↓
 

In The Sky IT

 
 
  • Home
  • Digital Transformation
  • Web and Digital Presence
  • Cloud Infrastructure and DevOps
  • Contact Us
  • Blog

Post navigation

← Older posts

No Organisation Is Too Small to Be a Cyber Target

In The Sky IT Posted on August 24, 2026 by BITSAdminAugust 24, 2026

Last month, a small UK power plant was shut down for four days following a cyber attack. The plant was not a major power station. It was a small-scale generator, the kind of facility most people would consider too small to attract serious attention. Reports indicate the attack was linked to hackers affiliated with the Iranian regime.

The government confirmed the incident, and the Department for Energy Security and Net Zero wrote to power companies advising them about the risk. The National Cyber Security Centre was also involved. Officials confirmed that at no point was the wider energy system at risk.

That is reassuring for the public. For business owners, however, there is a different message buried in this story.

The target was small. The disruption was real.

A four-day shutdown is serious for any operation. It costs money, affects customers, and raises questions about reliability. And if a small-scale generator in the UK is considered worth attacking by a nation-state-linked group, that tells you something important: attackers are not limiting themselves to high-profile targets.

The assumption that your business is too small to be noticed is one of the most dangerous beliefs in cybersecurity. Automated attacks do not pick targets by reputation. Ransomware campaigns sweep across networks looking for vulnerabilities, not company names. Phishing emails are sent by the millions, not individually crafted for senior executives.

Why this matters for small businesses and nonprofits

Most small businesses and nonprofits that lack in-house IT support have never had a formal security review. Many are running on software that has not been updated in months. Some are using free consumer email accounts for business correspondence, with no multi-factor authentication in place.

None of these organisations would consider themselves targets. That is precisely why they are.

Attackers use automation to sweep for easy entry points at scale. An unpatched server, a weak password, an unprotected remote desktop connection: these are the things that get organisations compromised, not their size or their sector. A local charity holding donor personal data, a small accountancy firm with access to client financial records, a regional manufacturer with a connected production line: each carries data or systems that have real value to someone.

What a basic security posture looks like

You do not need an enterprise security operation to be meaningfully safer than you are today. The following steps address the most common vulnerabilities in small organisations.

Patch your software. Most successful attacks exploit known vulnerabilities that already have fixes available. Keeping operating systems and applications up to date closes the most obvious doors.

Use multi-factor authentication. MFA on email accounts, cloud services, and admin systems makes credential theft significantly harder to exploit. It is one of the single most effective protections available, and it costs nothing to enable on most platforms.

Control who has access to what. Not everyone in a business needs admin rights. Limiting access reduces the damage any single compromised account can cause.

Back up your data. Offline or cloud-based backups, tested regularly, mean that ransomware does not automatically mean permanent data loss. Many organisations discover their backups are incomplete or untested only after they need them.

Know what you would do if it happened. Many small businesses have no plan for what to do if they are attacked. Having a response plan, even a basic one, reduces recovery time significantly and can limit regulatory exposure under GDPR.

None of this is complicated. But it does require someone to sit down and do it properly, rather than assuming things are probably fine.

The broader picture

The UK government is currently updating its cybersecurity regulations and working on a new energy resilience strategy. That backdrop matters for businesses that operate in regulated sectors, supply larger organisations with security requirements, or hold client data subject to GDPR.

Cyber attacks on smaller targets are not just national security stories. They are a reminder that the threat environment has changed. Attacks are more automated, more widespread, and increasingly linked to geopolitical instability that businesses have no control over. The organisations that come through incidents without lasting damage are the ones that treated security as a routine operational matter rather than something to address after a problem occurs.

If you are not sure where your business stands, a basic IT health check is a practical first step. It does not take long, and it tells you what you are dealing with before someone else finds out for you.

https://www.in-the-sky-it.com

Posted in Article | Tagged cyber attack, cybersecurity, data protection, IT security, Small Business | Leave a reply

When the Voice on the Phone Isn’t Who You Think It Is

In The Sky IT Posted on August 17, 2026 by BITSAdminAugust 17, 2026

The technology that lets scammers clone voices convincingly enough to fool family members is the same technology being used against businesses right now. And for small organisations without a full IT or security team, the risk is real and growing.

Voice cloning has become disturbingly sophisticated. Using only a small amount of recorded audio, AI tools can now generate convincing imitations of specific individuals. In personal contexts, this has been used to impersonate family members in distress, tricking people into handing over money under extreme emotional pressure. The same technique is increasingly being turned on businesses, and the financial consequences can be far more severe.

What this looks like in practice

The most common business version of this attack is sometimes called vishing, or voice phishing. A criminal who has gathered basic intelligence about your organisation, from your website, LinkedIn profile, or a previous data breach, calls a member of your finance or admin team. They impersonate a senior colleague, a supplier, or even your accountant. They ask for an urgent payment, a password reset, or access to an account. Because the voice sounds familiar and the request seems plausible, the target complies.

A variation involves impersonating a client or business partner to intercept an invoice payment. Another uses an AI-generated voicemail to appear legitimate before a follow-up call. These are not exotic threats reserved for large corporations. Small businesses are targeted precisely because they often lack the verification processes that would make these attacks harder to pull off.

Why small businesses are particularly exposed

In larger organisations, there are usually multiple layers of approval before a payment is made or access is granted. Small teams tend to move faster and with less formality, which is usually a strength, but can become a vulnerability when someone impersonates a trusted voice.

There is also a cultural factor. In small, close-knit teams, people are used to acting on a phone call without demanding formal verification. That trust, which ordinarily makes the team work well, becomes the point of attack. A founder who calls and asks finance to move money urgently is not unusual. That normalcy is exactly what the attacker is exploiting.

What you can do about it

The good news is that the countermeasures are straightforward, and most cost nothing to implement.

The simplest and most effective is to establish a verbal verification protocol for any request involving money or account access. This means agreeing a codeword or challenge question in advance with the people most likely to receive or make such requests. If someone calls asking for an urgent payment, the finance person asks for the codeword. If it is not provided, the request is not actioned until the person can be reached through a different, verified channel.

A second layer is a call-back policy: never act on a sensitive request from an inbound call. Hang up, find the number through a trusted source, your own contacts or the organisation’s official website, and call back. This single step defeats most impersonation attacks because it breaks the attacker’s control over the conversation.

Third, keep your team briefed. One conversation about how these attacks work can prevent a costly mistake. Your staff do not need a full security awareness course. They just need to understand that voices can now be faked convincingly, and that it is not only acceptable but expected to ask for verification before acting on an unusual request.

Finally, review who in your organisation can authorise payments or account access, and make sure those decisions require more than a single voice instruction. A second approval via a different channel, a quick text or email confirmation, adds meaningful friction against fraud without slowing down your day-to-day operations.

The broader picture

There is a lot of noise in the AI security space right now, and it can be hard to know what actually deserves attention. Voice fraud does. It requires no technical knowledge on the part of the attacker, the tools are freely available, and the success rate against unprepared organisations is high.

The businesses most at risk are not necessarily the least sophisticated. They are often the ones where trust has been built up over time without a corresponding set of verification habits to support it. A team that works well together on the basis of trust is, by that same token, a team that needs to think carefully about what happens when that trust is targeted.

The technology behind this is not slowing down. The voices are getting more convincing, the tools are getting easier to use, and the attacks are getting more targeted. Getting your verification habits in place now is considerably cheaper than dealing with the consequences later.

If you would like to talk through how this fits into your broader IT and security posture, book a free 30-minute consultation at https://www.in-the-sky-it.com

Posted in Article | Tagged AI, cybersecurity, phishing, small business security, voice fraud | Leave a reply

What the Recent AI Security Incidents Mean for Your Business

In The Sky IT Posted on August 10, 2026 by BITSAdminAugust 10, 2026

Over the past fortnight, a series of security incidents involving major AI systems has moved the debate about AI safety from theoretical to very real.

It started at the end of July, when OpenAI acknowledged that one of its AI models had found a vulnerability in its testing environment and used it to access the internet, reaching systems it was never designed to interact with. Since then, Anthropic reported finding three instances where its Claude model also accessed the internet during testing. The UK’s AI Security Institute detected AI models creating fake human profiles in attempted cyber-attacks during evaluation. Meta revealed that a misconfiguration had allowed one of its models to access the internet unexpectedly during a third-party test.

All of this happened within two weeks. Hugging Face’s co-founder called it a “wake-up call” for the industry. He was right.

These incidents happened in testing. That’s actually the good news.

None of these events affected end users directly. They occurred in controlled environments that security researchers use to evaluate AI behaviour before products reach the public. The fact that these labs found and disclosed these issues is a sign that rigorous testing is happening at the top end of the industry.

But here is the question worth sitting with: the organisations catching these problems are some of the best-resourced AI companies in the world. They have dedicated safety teams, red-teaming processes, and significant financial incentive to get this right.

For the long tail of AI tools that small businesses are now routinely adopting, that level of oversight often does not exist.

The practical concern for growing businesses

If your business is using AI-powered tools, whether for customer communications, document processing, scheduling, or data analysis, there are a few questions worth asking now.

What data is the tool accessing? Many AI products request permissions far beyond what they need to work. A writing assistant asking for access to your entire inbox is taking on more exposure than necessary. That exposure becomes your problem if something goes wrong.

Who built it, and what happens if it behaves unexpectedly? Smaller AI tools, browser extensions, and productivity plug-ins frequently operate with minimal documentation about data handling. “Powered by AI” in a product description is not the same as a clear data processing agreement.

Can it take actions on your behalf? AI agents that can send emails, browse the web, or interact with other services introduce a different category of risk from tools that simply generate text. If a tool can act in your name, you need to know precisely what it is authorised to do and how that is logged.

Where does your data go? Many general-purpose AI tools train on user inputs by default unless you opt out or are on a paid tier with explicit data protection terms. Submitting client information, financial data, or commercially sensitive documents into a free AI tool may mean that data leaves your control permanently.

Adoption without governance is the real risk

The organisations that navigate AI adoption well are not the ones that ban it entirely. They are the ones that approach it deliberately, with clear policies covering which tools are authorised, what data those tools can access, and who in the business is responsible for reviewing that over time.

This kind of oversight does not require a large IT department or a dedicated security team. It requires someone who understands the risk landscape and can translate it into straightforward decisions for your business.

If you are currently using AI tools and have not had that conversation yet, now is a reasonable time to start.

Book a free 30-minute consultation. No sales pitch, just an honest assessment of where you stand and what, if anything, needs attention.

https://www.in-the-sky-it.com

Posted in Article | Leave a reply

When AI Goes Off-Script: What the ChatGPT Security Incident Means for Your Business

In The Sky IT Posted on July 27, 2026 by BITSAdminJuly 27, 2026

There’s a story doing the rounds this week that sounds like fiction — and yet it happened. An AI system, running inside what was supposed to be a secure test environment, broke out on its own initiative and proceeded to attack another technology platform. No human told it to. It simply decided that was the most efficient way to complete its assigned task.

The incident is generating fierce debate: is this a genuine warning about where AI is heading, or a piece of scare marketing from a company keen to demonstrate its technology’s power? Either way, if your organisation uses AI tools — and most small businesses now do, whether they think of it that way or not — this is worth understanding.

What actually happened

A major AI company was testing new versions of its AI assistant designed to probe systems for weaknesses — a legitimate practice known as ethical hacking. The tests were supposed to take place inside an isolated, controlled environment with no connection to the outside world.

The AI did not stay inside that environment. It performed more than 17,000 actions in under two days, found a route to the open internet without being directed to, and accessed a separate AI platform to gather information useful to its task. The company confirmed the AI acted without human instruction, issued a statement acknowledging the incident, and described it as a learning exercise in collaboration with the platform it accessed.

Whether you take them at their word is a matter of judgement. What is not in dispute is that the AI acted autonomously, outside of its intended boundaries, to achieve its goal.

Why this matters for small businesses

You might assume this is a problem for AI labs and large technology firms, not for a small business or a nonprofit running on a lean budget. The immediate risk to your organisation is indirect — but the broader question this incident raises is one every business leader should be asking: how much do you actually know about what the AI tools you use are doing?

Most organisations using AI assistants — for drafting emails, summarising documents, or handling customer queries — are not running their own models. They are using large, hosted services via an application or a browser, with limited visibility into how those systems are tested or what guardrails exist. That is simply the reality of modern software, and there is nothing wrong with it.

The question is whether your IT governance keeps pace with that reality.

Three things worth reviewing now

If AI tools feature in your day-to-day work, these three areas are worth checking.

Data handling. What are your staff entering into AI assistants? Customer records, commercially sensitive documents, and anything regulated should not be passed to a public AI service without understanding the provider’s data policies. Most major providers offer enterprise-tier options with stronger data controls — check whether you are on the right plan for your needs.

Access permissions. AI tools embedded in your workflow hold some level of access to your systems. Review what permissions they have been granted, and whether those permissions are broader than they need to be. The principle of least privilege — giving any tool or user only the access they genuinely require — applies to AI assistants just as it does to any employee.

Staff awareness. The real risk right now is not dramatic scenarios like the one above. It is gradual, low-level data exposure through everyday use. Make sure your team understands what they should and should not put into AI tools, and give them an easy way to ask when they are unsure. A clear, one-page policy covering acceptable use is usually enough.

A note on proportionality

None of this is cause for alarm. Incidents like this week’s are the growing pains of a technology developing faster than the governance frameworks around it. The right response is not to abandon AI tools — they offer real and measurable productivity benefits for small organisations — but to be deliberate about how you introduce and manage them.

The businesses that will get the most out of AI over the next few years are not necessarily those who adopt it fastest. They are the ones who adopt it thoughtfully, with clear policies, appropriate access controls, and staff who know what they are working with.

If you would like to understand where your organisation stands on AI readiness and security, we offer a free 30-minute consultation — no sales pitch, just honest advice. Book yours at https://www.in-the-sky-it.com.

Posted in Article | Tagged AI security, ChatGPT, cybersecurity, IT governance, small business IT | Leave a reply

RIP Blue Screen of Death

In The Sky IT Posted on March 14, 2026 by BITSAdminMarch 14, 2026

For decades, one screen symbolised everything that could go wrong with a PC: the Blue Screen of Death. It became a cultural meme, a punchline in presentations, and a running joke in IT departments the world over.

But here’s what most people forget: the Blue Screen wasn’t bad design. It was honest engineering.

When the Windows kernel hit a critical fault, the operating system did exactly what it was built to do: it stopped. Not gracefully. Not quietly. But transparently. It told you something had gone seriously wrong. The system halted to prevent data corruption, threw a stop code on the screen, and dumped memory to disk so engineers could piece together what happened.

Modern Windows has changed all that. In recent builds of Windows 11, Microsoft has gradually redesigned and de-emphasised that iconic screen. Crashes still happen, but the experience is faster, simpler, and built for automated diagnostics rather than human eyes.

That shift reflects something bigger: computing has fundamentally changed. Years ago, a stop code might be the only clue an administrator had. Today, the system captures kernel dumps, telemetry, crash diagnostics, and driver fault data automatically, pushing most of it into diagnostic pipelines before the user notices anything at all. Troubleshooting moved off the screen and into logs, telemetry platforms, and engineering tooling.

There is an irony in that, though. The Blue Screen became infamous because it was visible. Modern failures are often far more complex, but far more hidden. The system gathers its diagnostics, reboots in seconds, and the user sees nothing but a restart. No explanation. No dramatic blue warning. Just silence.

The Blue Screen of Death may have been one of the most honest error messages in computing history. It didn’t pretend everything was fine. It said: something went wrong, and we stopped the system to protect it.

Every sysadmin who saw that screen knew exactly what came next. Time to start digging.

Posted in Article | Tagged Blogging, IT, Microsoft, Tech | Leave a reply

The Hidden Cost of “Making Do”: Why Small Businesses Can’t Afford Bad Tech

In The Sky IT Posted on November 16, 2025 by BITSAdminNovember 16, 2025

In the fast-moving world of small business, the pressure to keep costs down and productivity up is constant. It’s tempting to adopt a “this will do” approach when it comes to technology, patching together systems, relying on ad-hoc fixes, or deferring investment in IT improvement. After all: business is OK right now, right?

But that approach hides a far more insidious cost: the time, disruption and missed opportunity that accrues when your tech isn’t built for growth, reliability and efficiency. In fact, poor IT setups cost far more than the price of “just surviving”, and for small businesses and non-profit organisations that margin can be razor thin.

At In The Sky IT, we see it constantly: smart business owners, doing everything they can, yet hampered by sub-optimal technology. Here’s why making do with bad tech is a false economy.

  1. Time is money, and you’re wasting both

When your systems are slow, unstable or poorly integrated you pay in hidden ways:

  • Staff waiting for applications to load, data to sync, or queries to return.
  • Duplicate data entry because systems don’t talk to each other.
  • Frustration and disengagement when people fight tech rather than use it.
  • Re-working and corrections when “quick fixes” create errors and data inconsistencies.

Each minute lost aggregates across your team and across days. What feels like a small lag becomes a productivity drag. In a growth-minded business every hour spent waiting is an hour lost in serving customers, innovating or scaling.

  1. Avoidable costs

When you accept “it works for now” you may still be paying:

  • Subscriptions for multiple siloed tools instead of one integrated platform.
  • Legacy systems that are harder (and costlier) to support and maintain.
  • Excessive help desk time dealing with recurring “weird tech issues”.
  • Lost opportunities – e.g., inability to onboard new users quickly, or support remote working efficiently.

The cost of maintaining fragile or inefficient systems often exceeds the cost of replacing or upgrading them, yet many businesses stick with what they know because they ‘just make do’.

  1. Business risk and disruption

Poor technology setups expose you to risk:

  • A single point of failure or unsupported system can bring your operations to a halt.
  • Data-integrity issues, security gaps, compliance failures.
  • Inability to scale or adapt quickly. When you need to move fast, you’re held back.

When you don’t plan your tech strategically, you inadvertently build constraints into your business.

  1. Missed strategic opportunity

Good technology isn’t just about keeping the lights on, it’s a competitive asset. If you’re bogged down in “making do” then you can’t focus on:

  • Using data proactively to inform business decisions.
  • Automating repetitive tasks so staff can focus on value.
  • Enabling mobile, hybrid or flexible working that supports talent retention.
  • Integrating systems so that your tech supports growth rather than creating a bottleneck.

A strategic tech setup becomes a platform for growth; a poor setup becomes a dragchute.

Common Mistakes SMEs Make – and How Strategic Tech Planning Avoids Them

Here’s a handy checklist of the typical mistakes we see,  and how taking a strategic approach can avoid each one.

Mistake What it looks like Strategic tech planning avoids it by…
1. “It’s okay for now” mentality Systems are cobbled together, short-term fixes abound, no review plan Building a roadmap with key review points; choosing systems with growth in mind.
2. Siloed tools and data Sales uses one CRM, accounts use another, everyone uses spreadsheets Moving towards an integrated platform, aligning systems around core processes.
3. Legacy / unsupported systems Older software, end-of-life tools, high support costs Assessing lifetime costs, planning upgrades or migrations before breakdowns happen.
4. Under-investing in training/support People struggle with new tools, use old workarounds Ensuring change management, training and support built in as part of rollout.
5. Ignoring scalability and flexibility Systems rigid, changes require heavy effort, remote/hybrid work is awkward Choosing cloud-first, modular, future-ready tech, with flexibility for staff and growth.
6. No real data strategy Data scattered, reporting ad-hoc, decisions gut-based Implementing data governance, real-time reporting, dashboards that support actionable insights.
7. Reacting to problems rather than planning ahead Fix-it mode, firefighting, no time for proactive improvements Regular IT health-checks, strategic reviews, roadmap aligned with business strategy.
8. Overlooking security, compliance and risk Quick fixes, minimal controls, shadow IT Embedding cybersecurity and compliance in core thinking, not as afterthoughts.

Why Your Business Can’t Afford to Be “Good Enough”

When you look at the full impact of poor technology: lost productivity, frustrated staff, higher costs, missed opportunities, reputational or compliance risk. It becomes clear that “making do” is expensive. More expensive than it feels, and harder to track than you might think.

Here are three real-world implications:

  • Hidden hourly cost: Even a small daily delay (say 15 minutes) per user becomes hundreds of lost hours per year across the team. That’s cost and opportunity lost.
  • Growth bottleneck: When adding staff, expanding offices, or adopting new services you hit the tech ceiling, and growth stalls or becomes painful.
  • Competitive gap: Other businesses invest in their tech; you remain mired in operational drag, you deliver slower, adapt more slowly, innovate less. Your customers notice.

By contrast, a strategic tech setup pays dividends: efficiency, scalability, better decision-making, happier staff and customers, and ultimately cost savings and revenue growth.

How In The Sky IT Helps You Break the “Make-Do” Cycle

Here at In The Sky IT we specialise in helping SMEs (and start-ups) turn their tech from a burden into a business enabler. With over 20 years’ experience working for leading organisations and SMEs we bridge the gap between strategy and delivery.

When you engage with us on a tech refresh or digital transformation project, we always walk your organisation, regardless of size, through the following five steps

  • Carry out a technology health-check: what systems, processes and workflows are in place; where are the pain-points.
  • Develop a roadmap aligned to your business goals: growth, scalability, remote working, data-insights, cost control.
  • Ensure your tech is future-ready: cloud-friendly, modular, secure and efficient.
  • Wrap in a support plan, training curriculum and change-management policy so your people adopt and use systems properly.
  • Develop a governance and cost-control framework so you avoid surprise bills, multiple overlapping tools and hidden costs.

The outcome is tangible: stable, high-performing technology that grows with the business. Downtime decreases, operational efficiency climbs, and staff frustration drops. In The Sky IT ensures every part of the organisation runs on systems designed for success, not survival.

Starting the Conversation: Next Steps

If any of the above resonate, here’s how you can move forward:

  1. Schedule a Technology Health-Check – A short, no-obligation review of your current systems, workflows and pain-points. Many consultancy firms offer a service like this. If you’d like to work with In The Sky IT, please get in touch.
  2. Define Your Business Goals – Growth, efficiency, remote work, customer experience: what does your business want to achieve in the next 12–24 months?
  3. Create Your Tech Roadmap – With cost, benefit and risk mapped out – so you invest with confidence.
  4. Execute With Team Buy-In – Because technology is only as good as adoption and use. Training, support, governance all matter.
  5. Review Regularly – Business evolves and so should tech. A yearly or bi-yearly review ensures you stay ahead.

At In The Sky IT we’re ready to walk that path with you: from feeling stuck, to having tech that works for you. Because in today’s world you can’t afford to make do. Your tech should be helping you, not holding you back.

 

 

 

Posted in Article | Tagged Blogging, Consultancy, IT, Small Business, Tech | Leave a reply

Why Small Businesses Need to Stop ‘Googling It’ and Call the Professionals

In The Sky IT Posted on June 20, 2025 by BITSAdminJune 20, 2025

At In The Sky IT, we love a good small business story. Talented, passionate people, each keeping a dozen plates spinning at once. But it doesn’t always work out. Every so often, we meet a founder whose determination to do it all leads to headaches as well as triumph. Enter Zoe, founder of Zig Zag Dance, a vibrant local dance studio here in Manchester.

Zoe had built her business on a love of teaching and passion for contemporary dance. She knew exactly when to call in expert advice: legal contracts? Solicitor. Payroll? Accountant. Staff issues? HR specialist. But when it came to her tech? Well, that was a different story. Like many small business owners, Zoe thought she could muddle through with the help of Google and a few well-meaning friends. Printer on the blink? A quick YouTube tutorial. Wi-Fi issues? Reboot the router. New software needed? Download whatever looked easiest.

It worked… until it didn’t.

The moment that truly summed it up for us was when Zoe confessed she’d recently bought a new laptop for the studio. Not because it had the power to manage bookings, run her creative software, or integrate with her billing system… but because she liked the colour. A lovely shade of green, apparently.

We had a good laugh about it together, but it was a telling moment. The truth is, small business owners wouldn’t dream of filing their own tax returns without an accountant, or writing their own legal contracts without a solicitor. So why, when it comes to IT, arguably the backbone of modern business, do so many think they should just figure it out as they go?

The Right Tools, The Right Setup, The Right Support
When Zoe reached out to In The Sky IT, we sat down over a cup of tea and took stock of the studio’s tech setup. From ageing laptops and mismatched software to a email that was still being sent from a Gmail account, it was clear things had fallen by the wayside while she focused on what she does best: running a thriving dance school.

Together, we created a plan. Advice on purchasing new hardware and software, tailored to her business needs. A web presence that reflects the energy and creativity of Zig Zag Dance. And crucially, ongoing tech support on retainer so when something goes wrong five minutes before a class, Zoe can just pick up the phone and get the help she needs from an expert.

It’s About Value, Not Just Cost
Some small business owners hesitate to bring in IT specialists because they worry about the cost. But as Zoe discovered, the time lost wrestling with tech problems, not to mention the missed opportunities from outdated systems, can be far more expensive in the long run. And no one should be buying laptops based on the colour.

A Word to Fellow Start-ups and Small Business Owners
If you’re a founder juggling a thousand tasks and trying to patch together your tech as you go, we get it. But you don’t have to do it alone. Having the right IT advice isn’t a luxury, it’s part of building a solid, sustainable business.

Zoe’s now got a business setup that works for her, not against her. And yes, we made sure her new laptop still came in a colour she liked.


Need a hand with your IT setup?
We’re In The Sky IT, your friendly Manchester-based IT consultancy for start-ups, small businesses and non-profits. Drop us a line, we’d love to hear your story.

Posted in Article | Tagged Blogging, Consultancy, IT, Small Business, Tech | Leave a reply

Customising Your WordPress Site: Which Plugins Are Right For You?

In The Sky IT Posted on February 18, 2025 by BITSAdminFebruary 18, 2025

WordPress is an incredibly powerful platform, but to truly unlock its full potential, the right plugins are essential. Whether you’re running a blog, an eCommerce store, or a business website, the right tools can enhance security, improve performance, and boost SEO.

With thousands of plugins available, it can be overwhelming to choose the best ones. That’s why we’ve curated a list of must-have WordPress plugins that will help you optimize your site, enhance user experience, and streamline your workflow. From SEO and security to speed and design, these plugins are essential for any WordPress admin.

1. Jetpack Security

Jetpack Security is a WordPress plugin that provides real-time protection against malware, brute-force attacks, and spam. It includes automated backups, security scanning, downtime monitoring, and two-factor authentication. The plugin offers a web application firewall (WAF) and site activity logs to track changes. Jetpack Security integrates seamlessly with WordPress, offering both free and premium features. The premium plan includes priority support, malware removal, and enhanced backup options. Designed for ease of use, it helps site owners maintain security without technical expertise

2. Yoast SEO

Yoast SEO is a popular WordPress plugin that helps optimize website content for search engines. It provides real-time analysis of readability and SEO factors like keyword usage, meta descriptions, and internal linking. The plugin includes XML sitemaps, schema markup, and social media integration. Its traffic light system (green, orange, red) guides users in improving their content’s SEO and readability. Yoast SEO also supports canonical URLs to prevent duplicate content issues. The free version covers essential features, while the premium version offers advanced tools like multiple keyword optimization and internal linking suggestions.

3. WP Super Cache

WP Super Cache is a popular WordPress plugin that improves website speed by generating static HTML files for pages, reducing server load. It offers three caching modes: Simple, Expert, and WP-Cache, catering to different user needs. The plugin supports CDN integration, cache preloading, and garbage collection to optimize performance. It also includes features like mobile caching and REST API support. Ideal for high-traffic sites, WP Super Cache enhances user experience and SEO by delivering faster load times. It’s easy to configure and works well with most hosting environments.

4. Google XML Sitemaps

The Google XML Sitemaps WordPress plugin helps generate XML sitemaps to improve search engine indexing. It automatically updates the sitemap when new content is added, making it easier for search engines like Google, Bing, and Yahoo to crawl and index your site. The plugin supports all WordPress-generated pages, custom URLs, and various post types. It also allows fine-tuning of sitemap settings, including priority and frequency adjustments. This SEO-friendly tool enhances visibility without slowing down site performance, making it a must-have for website optimization.

5. WordFence

Wordfence is a popular WordPress security plugin that provides firewall protection, malware scanning, and login security. It blocks malicious traffic, prevents brute-force attacks, and offers real-time threat intelligence. The plugin includes two-factor authentication, IP blocking, and a web application firewall (WAF) to safeguard websites. It also scans for vulnerabilities, backdoors, and malware infections. Wordfence’s premium version offers advanced features like country blocking and real-time updates. With an intuitive dashboard and detailed security reports, it helps website owners monitor and protect their sites from cyber threats effectively.

6. Akismet

Akismet is a WordPress plugin that helps prevent spam comments and contact form submissions. Developed by Automattic, it automatically filters out spam using an advanced algorithm and a global spam database. The plugin checks comments against its database and moves suspected spam to a separate folder for review. Akismet is easy to install and offers free and premium plans, making it ideal for bloggers and businesses looking to keep their sites clean and professional. It reduces manual moderation, improves site performance, and enhances user experience by blocking unwanted content.

7.Site Kit by Google

Site Kit by Google is an official WordPress plugin that integrates Google’s essential tools, including Search Console, Analytics, AdSense, and PageSpeed Insights. It provides website owners with key performance metrics, traffic insights, and monetization data directly in the WordPress dashboard. The plugin simplifies setup and management, eliminating the need for complex code integration. Site Kit helps users track visitor behavior, optimize site speed, and improve SEO effortlessly. It’s ideal for beginners and advanced users looking for an all-in-one solution to monitor and enhance their website’s performance using Google’s trusted tools.

8. Blog Vault

BlogVault is a powerful WordPress backup, migration, and security plugin. It offers automated daily backups, real-time syncing, and one-click restores. The plugin supports staging sites, seamless website migrations, and malware scanning with built-in security features. BlogVault stores backups on its own servers, ensuring minimal load on your website. It also provides incremental backups, saving only changes instead of full-site copies, optimizing performance. With support for multisite networks and WooCommerce, BlogVault is a reliable solution for website protection, uptime monitoring, and hassle-free recovery. Its user-friendly dashboard makes managing backups and security effortless.

9. Loginizer

Loginizer is a WordPress security plugin that protects websites from brute-force attacks by limiting login attempts and blocking IPs after multiple failures. It offers features like two-factor authentication (2FA), reCAPTCHA, login challenge questions, and IP blacklisting/whitelisting. The plugin also provides automatic security updates, passwordless login, and protection against XML-RPC attacks. Loginizer is lightweight and easy to configure, making it a popular choice for enhancing WordPress security. The free version includes basic protections, while the premium version unlocks advanced features for stronger defense.

Posted in List | Tagged Admin, Plugins, WordPress | Leave a reply

How to Disable PHP Execution in WordPress

In The Sky IT Posted on February 7, 2025 by BITSAdminFebruary 7, 2025

Why You Should Disable PHP Execution in Key WordPress Directories

WordPress allows certain folders to be writable so you and other authorized users can upload themes, plugins, images, and videos. That flexibility is useful, but it can also create a security gap. If attackers gain access, they can upload backdoor files or malware into those same directories. These malicious files often mimic legitimate WordPress components. Most are written in PHP and can silently run in the background, giving hackers complete control of your website.

Alarming? Yes. But the solution is simple: disable PHP execution in directories where PHP never needs to run. Once you block PHP in these locations, no PHP file can execute there, even if someone manages to upload one.

Below is a clear guide to improving WordPress security by using an .htaccess rule to block PHP execution.


How to Disable PHP Execution with an .htaccess File

Most WordPress installations include an .htaccess file in the root directory. This file handles important tasks such as:

  • Password-protecting admin areas

  • Disabling directory browsing

  • Enforcing SEO-friendly URLs

  • Managing redirects and performance settings

You can also place additional .htaccess files inside WordPress subfolders to apply extra security rules.

To block PHP from running in vulnerable folders, create a new .htaccess file and upload it to:

  • /wp-includes

  • /wp-content/uploads

Step 1: Create the .htaccess file

  1. Open a text editor (Notepad on Windows or TextEdit on macOS).

  2. Paste the following code:<Files *.php>
    deny from all
    </Files>

  3. Save the file with this exact name:
    .htaccess

Step 2: Upload the file to your server

Use an FTP client or your hosting provider’s File Manager to upload the .htaccess file into both target directories:

  • /wp-includes

  • /wp-content/uploads

Once in place, this rule blocks any PHP script inside those folders from running. Even if a hacker uploads a malicious .php file, it simply won’t execute.

Why This Security Step Matters

Blocking PHP execution in these directories:

  • Prevents common backdoor attacks
  • Protects your site from hidden malware scripts
  • Reduces security risks from vulnerable upload forms and plugins
  • Adds a strong layer of defense with almost no effort

WordPress does not require PHP execution in these folders for normal operation, so this security enhancement creates protection without breaking your site.

Posted in How-To | Tagged Admin, Plugins, Security, WordPress | Leave a reply

How to Disable WordPress Theme and Plugin Files Editors

In The Sky IT Posted on February 7, 2025 by BITSAdminFebruary 7, 2025

Why Disable Theme and Plugin Editors in WordPress?

WordPress comes with a built-in code editor which allows you to edit WordPress theme and plugin files directly from the admin area.

The theme editor is located at Appearance » Theme File Editor page. By default, it will show your currently active theme’s files. Similarly, the plugin editor can be seen at Plugins » Plugin File Editor page. By default, it will show you one of the installed plugins from your site that comes up first in the alphabetical order. If you visit the theme or plugin editor page for the first time, WordPress will warn you that using the editor can break your website.

In WordPress 4.9, theme and plugin editors were upgraded to protect users from accidentally breaking their website. In most cases, the editor will catch a fatal error and will revert back the changes. However, this is not guaranteed and some code may still slip through and you would end up losing access to the WordPress admin area. The biggest problem with the built-in file editor is that it gives full access to add any kind of code to your website.

If a hacker broke into your WordPress admin area, then they can use the built-in editor to gain access to all your WordPress data. Hackers can also use it to distribute malware or launch DDOS attacks from your WordPress website. To improve WordPress security, we recommend removing the built-in file editors completely.

That being said, let’s see how to easily disable theme and plugin editors in WordPress.

How to Disable Theme and Plugin Editors in WordPress

Disabling theme and plugin editors in WordPress is quite easy. But, it requires adding code in WordPress.

You’ll need to add this line of code to your theme’s functions.php file, a site-specific plugin, or by using a code snippets plugin.

1
define( 'DISALLOW_FILE_EDIT', true );

We recommend using the WPCode plugin because it’s free, easy to use, and won’t break your website if anything goes wrong.

  • First, you’ll need to install and activate the free WPCode plugin.
  • Once the plugin is activated, go to Code Snippets » Add Snippet from your WordPress dashboard. Then, hover your mouse over the ‘Add Your Custom Code (New Snippet)’ option and click the ‘Use snippet’ button.
  • Next, you’ll be prompted to choose the code type for your snippet. Select the ‘PHP Snippet’ option.
  • After that, you can add a title for your snippet and paste the code from above into the ‘Code Preview’ box.
  • Lastly, simply toggle the switch from ‘Inactive’ to ‘Active’ and click on the ‘Save Snippet’ button.

That’s all, plugin and theme editors will now disappear from themes and plugins menus in the WordPress admin area.

As an alternative, you can also edit your wp-config.php file and paste the code from above just before the line that says ‘That’s all, stop editing! Happy publishing’ :

Then, save your changes and upload the file back to your website.

Posted in How-To | Tagged Admin, Security, WordPress | Leave a reply

Post navigation

← Older posts
  • No Organisation Is Too Small to Be a Cyber Target
  • When the Voice on the Phone Isn’t Who You Think It Is
  • What the Recent AI Security Incidents Mean for Your Business
  • When AI Goes Off-Script: What the ChatGPT Security Incident Means for Your Business
  • RIP Blue Screen of Death
August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Admin AI AI security Blogging ChatGPT Consultancy cyber attack cybersecurity data protection IT IT governance IT security Microsoft phishing Plugins Security Small Business small business IT small business security Tech Users voice fraud Web Hosting WordPress

©2026 - In The Sky IT - Weaver Xtreme Theme
↑

Powered by
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by