J2 Software

J2 Software J2 is a cyber security focused managed service group, founded in 2006. Operating in United Kingdom & South Africa. J2 serves over 800 customers on 5 continents.

J2 is a cyber security focused services business founded in 2006. Our experts work with your team to ensure that you are able to leverage technology to reduce risk, improve compliance reporting and remain operations in the modern world. The J2 Story

Founded in 2006, J2 Software began with a single desk in a shared warehouse in Honeydew, South Africa. What we lacked in space, we made up for in vision: to make cybersecurity accessible, practical, and effective for businesses of any size. Today, J2 is a trusted Managed Security Services Provider (MSSP), delivering operational cyber resilience to over 800 customers across five continents. From our offices in London, Johannesburg and Cape Town we help organisations reduce digital risk, improve visibility, and strengthen control of their most critical digital assets. We don’t believe in checkbox security. We believe in real protection. Our expert team uses the proven J2 Cyber Resilience Framework to address the five core areas of cyber risk — helping our clients build a solid foundation for growth, transformation, and long-term protection. Whether your business is just starting its security journey or scaling globally, we deliver solutions that evolve with you. You do not need to understand cyber security, you only need to know somebody that does.

John McLoughlin is speaking at the 18th Annual e-Crime & Cybersecurity Mid-Year Summit in London on 15 October.And the t...
05/10/2026

John McLoughlin is speaking at the 18th Annual e-Crime & Cybersecurity Mid-Year Summit in London on 15 October.

And the title of his session asks a very good question:
“Million Dollar Conversation: What happens when the criminal isn't breaking into the conversation, they're already in it?”

Most of us still picture a cyber attack beginning with somebody trying to get through the front door.

But what happens when everything looks normal?

The account is recognised. The names are right. The conversation already exists. The person at the other end appears to know exactly what is going on.

The challenge then becomes recognising that somebody who appears to belong in the conversation actually doesn't.

John will be exploring that territory at Park Plaza Victoria on 15 October as part of a day bringing together cyber security, risk and technology leaders from across the private and public sectors.

akjassociates.com

If you're attending, come and say hello.
Register for the event
J2 MSSP. Here to help.

Ask three people in your business the same question: “If we had a cyber incident tonight, who would you call first?”You ...
03/10/2026

Ask three people in your business the same question: “If we had a cyber incident tonight, who would you call first?”

You may assume everybody knows.
It is worth finding out.

One person might call your IT company. Another might call the boss. Somebody else may know there is a cyber security provider involved but have no idea how to contact them.

The worst time to work out who is responsible is when something has already happened.

At J2 we recommend that businesses assign responsibilities before an incident, record who owns them and make sure the relevant contact information is available. We also recommend thinking about how those details would be accessed if the systems you normally rely on were unavailable.

This does not need to become a complicated cyber security exercise.

You are trying to establish something much simpler.
Do our people know what to do first?
So try it.

Ask three people separately what they would do if they discovered a cyber incident.

Don't prompt them. Don't tell them who they should call.
Listen to the answers.
If all three know, good.

If you get three different answers, you've found a gap without spending a penny.

Because a cyber incident is a bad time to discover that everybody thought somebody else was responsible.

Preparation beats panic.

Twenty questions, under three minutes, and you get your score, your gaps and your next steps.

Take the J2 Test see out home page

You don't have to understand cyber security. You just need to know someone who does.

J2 MSSP. Here to help.

Your IT team can be brilliant and your business can still have a cyber security gap. IT keeps your people, devices, syst...
30/09/2026

Your IT team can be brilliant and your business can still have a cyber security gap. IT keeps your people, devices, systems and Microsoft 365 running every day, and that's a big job on its own.

Cyber security asks something else: would anyone recognise an attack, who would investigate it, and who responds if it happens at midnight on a Friday?

The National Cyber Security Centre's guidance says an incident response team will usually be built around IT or cyber security staff, and may bring in outside specialists too.

It's not about replacing IT. It's about making sure the capability exists somewhere and everyone knows who holds it.

So ask yourself: if we discovered a cyber attack tonight, who would investigate and respond? If you can answer that with confidence, great. If you can't, our Cyber Resilience Scorecard will show you where the gaps are in a few minutes.

Take the quiz.

https://j2mssp.com/cyber-risk-score/

You don't have to understand cyber security. You just need to know someone who does. J2 MSSP. Here to help.

Your supplier gets hacked. Your business may be the next place the attacker tries the key.Businesses give trusted third ...
28/09/2026

Your supplier gets hacked. Your business may be the next place the attacker tries the key.

Businesses give trusted third parties access for perfectly sensible reasons. Your IT provider may manage systems. Your accountant may access financial information. A software supplier may support an application. A contractor may need access to something in order to do their job.

The risk isn't that trusting suppliers is somehow a mistake.
The risk is forgetting what that trust allows them to reach.

If credentials associated with a supplier are compromised, the attacker may not need to hack their way through your defences.

They may simply try the access that already exists.

Verizon's 2026 Data Breach Investigations Report found third parties were involved in 48% of breaches in its dataset, following a 60% increase in a year.

So instead of only asking whether your suppliers are secure, ask something you can actually answer:

What access have we given them, and would we know if somebody else started using it?

That is a very different conversation.
Good suppliers matter. So does understanding exactly what your trust in them allows.

Twenty questions, under three minutes, and you get your score, your gaps and your next steps.

Take the J2 Cyber Resilience Scorecard. Check it out on our homepage.

You don't have to understand cyber security. You just need to know someone who does.

J2 MSSP. Here to help.

Look at your business online as though you don't work there.Spend ten minutes on your company website, LinkedIn and the ...
25/09/2026

Look at your business online as though you don't work there.

Spend ten minutes on your company website, LinkedIn and the public profiles of the people who work for you, but look at them as a stranger. We will.

What could you work out?

You might find names and job titles, who works in finance, who runs the company, who has recently joined or left, which suppliers the business works with, what projects are happening and where people are going.

Most of those things are perfectly normal for a business to talk about.

The problem isn't necessarily any one piece of information. It is the picture somebody can build when they put the pieces together.

Our J2 guidance for smaller organisations specifically recommends reviewing what your website and social media reveal publicly. It warns that information such as staff profiles, personal details, financial content, third-party relationships and old LinkedIn connections can be useful to criminals.

Why?

Because knowing something about a business makes it much easier to sound as though you belong in a conversation.

An unexpected request from a complete stranger should raise questions.

A request that appears to come from somebody who knows your people, your suppliers and the way your business works can feel very different.

So try something practical today.

Look at your business from the outside and ask:
What could somebody convincingly pretend to know about us from what we publish publicly?
You don't need to stop talking about your business.
You should know what your business is telling people.

Attackers exploit trust more often than technology.

Twenty questions, under three minutes, and you get your score, your gaps and your next steps.

Get your J2 Cyber Resilience Score https://j2mssp.com/cyber-risk-score/

You don't have to understand cyber security. You just need to know someone who does.

J2 MSSP. Here to help.

Passkeys are a genuine improvement on passwords, and we would encourage any business to move to them. They also change t...
23/09/2026

Passkeys are a genuine improvement on passwords, and we would encourage any business to move to them. They also change the question you should be asking.

Here is the plain version. A password is a secret you type, so it can be stolen, guessed, reused or phished out of you on a convincing fake login page. With a passkey, your device proves who you are using a fingerprint, face or PIN, and the secret never travels. That is why a passkey cannot be phished the way a password can.

Then in August, researchers at Palo Alto Networks’ Unit 42 published three techniques against Google’s synced passkeys in Chrome on Windows. The most serious reads the master key that encrypts every passkey on the account out of the browser’s memory, and there is currently no way to rotate that key.

Two things matter, because the coverage has been loose. None of it breaks the cryptography behind passkeys, and all of it needs malware already running on the machine as the logged in user.

That is the real lesson. Passkeys removed a phishing problem and left an endpoint problem. When a password was stolen you changed it. When a master key goes, there is nothing to change.

So ask three things. Do you know which devices your business credentials are synced to, including personal phones? If malware started running on one of them this afternoon, would anything notice? And when a device is compromised, do you treat it as a full credential reset, passkeys included?

Move to passkeys. Just do not assume they end the conversation.

https://j2mssp.com/cyber-risk-score/

You don’t have to understand cyber security. You just need to know someone who does.
J2 MSSP. Here to help.

Some of the team in the Johannesburg office showing thier heritage with traditional clothes and food.  Some new tastes. ...
23/09/2026

Some of the team in the Johannesburg office showing thier heritage with traditional clothes and food. Some new tastes.

Our diversity is our strength. Huge thanks to the social committee team who put this together.

🇿🇦

Somebody replied to one of our posts last week with three letters. EDR, MDR, SIEM. Their point was that we had just writ...
21/09/2026

Somebody replied to one of our posts last week with three letters.

EDR, MDR, SIEM.

Their point was that we had just written about confusion in cyber security and then used the language that causes it. Fair enough. So here they are in plain English.

Picture your business as a building.

EDR, or endpoint detection and response, is software on the devices people actually work on, such as laptops, servers and phones. It watches how they behave and can step in when something looks wrong. Think of a smoke detector in each room.

SIEM, or security information and event management, is where the records from all your systems get gathered so patterns can be spotted across the whole organisation instead of one device at a time. Think of the log book for the whole building.

MDR, or managed detection and response, is not a product. It is people on duty whose job is to look at what the technology reports, decide what matters, and act on it. Think of whoever hears the alarm at two in the morning.

Here is why that matters. Plenty of businesses have the first, have the second half configured, and have nobody doing the third. An alarm nobody answers is not protection.

So forget the acronyms and ask three ordinary questions instead. If a laptop started behaving oddly this afternoon, would anything notice?

If you needed to know what happened last Tuesday, could you find out? And if something happened at two on a Sunday morning, who acts?

Twenty questions, under three minutes, and no jargon in any of them.
https://j2mssp.com/cyber-risk-score/

You don’t have to understand cyber security. You just need to know someone who does.

J2 MSSP. Here to help.

The attacker is not always hacking in. Sometimes they are simply logging in.We think that changes the question a busines...
19/09/2026

The attacker is not always hacking in. Sometimes they are simply logging in.

We think that changes the question a business ought to be asking. If somebody turns up with a valid username and the right password, or with a session your systems have already trusted, then everything can look entirely normal from the outside. The account exists, the login succeeds, and nobody is alerted. The only thing that is wrong is who is behind it.

Stolen passwords are not the whole story either. In a joint advisory on cloud attacks, the NCSC described attackers using stolen access tokens to get into accounts without needing a password at all.

So rather than asking whether your security software is working, try a more useful question. Would you know if somebody logged in using one of your employees’ accounts? And if you would not know, how long could they stay there?

A legitimate account and a legitimate user are not always the same thing. Protecting the front door matters, and so does knowing who is walking through it.

Twenty questions, under three minutes, and you get your score, your gaps and your next steps.

https://j2mssp.com/cyber-risk-score/

You don’t have to understand cyber security. You just need to know someone who does.

J2 MSSP. Here to help.

You can outsource a service. You cannot outsource what happens to your business when that service fails.Verizon's 2026 r...
16/09/2026

You can outsource a service. You cannot outsource what happens to your business when that service fails.

Verizon's 2026 research found that 48% of breaches now involve a third party, up from 30% the year before. That matters because almost every business depends on other businesses to function. Payroll providers, IT companies, cloud platforms, payment systems, software suppliers.

The question is not whether outsourcing is wise, because it usually is. The question is whether you know what your business is quietly depending on each supplier for.

Try this. Think of one supplier you would struggle to operate without tomorrow, then ask what would stop working in your business tomorrow morning if they went offline tonight. Customers will still call. Staff will still need to work. Orders will still need processing. And the fact that the problem started in somebody else's system will not make any of that go away.

Good suppliers matter. So does knowing what happens when one of them cannot deliver.

Twenty questions, under three minutes, and you get your score, your gaps and your next steps.

https://j2mssp.com/cyber-risk-score/

J2 MSSP. Here to help.

Address

Suite 339 News Building, 3 London Bridge Road
London
SE19SG

Alerts

Be the first to know and let us send you an email when J2 Software posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to J2 Software:

Shortcuts

Share