already experiencing: South Africa is an attractive and active target.

    How criminals use AI

    Traditional phishing emails were often easy to identify because of poor grammar, strange wording or an obviously incorrect company logo.

    Generative AI can now produce polished emails that imitate the tone of a supplier, manager or colleague. Criminals can use information from company websites, social media profiles and leaked databases to create messages that feel relevant to the recipient.

    AI may help attackers:

    • Write convincing phishing messages
    • Translate scams into natural local language
    • Generate or modify malicious code
    • Analyse stolen information more quickly
    • Impersonate executives or suppliers
    • Automate reconnaissance against exposed systems
    • Produce fake voices, documents or payment instructions

    A small criminal operation can consequently target more businesses without employing a large technical team.

    Why SMEs are attractive targets

    Many business owners assume that criminals are interested only in banks, government departments and major corporations. In reality, SMEs frequently combine valuable information with weaker protection.

    A smaller business may hold customer identity documents, banking information, contracts, payroll records and access to larger customers or suppliers. At the same time, it may rely on a single administrator, basic antivirus and backups that have never been tested.

    Automated attacks do not need to know the company personally. They scan for weak passwords, exposed remote access, outdated websites, unpatched computers and compromised Microsoft 365 accounts.

    MFA is essential—but it is not the whole solution

    Multifactor authentication remains one of the most important protections a business can deploy. However, modern attackers also use fake login approval requests, stolen browser sessions, malicious email rules and social engineering.

    Effective SME protection should therefore include several layers:

    • MFA on all business accounts
    • Separate, protected administrator accounts
    • Endpoint security on every computer
    • Prompt Windows and application patching
    • Email filtering and domain protection
    • Independent Microsoft 365 and server backups
    • Regular restore testing
    • Monitoring for suspicious logins and forwarding rules
    • Staff training using current scam examples

    No individual security product can compensate for missing backups, excessive permissions or an administrator account shared by several people.

    What business owners should do now

    Start with a short security review rather than buying random products. Identify where company data resides, who has administrative access, whether departed employees still have access and whether the business could recover from a compromised account.

    Staff should also be given a clear verification rule: unexpected requests involving payments, bank-detail changes, passwords or confidential documents must be confirmed through a second communication channel.

    AI is increasing the speed and quality of cybercrime, but businesses are not powerless. Strong identity controls, managed protection, tested recovery and alert employees still stop many attacks.

    RandTech IT helps South African SMEs assess Microsoft 365, endpoints, backups and recovery readiness. A practical cybersecurity review can reveal the gaps before an attacker finds them.

    Source: INTERPOL’s 2026 African Cyberthreat Assessment announcement

  • Rand Water Cyberattack: Could Your Business Keep Operating?

    Rand Water Cyberattack: Could Your Business Keep Operating?

    A recent cyberattack against Rand Water has given South African businesses a very practical lesson in disaster recovery.

    Rand Water disclosed that attackers had penetrated parts of its network and damaged servers. Importantly, its core water operations continued, while affected treasury services were transferred to a disaster-recovery environment. The organisation’s debt officer indicated that without its disaster-recovery site, the situation would have been far more serious.

    The incident has not publicly been confirmed as ransomware, and the precise entry point and extent of any data exposure remain under investigation. Nevertheless, it demonstrates an important principle: preventing every cyberattack is unrealistic, but preventing an attack from stopping the entire business is achievable.

    A backup is not automatically a recovery plan

    Many small and medium-sized businesses believe they are protected because someone copies files to an external drive or because documents are stored in OneDrive.

    Those measures can help, but they do not answer the most important question: how will the business continue operating if its server, computers, Microsoft 365 accounts or administrative credentials become unavailable?

    A complete recovery capability should address:

    • Where business-critical information is stored
    • Whether backup copies are isolated from the main environment
    • How quickly information can be restored
    • Who has access to administrator accounts and recovery keys
    • How staff will communicate during an outage
    • Which systems must be restored first
    • Whether the recovery process has actually been tested

    Cloud storage and synchronisation should not be confused with independent backup. If a compromised account deletes or encrypts synchronised data, those changes may be carried into the cloud environment.

    Recovery time matters

    A business may technically have a backup but still face several days of downtime while someone finds equipment, downloads data and rebuilds systems.

    This is why businesses should define a recovery time objective: the maximum acceptable period before a critical service must be operational again.

    An accounting practice may need access to email, client documents and its accounting platform within hours. A retailer may prioritise point-of-sale systems, supplier information and internet connectivity. A professional-services company may regard Microsoft 365 identities and SharePoint files as its first recovery priorities.

    The correct plan depends on how the business works—not merely on how much data it owns.

    Five questions every SME should answer

    Business owners should be able to answer these questions confidently:

    1. When was our last successful backup?
    2. When was a full restore last tested?
    3. Could an attacker delete both the live data and its backup?
    4. Who can recover our Microsoft 365 tenant if the main administrator is compromised?
    5. How would we continue working tomorrow if our server or cloud accounts were unavailable?

    If the answers are uncertain, the business has a continuity risk.

    Turn backup into business resilience

    The lesson from the Rand Water incident is not that every SME needs an expensive secondary data centre. It is that recovery must be designed before an emergency.

    For smaller businesses, an effective solution may combine managed cloud backup, an isolated secondary copy, Microsoft 365 backup, documented administrator access, replacement-device planning and scheduled restore tests.

    RandTech IT helps South African businesses assess their existing backups, identify recovery gaps and build continuity plans that fit their size and budget.

    Do not wait for a cyberattack to discover whether your backup works. Arrange a business continuity and recovery assessment before the next incident becomes your incident.

    Source: ITWeb’s report on the Rand Water breach