Making Tax Digital – Woes for small business

The UK government’s roll-out of digital government continues apace. You can pay your Vehicle ‘road tax’ from your mobile phone or sign up for the Universal Credit system online. The tax collection arm of the UK government (Her Majesty’s Revenue and Customs – HMRC) is no slouch here either with the ability to check personal and business annual tax statements via the government gateway.

Hector, the taxman

Under the guise of making tax returns easier and more ‘error free’ the HMRC are rolling out yet more digitisation under the title of – Making Tax Digital (MTD). The first stage of this was supposed to be self assessment of individuals but they have backed off from this goal (or kicked the can down the road a little at least). Instead the first deliverable of MTD are changes to the way VAT (Value Added Tax) registered businesses must make their VAT Returns (often quarterly for most businesses).

HMRC used to allow businesses to use the government gateway to electronically enter their VAT returns to HMRC instead of sending in paper returns. This was obviously more efficient for the HMRC as processing digital returns is many times quicker than processing manual returns. Logically HMRC have now made paper returns obsolete and made businesses submit all returns digitally. This change really laid the ground work for MTD by forcing businesses to use digital means to enter their returns. The new changes under MTD however, go much further and if you are conspiracy minded seem a little like the thin end of the wedge of the government wanting to know all about your finances.

MTD came into force on 1-Apr-2019 and in my experience are widely mis-understood by the small business community which in large numbers have made no preparation for MTD and the deadline of 1st April. I cannot fault HMRC here are they have been communicating the changes by all sorts of media (TV, Radio, press and online). I have a harsher attitude to the accountancy profession however who largely seem to have left small businesses to their own devices regarding preparing for MTD. Most seem to have included an article or two in the newsletters over the past year or so but have not proactively contacted their clients and checked to see what progress they have made in complying with MTD.

So what are the changes that MTD will make to how companies file their VAT returns?

  • Your business can no longer use the government gateway to file VAT returns
  • You must use an accredited software package to submit your VAT returns
  • All transactions (Sales and Purchases) must be entered in the accredited software package (i.e. no double entry or manual copying of data between software packages)
LR Clouds Software Concepts image
Accountancy software packages now a necessity?

Now as well as not faulting HMRC I can’t fault the accountancy software companies (e.g. Xero, Intuit, Sage) here as they have been advertising like crazy about MTD and have updated all their software to comply with MTD. And well they should as they will be the main beneficiaries of MTD after HMRC itself. This change singlehandedly will force all VAT registered business into using accountancy packages whether they like it or not. Now for most companies in the SME (Small to Medium Enterprises) this won’t be anything new but in the micro to small business end of that sector this will be new. Even for companies who already use accounting software this will bring about unexpected changes. Lot’s of small businesses use desktop based software from one of the main accountancy software companies. However probably less than half are running the latest version of their software, many will NOT have software maintenance agreements which allow them to upgrade without further cost. Because of course, only the latest version of these software packages will have the code necessary to talk to the government gateway. In a stroke the HMRC have handed the accounting software providers with massive extra custom in the past year and to repeat year after year.

I have spent the last nine months trying to prepare my SME customer base for these changes that now are in force. If you are VAT registered and have a VAT return date of the 1st April 2019 or later then this applies to you.

So what has been my experience with MTD and my customer base? Well they break down into a number of categories: –

  • Already using accredited accounting software, running a version compliant with latest government gateway. Already use the accredited accounting software to submit their VAT returns to the government gateway. No action required already compliant.
  • Using out dated desktop accounting software and using the government gateway to submit VAT returns. Either upgrade accounting software to latest compliant version or move to a compliant cloud based accounting software package.  Start submitting VAT returns via software.
  • Using non-accounting software for recording Sales and Purchases (typically this will be via a spreadsheet(s) like Excel or Numbers) and using the government gateway to submit VAT returns. MUST migrate over to a compliant accounting software package (desktop or cloud) and enter all transactions (sales and purchases) in that package. MUST not continue using spreadsheet and copying over data to accounting package – this is specifically prohibited in MTD. Obviously there is a large training issue hereas well as cost. 
  • Not using any computer based system for recording sales and purchase
    and using the government gateway to submit VAT returns. It will be a surprise to many but lots of micro sized business (particularly ones using Flat Rate VAT scheme) are actually still using handwritten ledgers to record their business transactions. I have in particular found these businesses to have been let down by their accountants in terms of preparing them for MTD. These businesses have the highest barriers to climb, as they must abandon their book ledgers and start using computers in their everyday business activities. The training burden alone is considerable. Fortunately these businesses are good candidates for cloud based accounting packages which have the shallowest learning curves

A common thread that runs through a lot of micro to small businesses is the use of external bookkeepers who actually run the accounts for the business. These bookkeepers quite often submit the VAT returns on behalf of the business. This in itself is not a problem. What is potentially a problem is if the bookkeeper is just using summary figures (i.e. total sales per month, total purchases per month, VAT due on sales per month and VAT reclaimed on Purchases per month etc. Bookkeepers will no longer be able to just use these summary figures in the accounting software to produce VAT returns, each individual sales or purchase invoice (transaction) and it’s associated VAT element must be recorded to comply with MTD. To me this looks like a business procedure change with the business entering all transactions daily (i.e. sales and purchase invoices). Bookkeepers need to be aware of their responsibilities under MTD if they are doing the VAT returns.

Of course this is just potentially the start of HMRC wanting to have closer and closer views of our business activities. How long before they require access to our company bank accounts. Like I say if you are conspiratory minded is this the thin end of a wedge.

We can help with MTD!

If you need help or advice in complying the HMRC Making Tax Digital (MTD) then please use the contact form HERE to contact me.

Alan Sinclair-Brown is an IT Professional with over thirty years’ experience in managing, deploying and fixing computer systems. He is passionate about helping people and small businesses make the most of their investment in IT technology.

My memory is going…

Three hundred and ninety three passwords! 3 9 3 Passwords! No wonder I can’t remember why I walked into a room or what I was looking for. 393 passwords! All my memory capacity is being used to remember various combinations of passwords. The worst news is that that number is going up on average by five passwords a week!

Image of lady scratching her head about a password
Someone else with a password problem!

Now, I’ll be the first to admit I’m perhaps a special case, as I work in IT and look after many people’s computers and small business networks. But modern-day life seems to need a logon and password for everything. Even your favourite coffee shop loyalty scheme!

With over thirty years of working in the IT industry, as a systems administrator, I’m one of the people who has always advocated changing passwords regularly (every thirty days on a lot of corporate computer systems) and having strong passwords (i.e. mixtures of upper and lower case, number and punctuation). But through my own existence and also the window I have into how my customer manage their security and passwords I now realise that there’s a real problem out there that needs to be addressed.

Data breaches in 2018 so far (24th October 2018, source Wikipedia.org)

Image of man lifting a wooden block labelled Data Protection off a tower of blocks about GDPR
OH! There goes your data protection.

amount to 321 million loss of personal data (including email addresses and password) and includes such organisations as Facebook (50million), Google Plus (500,000) British Airways (380,000). And one can be sure that this is only the tip of the iceberg.

What does that mean to you or I. Even if our data was lost on Facebook or British Airways does that matter? Ask yourself one simple question. Do you ever reuse the same password for different websites? If so, and be honest here who doesn’t re-use passwords, then you should assume that ANY website where you use the same password is now also vulnerable to releasing your personal data to the Internet. So, for example, when the Facebook data breach happened a lot of people will have logged into Facebook and changed their password (or hopefully they did anyway). So, problem solved you say. Well maybe not. If I have just got access to 50million usernames and passwords and I was a criminal, then I’d be using those usernames and passwords to try other websites and see if I could access peoples accounts. In reality, after a data breach one should change the password at ALL sites where you use the same password. That can be a daunting task can’t it? Can you even remember all the sites you used that password for? How can you possibly change them all and not just make the same mistake again (and again.. and again…).

Well I’ve been using password managers now for about five years and (Ok I don’t really remember 393 passwords, I just remember one) and I’m still not at the point where I don’t re-use passwords but I’m getting better (some I can’t change because they are clients’ passwords). My password manager nags me regularly and bit by bit I’m moving to unique strong passwords for every site. My goal is to not use (or reuse) the same password again – EVER. Every new account I make up gets a new unique password (using a password generator tool). This means is one website gets compromised that I only have to change the password there, nowhere else.

The password manager nags me about reused, weak or compromised passwords every time I start it which is just fine by me.

Now if you are going to use a password manager (oh and a notebook where

Image of a physical spiral bound notebook with weak and strong passwords written down.
19th Century Password Manager!

you write down every single password is a password manager too, just a nineteenth century one). Then you need to make sure you can trust it. If you are using a physical notebook then hopefully you are keeping it under lock and key. If you are using a software one then you need to trust the software vendor of the software, as they are your lock and your key. Only use reputable security vendors for this crucial piece of software. A number of Anti-virus vendors provide free or cost-effective password managers as part of their suite. Or at the top end some vendors have products which allow you to sync password between devices and operating systems i.e. Windows 10 and Mac OS, Android and iPhone/iPads.

We should just assume that our data on the Internet will be hacked and try and limit the damage that causes. I know that sounds cynical and the not way things should be, but we do live in the real world and have to take practical steps to limit the damage. So my tips?

  • DON’T re-use passwords for Internet sites or anything!
  • DO use strong UNIQUE passwords.
  • DO use a secure way to remember those passwords.

Now why did I come in to the room…?

 

Alan Sinclair-Brown is an IT Professional with over thirty years’ experience in managing, deploying and fixing computer systems. He is passionate about helping people and small businesses make the most of their investment in IT technology.

New WiFi vulnerability – Krack

Hi all,

You may have heard about the new Krack vulnerability that is in the news. The question is should you be worried about it? The answer is YES but don’t go mad!

This vulnerability has been discovered by researchers at a Belgium University. More information on the vulnerability can be found at this website.

The research has shown that the most widely used security protocol for WiFi called Wi-Fi Protected Access II (WPA2) has a vulnerability or flaw which could allow someone within reach of your WiFi device or network to read your data being passed over WiFi protected by WPA2.

The vulnerability is present in end WiFi devices (smartphones, laptops, computers, tablets, WiFi security camera’s) AND HAS ALWAYS BEEN THERE!

WPA2 Krack Vulnerablity
WPA2 Krack Vulnerablity

There’s no known exploitation happened yet but it’s only a matter of time before someone  discovers one.

The key thing to note here is that ANY device using WPA2 protocol is at risk and will need the software upgrading ONCE the suppliers have fixed the problem.

The manufacturers are all aware of this problem and are making available patches for their devices as soon as possible.

For example Microsoft quietly released a security patch on 10th October 2017 to fix this problem in all supported versions of Windows (i.e. Windows 7, 8 and 10. Apple will release a fix for their iPhones in IOS 11.1 maybe. (Edit: this exploit has been resolved in iPhone/iPad operating system IOS v11.1 (15B93))

However, even with manufacturers fixing operating systems, the core of WPA2 protocol is buried in WiFi manufacturers hardware drivers. True resolution will only occur once ALL the WPA2 infrastructure code has been patched to resolve the issues.

The message I’d send out to people is make sure your WiFi devices get updated as fixes become available and if you are doing security stuff like Internet Banking then try not to use WiFi. Call if you are concerned.

Alan Sinclair-Brown is an IT Professional with over thirty years’ experience in managing, deploying and fixing computer systems. He is passionate about helping people and small businesses make the most of their investment in IT technology.

 

Windows 10 Fall Creators Update

Microsoft are due to release their new Windows 10 Fall Creators Update in the near future.

As usual there are promised new and improved features and updates to security included in the new release. See the link below for more information.

Microsoft:- Coming to Windows 10 post…

As this will be a major update you can expect it to be quite a long process once it reaches your machine. It will probably require multiple restarts and some of your apps and programmes may no longer run under the new release (Microsoft turns off any it thinks may cause instability), often all this means is you have to download the latest version of your disabled app or programme before running under the new release.

If you run up Settings in Windows 10, and go into System then About you’ll see what version you are currently running (probably version 1703, if earlier then something is wrong!). The new release is designated v1709 (read that as YearMonth so 2017Sep.

Any problems then give us a call, we are here to help.

Alan Sinclair-Brown is an IT Professional with over thirty years’ experience in managing, deploying and fixing computer systems. He is passionate about helping people and small businesses make the most of their investment in IT technology.