It is a common understanding that passwords are supposed to protect our accounts. But how much does your designated password protect you and your information? If the bad guys come hacking into your personal and corporate accounts one day, how sure are you that it’s going to be a tough job for them? Let us help you assess how easy it is for a hacker to take a quick guess of your password.

Image

Your password is your first line of defence from wrong doers in the digital world. And yet, it is something that we often overlook and take for granted. When was the last time you spent a dedicated amount of time to think about what password to use for your new account? We often just use a single password across all of our accounts to save us the time and effort. Am I right? This is a definite no-no! Using a single password for all accounts is just making a hacker’s job much easier. So what is the best way to manage passwords and protect your accounts?

In order to plan for an effective account protection strategy, let’s start with a rundown on how hackers guess passwords:

1. Wild guess

 Although you can’t really call it ‘wild.’ These hackers are trained to squeeze the juice out of your public information just to get a list of sophisticated guesses to your password. They use sophisticated programs and procedures to ultimately catch that one ticket into your personal data.

2. Shoulder Surfing

 Sadly there are lurkers who discreetly stick their heads out from behind your shoulder as you type in your password, prying on what you type and browse. Don’t underestimate them: always be cautious of who can see your information in your surroundings.

3. Dictionary-based attacks

 There are some hackers who are so hard working that they would endure matching your personal data with every word in the dictionary. Yes, they exist. They would browse through every possible word to partner with, for example, your birth month, in order to guess your passwords.

4. Phishing

 Be careful of strange emails that you find in your inbox: this might be a phishing attack. They might be schemes sent by scammers who are trying to lure you into clicking and opening malicious files that intend to steal your personal information. As of October 2018, phishing activities has already cost victims $47,676 of loss this year (source: scamwatch.gov.au). So beware of being tricked into opening an email about winning a brand new car and clicking on links.

5. Brute-force Attack

 As the label implies, it’s a pretty vicious attack on your accounts. All the hacking techniques mentioned above are used on your account to track your keystroke and eventually get whatever important data can be stolen from you.

Knowing these hacking strategies and your current password choices, can you confidently say that your accounts are safe? Now that you already have an idea how cyber criminals do it, here are some ways on how you can minimise your risks: 

Password Security Tips

1. Create a password with at least 8 characters.

I know people will usually recommend starting at 6 but, it wouldn’t hurt to add in two more characters if it means increasing your security because nowadays, the longer your passcode is, the more time a hacker needs to spend cracking their way into your account.

2. Make use of a variety of lowercase and uppercase letters, numbers and special characters.

To make it harder to track and follow your keystrokes, you might want to utilise as much letters and characters as you can.

3. Never use your personal data in your password. Remember how hackers can ‘guess’ well?

Remember that most of the time, the people who are trying to hack their way into your account already know enough about you. Don’t use a word or phrase that can be obviously related to you.

4. It’s better if you don’t use real words.

What I mean by this is that you can use words that are hard to “guess” and identify. Maybe use that one phrase you came up with in primary school that nobody understood.

5. Make random patterns that hackers will have a hard time following.

Hackers can track your keystrokes in order to decipher which letters or characters you are constantly using. Making your password random can help minimise the risk of getting your usual password input tracked and followed by cyber criminals. 

You can also have a look at an infographic of an anatomy of a secure account to have a more comprehensive view of how you should be securing your accounts.

Credit Card 1591492 1920 (2)

Don’t take your password for granted and take the easy way out, rather than thinking of a good one. And if you’re like me who tends to forget anything (and everything), including passwords, there are tons of useful tools and apps that you can use to store your precious security passcodes.

Here are some of the more well known password management programs.

1. LastPass

One of the top on the list of best password managers. It features advanced hashing that provides a secure haven for your passwords. It runs across a wide range of operating systems and is free of charge unless you want to buy Premium subscription. Having the free version is not bad at all with 2 Factor Authentication feature and a password generator.

2. Dashlane

Aside from keeping your password safe. Dashlane also has a feature called digital wallet where you can safely manage your credit card information so you can securely make online purchases. It also allows you to sync your data to the cloud so you can access your passwords wherever.

3. Sticky Password

It is one of the most user-friendly password applications in the market. It may look a little outdated but works as well as the other ones already mentioned. It provides secure management for an unlimited number of passwords. It is free of charge unless you upgrade to premium then you can sync your data into different devices.

4. bitwarden

It is an open source software (which means it’s free!) that features 2-Factor Authentication, end-to-end encryption and enables syncing to multiple devices without limits. It also boasts a password generator and runs through multiple operating systems.

At Grassroots IT, we recommend the BEST way to protect your accounts is using Multi Factor Authentication (MFA). So that even if the hackers guess your passwords, they still need a real-time authenticator to get into your accounts. Read more about that over here.

It can be easy to overlook such a thing as your account passwords but we really do live so much of our lives online these days, that it’s become increasingly important to be vigilant about protecting our personal information and corporate data. If you need any help setting up some additional security for your personal accounts, don’t hesitate to make a time with us.

Back to more news, updates and resources or learn more about Cybersecurity

Tips for installing Word and Excel

A lot of Microsoft Office 365 plans include what’s called Desktop Licensing. This is the bit that lets you install the Microsoft Office applications such as Word and Excel on your computer. In this post we show you how to install Office 365 on your computer.

1. Sign in with your work or school account at https://portal.office.com/OLS/MySoftware.aspx.

Note: If you don’t see Office listed, your plan probably doesn’t include Office applications. If you know your plan includes Office, you may not have a license assigned. See What Office 365 product or license do I have? If Office is not listed, ask your Office 365 administrator to assign a license to you.

2. On the Office page, set-up which version of Office 2019 you want to install. By default, the 64-bit version is selected. You can change this by clicking on the drop-down box under Version.

Install O365

IMPORTANT: The process that installs Office 2019 also uninstalls all Office 2016 products. If you previously have the 32-bit version of Office installed, you should first uninstall this version before upgrading to the 64-bit version.

If you’re not sure which version you currently use, have a look at What version of Office am I using? or if you’d like to know which version you should install, read on Choose between the 64-bit or 32-bit version of Office.

3. Select a preferred Language from the drop down list under Language.

Install O365 Lang
  1. Select Install.
  2. Depending on your browser, go to the install pop-up that appears then click:
  • Run (in Internet Explorer)
  • Setup (in Chrome) or;
  • Save File (in Firefox)

NOTE: If you’re using Edge, first click Save, and then click Run.

444

If you see the User Account Control prompt that says, “Do you want to allow this app to make changes to your device?” Click Yes.

6. The install begins…

555

7. Your installation of Microsoft Office 365 is finished when you see the phrase, “You’re all set! Office is installed now”and an animation plays to show you where to find your Office applications on your computer. Follow the instructions in the window.
For example Click Start > All Appsto see where your apps are, and select Close.

66 Office

8. Start using an Office application right away by opening any app such as Word or Excel. In most cases, Office is activated once you start an application and after you agree to the License terms agreement by clicking Accept.

777777777

Now you’re ready to use Office 365!

A quick recap of the steps for installing Office 365

  1. Sign in with your work or school account.
  2. On the Office page, set-up which version of Office 2019 you want to install.
  3. Select a preferred Language.
  4. Select Install.
  5. Depending on your browser, go to the install pop-up that appears.
  6. The install begins…
  7. Your installation of Microsoft Office 365 is finished when you see the phrase, “You’re all set! Office is installed now”
  8. Start using an Office application right away by opening any app such as Word or Excel.

If you’re curious as to how other successful businesses utilise the Office 365 suite to the best of their advantage, you can head to one of our free webinars by clicking here or if you’re looking for new features and new ways to work your way around your freshly installed Office 365, click here.

Right when you need professional assistance in your Office 365 journey, we’d be glad to be there and help! Just reach out to us and let’s talk about how you can make the most out of your Office 365.

Are you ready to get solutions that drive positive change to your business? Reach out to us to know more about how we can build these solutions together.

There is one app on my iPhone that I now simply cannot live without. The app is called Office Lens and it is available for free at the Apple App Store and for your Android phone on Google Play.

In a nutshell, the Office Lens app is a portable scanner in your pocket. Now, these kinds of apps aren’t new. You have Evernote, Scanbot and no doubt a variety of other flavours available to you on your Smartphone but where Office Lens shines is in its tight integration with the Office 365 suite.

If you are rocking Office 365, odds are that you already enjoy the mobility and agility of access to all your documents and productivity applications from anywhere on your phone. Here is another tool in your toolbox to get the most out of the modern workplace.

Practical uses of Office Lens

Here are just some of the ways that I have personally used Office Lens in the past few weeks:

  • At presentations:

I have been fortunate to attend some fascinating road shows hosted by cloud companies who are making fantastic presentations up on the big screen. Problem is, you’re often seated at a weird angle off to the side, right? You will see people snapping pics of the big screen at these kind of events, which is a great way of capturing the information. But, if you are using Office Lens, the image will automatically identify, keystone (correct the angle of the image for ease of viewing) and save with an optimised image where you can store it away in a OneNote file to annotate and comment so that you can more easily document and retain all of the cool stories on display.

  • When collecting business cards:

Collected a pile of business cards at that networking event? Snap them in Office Lens and the app will automatically identify the printed text with optical character recognition (OCR) and generate contacts that you can add right into your phone. Handy.

  • When documenting receipts:

When compiling expenses, having to dig out all those paper receipts can be tedious. Instead of being monopolising the office scanner in a scanning marathon, Office Lens enables you to snap a photo with your phone at the time. Office Lens will automatically crop, enhance and clean up the image and export it to your OneDrive as a PDF document ready to attach to your expense claim. Job done.

Sounds good, right? But how do you do it?

How-to Steps

  1. Install Office Lens on your device. Run the app, then give it permission to access your camera.
  2. The default view is a camera viewfinder. You can select from “Business Card”, “Document”, “Whiteboard” or “Photo” then point the phone at whatever you are wanting to capture.
  3. For Documents or Whiteboards, you’ll see the app attempt to frame the object by detecting the corners. Once it is framed to your satisfaction, snap it.
  4. The app will present you with a preview and give you the option to perfect the layout, be it cropping or rotating the image.
  5. You will be presented with a list of destinations for the image. This is where Lens comes into its own. You can save as: an image to your Photo Gallery, as a PDF to your OneDrive (perfect for those expense reports), to OneNote (perfect for saving presentation slides where you can annotate and comment) and you can even save directly to a Word document or PowerPoint Presentation.
  6. If you are working through multiple slides, or receipts, go ahead and append on the next one.

Have you given Office Lens a run yet? I’d love to hear how you are using it in your business.

4 tips for avoiding an embarrassing mistake

Have you ever experienced that sinking feeling as you realise you have accidentally sent an email to the wrong person?

If you are lucky, it could just be an embarrassing blip on your day, but there is the potential for some very real damage. There is the occasional story on the news, for example the story about the insurance company that accidentally sent out an email dismissing its entire workforce, instead of just firing “Terry from Accounts.”

So yes, sending an email to the wrong person or group can be embarrassing. Fortunately, there are measures you can take to prevent such disasters.

Measure 1: Use Common Sense

Yes. There are measures that you can take to avoid the embarrassing debacle but regardless of the technology, just like it is with cybersecurity the first line of defence should always be you. 

In all cases, you should read the “To”“CC” and “BCC” fields before you click on that Send button. Check what attachments are in the email and give the content in the body a once over. In fact, maybe write the email first and THEN add the addresses carefully at the end. And then double check that you’ve selected the correct email addresses.  

Beware of that ever so helpful feature in Outlook where it autocompletes the address! I was once injected into a river of emails between the management team of a retailer containing discussions about stuff that I really had no business knowing after an employee had unwittingly rapped out “Gary” on their Address field. Even after advising them, I continued to receive emails for some time.  

 Always proof read your emails. 

Measure 2: Delay Sending your emails

A very wise manager I once worked with had an excellent tactic to protect himself against the risk of the wayward email. He would set a rule in his Outlook to delay the transmission of his emails and allow himself some time to review and reflect before he pulled the trigger.

It’s not hard to do, and it can help you from some potential bad news be it an email launched into the wrong inbox, or an email to the right inbox that was banged out in haste.

Let’s guide you through how to do it, step-by-step. 

How to set a rule to delay emails 

1. While composing your message on Outlook, go over the Ribbon and click on the Options 

2 10

2. Under the Options tab, click Delay Delivery

2 10

3. A new window will appear with the delivery properties of your message. You’ll want to go over to the Delivery Option section 

4 5

4. Under Delivery Options, pick a date from the date picker of until when you want to delay your email delivery 

5 1

5. After choosing a day on when your email will be delivered, pick a specific time to send it out 

6 1

6. Close the window by clicking the Close button on the lower right part 

Measure 3: Recall the Message

So, you have checked and double checked, and your email is sitting there in the ‘Sent’ tray.  

You can try to recall the message from the recipients by using the Recall This Message feature in Microsoft Outlook. This lets you recall, replace or delete the messages sent.  

The success or failure of a message being recalled depends largely on their mail system and settings and whether they want to let you recall it, which is probably the single best reason why this method is probably not the best one to use. There’s also the fact that recalling a message will generally inform the recipient that the email exists and highlight the fact that you want to recall it.  

You can think of it like stopping a bullet in flight.  This is one of your last resorts. 

How to recall an email using Outlook

1. From your Sent Items folder, double click the email you’d like to recall.

2. Click on the Actions icon

7 2

3. From the Drop-down menu, click on Recall This Message

4. A dialog box would then appear to confirm how you want to recall your email

9 1

5. You can choose whether you’d like to receive notifications about your recall and track its activity.

6. Close the dialog box by clicking Ok

9 2

7. If you chose to get a notification, you should get an email confirming that the recall process was a success. It should look like this:

12

Measure 4: Disclaimer

Email disclaimers inform recipients about what they can and cannot do with the emails sent from your organisation. In fact, in North America and Europe having an email disclaimer is now a legal requirement, in Australia it’s simply a matter of good sense. 

For sensitive emails, it’s advisable to include a message that states for whom the message is intended and that sharing the content is strictly forbidden. For wayward emails to the random public, a humble request to inform the sender in case the message was intended for someone else will often work.

Here at Grassroots IT we use an excellent tool called Exclaimer! for helping to manage and control the email signatures. It means that we can have a consistent branding for all our email communications and focus on what we like to do, which is to help you do your best work possible through the best possible use of technology. It also means that we can add in and adjust information like disclaimers whenever we need to.

Recalling emails in Outlook is possible, but we recommend it as a last resort. Check, check and recheck before you send: especially if the topic is a bit controversial or includes highly private and confidential information.

For most of us, the goal of achieving Inbox Zero (“a rigorous approach to inbox management, aimed at keeping the inbox empty”) is not an easy task to work on. It’s just a lot to have to go through tons of emails from who-knows-when with the goal of clearing up unwanted emails from your Outlook Inbox then, as soon as you finish halfway through your emails, you start to realise that newer ones are replacing those that you have just removed. So what the heck is the point?

Well, what if I tell you that there’s a way to reduce the amount of redundant emails sitting around your Inbox?

Enter, Microsoft Outlook. There is a feature within Outlook called Conversation Clean Up that helps in clearing out unwanted emails by evaluating the contents of your email conversations. From there, it eliminates any emails with redundant content from previous conversations.

“What the what?!” You might think. Here, let’s go through it in more detail

What is a Conversation?

Does an “email thread” ring a bell? Well that is the quickest definition of an Outlook Conversation. “A Conversation is the complete set of email messages from the first message through all responses. The messages of a Conversation have the same subject.” (source: support.office.com)

Here’s an example, If I send an email to you, then you send me a response with MY original email still attached to YOUR reply then that, my friend, is a Conversation. Here’s a sample image to draw a clearer picture:

Image 12

How do I Use Conversation Clean Up?

This tool is most helpful with your emails that contains a lot of ping-pong responses, especially those with many recipients. Now, how do you utilise this cool Outlook feature?

“I’d like to remove redundant email messages.”

1. Open your Outlook desktop app.

2. Find one of your emails or email folder that has a lot of back and forth responses, open it.

3. Go to the Home tab.

Image 13

4. From the Home tab ribbon, find the Delete group.

Image 14

5. Click on Clean Up (a drop down list will appear).

Image 15

You can select one of the options from the drop-down list:

  • Clean Up Conversation.

This is the option for when you want your current Conversation be reviewed, and redundant messages be deleted.

  • Clean Up Folder.

This option allows you to have all email messages in your selected folder be reviewed, and redundant messages be deleted.

  • Clean Up Folders and Subfolders.

This will allow you to have all email messages in your selected folder and its subfolders be reviewed, and redundant messages be deleted.

Will the cleaned-up emails be permanently deleted?

Not entirely. Once you’ve enabled the Conversation Clean Up on one of your emails, email folders and subfolders, detected redundant messages will be moved to your Deleted folder and not eradicated permanently. If you wish to recover some of the most recently removed emails, you could head to the Deleted folder to find them (although we don’t recommend using your Deleted folder as a storage option!). But remember that the redundant information should still be located in the email you are keeping, that hasn’t been ‘cleaned up.’ 

You can also set an exception for emails that you do not want to be moved out of your main Inbox. You can find more details on how you can customise your options in one of Microsoft’s support docos available on their page.

Here are some bonus tips on how you can achieve Inbox Zero:

There are more ways than one for you to strategize your way to Inbox Zero without having to sacrifice loads of your precious time. Here are a few handy tips:

  1. Always remember that our time is very important.

This may sound cliched but, “Time is Gold.” Especially if you’re running a business, you can’t afford to use up a day or give it an hour just to sort out your overflowing inbox to eliminate the unwanted ones. Ideally, if you make deleting (and unsubscribing from promotional emails you no longer read) a regular habit, it’s less likely you’ll need to deal with tons of emails when you next face your inbox.

  1. Lose your attachment to ‘attachments.’

Do you feel guilty and anxious when asked to get rid of an old email you’re afraid you might need someday because it has a file attached? Just download all the files and links from emails that you find important so they are safely retained, then delete the email. Magic.

  1. Utilise your Outlook tools.

Besides the Conversation Clean Up Tool, there are a lot of tools in Outlook that can help you clean and organise your inbox. You just have to start exploring your Outlook ribbon or head to the handy Outlook help website for more ideas. Or seek for the assistance of your trusted IT partner who can give you pointers on where to find the handy tools. 

  1. Take out the trash right away.

Like your rubbish at home, you wouldn’t want to keep it hidden under the sink for too long. Once you’ve read an email that can be deleted or you’ve finished a conversation, make sure to get rid of it right away to prevent it from being buried under newer emails that will later on make it harder to find. 

Inbox Zero can be a lofty goal, but not unachievable. A daily habit of action to remove unwanted emails and the use of handy tools like Conversation Clean Up can help you keep on top of inbox clutter.

People do business with people, so your profile picture is a great way to represent you and your business. Whenever you send an Outlook email to your contacts, a little circle icon of you should be visible to the recipient and it should be something striking. Who wouldn’t want to look good in their email profile picture, right?

The members of your organisation would appreciate it if they can easily identify you in online collaborations and communication within Office 365. To maintain a personalised touch to your account, you should consider updating your profile picture and we can show you how to do that.

Here’s a video tutorial of how you can easily change your profile photo in Office 365 online:

Here’s another short and simple way to do it:

Update your profile photo in Outlook

1. Find a little circle at the top of the page. That’s where your photo is supposed to be, select it.

Image 6

2. A list of options will appear, hover over the profile photo where you will see a camera icon. Click on it

Image 7

3. A window will appear. Select +Upload a new photo

Image 8

4. Select your favourite photo from your file folders. Click Open

5. After choosing a photo to use, click Apply

Image 9

6. Select Done

Image 10

To recap the steps:

Update your Profile Photo in Outlook

  1. Find a little circle at the top of the page. That’s where your photo is supposed to be, select it.
  2. A list of options will appear, hover over the profile photo where you will see a camera icon. Click on it
  3. Select +Upload a new photo
  4. Select your favourite photo from your file folders. Click Open
  5. After choosing a photo to use, click Apply
  6. Select Done

If you would be needing more help with your Office 365 account, contact your reliable IT partner or don’t hesitate to reach out to us. The #nerdherd would be glad to assist.

Are you ready to get solutions that drive positive change to your business? Reach out to us to know more about how we can build these solutions together.

Learn more about Office 365 and Microsoft 

CEO’s play a vital role in protecting their business from cybersecurity attack, however for many CEO’s, the world of cybersecurity leaves them feeling confused and vulnerable. This is perfectly understandable given the complex and rapidly changing nature of security threats facing all organisations. So how does a CEO properly secure their business? The good news is that there is no need to become a cybersecurity expert! Here are our top 5 cybersecurity tips for CEOs to help their organisation stay safe from online attacks.

#1. Get board level buy-in for cybersecurity

In the past, cybersecurity was a technical IT responsibility. However, cybersecurity has been developing more into a business driver rather than a technology issue for some time. That’s why it’s important to ensure board level buy-in and support.

The main ways that CEOs can gain buy-in from their board are:

  • Quantifying the company’s cyber risk based on budgets
  • Defining a clear return on investment (ROI)

#2. Have a cybersecurity plan in place

A cybersecurity plan is something every staff member, at every level, must be aware of. This means that if a breach occurs, everyone knows what to do.

A cybersecurity plan should include:

  • Security policies, procedures, and controls required to protect the company
  • An outline of the specific steps to take to respond to a breach

This plan can also be called a ‘Crisis Management Plan’, which you can learn more about in our blog ‘5 questions board members need to ask’.

#3. Don’t skimp on your cybersecurity budget

Cybersecurity is not a one-size-fits-all kind of investment. Many companies: especially businesses, Non Profit organisations and start-ups: struggle to make the right security choices. Yet choosing cheaper options will end up costing more in the long term.

Cybersecurity is more than just having anti-virus software in place. The best cybersecurity measures are outlined in the Essential Eight Framework, as identified by the Australia Cyber Security Centre.

Essentially, your cybersecurity needs to cover:

  • Prevention/protection from an attack: aimed at preventing malware delivery and the execution of malicious code
  • Limiting the extent of an attack: aimed at limiting how far an intruder can get
  • Data recovery & system availability: aimed at restoring your data and systems if an attack occurs

#4. Expect to be breached

The chance of experiencing a ransomware breach, so it’s important to quickly identify when an attack has occurred. The sooner a breach has been identified, the better!

The main things for a CEO to understand are:

  • How the company monitors ransomware attacks or breaches
  • How staff report any suspicious activity
  • How a breach is communicated to the rest of the company

#5. Create a culture of awareness

All company departments and employees should be involved in protecting the company’s valuable and sensitive data. Crafting a culture where all employees see themselves as having an active cybersecurity role is the key to addressing an inevitable ransomware attack. It’s important that this culture starts at the top with the CEO.

Three ways to help create this desired culture are:

  • Create a cybersecurity plan that is well known, and referred to often
  • Launch cybersecurity awareness & education initiatives for employees along with regular and ongoing training sessions
  • Emphasise the importance of cybersecurity in all mass-communications with staff

Understanding ransomware and what to do when it occurs is the job of a CEO. By implementing the above 5 cybersecurity tips for CEOs, you will be well on your way to properly protect yourself from a ransomware attack, and ensure your company isn’t tomorrow’s news!

Engaging with an IT partner doesn’t need to be an all-or-nothing exercise. In many cases organisations will partner with an IT provider to work alongside existing in-house IT staff to provide complementary skills and capabilities. When choosing an IT partner to work alongside in-house IT staff it’s important to choose one familiar with a Co-managed IT model to ensure a productive, harmonious engagement.

Here are the top 5 ways that a Co-managed IT partner will be able to work alongside your existing IT staff.

#1. Work with senior business leaders to develop an overarching IT strategy

In some cases, companies may have internal IT staff who are well capable of taking care of day-to-day IT management support and project delivery. Yet senior business leaders may still need additional support in building an overall IT strategy for your IT staff to execute. Choosing a Co-managed IT partner will give you the confidence that your technology is aligned with your long-term business strategy, helping manage growth, improve profit and drive positive change.

#2. Provide ongoing IT management support to help your staff maintain focus and accountability

Companies with in-house IT staff may find there is still a gap in the management and execution of IT strategy into the organisation. Choosing a Co-Manage IT partner who can provide ongoing IT management support will ensure a smooth execution of any agreed IT strategy. Your IT partner will also ensure your IT staff stay focused and accountable on executing IT initiatives throughout the business.

#3. Provide help-desk support to allow in-house IT managers to focus on high value activities

It’s common for existing in-house IT support staff to become consumed with day-to-day help-desk support for staff and clients. This in turn doesn’t give them time to work on bigger picture IT strategies, planning and execution. Partnering with a Co-managed IT provider can help provide help-desk and service desk support for your company, allowing existing in-house resources, whether technical or management, to focus on higher value activities within your organisation.

#4. Deliver IT projects and change initiatives that require specialist skills

A Co-managed IT partner can provide project delivery capabilities to help companies deliver IT initiatives requiring specialist technical skills that your in-house IT staff may not have, such as Microsoft Office 365 migrations and process automation development. These IT capabilities can be complex, and something you want to implement correctly the first time.

#5. Provide escalation support for in-house support staff

In-house IT support staff may manage the incidents and problems that occur in your system, but may not have the higher level technical skills or experience to handle the more complex and involved issues. The right Co-managed IT partner can provide that higher level escalation support, from both a generalist perspective and a more specific product area. For example, in house IT support may handle all day-to-day help-desk requests, and then escalate the more complex or time consuming issues to your Co-managed IT partner.

As you can see, investing in the right Co-managed IT partner can provide additional IT support in a more targeted and specific way, becoming an extension to your IT team. You can never have too much support when it comes to your business IT needs.

Why should board members be concerned about cybersecurity?

A cybersecurity breach can be extremely disruptive and expensive, potentially resulting in significant downtime and lost productivity, permanent loss or public exposure of confidential information, reputational damage and direct financial loss. The potential impact of a security breach could be devastating or potentially fatal to any organisation. That’s why cybersecurity should have oversight at the highest level.
A cybersecurity strategy will also call on resources from across the organisation, including finance, human resources, IT, and operations. To gather this appropriate support and commitment from across the organisation requires a suitably senior authority to champion the cause.

Here are the 5 cybersecurity questions board members need to ask.

#1. What measures are in place to protect the organisation from cyberattack?

Although board members don’t need to have a deep technical knowledge of the organisation’s cybersecurity defences, some understanding of the systems that are in place is important. Equally critical is an understanding of how these systems are resourced and managed on an ongoing basis, as well as how the board will be kept informed.

Cybersecurity is not a “once-and-done” proposition; it’s one that must be actively managed. Are your security measures current and always evolving to keep up with new and more sophisticated threats? Are they being audited regularly to identify gaps and ensure compliance with established standards? Are your systems proactively tested, such as with mock attack scenarios and penetration testing?

#2. How do board members know if a cybersecurity breach has occurred?

In the event of a successful cybersecurity attack against your organisation, a rapid response is critically important to limit the extent of the attack and minimise the potential impact. The longer a successful attack is allowed to remain in place, the further it may spread and the more complex and expensive it may become to resolve.

As a board member you should satisfy yourself that any security breach will be rapidly identified and responded to. Ask:

  • How does the company monitor for cyberattacks and breaches?
  • Are staff appropriately trained to identify and respond to attacks quickly?
  • How do staff report any suspicious activity?

#3. How do we respond in the event of a cybersecurity breach?

Instead of considering how your organisation will respond if a breach occurs, think instead in terms of responding when a breach occurs. Assume that a breach will occur and plan accordingly by having an incident response plan in place.

At a basic level, a cybersecurity incident response plan should include:

  • Formation of an emergency cybersecurity incident response team to manage the incident response.
  • Definitions of what a cybersecurity incident is (and isn’t).
  • An incident response management flowchart to help employees understand the steps to be followed during a cyberattack.
  • Cybersecurity incident response communication templates to help with timely companywide communications for the more severe security breaches.
  • An emergency contact list and communications plan to keep internal and external stakeholders informed and coordinated.

#4. Are response plans in place and tested?

When you’re thinking about how the organisation will respond in the event of a security breach, there are three plans of critical importance. Satisfy yourself that all three plans are in place, and are reviewed and tested on a regular basis.

Backup plan

In many cases, when recovering from a security breach the organisation may need to recover lost or damaged data from backup. The backup plan should detail how the organisation backs up important data, and how often? What is included in the backups? How often are the backups tested? How secure are the backups if a security breach occurs?

Disaster recovery plan

A disaster recovery plan details how the organisation will recover from a disaster, such as a security incident. Disaster recovery will often rely on the backup plan, but will also consider how the backups are to be used, what order systems are to be recovered in, how long recovery efforts may take, and what additional resources may be required, such as new data centre equipment or cloud tenants.

Business continuity plan

A security breach may result in significant disruption to business operations, with key systems rendered useless. A business continuity plan should address how the business may keep operating (even at reduced capacity) while the security incident is addressed and business systems recovered to an operational state.

#5. Will we be covered by cyber-insurance?

Cyber insurance can help not only with the immediate response to an incident, but also with immediate and longer-term recovery efforts. Ensure you understand the scope and limitations of cyber insurance policies, that sufficient coverage is in place, and satisfy yourself that all policy obligations are being met by your organisation to ensure any claims are not denied. Cyber insurance may cover:

  • Loss of revenue due to interrupted business
  • Hiring negotiators
  • Paying a ransom
  • Recovering or replacing your data
  • Legal claims
  • Investigation by a government regulator
  • Copyright infringement
  • Misuse of intellectual property online
  • Crisis management and monitoring

Replacing a phone system is one of those projects that looks simple from the outside. You already pay for Microsoft 365, Microsoft Teams is already open on every desk, and Teams can already make calls. Switching the desk phones off starts to look like a licensing decision rather than a project.

It is not quite that simple, and the gap between “Teams can make calls” and “Teams is our phone system” is where most of the cost and most of the risk sits. This guide covers what a Microsoft Teams phone system actually is, the three ways an Australian business can connect it to the public phone network, what happens when someone dials 000, and when we would tell you to leave your existing system alone.

What is Microsoft Teams Phone?

Teams Phone is a cloud PBX built into the Microsoft Teams app you already use. It gives you what a phone system does: inbound and outbound calls to real phone numbers, transfers, hold, call queues, auto attendants, voicemail, call recording and reporting.

Microsoft has renamed it more than once, which is why the same product turns up as Teams Calling, Teams telephony, Business Voice and a Microsoft Teams phone system. They all describe the same capability, and if you are comparing quotes from different providers it is worth checking they are quoting on the same thing.

The difference from a traditional PBX is that there is no box in a comms cupboard and no fixed relationship between a person and a desk. A user’s number follows their Teams account, so the same number rings on their laptop, their mobile and a desk handset if they have one. For a business with people moving between sites, working from home some days, or out on the road, that is the main practical gain.

Microsoft Teams calling between colleagues has always been free and built in. Teams Phone is what extends that to the outside world.

The part most people miss: the licence is not the phone service

This is the single most common misunderstanding we see, and it is worth being precise about because it drives the budget.

A Teams Phone licence gives you the PBX. It does not give you a connection to the public phone network. Those are two separate purchases, and you need both.

It also is not included in the Microsoft 365 plans most Australian small and mid-sized businesses run on. Business Basic, Business Standard and Business Premium all exclude it. Teams Phone is an add-on licence per user, or it comes bundled inside Microsoft 365 E5 if you are on that plan. So a business on Business Premium moving to Teams Phone is adding a per-user licence cost on top of what it already pays, then adding a calling service on top of that.

Once you have the licence, you choose how calls actually reach the phone network. In Australia there are three options, and the choice matters more than most vendors let on.

Connecting Teams to the phone network: your three options

Microsoft Calling Plan

Microsoft is your telco. You buy the calling minutes and the phone numbers from Microsoft alongside the licence, in the same bill, through the same admin centre.

It is the simplest option to set up and the easiest to explain to a board. The trade-off is flexibility: you get Microsoft’s plans and Microsoft’s numbers on Microsoft’s terms, which can be limiting if you have unusual numbering, existing carrier contracts, or sites that need something specific.

Operator Connect

An Australian carrier remains your telco, but their service plugs directly into Teams. Numbers are provisioned into your tenant by the carrier from the Teams admin centre, without you building anything.

For most businesses in the 30 to 80 user range this is the option we recommend looking at first. You keep a local carrier relationship, local support and local commercial terms, without the engineering overhead of the third option.

Direct Routing

You connect your own carrier to Teams through a Session Border Controller, either one you run or one your provider hosts. This gives you the most control and it is the only option that comfortably handles the complicated cases: keeping an existing SIP trunk contract, integrating with a legacy PBX during a staged migration, unusual dial plans, analogue devices such as lift phones and duress alarms, or multi-site arrangements that need specific routing.

It is also the most work. There is real design and ongoing operational responsibility in a Direct Routing deployment, and it is the option where an unmanaged setup will quietly cause problems eighteen months later.

Which one to choose

 Microsoft Calling PlanOperator ConnectDirect Routing
Who is your telcoMicrosoftYour Australian carrierYour Australian carrier
Setup effortLowestLowHighest
Needs an SBCNoNoYes
Keep an existing carrier contractNoIf they participateYes
Handles analogue devices and legacy PBXNoLimitedYes
Best suited toSimple single-site setupsMost mid-sized businessesComplex or multi-site operations

There is a fourth option, Teams Phone Mobile, where your mobile number becomes your Teams number through a participating carrier. It suits businesses whose people genuinely live on mobiles, and it is worth asking about if that describes your field teams.

Calling 000 from Teams Phone in Australia

This section exists because it is the part of a Teams Phone migration most likely to be skipped, and it is the part with actual consequences.

Australian carriage service providers operate under the Telecommunications (Emergency Call Service) Determination 2019. They must give you access to the emergency call service on 000 and 112, carry the call to the emergency call person (Telstra answers 000 and transfers to police, fire or ambulance), and supply the operator with the best available location information for the service.

For a traditional PBX, “best available location information” was straightforward. The desk phone was bolted to a known building. For a softphone that follows a person between the office, home and a customer site, it is not straightforward at all.

Here is the specific thing Australian businesses need to know. Microsoft publishes how emergency call routing works country by country, and for Australia its documentation states that emergency addresses are configured and routed by the carrier partner. That is different from the way it works in some comparable markets. In Canada and New Zealand, for example, Microsoft’s documentation describes emergency calls being screened to determine the caller’s current location before routing. Australia is a carrier-configured market, so what happens on a 000 call depends on your carrier and how your service was set up, not on a Microsoft default.

The practical consequences:

  • A user working from home may present the registered office address to the 000 operator, because that is the address associated with their number.
  • Dynamic location, where Teams works out where a user is from the network they are connected to, has to be deliberately configured. It relies on an administrator mapping subnets, wireless access points, switches and ports to validated, geo-coded emergency addresses. It does not happen on its own, and a home broadband connection provides none of the network identifiers it depends on.
  • A generic head office address assigned to everyone is unsafe the moment you have a second site.
  • Teams Phone depends on power and internet. A traditional line often survived an outage that will take a cloud phone system down, so critical sites need a deliberate fallback.

None of this is a reason to avoid Teams Phone. It is a reason to make emergency calling a written requirement rather than an assumption. Before you sign, get your carrier to confirm in writing whether 000 is enabled for your numbers, whether emergency addresses are set per user, per number or per site, whether dynamic location is supported on your specific deployment, and what address is presented when a user is away from the office. Then set accurate addresses for every site, and tell your staff to state their exact location to the operator regardless of what the system is expected to send.

Can you keep your existing phone numbers?

Yes, in almost all cases. Australian local number portability means you can bring your existing numbers across, and for most businesses that is non-negotiable because the numbers are on vehicles, signage and ten years of documents.

Two things worth planning for. First, porting is the step most likely to hold up a cutover, particularly where numbers sit across multiple carriers or in an old block nobody has touched for years. Start it early and treat the port date as the real project deadline. Second, if you are using a Microsoft Calling Plan, an emergency address has to be registered against a number when you acquire it from Microsoft or when it ports in, so the emergency address work happens during the port rather than after it.

Where a number cannot port cleanly, the usual fallback is diverting the old service to a new number for a period while you update everything that references it. That works, but it is an ongoing cost until you can retire the old service.

What does Teams Phone cost?

We are not going to publish a per-user figure, because Microsoft’s pricing varies by agreement type and billing term and any number we print here would be wrong within months. Microsoft directs customers to the Microsoft 365 admin centre for the price that applies to their tenant, which is the right place to check.

What is more useful is knowing everything that goes into the number, because the licence is usually the smallest part:

  • The Teams Phone licence, per user, per month, unless you are on E5.
  • The calling service: a Microsoft Calling Plan, or the carrier’s charges under Operator Connect or Direct Routing.
  • Phone numbers, and any porting fees.
  • Handsets, if you need them, plus headsets for people who do not.
  • An SBC, if you go down the Direct Routing path.
  • The project itself: call flow design, auto attendants, queues, emergency addresses, testing and training.

The saving, where there is one, usually comes from retiring the old PBX, its maintenance contract and its separate line rental, not from the licence being cheap. Businesses that budget only for licences are the ones that get a surprise.

Do you still need desk phones?

Most people do not. A good headset on a laptop is a better experience than a desk handset for anyone who spends their day in Teams anyway.

The exceptions are real, though. Reception desks, warehouses, workshops, meeting rooms, lifts and any shared area where a phone belongs to a place rather than a person all still want a physical device. Certified Teams handsets exist for exactly these cases. Analogue devices such as lift phones and alarm diallers are a separate problem, and they are one of the main reasons a business ends up on Direct Routing.

When Teams Phone is the wrong answer

We sell and support Teams Phone, and we still talk businesses out of it a few times a year. It is the wrong move when:

  • You run a contact centre. Teams Phone has queues and reporting, but it is not a contact centre platform. If you need skills-based routing, workforce management or detailed agent analytics, you want a proper contact centre product, several of which integrate with Teams.
  • Your internet is not up to it. Voice is unforgiving about jitter and packet loss in a way that email and file sync are not. If a site is on a marginal connection, fix the connection first or the phones will be blamed for it.
  • You are mid-contract on a phone system that works. Paying out a contract to move to a platform that costs more per user is hard to justify on its own. Time the move with the contract or with a site move.
  • Nobody will own it. Teams Phone is a system that needs someone to maintain call flows, starters and leavers, and emergency addresses. Deployed and abandoned, it degrades.

Frequently asked questions

Can Microsoft Teams replace my phone system entirely?

For most businesses in the 30 to 80 user range, yes. The cases that need more care are contact centres, sites with analogue devices such as lift phones and alarm diallers, and businesses with complex multi-site routing. All of those are solvable, usually through Direct Routing, but they turn a licensing change into a project.

Can I use Teams to call landlines and mobiles?

Yes, once you have a Teams Phone licence and one of the three calling options above. Without a calling service attached, Teams will only call other Teams users.

Is Teams Phone available in Australia?

Yes. Microsoft Calling Plans, Operator Connect and Direct Routing are all available to Australian tenants, and Australian carriers participate in Operator Connect. Check the Microsoft 365 admin centre with your tenant set to Australia for what your organisation can buy.

Does Teams Phone work on mobile phones?

Yes. The Teams mobile app makes and receives calls on your business number, so people can work from a mobile without handing out a personal number. Teams Phone Mobile goes a step further and makes the mobile number itself the Teams number, through a participating carrier.

What happens to Teams Phone if the internet goes down?

Calls stop, the same as any cloud phone system. Voicemail and call forwarding still work because they run in Microsoft’s cloud, so a failure rule that diverts to mobiles will keep you contactable. Sites where losing the phones is unacceptable need a designed fallback rather than a hope.

Where to start

If you are considering the move, the questions worth answering before you look at licence pricing are: which of the three connection options fits your carrier situation, what your 000 arrangements will actually be, which numbers need to port and how long that will take, and where the physical phones still need to be.

Get those four right and Teams Phone is a straightforward improvement on a traditional PBX for most businesses. Get them wrong and you have a phone system that works fine until the day it matters.

We plan, deploy and support Microsoft telephony services for Australian businesses, including the carrier selection and number porting work behind a Teams Phone rollout. If you want to talk through which option suits your setup, have a look at our Teams Phone services or get in touch.

Logo

Fill Out Details To Download The Program Overview