Tech Insight : AI Agents Are Starting To Rewrite The Software Industry

Enterprise spending on AI-native software is now growing far faster than traditional cloud software, signalling a major change in how businesses buy, use, and value technology.

Why The Traditional SaaS Model Is Under Pressure

For more than two decades, most enterprise software has operated on a relatively simple model. Businesses bought software licences based on the number of employees using a platform, often referred to as “per-seat” pricing.

This approach helped drive the growth of companies such as Salesforce, Workday, ServiceNow, Slack, Zoom, and countless other Software-as-a-Service (SaaS) providers. Revenue grew as customers added more staff and purchased more licences.

However, the rapid rise of AI agents and AI-native platforms is starting to disrupt that model.

Instead of simply giving employees tools to work with, AI-native systems increasingly aim to complete tasks themselves. For example, AI agents can now respond to customer enquiries, generate marketing campaigns, summarise meetings, analyse contracts, process onboarding requests, monitor systems, and automate internal workflows with limited human involvement.

This changes the economics of enterprise software because companies may no longer need as many human users interacting directly with traditional platforms.

The Spending Gap Is Growing Quickly

One clear sign of this transition comes from procurement platform Tropic, which analysed more than $18 billion in managed software spending. Its latest figures show AI-native enterprise spending grew by approximately 94 per cent year-on-year among mid-market and enterprise organisations, while primarily traditional SaaS spending grew by around eight per cent.

It’s important to note that these figures reflect Tropic’s customer dataset rather than the entire global software market. However, analysts increasingly believe the underlying trend is real and accelerating.

Also, research from Deloitte suggests software companies are now under growing pressure to become “AI-first” businesses, with agentic AI expected to transform software operations, pricing models, and customer expectations across the industry.

Meanwhile, Gartner predicts that by 2030, at least 40 per cent of enterprise SaaS spending could move towards usage-based, agent-based, or outcome-based pricing models instead of traditional per-seat licensing.

What “AI-Native” Actually Means

Much of the current discussion centres around the difference between traditional SaaS, hybrid AI software, and fully AI-native systems.

Traditional SaaS platforms mainly rely on human users manually operating software interfaces. Hybrid systems add AI features into existing platforms, such as AI assistants inside Microsoft 365 or Salesforce.

AI-native platforms are different because the AI itself becomes the main worker inside the system.

For example, some newer customer service platforms now allow businesses to deploy autonomous AI agents capable of handling large volumes of enquiries across WhatsApp, email, web chat, and social media with minimal human input. Other AI-native systems can build workflows, generate reports, write software code, or analyse data through natural language instructions rather than manual configuration.

This helps explain why investors and software vendors are increasingly focusing on “agentic AI”, where software performs work autonomously rather than simply assisting humans.

Why Software Companies Are Rushing To Adapt

The pressure on traditional software firms is now becoming increasingly visible.

Many major software providers are rapidly embedding AI agents into their products, partly because investors fear that platforms failing to adopt AI quickly enough could lose market share to newer AI-native competitors.

Salesforce, Microsoft, Google, ServiceNow, Slack, Anthropic, OpenAI, and many others are now heavily promoting AI agents and autonomous workflow systems as core parts of their future strategies.

If one AI agent can perform work that previously required several employees using multiple software licences, the traditional per-user revenue model that has underpinned much of the software industry for decades becomes harder to sustain.

This has also created growing interest in alternative pricing structures based on usage, AI actions, outcomes, or completed tasks rather than simply employee headcount.

At the same time, many businesses are discovering that AI systems introduce very different cost structures from traditional SaaS.

Unlike standard software subscriptions, AI systems often consume large amounts of compute power, tokens, API calls, and cloud infrastructure. Research cited by Tropic suggests many organisations are now seeing AI-related software price increases far above normal annual SaaS uplifts.

What Does This Mean For Your Business?

For UK businesses, the most important point is that AI is increasingly moving beyond being a standalone productivity tool and is starting to reshape the software industry itself.

Businesses evaluating software suppliers may increasingly need to ask not just what a platform does, but how much human work it can realistically automate, what the long-term pricing model looks like, and how AI-generated decisions are monitored and controlled.

The trend also means software procurement is becoming more complicated. Traditional, predictable per-user pricing is gradually being replaced by models based on AI usage, actions, compute consumption, or business outcomes, which may make long-term costs harder to forecast.

At the same time, organisations adopting AI-native systems may gain significant efficiency advantages if these tools genuinely reduce manual workload, improve customer response times, or automate repetitive operational tasks.

However, many AI agents still remain imperfect, requiring human oversight, careful governance, and strong security controls. Businesses should therefore be cautious about assuming that AI-native automatically means lower risk or lower cost.

What is becoming increasingly clear, however, is that the software industry is entering a major transition period. The companies that succeed may not necessarily be those with the biggest software platforms, but those that can most effectively combine AI automation, workflow integration, trust, and measurable business outcomes into products organisations are willing to rely on every day.

Tech Insight : What Is ‘Vibe Coding’ ?

In this Tech Insight, we look at what vibe coding is, how it’s transforming the way software is created, what it’s being used for, and why it’s generating both excitement and concern across the tech industry.

What Is Vibe Coding?

Vibe coding is the term increasingly used to describe the process of creating software through natural language prompts rather than traditional coding. It relies on large language models (LLMs) to interpret a user’s intent and convert it into functioning code, often within seconds.

The approach builds on earlier trends in low-code and no-code platforms but takes them a step further. By removing the need for drag-and-drop interfaces or pre-built modules, vibe coding allows users to describe what they want in plain language, for example, “create a form that collects customer feedback and sends it to Microsoft Teams”, and receive a working prototype in response.

The idea has gained particular traction among solo founders, product designers, and teams that want to move quickly without relying on engineering resources. But as the technology evolves, attention is shifting to its potential in larger organisations.

From Indie Tools to High-Growth Startups

The rise of platforms like GitHub Copilot and ChatGPT has made AI-assisted coding familiar to many developers. However, newer startups such as Lovable, a Swedish company now valued at $1.8 billion following a $200 million Series A, are taking the concept in a different direction.

For example, Lovable’s product allows users to build fully functional apps by chatting with an AI assistant. It’s currently used by early-stage startups and solo creators who want to focus on design and user experience rather than infrastructure or syntax. According to RTP Global, one of Lovable’s backers, the company is part of a larger shift where technical skills are no longer the gatekeeper to building software.

“The cultural shift is real,” said Thomas Cuvelier, a partner at RTP Global. “If technical ability is no longer a differentiator, creativity and user experience become the new competitive edge.”

Other startups entering the space include Cody, Builder.ai, and Spellbrush, all of which aim to simplify software creation for non-coders. Meanwhile, major players like Google and Microsoft are integrating similar features into Gemini Code Assist and Power Platform respectively.

How Developers Are Responding

While vibe coding is often associated with new entrants and early-career developers, recent data appears to suggest that experienced engineers are embracing it even more actively.

For example, a July 2025 survey by cloud platform Fastly found that 32 per cent of developers with over 10 years of experience now use AI-generated code for more than half of their production output. That’s more than twice the rate among junior developers. Just 13 per cent of junior developers reported doing the same.

“When you zoom out, senior developers aren’t just writing code — they’re solving problems at scale,” said Austin Spires, Fastly’s senior director of developer engagement. “Vibe coding helps them get to a working prototype quickly and test ideas faster.”

However, the same survey found that developers often need to heavily edit the code AI tools produce. For example, around 28 per cent said they spent so much time fixing and refining outputs that it cancelled out most of the time saved. This was especially true for more complex or long-lived projects where quality, maintainability, and security matter.

The Enterprise Challenge

For enterprise IT teams, the promise of vibe coding, i.e. rapid prototyping, reduced cost, broader participation, is pretty compelling. However, practical adoption remains limited, largely due to concerns around compliance, security, and technical debt.

Most enterprise environments demand strict auditability, version control, and accountability for any code that enters production. That’s difficult to guarantee when the code is generated by a black-box model based on user prompts. Without clear documentation or traceability, teams can’t easily demonstrate how a particular function was created, or why it behaves the way it does.

Concerns about the transparency and reliability of AI-generated code appear to be a recurring theme in enterprise discussions. Tech ethicists and researchers have warned that without proper safeguards, businesses risk deploying software they don’t fully understand. This is especially problematic in regulated sectors such as finance, healthcare, and critical infrastructure, where audit trails and explainability are non-negotiable.

Anne Currie, co-author of the Sustainable Computing Manifesto, has written extensively on the importance of accountability in software systems. In previous talks and articles, she has argued that AI-driven automation must be transparent and traceable if it is to be used responsibly in real-world environments. While not commenting specifically on vibe coding, her work highlights the broader risks of black-box decision-making in enterprise IT.

In response to these types of concerns, some platforms are adding features like code justification, dependency maps, and access logs. GitHub Copilot Enterprise, for example, includes usage tracking and administrator controls, while Google’s Duet AI offers explainability features for its outputs. But these tools are still being refined.

The Changing Developer Culture

Alongside the technical debate, vibe coding appears to be changing the way developers think about their work, including its environmental impact.

For example, Fastly’s survey found that 80 per cent of senior developers now consider the energy usage of the code they produce, compared to just 56 per cent of junior developers. This awareness is beginning to shape how software is built, especially in companies with sustainability targets.

Energy Consumption

One concern is that AI coding tools themselves consume significant energy. For example, every prompt or suggestion involves inference from a large language model hosted in a data centre. Despite this, few platforms provide visibility into the energy footprint of each interaction, something developers increasingly want to see.

“There’s not a lot of transparency about the carbon cost of using AI tools,” said Spires. “But more experienced developers are thinking ahead to what that impact means for users and systems.”

New Risks

Despite its benefits, it seems that vibe coding is introducing new risks. For example, code quality is a recurring concern, especially in critical systems. Several developers surveyed by Fastly reported subtle bugs in AI-generated functions that took hours to diagnose. Others said the tools sometimes “hallucinate” logic that seems valid but fails under edge cases.

Security is another issue. AI tools can inadvertently copy insecure patterns from training data or introduce backdoors if prompts are unclear. There have already been real-world cases of AI-generated software containing vulnerabilities or misconfigurations, prompting caution among security teams.

Fastly’s findings also revealed a tension between perception and reality. Developers often feel faster using AI tools because of instant feedback and autocomplete features, but in many cases, actual productivity gains are offset by the need to test, rework or debug the generated code.

That disconnect was reflected in an RCT (randomised controlled trial) published in early 2025 (Stanford University), which found that developers using AI tools took 19 per cent longer on average to complete certain coding tasks, not because they weren’t effective, but because they relied too much on the suggestions and later had to fix them.

What Does This Mean for Your Business?

UK businesses exploring vibe coding will need to weigh speed and accessibility against long-term risks. While it can enable faster internal development and reduce reliance on overstretched IT teams, the lack of built-in governance creates some real concerns. For example, in regulated sectors, even a small oversight in explainability or security could carry legal and operational consequences.

Enterprise adoption is likely to depend heavily on how well platforms adapt to professional standards. The ability to generate working prototypes is not enough if those outputs can’t be documented, versioned, tested, or supported over time. Tools that offer strong administrative control, user permissions, and audit trails are more likely to gain traction in large organisations with strict oversight requirements.

For vendors and platform builders, meeting these expectations could open up substantial new markets. However, that is likely to require a move from consumer-grade UX tools to enterprise-grade development environments. Startups hoping to scale in this space will need to prove they can support secure, sustainable, and compliant deployments at scale, not just fast app creation.

For developers, it seems that a change in mindset is already visible. Vibe coding is changing how software is prototyped, reviewed, and refined, with new expectations around creativity, environmental impact, and collaborative input. That change is likely to influence not just how code is written, but who gets to write it, and who takes responsibility when things go wrong.

Tech Insight : New Apple Tech Unleashed @ WWDC 2025

In this Tech Insight, we look at how Apple used its annual WWDC event to unveil some major software updates, a striking new Liquid Glass design, and expanded AI tools for developers across its platforms.

Focus on New Website Features and Developer Tools

Held at Apple Park in Cupertino, California, WWDC 2025 brought developers and media together for the company’s yearly June event. As expected, the focus was on new software features and developer tools rather than hardware. The announcements spanned iOS, macOS, watchOS, visionOS, tvOS and iPadOS, alongside incremental upgrades to AirPods, CarPlay and Apple Wallet. However, while some Apple Intelligence features were expanded, Siri was notably absent, raising questions about Apple’s positioning in the increasingly competitive AI market.

Introducing ‘Liquid Glass’ Design and a New Naming Convention

One of the standout changes announced at WWDC 2025 was Apple’s complete visual overhaul of its operating systems. A new design language called Liquid Glass will replace the current aesthetic across iOS, iPadOS, macOS and visionOS.

The new interface uses semi-translucent, reflective elements that respond to lighting and context, creating what Apple describes as a more immersive and natural user experience. Context menus, alerts and backgrounds now blend with the device’s environment. Apple confirmed that this marks the most significant visual shift since iOS 7 back in 2013.

Alongside this, Apple also announced it would abandon sequential numbering for its OS versions. Instead, the 2025 releases will all carry the year in their names. This means users will see iOS 26, macOS 26 (also known as macOS Tahoe), watchOS 26, and so on.

Apple Intelligence Expands, but Siri Delays Raise Concerns

Apple made several announcements about its Apple Intelligence initiative (first introduced at WWDC 2024). This year, the company extended AI features to more apps and functions, positioning privacy-friendly on-device intelligence as a central part of the user experience.

Visual Intelligence Enhances Screen Awareness

A key update is Visual Intelligence, an AI tool that analyses screen content and lets users interact with what they’re viewing. For example, users can tap on a photo of a restaurant and get more details via Google, ChatGPT or supported apps. It can also detect events and suggest adding them to the calendar, automatically extracting date, time and location information.

Live Coaching, Translation and Smarter Shortcuts

It seems that Apple Watch users will be getting a new AI-powered workout coach called ‘Workout Buddy’. It uses personal fitness history and real-time performance data to deliver motivational voice feedback during exercise. Also, ‘Live Translation’ enables real-time, on-device translations across Messages, FaceTime and phone calls, displaying captions or speaking translations aloud depending on the context.

Apple’s Shortcuts app has also been upgraded. For example, users can now add intelligent actions, such as text summarisation or image generation, powered by Apple Intelligence. These can be run entirely on-device or use Apple’s Private Cloud Compute when needed, preserving user privacy.

Developers Gain Direct Access to On-Device Models

In what could be described as quite a significant shift, Apple announced the Foundation Models framework, giving developers access to its on-device large language model. For example, with native Swift support (developers using Apple’s language to build apps easily), apps can now integrate Apple Intelligence features like summarisation or natural language commands using as little as three lines of code.

As highlighted by Craig Federighi, Apple’s Senior Vice President of Software Engineering: “Now, the models that power Apple Intelligence are becoming more capable and efficient, and we’re integrating features in even more places across each of our operating systems.”

Siri Upgrades Still Missing in Action

Despite the expanded AI rollout, many attendees had been expecting a major upgrade to Siri. Instead, Apple confirmed delays to its next-generation voice assistant. Federighi admitted that the improvements had not reached the level of reliability Apple wanted, saying: “We weren’t able to achieve the reliability in the time we thought.”

This absence was widely noted and may add pressure to Apple’s position in the AI race. For example, while competitors like OpenAI, Google and Microsoft continue to push forward with conversational agents, it seems that Apple’s flagship assistant remains largely unchanged for now.

iOS 26 Brings Visual Overhaul and AI Features

iOS 26 was positioned as Apple’s flagship release, introducing Liquid Glass and a more adaptive Lock Screen and Home Screen experience. Key additions include contextual widgets, smarter Spotlight search with task-aware results, and updates to Messages such as AI-suggested polls and live translation. There are also enhanced privacy controls and accessibility tools.

A redesigned Control Centre and greater customisation options round out the update. Users can also activate features like Visual Intelligence directly from the Action button or screenshot shortcuts.

Also, Apple’s new child safety features will now require parental approval before children can communicate with new contacts, reflecting growing concern over online safety. Developers will also have access to a new ‘PermissionKit’ to implement similar controls within their apps.

macOS 26 ‘Tahoe’ and Spotlight Upgrades

The macOS 26 update, codenamed Tahoe, brings the Liquid Glass interface to Mac alongside new Spotlight functionality. Users can now trigger app actions directly from Spotlight, such as playing music, starting a workout or adding tasks to Notes.

The new theme options and improved menu navigation are designed to appeal to productivity users, while the expanded Shortcuts integration introduces AI-generated actions. macOS Tahoe will also be the last major version supported on Intel-based Macs, marking the end of an era as Apple completes its transition to Apple Silicon.

Multitasking Redefined on iPadOS 26

iPadOS 26 delivers a long-awaited overhaul to multitasking. For example, Apple says that users can now resize app windows more freely and reposition them anywhere on the screen, bringing the iPad experience closer to macOS. Developers will have to opt in to support the new features, but the system is reportedly intuitive and flexible.

Other changes include the arrival of the Journal app on iPad, new Apple Pencil features for image markup, and enhanced export options for creative users. Also, preview tools now allow users to inspect and annotate files more like on desktop platforms.

Vision Pro Gains New Accessories and Software Updates

visionOS 26, Apple’s latest operating system for its Vision Pro headset, brings new spatial widgets and easier profile switching to the headset. Apple also confirmed compatibility with the PlayStation VR2 Sense controller and a new Logitech Muse stylus. These accessories are intended to boost adoption of the device among gamers, designers and engineers.

Also, it seems that Persona avatars, previously criticised for their unnatural look, have been refined to look more realistic, while support for more third-party input devices reflects Apple’s efforts to expand the Vision Pro’s ecosystem.

watchOS 26 and tvOS 26: Subtle but Useful Enhancements

Apple also announced that as part of watchOS 26 (an update for Apple Watch), the Liquid Glass update introduces the Workout Buddy AI feature for real-time coaching. A new flick gesture enables users to interact with the watch without touching the screen, improving accessibility.

Also, tvOS 26 now focuses on usability, introducing faster profile switching, a sleeker interface and a karaoke feature. AirPods also now gain studio-quality audio recording and camera remote capabilities, making them more useful for content creators and on-the-go users.

New Apps and Smaller Updates

Apple also announced a new dedicated Games app for iOS and iPadOS. The app functions as a hub for tracking achievements, joining challenges and inviting friends to multiplayer sessions. Social features like “Play Together” aim to make gaming more collaborative on Apple platforms.

Apple Maps now uses on-device learning to suggest commute-based routes, while Apple Wallet will summarise delivery and tracking updates using AI. Podcast users can now listen at up to 3x playback speed, and News gains a new emoji-based trivia game.

Developer Tools and Global Expansion

A key announcement for developers was the expanded access to Apple’s foundation models. For example, developers can now build AI features directly into their apps using the on-device model, without relying on external APIs. The models support Swift and include built-in tools like tool calling and guided generation.

Apple also confirmed that Apple Intelligence will expand to eight more languages later this year, including Danish, Dutch and Turkish, with availability dependent on local laws and device compatibility.

A New Generation of Experiences?

After trailing behind rivals on AI, it seems that at this year’s WWDC, Apple doubled down on privacy-focused, on-device intelligence that integrates directly into apps and workflows. By opening up its core models to developers, it may be hoping to spark a new generation of experiences that differentiate its ecosystem.

For users, the changes are mostly evolutionary but important, particularly the design refresh, privacy-conscious AI tools, and new multitasking capabilities. However, the delay to Siri’s upgrade leaves a visible gap in Apple’s response to competitors like Google Gemini, OpenAI’s ChatGPT and Microsoft Copilot.

While Apple’s privacy model and integration strengths remain core advantages, some commentators have noted that many of the features shown at WWDC 2025, e.g. call screening, image generation and real-time translation, have been available on Android or third-party platforms for some time.

As Apple seeks to reassert itself in the AI space while maintaining its reputation for design and reliability, this year’s announcements appear to generally reflect both ambition and caution. It’s likely that the next 12 months will be critical in determining how far the company can evolve its AI strategy, and how willing users and developers are to embrace it.

What Does This Mean For Your Business?

The real test for Apple will be whether these updates deliver meaningful, seamless experiences in day-to-day use. While the Liquid Glass redesign brings a striking new aesthetic, and the Apple Intelligence features promise more contextual support, much depends on how consistently and reliably they perform across devices. The fact that developers now have access to Apple’s on-device models is likely to accelerate the creation of tailored, private AI experiences. For UK businesses, this opens up potential for more secure, integrated tools across sectors such as retail, healthcare, and finance, especially for those already embedded in Apple’s ecosystem.

However, questions remain about how quickly these new capabilities can reach mass adoption. With many features still in beta and some dependent on specific hardware or language settings, rollout may be uneven. Apple’s slower progress on Siri is also a strategic concern. In a market where AI-powered voice interaction is fast becoming a standard expectation, its absence puts Apple at a disadvantage, particularly in the enterprise and productivity space where hands-free interaction can offer real operational value.

Apple’s emphasis on privacy and on-device processing is clearly intended to differentiate it from AI competitors who rely heavily on cloud-based models. This may appeal strongly to consumers and businesses alike, particularly those facing increasing regulatory pressure around data handling. Even so, Apple will need to keep pace on usability and innovation if it wants to remain a leader in AI-enhanced computing.

As other players race ahead with chatbots, copilots, and custom models, Apple has opted for a slower but arguably more sustainable approach. Whether this proves to be a strength or a missed opportunity will depend not just on technical progress, but on how well it can support developers, reassure users, and turn these tools into something people actually want to use every day.

Tech Tip – Use “Print to PDF” to Save Files as PDFs Without Additional Software

Windows has a built-in “Print to PDF” feature, allowing you to save any file or webpage as a PDF, which is useful for sharing professional, non-editable documents. Here’s how it works:

– Open the document or webpage you want to save.

– Press Ctrl + P to open the Print dialog.

– Select Microsoft Print to PDF as the printer.

– Click Print, choose where to save the file, and it will be saved as a PDF.

Tech Insight : Lessons Learned

Following the massive after-effects of the faulty CrowdStrike update, we take a look at the lessons learned so far in this ongoing situation.

What Happened? 

On July 19, a faulty software update from cybersecurity technology company CrowdStrike affected approximately 8.5 million Microsoft devices globally causing chaos across multiple industries globally as key systems were disabled. The faulty software update only impacted Microsoft because the update for CrowdStrike’s enterprise security platform was specifically designed just for the Windows operating system. The update caused a ‘logic error’, leading to widespread system crashes and blue screens of death (BSOD).

The worst cyber event in history (so far), it has surpassed the scale of the 2017 WannaCry attack and highlighted significant vulnerabilities in modern cybersecurity frameworks.

What Is CrowdStrike? 

CrowdStrike, founded in 2011 and headquartered in Texas, provides the Falcon platform, a cloud-based endpoint protection solution used by large businesses and organisations globally.

Lessons Learned from the CrowdStrike Event 

Although (at the time of writing this), some of the after-effects are still being felt, the scale and severity of the event have already taught us some valuable lessons. For example:

– Businesses may have an over-reliance on the Cloud. The CrowdStrike incident has starkly highlighted our over-reliance on cloud services. Many businesses have embraced the cloud for its scalability, cost-effectiveness and convenience, often integrating critical operations and data storage into cloud platforms. However, this event demonstrated the potential risks of depending heavily on a single cloud provider or a homogeneous cloud environment.

– A re-evaluating of business cloud strategies may now be necessary. For example, the disruption caused by the faulty update has already led to some reconsidering their cloud strategies. Many businesses are now re-evaluating their cloud-first approaches to avoid single points of failure. Strategies being reported include moving away from a platform-centric approach to a more tailored, nuanced strategy which balances performance, costs, and security, and enhances efficiency and reduces risk. Also, adopting workload-specific strategies and determining the best platform for each application, e.g. a private cloud, industry cloud, on-premises data-centres, or a multi-cloud architecture, may now be a more attractive and less risky strategy.

Broadly speaking, building resilience through diversity (e.g. diversifying cloud providers and also implementing hybrid and multi-cloud strategies) plus ensuring all eggs aren’t just in one basket may now be the way forward (controversially) for some businesses. This approach could mitigate the risks associated with single points of failure, ensure greater operational continuity, perhaps even reduce (long-term) costs, and hopefully contain any cloud chaos in future.

– There is a need for rigorous software testing. The CrowdStrike incident emphasises the critical importance of thorough testing before deploying software updates, especially on a Friday! This event demonstrated that even minor configuration changes could have catastrophic consequences if not properly vetted. Comprehensive testing protocols must now be implemented to prevent such incidents from occurring in the future. Robust incident response plans are necessary. Businesses need to ensure they have comprehensive strategies in place to quickly address and mitigate the impact of IT failures. This includes regular drills and updates to incident response protocols to stay prepared for various scenarios.

– Enhanced employee security training and awareness is important. Increased vigilance against phishing and other cyber threats is crucial in the aftermath of such incidents. Businesses must invest in continuous employee training to recognise and respond to cybersecurity threats effectively. This proactive approach can significantly reduce the risk of successful cyberattacks exploiting the situation. For example, some of the reports of how cyber-criminals have already taken advantage of the situation include:

– Phishing campaigns, pretending to offer fixes and updates for the CrowdStrike-related issues. These campaigns are aimed to trick users into clicking on malicious links, leading to malware infections. The US The Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) reported that it had “observed threat actors taking advantage of this incident for phishing and other malicious activity”. People have been advised to avoid clicking links in any text or email related to the CrowdStrike or Windows disruption.

– Setting up fraudulent websites claiming to provide legitimate updates and solutions. These sites were designed to distribute malware under the guise of providing help. For example, cybercriminals distributed ZIP archives with names like “CrowdStrike-hotfix.zip” containing the HijackLoader payload (which loads malware) and was reportedly aimed at users and CrowdStrike customers in Latin America.

– Initiating ransomware attacks, taking advantage of the disruption.

– Stealing data. In some cases, attackers have exploited vulnerabilities exposed by the disruption to infiltrate systems and steal sensitive data, compounding the damage caused by the initial outage

– Continuous and transparent communication makes a big difference in a crisis. CrowdStrike’s swift communication and deployment of a fix were crucial in managing the incident’s fallout. Transparent and continuous updates helped affected organisations understand the issue and implement necessary measures. This event highlights the importance of maintaining open lines of communication between cybersecurity firms and their clients during crises to ensure timely and effective responses.

– Be cautious with third-party services. The CrowdStrike incident underscores the critical risks associated with relying on third-party services. Businesses learned that dependency on external providers for crucial functions can lead to widespread disruptions if those services fail. The incident highlighted the necessity of rigorous vetting processes to ensure third-party providers meet high security and reliability standards. Continuous monitoring and regular audits are essential to identify and mitigate risks promptly.

Diversifying service providers can reduce the risk of a single point of failure, enhancing overall resilience. Companies should ensure contracts with third-party providers include stringent security requirements and clear terms for liability and incident response. This approach helps maintain control and oversight over outsourced services, safeguarding operations and data integrity against potential vulnerabilities introduced by external partners.

Why Was The Aviation Sector So Badly Affected? 

The aviation sector experienced severe operational disruptions. Thousands of flights were cancelled or delayed, affecting major airports worldwide. The aviation and travel sectors were heavily affected by the CrowdStrike issue due to their reliance on real-time IT systems for critical operations. The system crashes disrupted flight scheduling, booking, and check-in processes, leading to thousands of cancellations and delays. Additionally, the outage compromised safety and security monitoring systems, exacerbating the operational chaos and inconvenience for passengers.

Why Was The Healthcare Sector Also Badly Affected? 

Hospitals and healthcare systems faced critical disruptions, delaying clinical procedures, and impacting patient care. The incident forced many institutions to revert to manual processes, highlighting the vulnerability of healthcare systems to IT failures. Healthcare and hospitals are particularly vulnerable to IT issues like the CrowdStrike incident (and cyberattacks) due to their reliance on IT systems for critical patient care functions, such as electronic health records (EHRs), medical devices, and communication systems. Also, the complex IT infrastructure in hospitals, often a mix of legacy and modern systems, creates additional vulnerabilities, as securely integrating these diverse systems is challenging.

This event demonstrates the urgent need for healthcare providers to invest in robust IT infrastructure and emergency protocols to ensure patient safety and continuity of care during technological crises.

What Does This Mean For Your Business? 

The CrowdStrike incident is a stark reminder of the inherent vulnerabilities in modern cybersecurity frameworks and the critical importance of robust IT management strategies. For businesses, the event offers many lessons, such as the need for rigorous testing and validation processes for all software updates. Ensuring that updates are thoroughly vetted before deployment can prevent similar catastrophic failures in the future.

Also, the incident highlights the necessity of developing comprehensive contingency plans to maintain operational continuity during IT disruptions. Businesses should conduct regular drills and update their incident response protocols to prepare for various scenarios, ensuring they can quickly address and mitigate the impact of unexpected failures.

The extensive disruption across various industries illustrates the interconnected nature of modern business operations and the potential widespread impact of a single point of failure. Businesses should, therefore, take a good look not only their own cybersecurity measures but also closely scrutinise and manage the cybersecurity protocols of their service providers and partners. This includes implementing stringent vetting processes, continuous monitoring, and regular audits of third-party services to ensure high security and reliability standards are maintained.

The legal and financial ramifications of such events also cannot be ignored. The anticipated lawsuits and claims for damages resulting from operational disruptions and customer inconvenience could set significant precedents, influencing future legal standards and liability expectations in the cybersecurity sector. That said, many businesses in the aviation and travel sector may decide to risk arguing that this was an exceptional event, thereby hoping to limit their legal/financial liabilities. Businesses may, however, need to enhance their insurance coverage and legal strategies to mitigate potential similar risks in the future.

Also, the increased risk of cyber-attacks following this incident (and other incidents in the past) should prompt businesses to heighten their vigilance against phishing and other cyber threats. The surge in CrowdStrike-themed phishing websites, for example, demonstrates the opportunistic nature of cybercriminals. Businesses must ensure their employees are well-informed and equipped to recognise and respond to these threats, investing in continuous security training and awareness programs.

While the disruption caused by CrowdStrike’s software update was not a cyber-attack, it nonetheless highlights the need for comprehensive cybersecurity strategies. Businesses that learn from this incident and proactively strengthen their cybersecurity frameworks will be better positioned to navigate the complexities of the digital age and safeguard their operations against future disruptions. By diversifying their cloud dependencies, implementing robust incident response plans, and maintaining stringent oversight of third-party services, companies can build a more resilient and secure operational environment.

Tech Insight : Restrictive Cloud Licensing & Public Sector Skills

In this insight, we look at how recent reports have revealed how the UK’s public sector is facing the dual challenges of potentially losing £300 million through restrictive cloud licensing and the limitations of an open-source software skills gap.

Restrictive Cloud Licensing Costs 

A report from the cross-party think tank, The Social Market Foundation (SMF), has shown that due to restrictive rules on cloud software licensing, the public sector looks set to waste more than £300 million over the next 5 years (£60 million per year over the next five years). According to the report, this is because current software licensing rules are making it harder to switch between providers, thus keeping public sector organisations locked into pricey deals.

The SMF says its report has only accounted for the costs of restrictions to users’ ability to freely use Office 365 and the overcharge of using SQL Server on third-party infrastructure, yet the actual additional costs incurred by all software licensing practices may be much higher.

The Benefits Of One Provider Wiped Out By Costs 

The UK government mandates that central departments adopt cloud services and, therefore, encourages public sector organisations to improve technological efficiency and to find savings within public services. One method of achieving savings in the public sector has been to choose one central (cloud) provider that delivers the full range of services required. However, as one IT professional (quoted by the SMF) recently pointed out, there’s “positives to having one provider with a suite of things that work together very well, but the challenge of that is you’re tied in”. 

Effect Worse On Public Sector 

The SMF says that while licensing costs and complications also affect the private sector, the overall detriment is likely to be worse in the public sector. For example, excess costs are financed by the taxpayer and may mean diverting resources from other government objectives or budgets, thereby resulting not just in direct financial costs but also in preventing the UK from achieving its technological, economic, and security goals.

An Economic, Technical, and Social Issue 

Jake Shepherd, Senior Researcher at SMF, said of the report’s findings: “Our research shows that restrictive software licensing practices squander millions of pounds – taxpayers’ money that could fund vital public services and boost national productivity – while interviews with public sector IT professionals reveal the ‘real’ day-to-day operational costs. Software licensing isn’t just a technical issue – there’s an economic and social imperative to ensure it works smoothly and prevents needless wastage of public resources in the future.” 

The Open Source Challenge 

Open source is integral to the UK’s digital economy, contributing significantly to business growth and competitiveness and the public sector is encouraged to increase its participation in open source projects to leverage these benefits further.

However, the recent ‘State of open report’ from OpenUK, a UK-based organisation promoting open source software, hardware, and data, has also highlighted how there is a gap in the skills and understanding of open source in the public sector.

Substantial Public Engagement With Open Source 

OpenUK’s report, which uses a collection of data from NHS Digital, Government Digital Service, and the Department of Business, Energy and Industrial Strategy has revealed the existence of 1780 GitHub repositories with 14,910 stars and 745,000 commits. OpenUK says this is evidence of “substantial public sector engagement with open source software in the UK” and highlights how the public sector embracing open source “aligns with government digital transformation goals, driving better public services and fostering a culture of continuous improvement”. Also, OpenUK says by leveraging open source, the UK public sector can address “complex challenges more effectively, ensuring robust, scalable, and secure digital infrastructure that supports economic resilience and growth”. 

Not Enough 

Despite these levels of engagement in open source by the public sector, OpenUK’s ‘Phase Two: The Open Manifesto Report’ highlights the need for policymakers to build skills in open source software to help the UK (public sector) make better use of open source and to improve AI openness. Some of the challenges to achieving this, identified in the report, include:

– A skills shortage / a significant lack of expertise in open source technologies within the public sector. This skills gap hinders the effective implementation and management of open-source projects. Training and upskilling initiatives could help address this issue. For example, OpenUK’s CEO, Amanda Brock, has said that working with people who learn to code in open source and contribute to open source code repositories is one way to help tackle the UK skills gap.

– A lack of coherent policies and governance frameworks for managing open-source contributions within many public sector organisations. This results in inconsistent practices and potential compliance issues and highlights the need for comprehensive policies and standardisation.

– Security concerns. For example, security is a significant concern with open-source adoption and public sector organisations often struggle with balancing cost and security, leading to vulnerabilities. Security in the development and deployment of open-source solutions is, therefore, crucial.

– Resistance to the cultural shift required for adopting open source technologies. Traditional public sector environments find it challenging to move towards more collaborative and transparent working practices.

– Resource Allocation. Financial constraints and competing priorities make it difficult for public sector organisations to allocate the necessary resources for open-source initiatives. Strategic investment and prioritisation are needed to overcome these barriers.

OpenUK has, therefore, called on the public sector to develop skills to curate open source well, and on policymakers to gain a greater understanding of open technologies to avoid a continued reliance upon multi-year contracts from “legacy IT providers and consultancies”.

AI Too 

In the report, Jennifer Barth, chief research officer at OpenUK, also points to the growth of the UK’s AI repositories as evidence of “the dynamism and innovation within the UK’s AI community, bolstered by open source principles”.

What Does This Mean For Your Business? 

For UK businesses, the insights from these reports show a pressing need to address both the challenges of restrictive cloud licensing and the open-source skills gap within the public sector. The repercussions of these issues are multifaceted, affecting financial efficiency, technological advancement, and overall competitiveness.

The substantial costs associated with restrictive cloud licensing (estimated at £300+ million over the next five years) highlight the importance of flexibility in software procurement. Businesses can learn from this by advocating for more open and competitive licensing agreements. This approach not only reduces costs but also fosters innovation by avoiding vendor lock-in. By negotiating contracts that allow easier transitions between providers, businesses can ensure they are not overpaying for services and can quickly adapt to better solutions as they emerge.

The public sector’s struggle with open-source software adoption due to a skills shortage could be seen as an opportunity for businesses to invest in training and upskilling their workforce. Open-source technologies can offer significant benefits, including cost savings, enhanced security, and the ability to drive innovation through collaboration. By developing in-house expertise in open source, the public sector and the private sector, businesses can improve their technological resilience and reduce dependency on proprietary solutions. This, in turn, can lead to more agile and responsive IT strategies, essential in today’s fast-paced digital landscape.

The identified lack of coherent policies and governance frameworks for open source usage in the public sector could also be seen as a cautionary tale for private enterprises. The challenges faced by the public sector in allocating resources to open-source initiatives show a need for strategic investment in technology. Businesses should, therefore, look at investment in open-source projects and technologies to remain competitive.

These findings from the SMF and OpenUK reports appear to offer valuable lessons not just for the public sector, but for all UK businesses. Embracing flexible licensing agreements, investing in open-source skills, establishing robust governance, fostering a collaborative culture, and strategically allocating resources can improve flexibility, scalability, security, and cost-efficiency.

Tech Tip – Update Your Software and Drivers

Managing privacy settings in your Microsoft 365 account can help protect your personal and business information. Properly configured privacy settings help ensure that your data is only accessible to those who are authorised and that your activities remain private. Here’s how to access and manage your privacy settings to enhance security and privacy:

Access Your Privacy Settings

– Sign in to your Microsoft 365 account.

– Click on your profile picture in the top right corner and select My Account.

Review and Adjust Privacy Settings

– In the left-hand menu, select Privacy.

– Here, by you can manage various aspects of your privacy settings, including ad preferences, location services, activity history (browsing and search), and more.

Configure Security and Privacy Settings

Under the Security section (left-hand menu – click on ‘Security’), you can:

– Review your sign-in activity and security settings.

– Enable Multi-Factor Authentication (MFA) for an additional layer of security.

– Regularly update your password and ensure it is strong and unique.

By taking steps to manage your privacy settings, you can enhance the security of your Microsoft 365 account, ensuring your personal and business information remains protected and private.

Tech Tip – Update Your Software and Drivers

Although cyber security insurance may be all very well for after the event, keeping your software and drivers up to date is crucial for helping to prevent security issues in the first place, and for maintaining the security and performance of your Windows device. Updates often include security patches that protect against newly discovered vulnerabilities. Here’s how to make sure your security is up to date:

Go to Settings > Update & Security > Windows Update.

Click ‘Check for updates’ to see if there are any new updates available.

Install any available updates to ensure your system is protected.

Additionally, check for updates for your installed applications and hardware drivers through their respective software or the manufacturer’s website.

Tech Tip – Restore Points For System Recovery

Creating ‘restore points’ regularly in Windows could save you from unexpected system failures and software installation issues and allow you to undo system changes by letting you return your computer to a previous state. Here’s how it works:

– Search for Create a restore point in the Start menu and open it.

– Under the ‘System Protection’ tab, ensure that protection is turned on for your system drive.

– Click ‘Create’ to start the process of creating a restore point. Give it a descriptive name e.g., the date, to remember what prompted the creation (like before installing new software).

– Click ‘Create’ again, and Windows will generate a restore point, capturing your system settings and configurations at that time.

– If needed, you can now restore your system by returning to this dialog and selecting ‘System Restore’, then following the prompts to revert to a selected restore point.

Tech Insight : What Is Customer Journey Mapping Software?

In this tech insight, we look at what customer journey mapping is, its benefits, the challenges of using it, and also we look at some of the popular customer journey mapping software solutions available.

What Is Customer Journey Mapping?

Customer journey mapping refers to a strategic process (that’s used by marketers) to visualise and understand the complete experience of a customer interacting with a product, service, or brand from the customer’s perspective. It’s a visual representation of the different interactions customers have with your brand, product, or service until they decide to purchase it from your business (and what happens beyond).

Identifying Key Interactions 

The customer journey mapping process involves identifying key interactions that the customer has with the organisation, understanding the customer’s feelings, motivations, and questions at each step, and recognising opportunities for improvement.

The map typically starts from the initial awareness or need recognition stage, through various touchpoints such as research, purchase, and post-purchase experiences, ending with loyalty or advocacy.

Who Does It? 

Broadly speaking, it’s used by marketing teams because they are directly involved in understanding and communicating with the target audience. Also, customer journey mapping can give marketers the kind of deeper understanding of customers’ experiences that enables them to improve how they target and serve prospects, which can ultimately deliver increased sales and loyalty.

More specifically, customer journey mapping is also carried out by:

– Product managers and development teams who use it to ensure that the product or service meets the customers’ needs and expectations at every point.

– Customer experience (CX) professionals, i.e. those specialising in understanding and improving the interaction between an organisation and its customers, and who want to identify gaps in the customer experience.

– User experience (UX) designers. These focus on the usability and overall experience of digital interfaces and tend to use journey maps to visualise how users interact with a website or app and identify areas for improvement.

– Service designers / those involved in designing and improving entire service processes, who use customer journey mapping to ensure that every touchpoint is optimised for the best customer experience.

– Senior managers who may also be involved in producing and reviewing the customer journey maps to make strategic decisions that align with customer needs and organisational goals.

Why Use It? 

Some of the key reasons for conducting customer journey mapping include:

– Enhancing customer understanding, i.e. helping organisations to see things from a customer’s viewpoint, leading to deeper insights into their needs and preferences.

– Identifying ‘pain points’ and bottlenecks – where customers face difficulties or get stuck, thereby allowing for prioritisation of improvements.

– Improving customer satisfaction, loyalty, and advocacy by addressing issues and optimising the journey.

– Aligning teams around the customer experience by providing a shared understanding across departments.

– Driving and informing strategic business strategies and decisions, such as for product development, and service improvements that align with delivering customer value.

– Optimising ‘touchpoints’ and channels – helping understand and optimise interactions and leveraging high-performing channels for a cohesive experience.

– Identifying gaps in the marketing strategy, e.g. by revealing channels and touchpoints that aren’t being used effectively, thus offering opportunities for optimisation.

Common Challenges

Although customer journey mapping can be very useful and deliver some important insights, it’s not without its challenges. For example, some popular challenges faced by marketers trying to use this type of mapping effectively include:

– Distinguishing fact from assumption. It’s crucial to rely on data to ensure the journey map accurately reflects actual customer behaviours rather than assumptions about how customers might interact with the company.

– Ensuring map accuracy. Inaccurate mapping can lead to misguided strategic decisions, potentially wasting resources and missing key opportunities to enhance the customer experience.

– Incorporating all touchpoints. For example, customers may interact with a brand through quite a variety of channels and actions, making it challenging to capture and understand every possible step in their journey.

– Dealing with the complexity of such a map. Comprehensive journey maps can become very detailed and complex, making them difficult to create, understand, and use effectively.

– Keeping maps updated. This is because customer behaviours and preferences evolve over time, necessitating regular updates to the journey maps to keep them relevant and useful.

– Tracking improvements. Once changes are made based on journey map insights, it’s important to measure their impact to ensure they’re driving the desired outcomes.

– Resource intensiveness. The process of creating, maintaining, and updating customer journey maps can be time-consuming and require significant effort from various team members, straining marketing resources.

– Adapting to digital tools. While traditional paper-based mapping can be cumbersome, transitioning to digital tools for journey mapping (i.e. customer journey mapping software), may involve a learning-curve and require additional resources.

Tackling The Challenges By Using Customer Journey Mapping Software 

As mentioned above, customer journey mapping software offers several key benefits to tackle the challenges of journey mapping efficiently, such as:

– Real-time data Integration, i.e. it enables accurate, live reflections of customers’ behaviour, facilitating quick strategic adjustments.

– Dynamic viewing and filtering. It simplifies the updating process, allows for easy navigation of insights, and supports decision-making with filterable maps.

– It helps deliver personalised experiences / tailored customer journeys by segment, improving conversion and satisfaction rates through continuous optimisation.

– Efficiency and simplicity, thereby transforming previously time-consuming tasks into quick and straightforward processes, eliminating the need for physical mapping materials.

– Enhanced collaboration by facilitating sharing across the organisation, allowing teams to focus on relevant touchpoints and insights, promoting a customer-centric culture.

Popular Customer Journey Mapping Software

Here are some examples of popular customer journey mapping software options for businesses and organisations of different sizes, some of whose names you may already be familiar with (particularly Microsoft):

Microsoft Dynamics 365 Customer Insights 

This provides an AI-driven customer data platform that combines customer journey mapping with actionable insights, predictive analytics, and personalisation options. Since it’s from Microsoft, a significant advantage is that it integrates seamlessly with other Microsoft products that a businesses probably already uses. It’s perhaps most suitable for medium to large enterprises looking for a comprehensive solution that not only maps customer journeys but also leverages AI to drive decision-making and personalised customer engagements.

HubSpot

Features/benefits include integrating customer journey mapping with CRM, marketing, sales, and service hubs, offering a comprehensive view of the customer journey. Features include email marketing, lead management, analytics, and automation tools.

This platform is suitable for businesses of all sizes due to its scalable platform, while HubSpot is particularly beneficial for those looking to integrate their customer journey mapping with a broader inbound marketing and sales strategy.

Salesforce Journey Builder 

Part of the Salesforce Marketing Cloud, this tool allows for the creation of personalised customer journeys across various channels and devices. It offers powerful segmentation capabilities, real-time interaction management, and analytics.

Salesforce Journey Builder may be ideal for medium to large businesses already invested in the Salesforce ecosystem, seeking to leverage advanced customer journey mapping with extensive customisation and integration options.

Miro 

This is a collaborative online whiteboard platform that’s quite versatile, enabling the visual mapping of customer journeys, brainstorming sessions, and project planning. It supports real-time collaboration, making it easy to work with teams remotely. Miro is well-suited for businesses of all sizes, especially those that value collaboration and flexibility in their planning and customer experience design processes.

Smaply 

This software offers detailed journey maps, persona creation, and stakeholder maps. It’s designed to provide a clear visualisation of customer experiences, including pain points and emotions, with exportable and shareable maps. Smaply may be best suited to SMEs or teams within larger organisations focused on service design and customer experience improvement projects.

Adobe Experience Platform 

This is a robust platform capable of delivering personalised customer experiences at scale, with real-time customer profiles, predictive analytics, and cross-channel journey orchestration. It’s probably ideal for large enterprises that require a powerful platform to manage complex customer journeys and deliver personalised experiences across various touchpoints.

What Does This Mean For Your Business? 

For UK businesses, the use of customer journey mapping (and popular customer journey mapping software) is helping to meet the need for a more nuanced understanding of the customer experience. By being able to clearly visualise the entire journey from initial awareness through to loyalty and advocacy, businesses can gain invaluable insights into customer interactions, pain points, and so-called ‘moments of delight.’ This strategic process not only helps businesses gain a deeper comprehension of customer needs and preferences but also highlights areas for improvement. In this way, it can help drive strategic decisions that enhance customer satisfaction and loyalty which, of course, can be of huge benefit to businesses.

Customer journey mapping software offers a way to address the common challenges associated with traditional mapping methods, i.e. it gives real-time data integration, dynamic viewing, and filtering capabilities, plus the ability to deliver personalised experiences. These software tools streamline the mapping process, making it faster, more accurate, and less resource-intensive, and facilitate collaboration across departments, ensuring a unified approach to improving the customer experience.

Businesses not currently leveraging customer journey mapping (software) therefore stand to gain a competitive edge by adopting it. The insights derived from journey maps can guide more effective marketing strategies, product development, and customer service improvements. Also, the use of customer journey mapping software can significantly reduce the time and effort required to create and maintain accurate maps, thereby saving costs, reducing risk, and allowing businesses to quickly adapt to changes in customer behaviour and market conditions.

In summary then, customer journey-mapping and the adoption of specialised software to facilitate this process offer businesses the opportunity to transform their understanding of the customer experience which can translate into greater business success. In a landscape where customer expectations are ever-evolving, the ability to swiftly and effectively respond to these changes is not just advantageous but essential.