3-2-1 backup rule
Keep three copies of your data, on two different types of storage, with one copy off-site. Many businesses now add an "immutable" copy that can't be changed or deleted, so ransomware can't reach it.
IT jargon buster
Heard an acronym in a meeting, a quote or one of our articles and not wanted to ask? Here are 60 of the IT, security and connectivity terms businesses ask us about most - explained without the jargon.
Nothing matches that yet. Ask us - if it’s a term we hear a lot, we’ll add it.
Keep three copies of your data, on two different types of storage, with one copy off-site. Many businesses now add an "immutable" copy that can't be changed or deleted, so ransomware can't reach it.
Failover
A mobile-network connection that takes over automatically if your main internet line goes down, so card machines, cloud apps and calls keep working while the fault is fixed.
Only letting approved software run on your computers and blocking everything else by default. It stops most malware before it starts, because unknown programs simply aren't allowed to run.
Bandwidth is how much data a connection can carry at once (its speed, in Mbps). Latency is the delay for data to make the trip, in milliseconds. Video calls and VoIP suffer more from high latency than from low bandwidth.
Your plan for keeping the business running when something goes wrong - a cyber attack, fire, flood or internet outage - and for getting systems and data back afterwards.
A scam where criminals take over or imitate a real email account - often a director or supplier - to ask for urgent payments or changes to bank details. Always confirm payment changes by phone, using a number you already have.
Bring your own device
Staff using their own phones or laptops for work. Workable with the right controls - such as keeping company data in managed apps that can be wiped without touching personal photos and messages.
Copies of your data stored securely off-site in a data centre, so you can restore files, emails or whole systems after a mistake, hardware failure or cyber attack.
Hosted PBX
A business phone system that runs in a provider's data centre rather than a box in your office. Features like call queues, hunt groups, voicemail to email and call recording are managed online.
Rules in Microsoft 365 that decide whether a sign-in is allowed based on who it is, where they are, which device they're using and how risky it looks - for example, blocking sign-ins from other countries or from unmanaged devices.
How many customers share the same capacity on a broadband connection. Shared ("contended") broadband can slow down at busy times; a leased line is uncontended, so the speed stays the same.
Microsoft's AI assistant, built into Microsoft 365 apps to draft documents, summarise emails and meetings, and answer questions using your business data. It can see whatever the person using it can see, so tidy file permissions matter first.
A UK government-backed certification showing a business has five basic security controls in place: firewalls, secure configuration, user access control, malware protection and security updates. Increasingly asked for by customers, insurers and public-sector contracts.
Watching criminal marketplaces and leaked-data dumps for your company's email addresses and passwords, so you're warned - and can change passwords - when staff details appear in a breach.
Domain name system
The internet's address book, turning names like valetech.net into the numeric addresses computers use. Your domain's DNS records also control where email is delivered and help prove your emails are genuine.
Scrambling data so only someone with the right key can read it. Encrypting laptops means a lost or stolen device doesn't mean lost data; encrypted connections protect information as it travels across the internet.
When a manufacturer stops providing security updates for a product, such as Windows 10 (October 2025) or an old firewall. It may still work, but new security flaws will never be fixed, so it should be replaced or upgraded.
Security software on each computer, laptop or server (each "endpoint") that blocks malware and watches for suspicious behaviour. EDR - endpoint detection and response - goes further, recording what happened so threats can be investigated and stopped.
A device or software that controls what traffic can pass between your network and the internet, blocking anything that isn't allowed. A business firewall needs updating and reviewing like any other system.
Fibre to the cabinet: fibre runs to the green street cabinet, then copper telephone wire covers the last stretch to your building. Speeds drop the further you are from the cabinet.
Full fibre
Fibre to the premises: fibre-optic cable all the way into your building. Much faster and more reliable than older copper-based broadband, with speeds up to and beyond 1Gbps where available.
Service desk
The team your staff contact when something isn't working or they need help. Each request becomes a "ticket", so nothing gets lost and you can see what's been done.
An older digital phone line technology used by many business phone systems, being switched off along with the PSTN. Systems still using it need replacing with VoIP or SIP-based alternatives.
A dedicated, uncontended fibre connection just for your business, with the same speed up and down and guaranteed fix times. The choice when the internet is critical to how you work.
Any software designed to cause harm: viruses, ransomware, spyware and programs that steal passwords. It usually arrives through email attachments, dodgy downloads or unpatched software.
An IT company that looks after your technology on an ongoing basis for a regular monthly fee - helpdesk, monitoring, security and planning - instead of charging each time something breaks.
Microsoft's subscription for businesses, combining Office apps (Word, Excel, Outlook) with cloud services such as Exchange email, Teams, SharePoint and OneDrive, plus security and device management on some plans.
A separate backup of your Microsoft 365 email, OneDrive, SharePoint and Teams. Microsoft keeps the service running, but its recycle bins and retention aren't a true backup - deleted or encrypted data can be lost for good without one.
formerly Azure Active Directory
The sign-in and identity system behind Microsoft 365. It holds your users and groups, and controls how they sign in - including multi-factor authentication and conditional access.
Mobile device management (MDM)
Microsoft's tool for managing laptops, phones and tablets from the cloud: applying security settings, installing apps and updates, and wiping company data from a lost or stolen device.
Microsoft 365's app for chat, video meetings and working together on files. With Teams Phone it can also make and take ordinary phone calls.
Signing in with something extra as well as your password - usually a code or prompt on your phone. A stolen password on its own is then no longer enough to get into an account, which stops most account takeovers.
Network-attached storage
A small storage box on your network for shared files or backups. Useful, but it isn't a backup on its own - it can fail, be stolen or be encrypted by ransomware like anything else on the network.
The box that connects your wired devices - computers, phones, printers and access points - so they can talk to each other and reach the internet.
Setting up everything a new starter needs (accounts, devices, access) and removing it all when someone leaves. Doing offboarding promptly is one of the simplest ways to keep data secure.
A secure app that creates, stores and fills in strong, different passwords for every account, so nobody has to remember them or reuse them. A business version lets teams share logins safely.
Installing the updates that software makers release to fix security flaws and bugs. Attackers move quickly once a flaw is public, so critical updates should go on within days, not months.
An authorised, simulated attack on your systems by security specialists, to find weaknesses before real attackers do. You get a report of what they found and how to fix it.
Emails, texts or calls that pretend to be from someone you trust, to trick you into clicking a link, opening an attachment, handing over a password or making a payment. Still the most common way attacks on small businesses begin.
Controlling who gets admin rights, when and for how long. Staff work from everyday accounts, and admin access is granted only for a specific task and recorded - so an attacker who gets into one account can't take over the whole system.
The UK's retirement of the old copper telephone network (PSTN and ISDN), due to finish by 31 January 2027. Traditional landlines, and anything that relies on them - such as some alarms, lift lines and card machines - need moving to digital alternatives.
Malicious software that locks or encrypts your files and demands payment to unlock them, often threatening to publish stolen data too. Tested backups and keeping admin rights tight are the best defences.
Remote monitoring and management
Software an IT provider uses to keep an eye on your computers and servers around the clock - spotting failing disks, missing updates and other problems early - and to fix many issues remotely.
Two numbers for planning recovery. RTO (recovery time objective) is how long you can afford to be down; RPO (recovery point objective) is how much recent work you can afford to lose - which decides how often backups need to run.
Software as a service
Software you use over the internet on a subscription, rather than installing and running it yourself - Microsoft 365, Xero and most CRMs are examples.
Short, regular training that helps staff recognise scams and handle data safely, often with realistic phishing tests. It turns your team into a layer of your security rather than its weakest point.
Apps and services staff start using for work without the business knowing - a personal Dropbox, a free AI tool, a WhatsApp group. Usually well-meant, but it puts company data outside your control.
Microsoft 365's file storage. OneDrive is each person's own files; SharePoint holds shared team and company files. Together they replace the traditional office file server for most small businesses.
Using one work account - usually your Microsoft 365 login - to sign in to other business apps. Fewer passwords for staff, and switching off one account removes access everywhere when someone leaves.
A virtual phone line delivered over the internet, connecting an on-site phone system to the phone network. It's the usual replacement for ISDN lines when a business keeps its existing phone system.
Service level agreement
The part of an IT support contract that sets out what's covered and how quickly the provider will respond to and fix problems of different priorities.
Single Order Generic Ethernet Access: FTTC-style broadband without a traditional phone line attached. It's replacing broadband-plus-landline packages as the old copper phone network is switched off.
An internet address for your connection that never changes. Needed for some remote-access, CCTV and security setups that have to find, or recognise, your office reliably.
A properly planned, labelled and tested network of cables running from a central cabinet to every desk and access point. It makes the network reliable and fixing faults quick.
Virtual LAN
Splitting one physical network into separate virtual ones - for example, keeping guest Wi-Fi, CCTV and phones apart from the network your business systems use.
Voice over IP
Making phone calls over an internet connection instead of a traditional phone line. Calls can ring desk phones, mobiles and laptops, so staff can take them anywhere.
Virtual private network
An encrypted connection that lets staff reach office systems securely over the internet, as if they were in the building. It should always be protected with multi-factor authentication.
A device, usually on a ceiling or wall, that provides Wi-Fi to an area. Several properly placed and managed access points give far better coverage than one router doing everything.
An approach to security that never assumes a person or device is safe just because it's on the office network. Every sign-in and request is checked - who you are, what device you're on and whether it's healthy - before access is given.
A security flaw that attackers know about before the software maker has released a fix - so defenders have had "zero days" to patch it. Layered security, like allowlisting and limited admin rights, helps when a patch isn't yet available.