One year and one week after attackers first crossed Jaguar Land Rover's perimeter, the Cyber Monitoring Centre's 1.9 billion pound UK economic-damage estimate acquired a much more concrete shape on Friday 5 September and this morning: JLR has opened a voluntary redundancy programme aimed at cutting up to 4,000 salaried and management roles across its UK operations over the next two years, targeting 1.7 billion pounds of cost savings and a reduced break-even point of 300,000 vehicles a year. Business Secretary Jonathan Reynolds meets the JLR leadership team this week. Meanwhile, line-by-line scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill continues in Grand Committee today (day three, from 15:45) and on Wednesday 9 September (day four), closing the four-day Committee stage that opened on 1 September; contested amendments on data-centre threshold symmetry, senior executive liability and statutory customer-communication windows are expected to be tested this week. Held back from post #35 because it was already five weeks old on Thursday, the Police National Legal Database (PNLD) breach — identified 26 July and confirmed 3 August, ExfilSquad actor, about 135,000 law enforcement contact records leaked to the dark web — had its technical root cause in a Microsoft Power Platform misconfiguration: sharing settings left where the vendor put them, not a CVE. Three jobs for the week commencing 8 September: (1) bring three numbers (27% board ownership, 1.9 billion pound JLR economic damage, ~4,000 UK jobs on a two-year runway inside JLR) to your next senior meeting and get cyber ownership assigned by name, in writing; (2) read Hansard for Committee days three and four and note which contested amendments are withdrawn (they will return at Report stage, likely mid-to-late October); (3) check who can create Power Platform apps and flows on your Microsoft 365 tenant, and who they can share with. Every action recommended is free or near-free and deliverable inside the week.
Key takeaways
- One year and one week after attackers first crossed Jaguar Land Rover's perimeter on the evening of Sunday 31 August 2025, JLR opened a voluntary redundancy programme on Friday 5 September and confirmed it this morning, aiming to cut up to 4,000 salaried and management roles across its UK operations over the next two years, targeting 1.7 billion pounds of cost savings and a reduced break-even point of 300,000 vehicles a year. Business Secretary Jonathan Reynolds meets the JLR leadership team this week. This is the moment the Cyber Monitoring Centre's 1.9 billion pound economic-damage estimate acquires a concrete UK jobs shape on top of the ~5,000 supplier businesses already in the figures.
- Line-by-line scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill continues in the House of Lords Grand Committee today (Monday 7 September, from 15:45) and again on Wednesday 9 September, closing the four-day Committee stage that opened on 1 September. Three clusters of contested amendments are worth watching this week: data-centre threshold symmetry, senior executive liability, and a statutory customer-communication window. Every contested amendment withdrawn in Grand Committee typically returns at Report stage, which is likely to be in mid-to-late October.
- The Police National Legal Database (PNLD) breach — identified 26 July 2026 and confirmed 3 August, with the ExfilSquad threat actor claiming a 1.9 GB dataset of roughly 135,000 law enforcement contact records leaked to the dark web — had its technical root cause in a Microsoft Power Platform misconfiguration. Not a CVE, not a zero-day, not ransomware: sharing settings on Power Apps, Power Automate, Power Pages and Dataverse left where the vendor put them. This is the third confirmed UK ExfilSquad drop in the running story after the DfE anchor of post #33, and the second UK breach of 2026 whose root cause is configuration rather than code.
- The 27% figure — the share of UK businesses whose board members, trustees or directors explicitly own cyber security, down from 38% three years ago in the Government's Cyber Security Breaches Survey 2025/2026 — is the single most consequential UK cyber statistic of 2026. Cyber ownership does not need a Chief Information Security Officer; it needs one named human being with the authority to say yes and no. Bring the 27%, the 1.9 billion pound JLR economic-damage figure and the 4,000 UK jobs to your next senior meeting and get the answer minuted.
- Three jobs for the week commencing Monday 8 September 2026: (1) name and minute the human being on your senior team who owns cyber, using the free five-principles Cyber Governance Code of Practice as the framing; (2) read Hansard for Committee days three and four (Tuesday and Thursday mornings) and note which contested amendments are withdrawn ahead of Report; (3) audit who can create Power Platform apps and flows on your Microsoft 365 tenant and who they can share with — a thirty-to-sixty-minute admin exercise inside admin.powerplatform.microsoft.com that produces a paper trail and costs nothing.
Three days after ReadyToday's last walk-through, and one year and one week after attackers first crossed Jaguar Land Rover's perimeter on the evening of Sunday 31 August 2025, the £1.9 billion economic-damage estimate that the Cyber Monitoring Centre published in June has this weekend acquired a much more concrete shape. On Friday 5 September and confirmed this morning, JLR opened a voluntary redundancy programme aimed at cutting up to 4,000 salaried and management roles across its UK operations over the next two years, targeting £1.7 billion of cost savings and a reduced break-even point of 300,000 vehicles a year. Business Secretary Jonathan Reynolds is due to meet the JLR leadership team this week to discuss the restructuring; the company employs about 30,000 people across the UK, chiefly at Solihull in the West Midlands and at Halewood on Merseyside.
The formal JLR statement puts falling sales, US tariffs, and the recovery from last year's cyberattack side by side. The 4,000 figure is not a "cyber-caused" number in the narrow sense; JLR has plenty of other headwinds and the redundancy programme is company-wide restructuring rather than a direct line item on the incident. But this is the moment at which the audience that has been reading ReadyToday's coverage of JLR through post #27 (Russian attribution) and post #35 (the one-year-on Cyber Monitoring Centre modelling) can see what a £1.9 billion economic hit converts into: a 4,000-headcount voluntary programme at the anchor employer, on top of the roughly 5,000 supplier businesses the Cyber Monitoring Centre already had in its figures. The lesson for a UK secondary school or an independent charity is not that they are one week away from a JLR-scale event. The lesson is what a Category 3 cyber incident at the top of a supply chain looks like twelve months later: the numbers do not go back into the box.
That is the first anchor of this post, and it is worth pausing on before we get to the Committee days that sit in front of us this week.
Committee days three and four are this week
Line-by-line scrutiny of the Cyber Security and Resilience (Network and Information Systems) Bill continues in the House of Lords Grand Committee today (Monday 7 September, from 15:45) and again on Wednesday 9 September, closing a four-day Committee stage that opened on 1 September. Post #35 walked through day one (1 September, Government Amendments 19, 36 and 44 agreed — the significance test now covers any data relating to the service, not only data about users) and day two (3 September, Baroness Harding's block of amendments to align UK incident-reporting with NIS2's 14-day interim and one-month final rhythm refused; the 24-hour initial notification plus 72-hour full report settled). Days three and four are the last chance to see contested amendments tested on the floor before Committee closes and the Bill moves to Report.
From the amendments paper published to bills.parliament.uk over the weekend, three clusters are worth watching this week. First, the data-centre threshold: day two included a debate about whether data centres should be judged against a broader "could have had a significant effect" test than the rest of the essential-services regime, with the ordinary significance factors omitted for the data-centre category. Peers pressed for symmetry across categories; the Government's line so far has been that data centres are structurally different because a single facility hosts many customer workloads. Second, senior executive liability: the ISC2-flavoured proposal to attach individual accountability at director level to the reporting duty (broadly analogous to NIS2's Article 20 but softer) is expected to be re-tabled this week. Third, customer-communication obligations: whether an entity that suffers a reportable incident should be under a statutory duty to tell its own customers, and inside what window, remains contested from day two.
Nothing predictive here. Every contested amendment in Grand Committee that is withdrawn typically returns at Report stage, which is likely to be in mid-to-late October. What the audience can usefully do this week is read Hansard for day three (published Tuesday morning) and day four (Thursday morning), and note which amendments are withdrawn on the understanding they will return, versus which are pressed to a vote and defeated (a Government defeat in Grand Committee is unusual and would be a signal to watch).
The Bill's calendar has not changed since post #35: Royal Assent is expected in late 2026, substantive effect follows around 2028 through secondary legislation, and the Government has an implementation consultation planned for later this year. The Cyber Governance Code of Practice that DSIT published in April 2025, and that the Government's Cyber Security Breaches Survey 2025/2026 continues to hold up as the voluntary answer to the falling board-level ownership number (38% in 2023 down to 27% in 2026), is the thing the audience can act on now, without waiting for the Bill.
The Police National Legal Database breach — an ExfilSquad sub-anchor
Held back from post #35 because it was already five weeks old on Thursday, the Police National Legal Database (PNLD) breach deserves its own paragraph now because the technical root cause is one every ReadyToday reader can check for on their own tenant. PNLD — the reference service used by police forces, criminal justice professionals and government partners across the UK, and the front end for the public-facing Ask the Police service — identified a data security incident on Sunday 26 July 2026 and confirmed on Monday 3 August that data had been leaked to the dark web. The threat actor is ExfilSquad, the same actor named in post #33's Department for Education anchor; the claimed haul is a 1.9 GB dataset containing roughly 135,000 law enforcement contact records — names, work email addresses, organisations, police force areas.
The technical root cause, as reported by the Rescana threat-intelligence write-up and cross-referenced against PNLD's own notification, was a Microsoft Power Platform misconfiguration. Power Platform (Power Apps, Power Automate, Power Pages, Dataverse) is Microsoft's low-code environment inside Microsoft 365. It is enormously useful and its default sharing model is more permissive than most Microsoft 365 administrators expect: apps and flows can be shared with entire security groups, with the Everyone-in-organisation group, or, if a tenant admin has not tightened the environment-creation permissions, published to Power Pages sites that anonymous users can reach. There is no ransomware, no zero-day, no CVE number to patch. The break in the fence is a sharing setting that was left where the vendor put it.
This is the third confirmed UK ExfilSquad drop in the running story (DfE in post #33, PNLD, and now — separately — the group continues to add smaller UK victims to its leak site) and the second time this year the audience has seen a UK breach whose root cause is not code but configuration. Post #35's Beacon CRM and Manchester Airports Group anchor was JavaScript-embedded credentials on the public web; this one is Power Platform sharing settings on the private-but-permissive side of the same fence.
Three jobs for the week commencing Monday 8 September 2026
Job one — bring the numbers to your next senior meeting, and lock cyber ownership by name. The Cyber Security Breaches Survey 2025/2026 figure — 27% of UK businesses now have a board member, trustee or director whose role explicitly includes cyber security, down from 38% three years ago — is the single most consequential UK cyber statistic of 2026. Cyber ownership does not need a Chief Information Security Officer; it needs one named human being with the authority to say "yes, spend this" and "no, do not do that". Bring three numbers into your next senior team meeting or trustees' meeting this week: (a) the 27%, (b) the Cyber Monitoring Centre's £1.9 billion JLR figure, and (c) the roughly 4,000 UK jobs now confirmed to be on a two-year runway inside JLR. Ask, on the record, who owns cyber. Get the answer minuted. If the answer is "the whole team" or "IT does it", the answer is nobody, and you now have a written record you can take back to the same room next quarter. The Cyber Governance Code of Practice is free, five principles long, and written for the seat that has to answer the question.
Job two — read Hansard for Committee days three and four, and note which amendments are withdrawn. Day three sits this afternoon; the transcript should be on Hansard by Tuesday morning. Day four sits on Wednesday and the transcript should be there by Thursday morning. Reading twenty minutes of Hansard is not the same as reading the Bill. What the audience is looking for is which of the contested amendments — data-centre threshold symmetry, senior executive liability, statutory customer-communication window — are withdrawn on the understanding they will return at Report (probably mid-to-late October), versus which are pressed to a vote. If your organisation is inside the direct scope of the Bill (an in-scope Managed Service Provider, a data centre operator, a designated critical supplier), the Report-stage shape is the one to plan against; if you are a school, charity or SMB adjacent to that scope, the useful output of reading Hansard is knowing what your suppliers are being asked to promise you and by when. Post #35's 24-hour-clock tabletop job stays live this week and, if you did not run it last week, this is the week to put an hour in the diary and run it.
Job three — check who can create Power Platform apps and flows on your Microsoft 365 tenant, and who they can share with. Sign in to admin.powerplatform.microsoft.com as a global or Power Platform admin. Open Environments → Default → Settings → Product → Features, and check whether Power Platform environment creation is restricted to admins (it should be) or open to everyone (it is by default). Then open Environments → Default → Settings → Product → Privacy + Security → DLP policies, and check whether a data-loss-prevention policy exists that separates business connectors (SharePoint, Dataverse) from non-business connectors (Twitter, Dropbox, HTTP). If no DLP policy exists, that is the same class of oversight as PNLD's. Third, in the Microsoft 365 admin centre, open Reports → Usage → Microsoft 365 apps and check whether Power Apps and Power Automate usage looks proportionate to what your organisation actually builds — a spike in "makers" (users who have created an app) that nobody in IT can explain is a signal worth chasing. This is a thirty-to-sixty-minute admin exercise, produces a paper trail, and costs nothing. If you do not run Microsoft 365, the equivalent check on Google Workspace is Apps Script, App Maker (deprecated but not removed everywhere), and Looker Studio sharing scopes; on Salesforce it is Flow Builder and Experience Cloud sites.
What is not in this post
The Kido International first anniversary falls on Thursday 25 September 2026 — the Metropolitan Police confirmed at the time that the incident was reported to Action Fraud on that date last year — and is the strongest single next-run candidate, particularly for the early-years, school-nursery and MAT slice of the audience. Two teenagers were arrested; the Kido International Wikipedia timeline is the compact single source for the facts, and the Famly platform's role in the account-compromise chain remains the specific lesson.
The Section 164A DUAA three-month mark falls on Saturday 19 September 2026. The Deputy Commissioner's first substantive Section 164A commentary still has not landed. The Cambridge University Hospitals crocodile-enclosure ICO investigation has still not produced a public decision. The Craneware LSE breach continuation, the July 2026 sub-threshold UK power-plant NIS-gap story, the Polish district-heating attack, the HIVE360 UK payroll DragonForce claim, the NHS England "don't let curiosity kill your career" campaign and the DfE ExfilSquad continuation (post #33) are all live threads that have not moved enough this week to earn an anchor slot.
Also not here: post #35's Beacon CRM and Manchester Airports Group JavaScript-credential anchor. The TruffleHog/GitLeaks audit of your own public JavaScript remains the highest-yield technical job any reader can do this week if they have not already. This week's Power Platform sharing check is the same shape of job applied to the other side of the fence.
The single sentence
One year on from Jaguar Land Rover, the £1.9 billion number acquired a 4,000-job UK shape this weekend; Committee days three and four of the Cyber Security and Resilience Bill are today and Wednesday; the Police National Legal Database breach was a Microsoft Power Platform misconfiguration; and the highest-yield thing any reader can do this week is name the human being on their own senior team who owns cyber, in writing.
If any of this feels unclear on your own estate, ReadyToday is running free thirty-minute discovery calls through September specifically for organisations that want to walk through the Cyber Governance Code of Practice, the Committee-stage Bill shape, or the Power Platform sharing audit on their own tenant — book one and we will talk you through the specifics.