Resources

Blog & insights

Practical posts focused on decisions and delivery. No hype, just patterns you can use.

Blog post

Qilin Ransomware's UK Escalation via Palo Alto GlobalProtect and the Accesso Ticketing Ransomware Drop: What UK Schools, Charities and SMBs Should Do in the Week Commencing 29 July 2026

Two ransomware anchors landed on the same evening on Tuesday 28 July 2026, both naming UK victims. The Qilin ransomware group added a UK organisation listed only as Hoc to its leak site at just before 22:00 UK time, its second confirmed UK casualty inside four weeks and the first since Arctic Wolf Labs published the definitive attribution paper on Monday 21 July linking Qilin's initial-access chain to active exploitation of CVE-2026-0257, the PAN-OS GlobalProtect authentication-bypass flaw that Palo Alto Networks patched on Tuesday 13 May 2026 and that CISA added to its Known Exploited Vulnerabilities catalogue on Thursday 29 May. Coinbasecartel, an emerging financially-motivated extortion actor active since April 2026, added Accesso - the UK-headquartered ticketing, virtual-queuing and guest-experience technology provider whose platforms sit under a large fraction of UK theme parks, ski resorts, cultural venues, cathedrals, museums and school-trip attractions - to its leak site at just before 20:00 UK time. Day Forty-One of the DUAA Section 164A regime closes the first calendar month of the new data-protection complaints duty. Three jobs pinned to Friday 31 July (Palo Alto GlobalProtect verification), Monday 3 August (Accesso supplier-question note to ticketing, virtual-queuing and school-trip partners) and end of week (Section 164A first-month five numbers on one sheet).

Related services
Blog post

LAUNDRY BEAR Zimbra Zero-Click, the DfE ExfilSquad Leak of 600,000 Parent and Staff Records, and the Cyber Security and Resilience Bill's Lords Committee Date: What UK Schools, Charities and SMBs Should Do in the Week Commencing 28 July 2026

Three anchors landed inside the four working days from Thursday 23 July to Sunday 26 July 2026. On 23 July the NCSC and fifteen partner agencies exposed LAUNDRY BEAR - the Russian state-supported actor also tracked as Void Blizzard - for a zero-click Zimbra Collaboration Suite espionage campaign using a custom Ulej exploit against CVE-2025-66376 that has been active since July 2025. On 26 July the ExfilSquad ransomware group added the UK Department for Education to its dark-web leak site inside a fourteen-victim, five-country simultaneous drop, claiming approximately six hundred thousand parent and staff records from the Customer Help Portal and seven thousand from the Turing Assessment Portal. And the Cyber Security and Resilience Bill's Lords Committee stage is now confirmed for Tuesday 1 September 2026. Three jobs pinned to Friday 31 July, Wednesday 30 July and end of week for UK schools, charities and small businesses.

Related services
Blog post

SharePoint ToolShell Zero-Day, the TfL Sentencing at Woolwich Crown Court, and the Cyber Security and Resilience Bill's Lords Second Reading: What UK Schools, Charities and SMBs Should Do in the Week After 14 July 2026

Three things landed inside the same seventy-two hours in the week of 14 July 2026. Microsoft shipped the largest Patch Tuesday in its history at more than five hundred and seventy CVEs, including an actively exploited SharePoint Server zero-day (CVE-2026-56164) that CISA added to the Known Exploited Vulnerabilities catalogue the same day with a three-day federal remediation deadline. The Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading. And at Woolwich Crown Court, Thalha Jubair and Owen Flowers were each sentenced to five years and six months for the September 2024 Transport for London attack in what the National Crime Agency called the largest cybercrime prosecution ever brought before the UK courts and the first successful conviction under Section 3ZA of the Computer Misuse Act 1990. Three jobs for UK schools, charities and small businesses in the week commencing 21 July: the SharePoint patch and four supplier questions by Friday 25 July, the phone-based password-reset script this week, and the DUAA Section 164A thirty-day rolling check from Monday 28 July.

Related services
Blog post

FortiBleed Is Now Linked to INC and Lynx Ransomware and to UK Foreign Office Logins on the Dark Web: What UK Schools, Charities and SMBs Should Do in the Four Working Days Before the Cyber Security and Resilience Bill's Lords Second Reading on 14 July 2026

SOCRadar updated its FortiBleed research this week to name INC Ransom and Lynx as the ransomware brands sitting on the other end of the credential pipeline, with twelve confirmed deployments and 354 domain-admin compromises tied back to the same operator. On Sunday 5 July The Telegraph reported that Foreign Office and UK government logins are on sale on the dark web for up to forty thousand pounds each, alongside credentials at NHS trusts, energy companies and local councils. Arctic Wolf's CISO calls the operation a repeatable credential factory. Four working days from now, on Tuesday 14 July 2026, the Cyber Security and Resilience Bill has its Lords second reading. Three jobs fit the four days: the two-hour FortiBleed exposure check and credential rotation today, the four supplier questions to the top five vendors on Monday, and the DUAA Section 164A paragraph for the complaints page on Tuesday.

Related services
Blog post

NCSC's Cyber Shield Blueprint Puts Agentic AI at the Centre of UK Cyber Defence: What UK Schools, Charities and SMBs Should Do in the Five Days Before the Cyber Security and Resilience Bill's Lords Second Reading on 14 July 2026

The NCSC and DSIT published the Cyber Shield blueprint on Tuesday 7 July 2026 - the UK's plan to hardwire agentic AI into national-scale cyber defence, first trailed by GCHQ Director Anne Keast-Butler at Bletchley Park on 27 May. Six core capabilities: reliable and explainable AI, federated agents, automated vulnerability discovery and mitigation, co-ordinated detection and response, national-level scanning and national-level mitigation. Downing Street pinned it, the same day, to the formal launch of the Cyber Resilience Pledge with more than sixty signatories including Marks and Spencer, Nationwide, Microsoft UK, Vodafone and Capita. Yesterday's post walked through the offensive-AI half of the same seven-day window (JADEPUFFER); Cyber Shield is the defensive-AI half. Three jobs fit the five days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026: on Friday 10 July write down the two-column list the NCSC blog implies but does not spell out - what fundamentals are in place and which of the six Cyber Shield capabilities you have imitated at your scale; on Monday 13 July run the four supplier questions against your top five vendors; on Tuesday 14 July over lunch, write the AI-application paragraph the DUAA Section 164A complaints inbox owner needs by day thirty.

Related services
Blog post

Sysdig Confirms JADEPUFFER, the First Fully Autonomous LLM-Driven Ransomware Campaign: What UK Schools, Charities and SMBs Should Do in the Six Days Before the Cyber Security and Resilience Bill's Lords Second Reading on 14 July 2026

Sysdig published its JADEPUFFER threat report on Tuesday 7 July 2026 - the first documented case of a ransomware operation in which every hands-on-keyboard step, from reconnaissance through credential theft, lateral movement, privilege escalation and destructive database extortion, was executed by an autonomous large-language-model agent. The operator picked the target and set the goal. The AI did the rest, moving from a failed login to a working credential in thirty-one seconds at one point in the captured session. The initial foothold was an internet-facing Langflow instance unpatched against CVE-2025-3248, a missing-authentication bug fixed by the vendor in April 2025. The agent then pivoted to a production MySQL and Alibaba Nacos server via CVE-2021-29441. Both patches were public. Three jobs fit the six days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026: inventory every LLM app running against your data on Friday 10 July, audit the credential each one holds the same afternoon, and on Tuesday 14 July write down the one paragraph that says what each AI agent can and cannot do and who owns the exceptions.

Related services
Blog post

Qantas Confirms 5.7-Million-Record Breach Through a Third-Party Salesforce Platform: What UK Schools, Charities and SMBs Should Do About Supplier-Side Help-Desk Risk in the 14 Days Before the Lords Second Reading on 14 July 2026

Qantas has confirmed that a cybercriminal walked through a third-party Salesforce-hosted customer-service platform used by a Manila call centre and walked out with personal data on 5.7 million customers. Darktrace's Toby Lewis says the breach bears the hallmarks of Scattered Spider - the crew behind Marks and Spencer, Co-op and Harrods last spring and now WestJet, Hawaiian Airlines and Qantas. It is the first big confirmed casualty of the airline wave the FBI, Mandiant and Palo Alto Unit 42 warned about last week. Three jobs fit the 14 days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026: list the suppliers who can change records or reset credentials on your behalf, send them a four-question side-letter on help-desk verification, and extend your DUAA Section 164A complaints page to name the supplier route.

Related services
Blog post

Scattered Spider Has Pivoted to Airlines and Jaguar Land Rover's Russian Attribution Lands: What UK Schools, Charities and SMBs Should Do About Help-Desk Social Engineering in the 15 Days Before the Lords Second Reading on 14 July 2026

Two stories landed between Thursday 26 and Friday 27 June 2026. The FBI's public advisory says the cybercrime crew tracked as Scattered Spider has pivoted to airlines, with Mandiant and Palo Alto Unit 42 advisories following the same week, after WestJet, Hawaiian Airlines and Qantas have all confirmed intrusions in the past three weeks. The New York Times and TechCrunch report Russian-speaking criminal hackers behind the 31 August 2025 Jaguar Land Rover attack that cost the UK economy an estimated 1.9 billion pounds. Both share the help-desk social-engineering vector that took down M and S, Co-op and Harrods in spring 2025. Three jobs fit the fifteen days before the Cyber Security and Resilience Bill's Lords second reading on Tuesday 14 July 2026.

Related services
Blog post

MPs Warn UK National Museums Are Cyber-Vulnerable and the Cyber Resilience Bill Has a Lords Date of 14 July: What UK Charities, Schools and SMBs Should Do in the Next 18 Days

The Public Accounts Committee report of Wednesday 24 June 2026 tells DCMS that UK national museums and galleries are being left vulnerable to cyber-attack, with the Government working reactively rather than strategically. Three weeks before the Cyber Security and Resilience Bill's now-scheduled Lords second reading on Tuesday 14 July, and on the Friday close of DUAA Week One, here is what UK charities, schools and SMBs should take from the report and the three jobs that fit the next eighteen days.

Related services
Blog post

DUAA Week One Closes and the Cyber Resilience Bill Enters the Lords: What UK Schools, Charities and SMBs Should Do in the Next 30 Days

DUAA Week One closes on Friday and the Cyber Security and Resilience Bill is in the Lords between its 17 June first reading and a second reading still to be scheduled. The DSIT Cyber Security Breaches Survey 2025/2026 puts 43 per cent of UK businesses and 28 per cent of charities at a breach last year, 91 per cent of universities, 85 per cent of FE colleges and 60 per cent of secondary schools the same. Here is the thirty-day plan for UK schools, charities and SMBs.

Related services
Blog post

NCSC Issues Fortinet Edge-Device Alert and 74,000 Credential Sets Are Out in the FortiBleed Dataset: What UK Schools, Charities and Businesses Should Do This Weekend

On Thursday 18 June 2026 the NCSC issued an alert advising UK organisations on a global credential-harvesting campaign targeting Fortinet firewalls and SSL VPN gateways, with indications of UK impact. CISA issued a parallel hardening advisory. Researchers put the verified dataset at around 74,000 working credential sets across more than 190 countries, in what has been dubbed FortiBleed. The DUAA Section 164A complaints duty switched on the morning after. Here is the four-day, 30-day and 90-day plan for UK schools, charities and businesses.

Related services
Blog post

NCSC Logs 200 Critical-Infrastructure Incidents and Reframes Cyber as a Contest: What UK Schools, Charities and Businesses Should Do as DUAA Goes Live Tomorrow

On 17 June 2026 the NCSC's Richard Horne told RUSI his teams had handled more than 200 cyber incidents affecting UK critical national infrastructure and its supply chain in the year to May 2026, with around three-quarters linked to hostile states - Russia, China and Iran. He reframed cyber as a 'contest' rather than a 'risk' and asked every board to focus on three core capabilities. Thirty-six hours later, the DUAA data protection complaints duty switches on for every UK controller. Here is the four-day, 30-day and 90-day plan for UK schools, charities and businesses.

Related services
Blog post

Three UK Education Cyberattacks In Ten Days And The DUAA Complaints Duty Switches On This Friday: What Schools, Charities and businesses Should Do Next

Three UK education organisations - Powys (13 schools), Great Marlow School and the University of Nottingham - disclosed cyber incidents in the ten days before the new Data (Use and Access) Act complaints duty switches on this Friday 19 June 2026. ShinyHunters used a pre-auth Oracle PeopleSoft zero-day (CVE-2026-35273) against more than 100 organisations, and Microsoft shipped its biggest ever Patch Tuesday on the same day Great Marlow closed. Here is the four-day, 30-day and 90-day plan for every UK school, charity and business.

Related services
Blog post

The Data Protection Complaints Regime Switches On 19 June 2026. Here's What UK Schools, Charities and businesses Should Have In Place By Friday Week.

From 19 June 2026 a new statutory duty under the Data (Use and Access) Act 2025 switches on. Every UK controller - every school, charity and business - must have a working data protection complaints process, an electronic form and at least one alternative route, a 30-day acknowledgement clock, and a record the ICO can ask to see. There are no carve-outs for size. Here is the minimum viable position for Friday week and the 30/60/90-day plan to make it boring.

Related services
Blog post

GCHQ Says UK Cyber Needs to Be 'Ten Times More Urgent'. Here's What UK Schools, Charities and businesses Should Actually Do This Quarter.

On 27 May 2026 the Director of GCHQ used the agency's first ever Annual Lecture at Bletchley Park to say UK cyber security needs to be 'ten times more urgent', from boardrooms to living rooms. Eight working days later, on 10 June 2026, the Cyber Security and Resilience Bill reaches report stage in the Commons. We unpack what the speech and the Bill mean for UK schools, charities and businesses - who are largely exempt from the Bill directly but not from its supply-chain cascade - and what to do across the next 30, 60 and 90 days.

Related services
Blog post

NCSC and the Five Eyes Just Warned About Agentic AI. Here's What UK Schools, Charities and businesses Should Actually Do Before Switching It On.

On 18 May 2026 the NCSC reissued joint guidance with CISA, the NSA and its Australian, Canadian and New Zealand counterparts on the 'Careful Adoption of Agentic AI Services.' Agentic AI - AI that does not just answer questions but plans, decides and takes actions inside your IT environment - is now arriving inside the SaaS that UK schools, charities and businesses already pay for. We unpack what changes about the risk picture, why the procurement signal is invisible, and what to do across the next 30, 60 and 90 days before switching it on across the organisation.

Related services
Blog post

The Canvas LMS Breach of 2026: What UK Schools, Universities, Charities and businesses Should Do This Quarter

ShinyHunters compromised Instructure's Canvas LMS via the free Free-for-Teacher programme in late April 2026 and lifted around 3.65 TB of data covering roughly 275 million records and 8,809 institutions worldwide, including Oxford and a long list of other universities. Instructure reached an agreement on 11 May. We unpack the entry route, why it lands harder on UK schools, charities and businesses than it might appear, and what to do across the next 30, 60 and 90 days.

Related services
Blog post

The UK Just Renewed Its Cyber Resilience Pledge. Here's What Signing It Actually Asks of businesses, Charities and Schools.

The UK government renewed its call on 12 May 2026 for organisations across the economy to sign the Cyber Resilience Pledge, the voluntary commitment first announced at CYBERUK 2026 on 22 April. The Pledge bundles three actions - board-level cyber ownership, the NCSC's free Early Warning service, and Cyber Essentials across the supply chain - into one signed, dated declaration. We unpack the three actions, why they map onto every major UK cyber story of the last twelve months, and what UK schools, charities and smaller businesses should do over the next quarter to be ready when the public signatory list opens in summer 2026.

Related services
Blog post

Cyber Insurance Just Got Stricter for UK businesses, Charities and Schools. Here's What to Have Ready Before Your Next Renewal.

BIBA's 2026 broker conference opens in Manchester on 13 May with cyber insurance as a feature topic for the first time, and the timing is not accidental. Premiums, exclusions and claim outcomes are now driven by a small set of security controls - the same controls Cyber Essentials Danzell now treats as auto-fail and the same controls the M&S, Co-op and Harrods stories told us actually matter. We unpack what underwriters are asking in 2026, where claims are getting denied, and what UK schools, charities and smaller businesses should have ready before they renew.

Related services
Blog post

NCSC Just Said 'Leave Passwords in the Past'. Here's What UK Schools, Charities and businesses Should Actually Do Next.

Last week the NCSC took a position it had been carefully avoiding for years: passkeys, not passwords, should now be the default way to log into online services. We unpack what changed in the April 2026 guidance, why it lines up so neatly with Cyber Essentials Danzell, the 2025/2026 breaches survey and the M&S supplier story - and the four things UK schools, charities and smaller businesses should actually do in the next ninety days.

Related services
Blog post

One Year On From M&S: What UK Schools, Charities and businesses Should Actually Do About Supplier Risk

It is one year since Marks & Spencer disclosed the cyber attack that took down its tills, click-and-collect and online store. The attackers did not exploit a zero-day - they phoned an outsourced IT helpdesk and got a password reset on a third-party supplier's account. We walk through what the M&S, Co-op and Harrods incidents really tell UK schools, charities and smaller businesses about supplier and service-desk risk - and the five things to change in the next ninety days.

Related services
Blog post

The 2026 Cyber Security Breaches Survey Just Landed. Here's What UK Schools and Smaller Businesses Should Actually Do With It.

DSIT published the Cyber Security Breaches Survey 2025/2026 on 30 April 2026. The headline of '43% of UK businesses breached' is broadly flat year on year, but the interesting findings are in the small movements - phishing increasingly AI-assisted, ransomware impact roughly doubled, and supply-chain reviews almost non-existent for smaller organisations. We unpack what the report actually says and the five things UK businesses, charities and schools should change in the next ninety days.

Related services
Blog post

Cyber Essentials v3.3 'Danzell' Went Live This Week. The First Auto-Fail Rules Will Catch People Out.

On 27 April 2026, Cyber Essentials v3.3 ('Danzell') replaced Willow as the mandatory question set. For the first time in the scheme's history there are auto-fail questions — missed MFA on a cloud service or a high-risk patch left longer than 14 days will now fail the assessment outright. Here is what changed and what to fix before your next renewal.

Related services

Want a guide tailored to your environment?

If you tell us your context (education/business/hybrid) and constraints, we’ll point you to the most relevant starting point.