Author: admin

  • Two-factor authentication: what it is and why every account needs it

    Two-factor authentication: what it is and why every account needs it

    News & Insights

    Two-factor authentication: what it is and why every account needs it

    Security 3 September 2026 4 min read
    A man standing outside an office checking a sign-in approval on his phone

    Overview

    Most break-ins to business accounts do not involve anything clever. Someone gets hold of a password, types it in, and they are in. The password might have been guessed, reused from another site that was breached, or handed over on a fake login page. Two-factor authentication, usually shortened to 2FA, is the one setting that makes a stolen password useless on its own.

    If you have ever had your bank send a code to your phone before letting you log in, you have already used it. This article explains what is happening behind that step, why we treat it as a requirement rather than a preference, and what it takes to get it switched on across a whole business.

    What 2FA actually is

    Logging in normally asks for one thing: something you know, which is your password. Two-factor authentication adds a second thing: something you have, which is usually your phone. To get in, an attacker would need both. Knowing your password is not enough if they do not also have the device sitting in your pocket.

    The second factor most people see is a six-digit code from an authenticator app, or a notification on the phone asking "Is this you?" with an Approve button. Text message codes still exist, but they are the weakest option and we move clients away from them where we can.

    How it works day to day

    In practice it is less disruptive than people expect. You enter your password as usual. On a device you have used before, that is often the end of it. On a new device, a new location or after a set period, you are asked to confirm on your phone. Tap approve, or type in the code, and you are through. The whole thing takes a few seconds and most staff stop noticing it within a week.

    Behind the scenes, the app on your phone and the service you are logging into share a secret that was set up when you first enrolled. The code the app shows changes every 30 seconds and is generated from that secret plus the current time. Nobody else can produce the same code without the phone, and a code that has been used or has expired is worthless.

    If someone is asking you to read out or type in your 2FA code, that is the attack. The code is for you to enter, never to share.

    Why it is not optional any more

    Passwords leak constantly. Large breaches at other companies release millions of email and password pairs, and attackers run those lists against Microsoft 365, Google, Xero and every other business service on the assumption that people reuse passwords. Many do. A phishing email that captures one login can be enough to read a mailbox, redirect a supplier payment or reset the passwords on everything else.

    With 2FA turned on, those attacks stop at the door. Microsoft's own figures put the reduction in account compromise at over 99 percent for accounts with it enabled. Cyber insurers now ask about it before they will quote, and several will decline cover or a claim without it. Industry and government frameworks in New Zealand list it as a baseline control, not an advanced one.

    The other reason it is not optional is that one unprotected account is enough. Security settings that are "mostly on" give a false sense of safety. Attackers do not need the director's login if the accounts inbox or a shared mailbox is still open.

    Where businesses fall short

    In the accounts we review, the pattern is usually the same. 2FA was recommended to staff but not enforced, so some people set it up and others did not. Shared logins for a generic mailbox or a software subscription were left out because nobody was sure whose phone should get the code. Old accounts for people who have left were never closed. And the systems outside Microsoft or Google, such as accounting, payroll, the website host and the domain registrar, were forgotten entirely.

    How New Solutions can help

    Turning 2FA on for yourself takes two minutes. Making sure it is on for every account in the business, and stays on, is the part that takes some organisation. This is work we do for clients as part of managed IT support, and it looks like this:

    Audit. We list every account and service the business uses, including the ones outside your main email platform, and check which have 2FA enforced, which have it available but unused, and which do not support it.

    Enforce rather than encourage. In Microsoft 365 and Google Workspace we set policies that require 2FA for everyone, so a new staff member cannot skip it and an existing one cannot switch it off. Where a service has no way to enforce it, we track it and check it.

    Handle the awkward cases. Shared mailboxes, service accounts and logins for the boardroom TV all need a sensible approach. We sort out who holds the second factor and document it, so nobody is locked out when someone is on leave.

    Roll it out without a bad day. We schedule the change, tell staff what to expect, help anyone who gets stuck and set up backup methods so a lost phone does not become a lost week.

    Keep checking. Accounts get added and people move on. We review regularly so the coverage you had at the start is the coverage you still have a year later.

    If you are not sure whether every account in your business has 2FA enforced, that is the answer. Get in touch and we will run through it with you.

    What our clients say

    “We have found them to be very flexible – they work nights and weekends to fix problems and install upgrades to minimise disruption. They are also proactive and offer solutions to simplify our IT, whilst being mindful of our budget.”

    Elaine Hogg, Reproflex3

    Looking for an IT partner that just gets it?

    No silly questions, just straight up answers.

  • Five phishing red flags your team should know

    Five phishing red flags your team should know

    News & Insights

    Five phishing red flags your team should know

    Security 12 August 2026 4 min read
    A person typing on a laptop showing an email inbox at a meeting room table

    Overview

    Nearly every security incident our team is called into begins the same way: one person, in a hurry, opens an email that looks exactly like the ones they get every day. The technology behind these attacks has improved, and the spelling mistakes we used to rely on as a warning sign have largely disappeared.

    Good filtering stops most of it. What matters is what happens to the small number of messages that get through. Below are the five checks we teach client teams to make, in the order they are quickest to apply.

    1. The request creates urgency

    Payment must be made today. The account will be closed within the hour. The manager is in a meeting and cannot take a call. Urgency is the one feature almost every phishing email shares, because it discourages the pause in which someone would normally check. Treat a deadline in an email as a reason to slow down, not speed up.

    2. The reply address is not the display name

    A display name is free text and can say anything. Expand the sender field and read the full address, then read it again from the right: the domain at the end is the part that cannot be faked. Lookalike domains that swap a letter or add a hyphen are common, and they are much easier to spot when you know to check the last part first.

    3. The link text and the link destination disagree

    Hover over a link before clicking and compare what it says with where it goes. On a phone, press and hold to preview the address. Attachments deserve the same treatment: a document that asks you to click through to a second site to view it is worth a phone call.

    If an email asks you to change bank details, confirm it by phone on a number you already have. Not the number in the email.

    4. It asks for credentials or a code

    No supplier, bank or IT provider needs your password, and none of them will ask for the six-digit code from your authenticator app. If a login page appears after clicking an emailed link, close it and reach the service through a bookmark or by typing the address yourself.

    5. Something about it is slightly off

    A supplier who has never emailed an invoice suddenly does. A colleague writes in a tone they do not usually use. A thread appears to continue a conversation you do not remember having. Staff instincts are accurate more often than they are given credit for, and the cost of asking is a two-minute interruption.

    Make reporting easy

    The single most useful change most businesses can make is giving people one obvious place to send a suspicious email, and thanking them when they do. If reporting feels like admitting a mistake, people delete instead, and you lose the chance to check whether anyone else received the same message.

    If you would like us to review your email security settings or run a short awareness session with your team, get in touch and we will talk through the options.

    What our clients say

    “We have found them to be very flexible – they work nights and weekends to fix problems and install upgrades to minimise disruption. They are also proactive and offer solutions to simplify our IT, whilst being mindful of our budget.”

    Elaine Hogg, Reproflex3

    Looking for an IT partner that just gets it?

    No silly questions, just straight up answers.

  • Building a hardware replacement plan you can budget for

    Building a hardware replacement plan you can budget for

    News & Insights

    Building a hardware replacement plan you can budget for

    Hardware 28 July 2026 5 min read
    A smartphone resting on a stack of two closed laptops on a light wooden desk

    Overview

    Hardware rarely fails at a convenient moment. The laptop that dies is almost always the one belonging to the person mid-way through a deadline, and the replacement then has to be bought at whatever price and specification is available that week.

    A replacement plan removes most of that cost and nearly all of the disruption. It does not need to be complicated. Three pieces of information are enough to build one.

    Start with an accurate list

    Before anything else, you need to know what you own, how old it is and who uses it. Most businesses are surprised by this list. Machines that were retired years ago are still on the network, and a handful of devices turn out to be well past the point where a warranty claim is possible.

    We maintain this list for clients as part of hardware management, but a spreadsheet updated twice a year is far better than nothing.

    Set a replacement age, not a replacement date

    Four years is a reasonable working life for a laptop in most offices, and five for a desktop. Rather than replacing everything at once, decide the age at which a device gets replaced and let the list tell you how many fall due each year. The spend levels out, and the annual number stops being a surprise.

    Emergency replacements cost more than planned ones, and the difference is rarely just the price of the device.

    Standardise where you can

    Two or three standard models covering most roles makes everything after purchase easier: spares are interchangeable, setup is repeatable, and support calls are faster because the environment is familiar. Specialist roles still get specialist machines, but they become the exception rather than the norm.

    Keep one spare on the shelf

    A single configured spare device turns a failure from a lost day into a twenty-minute swap. For most teams it is the cheapest resilience available, and it pays for itself the first time it is used.

    Plan disposal at the same time

    Retired equipment still holds business data. Decide up front how devices will be wiped and where they will go, whether that is trade-in, redeployment for lighter tasks or certified recycling. Handling it as part of the plan avoids a cupboard filling with machines nobody wants to make a decision about.

    If you would like help building a device list and a three-year replacement schedule for your business, we are happy to put one together with you.

    What our clients say

    “We have found them to be very flexible – they work nights and weekends to fix problems and install upgrades to minimise disruption. They are also proactive and offer solutions to simplify our IT, whilst being mindful of our budget.”

    Elaine Hogg, Reproflex3

    Looking for an IT partner that just gets it?

    No silly questions, just straight up answers.

  • Moving to a cloud phone system without disrupting the business

    Moving to a cloud phone system without disrupting the business

    News & Insights

    Moving to a cloud phone system without disrupting the business

    Phone Systems 9 July 2026 4 min read
    A man wearing a headset on a video call at his desk in a busy open plan office

    Overview

    The phone system is usually the last thing a business wants to touch. It works, everyone knows how to use it, and the risk of a bad changeover is obvious: missed calls are lost customers. In practice a cloud migration is one of the more predictable projects we run, provided a few decisions are made before any hardware arrives.

    Decide what happens to your existing numbers

    Numbers can almost always be ported, but porting takes time and has to be scheduled with the current provider. This is the item that sets the project timeline, so it is worth confirming early. Where a number is tied to an old contract, we look at whether it is simpler to port later and forward calls in the meantime.

    Map how calls should actually flow

    Most systems have grown by accident: a menu option added for a campaign that ended, an extension still ringing at a desk nobody sits at. A migration is the natural point to write down how a call should be answered during business hours, after hours and when the person is already on a call. It usually takes an hour and improves the caller experience more than the technology itself does.

    The technical work is rarely the hard part. Agreeing how calls should be handled is.

    Choose handsets, headsets or both

    Cloud systems work from a desk phone, a computer or a mobile app, and different roles want different things. Reception generally still wants a physical handset. People who spend the day in meetings often prefer a headset and the app. Deciding this per role avoids buying hardware that sits in a drawer.

    Check the network first

    Call quality depends on the connection and on how the network prioritises voice traffic. We test this before the changeover rather than after, because the fix is usually straightforward when it is found in advance and much more disruptive when it is discovered by a customer.

    Run both systems for a short period

    Where the connection allows, we keep the old system live while the new one is in use. Staff learn the new handsets with a safety net, and if anything is missing there is no rush to resolve it. Once a week has passed without issues, the old service is switched off.

    Add training on the day of the switch, keep a short written guide on hand for the first fortnight, and most teams stop thinking about the change within days. If you are weighing up a move, get in touch and we will talk through what it would involve for your setup.

    What our clients say

    “We have found them to be very flexible – they work nights and weekends to fix problems and install upgrades to minimise disruption. They are also proactive and offer solutions to simplify our IT, whilst being mindful of our budget.”

    Elaine Hogg, Reproflex3

    Looking for an IT partner that just gets it?

    No silly questions, just straight up answers.