Latest News for 4TC
We have loads to say!
We have loads to say!
Compare a £9,000 server quote against a cloud subscription costing a few hundred pounds a month, and the server looks cheaper. That comparison leaves out most of what determines real cloud computing costs and most of what a physical server costs to run over time. Power, cooling, support contracts and the hardware refresh that comes round on schedule all add up. Here is what the fuller picture looks like for a London business weighing up the two.
The server costs UK businesses often miss
A server quote covers the hardware itself, not what it costs to run for the next five years.
Power is one of the first costs people miss. A small server room can easily add a couple of thousand pounds a year to the electricity bill once you count the servers themselves and the extra cooling they need. UK businesses have been paying around 24p per kWh for electricity in early 2026, according to the government’s Quarterly Energy Prices data.
Ongoing support contracts rarely make it into the first comparison. Manufacturers typically charge for hardware support every year, and that can easily add another one or two thousand pounds on top. Warranty and firmware support usually only lasts three to five years, so once that support runs out, so does the vendor’s help with patching security problems.
Downtime is the hardest cost to put a number on and the easiest to underestimate. If a single server fails, how quickly the business is back up depends on how recent the last backup was and whether a replacement part is ready to go.
How IaaS pricing works
Most IaaS subscriptions are billed on what is called pay as you go. The bill reflects what gets used each month. A fixed asset in a cupboard costs the same whether it is busy or not. Microsoft’s own pricing documentation for Azure describes this as the standard model for virtual machines and storage, with lower rates available for workloads that run all the time. That matters for planning. A business with steady, constant demand can lock in a lower rate, while one with occasional spikes only pays for the extra capacity when it needs it.
What is included in that monthly fee differs by provider. A typical hosting subscription, such as 4TC’s IT as a Service, usually bundles the servers and storage with backup and a level of redundancy already built in. Patching is often included too. Power and cooling become the provider’s problem rather than the client’s, which is one reason a cloud quote can look more expensive per month than the fuller picture on the other side.
What cloud computing costs look like over five years
For a typical small office setup, the numbers can look something like this.
| Physical servers | IaaS subscription | |
| Setup cost | Around £9,000 | None |
| Running costs per year | Around £3,600 | Included in the monthly fee |
| Total over five years | Around £27,000 | Around £22,500 |
That running cost for physical servers also assumes nothing goes wrong. It does not include the extra time and cost of managing backup and patching in house, which is usually already included in a hosted subscription.
The difference between the two totals is not huge, and that is the point. A realistic cloud migration ROI rarely shows a dramatic difference. What changes is the shape of the spending. One option means a lump sum followed by a repeat purchase down the line. The other means one predictable monthly cost with nothing to repeat. Businesses that prefer predictable costs, or that are close to their next hardware refresh, tend to see the clearer benefit.
Other factors worth weighing up
Cloud computing costs are only one part of the comparison. A physical server is sized for what the business needs right now. Scaling it up usually means another order and another wait for delivery. A hosted setup can usually be resized within hours, so a business taking on new work is not stuck waiting for procurement to catch up.
Security works in a similar way. The National Cyber Security Centre’s cloud security guidance explains the shared responsibility model behind most hosted IT services. The provider looks after the physical infrastructure. The client is still responsible for setting up access and data correctly. That does not remove the client’s own responsibilities, but it does mean the physical security of the data centre and the patching of the platform are looked after by a team whose full-time job is exactly that.
Backup and recovery is often where the difference is biggest in practice. The government’s most recent Cyber Security Breaches Survey found only 44% of small businesses currently have a continuity plan that covers this kind of disruption, down from 53% the year before. Recovery for a physical server depends on backups being current and stored somewhere other than the server that just failed. Hosted setups, such as 4TC’s disaster recovery service, tend to build this kind of redundancy in as standard, so it is not something a business has to design and pay for separately.
When your own server can still make sense
A physical server is not the wrong choice for every business. A business that bought its hardware recently and still has a warranty left has little financial reason to move, as long as the workload stays steady. Specialist software tied to a particular local setup can also be harder to move than an ordinary file server. Businesses with specific data residency needs may also find that having physical control over where information sits matters more than the monthly running cost.
The right setup usually depends on where a business sits in its own hardware cycle. A general rule that cloud is always cheaper misses the timing question. Timing changes the maths. The closer a business is to its next hardware refresh, the stronger the case for costing out the alternative before signing off on another purchase.
If your last server purchase is closer to its replacement date than its first birthday, this is worth costing out properly using your own numbers, with an example like the one above only as a starting point. 4TC works with businesses across London and Essex on this exact kind of comparison, looking at real usage and support needs alongside list prices.
4TC can put together a tailored comparison between the cloud and physical servers for your own business. Get in touch to find out what that would look like in practice.

Most businesses are running IT built for a version of themselves that doesn’t exist anymore.
The server sits in the cupboard, or the cloud bill arrives on the same date every month, and nobody gives it a second thought. It was sized correctly once. That was the job. Whether it still fits the business running today is a different question, and it’s one most London small and mid-sized enterprises (SMEs) haven’t asked in years.
Some are running physical servers bought for a “just in case” scenario that never quite arrived. Others migrated to the cloud a while back and haven’t revisited the setup since. Either way, the bill tends to reflect a decision made in the past rather than the business as it operates now.
Here’s how to work out where you stand and what Infrastructure as a Service (IaaS), on-demand IT, and scalable infrastructure change once they’re set up properly.
What IaaS Actually Means, in Plain Terms
IaaS is the model where you rent computing power, storage, and networking from a provider instead of buying and housing the physical kit yourself.
Think of it as the difference between owning a server room and renting exactly the amount of server you need for exactly as long as you need it. Practically, that means:
With traditional infrastructure, you buy for the peak and live with the spare capacity the rest of the year. With IaaS, resources can be added or released as demand actually changes, and you’re billed accordingly.
Signs You’re Over-Provisioned (or Under-Provisioned) Right Now
Most businesses fall into one of two camps, and both are more common than owners assume. Look out for:
The first two point to over-provisioning. The last three points to under-provisioning. Either way, the root cause is usually infrastructure sized once and never revisited.
According to recent industry data, estimated wasted cloud spend rose to 29% this year, the first increase in five years, as AI workloads and newer cloud services make usage harder to forecast.
Even businesses that have already moved to the cloud can drift into paying for capacity they aren’t using, which is exactly why a setup reviewed once and left alone tends to become expensive over time.
How Scalable Infrastructure Handles Growth, Seasonal Spikes, and Downsizing
Scalable IT in London means your infrastructure moves with the business rather than sitting fixed until someone notices it doesn’t fit anymore. In practice, that looks like:
This is the core advantage of on-demand IT over a fixed server estate. That means capacity becomes a dial you can turn instead of being fixed on the day the kit was installed.
Cost Comparison: Fixed On-Premise Spend vs Pay-for-What-You-Use Cloud
On-premise infrastructure asks you to commit upfront. You’re covering the hardware itself plus the physical footprint needed to run it, sized to handle the busiest day the business might ever have, and then living with that outlay every day it isn’t needed.
A five-year server replacement cycle and ongoing maintenance contracts sit on top, regardless of how much the kit actually gets used.
Cloud infrastructure runs on a different model. With IaaS, you’re billed monthly for what you consume, there’s no large hardware purchase to plan around, and the provider handles maintenance and refreshes as part of the service.
This is what makes on-demand IT appealing for growing businesses: costs move with the business rather than sitting fixed at whatever number made sense when the servers were bought. The practical differences usually come down to the following:
Neither model wins outright. Stable, predictable workloads can make on-premise spend perfectly reasonable, but seasonal or growing demand usually favours cloud, since costs track how the business operates.
The real test behind scalable IT in London is infrastructure that flexes with you, rather than a figure decided years ago.
Questions to Ask Before Migrating
Not sure if your infrastructure matches what your business really needs? Get in touch with us to find out more about 4TC’s IT as a Service.
FAQs

Every Microsoft 365 subscription comes with a set of security tools built in. Most of them sit there unused.
It’s an easy thing to miss. You buy the licence, set up the mailboxes, the team gets going, and somewhere along the way you assume the protection came bundled in. Some of it did. Plenty of it’s still sitting there, waiting for someone to switch it on.
For SMEs running Microsoft 365 across London and the surrounding area, that gap matters. You are paying for capability you may not be using, and the unused parts are often the ones that would stop an attacker getting in.
A Microsoft 365 subscription goes beyond email and Office apps. Depending on your plan, it includes identity protection, access controls, threat policies and audit tools that many businesses never touch.
Microsoft runs a shared responsibility model, meaning they keep the platform itself patched and available while you configure what happens inside your own tenant, including who can sign in and what they can reach.
Default settings are designed for a smooth start rather than a hardened finish, so the tools you have paid for tend to stay in their out-of-the-box state. The ones most often left untouched include:
None of these draw attention to themselves, which is why the gap goes unnoticed for months.
MFA is one of the most effective controls available to a Microsoft 365 tenant, and it’s included in every plan. But it’s still not switched on everywhere it should be.
Part of the reason is friction. Enforcing it for every user takes a deliberate decision, and there is usually one account, often an admin or a senior leader, that someone decides to leave exempt. That exemption tends to be precisely the account an attacker wants.
This matters because of how most breaches begin. The government’s Cyber Security Breaches Survey 2025/2026 found that phishing was the most common type of attack, experienced by 38% of businesses.
Phishing works by capturing a password. With MFA enforced, that stolen password on its own isn’t enough to get anyone in.
Beyond MFA, a handful of areas build up risk over time without anyone deciding they should:
Each of these is manageable once someone has eyes on it. The difficulty is that they rarely get reviewed once the initial setup is done.
Even a well-configured tenant has its blind spots. It only sees what goes inside it, so it has no way of knowing when one of your staff has had a password caught up in a breach elsewhere on the internet.
Reused passwords are more common than you think. When a member of staff uses the same password for a work account and a personal account that later gets breached, those stolen credentials end up traded on the dark web. From there they get tested against business logins in bulk.
Dark web and credential monitoring watches for your domain and your users’ details appearing in known breach data. Paired with Microsoft 365, it means a leaked password can be flagged and reset before it is used against you.
This is the layer that connects what Microsoft 365 protects with what is happening beyond it.
Just because your tenant is configured well today doesn’t mean it can’t be exposed within a year. Staff join and leave, new apps get adopted, permissions get granted for a one-off task and never removed, and Microsoft changes its own features and defaults along the way.
Getting the most from Microsoft 365 depends on treating cyber security as something maintained on an ongoing basis. In practice that means the following:
At 4TC, we work with SMEs across London and Hertfordshire to keep Microsoft platforms secure and well managed, so the tools you are paying for stay switched on and doing their job as the business grows.
Want to make sure your Microsoft 365 environment is properly configured and protected? Speak to the 4TC team today. We work with SMEs across London and Hertfordshire to keep Microsoft platforms secure and well managed.

It all looked right. The logins worked, email started flowing, the files moved across without a hitch, and Microsoft 365 was declared ready to go.
That moment, when everything works and nobody touches the settings again, is exactly where the risk begins.
Microsoft 365 is one of the most capable platforms a small business can run on. It’s also one of the most heavily targeted, and the version most London SMEs are actually running isn’t configured to defend itself the way its owners assume it is.
Let’s explore the common misconfigurations and how Microsoft 365 security can be kept in good shape with the right managed IT in London behind it.
A Microsoft 365 licence gives you the tools to be secure, but it does not switch them all on for you.
Microsoft operates a shared responsibility model. That means they keep the platform itself running and patched, but everything inside your tenant is yours to configure. This includes who can log in, how they prove it’s them, what can be shared externally, and which old protocols stay open.
Default settings are built for a smooth start. Hardening the environment tends to add small frictions, so it rarely happens on its own. A few things are commonly left in their out-of-the-box state:
None of these announce themselves, which is precisely why the gaps go unnoticed.
These issues show up repeatedly across London businesses, but they’re rarely the result of carelessness. They’re usually the natural consequence of a setup that was done once and never revisited.
From April 2026, the UK’s Cyber Essentials scheme made MFA mandatory across every cloud service that supports it, Microsoft 365 included.
Under the updated v3.3 requirements, a single in-scope account without MFA is now an automatic fail. The change, set by the NCSC and administered by IASME, reflects how routinely unprotected cloud logins are still being exploited.
The usual suspects include the following:
Attackers think in terms of effort. Microsoft 365 is appealing because so many tenants look almost identical, so a technique that works against one often works against hundreds.
Automated tooling sweeps thousands of targets at once, which is how a small London business ends up caught in the same net as a large one. Attackers often probe for:
The reassuring part is that the most common entry point is also the most preventable. Identity attacks are usually password-based, so properly enforced MFA shuts out the vast majority of them.
Security drifts over time as your staff, tools and work processes change. That’s why it’s so important to regularly review your Microsoft 365 environment.
Proactive managed IT in London turns security into an ongoing discipline. In practice, that means:
At 4TC, we work with businesses across London and Hertfordshire to keep Microsoft 365 secure as standard practice, so the environment stays hardened as the business grows and changes.
You don’t need to be technical to get a rough sense of where you stand. Run through these questions:
If you hesitated on any of these, that is your starting point.
Not sure if your Microsoft 365 setup is as secure as it should be? Get in touch with the team at 4TC for a no-obligation review.

Six months after a member of staff leaves, the login still works. Messages keep landing in an inbox no one reads, and the shared drive shows the same access it did on that final day.
Nobody decided this should happen; it just never got undone, and that is the gap most businesses carry without realising it.
When someone leaves, the energy goes into the handover and the goodbyes. The accounts, devices and permissions they leave behind rarely get the same attention, because nothing visibly breaks when they go.
For SMEs in Bishop’s Stortford and throughout Hertfordshire, managing employee access can easily be overlooked during a hectic week. Treating it as a cyber security and continuity issue, rather than an afterthought, is what closes that gap.
The thing to remember about a leaver’s login is that it doesn’t know its owner has gone.
Email, Microsoft 365, the CRM, shared folders, the accounting platform, and the various SaaS tools picked up along the way – all of these stay exactly as functional the day after someone leaves as the day before, unless somebody steps in to change that.
While an account stays open, it remains a route into business data. The exposure usually takes one of a few forms:
Attackers tend to look for the path of least resistance, and a live login that nobody is watching fits that description well.
The government’s Cyber Security Breaches Survey 2025/2026 found that the proportion of businesses reporting a breach that led to loss of revenue or share value rose from 2% to 5% over the year, with reputational damage climbing from 1% to 3%.
When incidents do bite, they increasingly cost real money and real standing, and unmanaged access is one of the simpler ways to hand an incident the opening it needs.
It would be a mistake to file unmanaged access purely under cyber security. The fallout reaches into parts of the business that have nothing to do with hackers:
These are continuity issues as much as security ones. A business that cannot reliably account for who holds access to what is a business carrying hidden operational risk.
A decade ago, removing someone’s access mostly meant disabling their network account and collecting their laptop. The perimeter was the office. Today it’s far less tidy, for a few reasons:
The result is that the question “what does this person actually have access to?” has become difficult to answer. It’s that difficulty which is exactly why access control deserves more attention now.
You cannot remove access you don’t know exists, and the modern toolset makes it very easy for access to exist in places nobody is tracking.
There is a part of leaving that often gets missed entirely, which is making sure the business keeps what belongs to it.
Important emails, working files, client records and shared documents need to be transferred into the right hands before or immediately after someone goes. If that does not happen, the knowledge simply leaves with the person.
Think about what tends to sit only in one place:
All of it can vanish into a deactivated account or an unreturned device. Treating handover as a data exercise means deciding in advance where a leaver’s files should end up and who becomes responsible for them.
This protects continuity and keeps you on the right side of your data protection obligations at the same time.
The reason access lingers is often because offboarding gets handled differently each time, depending on who is around and how busy the week is.
Proactive IT support closes that gap by making access management an ongoing discipline rather than a scramble at the point of exit. That means keeping a clear view of who has access, managing permissions, and removing access promptly when someone leaves.
At 4TC, we work with businesses across Bishop’s Stortford and Hertfordshire to keep this consistent as teams grow and change so a departure is handled to the same standard, whoever happens to be managing it that week.
The goal is straightforward. When someone leaves, their access should leave with them, and your data should stay where it belongs.
Former employee access should not become a hidden security risk.
Speak to 4TC about managed IT support that helps keep your systems, data, and users under control. Get in touch today.

When an employee leaves, most businesses know how to handle the paperwork. Final pay is calculated, the P45 goes out, and the leaving card is organised. What happens to their accounts, devices and access rights is usually less organised, and it is the part that creates the most risk.
The window between a resignation date and a fully closed-out account is where former employees, lost devices and forgotten logins can still reach business data. For SMEs in Bishop’s Stortford and across Hertfordshire, where IT teams are often small or outsourced, employee IT offboarding can stretch out longer than anyone intends. The Information Commissioner’s Office expects employers to “document the leavers’ process and regularly check to confirm compliance” as part of basic data protection accountability. In practice, very few small businesses can show what good looks like.
The checklist below sets out the IT steps worth getting right every time someone leaves.
The single most important step is also the most delayed. Every system the leaver touched needs its access revoked on or before their final day – email, Microsoft 365, cloud platforms, CRMs, shared drives, VPNs, accounting tools and any line-of-business applications. That includes the smaller subscriptions as well as the obvious central accounts: design tools, marketing platforms, and anything where someone signed up using their work email.
ICO guidance on access control puts this in straightforward terms: businesses should keep records to demonstrate they “remove access rights in a timely fashion”. The UK government’s Cyber Security Breaches Survey 2024 shows that half of UK businesses experienced a breach or attack in the previous twelve months, and the most disruptive ones tend to involve credentials being misused rather than systems being broken into. Closing accounts promptly is one of the few entirely free controls a business has.
A useful practice is to disable accounts on the last day rather than deleting them immediately. That gives IT time to forward email, archive files and assign ownership of anything that needs to move on, without leaving access open.
Laptops, phones, tablets, monitors, security keys, dongles, chargers and the small mountain of accessories sent out during the hybrid-working era all need to be tracked back in. Without a record of what was issued and to whom, it is difficult to know whether anything is missing until somebody else needs it.
Two things make device recovery less painful. The first is keeping an up-to-date asset register, ideally linked to the standard staff lifecycle process so any new kit is added at the point of issue. The second is having the ability to remotely lock or wipe a device if it is not returned, which is now standard with most modern mobile device management platforms.
This is also the right point to make sure encryption is enabled and verified. A returned laptop with no encryption configured is still a meaningful data risk.
Most leavers will have created or saved files in a mix of locations such as their OneDrive, Teams sites, SharePoint, network shares, sales platforms, or the occasional Dropbox folder. A structured offboarding step should review every shared area the person had access to, transfer ownership of business-critical files, and check that nothing important is sitting somewhere only they could see.
The harder question is what to do about personal storage. If a leaver has used a personal device or a personal cloud account to handle business data, the business needs to know. The ICO’s employment records guidance makes clear that data protection accountability covers all the places business data ends up, not just the ones the employer chose. Asking the question as part of the exit conversation, and following up if anything is found, is part of doing this properly.
Shared logins are a fact of life in small businesses. The marketing inbox, the company social media account, and the supplier portal nobody else has set up a profile for. When somebody leaves, every shared password they knew needs to be changed, and any admin rights they held need to be reviewed and reassigned.
Two specific areas to check: saved passwords in browsers, which can quietly preserve access long after an account is closed, and any password manager memberships the leaver had. If those are left in place, the business can find that the leaver still holds the keys to platforms IT thought had been locked down.
Permissions are worth a wider sweep at the same time. The ICO recommends auditing privileged accounts and assigning end dates to access where it is not needed permanently. Someone leaving is a good moment to look across the rest of the team and confirm nobody else is carrying access they no longer need.
The reason so many small businesses end up with orphaned accounts and unaccounted-for laptops is rarely carelessness. It is that each exit gets handled slightly differently, depending on who is around and how busy the week is. A consistent, written process closes that gap.
A useful baseline is a single checklist that covers accounts, devices, data, passwords and confirmation that each step has been completed and by whom. The checklist should sit with whoever manages the IT function, whether that is an internal lead or an external partner, and trigger automatically when HR confirms a leaver.
When an employee leaves, work through the following:
4TC supports businesses across Bishop’s Stortford and Hertfordshire in setting up structured leaver processes alongside the rest of their IT, so each exit is handled to the same standard without anyone having to remember the steps.
If your business needs a clearer process for removing access, securing devices and protecting company data when staff leave, speak to 4TC about proactive IT support.


Email: support@4tc.co.uk
Tel: 020 7250 3840
5th Floor, 167‑169 Great Portland Street
London
W1W 5PF
Thremhall Park
Start Hill
Bishops Stortford
CM22 7WE

