Hybrid delivers managed IT and cybersecurity for businesses across Ireland, and this month’s newsletter covers a new AI email scam, what ISO 27001 certification really involves, and when your business should review its IT strategy.
Is Your Business Protected from the New AI Email Scam?
Scammers have found a way to write emails that trick Microsoft Copilot and tools like it into acting on hidden instructions, forwarding a file, approving a request, handing over access, all without needing to fool the person reading the email. This is called prompt injection, and it targets the AI assistant rather than the human reading the message. The message looks entirely ordinary. The AI assistant simply follows what it’s told.
Microsoft responded. Their biggest security update of the year, released in July, added protection in Defender built specifically to catch these emails before they reach an inbox. If your business runs Microsoft 365 with AI features switched on, this is a genuine gap that opened in the last year, and most businesses are only beginning to close it.
This is precisely the kind of threat we watch for. Your next step is simple: ask whoever manages your IT two direct questions. Is this protection switched on, and who is watching it? A vague answer to either tells you exactly where your gap sits.
See how our cybersecurity monitoring catches this before it reaches you.
What Does ISO 27001 Certification Involve for an Irish Business?
ISO 27001 is the international standard for managing information security. Hold it, and you put a completed security questionnaire in front of a customer, insurer, or tender panel in minutes, instead of scrambling to build one from scratch every time somebody asks.
That is increasingly what is at stake. NIS2 is pushing larger regulated organisations, hospitals, airlines, pharmaceutical manufacturers, aviation MRO providers, to assess the security of every supplier in their chain. A business that skips certification ends up answering a different, lengthy questionnaire for every customer that asks. A business that holds it hands over an answer that is already written and independently verified. Insurers are factoring certification into cyber cover and premiums. Public sector and enterprise tenders increasingly list it as a scoring criterion, sometimes a hard requirement. Missing it can cost you the contract before price even enters the conversation.
We took Antaris Consulting through certification, from their first gap analysis to full sign off. Read their story.
If you want to know exactly where your business stands against ISO 27001, book a meeting with our team and we’ll walk you through it.
How Often Should an Irish Business Review Its IT Strategy?
Every IT budget tells a story, and it is usually a rear view one, built from whatever broke last year rather than where the business is heading. That story locks into next year’s numbers before anyone has properly checked it holds up.
Here is what that costs in practice. A server nobody flagged for replacement fails in February, and the business replaces it in a panic, at a price nobody budgeted for. A software licence renews on autopilot months after a cheaper, better platform existed. A new product line launches on infrastructure nobody sized for it, and the strain shows up exactly when the business can least afford downtime.
A proper technology roadmap catches all three early. It covers hardware due for replacement, licences up for renewal, and whether your current setup can carry the business through its next stage of growth, built around where you are taking the business rather than a generic template.
July is when serious planning starts for next year. Book a roadmap review with us now, while there is still time to change the number before it locks in.
Talk to us about your IT roadmap.
Copilot is generally safe, but security researchers have found that hidden instructions embedded in an email can manipulate it into acting on them without a person noticing, a technique called prompt injection. Microsoft added protection against this in Defender in July.
ISO 27001 sits outside Irish law as a voluntary standard, though many organisations require it from suppliers and partners as a contractual condition.
A quarterly check paired with a full annual review is the rhythm experts commonly recommend, with an extra look any time headcount changes by more than 10 percent.
Written by: Jolene Oelofse – Head of Marketing, Hybrid Technology Partners
Jolene leads Hybrid TP’s content strategy, translating complex IT and cybersecurity topics into practical insights for Irish SMEs. She collaborates closely with the technical team and Managing Director Paul Browne to ensure every article reflects real-world accuracy and business value.





