Tech Insight : 45% Of MSPs Keep Cash To Pay Off Hackers

A new survey reveals 45 per cent of managed service providers (MSPs) are setting aside cash to pay ransomware demands, as fears over AI-fuelled cybercrime continue to mount.

MSPs Under Pressure as Ransomware Attacks Surge

The finding comes from the CyberSmart MSP Survey 2025, which examined the security posture of 900 MSPs across the UK, Europe, Australia, and New Zealand. According to the report, nearly half of those surveyed now maintain a dedicated pot of money in case they are hit by a ransomware attack, a tactic where cybercriminals encrypt a victim’s data and demand a payment for its return.

Counter To Guidance

This approach appears to run counter to guidance from insurers, governments, and law enforcement agencies, which consistently urge organisations not to pay. However, the growing scale and frequency of attacks, often powered by artificial intelligence, appear to be forcing MSPs to adopt a more pragmatic (if controversial) strategy.

“Organisations shouldn’t rely on ransomware payments; rather, they should partner with organisations that can help proactively secure them,” said Jamie Akhtar, CEO and co-founder of CyberSmart.

Be Prepared

The report’s findings highlight a deepening sense of vulnerability among MSPs, many of which provide outsourced IT and cyber-security services to small and medium-sized enterprises (SMEs). With AI-generated phishing emails, malware, and deepfakes becoming increasingly sophisticated, the pressure to be prepared for the worst has never been higher.

More Breaches, More Budgets, More Confusion

CyberSmart’s research revealed that 69 per cent of MSPs had suffered two or more cyber breaches in the last 12 months, while 47 per cent reported being hit three times or more. These incidents are not just one-off events. For example, many are the result of supply chain vulnerabilities, such as the May 2025 breach where the Dragonforce ransomware group exploited a remote monitoring and management (RMM) tool to compromise multiple MSP clients.

Faced with mounting threats, MSPs are reacting in different ways. For example, 36 per cent now rely on cyber insurance as their primary defence, while 11 per cent (worryingly) have neither cyber insurance nor a ransomware fund in place, leaving them financially and operationally exposed if attacked.

Guidance Not Clear

It seems that part of the problem is that official guidance around ransomware payments remains fragmented and unclear. While governments generally discourage paying ransoms, enforcement is inconsistent outside the public sector. “What your business is advised to do will largely depend on where you’re based and who’s advising you,” CyberSmart noted in its commentary.

This has led to a patchwork of interpretations, with some MSPs feeling they have little choice but to maintain a reserve, despite the moral and strategic risks involved.

UK Government Moves to Ban Ransomware Payments for Critical Services

In July 2025, the UK government announced proposals to ban ransomware payments for public sector bodies and operators of critical national infrastructure (CNI). The measures, introduced by the Home Office following a public consultation, would apply to organisations such as hospitals, councils, schools, and water providers, sectors where operational downtime can endanger lives.

“Ransomware is a predatory crime that puts the public at risk, wrecks livelihoods and threatens the services we depend on,” said Security Minister Dan Jarvis. “We’re determined to smash the cyber criminal business model and protect the services we all rely on.”

Private Businesses Would Need To Notify Government Before Paying

Under the proposals, private businesses would not be banned outright from paying, but would be required to notify the government before doing so. This would enable authorities to offer advice, check for potential sanctions breaches (such as paying Russian-linked gangs), and gather intelligence to disrupt criminal networks.

Cybercrime’s Business Model Under Scrutiny

The rationale behind the payment ban is to undermine the business model of ransomware gangs, which rely on victims caving in quickly to avoid reputational damage, data leaks, or prolonged disruption. However, experts have warned that banning payments, especially only for certain sectors, may not have the desired effect.

“Ransomware is largely an opportunistic crime, and most cyber criminals are not discerning,” said Jamie MacColl, a senior research fellow at the Royal United Services Institute (RUSI). “They’re unlikely to develop a rigorous understanding of UK legislation or how we designate critical infrastructure.”

Others suggest the ban could increase the stakes for victims. “If the best solution is to just turn around and say to the hackers, ‘We’re not giving in to your demands anymore,’ don’t be surprised if they double down,” said Rob Jardin, chief digital officer at NymVPN.

The British Library, one of the most high-profile public victims of ransomware in recent years, chose not to pay after an attack in October 2023 devastated its systems. “We are committed to sharing our experiences to help protect other institutions and build collective resilience,” said Chief Executive Rebecca Lawrence.

AI Attacks Are Changing the Game

Perhaps the most striking shift in this year’s CyberSmart survey is the rise of artificial intelligence as the top concern for MSPs in 2025. AI overtook ransomware itself, with 44 per cent of respondents citing it as their biggest worry, compared to 40 per cent for traditional malware and ransomware threats.

This change reflects a growing trend in how attackers operate. For example, AI tools are now being used to write convincing phishing emails, build more evasive malware, and even create deepfake audio and video to impersonate executives or support social engineering attacks.

In 2024, 67 per cent of MSPs reported falling victim to AI-enabled attacks, a figure expected to rise in 2025 as generative and agent-based AI tools become more widely available to threat actors.

However, many MSPs feel ill-equipped to counter these evolving threats, with a lack of user-friendly, AI-specific defence tools still a key issue. “MSPs are being asked to do more, with fewer tools at their disposal,” the report concludes.

Customer Expectations Are Rising, But So Is Investment

The research also showed that 84 per cent of MSPs now manage their clients’ cybersecurity infrastructure, or both their cybersecurity and broader IT estate. This shift reflects growing client expectations for MSPs to provide end-to-end protection which are the kind of expectations that often come with greater scrutiny.

According to the CyberSmart research, 77 per cent of MSPs said potential customers are now evaluating their cyber credentials more carefully, especially in the procurement stage.

To meet demand, it seems that MSPs are now investing heavily. For example, 81 per cent have increased spend on hiring security specialists, and 78 per cent have upped budgets for cyber defence tools, training, and client services. Compliance is also high on the agenda, with 60 per cent hiring regulatory specialists and 64 per cent enhancing capabilities to align with frameworks such as NIS2 in the EU and the UK’s upcoming Cyber Security and Resilience Bill.

According to NCSC Director of National Resilience Jonathon Ellison, such steps are critical: “Ransomware remains a serious and evolving threat, and organisations must not become complacent. All businesses should strengthen their defences using proven frameworks such as Cyber Essentials.”

MSPs Prepared Yet Vulnerable

Despite the high rate of breaches, MSPs remain surprisingly confident in their security posture. For example, CyberSmart found that 76 per cent rate their cyber confidence as above average or higher. That said, only 20 per cent described their confidence as complete, suggesting that many know there’s room for improvement.

Looking at this research, for businesses relying on MSPs to manage their security, the message appears to be that while many providers are stepping up their game, others are still reacting to threats in ways that may not align with long-term best practice.

Co-op CEO Shirine Khoury-Haq, who oversaw the retailer’s response to a Scattered Spider ransomware attack, captured the sentiment well, saying: “What matters most is learning, building resilience, and supporting each other to prevent future harm. This is a step in the right direction for building a safer digital future.”

What Does This Mean For Your Organisation?

For MSPs and their clients, the emergence of ransomware funds could be seen as a move from aspirational resilience to operational realism. Despite official advice against paying cybercriminals, it seems that many MSPs clearly believe they cannot afford to be unprepared. With 69 per cent already breached multiple times in a single year and AI accelerating the scale and complexity of attacks, the temptation to hold a contingency reserve is understandable. However, this pragmatic stance may also entrench the very business model that governments and law enforcement are working hard to dismantle.

The UK’s proposed ransomware payment ban for public bodies and CNI highlights just how far official thinking has moved towards systemic deterrence. However, the exclusion of private businesses from that ban, and the option for them to pay under notification, risks creating an uneven response that may ultimately frustrate enforcement and dilute its impact. As Jamie MacColl pointed out, most ransomware gangs operate opportunistically and will not necessarily distinguish between regulated and unregulated targets. This raises questions about whether partial bans can realistically alter attacker behaviour.

For UK businesses, especially SMEs dependent on MSPs for protection, the findings raise difficult questions. For example, while many providers are making serious investments in tools, people, and compliance, others are still relying on reactive strategies that may offer short-term cover but little long-term assurance. The increasing scrutiny on MSPs is likely to intensify, particularly as clients seek partners who are both cyber confident and operationally transparent. Businesses must now evaluate not only whether their MSP has a ransomware plan, but also whether that plan reflects best practice or a compromise born of confusion.

For regulators, the lack of clarity and consistency around ransomware responses remains a core problem. Guidance alone is proving insufficient. A broader and more unified framework, alongside mandatory reporting, may be needed to help ensure MSPs, their clients, and their insurers are working from the same playbook. For now, the reliance on private ransomware funds points to a cyber landscape still dominated by tactical survival rather than strategic coordination.

Tech Tip – Reverse‑Search Images in WhatsApp to Verify Authenticity

Want to trust what you see? WhatsApp now lets you check the origin of an image by searching it on Google without ever leaving the app.

How to:

– Tap the image in chat.
– Tap the ⋯ menu and select ‘Search on web’ (or ‘Search image with Google’).
– The image is sent (with consent) to Google and results open in your browser.

What it’s for:

Helps prevent sharing misleading or manipulated images — perfect for vetting news, verifying content, and avoiding misinformation in work or group discussions.

Pro‑Tip: Use this on images sent in group chats or forwards before trusting or sharing them further.

Microsoft Teams vs Zoom – Which Is Best?

If you’ve ever wondered whether Microsoft Teams or Zoom is the smarter choice for meetings, messaging, and collaboration at work, you’re not alone – and in this guide, we’ll clearly explain how they compare so you can choose the right platform for your business needs.

Why These Two Platforms Are Always Compared

Teams and Zoom dominate the workplace communication market for good reason. They both offer video conferencing, chat, screen sharing, and integrations with third-party tools – and both saw explosive growth during the remote work boom.

However, beneath the surface, their purpose, strengths, and day-to-day feel are quite different.

Microsoft Teams is built for structured collaboration. It works seamlessly with Microsoft 365 and offers persistent chat, file sharing, and integrated tools for planning, automation, and documentation. Zoom, meanwhile, built its reputation on simplicity and video quality. It remains a favourite for meetings and webinars – especially with external audiences or users who don’t need the full Microsoft stack.

What Is Microsoft Teams?

Microsoft Teams is a unified communication and collaboration platform that’s tightly integrated with Microsoft 365. It offers real-time chat, voice and video calls, file sharing, and direct access to Office apps like Word, Excel, and PowerPoint.

Teams is often used for:

  • Daily team chat and project channels
  • Scheduled and ad hoc meetings
  • Collaborative editing of Office documents
  • Structured access to files, wikis, and task management
  • Integration with tools like SharePoint, Planner, Power BI, and third-party apps

Microsoft Teams has steadily evolved since its 2017 launch and now includes Copilot AI features, webinar functionality, and even frontline workforce tools.

What Is Zoom?

Zoom is a video-first communication platform best known for its high-quality meetings and ease of use. While it now offers team chat, phone, and whiteboard features, its core strength remains virtual meetings and webinars.

Zoom is commonly used for:

  • External meetings and sales calls
  • Training sessions and large webinars
  • Virtual events with breakout rooms
  • One-to-one or small group video calls
  • Quick, link-based meeting access with minimal setup

In recent updates, Zoom has added more advanced tools like Zoom Whiteboard, Zoom Phone, and a new AI Companion for meeting summaries and smart responses.

How Do They Compare on Key Features?

Meetings and Video Quality

  • Zoom consistently delivers excellent video and audio quality, even on weak connections. Its intuitive controls and meeting layouts make it a favourite for video-first teams.
  • Teams meetings integrate seamlessly into calendars and chats, and have improved video quality significantly. But some users still find Zoom quicker and simpler for spontaneous calls.

Chat and Messaging

  • Teams offers persistent, threaded conversations with clear channels, tagging, and integration with tasks and files. It’s a true digital workspace.
  • Zoom’s chat is functional but less structured. It works well for simple direct messages or meeting follow-ups, but lacks the project-orientated features Teams excels at.

Webinars and Large Meetings

  • Zoom leads here. It allows up to 1,000 participants in standard meetings and up to 50,000 with webinar add-ons. It also includes advanced registration, polling, and Q&A tools.
  • Teams offers webinars too (up to 1,000 participants), but they require more setup and are less intuitive for external users.

Third-Party Integrations

  • Teams integrates deeply with Microsoft 365, as well as tools like Trello, Salesforce, Adobe Sign, and hundreds more via its app store.
  • Zoom also supports wide integrations – including Slack, HubSpot, and Google Workspace – but it’s more focused on video features than full business workflows.

Ease of Use

  • Zoom’s interface is famously easy. Users can join meetings with one click and no learning curve.
  • Teams takes longer to get used to. It’s powerful, but some users find it cluttered or hard to navigate at first.

Feature Comparison at a Glance

Feature / AreaMicrosoft TeamsZoom
Chat & MessagingTeam collaboration & integrated workflowsHi-quality video conferencing / webinars
Video MeetingsPersistent, threaded chat with channels and tabsBasic messaging with limited structure
Webinars & EventsGood quality, integrated with calendar and chatExcellent quality, fast and simple to join
Ease of UseSupported, but less intuitiveAdvanced webinar tools and large audience support
Office IntegrationPowerful but steeper learning curveVery user-friendly and intuitive
Third-Party IntegrationsSeamless with Microsoft 365 (Word, Excel, Outlook, etc.)Supports Office but no native integration
Security & Compliance1,000+ apps (Trello, Salesforce, Adobe Sign)1,000+ apps (Slack, Google, HubSpot)
Storage & File SharingEnterprise-grade with advanced controlsGood, but fewer built-in enterprise controls
Breakout RoomsFull file management with version controlBasic file sharing via chat or cloud links
AI FeaturesMicrosoft Copilot for notes, summaries, schedulingZoom AI Companion for meeting summaries, responses
Licensing ModelBundled in Microsoft 365 plansModular with add-ons for webinars, phone, etc.

Security and Compliance

Security has become a major differentiator – and both platforms have improved significantly.

Microsoft Teams

  • End-to-end encryption for one-to-one calls
  • Data residency options and tenant controls
  • Compliance with GDPR, HIPAA, ISO/IEC 27001, and more
  • Conditional access, Microsoft Defender integration, and retention policies

Zoom

  • End-to-end encryption for meetings (must be enabled)
  • Password protection, waiting rooms, and participant controls
  • SOC 2 and GDPR compliance
  • Some advanced controls only available on paid plans

For regulated industries, Teams tends to offer more robust compliance options out of the box – especially for firms already using Microsoft 365.

Pricing and Plans

Microsoft Teams

  • Included in Microsoft 365 Business Basic (£4.90/user/month), Standard (£10.30), and Premium tiers
  • Free version available with limited features
  • Enterprise plans available with advanced analytics, security, and integrations
  • Great value for organisations already using Microsoft 365

Zoom

  • Free plan with 40-minute meeting limit for groups
  • Pro plan from £11.99/user/month, with options for Business (£15.99) and Enterprise tiers
  • Add-ons for webinars, phone, and extra storage
  • Good standalone choice for video-centric organisations

Use Cases – Which Tool Fits Which Scenario?

Use Teams if:

  • Your organisation is already using Microsoft 365
  • You need persistent chat, document sharing, and structured collaboration
  • Your workflows span multiple apps and departments
  • Compliance, security, and data residency are high priorities

Use Zoom if:

  • You need an easy, reliable video meeting platform
  • You regularly host webinars, training, or external events
  • You need fast setup and minimal onboarding
  • You work with clients or guests outside your IT ecosystem

What Are the Limitations?

No platform is perfect, and while both Microsoft Teams and Zoom offer plenty of value, each has its own set of limitations that could affect how well it fits your organisation’s needs. Understanding these potential drawbacks will help you make a more informed, realistic choice.

Microsoft Teams Drawbacks

  • Can feel slow or cluttered, especially for new users
  • Some features hidden behind higher-tier licences
  • Webinar and event features less polished than Zoom

Zoom Drawbacks

  • Limited collaboration tools beyond meetings
  • Free plan has strict time and feature limits
  • Requires add-ons for full functionality (e.g. Zoom Phone, Zoom Rooms)

So, Which Should You Use?

It really depends on what your teams need most.

If you’re looking for a comprehensive, secure collaboration hub with deep Office integration, Teams is the clear winner. It’s ideal for long-term project work, internal communication, and enterprise compliance.

If your top priority is high-quality meetings, external events, or client-facing webinars, Zoom stands out for its simplicity and flexibility. It gets people into meetings fast, and it performs reliably every time. In fact, many businesses use both – Teams for day-to-day collaboration, Zoom for external meetings or events. That hybrid approach often delivers the best of both worlds.

Tech Insight : (Unbelievable) AI Advances For Businesses

In this Tech Insight, we look at the latest AI developments, including AI agents creating their own language, Opera’s new AI-powered browsing assistant, and a growing debate over the risks of an international race to artificial general intelligence.

AI Agents Are Speaking Their Own Language

A new experiment called ‘GibberLink’ has just demonstrated an intriguing concept, i.e. AI voice agents that can recognise when they are speaking to another AI and then switch to a more efficient communication method (which is incomprehensible to humans). Developed at a hackathon in London by Meta engineers Boris Starkov and Anton Pidkuiko, GibberLink replaces human-like speech with GGWave, a sound-based protocol that allows AI systems to exchange information faster and with less computing power.

To human ears, the communication sounds like a series of beeps and boops, reminiscent of dial-up internet modems from the 1980s. While it may seem like a niche experiment, the technology could actually have real-world applications. For example, as companies increasingly deploy AI-powered customer service agents, there may be a need for them to communicate directly. By using this machine-native ‘language,’ AI agents could cut computing costs significantly, making AI-driven voice interactions cheaper and more efficient.

The apparent viral success of GibberLink has sparked both fascination and concern. For example, some fear that AI developing its own incomprehensible communication methods could reduce transparency and accountability. However, Starkov and Pidkuiko insist their project is simply an experiment, and they have open-sourced the code rather than commercialising it (at least for now).

Opera’s AI Assistant Could Change How We Browse

It seems that Opera, the long-standing web browser, is aiming to redefine internet browsing with its AI-powered feature called ‘Browser Operator’. Unlike traditional AI assistants that simply summarise search results, Browser Operator actively completes tasks for users. For example, if you need to book a flight, it’s just a case of providing a few details, and the AI will search, compare prices, and add the best option for you.

What sets Opera’s AI apart from competitors like OpenAI’s Operator and Anthropic’s Claude is that it operates locally within the browser. This ensures not only faster performance but also better privacy, as user data never leaves the device. Unlike cloud-based AI tools, which require remote servers to function, Browser Operator processes requests directly on the user’s machine.

The potential benefits are clear, i.e. more efficient browsing, time saved on repetitive online tasks, and a more seamless digital experience. However, as with any AI-driven automation, questions remain about how much control users will ultimately have over decisions made on their behalf. Opera has included safeguards, allowing users to pause or cancel tasks at any time, ensuring that humans remain in the loop.

Eric Schmidt Warns Against an AI Arms Race

Amidst the rapid AI advancements, former Google CEO Eric Schmidt and two co-authors, Alexandr Wang and Dan Hendrycks, have just published a policy paper warning against a US-led push for artificial general intelligence (AGI). It seems they’re concerned that an aggressive AI race could provoke international retaliation, particularly from China, and potentially destabilise global relations.

Schmidt and his colleagues argue that the pursuit of AGI (a hypothetical AI system with intelligence surpassing human capabilities) should not be treated like the Manhattan Project, the US government’s programme to develop nuclear weapons in the 1940s. Instead, they propose a more cautious strategy, advocating for ‘Mutual Assured AI Malfunction’ (MAIM), which suggests that governments should focus on defensive measures to deter AI-driven threats rather than escalating an AI arms race.

The paper challenges the notion that the US must ‘win’ the AGI race, arguing that such thinking could lead to dangerous consequences, including pre-emptive cyberattacks from adversaries. Instead, they suggest limiting access to powerful AI chips, strengthening cybersecurity, and ensuring AI remains under human control.

What Does This Mean for Your Business?

These developments show just how rapidly AI is reshaping industries, and why businesses need to stay ahead of the curve. The rise of AI agents like GibberLink suggests a future where automated systems could interact more efficiently without human intervention. While this might reduce costs, businesses relying on AI-driven communication must consider transparency and ethical oversight to maintain customer trust and regulatory compliance.

Meanwhile, Opera’s Browser Operator signals a shift in how AI can automate everyday digital tasks. For businesses, this could mean exploring ways to integrate AI-powered automation into their workflows to improve efficiency. Whether it’s customer service, e-commerce, or operations, AI-driven task completion could actually free up human employees for more strategic work. However, as with any AI system, companies will need to carefully manage data privacy concerns and ensure these tools remain user-controlled rather than fully autonomous.

Also, the debate over AGI development highlights broader implications for businesses investing in AI research. If governments take a more defensive stance, regulations around AI chips and open-source models could tighten, limiting access to cutting-edge AI innovations. For businesses in cybersecurity, cloud computing, and AI ethics, this could create new opportunities (but also new risks). Understanding the shifting regulatory landscape will be critical for companies looking to leverage AI without falling foul of future legal constraints.

The main message here is, therefore, that as AI continues to evolve, businesses that can embrace its efficiencies while maintaining ethical and regulatory oversight are likely to be best positioned for long-term success. Whether integrating AI assistants, automating customer interactions, or staying informed on global AI policy, companies that adapt strategically will stay competitive in an increasingly AI-driven world.

Tech Insight : UK’s New Cyber Severity Scale

The UK’s Cyber Monitoring Centre (CMC) has now started categorising cyber events using a scale designed to assess the impact and severity of attacks (similar to the Richter scale for earthquakes).

What is the Cyber Monitoring Centre?

The Cyber Monitoring Centre (CMC) is an independent, non-profit organisation founded by the UK’s insurance industry to enhance trust in cyber insurance markets and improve national understanding of digital threats. Officially unveiled at a Royal United Services Institute (RUSI) event on 6 February 2025, the CMC has been operating behind the scenes for a year, refining its methodology before making its system publicly available.

How Does the Cyber Event Severity Scale Work?

The CMC has introduced a five-level categorisation system to rank cyber events based on their severity and financial impact. The scale ranges from one (least severe) to five (most severe), considering two key factors:

1. The proportion of UK-based organisations affected.

2. The overall financial impact of the event.

Only incidents with a potential financial impact exceeding £100 million, affecting multiple organisations, and with sufficient available data will be classified. The CMC will collect insights from polling, technical indicators, and other incident data, all reviewed by a Technical Committee of cyber security experts.

Once categorised, cyber events will be published along with detailed reports that outline the impact, methodology, and response strategies. This information will be freely available to businesses and individuals worldwide.

CMC CEO Will Mayes emphasised the importance of this classification system, stating: “The risk of major cyber events is greater now than at any time in the past as UK organisations have become increasingly reliant on technology. The CMC has the potential to help businesses and individuals better understand the implications of cyber events, mitigate their impact on people’s lives, and improve cyber resilience and response plans.”

The rating system initiative is being spearheaded by a team of cyber security experts and industry leaders, with former National Cyber Security Centre (NCSC) chief Ciaran Martin serving as Chair. Explaining the importance of the CMC’s work, Martin says: “Measuring the severity of incidents has proved very challenging. This could be a huge leap forward. I have no doubt the CMC will improve the way we tackle, learn from, and recover from cyber incidents. If we crack this, and I’m confident that we will, ultimately it could be a huge boost to cyber security efforts, not just here but internationally too.”

Why Is the UK Introducing a Cyber Severity Scale?

The new initiative has been launched in the UK to essentially help measure the severity of cyber threats, thereby (hopefully) bringing much-needed clarity to an ever-evolving digital battleground.

Cyber attacks have become increasingly frequent and damaging. In 2023 alone, the UK suffered over seven million cyber attacks, costing the economy an estimated £27 billion per year. From ransomware crippling hospitals to large-scale data breaches exposing personal and financial information, the need for an organised, systematic approach to assessing cyber threats has never been greater.

Martin has stressed that a standardised metric for cyber event severity has been long overdue, and has highlighted how: “If you get a major incident in a large organisation, the results can be absolutely devastating. Hospitals can be brought to their knees.”

Martin has also noted the fact that because international threat actors, including state-backed groups from Russia and China, are constantly evolving their tactics, the UK must now be better prepared.

How Will This Benefit UK Businesses?

For UK businesses, the introduction of the CMC’s cyber severity scale could be an important step in cyber risk management and its benefits could include:

– Clarity and consistency. Businesses will have an easily understood, objective framework to gauge the severity of cyber incidents and make informed decisions.

– Better risk assessment. Insurers, regulators, and industry leaders will be able to assess cyber risks more effectively, leading to better cyber insurance policies and risk management strategies.

– Faster response times. With categorised reports on cyber incidents, organisations can respond more quickly and appropriately to emerging threats.

– Improved cyber resilience. Detailed incident reports will help organisations refine their cyber security measures and prepare for future attacks.

CMC CEO Will Mayes has also highlighted how the CMC’s work will be supported by a broad range of global cyber security experts, saying: “I would also like to acknowledge the support from a wide range of world-leading experts who have contributed so much time and expertise to help establish the CMC, and continue to provide data and insights during events. Their ongoing support will be vital, and we look forward to adding further expertise to our growing cohort of partners in the months and years ahead.”

Potential Challenges and Drawbacks

Despite its promise, and although it’s still very early days, it should be acknowledged that the CMC’s classification system is not without potential challenges. These include:

– Accuracy and data availability. Since categorisation relies on accurate data collection, incomplete or delayed reporting could affect the reliability of classifications.

– Speed (or lack of it) of assessment. The CMC aims to classify events within 30 days, but in 2025 this timeline may take longer. Delays in categorisation could impact real-time responses.

– The threshold for categorisation. By focusing on incidents causing over £100 million in damage, smaller but still significant attacks may not be classified, potentially leaving some businesses without crucial insights.

– The potential for misinterpretation. While the scale is designed to simplify communication, businesses and the public may misinterpret severity rankings, leading to unnecessary alarm or complacency.

UK Not The First Country To Try It

The UK is not the first nation to attempt a structured approach to cyber threat classification, but the CMC’s initiative represents a more comprehensive framework than many existing models. The US, for instance, has the Cyber Incident Severity Schema, a classification system used by federal agencies, but it does not currently have the public-facing clarity or structured ranking system that the CMC intends to implement.

Other European nations have also been watching the CMC’s developments closely, with cyber security experts suggesting that if successful, this model could be replicated in the EU or even standardised internationally. According to industry insiders, discussions are already taking place regarding cross-border data sharing agreements to strengthen global cyber response strategies.

Some cyber security experts have noted how a universal classification that could be used by all countries would make for a better system and, as the CMC begins classifying real-world incidents, there is potential for the UK to take a leading role in shaping a globally recognised cyber threat severity scale. Such a scale would help both businesses and governments get the data needed to make informed, strategic decisions in the fight against digital threats.

What Does This Mean For Your Business?

The introduction of the CMC’s severity scale could offer a clearer, more structured approach to understanding and responding to cyber threats. As cyber attacks grow in frequency and complexity, businesses, insurers, and policymakers require reliable data to assess risk and improve resilience. The CMC’s initiative looks like it could provide just that, i.e. a structured, transparent framework that could transform how the UK, and potentially the wider world, categorises and responds to major cyber incidents.

However, while the system has some clear benefits, it’s not without its limitations. The reliance on accurate and timely data presents an ongoing challenge, particularly given the complex and often opaque nature of cyber incidents. The CMC’s approach of only classifying large-scale events, while logical for identifying major risks, may also leave some significant but smaller-scale attacks unaccounted for. Also, the speed at which classifications are made will determine how effective the system is in providing real-time insights for businesses and policymakers.

Despite these concerns, the CMC’s work has already garnered some strong backing from cyber security experts and industry leaders, who recognise its potential to standardise risk assessment in a sector where clear benchmarks have long been lacking. The fact that other nations are closely monitoring the UK’s efforts also suggests that this initiative could, in time, help shape a globally recognised classification system, which is something that could prove invaluable in the fight against international cyber threats.

The success of the CMC’s cyber event severity scale will depend on its ability to consistently deliver accurate, timely, and actionable insights. If it achieves this, it has the potential to improve cyber resilience not just for UK businesses but for organisations worldwide. With cyber threats showing no signs of slowing, initiatives like this are going to be increasingly necessary.

Tech Insight : How Employment Rights Bill Will Reshape Tech Industry

With the UK’s new Employment Rights Bill expected to become law by 2026, we look at what this could mean for tech employers, the key changes, and practical impacts.

Protections for Workers from Day One 

The UK’s new Employment Rights Bill is set to bring seismic changes to the employment landscape, with major implications for tech industry employers. Introduced by the recently elected Labour government following commitments in their recent manifesto, this legislative overhaul aims to recalibrate the balance of power between employers and employees, enforcing protections for workers from their very first day of employment. The Bill’s provisions, expected to become law by 2026, are poised to reshape the strategies tech companies must employ in managing their workforce.

The Nature of the Tech Industry 

The tech industry, with its reliance on dynamic and flexible workforces, will be among the sectors most affected by these new regulations. Typically known for short-term contracts and high turnover rates due to project-based work, tech businesses are set to face heightened responsibilities to justify employment decisions from the outset. As companies await further details on specific provisions, it’s clear that preparation for compliance with the Employment Rights Bill should start now. With this in mind, here’s a taste of what tech employers can expect from the forthcoming changes and how they can begin to adapt.

The Bill 

The new Employment Rights Bill essentially encompasses 28 individual employment reforms, such as ending zero-hours contracts, prohibiting ‘fire and rehire’ practices, establishing day-one rights for paternity, parental & bereavement leave, plus strengthening statutory sick pay.

Immediate Protection Against Unfair Dismissal 

One of the key changes in the Employment Rights Bill is the introduction of unfair dismissal protection from day one of employment. Traditionally, UK law allowed employers to terminate employees within the first two years without risking unfair dismissal claims, providing flexibility to assess a new hire’s fit within the company. The new Bill abolishes this two-year window, making dismissals riskier and costlier without valid and well-documented reasons.

For tech companies, where rapid hiring and firing is common, this change could be particularly disruptive. Tech firms will need to adopt more stringent hiring processes to avoid costly claims. With the new Bill, therefore, companies may be forced to rethink this approach, adopting more cautious recruitment policies to minimise the risk of tribunal claims.

Changes to Probationary Periods 

Another possible change under discussion is the introduction of a statutory probationary period, which might fall at around nine months. Labour has not confirmed this length, but it signals a potential rebalancing of early employment protections that could impact tech hiring processes. While details are still under consultation, the purpose is to balance the rights of new employees with the flexibility employers need during the early months of employment. A statutory probationary period could provide tech firms with a partial grace period, though still with less leeway than the current two-year standard. Industry analysts predict that tech employers will need to invest more heavily in robust onboarding and training systems to assess new hires effectively within a shorter time frame.

To counter these limitations, many employers are now re-evaluating their recruitment pipelines. For example, extended interview processes and multi-stage assessments are becoming the norm in the sector, with many tech firms planning to introduce enhanced technical evaluations before finalising hiring decisions. Such measures, while potentially beneficial for retaining high-quality talent, will also likely slow hiring speeds, a disadvantage in a field where innovation and speed are essential.

Impact on Flexible and Zero-Hours Contracts 

The Employment Rights Bill, as it stands, could limit the use of zero-hours contracts, compelling employers to offer minimum guaranteed hours that reflect previous work patterns. While some sectors rely heavily on this contract type, the proposed changes aim to offer greater stability without entirely abolishing zero-hours arrangements. For tech employers, who often rely on freelancers and gig workers to address fluctuating project needs, this could lead to significant operational changes. Under the new law, workers with zero-hours contracts must be offered guaranteed hours reflective of their actual working history within a reference period. Additionally, employees working shifts will gain the right to receive reasonable notice for shift changes, with a minimum notice period likely equal to the length of the shift itself.

This requirement has provoked mixed reactions in the tech industry. For example, although proponents argue it brings stability to gig workers who are essential to project-based tech work, critics warn that the added rigidity could make tech firms less competitive. Tech businesses that rely on on-demand skills being forced to offer set hours could, therefore, find that their ability to respond quickly to client demands is more limited, perhaps meaning tough decisions about workforce structure will need to be taken.

Enhanced Flexibility Rights 

The Bill introduces additional rights around flexible working, compelling employers to justify any refusal of such requests thoroughly. In a sector where remote and flexible work has been the norm since the pandemic, this mandate may present less of a challenge on the surface. However, the onus on providing documented reasoning for refusal could add administrative strain, especially for companies managing hybrid or remote workforces across different locations and time zones.

The Bill’s requirement that companies substantiate their grounds for rejecting requests is seen as a progressive step, but some fear it could reduce the industry’s ability to manage work output effectively. For example, with tech work being essentially output-driven, being forced to justify rejecting flexibility could lead to managers feeling micromanaged themselves, thereby reducing productivity.

Implications for Public Sector Contracts and Two-Tier Workforce Rules 

For tech firms involved in public sector contracts, the Bill’s potential inclusion of a two-tier workforce rule could add a layer of operational complexity. This rule is designed to prevent disparities in wages and benefits between public sector employees transferred to private companies and their new private sector colleagues. Under the proposed rule, public sector staff moving to a private contractor would retain their existing terms and conditions, and private sector employees working in similar roles on the same project would be entitled to receive equitable treatment.

This change is especially relevant for tech consultancies partnering with the public sector, such as those handling IT infrastructure or cybersecurity projects. Should this rule advance into legislation, many firms may need to standardise benefits and pay rates across their teams, potentially resulting in significant cost increases. However, some employee advocates within the tech industry support these changes as a step towards fairer treatment, particularly in promoting equal pay for public and private staff working side by side.

Collective Redundancy Reforms 

Collective redundancy consultation, too, will see changes, especially affecting larger tech companies with distributed workforces. Under the Bill, a company with plans to lay off 20 or more employees in a set period will be required to conduct a collective consultation, even if redundancies are spread across multiple locations. Current legislation allows firms to treat individual sites separately for redundancy purposes, but the new rules would mean that all redundancies across a business must be grouped together in calculating whether the threshold for collective consultation has been met.

For tech employers who rely on flexible, location-independent workforces, this could result in higher administrative burdens and longer lead times for making structural adjustments. Industry observers warn that this change could reduce operational agility, especially for multinational tech firms with UK subsidiaries.

Other Considerations for Tech Employers 

The proposed Employment Rights Bill is likely to include several other changes that tech employers may need to seriously consider. Although many details are still speculative, here are some key areas that could have a significant impact if the Bill is enacted as Labour envisions.

Right to Disconnect 

The proposed Bill also includes the possibility of a “right to disconnect,” which would protect employees from work-related communications outside of their working hours. For tech employers, where global operations and multiple time zones often demand constant connectivity, this could present operational challenges. Employers may need to set clear boundaries for communication, reassess expectations for remote and hybrid teams, and introduce policies that respect employees’ work-life balance while preserving productivity.

Enhanced Data Privacy and Monitoring Protections 

Tech firms, especially those managing remote teams, often use productivity monitoring tools to maintain standards. However, the Bill may introduce stricter data privacy requirements around employee monitoring, compelling employers to justify any data collection or surveillance and to maintain transparency with staff. For tech companies reliant on these tools, this could mean a rethinking of monitoring practices to ensure compliance with heightened privacy standards.

Improved Parental and Family Leave Rights 

Under the proposed Bill, parental, paternity, and carer’s leave could become available from day one of employment, thereby broadening family-friendly benefits. For tech employers, this may require adjustments to their standard employment packages, ensuring they offer robust support to attract and retain talent with family responsibilities. Additionally, employers may need to adapt workforce planning to address potential skill gaps when employees take family leave.

Redefining Employment Status for Gig and Contract Workers 

The Bill may bring new definitions for employment status, making it more challenging to classify individuals as self-employed if they perform regular work for a company. For tech employers, this could mean that many freelancers gain employee status, with accompanying rights to benefits like holiday pay, sick leave, and pension contributions. This change could impact the cost structure of tech projects and reduce the flexibility many firms rely on when managing short-term or project-based workforces.

Workplace Equality and Pay Transparency 

Greater pay transparency and equal pay provisions are anticipated, which would likely require tech firms to disclose salary ranges and provide justifications for pay disparities. Although many companies in the tech sector have begun taking steps towards pay equity, formalising these measures under the Bill could make regular pay audits and the publication of gender and racial pay gap data mandatory. This could, in turn, influence recruitment and retention strategies within the sector.

Mental Health Support Requirements 

Given the growing awareness around mental health, particularly in high-stress sectors like tech, the Bill may mandate employers to provide mental health support, such as employee assistance programmes (EAPs) or mental health first aiders. In response, tech firms may need to increase investment in mental health resources, which could involve budgeting for support initiatives and integrating mental health considerations into workplace policies.

Enhanced Protection for Whistleblowers 

The Bill is expected to reinforce protections for whistleblowers, ensuring employees feel secure when reporting unethical or illegal practices. For tech companies handling sensitive data or regulatory compliance-heavy work, this could necessitate more robust reporting frameworks and confidential processes for whistleblower protection.

Additional Support for Skill Development and Training 

Labour’s interest in upskilling and career development, especially in rapidly evolving sectors like tech, is likely to be reflected in the Bill. Employers may need to offer structured training opportunities or upskill workers regularly, potentially with paid training time. For tech employers, this could mean establishing regular training programmes to ensure teams remain proficient with current technologies and compliance standards, possibly including support for certifications or advanced technical skills.

Requirements for Diversity and Inclusion Programmes 

The Bill may also introduce new obligations around diversity and inclusion (D&I), particularly for larger companies. Tech firms, especially those within sectors where diversity remains a challenge, may need to formalise their D&I efforts, establish accountability metrics, and promote fair representation across all levels of their workforce. This could drive positive internal change, fostering a more inclusive and balanced working environment that reflects the full range of available talent.

What Does This Mean for Your Business? 

The Employment Rights Bill, if enacted as anticipated, will mean a substantial shift for tech businesses in the UK. For an industry known for its flexibility, innovation, and rapid adaptation, these reforms could mark a new era of more structured compliance and cultural change. As the Bill aims to enhance security, fairness, and transparency in employment, it brings potential benefits but also significant responsibilities for tech employers.

For example, for many tech firms, the Bill could mean rethinking traditional workforce management. Where rapid hiring, freelance reliance, and flexible contracts have been fundamental, there may soon be constraints requiring more rigorous documentation, justification, and stability in employment practices. Tech employers may need to adapt quickly by implementing stricter hiring processes, formalised leave policies, and a heightened focus on employee rights, whether through enhanced family support, mental health resources, or data privacy safeguards. While some of these shifts align with current social trends, the added administrative burden could prove challenging, particularly for smaller firms or those with dispersed workforces.

That said, these changes could also pave the way for positive outcomes in talent retention and workforce satisfaction. As the industry faces increasing demand for skilled professionals, a commitment to fairer, more transparent employment practices could enhance a firm’s appeal to top talent. Measures such as clearer pay structures, enhanced training support, and stronger diversity and inclusion initiatives might not only ensure compliance but actively contribute to building a more resilient, engaged, and diverse workforce. For businesses willing to embrace these changes, the reforms may well foster a stronger culture of respect, fairness, and employee loyalty.

In preparing for the Bill’s potential enactment, tech firms, thankfully, at least have a valuable window of time to evaluate their practices and strategies. Adjustments made now could mitigate potential disruptions, while proactive planning may reduce operational risk and offer a smoother transition. As the industry braces for these landmark changes, the key for tech employers will be balancing compliance with the need for innovation. A thoughtful approach to integrating these new protections, alongside the flexibility that defines the tech sector, will be essential in navigating this evolving regulatory landscape. Whether these reforms ultimately hinder or help the tech sector’s growth, what is certain is that they demand both readiness and resilience from employers as they prepare for a future where compliance and competitiveness go hand in hand.

Tech Insight : What Is ‘Open Washing’ ?

With many tech giants now using ‘open’ as in ‘open source’ as a marketing term, we look at what the issues around this are, why it needs to be discouraged, and how this can be achieved.

What is Open Source?

To understand the question about ‘open washing’, it’s important to understand what real open source is. Defined and stewarded by the Open Source Initiative (OSI), open source goes beyond simply sharing code. In fact, it means giving users the rights to view, modify, and redistribute the software without undue restrictions. According to the OSI’s Open Source Definition, true open-source software adheres to ten principles, including free redistribution, access to source code, and the right to create derivative works. Open-source licences must also be non-discriminatory, ensuring that anyone, anywhere, can access and modify the software for any purpose.

These principles are meant to support innovation, community-driven improvement, and freedom from vendor lock-in, which is why open source has become so important in technology.

Not Everyone’s a Fan of Open Source

Despite the positive aspects of the principles of open source and its widespread use, not everyone is sold on it, with critics pointing to risks in security and sustainability. For example, while the transparency in open-source code may allow anyone to inspect for flaws, it also enables malicious actors to exploit vulnerabilities. In many cases, open-source projects tend to lack dedicated security teams, meaning patches can be slow to release, leaving users exposed. Financial viability is another issue; many open-source projects rely on volunteer developers or donations, making funding unpredictable and threatening long-term support and innovation. Without the financial backing of licensing fees that proprietary software can leverage, sustaining high-quality development and support over time is a challenge. Some critics also argue that while open source enables collaboration, it often lacks the reliability and consistent support associated with proprietary systems, creating potential pitfalls for users and developers alike.

So, What Is Open Washing?

‘Open washing’ is a term coined by internet policy researcher Michelle Thorne in 2009, referring to where using the word ‘open’ as a marketing term allows companies to appear open while maintaining control over their products. The term open washing is, therefore, along the same lines as the term ‘greenwashing,’ where companies claim to be environmentally friendly without substantive action. In open washing, companies appear to use “open” branding to exploit open source’s positive connotations without meeting its core values of transparency and accessibility. This co-opting of the term, therefore, undermines the foundational principles of openness, confusing consumers and diluting the legitimacy of the open-source community (open washing is a negative term).

Why Has Open Washing Become More Common?

Open source’s transformation from a fringe movement to a widely adopted practice has also made it highly attractive to companies looking to capitalise on its reputation. In the early 2000s, companies were wary of open source. For example, Microsoft’s then-CEO Steve Ballmer even called Linux a “cancer” due to the licence requirements that would obligate them to make their entire codebase open if it incorporated open-source elements. Today, however, open source is seen as innovative, ethical, and collaborative. It is endorsed by tech giants, governments, and educational institutions alike, with open-source projects like Linux, Kubernetes, and TensorFlow at the core of many enterprise systems.

The Appeal of Open Washing in AI and Big Tech

The stakes are especially high in the field of AI. Many AI models, particularly those from major tech corporations, operate under significant secrecy, which allows them to avoid scrutiny on issues ranging from ethical concerns to regulatory compliance. Open washing appears, therefore, to have become a convenient way for these companies to leverage the credibility of open source without actually relinquishing control or opening their models for true public or scientific examination.

For example, research by Andreas Liesenfeld and Mark Dingemanse at Radboud University surveyed 45 models marketed as open source and found that few actually meet the standards of true openness. The researchers found that only a handful (e.g. AllenAI’s OLMo or BigScience’s BloomZ) genuinely embody open principles.

In contrast, models from Google, Meta, and Microsoft often allow limited access to specific aspects, such as the AI model’s weights, but withhold full transparency into the training datasets or the processes behind fine-tuning – factors that are crucial for replicability and accountability.

Regulatory Incentives for Open Washing

The regulatory environment has also further incentivised open washing, particularly with the introduction of the EU’s AI Act, which came into force on 1 August 2024. This legislation, set to shape the governance of AI in Europe, includes special exemptions for open-source models. These exemptions mean that open-source AI products face fewer compliance requirements, especially regarding dataset transparency and ethical considerations. However, the EU has yet to define “open source” for AI models explicitly, leading to a gap that companies can exploit by labelling restricted models as open.

This regulatory grey area appears to have encouraged large corporations to stretch the definition of open source. By classifying their models as ‘open,’ they can benefit from reduced regulatory burdens while still keeping proprietary information hidden. This kind of open washing could, therefore, shield companies from scrutiny and enable them to bypass scientific and ethical standards that would otherwise apply.

Why Open Washing Undermines Openness and Transparency

The widespread practice of open washing could be seen as posing a risk to the integrity of the tech industry. For example, when companies brand restrictive products as open, they dilute the meaning of open source and weaken public trust. This practice could harm consumers and developers who assume these models are accessible for improvement, modification, or auditing. Without full transparency, end-users and even governments can’t fully grasp the capabilities and limitations of these tools, potentially leading to misuse and ethical oversights.

What Does the Open Source Initiative Say About It?

The Open Source Initiative (OSI) is a global nonprofit organisation that promotes and protects open-source software by maintaining the Open Source Definition, approving compliant licences, and advocating for open-source practices across industries. It is also, therefore, one of the most outspoken critics of open washing. For example, the OSI says that “misuse of ‘open’ erodes the fundamental trust” in open-source communities. According to the OSI, this dilution of open-source principles not only misleads the public but also endangers the health of the open-source ecosystem itself, as genuine open-source projects may struggle to gain traction when overshadowed by well-marketed, quasi-open products.

Composite Measures of Openness

Recognising that transparency in AI is multi-faceted, researchers have now proposed a composite measure of openness that includes access to datasets, training protocols, licensing clarity, and the model’s documentation. An example of this composite measure is a framework on openness in generative AI, presented at this year’s ACM Conference on Fairness, Accountability, and Transparency (FAccT), by Andreas Liesenfeld and Mark Dingemanse, researchers from Radboud University’s Centre for Language Studies in the Netherlands, specialising in language and AI studies.

Their framework, with its 14 dimensions of openness, highlights how open-source claims cannot rest on a single factor, such as access to model weights or basic documentation. Instead, the researchers say these claims should involve comprehensive access across multiple domains, offering the public, scientists, and policymakers a way to meaningfully assess openness. The idea is that by developing and implementing composite standards, the tech community could, therefore, discourage open washing and promote genuine transparency.

Clearer Definitions and Standards for Open Source AI

The current ambiguity around open source, particularly in AI, highlights the need for clearer standards. To tackle open washing, the OSI has recently started working on a formal definition for open-source AI, collaborating with various stakeholders to address unique considerations, like access to training data and replicability. This evolving framework aims to set definitive standards for what constitutes open source in the AI landscape, with the goal of curbing open washing and providing a measure for consumers and regulators to gauge the authenticity of open-source claims.

The Role of Public Awareness and Advocacy

To counter open washing, it may be important for both consumers and developers to recognise and question the authenticity of open-source claims. Community-driven transparency tools, such as open-source databases and audit platforms, can play a role in empowering users to make informed decisions. As Dingemanse notes, “evidence-based openness assessment is essential for a healthy tech landscape.” Awareness campaigns and advocacy groups can also shed light on open washing practices, pressuring corporations to align with true open-source standards.

What Does This Mean for Your Business?

As technology continues to evolve and embed itself deeper into everyday life, the importance of distinguishing genuine openness from ‘open washing’ becomes ever more critical. Open-source software’s promise lies in its potential for transparency, innovation, and community-driven growth. However, when companies engage in open washing, they undermine these principles, eroding public trust and complicating the regulatory landscape. This practice not only weakens the authenticity of open-source initiatives but also risks obscuring the boundaries between proprietary and truly open technologies, leading to a diluted understanding of what “open” truly represents.

The movement to counter open washing is gaining momentum through research, community initiatives, and regulatory efforts, yet it ultimately depends on public awareness and industry accountability. Informed consumers and developers play a vital role in demanding transparency and authenticity from tech giants. With organisations like the Open Source Initiative working to refine definitions and create accountability standards, there is hope for a future where open-source principles are upheld, respected, and protected. Clear standards and genuine openness are essential to sustaining an ecosystem where “open” means more than marketing, symbolising a commitment to collaboration, integrity, and the shared progress of technology.

With clearer definitions, regulatory oversight, and a strong community voice, it appears possible for the tech industry to preserve the values of openness and transparency while guarding against open washing. By holding companies accountable to genuine open-source principles, users, developers, and policymakers could help ensure that “open” remains a meaningful and respected term in the technology landscape.

Tech Insight : New Ways To Search

Search technology has transformed significantly from text-based queries back in the nineties to now, where there’s a wide range of interactive methods like voice, visual, and AI-driven tools. Here, we look at how these advancements are reshaping the way we search, with a focus on the latest innovations and trends in the search landscape.

The Changing Landscape of Search 

Search technology is currently undergoing a rapid transformation, driven by fierce competition between major tech companies like Google, Microsoft, and Amazon. While Google remains the dominant force (processing over 8.5 billion searches per day), other players are innovating and closing the gap by integrating advanced AI capabilities and new features. Microsoft’s Bing AI is increasingly incorporating AI-driven results to enhance search relevance, while Amazon focuses on evolving its product search and recommendation algorithms, positioning itself as a major contender in the e-commerce space.

The Way We Search Is Changing 

The way we search is also evolving. Voice search is becoming more prominent, with predictions suggesting that it will account for 30 per cent of all browsing sessions by 2030. Simultaneously, visual search, powered by technologies like augmented reality (AR) and image recognition, is emerging as one of the fastest-growing areas in search technology. These innovations are fundamentally changing user behaviour, as people move from traditional text searches towards more interactive and immersive experiences.

Competition Driving The Change 

The competition between these tech giants is intensifying, with each company striving to create the most seamless, intuitive, and user-friendly search tools. This has led to the development of AI-powered chatbots, AR search experiences, and personalised recommendations that are reshaping the way users interact with search engines.

Now, we’re going to take a brief look at the many types of searches currently available, each offering unique ways to access information and interact with the digital world.

Text Search 

Text search remains the most widely used and traditional search method, where users input keywords or phrases into a search bar on platforms like Google. Whether on desktop, mobile, or the Google app, this type of search allows users to retrieve vast amounts of information based on specific queries. It’s the backbone of modern search engines and is complemented by additional tools that enhance precision, such as advanced search operators.

Voice Search 

With the rise of smart devices, voice search has become increasingly popular. Users can activate searches using voice commands by simply saying “Hey Google” on Android devices or through other assistants like Amazon Alexa or Apple’s Siri. Voice search allows users to ask questions, perform searches, or control their devices completely hands-free. This is particularly useful when multitasking or when typing isn’t practical, and the technology has greatly improved around understanding natural language and context.

Visual Search with Google Lens 

Visual search, led by Google Lens, allows users to search using their smartphone camera. By pointing their camera at an object, text, or scene, users can instantly receive information about it, find similar products, or even translate text in real-time. Google Lens has opened new possibilities, allowing people to search for objects they don’t know the name of but can see. For example, by scanning a plant or an animal, users can identify the species instantly. This tool reflects how search is becoming more intuitive and integrated into everyday experiences.

Google’s New Video Search 

Google is further innovating with its new Video Search feature, which allows users to point their camera at an object or scene, ask a question about it, and receive search results in real-time. This feature enables deeper interaction with the physical world, allowing people to get information on what they are seeing, whether it’s a historical building, a piece of art, or even a consumer product. This development is part of a growing trend where the boundaries between the digital and physical worlds blur, making search more accessible and context-driven.

Image Search 

Image search has evolved to allow users to perform reverse image searches, primarily through Google Images. Users can upload an image or drag and drop it into the search bar to find similar images, verify the source, or learn more about the content. This is particularly useful for identifying things like locations, people, or products based on an image alone. It’s a key tool for anyone needing to trace visual content across the web.

Multisearch (Combining Text and Image) 

Multisearch is an innovative approach that allows users to combine text and image input into a single query. This is ideal for instances where an image alone doesn’t provide enough detail. For example, users can upload a photo of a product and then add specific descriptors such as colour, brand, or style to refine the search. This combination enhances accuracy, especially when searching for specific items or variations that aren’t immediately obvious from an image alone.

Video Search (YouTube and Google Video Tabs) 

Search has become more multimedia-focused, and video search is a huge part of this shift. On Google, users can switch to the “Videos” tab to find relevant content from platforms like YouTube, Vimeo, or other video-based sources. YouTube itself offers an internal search function, supporting both text and voice searches, allowing users to locate tutorials, entertainment, or educational videos based on their interests. As more content shifts to video formats, this type of search is becoming an essential tool for users.

Maps Search 

Google Maps supports location-based searches, allowing users to find businesses, services, and landmarks in a specific area. With text or voice input, users can search for restaurants, shops, or attractions, while accessing additional features like reviews, photos, and directions. This has become an essential tool for daily life, integrating geographic data with business information, helping people navigate their world with ease.

Hum to Search

If you’re thinking of a song, Google allows you to hum, whistle, or sing the melody, and it can identify the song for you. Note, we have largely focused on Google for this text, although there are other specific platforms that allow users to search for specific sounds to identify their origin, such as identifying a species of bird via its birdsong (e.g. BirdNET or ChirpOMatic). Other specialist platforms doubtless exist for other animals and/or sources of noise.

Shopping Search 

Google Shopping is another popular tool, helping users compare products, prices, and store availability. This search method is increasingly tied to AR (Augmented Reality) tools, where users can visualise products in their space before purchasing. Shoppers can now search for items, filter results based on price, location, or store, and even see product reviews and specifications. The combination of search with AR enhances the shopping experience, making it more immersive and informed.

In-App Search on Mobile Devices 

On Android devices, in-app search allows users to locate content within specific apps directly from the Google search app. This includes finding emails, documents, or social media posts without switching between apps. It’s an efficient way to manage information across multiple platforms, ensuring users can access relevant data without leaving the search interface.

AR Search for 3D Objects 

Augmented Reality (AR) Search has become a notable development, particularly in fields like education and e-commerce. Using Google AR, users can view 3D models of search results, such as animals, historical artifacts, or even products. This type of search is highly interactive, allowing people to see life-like models of objects in their real environment, enhancing the depth of the search experience.

Discover (Content Recommendations) 

Google Discover shifts the search paradigm by offering content without the need for a direct query. This feature curates articles, videos, and other content based on a user’s interests and search history, presenting it in a personalised feed. It’s a proactive search tool, constantly updating to present users with new and relevant content as their interests evolve.

AI-Powered Search Using Chatbots 

AI chatbots, such as ChatGPT, Bard, and Bing Chat, have revolutionised search by offering conversational interfaces. Rather than simply retrieving links, these chatbots can generate detailed responses, summarise information, and offer personalised recommendations. For example, users can ask ChatGPT to find information on a specific topic and receive a coherent, natural-language answer, instead of browsing through multiple web pages. These AI tools are rapidly improving, offering new ways to search, especially for more complex, nuanced questions that traditional search engines might struggle with.

What Does This Mean For Your Business? 

The ongoing evolution of search technology presents both opportunities and challenges for businesses aiming to stay visible in this increasingly diverse landscape. As the methods people use to search diversify, companies must adapt their strategies to ensure they can still be easily found across all platforms and search types. It’s no longer enough to rely solely on traditional SEO tactics focused on text-based searches. To maintain or enhance their visibility, businesses now need to consider how they are appearing in voice, visual, and AI-driven searches, as well as adapting to the rise of augmented reality and interactive search experiences.

Voice search, in particular, has significant implications for businesses. As more users turn to devices like smart speakers and mobile assistants to ask questions and perform searches, optimising for voice queries is becoming more important. Voice searches tend to be more conversational and question-based, which means businesses need to adapt their content strategies to capture these queries effectively. For example, having concise, easily digestible answers to common questions about their products or services can help businesses rank higher in voice search results.

Similarly, visual search tools like Google Lens and augmented reality searches are transforming how consumers discover products. Retailers and brands need to ensure that their product images are optimised for visual search. High-quality visuals, detailed metadata, and clear product descriptions can help ensure that when users point their cameras at a product, the brand’s offering appears in search results. Also, augmented reality features, such as those in Google Shopping, allow consumers to visualise products in their environment before purchasing. Businesses that invest in AR-ready content and experiences can now tap into a growing consumer base that values immersive, real-time interactions.

The growing importance of AI-powered chatbots in search also means businesses will need to rethink how they engage with potential customers. AI tools like ChatGPT and Bing Chat provide more in-depth, conversational responses, making it essential for businesses to have well-structured and informative content that these systems can draw from. This means producing detailed yet user-friendly content that provides value and can be referenced by AI systems to give consumers the answers they seek.

For businesses operating in local markets, optimising for Google Maps and local searches is critical. Consumers increasingly rely on location-based searches to find services, restaurants, shops, and more. Ensuring that business listings are accurate, up to date, and include reviews, photos, and essential details is key to capturing local search traffic. Furthermore, investing in local SEO strategies to appear in voice searches for location-based queries will become increasingly important as consumers use voice assistants to find nearby services.

Tech Insight : Windows 10 vs Windows 11

In this insight, we compare and contrast the Windows 10 and 11 operating systems, focusing on how they perform in key areas like user interface, performance, security, compatibility, and cost.

Rolled Out 2021 

Since Microsoft’s rolled out Windows 11 in October 2021, many businesses have been deciding whether to upgrade or remain on Windows 10 even longer. For example, for some businesses, not yet upgrading to Windows 11 may have been due to concerns about hardware compatibility, the need for training on the new interface, potential software compatibility issues with legacy applications, and the costs associated with upgrading hardware and licences. Also, some may be waiting until closer to Windows 10’s end-of-support in 2025 to avoid any early adoption issues.

With this in mind, we’ll now shine a light on how both Windows 10 and 11 match up in terms of 9 key factors – user interface changes, performance improvements, security features, compatibility, deployment, productivity enhancements, customisation options, cost implications, and future-proofing, thereby helping you to get a more informed view of Windows 11 which could help OS decision making for your business.

1. User Interface and Usability 

Aspects of the user interface and usability are crucial as they directly impact how employees interact with the operating system on a daily basis.

Start Menu and Taskbar 

Windows 11 introduced a significant change in the Start Menu and Taskbar design. The Start Menu is now centred on the screen, a departure from the traditional left-aligned menu in Windows 10. This shift may initially have seemed disorienting to those who upgraded to Windows 11, but ultimately many have found that it provides a cleaner and more intuitive user experience. The centred Taskbar in Windows 11 complements this design by grouping app icons in the middle, which can improve accessibility for users working across wide-screen monitors. Although this change was intended to enhance user efficiency, it requires a brief adjustment period for users, i.e. employees familiar with Windows 10’s layout.

Snap Layouts and Multitasking 

One of the standout features in Windows 11 is the enhanced multitasking capabilities, particularly with the introduction of Snap Layouts and Snap Groups. These tools allow users to quickly organise multiple windows on their screen, maintaining an efficient workflow across various tasks. In contrast, Windows 10 offers basic snapping features that, while functional, lack the sophistication of Windows 11’s system. For businesses, this improvement in Windows 11 can translate into better productivity, especially for employees who need to manage several applications simultaneously.

Accessibility Features 

Windows 11 builds upon the accessibility features of Windows 10 by introducing enhancements such as improved screen readers, voice typing, and an updated dark mode. Microsoft designed these tools to make its operating system more inclusive, catering to users with different needs and preferences. The refinements in accessibility in Windows 11 could, therefore, be particularly beneficial for businesses that are more conscious of the need for inclusivity and seek to provide a flexible working environment for all employees.

2. Performance and Efficiency 

Performance and efficiency are important considerations because these factors determine how smoothly the operating system runs on business hardware.

System Requirements 

Windows 11 comes with more stringent system requirements than Windows 10, including the need for TPM 2.0, specific CPUs, and UEFI Secure Boot. These requirements mean that businesses using older hardware, for example, may need to upgrade their systems to support Windows 11, potentially leading to significant capital expenditure. However, for companies with newer hardware, the transition may be smoother, plus they could benefit from the optimised performance that Windows 11 offers.

Speed and Responsiveness 

All businesses are likely to want to work faster as well as smarter, and Windows 11 does offer faster boot times, better memory management, and overall improved responsiveness compared to Windows 10. These performance enhancements were designed to reduce downtime and improve efficiency, which is, of course, crucial in a business environment where time is money. For mobile users, Windows 11’s optimisation also offers a smoother experience when working on the go.

Battery Life (for Laptops) 

As most business laptop users will know, battery life is another critical factor. Windows 11 has battery optimisations that can extend the life of a laptop between charges, an improvement over Windows 10’s already decent performance in this area. For businesses, this could mean fewer interruptions and a more reliable mobile working environment.

3. Security Features 

Security is, of course, a top priority for businesses, as it protects sensitive data and ensures compliance with regulations.

Built-in Security Tools

Considering the level and evolving nature of cyber threats in today’s environment, security must be a top priority for businesses, and Windows 11 delivers several enhancements over Windows 10. Although both versions include robust tools like Windows Defender, Windows Hello and BitLocker, Windows 11 integrates these more deeply into the operating system. Also, Windows 11 supports more advanced security protocols, making it a better fit for businesses that need to protect sensitive data.

Zero Trust Security Model

Crucially, Windows 11 supports the Zero Trust security model more robustly than Windows 10. This model, which assumes that threats could be both external and internal, is becoming the standard for modern businesses. With features like hardware-based isolation, encryption, and malware prevention, Windows 11 is, therefore, designed to help businesses adopt a more comprehensive security posture.

End of Support for Windows 10 

One major factor in forcing the final switching decision will naturally be the fact that Microsoft has announced that support for Windows 10 will end in October 2025. This means that businesses still using Windows 10 after this date will be vulnerable to security threats due to the lack of updates and patches. This could be a compelling reason for many to plan an upgrade to Windows 11 sooner rather than later.

4. Compatibility and Application Support 

Compatibility with existing software and hardware is a vital consideration for a seamless transition.

Legacy Software Support 

One of the concerns when upgrading to a new OS is compatibility with legacy software. Windows 10 has been praised for its compatibility with a wide range of applications, including older ones. Windows 11, while designed to be compatible with most software that runs on Windows 10, may present some challenges with very old or niche applications. Businesses may, therefore, prefer to test their critical software on Windows 11 before committing to a full upgrade.

Virtualisation and Cloud Integration 

The cloud now plays a major role in the digital infrastructure of most businesses. Windows 11, for example, offers improved integration with cloud services and virtualisation technologies, such as Microsoft Azure. These enhancements support hybrid work environments, allowing businesses to leverage cloud computing more effectively. Windows 10 also supports these technologies, but Windows 11 is considered to be more streamlined in this regard, perhaps offering a more cohesive experience for businesses moving towards cloud-based operations.

Driver and Peripheral Compatibility 

One concern about upgrading to Windows 11 has been about driver and peripheral compatibility, particularly for older hardware. While Windows 11 is designed to support a wide range of devices, businesses using older peripherals may want to verify compatibility to avoid disruptions. Windows 10’s mature ecosystem, on the other hand, is likely to offer broader compatibility out of the box.

5. Deployment and Management

Deployment and management tools affect how easily businesses can upgrade, configure, and maintain their operating systems.

Upgrade Path

Obviously, it’s in Microsoft’s interest to make the upgrade path from Windows 10 to Windows 11 as smooth as possible (reducing support for older systems, boosting new hardware and software sales, and for Microsoft’s long-term revenue growth), with Microsoft providing tools to streamline the process. However, businesses may want to consider the logistics of deploying Windows 11 across their organisation, including the need for potential hardware upgrades and employee training. Windows 10 users may find the in-place upgrade process straightforward, but it’s still important to plan for any potential hiccups.

Device Management 

Windows 11 offers enhanced device management tools, including updates to Group Policy, Windows Update for Business, and Mobile Device Management (MDM). These tools are more advanced than those in Windows 10, offering businesses greater control over their devices and better alignment with modern IT management practices.

Windows Update and Servicing Model 

The update and servicing model for Windows 11 differs from Windows 10, with the former moving to annual feature updates. This change reduces the frequency of disruptive updates, allowing businesses to focus on stability. In contrast, Windows 10’s twice-yearly updates have been a source of frustration for some users due to the potential for unexpected issues.

6. Productivity and Collaboration 

Productivity and collaboration features are central to modern business operations, especially in remote and hybrid work settings.

Microsoft Teams Integration

Particularly since the pandemic, Microsoft Teams has become increasingly central to business communication, and Windows 11 features deeper integration with this tool (and the enhancements provided by AI). Many businesses have found that this integration has enhanced collaboration within businesses, making it easier for teams to stay connected and work efficiently, particularly in remote or hybrid work environments.

Microsoft 365 Enhancements 

Windows 11 is optimised for Microsoft 365 applications, offering performance improvements and new features that enhance productivity. These enhancements could make a noticeable difference in day-to-day operations for businesses that rely heavily on Microsoft’s productivity suite.

Widgets and Information Access 

The introduction of Widgets in Windows 11 has offered a new way to access information quickly. These customisable panels provide real-time updates on various topics, which are useful for business users needing quick access to data. While Windows 10’s Live Tiles offered a similar concept, Widgets in Windows 11 may be considered to be more refined and better able to serve a business context.

7. Customisation and Flexibility 

Customisation and flexibility are important considerations because they allow businesses to tailor the operating system to meet specific needs.

Personalisation Options 

Windows 11 offers a broader range of personalisation options compared to Windows 10, allowing users to customise the desktop experience to their liking. For businesses, this flexibility can help improve employee satisfaction by enabling a more tailored user experience.

Control over Updates 

One of the persistent issues with Windows 10 has been the control over when and how updates are installed. Windows 11, however, offers more refined options for managing updates, which can reduce downtime and disruption in a business setting. This improvement can be particularly valuable for businesses that need to maintain consistent uptime.

Support for Multiple Monitors 

Windows 11 provides better support for multiple monitors, a feature that is increasingly important in modern business environments. The improved handling of multi-monitor setups in Windows 11 can enhance productivity for employees who rely on complex screen arrangements, e.g. those in design or finance roles.

8. Cost and Licensing 

Cost and licensing considerations are essential for budgeting and long-term financial planning.

Licensing Requirements 

The cost implications of licensing Windows 11 versus Windows 10 are, of course, an important consideration for businesses. While Windows 11 may introduce new licensing models, the overall cost will depend on factors like hardware upgrades and training. Businesses should weigh these costs against the potential benefits of the new OS.

Total Cost of Ownership (TCO) 

The total cost of ownership for Windows 11 may be higher initially due to the need for hardware upgrades and potential training. However, the long-term benefits, such as improved security, performance, and productivity, could justify the investment.

Enterprise vs. Pro Versions 

Differences between the Pro and Enterprise versions of Windows 11 could influence the decision for businesses. The Enterprise version typically offers more advanced features, such as better security and device management tools, which could be particularly beneficial for larger organisations.

9. Future-Proofing and Innovation 

Future-proofing and innovation are important for ensuring that an operating system remains viable as technology evolves.

Long-Term Support and Updates 

Windows 11 offers a longer support timeline than Windows 10, which will reach end-of-support in 2025. For businesses looking to future-proof their operations, Windows 11’s extended support could be a decisive factor.

Emerging Technologies

Windows 11 is designed with emerging technologies in mind, such as AI, AR/VR, and 5G. For businesses looking to stay ahead of the curve, adopting Windows 11, therefore, may provide a competitive edge by enabling the integration of these technologies into their operations.

Integration with Next-Gen Hardware

Windows 11 is optimised for the latest hardware, including new CPUs, GPUs, and SSDs. This optimisation could influence business purchasing decisions, especially for companies planning to invest in new equipment to support future growth.

What Does This Mean For Your Business?

All things considered, the decision to stick with Windows 10 a bit longer or upgrade to Windows 11 is likely to be guided by your business’s specific needs and future goals. Windows 11 undoubtedly offers several improvements that can enhance productivity, security, and user experience, which make it an attractive option for businesses ready to invest in newer hardware and capitalise on emerging technologies.

However, with so much at stake in businesses, the upgrade process can’t be taken lightly. Businesses need to consider the implications for legacy software compatibility, potential costs associated with hardware upgrades, and the training required for employees to adapt to the new interface. For organisations that are looking for stability and have well-established workflows on Windows 10, there may be a case for delaying the upgrade until closer to Windows 10’s end-of-support date in 2025.

Ultimately, Windows 11 represents a relatively forward-looking operating system that aligns with the future of work, particularly for businesses embracing hybrid work models, advanced security postures, and cloud-based operations.