Security Centre
Free tools and plain-English guidance for UK businesses. Check a link before you click it, find out whether your email can be forged, and see what the NCSC is actually warning about right now. If something has already gone wrong, start with the red button below.
🚨WE THINK WE'VE BEEN HACKEDOpen this for what to do in the next ten minutes
Work through this in order. It is written for whoever is nearest the problem, not for an IT specialist. You do not need to know what has happened yet — for a ransomware screen, a hijacked mailbox or a fraudulent invoice, the first few steps are the same.
Do this now
- Disconnect it, but leave it switched on. Unplug the network cable or turn off the Wi-Fi. Powering the machine down wipes evidence held in memory, and part-way through ransomware it can leave files encrypted beyond recovery.
- Move to a different device. If that machine is compromised, every password you type into it is read as you type it.
- Change the email password first. Email is the master key — it resets everything else. Then change anything that shared that password.
- Turn on multi-factor authentication for email and banking if it is not already on. This is the single change that stops most account takeovers from continuing.
- Tell your IT support, and tell your bank if invoices, payment details or bank details appear anywhere in this.
Do not do this
- Do not wipe or rebuild it yet. That machine is the only record of how they got in and what they reached. Rebuilt too early, you often restore the same weakness or reinfect from the backup.
- Do not pay a ransom before taking advice. Paying does not reliably get the data back, it funds the next attack, and if the group behind it is sanctioned, paying can be a criminal offence in the UK.
- Do not delete the suspicious email, the logs or the files. They are the evidence, and without them nobody can tell you what was taken.
- Do not discuss it inside the compromised system. If they are reading the mailbox or the Teams chat, talking about it there simply tells them you have noticed.
Then, within days
- Work out whose data was involved. If personal data has probably been exposed and there is a risk to those people, the ICO must be told within 72 hours of you becoming aware. That clock starts now, not when the investigation finishes.
- Report it to Action Fraud on 0300 123 2040. For a live incident affecting a UK organisation, the NCSC takes reports too.
- Tell the people affected where the risk to them is high — customers, staff, anyone whose details were in there.
- Check your mail rules. Attackers routinely add a forwarding or auto-delete rule so that replies, and warnings, never reach you. It is the step most often missed.
Not sure how serious it is? That is normal in the first hour, and it is exactly the right time to call rather than the wrong one. If you are already an EasyLifeIT customer, call and say the word incident and we will treat it as one.
0333 322 1100Check a suspicious link
Paste a link and we will pull the address apart and show you where it actually goes. Nothing is sent anywhere — the whole check runs inside your own browser, and the link is never opened.
One warning before you paste: do not run a password reset or email confirmation link through this, or through any online scanner. Those links are built to work once, and submitting one can burn it or hand it to somebody else.
Is your password already on a criminal's list?
Attackers do not guess passwords one at a time any more. They work from lists of billions that have already leaked from other companies' breaches. If yours is on one of those lists, it does not matter how clever it looked when you chose it.
Free tools, no sign-up
Everything here is free whether you are a customer or not. None of it asks for your details, and none of it is a trial that stops working.
What is actually happening right now
These two feeds come straight from the source and refresh themselves, so this page stays current without anybody at EasyLifeIT having to remember to update it. The NCSC publishes every few weeks rather than every day — a headline from last week means nothing new has been declared, not that this page has gone stale. Everything is dated so you can judge that for yourself.
From the NCSC
The UK's National Cyber Security Centre, part of GCHQ
Live- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gatewayon September 28, 2026
- Iranian cyber targeting of dissidents, activists and journalistson September 15, 2026
- UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalistson September 15, 2026
- Disruptive cyber activity highlights risk from internet-exposed systems and edge deviceson August 27, 2026
- NCSC statement in response to recent incidents resulting from frontier AI evaluationson August 4, 2026
From Microsoft's security team
Threat research, incident write-ups and product news
Live- Insights from the 2026 Microsoft Digital Defense Report on October 1, 2026
- Preparing governments for an era of interconnected cyber riskon October 1, 2026
- Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026on September 30, 2026
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570on September 30, 2026
- Phishing Abuses RMM Tools for Persistent Accesson September 29, 2026
Worth checking elsewhere
Two things we have deliberately not rebuilt here. The originals are better than anything we would put in front of you, so these go straight to them.
Would you rather not have to think about any of this?
That is the job. We look after Microsoft 365, the patching, the backups and the awkward phone call at half past four on a Friday, for businesses who would rather get on with their actual work. UK based, and you speak to the same people each time.
Have a look at what that costs, or just call and describe the problem. There is no sales process and no obligation to do anything afterwards.
See the plans0333 322 1100