24 February 2026
The move to hybrid working has unlocked productivity and reduced overheads, but also widened the "attack surface" for cybercriminals.
The Man-in-the-Middle (MitM) attack is when a malicious actor intercepts and relays communications between two parties, whilst making them think they are talking to each other. It is used to steal data, alter messages and often uses unsecure wi-fi or vulnerability exploitation.
You can discover more about this and other common threats in our Cyber Risk Report.
Download the Cyber Risk Report here (PDF)
In a Man-in-the-Middle attack, a perpetrator inserts themselves into a communication session between a user and an application. To the employee, everything looks normal. However, the attacker is silently "listening" to the data being exchanged.
This often happens when employees work from local coffee shops or transport hubs using unsecured public Wi-Fi. By setting up a "twin" hotspot that looks legitimate, hackers can capture every packet of data that passes through it, from login credentials to sensitive client contracts.SMEs often rely on standard home routers or basic VPNs, making them easy targets.
Invoice Fraud is the most common issue. An attacker intercepts an email exchange with a supplier, alters the bank details on an invoice, and sends it on. The business pays the "supplier," but the money vanishes into a criminal account.
Capturing login details for Microsoft 365 or banking portals, leading to data breaches that trigger mandatory (and costly) reporting to the Information Commissioner's Office (ICO).
For a small consultancy or firm, trust is the primary currency. If a client’s data is intercepted because of poor security protocols, that trust evaporates instantly.
The basics include avoiding the use of public wi-fi, use a VPN, only visit websites which use the “https” protocol. Keep software up to date and use strong passwords supported by other controls such as MFA and location locking.
VPNs can slow down the user experience, and once a hacker breaches the VPN, they could have access to the entire network.
Microsoft now offers a more sophisticated alternative through Global Secure Access, the key of their Security Service Edge (SSE) solution. This is major improvement for SMEs, by focusing on identifying the employee rather than just locking the door.
Identity-Centric Security - Instead of just checking if a password is correct, the system looks at the "context." If an employee tries to access sensitive financial data from an unusual location on an unrecognised network, Global Secure Access can automatically block the connection or demand extra verification.
Seamless Protection Anywhere - Whether in a café, on a train, or working from a home office, network traffic is routed through a secure "tunnel." This encrypts the data and masks it from eavesdroppers.
Protecting your business is now a continuous exercise. But it should not detract from your productivity if done properly.
Global Secure Access integrates directly with the Microsoft Entra dashboard, allowing owners to manage internet, Microsoft 365, and private files from one place.
If you would like to find out more, get in touch.