Resources

Cyber Security and Resilience Bill Enters Lords Committee, Beacon CRM and Manchester Airports Both Leaked Their Own JavaScript, and One Year On From Jaguar Land Rover: What UK Schools, Charities and SMBs Should Do in the Week Commencing 8 September 2026

Three anchors landed for UK schools, charities and small and medium-sized businesses across the five weeks since ReadyToday's last walk-through. First: line-by-line scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill began in the House of Lords Grand Committee on Tuesday 1 September 2026 and continued on Wednesday 3 September, with day three on Monday 7 September and day four on Wednesday 9 September. Government Amendments 19, 36 and 44 have already changed the significance test so it covers any data relating to the service, not only data about users, and the 24-hour initial notification clock is now settled after Baroness Harding's staged-reporting amendments were refused. Second: two unrelated British breaches, six weeks apart, landed with the same root cause. Beacon CRM, used by more than a thousand UK charities including Ark, English National Ballet, the Molly Rose Foundation and Macmillan Cancer Support Jersey, confirmed on 3 August that its entire database was copied after an AWS access key was found inside its own publicly-served JavaScript. Manchester Airports Group disclosed on 27 August that 8.7 million car-park, lounge, Fast Track and Wi-Fi customer records had been stolen from its Iterable marketing platform after API credentials were left inside client-side JavaScript on Manchester, Stansted and East Midlands booking journeys. Third: Sunday 30 August marked one year to the day since attackers first crossed Jaguar Land Rover's perimeter on Sunday 31 August 2025, with the Cyber Monitoring Centre now scoring the total UK economic damage at 1.9 billion pounds across roughly 5,000 supplier businesses. Three jobs pinned to this week (audit public JavaScript bundles for exposed API keys with TruffleHog or GitLeaks), before Wednesday 9 September (a one-hour 24-hour-clock tabletop against the incident-notification duty), and end of week (the one-page JLR-shaped who-calls-whom exercise for your top ten suppliers).

Key takeaways

  • Line-by-line scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill began in the House of Lords Grand Committee on Tuesday 1 September 2026, continued on Wednesday 3 September, and is scheduled to sit again on Monday 7 September and Wednesday 9 September. Royal Assent is expected in late 2026 and substantive effect around 2028, delivered through secondary legislation after a government implementation consultation planned for later this year.
  • Government Amendments 19, 36 and 44 were agreed on day one. They delete the words 'users of' from the significance test, so a reportable incident now means one that compromises any data relating to the service, not only data about users. The Minister confirmed this pulls in compromises of commercially sensitive information, exposed usernames and exposed access details. Incident playbooks whose trigger reads 'customer data touched' should be rewritten to read 'any data relating to the service was touched'.
  • The 24-hour initial notification clock is now the fixed point of the reporting duty, followed by a full 72-hour report. Baroness Harding's block of amendments to add a 14-day interim and a one-month final report to align with NIS2 was refused. UK organisations have spent seven years building 72-hour muscle around UK GDPR Article 33; the 24-hour front end must be triggerable by an on-call engineer's judgment, out of hours, before a full assessment or legal sign-off exists. That is the capability worth building this month.
  • Beacon CRM (used by more than 1,000 UK charities) and Manchester Airports Group (8.7 million customer records across Manchester, Stansted and East Midlands) both suffered breaches whose root cause was production API credentials left inside JavaScript bundles that their own websites served to every visitor's browser. Beacon's key was AWS; MAG's was Iterable. Free open-source tools (TruffleHog and GitLeaks) can grep public JavaScript for exposed key prefixes in a single command; any hit is a same-day rotation.
  • Sunday 30 August 2026 marked one year since attackers first crossed Jaguar Land Rover's perimeter on the evening of Sunday 31 August 2025. The Cyber Monitoring Centre's post-incident modelling now sits at 1.9 billion pounds of UK economic damage across roughly 5,000 supplier businesses. The specific supplier-side lesson, one year on, is the one-hour who-calls-whom exercise: one page, ten rows, three fields per row (the person you would ring on a Sunday evening at each of your top ten suppliers, the number that would still work if their main phone system was down, and the person at your organisation who would take their call).

Three things landed for UK organisations in the five weeks between ReadyToday's last walk-through (post #34, Qilin and Accesso, 29 July) and today. All three are timely, all three matter to schools, charities and small and medium-sized UK organisations, and all three have direct jobs attached that can be done inside the week commencing Monday 8 September.

The first is the House of Lords Grand Committee, where line-by-line scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill began on Tuesday 1 September and continued on Wednesday 3 September, with day three sitting on Monday 7 September and day four on Wednesday 9 September. This is the calendar peg ReadyToday has been counting toward since post #25 (DUAA Week One), post #32 (Second Reading), post #33 and post #34. It has now begun in public, the first Hansard transcript is on the record, and the first substantive change to the Bill has already been made.

The second is a pair of British breaches, six weeks apart and unrelated in operator, that landed with the same root cause and produced the same specific lesson for every UK controller running a customer-facing website. Beacon CRM, a customer-relationship platform used by more than a thousand British charities, confirmed on Monday 3 August that its entire database was copied by an attacker who found an Amazon Web Services access key exposed inside the JavaScript build artifacts that Beacon's own marketing website was serving to every visitor. Manchester Airports Group, the UK plc that operates Manchester, London Stansted and East Midlands, disclosed on Thursday 27 August that data on 8.7 million car-park, lounge, Fast Track and in-airport Wi-Fi customers had been stolen after an extortion actor found Iterable marketing-platform API credentials sitting inside the client-side JavaScript on MAG's booking journeys. Two different platforms, two different sectors, two different attackers, one identical mistake — a key in the JavaScript that the browser downloads on page load — and one identical outcome: total data set out of the door.

The third is a first anniversary. Sunday 30 August marked one year to the day since the attackers who brought Jaguar Land Rover to a five-week production halt on Monday 1 September 2025 first entered its network on the evening of Sunday 31 August 2025. The Cyber Monitoring Centre's post-incident modelling, published in the summer, now sits at £1.9 billion of UK economic damage across roughly 5,000 supplier businesses, and the New York Times investigation ReadyToday walked through in post #27 — which attributed the initial access to Russia-based actors on Friday 26 June 2026 — remains the last public statement on attribution. One year on, the specific job for every UK organisation with more than one supplier is the same job JLR's suppliers wished they had done in the last week of August 2025: rehearse the one-hour "who calls whom" call, once, out of hours, before the next JLR-shaped Sunday evening arrives.

Below is what those three anchors mean for a UK school, charity, or small or medium-sized business, and three jobs — each of them free or near-free and each of them deliverable inside the week commencing Monday 8 September.

Anchor one: The Cyber Security and Resilience Bill is now under line-by-line scrutiny in the Lords

The Grand Committee opened at the Moses Room on Tuesday 1 September 2026, the first opportunity peers have had to test the Bill clause by clause. Day two followed on Wednesday 3 September. Two further sittings are scheduled — Monday 7 September and Wednesday 9 September — after which the Bill will exit Committee and return to the floor for Report stage. Royal Assent is expected in late 2026 and the substantive effect of the regime — the reporting thresholds, the RMSP definition, the data-centre threshold factors, the customer-notification duty — will be delivered in secondary legislation across 2027 and 2028, following a government implementation consultation planned for later in 2026.

Three things are worth writing down from the first two days on the record.

One change to the Bill has already been made. Government Amendments 19, 36 and 44 were agreed on day one. They delete the words "users of" from the significance test. In plain English, an incident now counts as significant if it compromises any data relating to the service — not only data about users. The Minister said explicitly this pulls into the reporting duty compromises of commercially sensitive information, exposed usernames and exposed access details. For a school or charity building its incident playbook against the current draft, this is the first concrete instruction: if your trigger for a reportable incident is "customer data touched," it is already stale. The trigger should read "any data relating to the service was touched," which is a much wider net.

The 24-hour clock is now the fixed point. Baroness Harding — who, having taken TalkTalk through its 2015 breach, spoke with some authority — moved a substantial block of amendments to add a 14-day interim report and a one-month final report to match NIS2. The Government refused, on the basis that regulators can ask for more information whenever they need it. Her reply — that regulators asking for more whenever they choose is "a company's worst nightmare" and that organisations want "really clear black-and-white guardrails" — did not carry the day. So the shape of the incident-reporting duty is now settled: an initial notification within 24 hours of becoming aware of a significant incident, a full report within 72 hours, both going to the relevant regulator and the NCSC. UK organisations have spent seven years building 72-hour reporting muscle around UK GDPR Article 33. The 24-hour front end is a different function: it must be triggerable by an on-call engineer's judgment, out of hours, before a full assessment exists and before legal sign-off is available. That is the capability worth building now.

AI is named nowhere in the Bill. Amendments to define AI products as relevant digital services, and to give the AI Security Institute statutory pre-deployment testing powers, were both resisted. The AISI amendment was refused on the ground that a statutory role "would undermine the voluntary collaboration on which AISI operates." A cybersecurity Bill in 2026 with no AI clauses is a decision, not an oversight, and one worth noting alongside the NCSC Cyber Shield / agentic AI framing from post #30: the regulatory position is that agentic AI risk is handled by consent-based collaboration with AISI plus vendor-direction powers already in the Bill.

One statistic from the day-two accountability debate is worth pinning up: the Government's own Cyber Security Breaches Survey shows board-level ownership of cyber risk in UK organisations has fallen from 38% in 2023 to 27% in 2026. The proposed answer in the Bill is a voluntary Cyber Governance Code of Practice. For any UK organisation whose board has not walked through a cyber tabletop in the last twelve months, that number and that response are the reason to schedule one before the year turns.

Anchor two: Beacon CRM and Manchester Airports — the same mistake, six weeks apart

The Beacon CRM breach ran from 01:20 UTC on Monday 27 July to 02:47 UTC the same morning — one hour and twenty-seven minutes of window, entire customer database out. Beacon's forensic report, published to affected customers in early August and confirmed publicly on Wednesday 5 August, traces the intrusion to an Amazon Web Services access key that had been left inside the JavaScript build artifacts that Beacon's own marketing website served to any visitor. The attacker discovered the key, used it to authenticate to Beacon's AWS environment, and copied the platform's database backups and file attachments to an external S3 bucket. Beacon's own dark-web monitoring has, at the time of writing, seen no evidence of the data being sold or held for ransom, but the exposure is real and the affected customer list includes names ReadyToday's audience will recognise: the education charity Ark, English National Ballet, the Molly Rose Foundation, The Upper Room, Chiswick House and Gardens Trust, Sheffield Hospitals Charity, Macmillan Cancer Support Jersey, Motiv8 and UK-Med, among a total of around a thousand UK charities. The data set is what a CRM holds — donor and supporter names, addresses, phone numbers, email addresses, donation histories, membership records, contact preferences and file attachments — which is to say precisely the data set a phishing operator wants for a follow-on campaign.

Six weeks later, on Thursday 27 August, Manchester Airports Group notified customers that a third party had accessed data on approximately 8.7 million people whose journeys touched an MAG car park, lounge, Fast Track lane or in-airport Wi-Fi network at Manchester, Stansted or East Midlands. FulcrumSec, the extortion actor that claimed the theft, told BleepingComputer it pulled roughly 86 gigabytes of data from MAG's Iterable marketing platform. The mechanism: Iterable API credentials embedded inside the client-side JavaScript that MAG's booking journeys served to every visitor's browser. The data set exposed included email addresses, phone numbers, vehicle registration numbers and postcodes — enough to build a highly targeted phishing campaign against 8.7 million people who can be plausibly told a specific story about a specific booking they made at a specific UK airport.

Two operators, two industries — a charity CRM and a UK airport plc — six weeks apart, same technical root cause: production credentials that let the browser do things the browser was never meant to do, sitting inside a JavaScript bundle that anyone could open in developer tools and read. This is not a novel attack technique. It is the oldest of them, and it recurs because the deployment pipelines that build front-end JavaScript will happily inline whatever secret is in an environment variable at build time if the code is written to read one — and because, once inlined, the secret sits on a public CDN indefinitely, cached in every browser and search-engine crawler that has ever touched the page.

The specific instruction for every UK controller running a customer-facing website is one that is genuinely deliverable inside a working morning: search every JavaScript bundle your production website serves for the string prefixes that identify AWS, Google, Azure, Iterable, Stripe and other API keys. There are free open-source tools — TruffleHog and GitLeaks are the two most widely used — that do this in a single command against a public URL and produce a list of hits. If it produces any hits, rotate the keys the same day, invalidate the CDN cache, and open a change-request to move the affected calls to a server-side proxy. This is the single highest-value job in this post for any UK organisation that runs its own website. It is the exact job Beacon and MAG both wish they had done in July.

Anchor three: One year on from Jaguar Land Rover

Sunday 30 August 2026 marked the one-year point since attackers first crossed JLR's perimeter on the evening of Sunday 31 August 2025. The company's manufacturing lines stayed down for five weeks, its supply chain — around 5,000 UK businesses, from tier-one seat and wiring-harness manufacturers down to the small logistics firms that move parts between plants — went through the deepest supply-chain shock in modern British manufacturing history, and the Cyber Monitoring Centre's post-incident modelling now sits at £1.9 billion of UK economic damage. The New York Times investigation of Friday 26 June 2026, which ReadyToday walked through in post #27, attributed the initial access to Russia-based actors and remains the most substantive public statement on who did it. There is no public prosecution, no public regulatory action against JLR, and no public confirmation of ransom payment.

For a UK school, charity or SMB, the anniversary matters less as a story about JLR than as a story about JLR's suppliers. The £1.9 billion damage total lands mostly on the suppliers, not on JLR itself, and the smaller the supplier, the harder the hit. The specific lesson, one year on, is not "buy a better firewall" — it is the one-hour "who calls whom" tabletop, run once, out of hours, before the fact. In the week the JLR incident began, the suppliers who came through best were the ones whose operations directors could reach a JLR contact by name inside sixty minutes of a Monday-morning call from their fulfilment team. The suppliers who came through worst were the ones whose only contact route was an email address at a domain that was, that Monday morning, being scrubbed from the outbound mail queue. The job — for every organisation that has more than one supplier — is to write down, on one sheet of paper, the person you would ring on a Sunday evening at each of your top ten suppliers, the person they would ring at you, and the number that would still work if their main phone system was down.

Three jobs for the week commencing 8 September 2026

Job one, this week — audit your JavaScript for exposed credentials. For any UK organisation running a public-facing website, download your live JavaScript bundles and grep them for API-key prefixes. TruffleHog and GitLeaks both do this in one command; NCSC's Early Warning service (free to any UK-registered organisation, still worth enrolling in per the FortiBleed edge-device walkthrough in post #24) can also flag exposed keys once they are indexed by third-party scanners. Any hit is a same-day rotation. The Beacon and MAG cases show what an unrotated key looks like at scale: it looks like your entire customer list on someone else's disk. This is the four-supplier-questions shape from post #24 (FortiBleed) and post #31 (FortiBleed INC/Lynx) applied inward to your own build pipeline.

Job two, before Wednesday 9 September — the 24-hour clock tabletop. Even if your organisation is not directly in scope of the Bill (most UK schools, small charities and SMBs will not be), the reporting rhythm the Bill is settling on is going to become the industry norm across regulated suppliers you buy from, insurers you renew with, and grant funders that ask about your incident response. Run a one-hour tabletop: it is 02:00 on Sunday and your MSP calls to say a ransomware note has appeared. Who at your organisation makes the decision to notify a regulator inside 24 hours? Who has legal authority to sign the notification? Who covers if that person is on annual leave? Write it down. This is a direct extension of the Section 164A five-numbers exercise from post #34, applied to the incident-notification rather than the data-protection-complaints side of the same regime.

Job three, end of week — the JLR-shaped one-hour "who calls whom" for your top ten suppliers. One page. Ten rows. For each of your ten most important suppliers, three fields: the person you would ring on a Sunday evening, the number that would still work if their main phone system was down, and the person at your organisation who would take the call from them. Test one row this week: pick a supplier, ring the person you have listed at 17:00 on a Friday, and see whether the number rings through to a human. Almost every organisation that does this finds that at least one of the ten rows is wrong. This is what the JLR suppliers wished they had done in the week of Monday 25 August 2025.

What is not in this post

Deliberately held for future runs: the Kido International nursery-chain first anniversary, which falls on Friday 25 September 2026 (a year to the day since Radiant first published children's images on the darknet), and which will be the natural moment to walk the specific early-years and school-nursery lessons; the Cambridge University Hospitals 40-staff crocodile-enclosure data-snooping ICO investigation, referenced in post #34 and still without a public ICO decision; the July 2026 sub-threshold UK power-plant incident and the NIS Regulations 2018 100MW generation-threshold gap; the Polish district-heating attack that reached from a wind farm across a private cellular APN into a frozen town; the DfE ExfilSquad continuation story (post #33); the Deputy Commissioner's still-awaited first substantive Section 164A commentary; and the amendments-list-with-Government-response document that will land after Report stage. Each is a live thread.

The three jobs above are the ones that pay back most inside the week commencing 8 September 2026. If any of them feels unclear on your own estate, ReadyToday is running free thirty-minute discovery calls through September specifically for organisations that want to walk through the JavaScript-credential audit, the 24-hour tabletop, or the JLR-shaped supplier phone-tree exercise on their own setup — book one and we will talk you through the specifics.

Written by Boris Didov