Tech & Security Intelligence● Issue 019 · 5 Oct 2026
The Weekly Brief
Cyber Smart Week starts today, and the NCSC wants you to spot the scam first. Microsoft’s annual threat report says phishing is back on top. Outside guests are about to lose access to files you shared with them, on a date Microsoft has just moved. And Office 2021 goes out of support next week.
Curated by Paul
Editor · Node-Red
4 stories · 8 min read
In this issue
01NZ Cyber Smart Week
Cyber Smart Week starts today: find the scam before it finds you
Cyber Smart Week 2026 runs from today, Monday 5 October, to Sunday 11 October. It is the National Cyber Security Centre’s annual public awareness week, and this year’s theme is “Find a scam before it finds you”. The timing is deliberate. The week follows straight on from the NCSC’s Cyber Threat Report 2026, which described a threat environment being reshaped by more aggressive cybercriminal activity and by criminals’ growing use of artificial intelligence. Scams are now better written, better targeted and harder to tell from the real thing.
The NCSC’s message for organisations is about getting the basics in place before something goes wrong, not after. It names three in particular: data backups, multi-factor authentication and an incident response plan, meaning a written answer to “what do we do, and who do we call, if this happens to us?” Free guides, checklists and posters for the week are on the government’s Own Your Online site at ownyouronline.govt.nz/csw. Most of that material is aimed at individuals, which makes it easy to use with staff.
02Threat Report
Phishing is back: nearly a quarter of break-ins now start with an email
On 2 October Microsoft released its 2026 Digital Defense Report, its yearly look at what attackers did between July 2025 and June 2026, based on more than 165 trillion security signals a day. The headline figure is about phishing. In the intrusions Microsoft’s own incident responders investigated, phishing was the way in 23% of the time, up from 7% the year before. Microsoft puts much of that down to AI, which lets attackers personalise every message, so the carefully researched, convincing email that used to be reserved for a few big targets can now be sent to everyone.
The other numbers point the same way. Attacks through public-facing systems — websites, VPNs, remote-access portals — rose from 15% to 24% of intrusions. The median time between a vulnerability being discovered and being turned into a working attack is now well under 24 hours. And once attackers were in through a real user’s account, more than 52% of the time they went on to harvest more passwords from inside the network. Microsoft’s Australia and New Zealand National Security Officer, Mark Anderson, summed it up: the basics have not changed, but the pace has. Attackers still get in through stolen logins, convincing phishing emails and systems that have not been patched.
03Microsoft 365
Files you shared with clients are about to say “access denied” — and Microsoft just moved the date
For years, when you shared a SharePoint or OneDrive file with someone outside your business, they could open it by typing in a one-time code sent to their email. Microsoft is retiring that method. Since mid-2026, new external shares have used Microsoft Entra B2B guest accounts instead: the outside person gets a proper guest entry in your Microsoft 365 directory. The second phase switches the old one-time-code access off completely, and on 1 October Microsoft updated its notice (MC1243549) with a new timetable. That phase now starts in mid-October and is expected to finish by the end of November 2026, later than the 1–31 October window Microsoft had previously announced.
The effect is easy to miss until a client complains. An outside person who was given access to a file or folder before the change, and who has no guest account in your tenant, will see an access-denied message on a link that used to work. Nothing is deleted, and the fix is simple: an administrator can create a guest account for them, or someone in your business who is allowed to share can re-share at least one file, folder or site with that person, which creates the guest account automatically. The catch is knowing in advance who is affected, rather than finding out from a client, accountant or contractor who cannot open a document on a deadline.
04End of Support
Office 2021 stops getting security fixes on 13 October
Next Tuesday, 13 October, Microsoft ends support for Office 2021, the one-off-purchase version of Word, Excel, Outlook and PowerPoint, along with the business volume-licensed Office LTSC 2021 and the 2021 versions of Visio and Project. Microsoft’s notice (MC1278920) is plain about what that means: no further updates, security fixes or technical support. The programs will keep opening and working the next day. They just stop being fixed, and Microsoft warns that carrying on brings security and compliance risks and may affect reliability.
Microsoft’s recommended way forward for organisations with fewer than 300 users is a Microsoft 365 subscription that includes the desktop apps: Business Standard, Business Premium or Microsoft 365 Apps for business. These update themselves continuously instead of having an end date. For machines that genuinely have to stay offline, the one-off replacement is Office LTSC 2024, which is supported until October 2029. Note that this is separate from a Microsoft 365 subscription: if your staff already sign in to Office with their work account and their apps say Microsoft 365, this deadline does not apply to them.
Tip of the week
Prove your backup works before you need it
Backups are the first thing the NCSC names for Cyber Smart Week, and the backup you have never restored from is a hope, not a backup. This week, give it twenty minutes. Pick one real file that changed last week — a quote, a spreadsheet, an invoice — and restore last Tuesday’s copy to a different location. Time how long it takes, and note who knew how to do it. Then ask two questions. Does the backup cover Microsoft 365? Email, OneDrive and SharePoint live in Microsoft’s cloud, and the recycle bin and version history are not a backup: they only keep things for a limited time, and anyone who can delete your files can usually empty them too. Is at least one copy out of reach? Ransomware looks for backups to encrypt or delete, so a copy that a compromised staff account can reach is not safe. If the restore worked, write the steps down on one page and save it somewhere you could find it with your main systems down. If it did not, you have found the problem on a quiet Monday instead of in the middle of an incident. Managed clients: ask us to walk through a test restore with you.
Node-Red
Want all of this handled for you?
We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.