Introduction

Back in 2002 the media did their usual frenzied attack on Donald Rumsfeld after he introduced them to the conept of “Known Unknowns” and “Unknown Unknowns”:

“Reports that say that something hasn’t happened are always interesting to me, because as we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns—the ones we don’t know we don’t know. And if one looks throughout the history of our country and other free countries, it is the latter category that tends to be the difficult ones”

His response was ridiculed by many but he was essentially trying to convey the concept introduced back in the 1950s and often referred to as the Johari window.

 

 

Why I use the Johari Window

I find Johari window showing table of permutations within education of businesses.this really useful when thinking about risks to business.  In my opinion all businesses should be aiming to  minimise the size of their “blind spot”.  As a company specialising in IT Support for business our potential blind spots are massive given they include:

  • Daily advances in technology
  • Changes in compliance and legislation
  • And that hot topic changing on an hourly basis called “Cyber Security”

Even when utilising the knowledge of many staff it is obviously not possible to know everything about these three massive areas of technology.  However, if it was possible to capture 100% and reduce the blind spot down to zero it is of little use unless it could be shared with the decision makers of our customer’s businesses.

Why knowledge needs to be shared

Why do I say this?  Well information known to me but not known to you exists in the area known as a “façade” and businesses have a tendency to not invest in what appears to be deceptive.

Essentially business is done in the area know as the “Arena” where we all understand the value of the knowledge.  It is for this reason I will be spending the next few weeks talking about cyber security.  There are significant cyber “blind spots” for many businesses and these are being actively exploited by criminal gangs and state sponsored groups on an increasing basis.  Unfortunately many businesses still believe their business is too “small” to warrant the attention of these groups.  However, most of the attack is automated which means even the smallest of businesses with one person turning a few thousand pounds a month is still at risk.

What would you consider to be your biggest “blind spot” and how are you planning on reducing its size?

 

What next?

If your business would like to talk about any aspect of IT and how you can use it to help grow your business then fill out our contact form, phone us or click on the appointment button below and lets start a conversation to see if we are able to help you and your business.

Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.

 

Cyber Security
A professional reviewing a cyber security incident response plan on screen, representing governance and ransomware resilience in a regulated firm.

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

AI
Illustration representing Microsoft 365 Copilot Wave 3 AI agents working within a business environment, symbolising automated workflows under governance oversight.

Copilot Wave 3, What It Means for Governance

Copilot Wave 3 has landed, and this release feels different. AI is moving from helping your team to acting on its behalf, through custom agents and a smarter, context-aware Copilot. For regulated firms, that shift is an opportunity, but only if governance keeps pace. Here's what's changing and how to stay in control.

Cyber Security
A close-up of a CAPTCHA-style "prove you're not a robot" verification prompt on a computer screen, illustrating the fake CAPTCHA scam targeting professional firms.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to "prove you're human" by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here's how the trap works, and how to protect your team.

AI
Rows of identical humanoid robots beside a December wall calendar with a Friday date pinned, illustrating the question of whether regulated firms should pause AI use on Fridays.

Should Your Firm Hit Pause on AI Every Friday Afternoon?

By the close of the working week, even careful professional teams are stretched thin, and that is exactly when AI-generated work slips through unchecked. The output looks board-ready, so a tired reviewer approves it without a second read. For regulated firms, that quiet moment of over-trust is a genuine compliance risk. So should you pause AI on Friday afternoons?

Cyber Security
A laptop screen displaying a Windows 11 update prompt, illustrating the risk of a convincing fake update targeting regulated professional firms.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.