Loading

The PSTN Switch Off: What Your Law Firm Needs to Check Now

The PSTN switch off is set for 31 January 2027. If your firm’s phone system or broadband still runs over the old copper network, you need a migration plan now, and you need to know which parts of that plan are IT and which parts belong to your landlord or security contractor.

Why the PSTN switch off affects more than your phone system

Most law firms treat the PSTN switch off as a phone upgrade and stop there. Openreach is retiring the whole copper network, not just voice calls, so any connection built on old copper lines is affected. That includes some broadband services still delivered over copper, such as ADSL and FTTC.

When is the PSTN switch off happening in the UK?

Openreach originally planned to retire the network by December 2025, then pushed the date to 31 January 2027 to give providers more time to migrate vulnerable customers safely. Openreach has since said this date will not move again.

More than half a million UK business lines are still on the old copper network. Many exchanges have already stopped selling new copper lines, so some areas are further along than the national deadline suggests. Costs for remaining copper services are rising as the deadline nears, so waiting means paying more for lines you could migrate now for less.

What needs checking in a law firm before the PSTN switch off?

Start by separating what your IT provider can fix from what needs a different call entirely.

Your main phone system and switchboard sit squarely in IT. If you’re still on an ISDN or analogue system, or a hosted VoIP setup that hasn’t been reviewed in a few years, that’s the first thing to migrate.

Your broadband connection matters too. If your office internet still runs over an old copper ADSL or FTTC line, that connection needs upgrading to full fibre before the switch off, or you risk losing internet access along with your phone lines.

Beyond IT, a law firm should also check anything else in the building that quietly relies on a phone line. Door entry systems, intruder alarms, lift emergency lines, and older card payment terminals sometimes dial out over PSTN. These aren’t something your IT provider will fix, since they belong to your landlord, alarm company, or lift maintenance contractor.

But if nobody checks them, they can fail without warning when the network switches off. Worth a call to whoever manages each one, so the responsibility doesn’t fall through the gap between IT and facilities.

What happens if you leave the PSTN switch off too late?

The practical risk is losing phone and internet service with no warning, right as your exchange is switched off. The financial risk is paying rising copper line charges in the meantime for a service you’ll have to replace anyway.

There’s also a coordination risk specific to law firms. If your phone system, broadband, and any facilities equipment migrate on different timelines with no one person tracking all three, something gets missed. That’s usually the alarm system or the intercom, since nobody in IT owns it and nobody in facilities knows it depends on PSTN.

How do you plan a PSTN switch off migration for a law firm?

Start with an audit of your own IT estate: phone lines, broadband circuits, and any analogue devices connected to your network, such as card machines or fax lines. Your IT provider should lead this part.

Separately, ask your landlord or facilities contact to confirm the status of door entry, alarms, and lift lines in your building. If you’re in a shared building, this may already be underway, but confirm it rather than assume it.

Once you have both lists, sequence the migration around business continuity. Move your phone system and broadband first, since those affect everyone in the firm daily. Building systems can follow on their own timeline, managed by whoever is responsible for them.

Where does Microsoft Teams fit in?

If your firm already uses Microsoft 365, moving your main phone system to Microsoft Teams Voice with Direct Routing is often the simplest way to get off PSTN. It keeps calling inside a platform your staff already use. Direct Routing still needs a telephony provider behind it to connect calls into Teams, so this is a migration to plan properly rather than a setting you switch on yourself.

How Labyrinth Technology helps

We’ve supplied and managed VoIP telephone systems for over a decade, and today that work is focused on law firms and financial services firms. We audit your phone system, broadband connections, and any network-connected devices still running over PSTN, then build a migration plan around your firm’s daily operations rather than a generic rollout schedule.

Get in touch to find out exactly what in your IT setup still depends on the old network.

Openreach’s deadline is 31 January 2027. That’s about six months away, and copper line costs are rising every month you wait.

How AI Is Changing the Legal Software Law Firms Rely On

TL;DR: Legal software providers are connecting more than one AI model to the same platform. LexisNexis now runs Anthropic’s Claude inside Lexis+ with Protégé, and NetDocuments connects Claude, ChatGPT and Microsoft Copilot to firm documents through a tool called ndConnect. Your firm’s data now sits with several vendors at once, and most contracts haven’t caught up to check for it.

What changed in legal software this year?

LexisNexis added Anthropic’s Claude legal plugin to Lexis+ with Protégé back in February, when the platform first replaced its previous AI tool. On 8 July, that same integration was extended to in-house legal and compliance teams for the first time, alongside more than 100 prebuilt workflows and over 50 skills built by LexisNexis.

Sean Fitzpatrick, CEO of LexisNexis Legal, said the update responds directly to what in-house customers asked for. Robb Hern, the company’s GM of Corporate Legal, put it more bluntly: in-house teams have historically been underserved by legal technology built with law firms in mind.

Who is responsible for how AI models connect to your legal software?

The SRA already expects your Compliance Officer for Legal Practice to own AI governance across the firm. That responsibility now stretches further than it did a year ago.

It’s no longer enough to know that your legal software uses AI. Someone at your firm needs to know which AI providers it uses, what each one is contractually allowed to do with your data, and who checks that before a new integration goes live.

Is this only happening at LexisNexis?

No. NetDocuments has built the same approach into a tool called ndConnect, which lets Claude, ChatGPT and Microsoft Copilot connect directly to a firm’s document repository through the Model Context Protocol, an open standard for linking AI tools to stored data.

Dan Hauck, Chief Product Officer at NetDocuments, described ndConnect as extending the platform’s document and AI capabilities to third-party AI vendors while keeping the underlying protection and productivity of the core system intact. NetDocuments says existing permissions, ethical walls and data loss prevention rules apply automatically at that connection point, with documents never leaving the platform.

Two of the largest legal software providers in the market have rebuilt their platforms around the same idea within months of each other, which tells you this is becoming standard practice rather than a one-off feature.

What should your firm check before adopting multi-model legal software?

Governance here doesn’t need to be complicated. It needs to exist, and someone needs to check it before signing anything.

Name every AI model connected to the platform

Ask the vendor which AI providers actually touch your data, not just the one featured on the marketing page. Each one may sit under a different agreement.

Confirm nothing is retained outside the platform

Even a brief handoff to an external model is a moment your document could be stored somewhere you don’t control. Get a specific answer on retention, not a general reassurance.

Check that permissions travel with the connection

Your firm’s ethical walls and access restrictions are only useful if they still apply once an external AI model connects. Ask whether that enforcement happens automatically, or whether someone has to configure it separately.

Ask what the audit log actually shows

If several AI systems can reach the same documents, you need to see, in full, what each one did and when. Ask to see a sample log before you commit.

Get liability agreed in writing

If a document is mishandled, you need to know upfront whether that sits with the platform provider or the AI model provider. That question is much harder to answer after something has already gone wrong.

How Labyrinth Technology can help

We work with law firms across the UK on exactly this kind of decision. That means reviewing how AI tools connect to your case management software, your document management software and your compliance software, and checking what a vendor’s security claims actually mean in practice.

If your firm is looking at Lexis+ with Protégé, NetDocuments, or any legal software adding AI capability, we can help you ask the right questions before you sign anything.

Two major legal software providers have rebuilt themselves around multiple AI vendors this year. The firms checking their contracts now won’t be the ones explaining a data question after the fact.

SRA AI Guidance: What Law Firms Need to Put in Place Now

TL;DR: SRA AI guidance makes solicitors personally responsible for anything AI produces, including research and court submissions. Two firms have already been referred to the SRA this year after AI-generated citations turned out to be fake. Verification, staff training, documented use and client disclosure are what the SRA expects firms to have in place.

What does the SRA’s AI guidance actually say?

The SRA has not written a rulebook for AI. Its compliance tips, last updated in February 2026, restate the Code of Conduct and apply it to AI tools directly.

You stay responsible for your work, whoever/whatever produced the first draft. Client confidentiality applies regardless of the platform. And you must understand a tool well enough to spot when it has got something wrong.

Who is responsible for AI compliance in your firm?

The SRA expects your Compliance Officer for Legal Practice (COLP) to take ownership of AI governance across the firm.

That means someone specific is accountable for how AI tools are used and checked, with the authority to enforce it.

Why are solicitors being referred to the SRA over AI use?

Pinsent Masons referred itself to the SRA after a junior solicitor used AI to research a point of insolvency law. The tool invented a statutory provision that did not exist, and it made it into a letter to the court. Two senior solicitors had signed that letter off without catching the error. (Source – Law Gazette)

In a separate case, Rodney v Gee’z Micro Bar & Pitstop, His Honour Judge Grimshaw referred two solicitors at AML Legal after a skeleton argument cited authorities that turned out to be fabricated. One document even included the line “your client was a litigant in person,” language the judge noted read like something generated rather than written by a lawyer. (Source – Law Gazette)

Judge Grimshaw called for a “robust approach” from the courts, describing fake AI citations as a growing threat to the justice system. Neither case involved a rogue actor trying to deceive the court. Both involved firms that skipped the verification step.

See what Matt has to say


What should your law firm have in place to meet SRA AI guidance?

Governance does not need to be complicated. It needs to exist and be followed.

Verify every citation before it leaves the building

Any citation or quotation an AI tool produces gets checked against the primary source before it reaches a client or a court. No exceptions for time pressure.

Train staff on what AI can and cannot do

Staff need to understand that a confident, well-formatted answer from an AI tool can still be entirely wrong, these are known as AI hallucinations.

Keep client data out of AI tools

AI tools can store and reuse whatever is typed into them, so confidential client information should never go near one. The confidentiality duty always applies, no matter which tool is involved. What matters most is knowing where shadow AI might be creeping into your firm, and training staff to use only the tools you have approved.

Record AI use in the matter file

If AI contributed to research or drafting, note it. This protects the fee earner and gives the firm a clear audit trail if something is later questioned.

Tell clients when AI is part of the process

The SRA’s guidance is explicit on this point. Clients should be told when AI is involved as a normal part of client care.

How Labyrinth Technology can help

We work with law firms across the UK to put the practical structures behind compliance guidance like this. That means secure systems for how AI tools connect to your data, and IT support that understands why a law firm’s obligations are different from a typical small business.

If you are reviewing how AI is used across your firm, we can help you build the policies and secure systems that sit behind it.

Two firms have already been referred to the SRA this year over uncaught AI citations. The next one is being decided right now, one verification step at a time.

Assurix Verification: What It Means for Managing Partners

Assurix verification proves your IT provider meets security and operational standards every day, not just on audit day. Only four MSPs in the UK currently hold it. Labyrinth Technology is one of them.

Why most IT provider claims are hard to verify

Every IT provider makes similar promises about their security and compliance. The problem is that most of those claims are impossible to verify between annual audits. You take their word for it, and find out whether that word was good when something goes wrong.

Assurix was built to address that. It is an independent UK trustmark that monitors IT providers continuously, using live data from the tools they use every day. If a provider’s standards slip and are not corrected within 30 days, their certification is suspended. That change in status is reflected publicly in the Assurix directory.

What does Assurix verification cover?

The Assurix framework covers 68 controls across three areas, with more than 20 tracked in real time.

Cybersecurity

Aligned to the NCSC Cyber Assessment Framework 4.0, this area looks at security fundamentals: how software is kept up to date, how access to systems is controlled, and what happens when a security issue is identified. These are the controls the UK government is building its regulatory expectations around.

Operational maturity

This looks at how a provider runs day to day. It covers whether SLAs are consistently met and whether the processes a provider says they follow are actually being followed. It is the area where the difference between what a provider says and what they do becomes measurable.

Business resilience

This covers backup integrity and restore testing. For a law firm, this is what shapes how quickly you can get back to work after a serious incident and whether your data is genuinely recoverable when you need it.

How is Assurix verification different from ISO 27001?

ISO 27001 is a well-respected standard and worth holding. It is also an annual assessment. A provider can pass in January and let things slip by April, and nobody outside the business will know until the following year’s audit.

Assurix monitors controls live. The public directory shows the current certification status of every verified provider, so you are not relying on a certificate with a date on it.

Why does Assurix verification matter for your law firm?

The SRA holds your firm responsible for the security of its systems, regardless of who manages them. If your firm’s IT support falls below the standard needed and a breach occurs, the regulatory exposure sits with you.

Choosing a provider with independently verified, continuously monitored standards is a compliance decision as much as a commercial one.

What questions should you ask your IT provider?

Can you show me a patch compliance report from the last 30 days?

Any provider actively managing your systems should produce this without hesitation. Regular, documented patch compliance is a basic requirement, and a provider who cannot evidence it is not managing your systems as proactively as they should be.

When was a full restore last tested, and what did it cover?

Backup testing is not optional. Ask your provider for a documented record of the last restore test: what was covered and how long recovery took. If that record does not exist, treating it as a priority to resolve is worthwhile. You can learn more about what a proper backup and disaster recovery arrangement looks like on our services page.

How are your standards independently verified between annual audits?

This is the most direct question you can ask. An annual certificate tells you a provider met a standard once. Ask them specifically how their performance is verified in the months between assessments. If they cannot give you a clear answer, you are working on trust rather than evidence.

How Labyrinth Technology can help

Labyrinth Technology is one of only four MSPs in the UK to hold the Assurix trustmark. That status is publicly verifiable through the Assurix directory and remains valid only while the underlying controls are maintained.

Our cyber security services and outsourced IT support are built around the same standards Assurix verifies. If you want to understand what that looks like for your firm, get in touch with the team.

Most firms only discover their IT provider’s standards have slipped when something goes wrong. By then, the SRA review and the client conversation are already unavoidable. Assurix verification is one way to make sure you are not finding that out under pressure.

What Is Shadow AI and Why Should Your Law Firm Care?

Shadow AI is when staff use unapproved AI tools at work, often without realising the risk. It can expose client data, breach GDPR, and widen your attack surface. To prevent the risks of shadow AI, create a policy around AI tool usage, train your staff on approved AI tools, and audit regularly.

What Is Shadow AI?

You have probably heard of shadow IT. Someone installs unapproved software or signs up to a cloud tool without telling anyone. Shadow AI is the same idea, but the risks go further.

Shadow AI refers to the unsanctioned use of artificial intelligence tools by employees, without IT knowledge or sign-off. Gen AI tools are free, fast, and genuinely useful, which is exactly why they spread.

According to a Microsoft survey of UK workers, 71% have used consumer AI tools at work without IT approval, yet most firms have no AI governance in place at all.

Unlike shadow IT, the risk is not just about where your data sits. Generative AI models are cloud-based, meaning anything your staff put in gets processed on external servers, outside your control and can even be retained long after the conversation ends.

What Does Shadow AI Actually Look Like in a Law Firm?

Rushed document drafts

A fee earner copies an internal strategy deck into a free AI tool before a client call. That company data is now sitting on an external server, outside your control.

Browser extensions and AI plug-ins

Someone installs an AI writing assistant as a plug-in. It reads everything they type, including client emails and case notes, often well beyond what the user expected.

Personal account workarounds

According to Menlo Security, 68% of employees used personal accounts to access free AI tools in 2025, with 57% entering sensitive data in the process. Restrict access at work and people find another way, with none of your firm’s security controls in place.

AI features embedded in existing tools

AI capabilities are being built into tools your staff already use, quietly activated through updates. Features embedded in a personal Microsoft account sit entirely outside your security oversight, even if the tool looks familiar.

What Are the Significant Risks for Law Firms?

Data leaks and client confidentiality

Unauthorised AI use means customer data can enter systems you do not control. According to a RiverSafe survey of UK CISOs, 1 in 5 UK companies has already experienced data leakage through employee use of generative AI.

GDPR and SRA compliance violations

Adopting AI tools without proper vetting can put your firm in breach of GDPR. The SRA takes data security seriously, and the EU AI Act is adding further obligations on top.

Inaccurate AI generated outputs

Unvetted AI apps can produce AI generated content that looks authoritative but is simply wrong. In a legal context, an AI-generated draft that contains errors could influence advice or reach a client completely unchecked.

A weaker security posture

Personal accounts have no enterprise security controls, no MFA enforcement, and no visibility from your IT team. By the time most firms know which AI tools are actually in use, a security incident has already forced the question. You can read more about how Labyrinth Technology approaches network security here.

How Do You Mitigate Shadow AI?

Write a policy and make it usable

Define which AI tools are approved, what data can go into them, and how AI generated outputs must be reviewed. Ensure it is brief and simple to understand for everyone in the organisation.

Give people sanctioned AI tools that work

People use unauthorised AI tools because they enhance productivity and there is nothing better on offer. Providing enterprise-grade alternatives removes the incentive and gives security leaders full visibility over AI use. If you are not sure where to start, our digital transformation strategies service helps firms adopt AI properly, with the right governance from the beginning.

Train your staff

Security awareness training is not just for phishing. Your people need to understand what shadow AI is, the AI risk it creates, and how to request approval for tools they want to use.

Audit regularly

New AI tools appear constantly, and the ones your staff are using today may not be the same ones they are using in six months. Regular audits, led by your IT team or provider, keep your approved list current and your exposure visible.

How Labyrinth Technology Can Help

Labyrinth Technology has been supporting law firms in London for over 20 years. We help firms get visibility over unauthorised AI use, build realistic governance frameworks, and put the right cyber security controls in place before shadow AI becomes a serious problem.

Shadow AI is not a future concern. It is happening now. Get in touch for a free consultation and let us help you get on top of it.

Labyrinth Technology is Now a NetDocuments Partner

We are pleased to announce that Labyrinth Technology is now a NetDocuments partner. We have been working with law firms running NetDocuments for years, and this partnership formalises that relationship.

What is NetDocuments?

NetDocuments is a cloud-based document management system built specifically for law firms. It is the system your firm’s documents and matter files are built around. A large number of UK firms have made it the foundation of how they manage their practice, and adoption has been growing steadily.

If your firm is already on NetDocuments, you will know how much of your day-to-day operation depends on it working reliably. A failed migration or a platform issue has an immediate knock-on effect across the whole practice. Having an IT partner who knows NetDocuments properly means you are far less likely to find yourself in that position.

Why this partnership matters for your firm

As a NetDocuments partner, Labyrinth Technology now has a direct relationship with the platform and its support infrastructure. For you, that means faster resolutions and better-informed guidance when your firm is planning anything significant on the platform.

We have dedicated in-house NetDocuments product owners who work with the platform day to day, which means the support your firm gets is grounded in real working knowledge of it. That knowledge is what makes the difference when something needs to move quickly.

This is not a new area of work for us. We have been supporting firms through NetDocuments implementations and migrations for a number of years. The partnership reflects experience we already had.

What Matt Dunn, CTO and COO at Labyrinth Technology, had to say

“As a specialist IT partner for law firms, we’ve spent a decade helping firms that put NetDocuments at the heart of their practice. Managing matters, documents, and client data with confidence.

NetDocuments is strategically important to our clients, so it’s strategically important to us.

With dedicated in-house NetDocuments product owners, we bring deep platform expertise that will translate directly into faster rollouts, smoother migrations, and ongoing support your team can rely on. We’re proud to formalise that commitment through this partnership.”

How can Labyrinth Technology support you

This partnership sits alongside everything else Labyrinth Technology does for law firms. We support firms across Microsoft 365, network security, backup and disaster recovery, and cloud migrations.

NetDocuments also integrates directly with Microsoft 365, so if we already support your firm’s Microsoft environment, the two areas of support connect naturally.

If you would like to talk through what this means for your firm, get in touch with the team.

Too Many AI Tools, Not Enough Strategy: A Guide for Law Firms

Every law firm I talk to is asking about Claude Legal at the moment.

Claude, Copilot, Lexis+ AI, Harvey, Thomson Reuters, Clio. The list goes on.

How do you stay ahead without ending up with 5 different AI subscriptions per person that most people are not using?

Here are some of my recommendations from experience.

1. Dedicated research team

It’s a good idea to have a test group of ‘power users’ from different roles across the business to be trying out new AI tools and features and seeing which ones deliver the most value. There needs to be some guard rails and governance here though.

You don’t want to be rolling out new tools every week, or you’ll end up needing an expensive digital transformation project in a year to unpick and consolidate it all!

You also need to do your cyber security due diligence and make sure anything you are testing is set up properly, securely and the data it leverages is ready (accurate, access controlled correctly etc.)

2. Lead with the requirements

Many other law firms are using or experimenting with these tools. So it can be easy to jump to leading with the solution and trying to make it fit.

Take the time to understand how fee earners work, sales, marketing, HR, accounts. Understand their pain points and where AI could save them the most time. Then you can look at matching a solution to those requirements.

3. Measure ROI

The reality is that most law firms will benefit from a combination of these tools to suit different requirements and business functions. Lexis+ for example only uses data from trusted legal sources. Copilot and Claude can leverage Microsoft 365 data and meet you where you work.

But can you clearly demonstrate and measure the ROI from each of these tools? Do that per department and consider whether each one is actually needed by everyone in the business.

4. Governance

You need to define how each of these tools will be used, and consider the appropriate quality, ethical, legal and data privacy implications.

Document it, but make it clear, concise and don’t hide behind policies. Train your team. Regularly. They will forget, trust me.

Look at technical controls to enforce your AI policies.

Cloud Consultancy Services: What You Need To Know

Cloud consultancy services help you plan, secure, migrate, and manage your cloud environment so it supports real business goals. With the right cloud consultants, you reduce risk, improve security, control costs, and turn cloud technology into measurable business value, not technical noise.

Why cloud decisions feel harder than they should

Moving to the cloud often sounds simple. In reality, it can feel overwhelming. You are expected to choose platforms, manage data security, control cloud usage, and still keep daily business operations running smoothly. Many companies rush in and later realise they have created tech debt, higher costs, or even security gaps.

This is what cloud consultancy aims to mitigate. Cloud consultancy services exist to guide you through your cloud journey with clarity and structure. The goal is not cloud for the sake of it. The goal is better outcomes for your business, improved efficiency, and a cloud environment that actually works for you.

At Labyrinth Technology, based in London, cloud consulting services are delivered with a practical mindset. The focus stays on your business objectives, your customers, and your long term growth.

What is cloud consultancy?

On the right side, there is a man wearing a blue navy sweater and glasses looking confused at a computer screen. He appears to be trying to type something on a PC keyboard. On the left side is a textbox reading "Trouble with tech? We've got it covered! Expert IT support."

Cloud consultancy is a professional service that helps you design, implement, and manage cloud solutions in a way that supports your business goals. Cloud consultants work alongside you to understand how your business operates, what challenges you face, and where cloud technology can add value.

This covers your full cloud adoption journey. It includes building a clear cloud strategy, choosing the right cloud computing platform, planning cloud migration, and setting up secure cloud infrastructure. It also includes ongoing management so your cloud environment stays cost efficient, secure, and continuously refined as your business changes.

Good cloud consultancy services are not about selling platforms. They are about using deep knowledge and technical expertise to deliver solutions that make sense for your organisation.

Why is cloud consultancy important for modern businesses?

Cloud technology has huge potential, but without guidance it often leads to confusion and wasted spend. Many companies adopt cloud services without a clear strategy and end up paying for resources they do not use or exposing sensitive information through poor configuration.

Cloud consultancy helps you avoid these mistakes. It brings structure to decision making and ensures your cloud foundation supports your strategic goals, not just short term fixes. It also helps you align cloud transformation with digital transformation across your wider business operations.

With the right cloud consultants, cloud becomes a key component of improving operational efficiency, reducing costs, and accelerating growth. It stops being a technical headache and becomes a business enabler.

How does cloud consultancy support your cloud strategy?

A strong cloud strategy starts with understanding your business objectives. Cloud consulting firms begin by learning how your teams work, how your data flows, and where inefficiencies exist. This allows them to identify opportunities where cloud solutions can improve performance or cut costs.

Cloud consultancy services then translate those needs into a practical plan. This includes choosing between platforms like Microsoft Azure or Google Cloud, deciding how cloud computing fits your operations, and setting clear milestones for your cloud journey.

The strategy is not static. It is continuously refined as your business evolves, ensuring cloud usage stays aligned with business value.

What role do cloud consultants play during cloud migration?

Cloud migration is one of the most critical stages of the cloud adoption journey. Done poorly, it leads to downtime, data loss, or security issues. Cloud computing consultants plan migration carefully to reduce risk and disruption.

They assess your existing infrastructure, applications, and data. They decide what should move, what should stay, and what should be redesigned. This ensures your cloud environment is scalable, resilient, and cost efficient from day one.

Cloud consultants also work closely with your internal teams during migration. This collaboration helps accelerate time to value while keeping staff confident and informed.

How does cloud consultancy improve cloud security and data protection?

Cloud security is often misunderstood. Many breaches happen not because the cloud is insecure, but because it is poorly configured. Cloud consultancy services focus heavily on security as a core part of the solution.

This includes designing secure cloud infrastructure, applying access controls, encrypting sensitive information, and aligning with data protection requirements. Cloud consultants also help you build processes that keep security strong as your cloud environment grows.

Enhanced security protects your data, your customers, and your reputation. It also gives you confidence to adopt advanced technologies like artificial intelligence and gen AI without unnecessary risk.

How do cloud consultancy services help control costs and improve efficiency?

Cloud is often seen as cost saving by default, but without oversight it can become expensive. Cloud consultancy services help you understand cloud usage and ensure resources match real demand.

Consultants review how your cloud services are used and identify areas where you can reduce costs or improve performance. This might involve resizing infrastructure, automating processes, or redesigning workloads for better efficiency.

The result is a cloud environment that supports business operations while remaining cost efficient and scalable.

How does cloud consultancy support innovation and growth?

Cloud consultancy is not only about stability. It also plays a key role in innovation. A well designed cloud foundation allows you to experiment safely, adopt new technology, and respond faster to market changes.

Cloud consultants help you use cloud computing to accelerate growth, improve customer experiences, and unlock business value from data. This includes supporting edge computing, artificial intelligence, and advanced analytics as part of your wider digital transformation.

By aligning cloud technology with strategic planning, cloud consultancy turns cloud into a platform for long term innovation.

What ongoing management is needed after cloud adoption?

Cloud adoption does not end after migration. Ongoing management is essential to keep your cloud environment secure, efficient, and aligned with business goals.

Cloud consultancy services include monitoring, optimisation, security reviews, and regular strategy updates. This ensures your cloud infrastructure evolves with your business and continues to deliver benefits of cloud over time.

Working alongside experienced consultants gives you peace of mind that your cloud remains a reliable part of your operations.

Why choose Labyrinth Technology for cloud consultancy services?

On the left side of the image is a hand extended to engage a handshake. On the right is a texbox reading "Trust Labyrinth Technology for all your IT needs

Labyrinth Technology keeps cloud consultancy practical and business focused. The aim is simple, make cloud work for your business, not the other way around.

As an IT support provider, Labyrinth Technology works alongside you to understand your business goals, risks, and existing systems before recommending cloud solutions. Advice is clear, realistic, and based on experience.

Security is built into every cloud environment from the start. Sensitive data stays protected, cloud usage stays under control, and costs are managed properly. Support does not stop after migration. Ongoing management keeps your cloud strategy aligned as your business grows.

If you want cloud consulting services that are clear, secure, and focused on real outcomes, Labyrinth Technology is the right partner.

Turning cloud potential into real business outcomes

Cloud consultancy services help you move beyond uncertainty and unlock cloud’s potential in a controlled and practical way. With expert guidance, cloud becomes a tool for improving efficiency, reducing costs, and supporting innovation, not a source of risk or confusion.

If you are planning a cloud migration, reviewing your cloud security, or trying to get more value from your cloud services, Labyrinth Technology can help. Our cloud consulting services are designed to support your business goals with clarity, security, and long term thinking.

Get in touch with our team today to discuss how cloud consultancy can support your business and deliver real, measurable outcomes.

What is Insider Threats: Risks and Prevention Strategies

Understanding what is insider threats is crucial for any SME looking to protect its data and operations. Insider threats happen when current or former employees, contractors, or third-party vendors misuse their legitimate access to steal, leak, or damage sensitive data. These threats can be malicious, negligent, or accidental, and they’re often harder to detect than external attacks. Effective prevention relies on layered security controls, continuous monitoring, user behaviour analysis, and strong security awareness training. At Labyrinth Technology, we help businesses identify and prevent insider threats through managed security services, access management, and tailored cybersecurity strategies that protect your data and keep your operations secure.


What is Insider Threats?

Insider threats refer to security risks that come from within your organisation. In simple terms, it’s when someone with legitimate access, like an employee, contractor, or business partner, uses that access to harm your business, intentionally or accidentally.

Not all insider threats come from malicious insiders looking for financial gain or revenge. Some arise from negligent insiders who mishandle confidential data or fall for phishing scams. Others stem from human error, like sending sensitive information to the wrong person or using weak passwords that expose login credentials.

An insider threat can involve stealing intellectual property, leaking customer information, downloading malware onto the organisation’s network, or sharing trade secrets with a competitor or foreign government. Because these individuals already have insider access, their actions often go unnoticed until the damage is done.

Nearly a quarter of UK SMEs surveyed believe that employees will steal sensitive or proprietary data for profit or competitive advantage, while 35% believe negligent insiders are a rising risk.


What are the Types of Insider Threats?

On the right side, there is a man wearing a blue navy sweater and glasses looking confused at a computer screen. He appears to be trying to type something on a PC keyboard. On the left side is a textbox reading "Trouble with tech? We've got it covered! Expert IT support."

Insider threats generally fall into three main categories: malicious, negligent, and accidental.

Malicious insider threats come from individuals who deliberately exploit their access for personal or financial gain. They may steal intellectual property, leak confidential information, or sabotage business operations. These insider attacks often involve former employees or those with privileged access who still have valid credentials.

Negligent insider threats are the result of carelessness. An employee might ignore security policies, use personal devices on the organisation’s internal network, or fall for social engineering techniques that give threat actors remote access to systems.

Finally, accidental insider threats happen when well-meaning staff make mistakes, such as misconfiguring security controls or emailing confidential data to the wrong recipient. Though there’s no malicious intent, the outcome can still be a serious data breach.

Regardless of type, insider threats can disrupt business operations, damage reputation, and result in financial loss or regulatory penalties.


Why do Insider Threats Matter to SMEs?

Many small and medium-sized businesses assume that insider threats only affect large corporations with thousands of employees. Unfortunately, that’s far from the truth. SMEs are often more exposed because they have fewer dedicated security professionals and weaker access management controls.

A single insider attack can lead to severe consequences: loss of customer data, intellectual property theft, or even a complete halt in operations. Since insiders already have legitimate access to critical assets, they can bypass many security systems designed to stop external threats.

SMEs also tend to rely on third-party vendors and business partners, which increases risk further. A compromised supplier or contractor can easily become an entry point for an insider threat within your supply chain.

Protecting your organisation means thinking beyond firewalls and antivirus software. You need a strategy that accounts for human behaviour, access privileges, and early detection of suspicious activity.


How do Insider Threats Manifest in a Business Environment?

Insider threats manifest in many subtle ways. A malicious insider might slowly collect sensitive data over weeks, sending small files outside the company to avoid detection. A negligent employee could click a phishing link that installs malware and allows a threat actor to gain access to your systems.

Sometimes, a former employee still has active user credentials and uses them to steal trade secrets or disrupt operations. Other times, the risk comes from legitimate users who are manipulated through social engineering techniques into giving away privileged access.

Common signs of insider threats include unusual login times, unexplained data downloads, changes in user behaviour, or spikes in network traffic. The problem is that these technical indicators often blend in with normal activity, making them difficult to spot without continuous monitoring.


How Can Organisations Identify These Threats?

Detecting insider threats requires both technology and human awareness. You need visibility into user activity across your network, including who accesses what, when, and how often. Security teams use tools that analyse user behaviour, flagging suspicious patterns such as abnormal file transfers or attempts to access confidential data outside someone’s job role.

However, identifying insider threats isn’t just about monitoring systems, it’s also about fostering a culture of awareness. Employees should feel comfortable reporting suspicious behaviour or potential security incidents without fear of blame. Regular security awareness training helps staff recognise phishing scams, understand the importance of protecting login credentials, and stay alert to the signs of insider risk.

At Labyrinth Technology, we help businesses set up continuous monitoring and user behaviour analytics tools that detect potential insider threats early, before they cause real damage.


What are the Best Practices to Prevent Insider Threats?

Preventing insider threats starts with knowing your people, your data, and your access points. Begin by limiting system access to only those who truly need it. Apply the principle of least privilege, which ensures each employee has just enough access to do their job but no more.

Implement strong access management policies and enforce multi-factor authentication to protect user credentials. Regularly review permissions, especially when employees change roles or leave the company. Make sure any remote access is properly secured and logged.

Training is equally important. Security awareness training should be ongoing, not just a one-off exercise. Teach your team how to identify phishing attempts, handle confidential data safely, and follow the organisation’s security policies.

Technical measures also play a crucial role. Deploy monitoring tools that track user activity and network traffic, alerting you to any suspicious behaviour or signs of data exfiltration. Encrypt sensitive data wherever possible, both in transit and at rest.

Finally, establish a clear incident response plan. Knowing how to respond quickly to an insider attack can reduce the impact of a data breach and protect your reputation.


How Can Labyrinth Technology Help Prevent Insider Threats?

On the left side of the image is a hand extended to engage a handshake. On the right is a texbox reading "Trust Labyrinth Technology for all your IT needs

At Labyrinth Technology, we help businesses take a proactive approach to insider threat management. Our managed security services include continuous monitoring, advanced access controls, and tailored cybersecurity frameworks that reduce your exposure to internal threats.

We assess your organisation’s network for vulnerabilities, implement robust security policies, and deploy monitoring tools that detect unusual user behaviour. Our team also supports you with practical guidance on employee training, privileged access management, and data protection.

We understand that not all insider threats are malicious. Some come from employee error or a lack of awareness. That’s why our approach combines both technology and education to protect your critical assets and prevent data breaches before they occur.

By partnering with Labyrinth Technology, you gain more than an outsourced IT team, you gain a trusted security partner dedicated to protecting your business and keeping your data safe.


What Should You Do Next?

Insider threats are a growing concern for every business, especially as hybrid work and remote access become the norm. Whether it’s a negligent insider, a malicious actor, or simple human error, these risks can cause serious harm to your organisation.

Understanding how to identify, detect, and prevent insider threats is the first step. The next is putting the right systems and processes in place.

If you want expert help to strengthen your defences, protect your sensitive information, and stop insider threats before they disrupt your business operations, get in touch with Labyrinth Technology today.

Kido Cyber Attack: What SMEs Can Learn

The Kido cyber attack saw hackers steal personal data of more than 8,000 children from a UK nursery chain. A ransomware group called Radiant threatened to publish sensitive information to pressure the company into paying. This case shows the growing risk of ransomware attacks on schools and nurseries, the vulnerability of third-party systems, and the lasting damage of a data breach involving children. For SMEs, the lesson is clear: robust cyber security and active monitoring are essential. At Labyrinth Technology, we protect London businesses with outsourced IT support, tailored security solutions, and practical defences against ransomware.


The Kido cyber attack

When news broke of the Kido nursery hack, it made headlines not just in the UK but worldwide. A nursery chain, trusted with the most personal details of young children and their families, had been targeted by cyber criminals. Sensitive information was stolen, parents were threatened, and the reputation of the company was shaken overnight.

It is one of the most disturbing examples of how far ransomware groups will go. And for small and medium-sized businesses, it is a reminder that cyber attacks no longer stop at banks or tech firms. If a nursery can be breached, so can any organisation that holds valuable data.


What happened in the Kido cyber attack?

On the right side, there is a man wearing a blue navy sweater and glasses looking confused at a computer screen. He appears to be trying to type something on a PC keyboard. On the left side is a textbox reading "Trouble with tech? We've got it covered! Expert IT support."

Last week, a ransomware group called Radiant claimed responsibility for breaching Kido International, a nursery chain with sites in London and beyond. They said they had stolen records of around 8,000 children.

To prove it, they posted profiles of ten children on a leak site, showing names, photos, home addresses, dates of birth, and even safeguarding notes. Parents were later contacted directly in an attempt to force pressure on the nursery.

Although Radiant later claimed they deleted the data after massive media coverage and public backlash, trust was already lost. Investigations suggested weaknesses in third-party systems were the likely entry point, a common issue in many SME data breaches.


What does the Kido ransomware attack mean for SMEs?

The attack on Kido shows that cyber criminals targeting education and childcare providers are prepared to exploit sensitive data for profit. For SMEs, the message is clear. Hackers do not discriminate based on company size or sector. They go after whoever appears vulnerable.

This means that your business, no matter how small, is a potential target. If you hold personal or financial information, you need the same level of vigilance as larger companies. A data breach can bring fines, lawsuits, and reputational damage that some SMEs will not survive.

Reliance on third-party suppliers is another weak link. Whether it is a childcare management platform, payroll system, or booking tool, an attack on your supplier can put your business at risk. Supplier vetting and strong contracts are just as important as protecting your own systems.


What was the outcome of the Kido nursery hack?

The outcome has been serious. Families are angry, regulators are watching closely, and Kido’s reputation has been badly harmed. Even though the hackers claimed to remove the leaked child profiles, there is no way to guarantee those files are gone forever.

This is a key lesson for businesses. Once sensitive data is stolen, it is out of your control. Criminals may resell it or use it years later. Paying a ransom rarely means safety. Prevention must always be the priority.


How can SMEs protect against a ransomware attack?

Protecting your business from a cyber attack requires more than a firewall. You need a layered approach. Multi-factor authentication should be standard. Backups need to be frequent, secure, and tested. Software updates must be applied quickly to close off vulnerabilities.

You also need people on your side. Most attacks begin with phishing emails, so staff training is essential. Teach your team to spot suspicious links and report them.

Monitoring systems can give you visibility. If you can detect unusual activity, you have a chance to stop an attack before it escalates. And every SME should have an incident response plan. A written, rehearsed strategy can make the difference between swift recovery and total chaos.


How Labyrinth Technology helps SMEs stay secure

On the left side of the image is a hand extended to engage a handshake. On the right is a texbox reading "Trust Labyrinth Technology for all your IT needs

At Labyrinth Technology, we provide outsourced IT support in London with security at the core. We know SMEs face the same threats as larger companies but without the same resources. That’s why we focus on practical, affordable measures that work.

We build layered protection into your systems, monitor activity in real time, patch vulnerabilities before they are exploited, and back up your data securely and make sure recovery is possible when you need it most.

We also go beyond the technology and train your staff to recognise risks and work with you to strengthen your supply chain security. If an incident does occur, our team acts fast to contain and resolve it.

Most importantly, we aim to stop you ever becoming the next victim of a ransomware group like Radiant.


Why the Kido cyber attack matters beyond one nursery

The Kido data breach is more than a nursery story. It is proof that cyber criminals are willing to go to shocking lengths. If nurseries are on the target list, every SME is too.

For parents, the idea of their child’s data being traded online is devastating. For business owners, the equivalent is the loss of customer trust, financial penalties, and public shame. The message could not be clearer: protect your data before someone else takes it.


Lessons from the Kido cyber attack

The Kido nursery hack is one of the most unsettling breaches in recent memory. It exposed thousands of children’s personal details, involved direct threats to parents, and shook trust in a respected childcare provider.

For SMEs, it should be a wake-up call. Protect your systems. Review your suppliers. Train your staff. Back up your data. Monitor activity. And make sure you have a partner you can rely on.

At Labyrinth Technology, that’s what we deliver. We keep your business resilient, so you never become the next name in a cyber criminal’s ransom note. Get in touch today!

Kering Cyber Attack and Data Breach: Lessons for SMEs

Kering Cyber Attack and Data Breach: In June 2025, luxury group Kering confirmed a cyber attack that exposed limited customer data, including names, contact details, and purchase amounts. The incident, claimed by hacker group ShinyHunters, reportedly affected over 7 million email addresses. While no payment data was taken, the breach highlights how personal information can fuel phishing and fraud. For SMEs, the lesson is clear: strong backups, multi-factor authentication (MFA), regular patching, staff training, and clear incident response plans are essential for resilience.


What Happened at Kering?

Kering, the parent company of brands like Gucci, Balenciaga, and Alexander McQueen, confirmed it had suffered a cyber incident. Attackers gained unauthorised access to customer information. Kering said no financial data was involved, but names, emails, phone numbers, postal addresses, and total spend amounts were affected.

Hacking group ShinyHunters claimed responsibility. They told reporters the breach involved 7.4 million email addresses, although Kering has not confirmed the number. By September, media outlets were reporting on leaked samples, showing how far the data had spread.

The key point is this: the damage didn’t require stolen credit cards. Contact details and spend profiles alone are enough for cybercriminals to launch convincing phishing campaigns.


Why Cyberattacks Don’t Stay in IT

It is tempting to think of data breaches as a problem for “the IT team.” The Kering Cyber Attack and Data Breach shows that’s not true. Once sensitive information is exposed, the impact runs through the entire business.

Customers lose trust. High-value clients may be targeted with tailored scams. Regulators take an interest. Reputational damage lingers.

For SMEs, the same principle applies. If your customer list is exposed, attackers will use it to send phishing emails, impersonate your brand, and exploit your reputation. A breach is not just about data, it is about your operations, your sales, and your future growth.


Cyber Security Best Practices for Businesses

On the right side, there is a man wearing a blue navy sweater and glasses looking confused at a computer screen. He appears to be trying to type something on a PC keyboard. On the left side is a textbox reading "Trouble with tech? We've got it covered! Expert IT support."

The Kering case highlights simple but powerful lessons that SMEs can act on today.

Backups and Recovery Planning

Keep tested backups of critical systems. Store at least one offline, beyond the reach of ransomware. Test restores often. A backup is only useful if it works when you need it.

Multi-Factor Authentication and Access Control

MFA is essential. It makes stolen passwords far less useful. Review admin accounts and cut down access where possible. The fewer privileged accounts you have, the smaller your risk surface.

Regular Patching and Updates

Attackers often exploit weaknesses that already have a fix. Apply updates for your operating systems, applications, and security tools. Regular patching is one of the cheapest and most effective defences you can deploy.

Monitoring and Detection

Prevention is never perfect. Tools like endpoint detection can help you spot suspicious behaviour before it spreads. Even basic monitoring of logins, email forwarding, or unusual file access can give you early warning.

Staff Awareness and Training

In the Kering incident, leaked contact details could be used for phishing. Staff need to recognise suspicious messages, fake invoices, or refund requests. With training, your people go from being a risk to being part of your defence.

Incident Response and Communication Plans

When something goes wrong, clarity saves time. Write down who shuts down systems, who informs staff and customers, and who deals with regulators. A short, practical incident response plan helps you recover faster and with less confusion.


The Wider Business Impact of Cyber Incidents

The Kering Cyber Attack and Data Breach proves that a breach doesn’t need to involve stolen credit cards to be costly. Exposure of personal data creates reputational damage, legal obligations, and targeted fraud risks.

For SMEs, the stakes are just as high. Ask yourself: if your client database leaked, how would you explain it to customers? Could you still trade confidently while dealing with regulatory investigations or public questions?

Cyber incidents don’t just hit IT. They hit your ability to operate.


Why Every Business Is a Target

You might think criminals only bother with global brands like Kering. In reality, small and medium-sized businesses are often easier prey. You may not have an internal security team. You may not patch every system on time. That makes you an attractive target.

Hackers look for weak links, not big names. If your defences are thin, you’re on their radar.


How Labyrinth Technology Can Help

On the left side of the image is a hand extended to engage a handshake. On the right is a texbox reading "Trust Labyrinth Technology for all your IT needs

At Labyrinth, we work with SMEs across London to build resilience against exactly these risks. Our role is to make cyber security practical, not complicated.

We help you put the basics in place: strong MFA, regular patching, secure backups, and clear incident response plans. We also support your people with training, so phishing emails and social engineering attempts don’t catch them out.

Because even with best practice, incidents can still happen, we guide you in setting up monitoring and recovery that fits your budget. That way, if you do face a breach or ransomware attack, you can get back on your feet quickly.

Cyber security isn’t about endless tools or big spending. It is about making sure your business can keep running when things go wrong. That’s where we step in.


Cyber Security as Business Continuity

The Kering Cyber Attack and Data Breach is a warning to businesses everywhere. It shows that cyber incidents are not just about stolen data, they are about continuity, resilience, and reputation.

By acting now with tested backups, enforced MFA, regular patching, real monitoring, staff training, and a written response plan, you protect more than just information. You protect your ability to serve customers, pay staff, and grow your business.

At Labyrinth Technology, we help SMEs build that resilience. Don’t wait for an attack to expose the gaps in your defences. Get in touch today.

Why Are Small Businesses Struggling with Telecoms Costs?

Telecoms should be straightforward. You sign a contract, pay a fixed amount, and get a service that supports your business. But for many small businesses in the UK, that’s no longer the case. Telecoms costs are fast becoming a hidden expense that’s draining budgets, increasing stress, and tying businesses into contracts they never meant to sign.

If you’re confused by your telecom bills, locked into a long contract, or paying over the odds for basic services, you’re not alone. And you don’t have to put up with it.

We’ll break down what’s really happening, why so many small businesses are struggling, and how Labyrinth can help you take back control of your telecoms and IT support.

What Do We Mean by Telecommunications?

Telecommunications refers to the services and equipment your business uses to communicate. This includes phone systems, broadband, mobile contracts, and related software or hardware. For most small businesses, having reliable telecoms is essential. It keeps you connected to your clients, your team, and the services you rely on.

But while the technology has improved, the contracts behind it have become more complex. A simple monthly cost can quickly become a long-term financial burden if you don’t fully understand the contract terms.

Why Telecoms Costs Have Become a Problem for Small Businesses

A recent investigation by the BBC revealed that thousands of small businesses across the UK are being charged inflated telecom prices through lengthy finance deals. These deals often involve renting phones or equipment at a price that far exceeds their value, and many business owners say they weren’t fully aware of what they were signing up for.

One example is Gary Pride, who runs a small graphic design business in Bradford. He’s now paying over £54,000 to rent just five phones and some basic software. The stress of these payments has affected his health and nearly pushed his business to the brink.

Mr Pride, like many others, received an initial offer with a low monthly fee. This followed by a steep increase after a two-year “introductory period”. When the bills soared, he felt he had no choice but to renew. This added more years and more debt to the original agreement.

These contracts often involve third-party finance companies, and many small business owners say the sales pitch didn’t match the actual contract. Some were rushed into signing, weren’t told about extra charges, or were encouraged to agree to upgrades that only made the situation worse.

Experts told the BBC that some companies were charging “outrageous” prices for these systems, selling basic phone services at many times the industry standard. They also charged customers for features like call logs and maintenance, even though other providers often include these services as standard.

To make matters worse, business contracts don’t come with the same protections as consumer ones. Without a cooling-off period, many businesses remain tied in for five to seven years, with no affordable way to exit early.

What Labyrinth Can Do to Help

At Labyrinth Technology, we work with small and medium-sized businesses across London and beyond, helping them take control of their telecom and IT services. We’ve seen these problems first-hand, and we know how damaging they can be, not just financially, but emotionally too.

Here’s how we help.

At Labyrinth, we start by assessing your current telecom setup in detail. We review your contracts to spot any hidden fees or confusing terms. Many small businesses don’t realise they’re tied into costly leasing deals or end up with duplicate contracts through “upgrades.” We help you understand exactly what you’re paying for and where you might be overpaying.

Next, we recommend smarter telecom options tailored to your business. Using our expertise with VoIP phone systems and trusted providers like 8×8, we deliver solutions that offer clear, transparent pricing and the flexibility you need. Additionally, we design a cloud-based phone system or upgrade your current setup to deliver the best fit without unnecessary costs.

We integrate your telecom services into your wider IT strategy. We set budgets that work for you, monitor contract timelines, and help prevent sudden price hikes. On top of that, we provide ongoing support and maintenance, so you get reliable service and don’t have to worry about day-to-day telecom issues.

Our goal is to give you peace of mind and control over your telecom expenses. With the right advice and modern, reliable technology like Labyrinth’s VoIP solutions, you can stop wasting money and focus on growing your business, not stressing over your phone bill.

Moving Forward

It’s clear the telecoms industry still has work to do. Regulators like Ofcom are starting to take notice, and new rules on pricing transparency are coming in 2025. But until then, small businesses need to be proactive and aware of their telecoms costs.

If you’re worried about your telecoms costs, or just want someone to take a proper look at your setup, get in touch. At Labyrinth, we offer honest advice and real solutions. Whether you’re based in London or further afield, we’re here to help.

Telecoms should support your business, not hold it back. Let us show you how.