Focus Tech Insider – August

This month, it’s all about what’s hiding in plain sight

Not always the big, obvious stuff.

Sometimes it’s smaller than that. An AI tool nobody signed off. A forgotten login. Someone on the phone claiming to be IT Support who isn’t.

This month we’re looking at how cyber attacks usually start smaller than you’d think, why so many businesses have AI tools running that nobody’s approved, and a warning about fake IT Support callers. We’ve also got round two of the Focus Tech Quiz, and a quick game to see if you can actually spot AI-written text.

Contents:

The threats hiding in the tools you use every day

How do you imagine a cyber attack happening?

A skilled hacker, breaking through layers of security no one else could crack?

The reality is usually far less dramatic.

Most breaches start with something small. A gap nobody thought to check, sitting there quietly until someone finds it.

This is where the danger usually starts.

Forgotten accounts are a good example.

A login that was never removed when someone left. A laptop that missed an update. A setting switched off months ago and never switched back on. None of it looks like a threat on its own, but it’s exactly what attackers go looking for.

Logins work the same way.

One of the biggest shifts in cyber security right now is criminals targeting usernames and passwords first, rather than systems. Once they’re in, they look like a normal user logging in, which makes them much harder to spot. Some attacks spread within hours of the first breach.

Everyday tools are another common one.

Attackers increasingly rely on what’s called living off the land, using legitimate tools already built into Windows and Microsoft 365 to carry out the attack. Because IT teams use those same tools every day, suspicious activity can blend straight into the background.

Artificial intelligence is likely to speed all of this up. AI tools can help criminals spot weaknesses faster, automate attacks, and adapt more quickly than before.

But the most effective protection is still the basics, done properly. Strong passwords, multi-factor authentication, regular updates, controlled access, and staff who know what to look for remain some of the strongest defences you can have.

If you’d like a hand spotting and closing the small gaps before someone else finds them, get in touch.

It's happening, whether you like it or not

AI tools are becoming a normal part of the working day.

Someone uses a chatbot to tidy up a report. Someone else asks it to summarise meeting notes. A team member installs an AI browser extension because it helps them work faster.

Most of this happens with good intentions. But plenty of businesses have no visibility of it at all.

This is what’s known as shadow AI. Staff using AI tools that haven’t been approved, reviewed, or managed by the business.

In some ways it’s just like shadow IT, where people quietly bring in their own software without telling anyone. The difference is that AI tools interact with your information in deeper ways. Someone might paste a confidential document into a public chatbot, connect an AI assistant to their inbox, or let an AI tool access files and calendars without really knowing what happens to that data afterwards.

None of this comes from bad intentions. These tools genuinely save time and cut down on admin. That’s exactly why banning them outright rarely works. If a tool genuinely helps someone do their job, they’ll keep using it, just more quietly, and that’s when a business loses visibility altogether.

The better approach is accepting that AI is already part of how people work, then guiding your team towards safer, approved options, with a person still checking what actually gets sent, saved, or shared.

If your business runs on Microsoft 365, tools like Copilot are a safer route, since they sit inside your existing permissions and security controls. It doesn’t remove the risk completely, but it gives you far better visibility over how AI is actually being used.

Whatever tools your team has picked up, the one thing worth avoiding is ignoring it altogether.

If you’d like a clearer picture of how AI is being used across your business, get in touch.

DID YOU KNOW...

That might not really be IT Support

The FBI has warned businesses about a cyber crime group posing as IT Support staff.

In some cases, attackers have reportedly turned up in person after first calling ahead. They pose as a technician fixing a problem, then quietly copy files onto an external drive or install malware while nobody’s looking.

Staff awareness and a clear process for checking who’s actually meant to be on site matter just as much as any technical security control.

New to Microsoft

Microsoft may soon quarantine infected devices automatically

A new feature being tested in Microsoft Defender for Endpoint can automatically isolate a compromised device before an attack has the chance to spread across the network.

If something suspicious is detected, the affected device gets cut off from the rest of the business, while staying connected to Microsoft’s security systems so it can still be investigated.

The aim is simple. Slow attackers down fast, and limit the damage before it spreads.

Technology Update

Google’s biggest search overhaul in 25 years

Google is giving Search its biggest shake up in more than 25 years, and unsurprisingly, AI is at the centre of it.

The search box is being redesigned to handle longer, more conversational questions, along with AI powered suggestions and image based search.

Google says traditional website links aren’t going anywhere, but AI generated summaries are expected to play a much bigger part in what people see first.

Round two: the Focus Tech Quiz returns

Last month’s quiz went down well, so here’s round two. Five quick questions, still no prizes, still just bragging rights.

Focus Tech Quiz — August 2026

Focus Tech Quiz — August 2026

Round two: how many can you get right?

Question 1 of 5

Next question

Focus Tech Quiz — Results

0

out of 5

Try again
Get in touch

Spot the AI slop

One quick game before we let you go.

Two bits of text below. One was written by a person. One was written by AI. Have a guess which is which (no cheating by asking your own AI to check).

Spot the AI Slop — August 2026

Focus Newsletter — August 2026

Spot the AI slop

Option A

"In today's fast-paced digital landscape, businesses must leverage innovative solutions to stay ahead of the curve and maximise operational efficiency."

Option B

"Honestly, we've fixed that printer three times this month. Someone's just going to have to replace it."

Option A is the AI one.

If you spotted it in under two seconds, congratulations, you've just identified your first bit of "AI slop", officially Merriam-Webster's word of the year. It's everywhere at the moment, and once you notice it, you can't stop noticing it.

Try again

FAQs

Are smaller businesses really targeted by hackers?

Yes, more than most owners think. Most attacks are automated and look for whoever’s easiest to get into, regardless of size.

Short, regular reminders beat one big annual session every time. People remember guidance that fits into their actual day, not a slide deck they saw once in January.

If you ever have visitors, yes. It stops someone accidentally landing on company devices, files, printers, or anything else sensitive on the network.

That's this month wrapped up

Plenty of AI news this month, but the theme underneath most of it is the same. The boring basics, checked properly, still do most of the heavy lifting.

If anything in this raises a question about your own setup, we’re always happy to have a straightforward conversation.