Author name: admin

Uncategorized

We Are Exhibiting at Smart Retail Tech Expo 2026, ExCeL London

We are pleased to say that Cirrus Technology Solutions will be exhibiting at Smart Retail Tech Expo 2026 at ExCeL London on Wednesday 11 and Thursday 12 November. You will find us on stand S372, and we would genuinely like to see you there. The details Dates: Wednesday 11 and Thursday 12 November 2026 Venue: ExCeL London, Royal Victoria Dock, One Western Gateway, London E16 1XL Opening hours: Wednesday 10.00am to 5.00pm, Thursday 10.00am to 4.00pm Our stand: S372 Tickets: Free Around 3,000 retail professionals attend across the two days, all looking at how technology can improve the customer journey and support growth. Your free ticket also gets you into White Label World Expo, Retail Supply Chain and Logistics Expo, and E-commerce, Packaging and Labelling Expo, all running alongside in the same building. Getting there is straightforward. Custom House on the Elizabeth line and DLR puts you at the west entrance. Why we are going Retail and hospitality have more in common than either sector tends to admit. Both take card payments across multiple locations. Both run networks that have to hold up when the room is full. Both depend on systems that nobody notices until they stop working. And both grow one site at a time, which is exactly how estates end up with twelve locations running twelve slightly different configurations. We have spent more than a decade working with multi-site operators on precisely that problem. A show focused on retail infrastructure, in-store technology and unified commerce is a natural place for us to be, and an easy place to have the kind of conversation that is difficult to have any other way. There is also a simpler reason. We like meeting people properly. Two days in a room full of operators who actually run sites is worth a great deal more than any amount of outreach. What we will be talking about Three things, mostly, because they are the three things that come up in almost every conversation we have with multi-site businesses. Who owns technology during a new opening. Every new site has a main contractor for the building. Far fewer have anyone equivalent for the technology, which is why connectivity, EPOS and network decisions so often get made late and separately. We take that role on for hospitality and retail groups, and it changes the shape of a project completely. Making every site work to the same standard. Head office usually has strong processes. The estate is where consistency slips, because each site was fitted out at a different time by different people. Getting every location onto the same foundation is what makes support, security and compliance manageable rather than constant. Keeping the technology invisible. The best outcome for any operator is a system nobody has to think about. That is genuinely the goal we work towards, and most of what we do sits quietly underneath a business making sure nothing reaches the customer. If any of those are live issues for you at the moment, come and have a conversation. No presentation, no pitch, just a chat about how your estate is set up and whether there is a better way to run it. What we can help with For anyone who has not come across us before, Cirrus is a UK managed service provider working mainly with multi-site hospitality, retail and leisure businesses. The work usually falls into a few areas. You can read more about our approach to multi-site hospitality, most of which applies equally to retail estates. Come and say hello We will have the full team on the stand across both days. Whether you want to talk through a specific problem, get a second opinion on something you are already planning, or just find out who we are, you are very welcome. We are also running something on the stand to make it worth stopping by. Details closer to the time, but bring a bit of competitive spirit. Stand S372, Smart Retail Tech Expo, ExCeL London, 11 and 12 November 2026. Tickets are free and available from the Smart Retail Tech Expo website. Full venue and travel information is on the ExCeL London event page. Want to arrange a time to meet? If you would rather book a slot than take your chances on the day, get in touch and we will put something in the diary. Book a meeting at the show → or call 0330 313 0966. Related reading

Restaurant IT checklist being worked through on a tablet before service
Uncategorized

Restaurant IT Checklist: 10 Checks to Run Before Service

Almost every IT problem that ruins a service was detectable that morning. The card machine that fails at 8pm was already struggling at 4pm. The printer that stops sending tickets to the kitchen had run out of paper before anyone opened the doors. The Wi-Fi that collapses on a full room had been sitting on a router that quietly rebooted overnight and never came back properly. None of that is bad luck. It is timing. Problems surface when the system is under load, which in hospitality means the worst possible moment, in front of a full room. This restaurant IT checklist covers ten checks a duty manager can run before service. Most take under a minute. Together they catch the overwhelming majority of issues that would otherwise land at 7.30pm. Why pre-service checks matter more in hospitality In most industries, an IT problem means someone raises a ticket and works on something else for an hour. In a restaurant, an IT problem means guests are sitting in front of you with no way to order and no way to pay. There is no working on something else. There is no rescheduling. The revenue for that hour does not come back, and the guest who waited twenty minutes for a card machine to reconnect remembers it far longer than they remember the food. That asymmetry is why hospitality benefits from a pre-service routine more than almost any other sector. Ten minutes before doors open is worth an hour of firefighting during service. It is the same principle behind checking the gas, the fridges, and the floats. Technology deserves a place on the same list. The 10-point restaurant IT checklist Run these in order. Assign them to the opening manager and make them part of the standard opening routine. 1. Test a card payment on every terminal Not just one. Every terminal on the floor. Run a low-value transaction or use your provider’s test function. A terminal that has lost its connection will often look completely normal on screen until someone tries to use it. Finding that out with a guest waiting is the expensive version of this test. 2. Print a test ticket to every kitchen printer Send one ticket to each printer and physically walk the pass to confirm it arrived. Kitchen printers fail quietly. They run out of paper, drop off the network, or jam without anyone noticing. The failure only becomes visible when a table’s food never appears, by which point you are twenty minutes behind. While you are there, check the paper. Every printer, every day. 3. Confirm the EPOS is talking to head office Open your reporting or sync screen and confirm the last successful sync was recent. An EPOS that has stopped syncing will usually keep taking orders locally, which is why nobody notices. Then a week of trading data is missing, stock figures are wrong, and someone in finance is trying to reconstruct it manually. 4. Check the internet connection, properly Do not judge this by whether a phone shows bars. Run a speed test on a device connected to the venue network. You are looking for two things: that it works at all, and that the result looks like a normal day. A connection that has failed over to a backup line will often still work, just slower, and you want to know that before the room fills up rather than after. 5. Check guest Wi-Fi from the guest side Disconnect from the staff network, connect as a guest, and load a page. Guest Wi-Fi runs on separate configuration from staff Wi-Fi, so testing one tells you nothing about the other. The landing page can break, the daily reset can fail, and the network can look perfectly healthy from the office while being unusable at table twelve. 6. Confirm the booking system is live and synced Open the booking system and confirm today’s covers are showing correctly. Booking platforms sit between your website, third-party channels and the floor. When the sync breaks, the diary looks fine but the covers are wrong, and you find out when two parties arrive for the same table. 7. Glance at the CCTV feed Load the viewer and confirm every camera is showing a live image and recording. Cameras fail silently and nobody looks until something happens and the footage is needed. Ten seconds a day is a very low price for knowing the system is actually running. 8. Check the back office machine and any tablets are charged and online Handheld ordering devices, manager tablets, and the back office PC all need to be awake, charged and connected before service, not during it. Devices that spend the night on a shelf rather than a dock are the most common cause of a mid-service scramble for a working handheld. 9. Confirm music and screens are running Background music and digital screens are not critical systems, but a silent room at 6pm is noticeable and reflects on the venue. These usually run on their own devices and their own subscriptions, which means they fail on their own schedule and nobody owns them. Add them to the list. 10. Log anything unusual, even if it fixed itself This is the one most teams skip and the one that pays back the most. If a terminal needed restarting twice, or the Wi-Fi dropped for a minute, write it down. Intermittent problems are almost always early warnings, and a written record is what lets your IT provider find the cause instead of guessing. A short shared note or a channel in your messaging app is enough. It does not need to be a system. Make it a standard, not a good intention A checklist only works if it belongs to someone. Put it in the opening routine alongside the fridge temperatures and the float count. Name the role responsible, not the person, so it survives holidays and staff changes. Keep it to ten minutes, because a check that takes half an

Busy UK restaurant where PCI DSS compliance applies to every card payment taken
Uncategorized

PCI DSS Compliance for Restaurants: Your 2026 Guide

You take card payments. That means PCI DSS applies to you. It applies whether you run one site or twenty, whether you use a full EPOS system or a card terminal on the bar, and whether anyone has ever asked you about it or not. Most restaurant operators know the acronym. Far fewer could say what it actually requires, and even fewer know where their business currently stands. That is not a criticism. It is a standard written by the card industry, in the card industry’s language, and nobody in hospitality signed up to become a security specialist. This guide explains what PCI DSS compliance for restaurants actually involves, where multi-site operators tend to slip, and what to do about it without turning it into a six-month project. What is PCI DSS? PCI DSS stands for the Payment Card Industry Data Security Standard. It is a set of security requirements created by the major card brands to protect cardholder data. It is not law. It is a contractual obligation that sits inside your merchant agreement with your acquirer or payment provider. Which in practice means it carries real consequences: monthly non-compliance fees, higher transaction charges, and in the event of a breach, fines and liability that fall on you rather than the bank. The current version is v4.0.1. Since 31 March 2025, requirements that were previously treated as future-dated best practice have been mandatory, and assessments now cover the full standard. The bigger shift is philosophical. The standard has moved away from an annual point-in-time validation model towards continuous evidence that controls are actually working across the year. That matters for hospitality more than most sectors, because a restaurant group changes constantly. New sites, new staff, new devices, new suppliers. A snapshot taken in January tells you very little about July. What does PCI DSS actually require? The standard runs to twelve requirement areas. For a typical restaurant or restaurant group, the ones that bite in practice are these. Network security. Your payment devices should not sit on the same network as guest Wi-Fi, back office machines, or the smart TV in the bar. Segmentation is the single most valuable thing most operators can do, because it shrinks the amount of your estate that falls in scope. Access control. Every person with access to payment systems needs their own login. Shared accounts, generic manager logins, and the password written inside the till drawer all fail. Multi-factor authentication is now expected for access into the cardholder data environment, not just for administrators. No storing what you do not need. Card numbers should not be written on paper for phone bookings, stored in a spreadsheet, or kept in a booking note field. If you do not store it, you cannot lose it. Patching and anti-malware. Every device in scope needs to be current. That includes the EPOS terminals, the back office PC, and the router. Logging and monitoring. You need to be able to show what happened and when. This is the requirement most operators discover they cannot meet, usually at the worst possible moment. Policy and training. Someone has to own this, staff need to know the basics, and it needs to be written down. You can read the full requirement set on the PCI Security Standards Council website, though be warned that it is written for assessors rather than operators. Where multi-site restaurant groups go wrong This is the part that catches good businesses out. Head office has strong processes. The finance team knows what it is doing. The policy exists and it is a genuinely decent policy. Then you look across the estate and every site is running slightly differently. Different EPOS versions because site four was refurbished two years later. Different network configurations because three different installers did three different fit-outs. Different Wi-Fi setups because one landlord insisted on their own provider. Different people, with different levels of understanding, doing broadly the same job in slightly different ways. None of that is anyone’s fault. It is what happens when a business grows one site at a time, with technology decisions made in the moment by whoever was closest to the problem. But PCI DSS does not assess your best site. It assesses your business. If site nine has a flat network and a shared admin login, that is your compliance position, regardless of how good site one is. Consider a nine-site group with an average of 600 covers a week per site. That is a lot of card transactions passing through nine different configurations. The risk is not evenly spread, and until someone maps it, nobody knows where it sits. The SAQ question Most restaurants validate compliance through a Self-Assessment Questionnaire rather than a full assessor-led audit. Which SAQ applies depends on how you take payments. If you use a standalone terminal with a dial-up or dedicated line and no electronic cardholder data storage, you are likely in the simplest bracket. If your EPOS is integrated, connected to your network, and handling card data, the questionnaire gets considerably longer. Two things worth knowing. First, the SAQ is a declaration. Signing it says the controls are in place. If they are not and a breach follows, that signature matters. Second, your acquirer decides which SAQ applies, not you. If you are unsure which one you should be completing, ask them directly. It is a five-minute email and it removes a lot of guesswork. Making compliance part of how the business runs The operators who find PCI DSS manageable are the ones who stopped treating it as an annual event. Practically, that looks like a handful of habits. That last one is the difference between a group that is compliant and one that hopes it is. This is the work we do with multi-site operators as part of ongoing cybersecurity support and our wider hospitality practice: building the same strong foundation into every site so that compliance is a by-product of good infrastructure rather than a separate project bolted

Restaurant fit-out in progress showing cabling before leased line installation
Uncategorized

How Long Does a Leased Line Take to Install? (UK Guide for New Site Openings)

You’ve signed the lease. The fit-out programme is agreed. The opening date is in the diary and the marketing has gone out. Then someone asks about the internet. If you’re ordering a leased line at that point, you’re already behind. So how long does a leased line take to install? In the UK, typically 60 to 90 working days, and sometimes considerably longer. That’s three to five months of calendar time, not weeks. Here’s what actually happens during that period, what causes the delays, and when you need to place the order to open on a proper connection rather than a temporary one. How long does a leased line take to install in the UK? Most UK providers quote a standard lead time of 45 to 90 working days. In practice, a realistic planning assumption for a new site is 90 working days from order to live. The range is wide because no two installations are the same. Here’s roughly how it breaks down: Stage Typical duration Order processing and provider survey 5–10 working days Desktop planning and route design 10–15 working days Wayleave agreements (if required) 20–60+ working days Civil works (digging, ducting) 10–30 working days Fibre installation and testing 5–10 working days Router configuration and handover 2–5 working days Some of these run in parallel. Others don’t start until the previous one finishes. Wayleaves in particular can stop everything dead. If your site already has fibre to the building and spare capacity in the duct, you might be live in six weeks. If your site is a listed building on a high street with a landlord in another country, you might be looking at six months. Why does it take so long? A leased line isn’t broadband. Broadband shares an existing connection with everyone else on your street. A leased line is a dedicated physical fibre run from the exchange to your building, uncontended, symmetrical, with a service level agreement behind it. That physical run has to be planned, permitted, and often dug. Which means several things have to go right. Wayleaves A wayleave is legal permission to install cable across land you don’t own. If the fibre route crosses a car park, a neighbouring property, or a landlord’s common area, someone has to sign. This is the single biggest cause of delay on leased line installs. Not because it’s technically difficult, because it’s an administrative process that sits with people who have no deadline pressure. A landlord who takes three weeks to reply has just added three weeks to your opening. Civil works If there’s no existing duct to your building, Openreach or your provider’s contractor needs to dig one. That means street works permits from the local authority, traffic management if it’s a busy road, and a crew booked in. Permit lead times vary by council. In some areas it’s two weeks. In others it’s considerably more, particularly if your site is in a conservation area or a pedestrianised zone. Site readiness The fibre terminates somewhere physical. That location needs power, needs to be accessible, and needs to exist by the time the engineer turns up. Openings often fall down here. The comms room is still a stud wall on the day the install is booked, so the engineer leaves and you go back into the queue. What happens if you order too late? You open on 4G or a temporary broadband line. That’s the honest answer. Picture a 90-cover restaurant on a Saturday night. Card payments, EPOS syncing to head office, CCTV recording to cloud, guest Wi-Fi, background music streaming, the booking system, and staff devices. All of it running through a consumer broadband router or a 4G dongle. It usually holds until it doesn’t. Peak service is exactly when contended connections fall over, and that’s the moment you find out. Card machines time out. Orders don’t reach the kitchen. Guests notice. You also end up paying twice, the temporary line, then the leased line, and running a second migration a few months after opening when the team is already stretched. When should you order? The 90-day rule Order your leased line at least 90 working days before your planned opening date. For a multi-site group, build it into the standard site opening process so it happens automatically. The best trigger point is the moment the lease is signed. Not when the fit-out starts. Not when the build programme is agreed. At heads of terms, you know the address, and the address is all the provider needs to start a survey. If you’re working backwards from an opening date, here’s the sequence: Order a backup connection at the same time. A 4G or 5G failover circuit costs very little and means a single fibre fault doesn’t stop trade. Who owns this in your business? This is the part that catches multi-site operators out. The building has a main contractor. Someone owns the programme, coordinates the trades, and answers for the date. The technology usually has three or four separate suppliers, all working to their own timelines, with nobody joining them up. The leased line provider doesn’t know when the EPOS is being installed. The EPOS supplier assumes the network is ready. The CCTV installer turns up expecting cabling that nobody ordered. Somebody has to own the technology programme the way your contractor owns the build. On the openings we run for multi-site hospitality groups, that’s the role we take, one point of contact, one programme, costed upfront and planned around the build. Site five then runs smoother than site one, because the process is the same every time. You can read more about how we approach IT projects for new site openings and our work across multi-site hospitality. The short answer Leased lines take 60 to 90 working days in the UK, and longer if wayleaves or civil works are involved. Order at lease signing, plan for 90 days, get a 4G failover as standard, and give one person ownership of the whole technology

Uncategorized

Cybersecurity for Multi-Site Restaurants: What Actually Works (2026)

Most restaurant groups think they’ve handled cybersecurity. There’s a password policy somewhere. A training session from last year. Maybe a conversation with someone in IT that ended with a nod and a PDF nobody reads again. It feels like enough. Until one compromised login shuts down your EPOS across three sites on a Saturday night. This post covers what cybersecurity for multi-site restaurants actually looks like in 2025, and the one piece of infrastructure most operators are missing. Why Multi-Site Restaurants Are a Target You might think cybercriminals go after banks and hospitals. They do. But hospitality is one of the most targeted sectors in the UK, and restaurants specifically sit in a difficult position. You process card payments across multiple sites. You hold guest data. You run booking systems, EPOS platforms, kitchen display screens, and guest WiFi, often on the same network. Each site is a potential entry point. Each staff member is a potential vulnerability. And unlike an office business that closes at six, you’re trading seven days a week, often until midnight. The NCSC reports that 39% of UK businesses identified a cyberattack in 2024. In hospitality, the attack surface is wider and the consequences hit harder, because downtime doesn’t just cost money, it costs covers, reputation, and reviews. The Problem With How Most Restaurants Handle Security The standard approach looks like this: This isn’t a criticism. It’s what most operators do, because most operators have never been told there’s a better way. The problem is that this approach is built on assumption. It assumes staff will follow the policy. It assumes no one will click a phishing link. It assumes that because nothing has gone wrong yet, the setup is fine. A 40-cover restaurant in Chester we spoke to had exactly this setup. Three sites, seven years of trading, no incidents. Then a phishing email reached a site manager. One click. The attacker was inside the network for eleven days before anyone noticed. The cost wasn’t just financial. The reputational damage with guests took months to recover from. What the Top Operators Do Differently The restaurant groups scaling past five venues aren’t running a tighter version of the same approach. They’ve changed the underlying structure. They’ve moved from a policy-based model to an infrastructure-based one. The difference is significant. A policy requires humans to behave correctly, every time, under pressure. Infrastructure doesn’t rely on that. It works regardless of whether someone’s tired, distracted, or simply didn’t read the handbook. Here’s what that infrastructure looks like in practice. The One Layer Most Multi-Site Restaurants Don’t Have It’s called Zero Trust architecture. The name sounds technical. The concept isn’t. Most networks operate on a simple assumption: if you’re inside the network, you’re trusted. Log in with the right credentials, and you have access. This is how most restaurant IT is set up. Zero Trust removes that assumption entirely. Every device, every login, every access request is verified every single time, regardless of where it’s coming from. A team member logging in from the restaurant floor gets the same check as someone trying to access your systems from the other side of the world. Your team doesn’t notice it. Your operations don’t slow down. But nothing gets through without being verified. And if credentials are ever compromised, the attacker doesn’t automatically get access to everything. For multi-site operators, this matters more than it does for a single-site business. You have more devices, more access points, more staff across more locations. The standard trust model creates a larger and larger gap the more you grow. Zero Trust closes that gap at the infrastructure level, not the policy level. What This Looks Like in Practice Implementing Zero Trust for a restaurant group doesn’t mean ripping everything out and starting again. For most operators it involves three things: None of this is complicated. But it requires a provider who understands hospitality operations, not just general IT. You can read more about how Cirrus approaches cybersecurity for hospitality businesses here, and what a properly structured hospitality IT setup looks like across a multi-site operation. The Question to Ask Yourself If one member of staff clicked a phishing link today, how far into your business could an attacker get? If the honest answer is “quite far,” that’s not a people problem. It’s an infrastructure problem. And it’s one that’s straightforward to fix with the right setup in place. The operators who sleep well at night aren’t crossing their fingers. They’ve built something that doesn’t depend on everyone doing the right thing every single time. Find Out Where Your Business Stands Not sure whether your current setup has these layers in place? We’ll take a look and tell you honestly what we find. Book a free IT security review or call us on 0330 313 0966. We’ll give you a plain-English answer, not a sales pitch.

IT downtime in hospitality
Blog

5 Costly IT Downtime in Hospitality Risks You Can Stop Now

IT downtime in hospitality costs more than most operators realise. You already know what a quiet Saturday costs you, but few can say what an hour of downtime does to the P&L. That gap is where the money quietly goes. This post puts a real number on it. It covers what downtime actually costs a hospitality business once you count everything, why the sector gets hit harder than most, and what reducing IT downtime in hospitality looks like in practice. No jargon, no scare tactics, just the maths most operators have never been shown. What does IT downtime actually cost a hospitality business? The repair bill is the smallest part of it. When your EPOS goes down mid-service, the cost stacks up across several lines at once. There’s the revenue you can’t take while tills are frozen. There’s the labour you’re still paying for staff who can’t work at full pace. There’s the covers you turn away because you can’t process them. And there’s the goodwill you spend on customers whose night you’ve disrupted. A 40-cover restaurant in Chester doing an average spend of £35 a head loses around £1,400 in covers for every hour of a full Saturday-night outage. That’s before staff cost, before refunds, before the table that walks out and posts about it. Run that across a multi-site group and a single bad evening can cost more than a month of IT support. Why does hospitality suffer more downtime than other sectors? Three reasons, and they compound. First, hospitality runs on more systems than people think. EPOS, card terminals, booking platforms, guest WiFi, CCTV, kitchen displays, stock and ordering, payroll. Each one is a point of failure, and most of them are connected. Second, the trading hours are brutal on IT. A law firm that loses its systems at 2pm has a bad afternoon. A restaurant that loses EPOS at 7pm on a Saturday loses the most valuable trading window of the week, and there is no quiet period to recover in. Third, the sector is now being targeted directly. Threat actors have built phishing campaigns specifically around hospitality workflows, using fake booking and reservation emails that staff are trained to action quickly. The National Cyber Security Centre has warned about exactly this kind of sector-specific social engineering. Downtime is no longer just a hardware question. It’s a security one. The downtime nobody budgets for Most operators plan for the obvious failures. A server dies, a router fails, a screen goes black. Those are visible and they get fixed. The expensive downtime is the kind that arrives through an email. A member of front of house clicks a link in what looks like a booking notification. Nothing appears to happen. Days later the systems lock, and the recovery runs into a second week while service limps along on paper. By then the cost has moved well past the IT line and into lost revenue, staff overtime, and in the worst cases, guest data on a leak site. This is the downtime that doesn’t show up in any budget, because nobody plans for the thing they haven’t been told is happening. What does reducing IT downtime in hospitality look like? It comes down to a handful of things done consistently, rather than one big purchase. None of this is exotic. The businesses that avoid expensive downtime are not the ones spending the most. They are the ones who treat IT as an operational risk, the same way they treat food safety or fire. The bottom line Hospitality margins in 2026 are tight enough without losing a weekend to an outage you could have prevented. The real cost of downtime is never the repair bill. It’s the trading you lose, the staff you pay to stand still, and the customers who don’t come back. If you don’t know what an hour of downtime would cost your business, that’s the first thing worth working out. The second is making sure it happens as rarely as possible. Not sure where your business stands? Book a free 30-minute IT review and we’ll tell you straight where your risks are. Call 0330 313 0966 or visit our hospitality IT page.  

Professional services team working at office desks with laptops, representing Microsoft 365 adoption in a legal or accountancy firm environment
Uncategorized

Microsoft 365 for Professional Services Firms: Are You Actually Using It?

You’re paying for Microsoft 365 every month. But if your firm is like most in professional services, you’re using about 30% of it. Email. Word. Excel. Maybe Teams for the occasional call. The rest of the platform, SharePoint, Defender, Intune, Conditional Access, sits there, licensed and idle, on an invoice nobody questions. This post covers what Microsoft 365 for professional services firms should actually look like, what most firms are missing, and what it’s costing them in real terms. Why Most Professional Services Firms Underuse M365 It usually starts the same way. Licences were set up at the start, by a supplier, during a growth phase, or because someone made a recommendation at the time. Nobody came back to finish the job. The team adapted. Workarounds became habits. New starters learned the broken version of things from whoever sat next to them. The platform never got configured for how the firm actually works. It got configured once, loosely, and then left. This isn’t a technology problem. It’s a configuration problem. And it’s almost universal across firms in legal, accountancy, consultancy, and financial services. What Microsoft 365 Business Premium Actually Includes If your firm is on Business Standard or Business Premium, the following is already in your licence. No upgrade required. SharePoint for client file management. Every matter in a structured, permission-controlled library. Version history built in. No more shared drives with six copies of the same document. No more emailing attachments between colleagues. Microsoft Defender for Business. Endpoint protection across every device, included in Business Premium. Most firms have it assigned. Almost none have it configured. Assigned and configured are not the same thing. Microsoft Intune for device management. Enforce security policies across every laptop, desktop, and mobile that touches your network. Remote wipe a lost or stolen device before the data on it becomes a problem. Most firms discover they need this capability when someone leaves unexpectedly, not before. Teams channels per client or project. All messages, files, and notes for a matter in one place. Searchable. Accessible to the right people. Not scattered across email threads, WhatsApp groups, and someone’s local desktop. Conditional Access and MFA policies. Multi-factor authentication on for some users is not the same as a properly configured security baseline. Conditional Access is where the real protection sits, blocking sign-ins from unrecognised devices, enforcing compliant endpoints, restricting access by location. Most firms haven’t touched it. What Does Poor M365 Configuration Actually Cost a Professional Services Firm? The idle licence fee is one number. The bigger cost doesn’t appear on any invoice. Fee earners in professional services lose between 45 and 90 minutes a day to tasks Microsoft 365 is already built to handle. Hunting for the right version of a document. Chasing a file buried in a colleague’s inbox. Rebuilding work after a leaver’s account was removed and their files went with it. At a £60,000 salary, 45 minutes a day is roughly £6,000 per person per year in lost productive time. Across a 20-person firm, that’s £120,000 annually in hours that could be billable, or at minimum, better spent. Then there’s the compliance risk. Firms in legal and financial services operate under SRA Principle 7, FCA SYSC requirements, and ICO registration obligations, all of which carry expectations around how client data is stored, accessed, and protected. A SharePoint environment that hasn’t been set up correctly, combined with Defender sitting unactivated, is a gap that won’t show up until something goes wrong. According to the NCSC, the most common cause of data breaches in professional services is compromised credentials, typically from phishing. Properly configured Conditional Access and MFA policies are the most direct defence. Both are included in Business Premium. Both are consistently under-configured. Four Checks You Can Run This Week You don’t need an IT firm to tell you where your gaps are. These four checks take under an hour and will surface most of what you need to know. 1. Pull your licence report. Microsoft 365 Admin Centre, then Billing, then Licences. Check what’s assigned against what’s available. If you’re on Business Premium and Defender and Intune aren’t configured, that’s the gap confirmed in one screen. 2. Check your MFA status. Admin Centre, Users, Active Users, then Multi-factor authentication. Any user showing “Disabled” or “Not registered” means that account is one convincing phishing email away from being compromised. 3. Look at your SharePoint usage. Admin Centre, Reports, Usage, SharePoint. If active file count is low relative to your headcount, your team is storing files somewhere else, shared drives, local machines, inboxes — and you have no central visibility over any of it. 4. Ask what happens when someone leaves. When a member of staff exits, what happens to their files? If the answer is “IT removes their account,” ask specifically where their OneDrive and SharePoint content goes in that process. If nobody knows, that’s the answer, and it’s a risk worth understanding before it becomes a problem. What a Properly Configured M365 Environment Looks Like A professional services firm running Microsoft 365 properly looks like this. Client files live in SharePoint, structured by matter, with permissions set so only the right people can access them. Teams channels are set up per client or project. Defender is active and monitored across all endpoints. Intune enforces a security baseline on every device. MFA is on for every user, with Conditional Access policies blocking anything that doesn’t meet the firm’s baseline. When someone joins, they’re set up in minutes with access to everything they need and nothing they don’t. When someone leaves, their account is disabled, their files are transferred, and their access is revoked, with a full audit trail. That’s not a complicated setup. It’s what the licence is designed to deliver. It just needs to be configured. If you want to see what this looks like for a firm your size, our professional services IT page covers how we approach it. Is Microsoft 365 Enough for a Professional Services Firm on Its Own?

Blog

Why Poor Wi-Fi is Costing UK Restaurants More Than You Think

In 2024, restaurants are expected to deliver more than just great food and atmosphere. Diners want fast, convenient service, digital ordering options, seamless payments, and strong, reliable Wi-Fi. But across the UK, Wi-Fi connectivity is quietly sabotaging even the most well-run hospitality businesses. This blog explores the real cost of poor Wi-Fi in restaurants and why it affects more than just your customer reviews. From lost revenue and order delays to operational chaos and security risks, we break down what bad Wi-Fi is really costing your business and how to fix it. Why Wi-Fi Is Business-Critical in Hospitality Wi-Fi used to be a nice-to-have feature. Today, it’s a core part of running a successful hospitality business. In a UK survey, 56% of customers said free Wi-Fi is the most important feature they expect when visiting a restaurant or pub. And 75% said high-quality Wi-Fi would make them more likely to return. Poor connectivity doesn’t just irritate customers—it directly impacts service. With more restaurants using wireless POS systems, QR code menus, mobile ordering, and cloud-based tools, a stable Wi-Fi connection is essential to keep the front and back of house running. Common Front-of-House Wi-Fi Issues 1. Poor Guest Wi-Fi Experience Customers expect strong internet access. If your guest network is slow, unreliable, or unavailable, many diners will be frustrated. This can: Lead to negative reviews Reduce average dwell time and spending Discourage return visits 60% of UK diners say internet access increases loyalty to a restaurant. On the other hand, customers are quick to avoid venues with spotty Wi-Fi. 2. Payment Processing Delays With the rise of cashless payments, card readers and POS systems rely on your internet connection. A poor connection can: Cause card transactions to fail Force staff to restart devices Lead to abandoned sales In the UK, the average restaurant loses £900 per hour of internet downtime, particularly during peak times like lunch or dinner service. 3. Order Delays and Drops When orders are taken via tablets and sent to the kitchen through the cloud, Wi-Fi failure can cause: Orders being lost or not sent Delays in service Confusion between front- and back-of-house staff These issues affect the dining experience, increase staff stress, and lead to wasted food. 4. Online Ordering and Delivery Glitches Restaurants now rely on platforms like Deliveroo, Uber Eats, and Just Eat. But if your internet drops: Your business may disappear from delivery apps Orders can’t be received You lose visibility and customers choose competitors Just one 30-minute outage at peak time can mean dozens of lost orders-worth hundreds or even thousands of pounds. Common Back-of-House Wi-Fi Issues 1. POS System Failures Cloud-based POS systems depend on Wi-Fi to sync orders and process data. If the connection drops: Orders may not sync between devices Menu updates don’t reach all terminals Reporting and sales data may be lost or delayed This results in confusion, duplicated orders, or missed items-impacting both revenue and reputation. 2. Inventory Management Issues Many restaurants use smart inventory systems to track ingredient levels and reorder stock. Wi-Fi issues can: Prevent real-time updates Cause reordering delays Lead to stock shortages or over-ordering When kitchens don’t know what’s in stock, the result is inconsistent menus, staff frustration, and customer disappointment. 3. Admin and Scheduling Disruptions Back-office tools like rotas, payroll, reservation platforms, and cloud HR systems also need internet. If these tools go offline: Managers can’t update schedules or respond to changes Reservation systems might double-book or cancel incorrectly Payroll data may not sync All of this leads to inefficiencies, overtime costs, and frustrated employees. 4. Security and Compliance Risks A poorly managed Wi-Fi network isn’t just slow—it’s risky. Without proper security: Guests may access your internal systems Sensitive data may be exposed You may fail to meet PCI compliance for payment security Security breaches can result in serious fines and reputational damage. What’s the Real Cost? According to a UK business connectivity report, small businesses lose an average of £900 per hour during internet outages. For restaurants operating on slim margins, a few lost hours per week quickly add up. In 2023 alone, UK businesses lost an estimated £3.7 billion due to internet outages-up from £742 million in 2018. Examples: A small restaurant with an average turnover of £400/hour loses £800 during a 2-hour outage. A delivery-focused restaurant could lose 30+ online orders during an outage, costing £600–£1200 in one evening. Downtime during service hours may also mean extra labour to catch up, refunds, and bad reviews. How Restaurants Compare to Other Industries Retail Suffers from high device density (card readers, kiosks, tablets) 94% report growing bandwidth challenges Lost sales when tills go offline or apps don’t work Construction Often in remote sites with poor signal Internet dropouts delay project updates and communications Offices Lost productivity and missed deadlines Estimated to cost UK businesses £11 billion annually But hospitality stands out because issues impact real-time sales and customer satisfaction, not just productivity. How to Fix It: Improving Wi-Fi in Your Restaurant 1. Invest in Business-Grade Hardware Stop using cheap home routers. Upgrade to professional equipment: High-performance access points Multiple coverage zones Dual-band routers (2.4GHz and 5GHz) Conduct a Wi-Fi site survey to detect weak zones and signal interference. 2. Separate Guest and Internal Networks Create separate networks for: Customers (guest Wi-Fi) POS, staff tablets, back-office systems Use VLANs and apply bandwidth limits to prevent guests from slowing down your systems. 3. Use Redundancy and Backups Have a plan if your main connection fails: Use dual connections (e.g. fibre + 4G backup) Auto-failover routers ensure the system stays up This reduces the risk of outages during peak service hours. 4. Regularly Maintain and Monitor Schedule firmware updates during off-hours Use dashboards to monitor signal strength, usage, and errors Train key staff to troubleshoot minor Wi-Fi issues 5. Optimise Placement and Bandwidth Use both 2.4GHz (long range) and 5GHz (fast speed) Add access points in areas with poor coverage Prioritise important devices (POS, printers) over guest traffic 6. Prioritise Security Use WPA3 or

Illustration of a Williams Racing Formula 1 car overlaid with Keeper Security's logo, symbolising enterprise cybersecurity in high-speed environments
Blog

F1-Level Cybersecurity: Our Partnership with Keeper

When Cybersecurity and Motorsport Combine This past weekend’s Formula 1 race showcased not only raw driver talent but the strategic excellence of engineering teams. Oscar Piastri and Lando Norris clinched first and second for McLaren, while Alex Albon’s impressive 5th place finish for Williams Racing drew attention beyond the track. Behind that performance is a relentless focus on data integrity, secure communication, and controlled system access – enabled by Keeper Security. In motorsport, milliseconds and megabytes are equally important. A single breach in data confidentiality or a delay in system access can mean the difference between podium and the pit lane. That’s why Keeper Security’s partnership with Williams Racing isn’t just symbolic – it’s operationally essential. Why Keeper Security Powers F1-Level Protection Keeper Security delivers zero-trust, zero-knowledge architecture, offering enterprise-grade protection for credentials, secrets, and infrastructure access. For Williams Racing, this translates to: Protection of proprietary strategy models and telemetry data Secure credential access across international engineering teams Defence against phishing, ransomware, and credential compromise With solutions like KeeperPAM®, Secrets Manager, and real-time threat intelligence, Keeper ensures uninterrupted, secure collaboration from garage to grid. Keeper’s technology goes beyond passwords. It includes: Privileged Session Management for auditing sensitive actions Secure File Sharing across global operations Passwordless and SSO integrations that streamline access while preserving control Just as pit crews operate with precision and clarity, Keeper equips cybersecurity teams with the visibility and governance to act with speed and certainty. What Businesses Can Learn from the Track Formula 1 is a masterclass in systems integration and situational awareness. Every subsystem – brakes, aerodynamics, engine performance – feeds into real-time strategic decisions. Likewise, businesses rely on efficient yet secure system access. Keeper enables: Secrets Management for DevOps to secure credentials in CI/CD environments SSH Key and Remote Database Access without exposing credentials Automated Password Rotation for critical infrastructure Whether you’re running retail operations, financial systems, or cloud-native deployments – your architecture deserves the same discipline and protection. Trusted Globally – And Locally As Williams Racing’s cybersecurity partner, Keeper is trusted at the highest level of competitive performance. But the same tools that power elite motorsport teams are available for businesses across the UK. Keeper helps you: Prevent breaches caused by compromised credentials Maintain compliance with standards like GDPR, ISO 27001, and Cyber Essentials Gain full control over infrastructure access without sacrificing speed In fact, 81% of UK businesses experienced cyber incidents in the past 12 months – many from common vectors like email compromise and poor credential hygiene. Want F1-Level Cyber Control in Your Organisation? From passwordless authentication to privileged access auditing, Keeper Security delivers the same technologies trusted in Formula 1 to protect your business. Whether you’re managing five users or five thousand, your access control deserves the same precision as a race-winning pit stop.

GiftAid
Blog

Gift Aid

Gift Aid Simply put, Gift Aid is a form of tax relief.  This allows charities to receive up to 25% more income from a donation made by a UK taxpayer. Once a donation has been made, a charity is able to claim back the basic rate of tax from it from the government CAF Cirrus has developed a paperless Gift Aid system, that also has Point of Sale (POS) stock control and can link into accounting systems specifically for charities.  Your all-in-one system for charity led retail is now available.  To help here are a few essential Q&A’s Q:  Can we just use the Gift Aid standalone, without the POS? – YES.  The system is modular so we can turn this on or off as needed Q: Does the system allow multiple items as part of a single gift (Perhaps a bag of clothes or box of books)? – YES.  Each item can be individually tracked, priced and sold Q:  Does the system capture details and report on them in-line with HMRC guidelines? – YES.  We have back office reporting that tracks each person who gifts and each item they have gifted, been sold or held in stock Q: Can the system remember people who gift on a regular basis and save their information for speedy drop-off? – YES.  Our system securely records the contact details and can issue a membership style system.  These frequent drops off are also recorded for HMRC requirements Q: Can we set prices and calculate profit? – YES.  Our production valuation screen lets you set this per item and print the necessary labels POS Our cloud based POS system is perfect for retail, bars & restaurants, builders merchants, Garden Centres, Visitor Attractions and more. The system integrates with a number of handheld payment terminals and accounting systems for real end to end record keeping too. At Cirrus we strive to be your technology partner of choice.  In the case of Gift Aid we listened to our clients, developed a system and put it into use in their locations, saving them not only in tax but also the efficiencies the business realized in the process. Get in Touch If you are in need of a partner to manage your IT, drive change &  improve operations perhaps you should #ThinkCirrus. For Consulting, Design, Delivery and Managed Service…. #ThinkCirrus Call us on 033013 130966 or book an appointment here : Time to #ThinkCirrus   #Giftaid #Manageditservices #POS #ukwide

Scroll to Top