Latest News for 4TC
We have loads to say!
We have loads to say!
Ask a business owner about their server, and you’ll often get a slight wince before an answer. Most people leave on-premise IT running as long as it’s still working, the same way they’d ignore a boiler that hasn’t quite broken down yet.
Old infrastructure rarely fails all at once. It wears down in small, forgettable moments, like a slow login this week or a support call your IT provider has already fielded twice this month.
Each moment feels manageable alone, but together they add up to SME IT infrastructure costing more than it delivers, without ever forcing a decision.
Here’s a practical check of four warning signs that your on-premise IT has become a liability and what each one means for your cloud readiness.
Sign 1: Hardware Is Reaching End-of-Life or Requiring Frequent Repairs
Every server and network has a working lifespan, usually three to five years, before performance drops off and manufacturer support winds down. Past that point, on-premise IT that once ran with little attention starts needing it regularly, and the warning signs build into a steady pattern.
These signs mean the true cost of keeping your current setup running is rising steadily, in engineer time and in the productivity lost whenever someone is waiting on a machine that’s having a bad day.
Sign 2: Remote and Hybrid Working Is Exposing Gaps in Access and Performance
On-premise IT was built for a team working from one building, connected to servers down the corridor. Hybrid working asks the same infrastructure to support people logging in from home or a client’s office, and the strain tends to show up first in daily frustration, like slow file access and unreliable remote connections.
That gap is measurable at a national level, too. According to the government’s Cyber Security Breaches Survey 2025/2026, just 36% of UK businesses have a VPN in place for staff connecting remotely, up only slightly from 31% the year before.
Without one, remote and hybrid staff are often left finding less secure ways to reach the systems they need, which raises a cloud readiness question alongside the security one.
Each of these is a symptom of infrastructure that was designed for a different way of working. Fixing them one at a time, with a faster VPN here or an extra remote licence there, tends to patch the symptom without addressing why remote access is hard in the first place.
Sign 3: Scaling Up Is Slow or Costly
Growth tends to expose the limits of on-premise IT fastest.
A new starter needs a machine and a licence, and procurement rarely moves as fast as a start date requires. Opening a new site raises the same problem on a larger scale, extending or duplicating SME IT infrastructure that’s already stretched.
None of this makes on-premise IT the wrong choice for every business. It does mean that if growth is part of your plan, the pace your infrastructure can move at deserves the same scrutiny as everything else in that plan.
Sign 4: Backup and Disaster Recovery Rely on Physical, Single-Site Infrastructure
Backup is often the part of on-premise IT that gets set up once and left alone. That’s usually fine until the day it’s needed, at which point where the backup lives matters as much as whether it exists at all.
A backup stored in the same building as the servers it protects offers little real protection against fire, flood, theft, or a ransomware attack that reaches the original data and the copy of it at the same time.
Backup is the sign that catches most owners out, since it’s usually assumed to be covered.
When people weigh up cloud vs on-prem in the UK, this is where the comparison comes down hardest. A single-site backup protects against far fewer scenarios than most on-premise IT owners assume.
What These Signs Mean for Your Business
None of these signs, on their own, means it’s time to abandon on-premise IT. Add them up, though, and a pattern starts to emerge.
Businesses don’t often notice they’ve outgrown their setup in one dramatic moment; it creeps in through rising repair bills and a backup plan that’s never really been tested.
Recognise some of these signs in your own business? Speak to 4TC about whether cloud or hybrid IT could be the right next step.
FAQs

“Everyone else is moving to the cloud” isn’t a migration strategy, and for most London SMEs the honest answer is a mix of models rather than an all-or-nothing move. The right choice depends on your costs, control, compliance, and growth plans, so the smart first step is knowing which questions to ask before you migrate anything.
Somewhere in your inbox there’s a message telling you to move to the cloud. Maybe it’s a supplier, a peer at a networking event, or an article that made it sound inevitable. But how many of these provide an honest look at whether it’s right for your business?
Moving to the cloud because “everyone else is doing it” isn’t a migration strategy. Cloud migration in the UK has matured past the point where moving everything is automatically the smart move, and the businesses getting it right are the ones asking better questions first.
Before you commit, this is what London small and mid-sized enterprises (SMEs) should really weigh up when choosing between on-premise, hybrid, or full cloud: cost, control, compliance, and room to grow.
What works for a fast-scaling startup or a 500-seat enterprise tells you very little about what your business actually needs, so blindly following what everyone else is doing is how you end up paying for a model that doesn’t fit.
The more revealing trend is the one that doesn’t make the headlines. According to a recent Barclays CIO Survey, 86% of CIOs planned to move at least some public cloud workloads back to private cloud or on-premises infrastructure, the highest figure ever recorded. These are the businesses that already migrated, now correcting course.
That isn’t a reason to avoid the cloud. An IDC survey found only around 8% of organisations are moving everything off of it, so this is selective repositioning, not a retreat. The real question was never cloud or no cloud. It’s which workloads belong where.
The on-premise vs cloud debate is usually framed as a winner and a loser. In reality, each model trades one set of advantages for another, and the right fit depends on which of these matters most to your business.
No model wins outright. The right answer tracks how your business actually operates, not which option sounds most modern.
Hybrid gets described as “some of both”, which makes it sound like a compromise nobody quite committed to. It isn’t. ‘Hybrid cloud’ means deliberately placing each workload where it makes the most sense, rather than forcing everything into one environment to keep things tidy.
In practice, that usually looks like:
Far from being a fence-sit, this is now the mainstream approach. Flexera’s 2026 State of the Cloud Report found that 73% of organisations now operate hybrid estates, making it the leading model.
The advantage is that you stop paying a premium for someone else’s hardware on workloads that never needed it, while still getting cloud flexibility where it genuinely pays off. The catch is that hybrid only works when someone has actually mapped which workloads belong where. Done without that thinking, it becomes two environments to manage instead of one, and none of the saving.
A migration checklist usually asks whether you’re ready to move. The more useful question for most SMEs is a different one: which model, for which workload, and why. These are the questions that decide that:
If those answers aren’t clear, your next step should be getting an impartial view of which one fits before budget and momentum make the choice for you.
Most migration regret traces back to a handful of avoidable mistakes:
Get those five right and migration stops being a gamble. It becomes a decision you can stand behind.
Before you even consider deciding between on-prem, hybrid, or full cloud, the place to start is with a look at your own workloads, costs, and obligations. Then you’re in a much better position to choose the model that fits, which for a lot of London SMEs turns out to be a considered version of hybrid rather than an all-or-nothing move.
At 4TC Solutions, we help you assess what should move, what shouldn’t, and what it will genuinely cost before anything changes. Not sure whether on-prem, hybrid, or full cloud is right for your business? Explore our Cloud Computing services to talk it through.
Is hybrid cloud actually cheaper than going fully cloud?
It can be, because you keep steady, predictable systems on hardware you already own and only pay cloud rates for the workloads that genuinely benefit from them. The saving depends on someone mapping which workloads belong where, rather than splitting things down the middle and hoping.
Do we have to migrate everything at once?
No, and the strongest migrations rarely do. Moving in stages lets you prove the model on lower-risk systems first while keeping control of cost and disruption. Deciding what to leave in place is as much a part of the plan as deciding what to move.
Can we move a workload back on-premise if the cloud doesn’t work out?
Yes, and plenty of businesses do exactly that. It’s worth pricing that exit before you migrate, though, because bringing a workload back is usually harder and more expensive than moving it out in the first place.
How do we know which model is right for our business?
Start with your own usage patterns, compliance needs, and growth plans rather than what similar businesses have done. If the answer still isn’t obvious, an impartial assessment will settle it faster and more cheaply than a vendor comparison ever will.

Compare a £9,000 server quote against a cloud subscription costing a few hundred pounds a month, and the server looks cheaper. That comparison leaves out most of what determines real cloud computing costs and most of what a physical server costs to run over time. Power, cooling, support contracts and the hardware refresh that comes round on schedule all add up. Here is what the fuller picture looks like for a London business weighing up the two.
The server costs UK businesses often miss
A server quote covers the hardware itself, not what it costs to run for the next five years.
Power is one of the first costs people miss. A small server room can easily add a couple of thousand pounds a year to the electricity bill once you count the servers themselves and the extra cooling they need. UK businesses have been paying around 24p per kWh for electricity in early 2026, according to the government’s Quarterly Energy Prices data.
Ongoing support contracts rarely make it into the first comparison. Manufacturers typically charge for hardware support every year, and that can easily add another one or two thousand pounds on top. Warranty and firmware support usually only lasts three to five years, so once that support runs out, so does the vendor’s help with patching security problems.
Downtime is the hardest cost to put a number on and the easiest to underestimate. If a single server fails, how quickly the business is back up depends on how recent the last backup was and whether a replacement part is ready to go.
How IaaS pricing works
Most IaaS subscriptions are billed on what is called pay as you go. The bill reflects what gets used each month. A fixed asset in a cupboard costs the same whether it is busy or not. Microsoft’s own pricing documentation for Azure describes this as the standard model for virtual machines and storage, with lower rates available for workloads that run all the time. That matters for planning. A business with steady, constant demand can lock in a lower rate, while one with occasional spikes only pays for the extra capacity when it needs it.
What is included in that monthly fee differs by provider. A typical hosting subscription, such as 4TC’s IT as a Service, usually bundles the servers and storage with backup and a level of redundancy already built in. Patching is often included too. Power and cooling become the provider’s problem rather than the client’s, which is one reason a cloud quote can look more expensive per month than the fuller picture on the other side.
What cloud computing costs look like over five years
For a typical small office setup, the numbers can look something like this.
| Physical servers | IaaS subscription | |
| Setup cost | Around £9,000 | None |
| Running costs per year | Around £3,600 | Included in the monthly fee |
| Total over five years | Around £27,000 | Around £22,500 |
That running cost for physical servers also assumes nothing goes wrong. It does not include the extra time and cost of managing backup and patching in house, which is usually already included in a hosted subscription.
The difference between the two totals is not huge, and that is the point. A realistic cloud migration ROI rarely shows a dramatic difference. What changes is the shape of the spending. One option means a lump sum followed by a repeat purchase down the line. The other means one predictable monthly cost with nothing to repeat. Businesses that prefer predictable costs, or that are close to their next hardware refresh, tend to see the clearer benefit.
Other factors worth weighing up
Cloud computing costs are only one part of the comparison. A physical server is sized for what the business needs right now. Scaling it up usually means another order and another wait for delivery. A hosted setup can usually be resized within hours, so a business taking on new work is not stuck waiting for procurement to catch up.
Security works in a similar way. The National Cyber Security Centre’s cloud security guidance explains the shared responsibility model behind most hosted IT services. The provider looks after the physical infrastructure. The client is still responsible for setting up access and data correctly. That does not remove the client’s own responsibilities, but it does mean the physical security of the data centre and the patching of the platform are looked after by a team whose full-time job is exactly that.
Backup and recovery is often where the difference is biggest in practice. The government’s most recent Cyber Security Breaches Survey found only 44% of small businesses currently have a continuity plan that covers this kind of disruption, down from 53% the year before. Recovery for a physical server depends on backups being current and stored somewhere other than the server that just failed. Hosted setups, such as 4TC’s disaster recovery service, tend to build this kind of redundancy in as standard, so it is not something a business has to design and pay for separately.
When your own server can still make sense
A physical server is not the wrong choice for every business. A business that bought its hardware recently and still has a warranty left has little financial reason to move, as long as the workload stays steady. Specialist software tied to a particular local setup can also be harder to move than an ordinary file server. Businesses with specific data residency needs may also find that having physical control over where information sits matters more than the monthly running cost.
The right setup usually depends on where a business sits in its own hardware cycle. A general rule that cloud is always cheaper misses the timing question. Timing changes the maths. The closer a business is to its next hardware refresh, the stronger the case for costing out the alternative before signing off on another purchase.
If your last server purchase is closer to its replacement date than its first birthday, this is worth costing out properly using your own numbers, with an example like the one above only as a starting point. 4TC works with businesses across London and Essex on this exact kind of comparison, looking at real usage and support needs alongside list prices.
4TC can put together a tailored comparison between the cloud and physical servers for your own business. Get in touch to find out what that would look like in practice.

Most businesses are running IT built for a version of themselves that doesn’t exist anymore.
The server sits in the cupboard, or the cloud bill arrives on the same date every month, and nobody gives it a second thought. It was sized correctly once. That was the job. Whether it still fits the business running today is a different question, and it’s one most London small and mid-sized enterprises (SMEs) haven’t asked in years.
Some are running physical servers bought for a “just in case” scenario that never quite arrived. Others migrated to the cloud a while back and haven’t revisited the setup since. Either way, the bill tends to reflect a decision made in the past rather than the business as it operates now.
Here’s how to work out where you stand and what Infrastructure as a Service (IaaS), on-demand IT, and scalable infrastructure change once they’re set up properly.
What IaaS Actually Means, in Plain Terms
IaaS is the model where you rent computing power, storage, and networking from a provider instead of buying and housing the physical kit yourself.
Think of it as the difference between owning a server room and renting exactly the amount of server you need for exactly as long as you need it. Practically, that means:
With traditional infrastructure, you buy for the peak and live with the spare capacity the rest of the year. With IaaS, resources can be added or released as demand actually changes, and you’re billed accordingly.
Signs You’re Over-Provisioned (or Under-Provisioned) Right Now
Most businesses fall into one of two camps, and both are more common than owners assume. Look out for:
The first two point to over-provisioning. The last three points to under-provisioning. Either way, the root cause is usually infrastructure sized once and never revisited.
According to recent industry data, estimated wasted cloud spend rose to 29% this year, the first increase in five years, as AI workloads and newer cloud services make usage harder to forecast.
Even businesses that have already moved to the cloud can drift into paying for capacity they aren’t using, which is exactly why a setup reviewed once and left alone tends to become expensive over time.
How Scalable Infrastructure Handles Growth, Seasonal Spikes, and Downsizing
Scalable IT in London means your infrastructure moves with the business rather than sitting fixed until someone notices it doesn’t fit anymore. In practice, that looks like:
This is the core advantage of on-demand IT over a fixed server estate. That means capacity becomes a dial you can turn instead of being fixed on the day the kit was installed.
Cost Comparison: Fixed On-Premise Spend vs Pay-for-What-You-Use Cloud
On-premise infrastructure asks you to commit upfront. You’re covering the hardware itself plus the physical footprint needed to run it, sized to handle the busiest day the business might ever have, and then living with that outlay every day it isn’t needed.
A five-year server replacement cycle and ongoing maintenance contracts sit on top, regardless of how much the kit actually gets used.
Cloud infrastructure runs on a different model. With IaaS, you’re billed monthly for what you consume, there’s no large hardware purchase to plan around, and the provider handles maintenance and refreshes as part of the service.
This is what makes on-demand IT appealing for growing businesses: costs move with the business rather than sitting fixed at whatever number made sense when the servers were bought. The practical differences usually come down to the following:
Neither model wins outright. Stable, predictable workloads can make on-premise spend perfectly reasonable, but seasonal or growing demand usually favours cloud, since costs track how the business operates.
The real test behind scalable IT in London is infrastructure that flexes with you, rather than a figure decided years ago.
Questions to Ask Before Migrating
Not sure if your infrastructure matches what your business really needs? Get in touch with us to find out more about 4TC’s IT as a Service.
FAQs

Every Microsoft 365 subscription comes with a set of security tools built in. Most of them sit there unused.
It’s an easy thing to miss. You buy the licence, set up the mailboxes, the team gets going, and somewhere along the way you assume the protection came bundled in. Some of it did. Plenty of it’s still sitting there, waiting for someone to switch it on.
For SMEs running Microsoft 365 across London and the surrounding area, that gap matters. You are paying for capability you may not be using, and the unused parts are often the ones that would stop an attacker getting in.
A Microsoft 365 subscription goes beyond email and Office apps. Depending on your plan, it includes identity protection, access controls, threat policies and audit tools that many businesses never touch.
Microsoft runs a shared responsibility model, meaning they keep the platform itself patched and available while you configure what happens inside your own tenant, including who can sign in and what they can reach.
Default settings are designed for a smooth start rather than a hardened finish, so the tools you have paid for tend to stay in their out-of-the-box state. The ones most often left untouched include:
None of these draw attention to themselves, which is why the gap goes unnoticed for months.
MFA is one of the most effective controls available to a Microsoft 365 tenant, and it’s included in every plan. But it’s still not switched on everywhere it should be.
Part of the reason is friction. Enforcing it for every user takes a deliberate decision, and there is usually one account, often an admin or a senior leader, that someone decides to leave exempt. That exemption tends to be precisely the account an attacker wants.
This matters because of how most breaches begin. The government’s Cyber Security Breaches Survey 2025/2026 found that phishing was the most common type of attack, experienced by 38% of businesses.
Phishing works by capturing a password. With MFA enforced, that stolen password on its own isn’t enough to get anyone in.
Beyond MFA, a handful of areas build up risk over time without anyone deciding they should:
Each of these is manageable once someone has eyes on it. The difficulty is that they rarely get reviewed once the initial setup is done.
Even a well-configured tenant has its blind spots. It only sees what goes inside it, so it has no way of knowing when one of your staff has had a password caught up in a breach elsewhere on the internet.
Reused passwords are more common than you think. When a member of staff uses the same password for a work account and a personal account that later gets breached, those stolen credentials end up traded on the dark web. From there they get tested against business logins in bulk.
Dark web and credential monitoring watches for your domain and your users’ details appearing in known breach data. Paired with Microsoft 365, it means a leaked password can be flagged and reset before it is used against you.
This is the layer that connects what Microsoft 365 protects with what is happening beyond it.
Just because your tenant is configured well today doesn’t mean it can’t be exposed within a year. Staff join and leave, new apps get adopted, permissions get granted for a one-off task and never removed, and Microsoft changes its own features and defaults along the way.
Getting the most from Microsoft 365 depends on treating cyber security as something maintained on an ongoing basis. In practice that means the following:
At 4TC, we work with SMEs across London and Hertfordshire to keep Microsoft platforms secure and well managed, so the tools you are paying for stay switched on and doing their job as the business grows.
Want to make sure your Microsoft 365 environment is properly configured and protected? Speak to the 4TC team today. We work with SMEs across London and Hertfordshire to keep Microsoft platforms secure and well managed.

It all looked right. The logins worked, email started flowing, the files moved across without a hitch, and Microsoft 365 was declared ready to go.
That moment, when everything works and nobody touches the settings again, is exactly where the risk begins.
Microsoft 365 is one of the most capable platforms a small business can run on. It’s also one of the most heavily targeted, and the version most London SMEs are actually running isn’t configured to defend itself the way its owners assume it is.
Let’s explore the common misconfigurations and how Microsoft 365 security can be kept in good shape with the right managed IT in London behind it.
A Microsoft 365 licence gives you the tools to be secure, but it does not switch them all on for you.
Microsoft operates a shared responsibility model. That means they keep the platform itself running and patched, but everything inside your tenant is yours to configure. This includes who can log in, how they prove it’s them, what can be shared externally, and which old protocols stay open.
Default settings are built for a smooth start. Hardening the environment tends to add small frictions, so it rarely happens on its own. A few things are commonly left in their out-of-the-box state:
None of these announce themselves, which is precisely why the gaps go unnoticed.
These issues show up repeatedly across London businesses, but they’re rarely the result of carelessness. They’re usually the natural consequence of a setup that was done once and never revisited.
From April 2026, the UK’s Cyber Essentials scheme made MFA mandatory across every cloud service that supports it, Microsoft 365 included.
Under the updated v3.3 requirements, a single in-scope account without MFA is now an automatic fail. The change, set by the NCSC and administered by IASME, reflects how routinely unprotected cloud logins are still being exploited.
The usual suspects include the following:
Attackers think in terms of effort. Microsoft 365 is appealing because so many tenants look almost identical, so a technique that works against one often works against hundreds.
Automated tooling sweeps thousands of targets at once, which is how a small London business ends up caught in the same net as a large one. Attackers often probe for:
The reassuring part is that the most common entry point is also the most preventable. Identity attacks are usually password-based, so properly enforced MFA shuts out the vast majority of them.
Security drifts over time as your staff, tools and work processes change. That’s why it’s so important to regularly review your Microsoft 365 environment.
Proactive managed IT in London turns security into an ongoing discipline. In practice, that means:
At 4TC, we work with businesses across London and Hertfordshire to keep Microsoft 365 secure as standard practice, so the environment stays hardened as the business grows and changes.
You don’t need to be technical to get a rough sense of where you stand. Run through these questions:
If you hesitated on any of these, that is your starting point.
Not sure if your Microsoft 365 setup is as secure as it should be? Get in touch with the team at 4TC for a no-obligation review.


Email: support@4tc.co.uk
Tel: 020 7250 3840
5th Floor, 167‑169 Great Portland Street
London
W1W 5PF
Thremhall Park
Start Hill
Bishops Stortford
CM22 7WE

