Category: Cybersecurity

  • How Social Engineering Turns a Trusted Identity Into Payment Fraud

    How Social Engineering Turns a Trusted Identity Into Payment Fraud

    The most dangerous part of an online scam is often not the technology. It is the relationship the criminal constructs before asking for money or information.

    On 11 September 2026, Reuters reported that South Africa had agreed to extradite six alleged members of the Black Axe network to the United States. US authorities accuse them of wire fraud and money laundering connected to online romance scams that allegedly defrauded more than 100 victims. The accusations will still need to be tested through the legal process. Reuters’ report provides the case details.

    Romance scams and business payment fraud are not identical. The useful connection is the method: establish credibility, control communication, create urgency and convert trust into a transaction.

    A believable identity is not proof

    Criminals can assemble a persuasive profile from public websites, social media and leaked data. They may know a director’s name, the company’s suppliers and which employee processes payments.

    They can also compromise a real mailbox or messaging account. A message coming from the correct address therefore does not always mean the legitimate owner sent it.

    Staff should judge high-risk requests through an agreed process, not through confidence in the sender’s writing style or profile photograph.

    Slow down the transaction

    Social engineering often uses urgency: a payment must happen before close of business, the supplier’s bank account has suddenly changed, or an executive is “in a meeting” and cannot take a call.

    The business needs rules that remain in force when someone applies pressure. Require independent verification for:

    • New or changed banking details
    • Unusual payment destinations
    • Confidential payroll or customer records
    • MFA codes or login approvals
    • Requests to install remote-access software
    • Exceptions to normal approval limits

    Do not verify using the phone number supplied in the suspicious message. Use a trusted number already recorded in the accounting system, contract or official directory.

    Separate request, approval and payment

    Where practical, one person should not be able to receive a request, change supplier details and release the payment alone. Dual approval creates a second opportunity to notice an inconsistency.

    Record who confirmed the change, which number was called and when approval occurred. A clear audit trail helps staff follow the rule consistently rather than relying on memory.

    Protect the communication accounts

    Process controls work best with secure accounts. Enable multifactor authentication, use separate administrator accounts, remove former employees promptly and investigate unexpected forwarding rules or login alerts.

    Train employees to report mistakes immediately. If someone approved a suspicious login or sent information, a fast report gives administrators a better chance to revoke sessions and limit damage. Punishing the first person who reports a mistake teaches everyone else to hide the next incident.

    Respond quickly to suspected fraud

    Contact the bank immediately through an official channel, preserve messages and transaction information, and involve the IT provider to check whether email or other accounts were compromised. Obtain appropriate legal, insurance and law-enforcement guidance for the circumstances.

    RandTech IT helps South African SMEs secure Microsoft 365, investigate suspicious access and implement practical security-awareness procedures. Trust is essential to business, but payments and confidential data need verification that does not depend on trust alone.

  • Cloud Services Still Need a Business Continuity Plan

    Cloud Services Still Need a Business Continuity Plan

    The debate concerns national infrastructure and development policy, but it also highlights a simpler lesson for small businesses: “it is in the cloud” does not mean every dependency has disappeared.

    The Associated Press reported on 5 September that South Africa hosts a substantial portion of Africa’s data-centre capacity and that campaigners are challenging further hyperscale expansion. Reuters had previously reported approval and objections around proposed Equinix facilities in Cape Town on 28 July 2026.

    For an SME in Johannesburg, the immediate risk is usually not the hyperscale facility. It is the fibre line, router, office power, DNS, user account or laptop between the employee and the service.

    Map the full chain

    Ask what is required for staff to open email, process an order or help a customer.

    The chain may include:

    • Electricity to the office and network cabinet
    • Fibre or fixed-wireless connectivity
    • Router, firewall, switches and Wi-Fi access points
    • Microsoft 365 or another cloud provider
    • Multifactor authentication on an employee’s phone
    • A working, updated laptop
    • Access to files and passwords

    A highly resilient cloud platform cannot compensate for a router that switches off two minutes into an outage.

    Add connectivity failover carefully

    An LTE or 5G connection can keep essential users online when fibre fails, but only if it is configured and tested in advance. Confirm signal quality, data limits, network coverage and whether the router changes connections automatically.

    Failover should prioritise essential services. A software update or cloud backup can consume mobile data while accounts staff are trying to process payments. Appropriate firewall and traffic rules can preserve the link for email, voice and critical applications.

    Size backup power for the network

    Keeping laptops charged does not help when the fibre terminal, router and switch have no power. Identify every network component that must remain on, measure its load and set a realistic runtime objective.

    A UPS battery also degrades. Test it under load and replace it based on condition, not merely age or a green indicator light.

    Prepare a degraded way of working

    Business continuity is not always full restoration. It may mean allowing a smaller group to continue essential work while the main connection is repaired.

    Document who needs priority access, which phone hotspot may be used, how incoming calls are handled, and which files can be securely available offline. Avoid copying uncontrolled customer data onto personal devices as an emergency shortcut.

    Test the plan

    Disconnect the primary internet connection during a controlled window and observe what happens. Can users still authenticate? Does Teams calling work? Can the business reach cloud accounting and retrieve key documents? Record the gaps and repeat the test after remediation.

    RandTech IT helps Johannesburg businesses design and test internet failover, office-network UPS protection and Microsoft 365 continuity. The cloud removes many local server risks, but resilience still depends on the last kilometre—and on a plan that has been proved before the outage.

  • September 2026 Windows Update: What Businesses Must Do Now

    September 2026 Windows Update: What Businesses Must Do Now

    Microsoft’s September 2026 security release deserves more attention than an ordinary monthly update. Published on 8 September, it addresses an exceptional number of vulnerabilities across Windows and other Microsoft products. Technical analyses count roughly 970 Microsoft vulnerabilities, with two already known to be exploited; totals vary slightly depending on how products and CVEs are counted.

    For a South African SME, the important question is not whether the headline says 972 or 974. It is whether every supported business computer receives the right updates, restarts successfully and continues to run the applications on which staff depend.

    Why this update matters

    Security updates close weaknesses that attackers can use for activities such as running code, gaining higher privileges or bypassing protections. Once a vulnerability and its fix become public, criminals can study the change and look for organisations that have not yet patched.

    Microsoft’s Windows message centre confirms that the September security update is available for supported Windows versions. Rapid7’s technical review records the unusually large release and the known exploitation status.

    Installing promptly matters, but “promptly” should still be controlled. Applying a large update to every device simultaneously can turn one compatibility problem into a company-wide interruption.

    Use a staged deployment

    A small business does not need enterprise-scale infrastructure to patch sensibly. Start with one or two representative PCs: an ordinary office workstation, a laptop used remotely and, where relevant, a machine running specialist software.

    Check that the pilot devices can:

    • Start and sign in normally
    • Connect to printers, scanners and shared folders
    • Open Outlook, Teams and Microsoft 365 apps
    • Run accounting, payroll and industry software
    • Use VPN and remote-access tools
    • Complete endpoint-security scans
    • Restart without requesting an unavailable BitLocker key

    If the pilot is healthy, deploy to the remaining devices in manageable groups.

    Confirm the update actually installed

    Clicking “Check for updates” is not proof of completion. A computer may have insufficient free space, a damaged Windows Update component, a pending restart or an unsupported Windows version.

    After deployment, record the Windows version, installed update and last successful update date. Investigate devices that have stopped checking in or repeatedly roll back an update. They are often the machines most exposed when a vulnerability is actively exploited.

    Prepare for recovery before restarting

    Before major maintenance, verify that important files are backed up and that BitLocker recovery information can be retrieved. Firmware and security-related changes can occasionally trigger a recovery prompt. The right moment to discover that nobody has the key is before the restart, not while an employee is locked out.

    Keep a rollback and support plan for business-critical machines. Do not erase or reinstall a device merely because one update fails; preserve data and diagnose the cause first.

    Patching is an ongoing service, not a monthly click

    The size of September’s release is a useful reminder that patch management includes inventory, testing, deployment, monitoring and evidence. Antivirus cannot protect an unpatched operating system from every known weakness.

    RandTech IT helps Johannesburg SMEs monitor Windows updates, test critical changes and remediate computers that have fallen behind. If you are unsure whether every company PC installed September’s security fixes, arrange a patch-health review before the gap becomes an incident.

  • Windows 11 26H2: A Business Upgrade Guide

    Windows 11 26H2: A Business Upgrade Guide

    Windows 11 version 26H2 has moved into Microsoft’s Release Preview Channel, bringing the next annual Windows feature update close enough for businesses to begin preparation.

    This does not mean every employee should install a preview build. Release Preview is still a testing stage. It means IT providers and software vendors can now validate the near-final update against real business workloads before general deployment.

    Microsoft announced Release Preview availability on 27 August 2026 and says 26H2 uses the shared servicing model of recent Windows 11 releases. For eligible PCs already on a recent version, the eventual update should be lighter than a full operating-system replacement. See Microsoft’s 26H2 Release Preview announcement.

    Do not install previews on production computers

    A production PC is one whose failure would interrupt normal work. Accounts, reception, claims and management laptops are poor places to test unfinished software.

    Use a spare machine or a controlled IT test device that resembles the company’s normal hardware. Back it up, document its applications and confirm that it can be restored.

    What businesses should test

    The Windows desktop may look familiar after the upgrade while a small compatibility issue breaks an essential workflow. Test the work, not merely the login screen.

    Check:

    • Accounting, payroll and line-of-business applications
    • Outlook profiles, shared mailboxes and add-ins
    • Teams audio, cameras and meeting-room equipment
    • Printers, scanners, label printers and signature pads
    • VPN, remote desktop and support agents
    • Endpoint protection, backup and encryption software
    • Network drives and SharePoint synchronisation
    • Sleep, docking stations and multiple monitors

    Record the exact software and driver versions. “It worked on my laptop” is not a rollout plan when the finance team uses different printers and add-ins.

    Check device eligibility and health

    An eligible Windows 11 PC can still be a poor upgrade candidate if it is short of storage, already unstable or using outdated firmware. Review free disk space, Windows Update health, BIOS/UEFI updates, TPM and Secure Boot status, drive health and BitLocker recovery-key availability.

    Do not bypass Microsoft’s hardware requirements on critical business PCs simply to force the newest version. Unsupported configurations can create security, update and support problems later.

    Build a staged rollout

    Start with an IT test device, then a small pilot group of users who can report problems clearly. Expand by department only after the pilot has completed normal work for an agreed period.

    Plan maintenance windows and make sure urgent support is available after the first production rollout. Keep senior decision-makers informed about genuine blockers rather than treating every cosmetic change as a reason to delay indefinitely.

    Upgrade readiness is also replacement planning

    The inventory may reveal computers that are technically compatible but no longer economical to maintain. A slow machine with a healthy processor may benefit from RAM or an SSD; an unreliable device with battery, hinge and motherboard problems may be better replaced.

    RandTech IT can assess a business’s Windows fleet, test 26H2 compatibility and manage a staged deployment. PC Warehouse can diagnose and upgrade suitable machines or provide correctly specified replacements.

    Prepare now, but wait for the supported general release before normal business deployment. A short pilot protects far more time than an untested company-wide click.

  • Why a Slow PC May Need an SSD, Not Replacement

    Why a Slow PC May Need an SSD, Not Replacement

    Why a Slow PC May Need an SSD, Not Replacement

    A computer that takes several minutes to start, freezes while opening applications and becomes unresponsive during updates may appear to have reached the end of its life.

    In many cases, the real bottleneck is an old mechanical hard drive.

    Replacing that drive with a solid-state drive can dramatically improve startup times, application loading and everyday responsiveness. For a suitable computer, an SSD upgrade can provide several more years of useful service at a fraction of the cost of replacement.

    Why traditional hard drives feel slow

    A mechanical hard disk stores information on spinning platters and uses a moving read-and-write head to access it. This design works well for inexpensive bulk storage, but it is relatively slow when Windows needs to access thousands of small files.

    A solid-state drive has no moving parts. It can retrieve information far more quickly, which is particularly noticeable when:

    • Windows starts
    • Outlook opens
    • Applications launch
    • Updates install
    • Files are searched
    • Several tasks run simultaneously

    An SSD will not turn every old PC into a high-performance workstation, but it can remove one of the most common performance bottlenecks.

    Signs the hard drive may be the problem

    Possible indicators include:

    • Disk usage repeatedly reaching 100%
    • Extremely slow startup
    • Delays when opening folders
    • Freezing during Windows updates
    • Clicking or unusual mechanical sounds
    • File errors or corrupted data
    • Applications becoming unresponsive while the disk is busy

    A failing hard drive is more than a performance problem. It can also become a data-recovery emergency, so unusual sounds and file errors should be investigated promptly.

    When an SSD upgrade makes sense

    An upgrade is usually worth considering when:

    • The processor still meets the user’s needs
    • The computer has enough RAM or can be upgraded
    • The motherboard, screen and hinges are healthy
    • The machine supports the required operating system
    • The total upgrade cost is well below replacement cost
    • The device is otherwise reliable

    A good-quality business laptop with an older hard drive may be a better upgrade candidate than a low-cost new laptop with weaker construction.

    When an SSD will not solve the problem

    Storage is only one component.

    An SSD cannot repair a damaged motherboard, overheating processor, broken hinge or unsuitable amount of RAM. It also cannot make an unsupported computer appropriate for critical business use indefinitely.

    Before approving an upgrade, a technician should evaluate the complete device, including:

    • Drive health
    • RAM usage
    • Processor performance
    • Cooling system
    • Battery condition
    • Windows compatibility
    • Physical condition
    • Backup status

    This prevents customers from spending money on one improvement when several expensive repairs are approaching.

    Cloning versus a clean installation

    An existing hard drive can sometimes be cloned onto the SSD, preserving Windows, applications and settings. This is convenient when the current installation is healthy.

    A clean Windows installation may be preferable when the old system contains corruption, unwanted software or years of accumulated problems. User data must be backed up and verified before either process begins.

    The correct method depends on the condition of the original drive and the customer’s software requirements.

    Diagnose before replacing

    PC Warehouse and RandTech IT provide computer diagnostics, SSD upgrades, data migration and replacement advice in Randburg and Johannesburg.

    We assess the complete machine and explain whether repair, upgrade or replacement offers the best value. If the device is worth saving, an SSD can be one of the most noticeable upgrades available.

    Before replacing a frustratingly slow computer, have it tested. The machine may not be finished—it may simply be waiting for its slowest component to be replaced.

  • Business Email Compromise: The Invoice Scam Targeting SMEs

    Business Email Compromise: The Invoice Scam Targeting SMEs

    Business Email Compromise: The Invoice Scam Targeting SMEs

    A supplier sends an email advising that its banking details have changed. The address appears correct, the invoice looks familiar and the message refers to a genuine project.

    The accounts department processes the payment. Days later, the real supplier asks why the account remains unpaid.

    This is business email compromise, commonly abbreviated to BEC. It is one of the most financially damaging forms of cybercrime because it exploits trusted relationships and normal business processes rather than relying only on malicious attachments.

    How the scam works

    Criminals may use several methods.

    They can register a domain that closely resembles the supplier’s real address. They may compromise the supplier’s mailbox and send messages from the genuine account. In other cases, they access the customer’s email and monitor correspondence until the correct moment to insert fraudulent payment instructions.

    Because the criminals have observed real conversations, they may know:

    • The supplier’s name
    • Which employee handles payments
    • The expected invoice amount
    • The project being discussed
    • When payment is due
    • The wording normally used in emails

    The message can therefore look completely legitimate.

    Why antivirus may not stop it

    A BEC message may contain no virus, malicious attachment or obvious phishing link. It may simply provide different banking details on a modified invoice.

    Traditional antivirus has little to detect. The most effective control is a combination of account security and a strong payment-verification process.

    Warning signs to watch for

    Treat these situations with caution:

    • New banking details
    • An unexpected request for urgent payment
    • Pressure to keep the transaction confidential
    • A subtle change in the sender’s domain
    • A reply-to address that differs from the sender
    • An invoice that looks slightly different
    • A request to bypass normal approval
    • Unusual timing or writing style
    • Claims that the supplier’s phone is unavailable

    A correct-looking email address is not absolute proof. A genuine mailbox may be compromised.

    Verify through an independent channel

    Every bank-detail change should be verified using contact information already held by the business.

    Do not phone the number included on the new invoice or in the suspicious email. Retrieve the supplier’s established number from your accounting records, original agreement or trusted website.

    The person verifying the change should record:

    • Who was contacted
    • Which trusted number was used
    • Who confirmed the details
    • The date and time
    • Whether a second person approved the payment

    The same procedure should apply to executives and long-standing suppliers. Familiarity is exactly what the criminal is exploiting.

    Secure the email environment

    Businesses should also:

    • Enable multifactor authentication
    • Protect administrator accounts
    • Review suspicious mailbox rules
    • Remove access belonging to former employees
    • Configure domain-authentication protections
    • Monitor unusual logins
    • Train finance staff using realistic examples
    • Use dual approval for significant payments

    If fraud is discovered, immediately contact the bank, IT provider and appropriate authorities. Speed may affect whether funds can be traced or frozen.

    RandTech IT helps South African SMEs secure Microsoft 365, investigate suspicious mailbox activity and implement practical anti-phishing controls.

    A professional-looking invoice is not proof of authenticity. When banking details change, pause the payment and verify the request independently. A two-minute phone call can prevent a loss that takes months—or longer—to resolve.

    Reference: INTERPOL guidance on business email compromise

  • POPIA and AI: Can Staff Paste Client Data Into ChatGPT?

    POPIA and AI: Can Staff Paste Client Data Into ChatGPT?

    POPIA and AI: Can Staff Paste Client Data Into ChatGPT?

    Employees are increasingly using ChatGPT, Microsoft Copilot, Claude and other generative-AI tools to summarise documents, draft correspondence and analyse information.

    The productivity benefits can be substantial. The risk appears when staff paste client records, identity documents, contracts, financial information or confidential company data into an AI service without understanding where that information goes.

    Under South Africa’s Protection of Personal Information Act, a business remains responsible for personal information under its control. Using a convenient AI tool does not remove that responsibility.

    What information should concern businesses?

    Potentially sensitive prompts may contain:

    • Customer names and identity numbers
    • Contact and address information
    • Medical or insurance information
    • Banking and payment details
    • Employee disciplinary records
    • Contracts and legal correspondence
    • Passwords or security configurations
    • Confidential pricing and proposals
    • Proprietary source code
    • Information received under a non-disclosure agreement

    Even when a task seems harmless, the surrounding document may contain far more information than the employee intended to share.

    Is using AI automatically a POPIA violation?

    No. AI use is not automatically unlawful, and the answer depends on the service, configuration, contract, purpose and information involved.

    However, the business should establish whether it has a lawful basis for processing the data, whether the use is compatible with the original purpose, whether adequate security safeguards exist and whether information may be processed outside South Africa.

    The organisation must also consider contractual confidentiality—not only POPIA. A client agreement may prohibit disclosure to an unapproved third party even if the information does not meet a narrow definition of personal information.

    Consumer and enterprise AI are not identical

    AI products may offer different privacy and data-handling terms depending on the plan being used.

    An enterprise service configured through an approved company tenant may provide stronger controls than an employee’s personal free account. Features can include administrative management, access controls, contractual protections and limitations on using business data for model training.

    That does not mean every enterprise AI prompt is automatically safe. The business must still control access, minimise information and configure the service correctly.

    Adopt a simple staff rule

    Until a tool has been formally approved, employees should not paste personal, confidential or client-identifiable information into it.

    Where AI assistance is appropriate, staff can often remove or replace sensitive information. For example:

    • Replace names with “Client A”
    • Remove identity and account numbers
    • Exclude signatures and contact details
    • Summarise the relevant facts instead of uploading the full file
    • Use fictional figures when testing a calculation
    • Paste only the paragraph needed for editing

    Redaction should be performed before information reaches the AI tool.

    What should an AI policy include?

    A practical workplace AI policy should define:

    • Approved tools and accounts
    • Prohibited information
    • When redaction is required
    • Who may upload documents
    • Human review requirements
    • Rules for generated legal, financial or technical advice
    • Retention and record-keeping
    • Incident reporting
    • Approval for new AI services

    Staff also need short, realistic training. A policy hidden in a folder will not change daily behaviour.

    Use AI deliberately

    RandTech IT helps South African businesses assess AI tools, secure Microsoft 365 environments and develop practical usage policies that balance productivity with privacy.

    Generative AI can be enormously useful, but convenience should not bypass client confidentiality. Before pasting business information into an AI prompt, employees should ask: is this tool approved, is this data necessary, and can the request be completed without identifying the person?

    For formal compliance decisions, businesses should also obtain advice from a qualified privacy or legal professional.

    Reference: South African Information Regulator

  • How to Recognise AI-Generated Phishing Emails in 2026

    How to Recognise AI-Generated Phishing Emails in 2026

    How to Recognise AI-Generated Phishing Emails in 2026

    “Look for bad spelling” is no longer enough to protect a business from phishing.

    Generative AI can produce professional emails with correct grammar, convincing formatting and a tone that sounds like a supplier, manager or colleague. Criminals can combine AI with information from websites, LinkedIn profiles, data breaches and previous email compromises to create highly believable messages.

    INTERPOL’s 2026 African Cyberthreat Assessment says artificial intelligence is enabling cybercrime across Africa to become faster, more scalable and increasingly sophisticated.

    Employees therefore need to judge an email by its request and context—not simply by how well it is written.

    AI makes personalisation easier

    A criminal can quickly gather names, job titles, suppliers and current projects from public sources. AI can then turn that information into a message aimed at one specific employee.

    For example, an accounts user may receive a message appearing to come from a known supplier, explaining that its banking details have changed. A manager may receive a realistic Microsoft 365 login alert. An employee may hear a voice note that resembles an executive asking for an urgent payment.

    The individual details may be accurate even when the request is fraudulent.

    Warning signs still exist

    AI-generated phishing may be polished, but criminals still need the recipient to perform an action. Focus on that action.

    Be suspicious when a message requests:

    • An urgent or confidential payment
    • A change to supplier banking details
    • Login through an unexpected link
    • An MFA code or approval
    • Confidential customer or employee information
    • Installation of remote-access software
    • Purchase of vouchers or gift cards
    • Bypassing the normal approval process
    • Opening an unexpected shared document

    Urgency, secrecy and unusual procedure are stronger indicators than spelling mistakes.

    Check the sender carefully

    A displayed name can be copied easily. Examine the full email address and domain.

    Criminals may use a lookalike domain containing an extra letter, substituted character or different ending. An email may also come from a legitimate account that has been compromised, so a correct address is not absolute proof.

    Do not use the phone number or contact details included in the suspicious message to verify it. Use a number already held in your records or speak to the person directly.

    Treat login links with caution

    Fake Microsoft 365 pages can closely resemble the real sign-in screen. Some attacks also relay authentication in real time or attempt to trick users into approving an MFA request.

    Instead of clicking an unexpected email link, open the service through a saved bookmark or enter the known address manually. Never provide an MFA code to another person or approve a login you did not initiate.

    If a user enters credentials into a suspicious page, report it immediately. Quick action may allow administrators to reset the password, revoke active sessions and investigate before the account is used against customers or colleagues.

    Introduce a second-channel verification rule

    Every business should have a rule for high-risk requests:

    Changes to banking details, unusual payments and requests for confidential records must be confirmed through a second trusted channel.

    A phone call to a known number may feel inconvenient, but it can prevent a major loss. The verification process should apply regardless of whether the email appears to come from the CEO or a long-standing supplier.

    Technology and training must work together

    Email filtering, endpoint security and MFA remain important. However, no filter can guarantee that every well-crafted message will be blocked.

    RandTech IT helps South African businesses strengthen Microsoft 365 security, review suspicious email activity and train employees using realistic examples.

    The new rule is simple: do not trust an email because it looks professional. Verify the identity, request and procedure before money, passwords or sensitive information leave the business.

    Source: INTERPOL’s 2026 African Cyberthreat Assessment

  • What to Do After a Ransomware Attack: An SME Response Guide

    What to Do After a Ransomware Attack: An SME Response Guide

    What to Do After a Ransomware Attack: An SME Response Guide

    A ransomware incident rarely begins with a dramatic message appearing on every screen. The first warning may be a user unable to open a document, a shared folder containing strangely renamed files or a computer suddenly running unusual processes.

    What happens during the next hour can determine whether the incident affects one computer or spreads across the business.

    South African SMEs should have a simple ransomware response plan that employees and decision-makers can follow without improvising under pressure.

    1. Isolate affected devices

    Disconnect a suspected computer from wired and wireless networks as quickly as possible. Remove its network cable or disable Wi-Fi, but do not immediately erase, reset or reinstall it.

    If several devices show similar symptoms, disconnect affected network segments and shared storage where practical. The objective is to limit further encryption, data theft and movement between computers.

    Do not continue opening files to test whether they work. Every additional action may spread damage or overwrite useful evidence.

    2. Contact your IT and security provider

    Treat the event as a security incident rather than an ordinary computer fault.

    Your provider needs to determine:

    • Which users and devices are affected
    • Whether administrator credentials may be compromised
    • Whether files are still being encrypted
    • Whether Microsoft 365 or other cloud accounts were accessed
    • Whether data may have been stolen
    • Whether backups remain safe
    • How the attacker gained access

    Modern ransomware incidents may include data theft before encryption. Restoring files alone does not establish that the threat has been removed.

    3. Protect identities and administrative access

    If account compromise is suspected, passwords and sessions may need to be reset from a known-clean device. Administrative accounts, remote-access tools, VPN credentials and Microsoft 365 access should receive priority.

    Simply changing one employee’s password may be insufficient. Attackers sometimes create forwarding rules, add authentication methods or establish alternative accounts that allow them to return.

    Security changes should be coordinated carefully so the response team does not accidentally lose access to essential evidence or recovery systems.

    4. Preserve evidence

    Keep affected devices, ransom notes, suspicious emails, timestamps and security logs. Take photographs or screenshots where appropriate, but do not interact unnecessarily with malicious files.

    Evidence can help establish the entry point, scope of the incident and whether personal information was affected. This may also be important for cyber-insurance claims, regulatory obligations and law-enforcement reporting.

    Where personal information may have been compromised, the business should obtain appropriate POPIA and legal guidance regarding notification requirements.

    5. Verify backups before restoring

    Do not reconnect backup drives or begin restoring data until the environment has been assessed.

    A backup connected too early could also be encrypted or contaminated. The recovery team should confirm that the backup predates the attack, remains isolated and can be restored into a clean environment.

    Recovery should follow business priorities. Email, accounting, customer records and operational systems may need to be restored in a planned sequence.

    Should a business pay the ransom?

    Paying does not guarantee that criminals will provide a working decryption key, delete stolen information or avoid attacking again. Payment may also create legal, ethical and insurance complications.

    This decision should not be made impulsively. Obtain specialist incident-response, legal and insurance advice based on the exact circumstances.

    Prepare before the attack

    The best time to decide who disconnects systems, contacts the insurer and authorises recovery is before ransomware is discovered.

    RandTech IT helps SMEs implement managed endpoint protection, Microsoft 365 security, independent backups and tested incident-response procedures.

    If you suspect ransomware, stop using the affected device, disconnect it from the network and contact professional support immediately. Fast containment is far less expensive than allowing a single compromised computer to become a business-wide outage.

    Source: CISA StopRansomware Guide

  • Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Microsoft 365 stores business email, documents, Teams information and SharePoint data in highly resilient cloud infrastructure. That often creates the impression that everything in Microsoft 365 is automatically backed up forever.

    It is not quite that simple.

    Microsoft protects the availability and operation of its cloud platform, while your business remains responsible for how its users, administrators and connected applications handle company information. Deleted data may be recoverable for a limited period, but Microsoft 365 retention features should not automatically be treated as a complete independent backup system.

    Cloud storage and backup are different

    OneDrive synchronises files between a user’s computer and the cloud. SharePoint gives teams a central place to store and collaborate on documents. Exchange Online keeps business email accessible across devices.

    These services are built for productivity and availability. Backup has a different purpose: maintaining a separate recoverable copy of data in case the live information becomes unavailable, corrupted or deliberately removed.

    If a user deletes a synchronised folder, the deletion may be reflected across the environment. If an attacker compromises an administrator account, they may attempt to delete data or weaken retention settings. Malware can also encrypt files before the damaged versions synchronise to OneDrive or SharePoint.

    Microsoft 365 includes recycle bins, version history and retention capabilities, but each feature has rules, limits and configuration requirements.

    Common ways businesses lose Microsoft 365 data

    Data loss is not always caused by Microsoft suffering a major outage. More common causes include:

    • A staff member accidentally deleting a mailbox or folder
    • An employee leaving before important information is transferred
    • A compromised account deleting or manipulating data
    • Incorrect SharePoint permissions exposing files
    • Malware encrypting synchronised documents
    • An administrator changing a retention policy
    • A third-party application corrupting or deleting information
    • The business discovering a loss after the recovery window has passed

    A backup becomes particularly valuable when nobody notices the problem immediately.

    What should be protected?

    A Microsoft 365 backup strategy should account for the services the business actually uses. This may include:

    • Exchange Online mailboxes
    • Shared mailboxes
    • OneDrive accounts
    • SharePoint sites and document libraries
    • Teams files and associated SharePoint data
    • Contacts and calendars

    The system should also make it possible to restore individual items. Recovering one deleted email or folder should not require rebuilding an entire environment.

    Retention and backup solve different problems

    Retention policies are important for governance, compliance and controlling how long information is kept. They can help prevent permanent deletion during a defined retention period.

    Independent backup provides another recovery layer. It can preserve separate copies, offer longer recovery histories and reduce dependence on the state of the live Microsoft 365 tenant.

    Many businesses benefit from using both. Retention helps govern information inside Microsoft 365, while backup provides an additional route to recovery.

    A backup must be tested

    A dashboard showing successful backup jobs is reassuring, but it does not prove that the correct data can be restored quickly.

    Businesses should periodically test:

    • Restoring an individual email
    • Recovering a OneDrive folder
    • Restoring a SharePoint document and its previous version
    • Recovering data belonging to a former employee
    • Confirming who is authorised to initiate a restore
    • Measuring how long recovery takes

    These tests turn backup from a subscription into an operational recovery capability.

    RandTech IT helps South African businesses assess Microsoft 365 retention, implement independent cloud backup and test the recovery of Exchange, OneDrive and SharePoint information.

    Your data may be in Microsoft’s cloud, but it is still your business’s responsibility. A properly configured and tested backup ensures that one mistake, compromised account or late discovery does not become permanent data loss.

    Source: Microsoft 365 Backup documentation