Lost or Stolen Business Device? A Practical Response Checklist for UK SMEs

Managed office devices with a security lock displayed after a business laptop goes missing

A laptop left on a train, a phone taken from a vehicle or a tablet that cannot be found can quickly become a business security incident. The device itself can be replaced. The more important questions are what it contained, which accounts it could access and whether anyone else can use it.

The response does not need to be chaotic. A clear process, supported by device management and accurate records, can help a business contain the risk and restore the user safely.

Why the first hour matters

Do not wait until the next working day in the hope that the device turns up. The person who notices the loss should report it to the organisation’s IT contact immediately, even if they are unsure whether it has been misplaced or stolen.

Early action gives the support team a better chance to lock the device, revoke active sessions and review recent activity before information disappears from logs. It also starts a reliable incident record if the loss later needs to be reported to an insurer, the police or the Information Commissioner’s Office (ICO).

1. Record the essential facts

Start a simple incident log and record facts rather than assumptions:

  • the user’s name and contact details;
  • the device type, make, asset number and serial number, if known;
  • when and where it was last seen;
  • whether it was locked, switched on or connected to a network;
  • which email, cloud, finance or business systems it could access;
  • whether files were stored locally; and
  • whether the device held personal, confidential or commercially sensitive information.

An up-to-date asset register makes this much quicker. It should connect each device to its assigned user, management status, encryption state and replacement history.

2. Lock, locate or erase the device

If the device is enrolled in mobile device management (MDM), an administrator may be able to put it into a lost mode, lock it or erase it remotely. The right action depends on the circumstances. Location information might help recover a misplaced device, while a remote wipe may be more appropriate when theft is likely or the information risk is high.

The National Cyber Security Centre explains that an MDM-enrolled device can receive a remote-wipe command when it is powered on and has a data connection. A wipe is not guaranteed to happen immediately if the device remains offline, so it should be one part of the response rather than the only control. See the NCSC guidance on erasing devices.

Do not attempt to confront someone shown at a device’s reported location. Pass relevant information to the police where theft is suspected.

3. Secure the user’s accounts

A locked screen does not necessarily end every active cloud session. Review and, where appropriate, revoke the device’s access to:

  • Microsoft 365 or Google Workspace;
  • business applications and file-sharing services;
  • remote-access and VPN services;
  • password managers;
  • finance, payment and customer systems; and
  • administrator or supplier portals.

Reset credentials where there is a credible risk of exposure, beginning with privileged accounts and the user’s primary email account. Check that multi-factor authentication remains under the user’s control and that no new authentication method or forwarding rule has been added.

Review sign-in and security logs for unusual locations, downloads or configuration changes. Preserve anything suspicious rather than deleting it, because it may help establish what happened.

4. Decide whether personal data may be affected

Losing a device does not automatically mean that data has been accessed, but the organisation still needs to assess the risk. Consider the strength of the screen lock and encryption, the sensitivity of the information, whether the device was remotely managed, and the likelihood that an unauthorised person could use it.

The ICO says organisations must keep a record of personal data breaches, whether or not a report is required. If a breach is likely to risk people’s rights and freedoms, the ICO must be notified as soon as possible and, where feasible, within 72 hours. If the likely risk is high, affected people must also be informed without undue delay. The ICO provides a small-business guide to the first 72 hours and a personal data breach self-assessment.

This assessment should be made by an appropriately authorised person and, where necessary, with legal or data-protection advice. Record the reasoning even when the decision is not to report.

5. Restore the user safely

The priority is to get the person working again without recreating the same risk. Supply a known, managed replacement rather than allowing an unprotected personal device to become a permanent workaround.

Restore approved business data from a verified backup or managed cloud service. Reapply security policies, software updates, endpoint protection, encryption and access restrictions before returning the user to normal work. If the missing device later reappears, do not reconnect it automatically; let IT inspect and re-enrol it first.

Controls to put in place before the next incident

The easiest incident to manage is one for which the business is already prepared. A sensible baseline includes:

  • full-disk encryption and a strong automatic screen lock;
  • MDM or another suitable management platform for company devices;
  • multi-factor authentication for important accounts;
  • least-privilege access, with separate administrator accounts;
  • an accurate asset register and clear joiner, mover and leaver processes;
  • tested backups for important business data;
  • a written lost-device and personal-data-breach procedure; and
  • staff training that makes prompt reporting easy and blame-free.

These controls should cover the complete workplace. Windows PCs, Macs, iPhones, iPads and Chromebooks use different management tools, but the business outcome is the same: know what you own, apply a consistent security baseline and retain the ability to remove access when a device is no longer trusted.

A simple lost-device action plan

When a device goes missing, remember this sequence:

  1. Report it immediately.
  2. Record the facts and the systems involved.
  3. Lock, locate or wipe the device where appropriate.
  4. Revoke sessions and secure affected accounts.
  5. Assess the information and personal-data risk.
  6. Preserve evidence and make any required reports.
  7. Restore the user on a known, managed device.
  8. Review what would make the next response faster.

Make device loss a manageable event

MSP247 supports mixed Windows, Apple and Chromebook environments alongside networks, Microsoft 365, backups and business continuity. We can help you review device management, encryption, account security, asset records and recovery arrangements as one joined-up service.

If you are unsure how quickly your business could contain a lost-device incident, book a free IT review or call 0330 301 0500.

How to Test a Business Continuity Plan: A Practical Exercise for UK SMEs

Yorkshire business team rehearsing an IT continuity and incident recovery plan

A business continuity plan can look perfectly sensible until something actually goes wrong.

During a genuine outage, people may discover that an important password is unavailable, the nominated decision-maker is on holiday, a supplier cannot be reached or the backup does not contain what everyone expected. These are expensive problems to uncover while customers are waiting and staff cannot work.

A tabletop exercise gives your team a safe way to rehearse an incident before it happens. It does not require anyone to disconnect live systems or simulate a technical attack. Instead, the people involved work through a realistic scenario, discuss what they would do and record the gaps that need attention.

What is a business continuity tabletop exercise?

A tabletop exercise is a structured discussion based on an unfolding incident. A facilitator introduces the situation in stages. Participants explain how they would respond, who they would contact, what decisions they could make and what information they would need.

The National Cyber Security Centre provides a free Exercise in a Box service covering scenarios including ransomware, phishing, supply-chain compromise and vulnerable systems. It is designed for organisations of different sizes and does not require participants to be cybersecurity experts.

The objective is not to catch people out. It is to find assumptions, unclear responsibilities and missing information while there is still time to correct them.

Choose one believable disruption

Begin with a scenario that could materially affect your organisation. Keep it specific enough to prompt decisions without turning the exercise into a technical examination.

  • Staff cannot access Microsoft 365 after several accounts are compromised.
  • A server or important cloud application becomes unavailable.
  • A ransomware warning appears on multiple computers.
  • The main internet connection fails during a busy working day.
  • A laptop containing business information is lost.
  • A critical supplier reports that its own systems have been breached.
  • Your premises cannot be accessed following a power, fire or security incident.

Choose the scenario that would have the clearest effect on customers, revenue, safety or essential operations.

Bring the right people together

A useful exercise normally needs more than the IT contact. Include people who understand how the organisation operates and who would have responsibilities during a disruption.

  • A senior decision-maker.
  • The person responsible for IT or the managed service provider.
  • Operations or service-delivery staff.
  • Finance or payroll.
  • Communications or customer service.
  • HR or data-protection responsibilities.

Nominate one person to facilitate the exercise and another to record decisions, unanswered questions and follow-up actions.

A practical 60-minute exercise

You can run a useful first exercise in approximately one hour.

1. Introduce the incident

It is 9:15 on Monday morning. Several employees cannot open shared files. Two computers display an unexpected ransom message, and a customer says an email from your finance team asked them to use a different bank account.

Ask who should be contacted first, how staff would report the problem, who has authority to make urgent decisions and whether any equipment or accounts should be isolated.

2. Add uncertainty

The main administrator account cannot be accessed. Your usual IT contact is unavailable, and it is not yet clear whether backups have been affected.

Discuss where emergency access details are kept, whether there is a second authorised contact, who can reach key suppliers and which services should be restored first. This stage often reveals that a technical control exists but nobody is certain who owns it or how it would be used.

3. Consider customers and communications

Telephone enquiries are increasing, and an important customer wants to know whether its information has been affected.

Decide who approves internal and external updates, how employees receive instructions if email is unavailable, and which customers, suppliers or insurers may need to be contacted. The NCSC recommends keeping a careful incident record, including decisions, actions and missing information. It also stresses the importance of clear communication with customers and other stakeholders during an incident. Read the NCSC incident-management guidance.

4. Work through recovery

  • Which data and systems are the highest priority?
  • What is the most recent acceptable recovery point?
  • Has the relevant backup ever been restored?
  • Are recovery credentials separate from everyday accounts?
  • Can the business operate from another location or connection?
  • Who decides when normal service can resume?

A green backup status is reassuring, but it is not proof that the required information can be restored within an acceptable time. Restoration testing should form part of the exercise where it can be performed safely. Our backup and business continuity service explains how recovery priorities and testing fit together.

Include personal-data decisions

A cyber incident does not automatically mean that a report must be made to the Information Commissioner’s Office. However, the team should know who will determine whether personal data has been affected and whether the reporting threshold is met.

For a notifiable personal-data breach, organisations must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Organisations must also keep records of personal-data breaches, including those that are not reported. See the ICO personal-data breach guidance.

Your exercise should identify who starts the incident record, who assesses the risk and where legal or specialist advice would be obtained.

Turn the discussion into an action plan

The exercise is only valuable if its findings lead to improvements. For every gap, record the required action, the person responsible, the completion date, the affected service and how completion will be checked.

Typical actions might include creating a second emergency administrator account, updating supplier contacts, testing a Microsoft 365 or server restoration, documenting call-diversion instructions or agreeing who can authorise emergency expenditure.

How often should an exercise be run?

There is no single schedule suitable for every organisation. As a practical starting point, consider an exercise at least annually and after significant changes to systems, premises, suppliers or senior responsibilities.

Use different scenarios over time. A ransomware discussion tests different decisions from a broadband failure, lost device or unavailable cloud supplier. Repeating an exercise after improvements have been made is an effective way to confirm that the original weaknesses have genuinely been addressed.

Make continuity something you can use

Business continuity should not be a document that is written once and forgotten. It should give people clear priorities, dependable contact routes and recovery arrangements they have seen work.

MSP247 helps organisations across Yorkshire review critical systems, backup arrangements, connectivity dependencies and incident responsibilities. We can also help structure a practical exercise and turn the results into a prioritised improvement plan.

Call 0330 301 0500 to discuss your current arrangements.

Passkeys for Small Businesses: A Practical UK Guide

Business colleagues using passkeys across laptops and a smartphone in a mixed-device workplace

Passwords remain one of the weakest points in business security. Staff reuse them, attackers steal them through convincing sign-in pages, and support teams spend time resetting them when they are forgotten.

Passkeys offer a practical alternative. They let someone sign in using the security already built into their phone, computer or hardware security key, without sending a reusable password across the internet.

The UK National Cyber Security Centre recommends choosing passkeys over passwords wherever they are available because they are resistant to phishing and cannot be intercepted or reused in the same way as a password. Read the NCSC’s passkey guidance.

That does not mean every business should immediately disable every password. A safe move to passkeys requires planning, testing and a reliable account-recovery process.

What is a passkey?

A passkey is a digital credential created for a specific website, application or online service. It consists of two related cryptographic keys.

The service keeps the public key. The private key remains protected by the user’s device, security key or approved password manager. When the user signs in, the device proves it holds the private key without revealing it.

The user normally authorises the sign-in with the same method used to unlock the device, such as Face ID, Touch ID, a fingerprint, a device PIN or a hardware security key.

The biometric information is not sent to the website or cloud service. It is checked locally by the device to unlock the passkey. Google’s Workspace guidance confirms that a fingerprint, face scan, PIN or pattern remains local and is not shared with Google or other parties. See Google Workspace passkey guidance.

Because a passkey is tied to the genuine website or application for which it was created, a fraudulent login page cannot simply collect and reuse it.

Where can a business use passkeys?

Support is already available across many of the platforms commonly used by small businesses.

Microsoft Entra ID supports both synced and device-bound passkeys. Credentials can be held in Microsoft Authenticator, on a FIDO2 hardware security key or through an approved passkey provider. Microsoft also allows administrators to target deployment at selected groups before extending it across the organisation. Review Microsoft’s current Entra passkey guidance.

Apple devices can store passkeys in iCloud Keychain and make them available across compatible iPhones, iPads and Macs using the same Apple Account. Apple requires two-factor authentication and iCloud Keychain to be enabled. See Apple’s UK passkey instructions.

Google Workspace administrators can allow users to skip password challenges and authenticate with a passkey stored on a phone, computer or security key. Administrators can also restrict deployment to hardware security keys where that is appropriate.

Availability still varies between applications. Older software, legacy email clients and some specialist services may continue to require passwords, so passkeys should be introduced as part of a wider identity-security plan.

A sensible passkey rollout for a small business

1. Start with the accounts that matter most

Begin with administrators, directors, finance users and anyone who can access sensitive customer information. These accounts present the greatest risk if their credentials are stolen.

Do not overlook shared cloud services, domain administration, backup platforms, remote-access tools and social-media accounts.

2. Review the devices people actually use

A passkey plan must reflect the real workplace. Check whether staff use managed Windows PCs, Macs, iPhones, Android phones or Chromebooks, and whether personal devices are permitted.

Decide whether passkeys may synchronise through personal accounts or whether company-controlled authenticators and hardware security keys are required.

3. Plan account recovery before deployment

A lost phone must not become a business emergency.

Privileged users should normally have more than one approved authentication method. This might include a second managed device, a spare hardware security key stored securely or an administrator-controlled recovery process.

Recovery must be documented, tested and protected from social engineering. An attacker who cannot steal a passkey may instead attempt to persuade someone to reset it.

4. Run a small pilot

Choose a group representing different roles and devices. Test everyday sign-ins, remote working, replacement devices and recovery.

The pilot should identify unsupported applications and unclear instructions before they affect the whole company. Record what users found confusing and improve the guidance before expanding the rollout.

5. Update joiner, mover and leaver procedures

Authentication credentials must follow the employment lifecycle. New starters need an approved enrolment process. Role changes may require different security controls, while leavers must have passkeys and active sessions removed promptly from company services.

Company-owned hardware security keys should be inventoried and recovered where possible.

6. Keep stronger controls for privileged access

Convenient synced passkeys can be suitable for many everyday users. Administrators or people handling particularly sensitive systems may benefit from device-bound passkeys or dedicated hardware security keys.

Microsoft describes FIDO2 security keys as an appropriate option for elevated and highly regulated users because the private key remains on the physical authenticator. Read Microsoft’s explanation of FIDO2 security keys.

7. Train staff in the new sign-in process

Passkeys reduce phishing risk, but people still need to understand what has changed.

Explain that staff should not approve unexpected recovery requests, scan unsolicited sign-in QR codes or disclose device PINs. Provide a clear route for reporting lost devices and suspicious prompts.

Passkeys are one part of good account security

Passkeys can make sign-in both safer and easier, but they do not replace device management, software updates, access reviews or reliable backups.

A compromised or unmanaged device can still expose business information after a legitimate user has signed in. Businesses should combine passkeys with:

  • Managed and encrypted devices
  • Prompt removal of unused accounts
  • Restricted administrator privileges
  • Regular access reviews
  • Secure recovery procedures
  • Monitoring for unusual sign-ins
  • Tested backup and incident-response arrangements

The objective is not simply to remove passwords. It is to create an authentication process that is easier for genuine users and substantially harder for an attacker to exploit.


Need help planning a safe rollout?

MSP247 supports businesses using Windows, Mac, iPhone, iPad, Chromebook, Microsoft 365, Google services and mixed-device environments. Our free business IT review can examine your current authentication methods, administrator accounts, device management and recovery arrangements.

Related services: managed IT support, Apple business IT support, Microsoft 365 support and management, and cybersecurity services.

Seven Warning Signs Your Business Wi-Fi Needs Redesigning

Business office with ceiling access points providing complete Wi-Fi coverage

Published July 2026

Business Wi-Fi often develops gradually: one router becomes two access points, a meeting room gets an extender, and a separate guest network is added later. It may work well enough for a time, but growing device numbers, cloud applications and video calls eventually expose weaknesses in the design.

If staff regularly blame “the internet”, the real problem may be inside the building. These seven warning signs show when a professional wireless survey and redesign could improve reliability, security and performance.

1. Coverage disappears in predictable places

Dead zones in meeting rooms, warehouses, stairwells or at the far end of an office usually indicate poor access-point placement or an unsuitable building layout. Thick walls, metal shelving, reinforced glass and machinery can all weaken or reflect wireless signals.

Adding an extender without measuring the environment can make roaming and interference worse. A wireless survey maps signal strength and helps place managed access points where users actually need them.

2. Video calls freeze when the office is busy

A speed test early in the morning may look excellent, yet performance collapses when staff arrive. The cause could be too many devices sharing one access point, congested radio channels, poor airtime management or an undersized internet connection.

Voice and video need stable latency and low packet loss, not only a high headline download speed. Business Wi-Fi should distribute clients sensibly and prioritise real-time traffic where appropriate.

3. Users keep disconnecting while they move

In a multi-access-point network, phones and laptops should roam without the user noticing. If calls drop when someone walks between rooms, access points may be configured independently, transmitting too strongly or using inconsistent settings.

A coordinated wireless system can manage radio power, channel choice and roaming assistance. The design still needs testing with the devices and applications your staff use.

4. Staff use personal hotspots to get work done

Personal hotspots are a clear sign that employees do not trust the company network. They also bypass monitoring, filtering and other business controls. Ask where and when people switch to mobile data; the pattern often identifies a coverage, capacity or authentication problem.

5. Guests share the same network as company devices

A guest password written on reception should not provide a route to business computers, printers, cameras or servers. Guest access should be isolated, rate-limited where sensible and easy to change without reconfiguring every company device.

Separate networks are also useful for building systems, payment terminals, printers and other connected equipment. Segmentation limits unnecessary access and reduces the impact of a compromised device.

6. Nobody can explain the current configuration

If access points use different passwords, firmware versions or management accounts, support becomes slow and risky. The business should know where equipment is installed, who manages it, which networks exist, what each network can reach and when firmware was last updated.

Central management gives IT teams a consistent configuration and useful visibility into clients, utilisation and faults. It also makes it easier to apply updates and replace hardware in a controlled way.

7. The office has changed but the Wi-Fi has not

Wireless designs age when teams grow, desks move, walls are added or new cloud, voice and collaboration services arrive. A network sized for 20 laptops may struggle with 20 people carrying a laptop, phone, tablet and wireless headset.

New cameras, scanners, sensors and visitor devices add more competition for airtime. Review the design after office changes and before moving critical applications onto Wi-Fi.

What a professional Wi-Fi review should include

  • A discussion about users, applications, floor plans and business priorities.
  • A survey of coverage, interference, channel use and client density.
  • Review of cabling, switches, PoE capacity, firewall and internet connectivity.
  • A plan for access-point locations, network names, security and segmentation.
  • Separate policies for staff, guests and connected devices.
  • Performance and roaming tests after installation.
  • Documentation, monitoring, updates and a support owner.

Do not overlook the wired network

Wireless access points depend on cabling, switches, power and a properly configured firewall. Replacing access points alone will not fix a failing switch, damaged cable or saturated broadband circuit. Review Wi-Fi as part of the complete network, including resilience and business connectivity.

Plan Wi-Fi around the business

A good wireless network should be boring: staff connect, move and work without thinking about it. MSP247 designs and supports business networks and Wi-Fi as part of a complete managed IT solution.

Book a Wi-Fi and network review if you are seeing dead zones, unreliable calls, slow performance or unmanaged equipment.

How to Manage Windows, Mac, iPhone, iPad and Chromebook Devices Under One IT Policy

Windows, Mac, tablet and mobile devices connected to one secure IT management platform

Published July 2026

Most small and medium-sized businesses no longer run a single type of computer. Windows laptops may sit beside Macs, directors use iPhones and iPads, and some teams prefer Chromebooks. This can improve productivity, but only if every device follows a consistent security and support policy.

The goal is not to make every platform identical. It is to apply the same business outcomes—known ownership, secure access, current software, protected data and reliable support—using the right management tools for each operating system.

Begin with one device standard

Create a written standard that applies to company-owned and approved personal devices. It should define which operating systems and versions are supported, how devices are enrolled, who can install software, where business data may be stored, and what happens when a device is lost, replaced or returned.

A useful policy is short enough for staff to understand but specific enough for IT to enforce. Avoid vague statements such as “devices must be secure”. State the controls: automatic updates, disk encryption, multi-factor authentication, screen-lock timing, endpoint protection and approved cloud storage.

Keep a complete inventory

Every device should have an owner, serial number, model, operating system, purchase date, warranty status and management status. Record whether it is company-owned or personal and which business services it can access.

Inventory is the foundation of good support. You cannot patch, replace or recover a device you do not know exists. A managed IT service can maintain this view automatically instead of relying on a spreadsheet that goes out of date.

Use central identity across every platform

Staff should use named business accounts rather than shared passwords or local-only logins. A central identity platform gives the organisation one place to add users, enforce multi-factor authentication, remove access and review suspicious sign-ins.

Apply conditional access where appropriate. For example, sensitive applications may require a managed, compliant device and a stronger sign-in method. This protects business data without banning Macs, iPads or Chromebooks simply because they are different.

Enrol devices before they reach the user

Modern device management can configure equipment during setup. Windows devices can be enrolled into a management platform; Apple devices can use Apple Business Manager with mobile-device management; Chromebooks can be enrolled into Google Admin; and iPhones or iPads can receive managed settings, applications and restrictions.

Pre-enrolment reduces manual work and gives every new starter a repeatable experience. It also ensures encryption, security settings and required applications are present before business data is accessed.

Patch operating systems and applications

Automatic operating-system updates are essential, but browsers, productivity tools, PDF readers and specialist applications need attention too. Define an update window, monitor failures and keep an exception process for software that requires testing.

Do not assume an Apple or Chromebook device is automatically secure. Every platform receives security fixes, and every platform can become exposed when it is left behind.

Protect data, not just hardware

Keep business documents in approved cloud services or managed file systems, not only on the local desktop. Use encryption on laptops and mobile devices, restrict unapproved sharing, and make sure important data is backed up independently of synchronisation.

For personal devices, separate business data from private data as far as the platform allows. Selective wipe can then remove company accounts and information without erasing the user’s photographs and personal applications.

Apply a practical security baseline

  • Multi-factor authentication for business accounts.
  • Encryption enabled and recovery keys stored securely.
  • Supported operating-system and browser versions.
  • Endpoint protection appropriate to each platform.
  • No routine local administrator access for standard users.
  • Automatic screen locks and strong device passcodes.
  • Remote lock or wipe for lost company devices.
  • Approved Wi-Fi, VPN and remote-access configurations.

Design onboarding and offboarding together

A device policy is tested when someone joins, changes role or leaves. Use a checklist to create accounts, assign licences, enrol equipment and grant only the access needed. At departure, disable sign-in promptly, recover company devices, remove managed data from personal equipment and preserve required business records.

Support users consistently

People should have one route to request help regardless of device. Support teams need remote-assistance tools, documentation and escalation paths covering Windows, macOS, iOS, iPadOS and ChromeOS. Procurement should also be coordinated so new hardware is compatible, supportable and covered by an appropriate warranty.

One policy, several technical controls

A mixed-device workplace is manageable when policy starts with business outcomes and the technical controls are adapted to each platform. The result is more choice for staff without losing visibility, security or accountability.

MSP247 supports complete environments across Windows, Mac, iPhone, iPad, Chromebook, servers, networks and cloud services. Talk to us about a mixed-device management review.

Windows 10 End of Support: A Practical Migration Checklist for UK SMEs

Secure Windows 10 migration and device upgrade for a UK small business

Published July 2026

Microsoft ended support for Windows 10 on 14 October 2025. Windows 10 PCs did not suddenly stop working, but most no longer receive free security updates, feature updates or standard technical support. For a business, that turns every remaining Windows 10 device into a risk that needs an owner and a plan.

If your organisation still has Windows 10 laptops, desktops or specialist systems, this checklist will help you move forward without disrupting staff or replacing equipment blindly.

Why unsupported Windows 10 devices matter

An unsupported computer may continue to run familiar software, but new vulnerabilities can emerge without being fixed through normal Windows Update. Over time, browsers, security tools and business applications can also reduce or end compatibility. That creates avoidable exposure and may conflict with customer, insurer or regulatory expectations.

Microsoft offers paid Extended Security Updates (ESU) for eligible Windows 10 22H2 devices. ESU can provide critical and important security updates for a limited period, but it does not add new features or replace a migration plan. It is best treated as a temporary bridge for devices that genuinely cannot move immediately.

1. Build an accurate device inventory

Start with facts. Record every Windows device, its user, location, age, model, warranty, Windows edition, storage capacity, encryption status and business purpose. Include shared reception PCs, workshop machines, meeting-room devices and laptops that rarely connect to the office.

A managed inventory is much safer than relying on staff to report what they use. MSP247’s managed IT support can give you a current view of operating systems, patch status and hardware health across the estate.

2. Check Windows 11 eligibility

Some Windows 10 computers can be upgraded to Windows 11; others do not meet Microsoft’s hardware requirements. Check processor support, TPM 2.0, Secure Boot, memory and storage. Do not force Windows 11 onto unsupported hardware: that can create another device that is difficult to support and may not receive the expected updates.

Hardware eligibility is only half the decision. A five-year-old PC that technically qualifies may still be slow, unreliable or close to the end of its useful life. Compare the cost of upgrading, testing and supporting it with the cost of a suitable replacement from a planned IT procurement programme.

3. Map critical applications and peripherals

List the software and hardware each team depends on: line-of-business applications, browser extensions, accounts packages, label printers, scanners, smart-card readers, VPN clients and specialist USB or serial equipment. Confirm vendor support for Windows 11 and test important workflows before a wide rollout.

Pay special attention to systems that are tied to old machinery or software. They may need ESU, network isolation, restricted internet access or a carefully planned application upgrade. A legacy dependency should be documented as an exception, not allowed to remain invisible.

4. Decide: upgrade, replace, isolate or retire

  • Upgrade eligible, healthy devices after compatibility testing.
  • Replace ageing or ineligible devices with models suited to the user’s workload.
  • Isolate temporarily a specialist Windows 10 system, using ESU where eligible and additional network controls.
  • Retire unused devices, securely erasing business data and recording disposal.

5. Protect data and user settings

Before any upgrade or replacement, verify that business data is stored in an approved location and backed up. Cloud synchronisation is useful, but it is not automatically a complete backup. Check browser favourites, email archives, application settings, certificates and locally stored files.

Confirm that BitLocker recovery keys and administrator credentials are available. Test at least one restore rather than assuming the backup works.

6. Pilot before the main rollout

Select a small group representing different roles and applications. Upgrade or replace their devices first, then monitor sign-in, printing, scanning, VPN access, Microsoft 365, line-of-business software and performance. Record fixes so the wider rollout is repeatable.

Schedule migrations in manageable groups and keep users informed. A clear appointment, a short checklist and a known support contact reduce downtime and frustration.

7. Apply a consistent security baseline

A new operating system is an opportunity to standardise security. Enforce multi-factor authentication, disk encryption, supported endpoint protection, automatic patching, screen locks and least-privilege access. Remove unnecessary local administrator rights and enrol devices in your management platform before they are handed to users.

8. Finish the job

After migration, check the inventory again. Every Windows 10 device should have been upgraded, replaced, formally excepted or retired. Remove old computer accounts, licences and remote-access tools, and arrange secure data destruction for disposed hardware.

Need help completing your Windows 10 migration?

MSP247 can inventory your estate, assess Windows 11 compatibility, plan procurement, migrate users and manage the finished environment across Windows, Mac, iOS and Chromebook devices. Contact us for a practical migration review.

Official references: Microsoft: Windows 10 support has ended and Microsoft Learn: Windows 10 ESU.

IT Support for York Hospitality and Tourism Businesses

York skyline connected by secure cloud and network technology

York’s hotels, restaurants, visitor attractions and tourism businesses depend on technology at exactly the moments they are busiest. Booking platforms, payment systems, guest Wi-Fi, telephony, cameras and staff devices all need to work together. Support must therefore consider the whole operation, not just the computer behind reception.

Identify the services that cannot stop

Map the customer journey from online booking to arrival, payment and follow-up. Record the systems used at each stage, their suppliers and what staff should do during an outage. Payment processing, booking availability and communications may need priority recovery arrangements.

  • Property, booking or reservation systems
  • Point-of-sale and payment connectivity
  • Guest and staff Wi-Fi
  • Cloud telephony and messaging
  • Door access, cameras and other site systems
  • Back-office devices, email and finance applications

Separate guests from business systems

Guest Wi-Fi should not provide a route to tills, office devices, printers, cameras or building controls. Use network segmentation, current encryption and managed business-grade equipment. Busy venues also need capacity planning: coverage that works in an empty dining room may fail during an event or full check-in period.

Build continuity around real trading conditions

A secondary internet connection can protect essential cloud and payment services, but failover must be tested. Consider which devices need battery protection and how staff will operate if a supplier platform is unavailable. Backups should cover business data, with documented restore priorities and regular checks.

Maintenance windows should respect opening hours and seasonal peaks. Monitoring can identify many developing device, server and network issues before customers notice them, allowing work to be scheduled with less disruption.

Make support easy for every shift

Seasonal and shift-based teams need a simple way to request help. Display the helpdesk route where staff can find it, document common checks and define who can approve account or configuration changes. Fast initial response matters, but clear priority and escalation are equally important during a live service issue.

MSP247 averages an initial ticket response within ten minutes and records 97% helpdesk satisfaction. Our team supports devices, networks, cloud services, connectivity and site technology through one helpdesk.

Review the complete guest and staff technology journey

Our free business IT review can assess Wi-Fi, connectivity resilience, security, backup, device management and supplier dependencies for a York hospitality or tourism business. The outcome is a prioritised improvement plan built around service continuity and the customer experience.

Microsoft 365 Security Checklist for Yorkshire Businesses

Microsoft 365 security checklist for Yorkshire businesses

Microsoft 365 security begins with identity. If an attacker gains control of a user or administrator account, they may be able to read email, change rules, access shared files and impersonate the business. This checklist gives Yorkshire SMEs a practical starting point, but settings should be matched to licence, risk and operational needs.

Protect identities and administrator access

  • Require multi-factor authentication using appropriate modern methods
  • Block legacy authentication where it is not required
  • Use separate named administrator accounts
  • Keep emergency access arrangements tightly controlled and monitored
  • Review sign-in risk, unusual locations and repeated failures
  • Remove leavers promptly and review dormant accounts

Reduce email and collaboration risk

Review anti-phishing, impersonation and malicious-link protection. Configure email authentication for your domains and monitor reports. Users should know how to report suspicious messages without forwarding harmful content around the business.

Check external sharing in SharePoint, OneDrive and Teams. Public or anonymous links should be deliberate, time-limited where appropriate and reviewed regularly. Guest accounts need an owner and a business purpose.

Bring devices into the security boundary

Cloud controls are weakened if an unmanaged or infected device can download sensitive data. Maintain an inventory, require supported software, encrypt storage and apply appropriate device-management and endpoint-protection policies across Windows, Mac and mobile platforms. MSP247’s RMM supports all major platforms and helps identify health and update issues early.

Plan for recovery and investigation

Decide how long logs are retained and who will investigate an alert. Document the steps for a compromised account: disable access, revoke sessions, reset credentials, inspect forwarding rules, preserve evidence and communicate safely. Test the process before a real incident.

Retention settings and recycle bins are not automatically a complete backup strategy. Confirm whether independent backup is required for email, OneDrive, SharePoint and collaboration data, and test actual restores.

Review continuously

Security settings change as Microsoft adds features, licences are altered and staff join or leave. Schedule regular reviews of privileged roles, sharing, application consent, mail rules, device compliance and backup status. Record exceptions and assign an owner.

Turn the checklist into a prioritised plan

MSP247’s free business IT review includes Microsoft 365 security, backup, device management, connectivity and supplier gaps. We can identify quick wins and build a proportionate improvement roadmap for your organisation.

How Much Does Managed IT Support Cost in Yorkshire?

Managed IT support costs and services for Yorkshire businesses

Managed IT support pricing varies because two businesses with the same number of employees can have very different technology, risks and expectations. A useful proposal should explain what is included and which assumptions drive the price. The lowest monthly figure is not necessarily the lowest total cost if essential monitoring, security or project work sits outside it.

The main factors that affect cost

  • Number of supported users and devices
  • Servers, cloud platforms, networks and business locations
  • Required support hours and priority response arrangements
  • Security, monitoring, patching and backup coverage
  • Complexity of line-of-business applications and supplier liaison
  • Age and condition of the existing estate
  • Included on-site time, projects and strategic reviews

Common pricing models

Per-user pricing can be simple when each person has a predictable set of devices and services. Per-device pricing may suit infrastructure-heavy estates, while a fixed managed-service fee can combine users, platforms and agreed outcomes. Some providers offer a core package with optional security, backup or on-site elements.

Whichever model is used, compare proposals line by line. Ask whether onboarding, documentation, monitoring, endpoint security, Microsoft 365 administration, backup checks, network support, procurement and service reviews are included. Confirm how after-hours work and projects are charged.

What good value looks like

Value is measured in avoided disruption, secure operations and productive staff—not only tickets closed. MSP247 averages an initial ticket response within ten minutes and records 97% helpdesk satisfaction. Our most senior engineer has 25 years of experience, while our all-platform RMM coverage raises alerts on many developing issues before customers notice them.

These figures should support, not replace, a clear agreement. Response is different from resolution, and complex incidents may depend on access, third-party suppliers or replacement equipment. A credible provider will explain those dependencies.

Budget for improvement as well as support

If the estate contains unsupported devices, weak backups or unreliable connectivity, the first year may include remedial projects. Separating those one-off changes from the ongoing service fee makes the comparison fairer. A staged roadmap can spread work according to risk and budget. MSP247 can also supply equipment from leading vendors including HP, Apple and Lenovo.

Get a price based on evidence

Our free business IT review covers Microsoft 365 security, backup and recovery, unsupported equipment, Wi-Fi and connectivity resilience, device management, and gaps in existing supplier arrangements. It gives both sides a clearer scope before a managed support proposal is prepared.

Switching IT Providers: A Practical Checklist for SMEs

Checklist for switching managed IT support providers

Changing IT provider should feel like a controlled handover, not a leap into the unknown. The safest transitions start with an agreed plan, a verified inventory and clear ownership of access. Avoid asking an outgoing provider to hand everything over before the new team has identified what is needed and how it will be protected.

Before giving notice

Review your current contract, notice period, licence commitments, equipment ownership and termination clauses. Identify internal decision-makers and critical business dates when disruption would be unacceptable. A new provider should complete an initial discovery without making risky changes.

  • Users, devices, servers, networks and sites
  • Domains, DNS, email and cloud tenants
  • Internet, telephony and mobile contracts
  • Backups, security tools and monitoring
  • Line-of-business applications and support contacts
  • Administrator accounts, encryption keys and recovery methods

Plan the secure transfer of access

Passwords should be transferred through an agreed secure method, not attached to ordinary email. Create named administrator accounts for the incoming team where possible, verify multi-factor authentication and remove legacy access only after the handover is proven. Keep an audit trail of what changed and when.

The outgoing supplier may hold documentation in its own system. Request current network diagrams, asset lists, licence details, backup schedules, policies, open issues and project history. The incoming provider should validate the information rather than assuming it is complete.

Protect continuity during the change

Decide who receives tickets at every stage and how emergencies will be escalated. Monitor email flow, backups, endpoint protection, internet connectivity and critical applications through the transition. Communicate the new support route to staff before the cutover, using simple instructions and a known contact.

Review after the first month

A transition is not complete when the passwords arrive. Hold an early service review to close documentation gaps, remove unused accounts, prioritise unsupported equipment and agree an improvement roadmap. This is also the right time to check whether the proposed agreement matches the real environment.

Start with an independent view of the estate

MSP247 supports businesses across Yorkshire with structured onboarding, ongoing monitoring and a single helpdesk across devices, networks and cloud services. Our free business IT review can help you understand the current position before you commit to a switch.

A practical technology partner

Clear ownership across your whole IT environment

MSP247 brings day-to-day support, security, connectivity and planning together so your team has one accountable route for help.

Whole-environment support

Windows, Mac, iPhone, iPad, Chromebook, servers, networks and cloud services supported as one working environment.

Yorkshire coverage

Responsive remote support with planned on-site assistance across York, Leeds and the wider Yorkshire region.

A clearly agreed scope

Responsibilities, priorities, escalation routes and available response arrangements are explained before service begins.

Security and continuity

Accounts, devices, backups and connectivity resilience are reviewed together instead of as isolated products.

This site uses analytics.