# Woodruff Training > Cyber and AI awareness training, business continuity plans and tabletop disaster exercises for small businesses. Onsite in West Sussex, live online UK-wide. Everything below is the complete public content of https://www.woodrufftraining.com, generated at build time. Last built 2026-08-15. ## About the business Woodruff Training is based in West Sussex and works across the South Coast of England and remotely UK-wide. Your People Are Your Best Firewall. ## Services ### Training & Awareness Turn your team into the part of your defences that works. - Live staff awareness workshops - Annual refresher training - Onboarding training for new starters ### AI Adoption & Safe Use Put AI to work in your business without opening a new security hole. - Finding where AI genuinely helps your workflow - Choosing reputable AI tools you can trust - Staff training on using AI safely and sensibly - Keeping sensitive data out of AI tools ### Rollout & Hardening Close the obvious gaps and get ready for the standards clients ask about. - Multi-factor authentication (MFA) rollout - Password manager deployment - Domain & email exposure checks - Third-party & SaaS software audits - Cyber Essentials readiness support ### Continuity & Resilience Decide what you would do while everything is still working. - Business continuity plans, written with you - Tabletop disaster exercises - Incident response roles and contacts - Annual plan reviews and re-tests ## Courses Practical, plain-English courses that upskill your team on cyber security and safe AI use. Delivered onsite across West Sussex, live online UK-wide, or self-paced through the learning portal. Every course is built around a real small business, not an enterprise. Every course ends with a certificate of completion for each person, issued automatically and recorded on the portal, so you have evidence to show an insurer, a client or an auditor. ### Cyber Security Awareness Onsite or live online. 90 minutes. For All staff. The core session: how attacks actually happen, and the everyday habits that stop them. - Spotting phishing and scam messages - Strong passwords and password managers - Safe handling of data and devices - What to do when something looks wrong Outcome: Staff who can spot and report the most common attacks before they cost you anything. ### Using AI Safely at Work Onsite or live online. 60 to 90 minutes. For All staff and managers. Get the benefits of AI tools without leaking data or trusting the wrong answer. - Where AI genuinely helps, and where it does not - Choosing reputable tools you can trust - Keeping confidential and personal data out of AI - Checking AI output before you rely on it Outcome: A team that uses AI confidently, with a simple acceptable-use approach to follow. ### Phishing & Social Engineering Onsite or live online. 60 minutes. For All staff. A closer look at the tricks attackers use, worked through with real examples staff will recognise. - Email, text and phone-based scams - Invoice and payment fraud - Red flags and verification habits - Reporting quickly and without blame Outcome: Staff who can pick apart a convincing message, and know to report it quickly. ### Managers & Owners: Building a Security Culture Onsite or live online. 60 minutes. For Owners and managers. Practical steps to lead on security, meet client and insurer expectations, and keep it going. - Cyber Essentials, in plain English - The policies your business actually needs - MFA, backups and the basics that matter most - Responding calmly when something goes wrong Outcome: A clear, prioritised action list sized to your business and budget. ### AI Adoption for Decision Makers (free) Online, self-paced. Short modules. For Owners, managers & decision makers. A practical grounding for leaders deciding where AI fits, what it risks, and how to roll it out responsibly. - Spotting where AI adds real value in your business - The risks to weigh: data, accuracy, cost and compliance - Choosing tools and setting an acceptable-use policy - Rolling AI out to your team with confidence Outcome: A clear, informed plan for adopting AI safely, with a policy your team can follow. Your online learning portal: A self-paced portal where your team works through short courses on using AI safely in your business and on cyber security awareness, in their own time. The courses are not off-the-shelf. Every one is written and built in house, so the content stays practical, current and pitched at a real small business. Perfect for onboarding new starters, with completion tracked and certificates issued automatically. ## Services in detail ### Bespoke courses for your organisation From £1,950. Per course, including the first year of hosting on the portal. Takes: Four to six weeks from brief to launch. For: Organisations whose systems, sector or regulator do not fit an off-the-shelf course. Staff can tell when training was written for somebody else. Generic awareness courses use screenshots of software nobody here uses and scenarios that could not happen in this building, and people switch off within two slides. The content might be correct, but nobody remembers it on a Tuesday morning when the real email arrives. A bespoke course fixes that by using your systems, your terminology and the situations your people genuinely run into. We write it, build it and host it on our learning portal, so your team works through it in their own time and you get the completion records without chasing anybody. - **Work out what it actually needs to cover**: A short discovery session: which systems your staff use every day, what data they handle, what has gone wrong before or nearly gone wrong, and what any client, insurer or regulator has asked you to demonstrate. This is also where we agree whether the course is about cyber security, safe AI use, or both. - **Write it around your business**: We script it in plain English, using your tools and your scenarios rather than stock examples. You see and approve the script before anything gets built, because changing a sentence at that stage costs nothing and changing it afterwards does not. - **Build it on the portal**: Short modules that fit in a coffee break, with knowledge checks along the way and a certificate at the end. It works on a phone as well as a desktop, so people who are rarely at a computer can still do it. - **Launch it, then keep it current**: We enrol your team, set new starters to be assigned it automatically, and show whoever manages it how to see who has finished. When you change a system or a new risk turns up, we update the course rather than leaving it to go stale. What you get: A course written specifically for your organisation, not a template with your logo dropped in; Modules on cyber security, safe AI use, or a mix of the two; Knowledge checks and a certificate issued automatically on completion; Completion tracking you can show an insurer, a client or an auditor; New starters enrolled automatically, so onboarding looks after itself; Content updated as your systems and your risks change. When you do not need this: Most small businesses do not. Our standard courses cover the great majority of what a team needs, and at a fraction of the price. This is worth paying for when something about your situation is genuinely unusual: software nobody else uses, a regulator with specific expectations, an incident you need everyone to learn from properly, or an AI rollout with rules particular to your business. If a standard course would do the job, we will tell you that on the first call rather than sell you this. ### Business continuity planning From £850. Half-day workshop, the written plan, and a review a year later. Takes: Two to three weeks from workshop to finished plan. For: Businesses asked for a plan by a client, an insurer or a tender, and anyone whose honest answer to "what would we do?" is a shrug. Most small businesses have a plan of sorts. It lives in the owner’s head, it quietly assumes the owner is available, and it has never been said out loud. That holds up right until the morning it has to, which tends to be the morning the owner is on a plane. A continuity plan is not a binder. It is a short document saying what you cannot afford to lose, how long you could cope without it, who decides, and who to ring. Ours run to a handful of pages, because a plan nobody has read is worth nothing at eight in the morning with the shutters down. - **Work out what actually matters**: Not everything you do: the handful of things that start hurting within days. We put an honest recovery time against each one, which usually turns out to be sooner than it feels, and write down what each depends on. Which system, which supplier, which person, which key. - **The half-day workshop**: Done with the people who would be holding the plan, not just whoever signs the invoice. What could stop us, what we already do about it, and what we would actually do. Most of the value is in the room: this is usually where somebody discovers three people each thought a fourth had the backups. - **Write it down, and keep it short**: You get a plan in plain English: critical activities, recovery times, who can invoke it, the first hour, contacts, what goes in the emergency pack and a log to fill in as things happen. Plus a copy that lives somewhere other than the building it describes. - **Test it, then keep it current**: A plan that has never been rehearsed is a guess. We run it as a tabletop disaster exercise and fix what the exercise breaks, then come back a year later, or sooner if something has actually happened. What you get: A written continuity plan sized for your business, not an enterprise; Critical activities and honest recovery times, agreed by the people who own them; A risk list with what you already do about each, which is usually more than you think; Contacts, emergency pack contents and a decision log, ready to use; A copy stored outside the premises it covers; Evidence for an insurer, a client or a tender question; A review twelve months later, or after anything that actually happens. What a plan will not do: Writing one does not make you resilient. A plan is a decision made calmly in advance, nothing more. It does not get your data back, which is backups you have actually tested restoring, and it does not replace insurance. It also goes stale: the contact list is wrong within a year, every time. We would rather sell you a short plan you use and revisit than a long one that impresses a tender panel and then sits in a drawer. ### Cyber Essentials readiness From £695. Excludes the certification body’s own assessment fee. Takes: Usually two to four weeks, depending on what needs changing. For: Small businesses whose clients, insurers or tender documents have started asking for it. Cyber Essentials is the government-backed scheme, run by IASME on behalf of the NCSC, that more and more clients and insurers expect a supplier to hold. It asks you to have five basic controls in place and to answer honestly about them. Most small businesses are further along than they think, and stuck on the same two or three points. The work is rarely difficult. Knowing which questions are really being asked, and what counts as an acceptable answer, is the part that trips people up. - **Find out where you stand**: We go through your devices, cloud services and working setup, including staff who work from home and anyone using their own phone for work. Scope is what most applications get wrong, so we settle it first. - **A plain list of what needs to change**: You get the gaps written down in order of what matters, with an honest note on which ones you can do yourself and which are worth paying for. - **Close the gaps**: We can roll out multi-factor authentication, sort a password manager, tidy up admin accounts and retire software that no longer gets updates. Or we can point and you can do it. Whichever is cheaper for you. - **Get your answers ready**: We prepare your responses to the self-assessment so the wording matches what the assessor is looking for, and you are not guessing on the day. What you get: A written gap report covering scope and all five controls; A prioritised action list, sized to your business and budget; The technical work done, or clear instructions if you would rather do it; Draft answers to the self-assessment questions; Someone to ring while your application is in progress. What we cannot do: We cannot issue the certificate, and nobody who prepares you can. Cyber Essentials is awarded by a certification body licensed by IASME, who mark your self-assessment independently. We also cannot promise a pass: the answers have to be true, and if something is not in place we will tell you rather than word around it. What we can do is make sure there are no surprises. ### Tabletop disaster exercises From £595. Half a day, onsite across West Sussex or live online. Takes: Two to three hours, plus a short call beforehand. For: Owners, managers, finance and whoever looks after IT, in the same room. A tabletop exercise is a conversation, not a technical test. Everyone sits down, a realistic disaster unfolds, and the group works out what they would do. Nothing is plugged in, nothing is attacked, and nobody needs to be technical. It is the cheapest way to find out that three people each think a fourth has the backups, that the only person who can lock an account is on holiday, or that nobody knows who rings the customers. Those discoveries are uncomfortable in a meeting room and expensive at eight on a Monday morning. Not every disaster is a cyber attack. Fire, flood, a burst pipe upstairs, a key supplier going under and the one person who understands the invoicing being in hospital all stop a business just as effectively, and the response is largely the same set of decisions. - **A short call first**: We pick a scenario that could genuinely happen to you. A ransomware note on the shared drive, no access to the building on a Monday, an invoice paid to a criminal, a supplier that has stopped answering the phone. Generic scenarios get generic answers. - **The session**: The scenario unfolds in stages. New information arrives as you go, the way it does in reality, and the group decides what to do at each point. We facilitate, keep it moving and make sure the quiet people get heard. - **The awkward questions**: Who rings the bank. Who talks to customers. What do we tell staff. When do we notify the ICO. Who decides whether to pay. These are the questions that stall a real response. - **Debrief and write-up**: We finish with what went well and what did not, then send a short written report a few days later while it is still fresh. What you get: A scenario built around your business, not a template; Two to three hours of facilitated discussion; A written report on what worked and where the response stalled; A prioritised action list, usually shorter and cheaper than people expect; A proper test of your continuity plan, or a running start on writing one if you do not have it yet; Something concrete to show an insurer or a client who asks whether you have tested your response. What this is not: It is not a penetration test and not a technical assessment. Nobody attacks your systems and nothing gets broken. If what you want is somebody trying to get in, that is a different piece of work and we will say so. It is also not a substitute for a written continuity plan: an exercise shows you where the gaps are, and something still has to be written down afterwards or the same gaps are there next year. A tabletop tells you about decisions, roles and communication, which is where most small business disruptions actually go wrong. ## Pricing ### Learning Portal: £12 per person, per year Every course, self-paced, for everyone in the business. - All courses, including the free one for decision makers - New courses added at no extra cost - New starters train themselves on day one - Progress tracked and certificates issued automatically - Minimum 10 people ### Portal + Training: £895 up to 30 staff The portal, plus live sessions that make it stick. - A year on the portal for the whole team - Two live sessions, onsite or online - Completion certificates for everyone who attends - A refresher session within 12 months - Cyber Essentials readiness checklist ### Ongoing: From £1,750 a year, 30+ staff Multi-site teams and businesses with clients who ask questions. - Everything above, refreshed through the year - Quarterly refresher sessions on what has changed - Monthly micro-training on the portal - Named point of contact - Annual review with your leadership ### Priced separately - Business continuity plan: From £850. A half-day workshop and a plan short enough to use - Tabletop disaster exercise: From £595. A realistic scenario, walked through with your team - Extra live session: From £295. Any course, for a team already on the portal - Domain & email exposure check: £195. What a criminal can find before they start - Cyber Essentials readiness: From £695. Gap review and the work to close it - AI adoption support: From £750. Where AI helps, plus a policy your team can follow All prices exclude VAT. Onsite delivery is included across West Sussex. Audits and multi-site continuity work are quoted per project, and schools, charities and community groups pay considerably less. ## Frequently asked questions ### Do you only offer training? No. Training is the core, but we also write business continuity plans with you, run tabletop disaster exercises, help your team adopt AI tools safely, roll out MFA and password managers, run domain and email exposure checks, and prepare you for Cyber Essentials. Most clients start with one thing and build from there. ### What is a tabletop disaster exercise? Everyone who would have to deal with a crisis sits down together, a realistic scenario unfolds, and the group works out what they would actually do. Ransomware on the shared drive, no access to the building on a Monday morning, a supplier that has stopped answering the phone. Nothing is plugged in and nobody needs to be technical. It usually takes two to three hours, and it is the cheapest way to find out that three people each thought a fourth had the backups. ### We are quite small. Do we really need a continuity plan? You already have one, it is just unwritten and it assumes you are available. Writing it down matters most for the smallest businesses, because there is nobody spare to work it out on the day. Ours run to a handful of pages rather than forty, and there is a free template on the resources page if you would rather do it yourself. Clients, insurers and tender documents have also started asking to see one. ### Do our staff need to be technical? Not at all. Every session is built for everyday employees and deliberately avoids jargon. If your team can use email, they will follow the training and take something useful away. ### Do you deliver onsite or online? Both. We run in-person sessions across West Sussex and live, interactive sessions online for teams anywhere in the UK. Plenty of clients mix the two: an onsite kick-off, then online refreshers. ### How long does a session take? A core awareness workshop runs around 60 to 90 minutes. Ongoing programmes use much shorter monthly refreshers designed to fit around a normal working day. ### Will this help with Cyber Essentials or our insurance? Staff awareness is a growing requirement for cyber insurance and a sensible step toward Cyber Essentials. We will show you what matters and get you ready, though the formal certificate itself is issued by a licensed certification body, not by us. ### How often should we train? An initial workshop followed by refreshers is far more effective than a one-off. For most small businesses, a session when people join plus quarterly or annual top-ups works well. ## Articles ### AI will answer any question you ask it. That is the risk. Published 2026-08-09. Topics: AI, Business advice. Web version: https://www.woodrufftraining.com/blog/asking-ai-for-business-advice Somewhere between the quote you did not want to pay for and the accountant you did not want to bother at nine on a Sunday evening, there is now a chatbot that will answer anything, instantly, for nothing. Small business owners have noticed. Redundancy questions, contract wording, what a clause in the insurance schedule actually means: it all goes into the same box now. That is not a foolish thing to do. It just needs one piece of judgement that nobody hands you with the tool. ## Confident is not the same as correct An AI tool writes every answer in the same assured tone. It has no sense of the difference between something it has seen a thousand times and something it is more or less guessing at, so the answer about your dismissal process arrives sounding exactly as certain as the answer about how long to boil an egg. Four things go wrong more than owners expect: - **It answers as if you were American.** A great deal of what these tools learned came from the United States. Employment advice that would be perfectly sound in Texas can walk you straight into a tribunal claim here. - **It may be working from an older version of the world.** Thresholds, rates and rules change with each Budget. The tool will quote you the figure it learned without mentioning that it has moved. - **It invents specifics that sound real.** Ask which regulation applies and you can get an official-sounding name with a section number attached to it that does not exist. Lawyers have been caught filing court documents citing cases that were never heard. - **It knows nothing about you.** It does not know one of your staff is on a contract from 2014, that your insurer requires a particular control, or that you took a payment holiday two years ago. It answers the general question, and your question is never the general one. The same applies to technical fixes, which is where we see it most. Somebody cannot receive email from a supplier, asks an AI tool why, and gets a workable instruction to relax a filter or add an allow rule. The email starts arriving. A protection you were relying on is now off, and nobody wrote that down anywhere. ## Where it earns its place None of this is an argument for banning it, any more than it is for [staff using AI day to day](/blog/staff-using-ai-safely). Used properly it saves real money: - **Translating jargon.** Paste in the paragraph of the contract or the insurance schedule you cannot follow and ask what it means in ordinary English. Low risk, and it makes you a better reader of your own paperwork. - **First drafts.** A job advert, a policy, an awkward email to a customer. You were going to rewrite it anyway. - **Preparing for the professional.** Ask it what you should be asking your accountant or solicitor. Turning up with sharp questions is the cheapest way to shorten a billable hour, and almost nobody does it. - **Getting through something long** you would otherwise never read at all. Notice what those have in common. Every one of them uses AI to help you think, and not one of them lets it decide. ## Ask what being wrong would cost That is the whole test, and it takes about two seconds. If a wrong answer costs you an afternoon, go ahead and trust it. If a wrong answer costs you money, someone's job, a client, or a letter from a regulator, then AI is where you start rather than where you stop. Employment, tax, contracts, data protection and anything a regulator oversees all sit firmly in the second group. Worth remembering too: "the AI told me" has never once worked as a defence. HMRC, the ICO and an employment tribunal will hold you responsible for the decision, whatever helped you reach it. The tool takes none of the risk, which is rather the point of it being free. If you would rather your managers made that call consistently, our [free AI course for decision makers](/courses) covers this ground, and we are happy to [talk it through](/#contact). --- ### A client has asked if we have Cyber Essentials. What now? Published 2026-08-02. Topics: Cyber Essentials, Compliance. Web version: https://www.woodrufftraining.com/blog/client-asked-for-cyber-essentials It usually arrives in a tender document, or an email from a client's procurement team, phrased as though you will obviously know what it means. Do you hold Cyber Essentials? For most small businesses the honest answer is no. The second honest answer is that it is more achievable than it sounds. ## What they are actually asking for Cyber Essentials is a government-backed scheme. The NCSC owns it and IASME runs it on their behalf. It asks you to have five basic technical controls in place, and then to answer a questionnaire about them truthfully. A certification body licensed by IASME marks those answers and issues the certificate. Nobody comes to your office. There are two levels, and it is worth pinning down which one you need before you spend anything. The standard certification is that self-assessment. Cyber Essentials Plus covers exactly the same five controls, but somebody from the certification body tests them hands-on, which costs more and takes longer. Ask your client which they mean. Plenty of procurement teams write "Cyber Essentials" when the standard certification would satisfy them perfectly well, and a few are working from a template and have no firm requirement at all. ## The five controls None of it is exotic. - **Firewalls.** Something sensible between your devices and the internet, including for people working from home. - **Secure configuration.** Default passwords changed, software and accounts nobody uses removed, devices that lock themselves. - **Security update management.** Updates applied promptly, and nothing still running that the vendor has stopped supporting. - **User access control.** Everyone on their own account, administrator rights used only for administrator work, and [multi-factor authentication](/blog/mfa-small-business) on your cloud services. - **Malware protection.** Anti-malware kept current, or only allowing applications from an approved list. Most businesses are already further along than they expect. Multi-factor authentication and retiring old software are the two that usually need real work. ## Where applications come unstuck Scope, more than anything else. Before you answer a single question, decide what is being certified: the whole organisation, or a clearly defined part of it. That decision has to account for laptops, phones, staff working from home and every cloud service people log into. It is tempting to quietly leave out the awkward machine in the corner, and that is exactly the thing that unravels later. The other one is answering hopefully. The questionnaire is a declaration you are signing, and "we are getting round to it" is not a yes. If a control is not in place, put it in place and then answer. ## What to do this week Work out roughly where you stand before you commit any money, then get a quote from a certification body and remember their fee sits on top of any help you pay for. It is also worth asking what else comes with certification, because for smaller UK organisations it can include a limited cyber insurance option. Check the current terms rather than assuming, since they change. Being asked is good news, in a roundabout way. It means somebody wants to work with you and has a box that needs ticking. Most small businesses get there in a few weeks rather than a few months. If you want to know where you stand before speaking to anyone, our [free readiness checklist](/cyber-essentials-checklist) covers scope and all five controls in thirty plain-English questions. If it turns up more than you fancy tackling on your own, [that is the work we do](/services/cyber-essentials-readiness). --- ### Why telling staff off makes your security worse Published 2026-07-27. Topics: Staff training, Culture. Web version: https://www.woodrufftraining.com/blog/carrot-not-stick-security-culture The employee who clicks a phishing link is not your biggest problem. The one who clicks it, realises something is wrong, and says nothing for three days is. That gap is where the damage happens, and the way you handle the first mistake decides how long the gap will be next time. ## Fear buys you silence Hardly any owner sets out to run security by telling people off. It creeps in anyway. Someone falls for a convincing email, there is an awkward meeting about it, word gets round the office, and the lesson everybody quietly takes away is that owning up is expensive. So the next person who clicks something odd sits on it. They hope it was nothing, wait to see whether anything happens, then get on with their afternoon. Meanwhile the criminal has a free run: reading the mailbox, learning who pays the invoices, and setting up a rule that hides their own replies from the person whose account it is. Phishing simulations run as a trap do the same damage. Once the results turn into a list of names, staff stop treating the test as practice and start tipping each other off. You end up with a flattering number that tells you nothing about how the team would cope with the real thing. ## Measure reporting, not clicking Click rate is the figure everyone reaches for. Reporting rate is the one worth watching, because it tells you how fast you would hear about a genuine attack, and speed is what limits the damage. A team where a third of people click but everyone reports within ten minutes is in better shape than a team where nobody clicks and nobody speaks up either. Push the reporting number up. The clicking number usually falls on its own once people are paying attention. ## What works instead - Thank people for reporting, out loud, including the false alarms. Someone forwarding a real invoice just in case is doing exactly what you want them to do. - Make reporting take one click. A button in Outlook, or one address everybody knows. If it needs a written explanation, most people will not bother. - Keep individual results private. Share the team's overall figures, and coach anyone who is struggling quietly, without an audience. - Train during work hours and keep sessions short. Asking staff to do security learning in their own evening tells them precisely what you think it is worth. - Go first yourself. When the owner admits they nearly fell for something last month, it stops being a test of competence and becomes a normal part of the job. None of this is soft. A business where people put their hand up early gets an incident closed in an afternoon instead of a fortnight, and the difference shows up in what it costs you. The other half of this is knowing what happens next. We have put that on a one-page [first hour incident card](/resources/first-hour-incident-card.pdf) you can print and keep by the phone. If you cannot fill in the "who to call" lines today, that is worth half an hour of somebody's time this week. If you want a hand building that habit, our [course for managers and owners](/courses) is built around exactly this. [Get in touch](/#contact) and we'll talk it through. --- ### If your website runs WordPress, update it this week Published 2026-07-19. Topics: Websites, Quick wins. Web version: https://www.woodrufftraining.com/blog/wordpress-update-now WordPress runs a large slice of the world's websites, so there is a good chance this affects you. In mid-July 2026, WordPress released an urgent update after researchers found a flaw serious enough that an attacker could take over a website without ever logging in. By the time the fix appeared, criminals were already using it. The good news is that the fix itself is simple. Update WordPress, and the door closes. ## What actually happened WordPress powers a huge share of the world's sites, plenty of them small business ones, from the local plumber to the village shop. The flaw, patched in WordPress version 7.0.2 on 17 July, let an attacker with no password and no account run their own code on a vulnerable site. In plain terms, a stranger could hijack the site: deface it, plant scam pages, redirect your customers, or quietly use it to send spam in your name. The United States cyber agency added the flaw to its list of bugs being actively exploited. That is as clear a signal as you get to patch now rather than later. ## What to do If someone else looks after your website, send them one line: "Please confirm we are on WordPress 7.0.2 or later." That is the whole job. If you manage it yourself: - Log in to your WordPress dashboard and update to the latest version (7.0.2 or newer) today. - Update your plugins and themes while you are there. Out-of-date plugins are the other common way in. - Turn on automatic updates for WordPress itself, so the next urgent fix installs on its own. - Take a fresh backup before you start, and keep taking them regularly. ## Why this keeps happening Websites are software, and software gets flaws. That is normal, and not a reason to panic. What matters is how fast you apply the fixes. A site that updates promptly is a hard target. A site still running last year's version is the one attackers go looking for. If keeping your site patched and backed up is one more job you never quite get to, we can set it up to look after itself. [Ask us to take a look](/#contact) at your current setup. --- ### The best password is no password Published 2026-07-12. Topics: Passwords, MFA, Quick wins. Web version: https://www.woodrufftraining.com/blog/best-password-is-no-password Almost all password advice is damage limitation. Make it long, make it different on every site, and keep it in a password manager. That is sound, and we still recommend it, but it works around the flaw rather than fixing it. A password is a secret you hand over to prove who you are, so anyone who persuades you to hand it over somewhere else now has it too. Passkeys deal with that by getting rid of the secret. ## Why the password rules kept changing The National Cyber Security Centre, the government body that advises UK organisations on security, has spent years undoing password habits that made things worse rather than better. It advises against forcing staff to change their password every 90 days. People respond to that with Summer2025, then Summer2026, and the account ends up weaker. It suggests three random words instead of a jumble of symbols, because length does more work than complexity and people can actually remember it. It is comfortable with password managers, including the one built into your browser, on the grounds that almost anything beats using the same password everywhere. Sensible advice, and worth following. But it is still a password, still typed into a box, and a convincing fake login page still collects it. ## What a passkey actually is When you set up a passkey, your device creates two matched keys. One stays on your phone or laptop and never leaves. The other goes to the website, where it is useless on its own. Signing in means your device proving it holds the private half, which it does once you unlock it with a fingerprint, your face, or the PIN you already use to open the phone. A few things follow from that: - Phishing stops working. Your device checks the web address before it responds, so a lookalike page gets nothing even if the person is completely taken in. - A breach at the supplier costs you little. Attackers walk away with the half of the key that does nothing without your device. - Your fingerprint never leaves your phone. The biometric only unlocks the key sitting on the device. This is the part that worries people most, and it is the part they need not worry about. ## Where to start - Turn on passkeys for your Microsoft 365 or Google Workspace account first. Email resets every other account you own, so it deserves the strongest protection you have. - Add them anywhere else they are offered. Banks, accounting software and the bigger online services are steadily adding support. - Keep multi-factor authentication switched on everywhere else. Most systems will not offer passkeys yet, and MFA remains the [best free thing you can do](/blog/mfa-small-business) for an account. - Work out recovery before you need it. Know how someone gets back in after a lost phone, and make sure more than one person can reach the business accounts. Passwords are not going away this year, and you will run both side by side for a while yet. Start with the accounts that would hurt most to lose, and let the rest follow. If you want an honest read on the passwords in your business today, our [password checker](/password-check) will tell you in a few seconds. [Get in touch](/#contact) if you would like a hand moving a team across. --- ### Your staff are already using AI. Are they doing it safely? Published 2026-07-04. Topics: AI, Data protection, Staff training. Web version: https://www.woodrufftraining.com/blog/staff-using-ai-safely If you have not handed your team an AI tool, some of them are almost certainly using one anyway. A quick draft knocked out by ChatGPT, a spreadsheet tidied up by Copilot, a tricky email reworded in seconds. People reach for these tools because they genuinely make the work quicker, and that is not something to stamp out. The question is not whether your staff use AI. It is what they are typing into it. ## The quiet risk is what goes in Most AI chatbots are run by third parties. When someone pastes text into one, that text leaves your business and lands on a company's servers somewhere else. Usually that is harmless. It stops being harmless the moment the text contains personal or confidential information. Picture the everyday examples: - A member of staff pastes a customer list into an AI tool to "tidy up the formatting". - Someone drops a client contract in and asks for a plain-English summary. - An employee's details, a supplier's bank information, or a list of names and email addresses gets shared to save five minutes. Each of those is personal or commercial data going to an outside company you may never have checked. Some tools, particularly the free consumer versions, may use what people type to improve their systems, depending on the settings. Under UK data protection law, personal data stays your responsibility even when a well-meaning employee is the one who pasted it in. Nobody did anything malicious. That is exactly why it keeps happening. ## Banning it does not work The gut reaction is to forbid AI outright. In practice that just drives it underground. People use it on their phones instead, and you lose any say over how. The businesses that handle this well do the opposite: they accept that AI is useful, then make it safe to use. That comes down to a few simple ground rules everyone can follow: - Never paste customer, staff, or financial data into a public AI tool. If in doubt, leave it out. - Strip out names and identifying details before asking for help with a document. - Use a business-grade version of a tool where you can. Paid and business tiers usually keep your data private and do not train on it, unlike some free ones. - Agree which tools are approved, and only install them from the official source. Lookalike AI apps are a [real scam](/blog/fake-ai-tools-scams). ## Turn shadow use into safe use The aim is not to slow your team down. It is to let them keep the speed AI gives them without the data leak that can come with it. A short, honest conversation and a one-page set of rules gets you most of the way. Training people on what is and is not safe to share gets you the rest. We have written those rules up as an [AI acceptable use policy template](/resources/ai-acceptable-use-policy-template.pdf) you can adopt as your own. It leaves blanks for the tools you approve and the person to tell when something goes in that should not have. Change whatever does not match how you work, then put your name on it. That is exactly what we help small businesses do, so your team can use AI with confidence rather than in secret. If you are not sure what your staff are already pasting into these tools, [let us take a look](/#contact), or see how our [AI adoption and safe use](/#services) support works. --- ### The fake AI tool problem, and how to download safely Published 2026-06-26. Topics: Scams, AI, Quick wins. Web version: https://www.woodrufftraining.com/blog/fake-ai-tools-scams Small businesses are trying out AI tools faster than almost anyone, and criminals have noticed. Across the first four months of 2026, security researchers at Kaspersky counted more than 33,000 attacks that hid malware inside apps pretending to be popular AI services. That is a rise of almost 500% on a year earlier. The fakes look like the real thing. Behind the familiar logo, some quietly install software that steals passwords or hands an attacker a way onto your computer. None of this means you should avoid AI. It means you should be a little careful about where you get it. ## How the scam works The pattern is simple. You search for a well-known AI assistant, a "free" version of a paid tool, or a browser add-on that promises to write your emails for you. One of the results is fake. It might be an app, a download, or a subscription page that takes your card details and gives you nothing useful in return. The worst ones install something harmful at the same time. Criminals do this because they know people trust these names. A logo you recognise lowers your guard, which is exactly the point. The best-known AI tools are impersonated most, precisely because so many people are looking for them. ## Staying safe without missing out A few habits keep you on the right side of this: - Go to the official website directly. Type the address yourself or use a saved bookmark, rather than clicking a search advert or a link someone sent you. - Treat "free premium" offers with suspicion. If a paid tool is suddenly free from some other site, that is a warning sign, not a bargain. - Read the web address carefully before you enter card or login details. Fakes use names that are close but not quite right. - Install browser add-ons only from the official store, and only ones with a genuine track record. - Do not grant an app more access than its job needs. If a note-taking tool asks to read every file on your computer, stop. ## Decide your tools, then tell your team The simplest protection is to choose which AI tools your business actually uses, get them from the official source, and let staff know that is the approved list. When everyone knows what normal looks like, the odd fake stands out a mile. If you would like help choosing tools safely, or training your team to spot the fakes, [that is part of what we do](/#services). [Get in touch](/#contact) for a quick chat. --- ### There is a market for stolen business logins. Stay off it. Published 2026-06-19. Topics: Passwords, Staff training. Web version: https://www.woodrufftraining.com/blog/stolen-logins-for-sale Here is an uncomfortable fact. When criminals break into a business, they often do not use the access themselves. They sell it. There is a working market where one group steals logins and another buys them to launch a scam or a ransomware attack. And small businesses are the bulk of the stock. In one 2026 analysis by Kaspersky, more than half of these "access for sale" listings concerned small and medium organisations. The reassuring part is that you do not need to be a security expert to stay off that list. You need a few habits that make your accounts more trouble than they are worth. ## How your login ends up for sale Usually it is nothing dramatic. A staff member reuses the same password across several sites. One of those sites is breached, the password leaks, and criminals quietly try it everywhere else, including your email and your accounting. Or someone types their details into a convincing fake login page. Either way, a working username and password is now worth money to somebody. ## The habits that keep you off the list - Turn on multi-factor authentication everywhere it is offered. Even if a password leaks, it is not enough on its own. This is the big one, and we wrote a [separate note on it](/blog/mfa-small-business). - Use a password manager so every account has its own long, unique password. Then a leak from one site cannot unlock the others. - Close accounts for people who have left, and old logins nobody uses. Every unused account is a door left unlocked. - Watch for sign-ins from odd places or at odd hours, and act on the alerts your systems send you. ## Find out if you are already exposed Some of your passwords may already be out there from past breaches, and it is worth knowing which. A quick check of your business email addresses against known leaks shows you where to focus first. We run exactly that as a [domain and email exposure check](/#services), and it is often a sobering but genuinely useful place to start. Stay off the list, and most of these attacks never get going. [Get in touch](/#contact) if you would like a hand. --- ### Five phishing red flags every employee should know Published 2026-06-11. Topics: Phishing, Staff training. Web version: https://www.woodrufftraining.com/blog/spotting-phishing-emails Nine times out of ten, an attack on a small business does not start with clever hacking. It starts with an email that looks normal enough for a busy person to click without thinking. The good news is that the same handful of warning signs show up again and again, and once your team knows them, most of these emails get spotted and deleted. ## 1. A sense of urgency "Your account will be closed in 24 hours." "Pay this invoice today to avoid a late fee." Attackers push you to act before you think. A genuine supplier or bank is almost never that dramatic. If an email is rushing you, slow down. ## 2. The address is *almost* right The display name might say your bank, but the real address behind it is something like `security@bank-alerts-uk.com`. On a phone this is easy to miss. Teach staff to press and hold (or hover on a desktop) to see the true sender before trusting anything. ## 3. It asks you to change how you get paid Any email asking to update bank details, redirect a payment, or "confirm" account information deserves a second channel. **Phone the supplier on a number you already have** (never the one in the email) and confirm before moving a penny. This one habit stops most invoice fraud. ## 4. Unexpected attachments or links An invoice you were not expecting. A "delivery" you did not order. A shared document from someone you barely know. When in doubt, don't open it. Check with the person first. ## 5. It just feels slightly off Odd phrasing, a greeting that isn't quite how a colleague speaks, a logo that looks stretched. Trust that instinct. It is usually right, and it costs nothing to double-check. ## Make it a habit, not a one-off Reading a list once does not change behaviour. Short, regular reminders keep these signs fresh, which is exactly what our [awareness training](/#services) is built to do. We have put these five flags on a one-page poster you can [print and pin up in the office](/resources/phishing-red-flags-poster.pdf). There is a blank line at the bottom to write in whoever your staff should report to, which is the detail people forget when it matters. *Want a plain-English session for your team? [Get in touch](/#contact).* --- ### MFA, the best £0 you'll spend on security Published 2026-06-03. Topics: MFA, Quick wins. Web version: https://www.woodrufftraining.com/blog/mfa-small-business If you only do one thing after reading this, make it this: **turn on multi-factor authentication.** It is free on almost every business system you already use, and it stops the single most common way small businesses get breached: someone else logging in with a password that has been guessed, reused, or stolen. ## What MFA actually is MFA (sometimes called two-factor or 2FA) simply means a password is not enough on its own. After the password, the system asks for a second thing, usually a code from an app on your phone, or a tap to approve. Even if a criminal has your password, they cannot get in without that second step. ## Why it matters so much Passwords leak constantly. People reuse the same one across their email, their bank, and a dozen websites, and when any of those sites is breached, that password ends up on a list criminals buy and try everywhere. MFA breaks that chain. Microsoft and others have repeatedly found it blocks the overwhelming majority of these automated account-takeover attempts. ## Where to switch it on first Start with the accounts that would hurt most if someone else got in: - **Email**: the master key. Whoever controls your email can reset the password on everything else. - **Online banking and accounting**: the obvious target. - **Microsoft 365 / Google Workspace**: where your files and staff accounts live. - **Your website and domain host**: so nobody can hijack your address. ## Do it properly A few things make MFA far more effective: 1. Use an **authenticator app** (or a hardware key) rather than SMS text codes where you can. Text messages can be intercepted. 2. Turn it on for **every staff member**, not just the owner. 3. Save the **backup codes** somewhere safe so nobody gets locked out. It really is an afternoon's work for most small teams, and it is one of the highest-value hours you will spend all year. If you would rather someone rolled it out across your team properly, and showed everyone how to use it, that is exactly what our [MFA rollout](/#services) covers. --- ### Invoice and QR-code scams to watch for on the South Coast Published 2026-05-27. Topics: Scams, Local. Web version: https://www.woodrufftraining.com/blog/invoice-and-qr-scams-south-coast Speak to enough small businesses along the South Coast (the cafés, letting agents, trades and small offices between Brighton, Worthing and Portsmouth) and the same handful of scams come up again and again. Two in particular are worth knowing about, because they are cheap for criminals to run and surprisingly effective. > This post describes common, widely reported scam patterns so you can recognise them. It is general guidance, not a report of a specific incident. ## 1. The changed bank details ("invoice redirection") This is the one that costs businesses the most. It usually goes like this: 1. A criminal gets into, or convincingly imitates, a supplier's email. 2. You receive a real-looking invoice, or a note that "our bank details have changed." 3. You pay as normal. The money goes straight to the criminal, and it is very hard to get back. **How to stop it:** treat *any* change of bank details as a red flag. Before paying, call the supplier on a number you already have on file (never the number printed on the new invoice) and confirm the change verbally. Build this into your payment process so it does not depend on one person remembering. ## 2. Fake QR codes ("quishing") QR codes are everywhere now, on parking meters, menus, and payment terminals, and criminals have noticed. The trick is simple: a sticker with a malicious QR code is placed over a genuine one, or sent by email. Scan it and you land on a convincing fake page asking for card or login details. **How to stop it:** - Be wary of QR codes on **stickers**, especially in car parks and on payment machines. Check for anything stuck over the original. - Look at the **web address** the code opens before typing anything. If it is not the official site, close it. - For anything involving payment, **type the address yourself** or use the official app instead of scanning. ## The common thread Both scams work by catching a busy person on autopilot. The defence is not clever technology. It is a small pause and a habit of verifying through a second channel. Sharing this with your team, and practising it, is most of the battle. *We help South Coast businesses build these habits through [staff training](/#services). [Get in touch](/#contact) if you would like a hand.* ---