CBN Newsletter | August 2026

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.

This month, we examine the fallout from a wave of government data breaches, the machinery of government changes reshaping the Burnham government’s approach to cyber, and what recent AI containment incidents at OpenAI and Anthropic mean for those managing frontier AI risk.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines

Photo credits: National Crime Agency (NCA)

Third government hack in a week exposes details of 100,000 police staff

Full names and contact details belonging to more than 100,000 police officers and staff have appeared on the dark web, following a breach that also touched the Ministry of Defence, Home Office, National Crime Agency and Crown Prosecution Service. Reported by The Times on the 2nd August, this marks the third such incident to hit the government in a week, after the Department for Education had over half a million records compromised only days earlier.

The breach originated in the Police National Legal Database (PNLD), a system used by officers across England and Wales for day-to-day legal guidance. A group calling itself ExfilSquad is believed responsible, having compromised 114,000 subscribers to the database along with smaller numbers of staff at the CPS, Home Office, NCA and MoD. Very little is known about ExfilSquad, however details are expected to emerge in the coming days.

The pattern points to a wider problem than any single system failing. ExfilSquad has also claimed attacks on Newcastle University, two US city governments and, unconfirmed, Microsoft customer records including password hashes.

ESET’s Jake Moore noted that government bodies are increasingly viewed as softer targets, often because underinvestment in basic protections leaves legacy systems exposed. This is something that the government has tried to address, such as through the £210 million Government Cyber Action Plan announced in January this year.

If you have any questions about this breach, or about the government’s current resilience measures, please feel free to get in touch at secretariat@cb-network.org.


Autonomous AI models breach containment: what the OpenAI and Anthropic incidents mean for cyber risk

Within days of each other, OpenAI and Anthropic both disclosed that their frontier models had broken out of controlled testing environments. Firstly, on the 21st July, OpenAI announced an unreleased model, built to work autonomously for long stretches, hit a sandbox restriction while testing a training improvement and found a way around to obtain test solutions directly from Hugging Face’s production database.

The following week, Anthropic announced an equally concerning incident. During ‘Capture the Flag’ exercises that strip away standard safeguards to test raw offensive capability, three models, including Claude Opus 4.7 and Claude Mythos 5, moved beyond their intended sandbox and touched real enterprise infrastructure rather than the isolated environment that the exercise was meant to confine them to.

While neither case indicated any malicious intent and both incidents were addressed quickly, this represents a worrying development for those working with frontier AI security models. Older models tend to stop when they hit a wall of this nature. However, models built to work independently for hours or days treat that wall as a problem to solve.

Both incidents were caught because deployment was limited and monitored, with the ability to pause and roll back. As agentic systems take on longer, more open-ended tasks, boards and security leaders will need assurance that a model’s entire course of action can be understood and stopped.


Policy & Political

Burnham government abolishes the Department of Science, Innovation and Technology – what does it mean for cyber?

New Prime Minister Andy Burnham has set out to dismantle the Department for Science, Innovation and Technology, with its responsibilities being divided up between the Department of Business, Innovation, Science and Trade, the Department of Digital, Culture, Media and Sport, and the Cabinet Office – returning to a similar structure to how it was in 2022.

Under the new plan, DSIT’s remit would be redistributed across three departments. The Cabinet Office would absorb some responsibilities, a newly created Department of Business, Innovation, Science and Trade would take on others as a merger of DSIT and the Department for Business and Trade, and other remits will move to an expanded Department for Digital, Culture, Media and Sport .

According to an internal memo reported by Computer Weekly, cyber security will fall under the remit of the Department for Digital, Culture, Media and Sport, alongside telecoms, media, online safety and the Government Digital Service (GDS).

Lisa Nandy remains Secretary of State, with her brief formally expanded to restore responsibility for digital policy. Ian Murray stays in the department as Minister of State, the most senior role below the Secretary of State, alongside Stephanie Peacock, Vicky Foxcroft, Baroness Twycross and newly appointed peer Ruth Mackenzie as junior ministers. Baroness Lloyd of Effra has been confirmed as Parliamentary Under-Secretary of State at DCMS, alongside her existing role as Parliamentary Under-Secretary (Digital Economy Minister) at DBIST.

Separately, Kanishka Narayan has been appointed to a new cabinet-level Secretary of State role for AI, signalling that artificial intelligence policy will be treated as a major, standalone priority rather than folded into a broader technology brief.

If you have any questions about what this departmental shakeup might mean for your organisation, feel free to get in touch at secretariat@cb-network.org


Parliament presses government on mandatory ransomware reporting

Gordon McKee, Labour MP for Glasgow South, tabled a question to the Home Office in July whether the government plans to introduce mandatory reporting of ransomware incidents and payments, putting fresh parliamentary attention on proposals that have been in the works since last year’s consultation.

Home Office Minister Sarah Jones MP replied, stating that the measures are designed to strike at the ransomware business model by giving law enforcement more information and sharpening the government’s understanding of the threat landscape. Bringing ransomware activity out of the shadows, she said, will improve the intelligence picture and support more effective disruption of those responsible.

The exchange follows the Home Office’s consultation on legislative proposals to tackle ransomware, which ran from January to April 2025 and drew 273 responses. The government’s response confirmed it intends to legislate on three fronts. Firstly, as Minister Jones highlighted in her response, mandatory incident reporting would be brought in, requiring all UK organisations to report suspected ransomware incidents regardless of whether a payment was made. This measure drew broad support from consultation respondents at 63%.

Secondly, public sector bodies and CNI operators would face a targeted ban on paying ransoms, with no notification or exemption route, a measure that drew 72% support. Thirdly, businesses outside those categories would instead be required to notify the government before paying a ransom, so authorities can assess the situation and potentially offer alternatives, backed by 47% of respondents.

A 72-hour initial reporting window is under consideration, though which organisations fall in scope and what penalties apply for non-compliance remain undecided. Currently, no date for legislation has been set. CBN will continue to track the Bill’s progress and keep members updated as further detail emerges.


Business & Industry

Britain’s biggest firms sign the government’s Cyber Resilience Pledge as threat landscape continues to change.

More than 60 businesses have signed the Government’s new Cyber Resilience Pledge, launched at 10 Downing Street on 7th July by Technology Secretary Liz Kendall. Founding signatories span retail, financial services, media, utilities and technology, including M&S, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte, Accenture UK etc.

As a reminder, the Pledge is voluntary and designed principally for medium and large organisations, though open to any sector or size. It asks signatories to take three concrete actions: to treat cyber security as a board-level responsibility by adopting the Cyber Governance Code of Practice and completing the NCSC’s Cyber Governance Training at board level; to register for the NCSC’s free Early Warning service, which flags suspicious activity on organisational networks; and to take a risk-based approach to mandating Cyber Essentials certification across an organisation’s supply chains.

The pledge was introduced against the backdrop of an increasingly dangerous cybersecurity landscape. According to the government’s Cyber Breaches Survey, over 5 million cyber crimes were committed against UK firms in the past year, which is roughly one every six seconds. while the NCSC handled 204 nationally significant incidents in the year to September, up from 89 in 2025.

The Pledge is a central part of the government’s upcoming National Cyber Action Plan, which will set out further investment in AI-powered defensive capabilities. If you have any questions about the pledge, please feel free to get in touch at secretariat@cb-network.org.


CBN Updates

Cyber Innovation APPG hears from parliamentary roundtable on digital sovereignty in the UK

On the 15th July, members of the APPG for Cyber Innovation convened a roundtable discussion with industry, academics, and parliamentarians to test working definitions, compare the UK’s position with the EU and other international partners, and identify where policy or governance gaps most need addressing.

The discussion was chaired by Lord Clement-Jones who opened by noting that ‘digital sovereignty’ is a term widely used but without a universal definition. Participants how sovereignty could be defined, separating sovereignty into three layers: technological sovereignty (owning the technology), operational sovereignty (the ability to switch providers) and governance (a UK-specific trustworthy framework).

There was some divergence on views around alignment with international standards, including the EU’s digital sovereignty package in June. Delegates also examined the merits of establishing a codified digital sovereignty strategy, and how this could also act as a potential area for growth in UK tech.

To read the full write-up from the event, please click here. If you’d like to contact the APPG secretariat, please send an email to secretariat@cb-network.org with the subject line: “For the attention of the APPG:”.


NCSC Updates


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.

CBN Newsletter | May 2026

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.

This month, we examine the King’s Speech and its implications for the cyber sector, explore the findings of the latest Cyber Breaches Survey, and follow up on the industry hype surrounding frontier AI models such as Claude Mythos.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines

Photo credits: Getty Images

King’s Speech goes ahead amid political chaos – what did it say about cyber?

On Wednesday, the State Opening of Parliament took place, with the highly anticipated King’s Speech delivered in a fraught political environment, with ongoing speculation over potential leadership challenges to Sir Keir Starmer’s premiership. Broadly, the Speech set out a legislative agenda centred on building national resilience, improving public services, and strengthening the UK’s international partnerships.

On cyber specifically, the King stated that the Government will ‘introduce legislation to improve the country’s defences against cybersecurity threats’. This refers to the long anticipated Cyber Security and Resilience Bill currently before Parliament. As of today, the Bill has completed its committee stage and is awaiting dates for its report stage in the House of Commons.

The King’s Speech also trailed an upcoming Digital ID Bill, signalling the Government’s intention to introduce a Digital ID scheme in the UK. However, the announcement contained very little detail on the design, scope or implementation timeline of the scheme, and further clarity will only emerge as draft legislation and guidance are published.

In addition, the Government intends to bring forward a Regulatory Reform Bill aimed at streamlining regulation and reducing the burden on businesses, with the stated goal of ensuring that regulatory requirements don’t act as a barrier to innovation.

That said, given that the Cyber Security and Resilience Bill will strengthen the oversight of regulators, we do not expect that a new Regulatory Reform Bill would have a material impact on the new cyber incident reporting regimes, or the tightening of regulatory powers, mandated by the Cyber Security and Resilience Bill

We’ll continue to follow any updates on the government’s overarching cyber strategy and will be keeping members updated. If you have any questions about the King’s Speech, or the government’s cyber strategy, feel free to get in touch at finlay@cb-network.org.


UK cyber breaches survey: Attack rate unchanged, but phishing and fraud continue to target British business

The government’s 2026 Cyber Security Breaches Survey shows that cyber attacks remain a stubbornly high risk for organisations. According to the findings, 43% of UK businesses experienced at least one cyber breach or attack in 2025/26, unchanged from the previous year. This equates to approximately 612,000 businesses impacted in the last 12 months. This is down from the high of 50% recorded in 2023/24 but still representing a major and persistent threat landscape.

Phishing remains the most common type of incident, affecting 38% of businesses, the same level as in 2024/25. However, traditional phishing emails are now being compounded by voice‑phishing and other social engineering tactics, which attackers increasingly use to gain undue access to systems, steal credentials and install other forms of malicious software.

The survey highlights the growing problem of fraud directly enabled by cyber incidents. An estimated 3% of all businesses and 1% of all charities suffered fraud that resulted from a cyber breach or attack in the last year, equating to around 43,000 businesses, 3,000 charities and roughly 130,000 cyber‑facilitated fraud events. 

Financial impacts to affected organisations vary widely. When including cases where organisations reported no direct financial loss, the median perceived cost was £110, with most falling between £0 and £2,000 and the top 10% reaching £12,000. Excluding zero‑cost cases, the median rises to £500, with most between £150 and £5,000 and the top 10% hitting £15,000.


Policy & Political

Government urges businesses to strengthen cyber defences as AI threats accelerate

Amidst growing threat from AI cyber capabilities, the government is urging businesses to sign the new Cyber Resilience Pledge, backed by £90 million in government investment as part of the government’s larger cyber resilience strategy. Baroness Liz Lloyd, Minister for Digital Economy, has warned that traditional cyber protections alone are not enough, with AI lowering the barrier for criminals to find vulnerabilities and launch attacks at a scale that would have been impossible even a year ago.

The Cyber Resilience Pledge sets out three steps to improve cyber security across organisations. Firstly, by mandating cyber security as a board-level responsibility. Secondly, signing up to the NCSC’s free Early Warning Service, and thirdly, mandating Cyber Essentials certifications across the organisation’s supply chains. Ministers have written directly to leading UK companies urging sign-up.

The announcement is accompanied by strong figures for the UK’s cyber sector. The government press release states that the sector at large grew 11% last year to £14.7 billion, with the number of firms rising 20% to 2,603 and 2,300 new jobs created. 

Additionally, the number of UK firms offering cyber security products specifically for AI rose 68% in 2025, underlining the scale of emerging opportunity across the industry amid the ongoing cyber-AI discussion centering around the release of frontier AI models, such as Anthropic’s Claude Mythos.


Britain must act now to secure AI future, warns Technology Secretary Liz Kendall

Following the launch of the government’s Sovereign AI Unit on April 16th, which acts as a state-backed venture capital fund, the government has been announcing major investments, Technology Secretary Liz Kendall has warned that Britain must move decisively to cement its place in a new AI-driven era of global power, security and prosperity. In a speech at the Royal United Services Institute (RUSI) on the 28th April, Kendall argued that technology has become the ‘defining currency’ of the modern era.

Kendall stressed that AI sovereignty is about reducing over‑dependence and increasing resilience in key national priorities. To support this domestic ecosystem, she announced that the government will develop a UK AI Hardware Plan that will be released in June during London Tech Week; the fully funded access to the UK’s largest supercomputers for over 30 companies; and the £400m the Ministry of Defence has ringfenced to back British-built AI and innovative technologies.

Kendall highlighted the growing concentration of AI capability, noting that 70% of global AI compute is now controlled by just five companies. Control over where AI systems are built and how they operate is now ‘fundamental to economic security, energy security and defence security’. Kendall warned that failing to master AI risks ceding control over the future of the tech sector.


Business & Industry

AI cyber capabilities are advancing faster than expected, according to the UK AI Security Institute

The UK’s AI Security Institute (AISI) has published new findings which show that frontier AI models, such as Anthropic’s Claude Mythos and GPT-5.5, are able to carry out increasingly complex cyberattacks autonomously, and the progress of their abilities are accelerating.

As a reminder, Anthropic announced their new Mythos model last month, which triggered an intense reaction across the cyber sector. The model has already shown itself to outperform many humans in finding and exploiting cyber vulnerabilities, and has uncovered thousands of previously unknown bugs. 

AISI’s new research measures the time difference between an AI model and a human cyber expert in completing complex cyber tasks. Since late 2024, that figure has been doubling roughly every few months. In February 2026, the doubling rate was estimated at 4.7 months, already faster than the 8-month estimate from November 2025.

Most strikingly, Mythos became the first AI model to complete both of AISI’s ‘cyber range’ simulations, which are realistic multi-step attacks against small enterprise networks. One range was solved in 6 out of 10 attempts; the other, previously unsolved by any model, was completed in 3 out of 10.

As the capabilities of cyber AI models grow, boards should realise that the window to build strong security foundations is now. Frontier AI models are already helping defenders find vulnerabilities, but it’s important to remember that the same capabilities are available to attackers.n 


CBN Updates

AI cyber capabilities are advancing faster than expected, according to the UK AI Security Institute

On Monday, 11th May, CBN attended a briefing on the Government Cyber Action Plan, announced earlier this year, with Bella Powell, Government Chief Information Security Officer (CISO) and Director of the new Government Cyber Unit. 

It was great to see engagement between government and industry on key issues of cyber resilience within the public sector. CBN is looking forward to continuing to engage with government and industry leaders to help strengthen UK cyber resilience.

Through recent briefings with CBN and DSIT on the upcoming National Cyber Action Plan, our January roundtable on the Cyber Security and Resilience Bill, and attending this briefing on the Government Cyber Action Plan, CBN is closely engaged with, and fully up to date on, the government’s evolving cyber strategy.

If you’d like to get involved with CBN’s work, feel free to get in contact at secretariat@cb-network.org.


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.

This month, we look at new updates and guidance from the NCSC as CyberUK 2026 kicks off, examine the hype around Anthropic’s new ‘Mythos’ model, and review the government’s open letter on AI and cyber.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines

Head of NCSC warns that the UK is at the edge of a ‘perfect storm’ of cyber threat

Richard Horne, chief executive of the National Cyber Security Centre (NCSC), used his opening keynote at CyberUK in Glasgow to frame the next decade of UK cyber security as navigating a ‘perfect storm’ of rapid technological change and intensifying geopolitical tension. 

His message to government, regulators, and organisations was that cyber security is now a core strategic capability and must be treated as such. Horne argued that AI in cyber defence, such as Anthropic’s new Mythos system, will be a net positive if the UK moves as fast as its adversaries. 

Frontier AI systems are already helping to identify and exploit vulnerabilities at scale, exposing organisations running unpatched, insecure or legacy systems. While the UK has not yet seen a wave of new AI‑driven attacks, Horne warned that defenders must adopt AI ‘at least as quickly’ as attackers, normalising AI‑enabled detection, monitoring and incident response. 

Horne also highlighted the sobering statistic that state-sponsored attacks now account for the majority of the NCSC’s nationally significant incidents, even as criminal ransomware remains the most common threat for most organisations.

Horne listed China, Iran and Russia as posing the greatest threat to the UK and Europe, and emphasised the importance of developing the UK’s offensive cyber capabilities in order to match escalating risks to national security. 


Anthropic announces Claude Mythos to mixed response across industry and government

Anthropic’s new Claude Mythos model, announced on the 7th April as part of the larger ‘Project Glasswing’, is a new model for Anthropic’s Claude AI designed to find and exploit software vulnerabilities. However, the new model has rapidly become a test case for how governments and regulators handle emerging technologies – particularly frontier AI.

Mythos is capable of identifying vulnerabilities by reading a program’s source code, configuration files, logs and documentation to map out an attack surface (inputs, APIs, authentication flows, etc.). It then applies its training on common bug patterns to identify weaknesses and vulnerabilities. 

Anthropic has said Mythos has already outperformed ‘all but the most skilled humans’ at finding and exploiting vulnerabilities, and has uncovered thousands of previously unknown bugs, some up to 27 years old, as reported by The Guardian.

This has triggered a large-scale reaction from both industry and government. NCSC CEO Richard Horne stated that it could be a net positive if the UK is quick to embrace it in his keynote address at CyberUK.

Meanwhile, in Washington, US Treasury Secretary Scott Bessent reportedly summoned the CEOs of major US banks, including Goldman Sachs, Bank of America, Citi, Morgan Stanley and Wells Fargo, to discuss the cyber risks posed by the potential use of Mythos by bad faith cyber actors. 


International cyber agencies warn on China-linked covert cyber networks

In a new joint advisory launched on the second day of the UK government’s CyberUK 2026 conference, international cyber security agencies are urging organisations to strengthen their defences against a growing threat from China-linked covert cyber networks. 

The guidance, led by the NCSC with the support of industry and 15 international partners across 9 countries, sets out how organisations can better protect themselves against attacker tactics used to hide malicious activity.

Covert networks take advantage of the Internet of Things (IoT) by compromising a number of smaller, everyday internet-connected devices, such as home routers or smart devices. NCSC are warning that these networks are currently being used by attackers linked to China in order to target critical sectors worldwide, steal sensitive data, and maintain persistent access to victims systems. 

The advisory also highlights the role of Chinese information security companies in creating and operating these covert networks. NCSC highlighted a China-based firm named Integrity Technology Group, which had been linked to the Flax Typhoon botnet and publicly called out by the NCSC and partners in September 2024. They were later sanctioned by the UK government for reckless and indiscriminate malicious cyber activity.


Policy & Political

UK ministers warn business on rapidly escalating AI-driven cyber threats

The government published an open letter on the 22nd April to business leaders from Security Minister Dan Jarvis and Secretary of State for Science, Innovation and Technology Liz Kendall that AI is currently transforming the cyber threat landscape, and that companies must urgently raise their game when it comes to cyber security policy.

Jarvis and Kendall highlight that advanced AI models, like the previously mentioned Mythos, can now perform tasks that once required rare specialist skills, such as finding and exploiting software vulnerabilities, at an unprecedented speed and scale. 

Recent testing by the government’s AI Security Institute (AISI) found Mythos to be significantly more capable in cyber offence than any system previously assessed, with frontier AI capabilities judged to be doubling roughly every four months. This has triggered an industry-wide shift, as OpenAI followed by expanding its Trusted Access for Cyber programme – including through a new partnership with Microsoft’s Secure Future Initiative, which was announced after the letter was published on the 23rd April.

The letter stresses that the UK Government is acting through evaluation capabilities at AISI, guidance from the NCSC, the Cyber Security and Resilience Bill, and the upcoming National Cyber Action Plan. But ministers are clear that government efforts alone are not enough, and that criminals will target organisations of all sizes, across every sector. 

The letter concludes by urging boards to treat cyber risk as a standing leadership issue, calling on organisations to adopt the Cyber Governance Code of Practice, rehearse incident response, and consider investing in cyber insurance. They also recommend achieving a Cyber Essentials certification and embedding the requirements across supply chains.


Photo credits: RUSI

Government publishes new Defence Diplomacy Strategy

The UK Government has published a new Defence Diplomacy Strategy, setting out how defence will be used more systematically as a tool of statecraft to support foreign policy, economic resilience, and industrial growth. 

The new strategy focuses on developing larger defence assets, including deployable military forces, specialist engineering, credible maritime presence etc. It also places emphasis on developing offensive and defensive cyber expertise. These tools will be used in support of the priorities of the Foreign, Commonwealth & Development Office, Cabinet Office, Home Office, Department for Business and Trade, and other government departments.

A central focus of the strategy is on integrating defence diplomacy with wider government activity overseas. That means all defence activity will be tightly aligned with cross-government objectives: countering hostile state activity, supporting allies, enabling trade, protecting critical infrastructure and promoting UK expertise in emerging domains, including cyber.

The new strategy will also work to deepen industrial partnerships and attract inward investment. Since July 2024, the UK defence sector has already secured a record £3.2 billion in foreign direct investment, and ministers argue that a secure, thriving and innovative defence industrial base is key to building lasting strategic relationships with allies and partners. 


NCSC Updates


Business & Industry

New research demonstrates culture of fear around reporting cyber incidents in UK businesses

New research from UK cybersecurity and cloud services provider Kocho reveals a worrying culture of fear and blame around cyber breaches in UK organisations. Out of the 501 UK CIOs, security analysts and IT professionals surveyed in the new research, 27% say they’ve felt pressured to cover up a security breach or data loss. This is despite the fact that 92% reported believing that their board understands day‑to‑day cyber realities. 

Businesses must currently report incidents under GDPR breach‑notification and NIS reporting regimes. The incoming Cyber Security and Resilience Bill, currently before Parliament, will mandate initial reporting after 24 hours for in-scope businesses.

Additionally, 20% of UK professionals reported a persistent culture of blame, and 14% said that they’ve been personally held responsible for incidents. Boardroom dynamics are reportedly a major stressor, with 73% saying that managing C‑suite expectations is demanding, rising to 81% in organisations with 100-250 employees. 

The research also highlighted a level of brutal honesty amongst them. 52% have been asked by boards or customers for cyber assurances they cannot honestly give. 39% believe clearer support and recognition from senior leadership would reduce stress, while 28% say visible executive backing for cyber priorities would make them feel more positive about their role.


CBN Updates

All-Party Parliamentary Group for Cyber Innovation holds briefing with DSIT to discuss Cyber Security and Resilience Bill

On Thursday 16th April, the All-Party Parliamentary Group (APPG) for Cyber Innovation met with the Government’s lead Minister on Cyber Security, Baroness Liz Lloyd of Effra, and the Department for Science, Innovation and Technology to discuss the progress of the Cyber Security and Resilience (Network and Information Systems) Bill ahead of its report stage in the House of Commons.

Alongside a comprehensive analysis of the Bill, the APPG also explored wider areas of the government’s cyber security policy with the Minister and DSIT. These included greater investment in cyber skills, the changing role of regulators, international standards alignment, and digital sovereignty.

If you’d be interested in keeping up to date with the activities of the APPG for Cyber Innovation, please feel free to follow the APPG LinkedIn page here

If you’d like to get in touch with the APPG secretariat, please email secretariat@cb-network.org


Events

Clarity Cyber Leaders Forum: Bridging the policy-industry gap on UK cyber resilience

The UK’s cyber resilience is being tested on every front – from escalating state-sponsored attacks to ransomware and supply chain threats. Yet, the way cyber progress is discussed in Westminster too often diverges from what security leaders can deliver day-to-day.

Clarity’s Cyber Leaders Forum will bring together Parliamentarians, senior security leaders and analysts for an on-the-record, fast-paced panel debate on how to close this gap and drive real-world security outcomes. 

Underpinned by new survey findings on where policy and industry priorities align, and where they don’t, the discussion will explore accountability, board-level preparedness, sovereignty, skills, AI, and the evolving threat landscape.

Our expert panellists include Matt Warman, Chair, Cybersecurity Business Network and former Minister for Digital, and Mark Ward, Senior Research Analyst at the Information Security Forum. 

See below for more event details:

Title: Clarity’s Cyber Leaders Forum

Date: Monday, 1st June 2026

Time: 17:00-19:30

Venue: Zetland House, 5-25 Scrutton Street, London, EC2A 4HJ

Format: Panel discussion, Q&A and networking

Places are limited – if you’d be interested in attending, please get in touch to secure your spot at secretariat@cb-network.org 


Join CyberSummit 2026 – Turning Cyber Threats into Resilience and Growth

Senior leaders from across the UK cyber ecosystem will come together on Tuesday 23 June 2026 for CBN’s inaugural CyberSummit.

Held at Bird & Bird, 12 New Fetter Lane, London EC4A 1JP, this full‑day forum (10:00–17:00, followed by networking) will bring together 100+ senior figures including policymakers, government representatives, CISOs and C‑suite executives from critical sectors such as health, finance, energy, telecoms and insurance.

The summit will move beyond threat awareness to focus on tangible, layered resilience strategies, structured around four core themes:

Open to CBN members, C‑suite leaders, technology heads and senior public sector representatives, CyberSummit 2026 is your chance to help shape a more resilient and prosperous digital future for the UK.

Please see more details about the CyberSummit here

If you have any questions about CyberSummit or any upcoming events, feel free to get in touch at secretariat@cb-network.org.


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.

CBN Newsletter | March 2026

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.

This month, we examine the heightened threat against UK businesses following the outbreak of conflict in Iran, as well as reviewing the government’s new ‘lock the door’ strategy, and analysing the market impact of new AI cybersecurity tools.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines

NCSC warns UK organisations over heightened Iranian cyber threat

The National Cyber Security Centre (NCSC) has issued a warning to UK businesses, urging them to prepare for heightened risk from Iranian cyber attacks following Britain’s defensive support for US-Israeli military action against Iran.

The NCSC has urged all UK organisations, particularly those with assets, operations or supply chains in the Middle East, to urgently review and strengthen their cyber defences. While Iran is currently experiencing internet outages as part of their wider communications blackout, the NCSC says state-sponsored hacking groups retain the capability to conduct cyber operations against the UK. 

Iran’s Islamic Revolutionary Guard Corps (IRGC) has long used both state-backed hackers and aligned ‘hacktivist’ groups to target Western interests, including attempts to disrupt or deface websites linked to US and Israeli businesses, and to run online influence and misinformation campaigns – such as an Iranian-backed campaign around Scottish independence, as reported by The Telegraph earlier this year. 

This is against the backdrop of a larger history of cyber operations in the conflict between the US, Israel and Iran, including the infamous ‘Stuxnet’ virus that targeted Iranian nuclear centrifuges at the Natanz nuclear enrichment facility, which was uncovered in early 2010. 

The NCSC is calling on UK companies, especially those with a significant presence in Gulf hubs such as Dubai and Abu Dhabi, to remain on high alert and act now to improve their cyber resilience.


New government campaign urges SMEs to ‘lock the door’ on cyber criminals

The UK government has launched a new cyber security campaign aimed at helping small and medium-sized businesses protect themselves from common online threats, amid rising costs to the economy estimated at £14.7 billion a year. 

Half of UK small firms have reported suffering a cyber breach or attack in the past 12 months, with significant incidents costing an average of £195,000, according to the government’s 2025 Cyber Breaches Survey

The campaign, led by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC), promotes the Cyber Essentials scheme, a government-backed standard that helps organisations put basic protections in place. 

Cyber Essentials focuses on five key controls: firewalls, secure configuration, software updates, user access control and malware protection. According to government statistics, organisations compliant to Cyber Essentials made 92% fewer cyber insurance claims last year.

Targeted particularly at SMEs, the campaign will run across social media, podcasts, radio and business networks, directing firms to practical, free tools including the Cyber Essentials Readiness Tool, free 30‑minute consultations with NCSC‑assured advisors, and access to the Cyber Essentials question set. 

Government and NCSC leaders stressed that cyber risk is now a core business risk, urging companies of all sizes to adopt baseline protections to safeguard jobs, growth and critical services.


Cyber Security and Resilience Bill completes committee stage

On the 3rd March, the committee stage of the Cyber Security and Resilience Bill concluded, following weeks of debate and industry evidence, including the evidence submitted by CBN to the Bill Committee.

The committee stage hearings on the Cyber Security and Resilience Bill brought together regulators, public bodies, industry and academia to scrutinise the government’s flagship cyber legislation to significantly expand and update the existing Network and Information Systems (NIS) framework. 

While there is broad agreement that the Bill is a positive step towards strengthening resilience in vulnerable sectors, witnesses raised concerns about scope, legal clarity and the potential burden on smaller firms.

Throughout the committee stage, industry voices called for clearer definitions and legal certainty throughout the Bill as it sought to expand the scope of NIS to cover data centres, large load controllers and managed service providers, and introduced a new five-step test to designate ‘critical suppliers’. 

Critics warned that heavy reliance on secondary legislation to define thresholds risks creating an ambiguous and costly compliance environment, particularly for SMEs, as well as pressing for more impact-based thresholds, and highlighted the need for a single, consolidated incident reporting portal. 

You can find CBN’s summary of insights from the Committee Stage in the following article.

While the committee stage has concluded with few amendments adopted to calm industry concerns, greater scrutiny and examination of the Bill is expected as it progresses to Report Stage in the House of Commons, before being sent to the Lords’ to undergo further debate.
The date of the Bill’s Report Stage has yet to be announced. If you have any questions about the Cyber Security and Resilience Bill, feel free to get in touch at secretariat@cb-network.org.


Policy & Political

UK steps up action against foreign interference in universities and politics

The UK government has announced new measures to strengthen protections against hostile state interference aimed at universities and the political system. 

Senior leaders from more than 70 universities attended a high-level security briefing led by MI5 Director General Sir Ken McCallum and NCSC CEO Richard Horne, focused on how foreign states seek to shape or censor research and teaching – and how institutions can resist and report such activity. A separate briefing was also held for officials from all UK political parties.

Backed by £3 million in new funding, the new measures introduce the ‘Academic Interference Reporting Route’, offering senior university staff a direct channel to raise concerns with government and the security services, plus a planned proactive advisory service, updated guidance, and training to help staff and students understand and respond to threats.

Security Minister Dan Jarvis reinforced the importance of tough action on foreign interference, stating that the UK must be “clear-eyed that our world-class universities and democratic processes are being targeted by states who want to undermine our way of life”.

In addition to the new measures, The Department for Education will also consult the wider sector on the design of a new proactive advisory service, alongside further guidance and training.


Northern Ireland Secretary visits Queens University Belfast’s Centre for Secure Information Technologies

On the 24th February, Secretary of State for Northern Ireland Matthew Patrick visited Queen’s University Belfast’s Centre for Secure Information Technologies (CSIT) and the Cyber-AI Hub to see how its research is advancing cyber security in areas such as secure hardware, critical national infrastructure protection and trustworthy AI.

Professor Paul Miller led the Secretary of State tour of CSIT’s state-of-the-art facilities, showcasing collaborative R&D with NI-based cyber firms on AI-enabled security and securing AI itself. PhD researchers presented lightning talks on their projects, while engineers demonstrated in-house adversarial AI defence technologies.

The visit served to demonstrate the importance of the cyber industry to the regional economy, as the 2025 NI Cyber Security Sector Snapshot identified over 2,750 cyber security roles in Northern Ireland and an estimated £258 million contribution to the local economy. The report underscored the importance of CSIT’s Cyber-AI Hub in driving collaboration and innovation.


NCSC Updates


Business & Industry

New AI tools rattle cybersecurity stocks amid fears over disrupted business models

Cybersecurity stocks fell sharply in late February as investors reacted to the release of new AI-powered security tools that could challenge traditional cybersecurity offerings. 

The market-wide sell-off followed Anthropic’s limited research preview of a new Claude-based security tool that can scan software code for vulnerabilities and suggest fixes, with further enterprise product announcements expected.

Major sector leaders including CrowdStrike and Zscaler dropped around 10%, Netskope and Tenable fell about 12%, while Okta, SailPoint, SentinelOne, Fortinet and Palo Alto Networks also lost ground. 

Industry executives pushed back against the market’s reaction, arguing that AI code-scanning tools remain a cutting-edge innovation, but not a replacement for full-scale, ‘battle-tested’ security platforms. This comes as AI-powered security platforms continue to divide expert opinion 


Government releases the results of fifth wave results from Cyber Security Longitudinal survey:

The government has released the fifth wave of results from its Longitudinal Survey on Cyber Security, showing that while incidents remain high, general cyber resilience measures do appear to be improving across industries and organisations. 

The study tracked how UK organisation’s cyber practices, policies and investments are changing over time, combining survey data from 2021–2025 with in‑depth qualitative interviews.

The results show that incidents are still widespread: 82% of businesses and 77% of charities experienced a cyber incident in the latest wave, with over half of organisations (54%) reported a similar incident experience across both time points measured. 

Adherence to NCSC’s Cyber Essentials program has risen significantly since the previous wave, with 30% of businesses now compliant (up from 23%) and 28% of charities (up from 19%). Organisations were also more likely over time to adhere to at least one recognised standard (Cyber Essentials, Cyber Essentials Plus or ISO 27001). 

Supplier security remained an issue, with the data showing that medium-sized businesses and charities were less likely over time to formally assess cyber security of suppliers. UK organisations have been urged to assess the security of their critical suppliers as the threat of supply chain attacks continues to increase.


Events

Join CyberSummit 2026 – Turning Cyber Threats into Resilience and Growth

Senior leaders from across the UK cyber ecosystem will come together on Tuesday 23 June 2026 for CBN’s inaugural CyberSummit.

Held at Bird & Bird, 12 New Fetter Lane, London EC4A 1JP, this full‑day forum (10:00–17:00, followed by networking) will bring together 100+ senior figures including policymakers, government representatives, CISOs and C‑suite executives from critical sectors such as health, finance, energy, telecoms and insurance.

The summit will move beyond threat awareness to focus on tangible, layered resilience strategies, structured around four core themes:

Open to CBN members, C‑suite leaders, technology heads and senior public sector representatives, CyberSummit 2026 is your chance to help shape a more resilient and prosperous digital future for the UK.

Please see more details about the CyberSummit here

If you have any questions about CyberSummit or any upcoming events, feel free to get in touch at secretariat@cb-network.org.


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.

CBN Newsletter | February 2026

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector. 

This month, we analyse the first two hearings at committee stage for the Cyber Security and Resilience Bill, as well as taking a look at the WEF’s Global Cybersecurity Outlook, and examining some big announcements across the industry.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines


Witnesses provide oral evidence for the Cyber Security and Resilience Bill at committee stage

The first two oral evidence sessions on the Cyber Security and Resilience Bill at committee stage, held on Tuesday 3 February, brought together witnesses from industry, regulators, public bodies and academia.

While they broadly welcomed the Bill’s aims, they also raised significant questions about its scope, its impact on supply chains, and the practicality of its incident reporting mechanisms. Witnesses further explored how the Bill could help foster a stronger cyber risk culture within organisations, and the role it might play in promoting cyber skills development and training.

Witnesses generally agreed that the Bill’s effectiveness would be improved by revisiting and adjusting its scope. Jen Ellis, Associate Fellow at RUSI argued that the Bill should move away from static sector lists towards size or impact‑based thresholds, such as FTSE 350 companies or widely used tech providers. There were also concerns raised by techUK and Nine23 around the Bill’s broad definition of a managed service provider (MSP), creating issues around clarity, and its narrow size threshold, which may leave many MSPs out of scope.

There was a broad welcome of bringing key supply‑chain providers into scope, but that was met with a recognition of the complexity of the issue. Ofcom stated that they would adopt a pragmatic regulatory approach, starting from the suppliers that operators themselves worry most about, and building a more cohesive methodology from there. However, not all witnesses agreed on which supply-chain providers should be in-scope, and how that should be determined.

However, there was a broad agreement that the incidence reporting mechanism needed to be streamlined. ISC2, techUK and others were uneasy about phrasing within the legislation around incident reporting, such defining cyber incidents as ‘capable of having a significant impact’, without providing clearer metrics (e.g. number of customers affected, geographic spread, duration). They warned this could drive over‑reporting, regulator overload and box‑ticking, especially among SMEs.

Written evidence will now be considered by the Public Bill Committee, with the first reading on Thursday, 5th February. In general, the voices of industry mirrored the concerns raised in the written evidence submitted by the Cybersecurity Business Network last week – which outlined recommendations around modifying the Bill’s scope, aligning the regulation with pre-existing resilience standards, streamlining incident reporting requirements, and ensuring board-level accountability.

If you have any questions around the Bill, or any amendments proposed at committee stage, please contact secretariat@cb-network.org.


Cyber‑fraud overtakes ransomware as top concern for business leaders

Phishing and cyber‑enabled fraud have overtaken ransomware as the leading cybersecurity concern for global business leaders, according to the World Economic Forum’s Global Cybersecurity Outlook 2026.

The report, released on 12 January 2026 ahead of the WEF Annual Meeting in Davos, warns that levels of cyber‑enabled fraud have reached record highs, and continue to erode trust in digital systems. The survey of global executives found that 77% have seen an increase in cyber‑enabled fraud and phishing, and 73% say they or a peer have been directly affected. 

Phishing is the most commonly reported threat, with the report emphasising the growth in email, voice (vishing) or SMS (smishing) scams. Other major issues include invoice and payment fraud tied to business email compromise (37%), identity‑related attacks (32%), insider or employee‑led fraud and romance or impersonation scams (both affecting around one in five), and growing concern about cryptocurrency and investment fraud.

The report also highlights the rapid escalation of AI‑driven cyber risks. Eighty‑seven percent of respondents experienced rising AI‑related vulnerabilities last year and 94% expect AI to be the dominant force shaping cybersecurity in 2026. The WEF argues that cyber risk is now a strategic, economic and societal challenge rather than a purely technical one, calling for coordinated action between governments, businesses and technology providers. 


New Chinese embassy sparks communication concerns

The plan to build a new Chinese embassy next to the Tower of London was approved by the government, following a lengthy debate around potential security risks.

The new site would be China’s largest embassy in Europe, hosting over 200 staff and consolidating seven existing diplomatic sites into one. The Security Service, MI5, says that this could make monitoring easier. Critics warn the complex could become a hub for espionage, cyber activity and intimidation of dissidents.

The Telegraph newspaper ran an article spotlighting concerns around a subterranean basement room being built within the embassy that will run alongside sensitive fibre optic cabling, transmitting data between the City of London and Canary Wharf – the city’s main two hubs of financial services.

Critics have raised potential communications interference or internet traffic monitoring, however, British intelligence services noted that it was ‘not realistic to expect to be able wholly to eliminate each and every potential risk’, in a letter addressed to the Home Secretary and Foreign Secretary.


Policy & Political

The UK and Japan agree to boost joint cybersecurity measures following state visit

On the 31st January, the governments of the UK and Japan agreed to accelerate co-operation on cybersecurity measures in the UK-Japan strategic cyber partnership. This followed Prime Minister Keir Starmer’s visit to Japan, and meeting with new Japanese prime minister Sanae Takaichi. The new partnership comes as tensions between Japan and China have heightened since Takaichi became prime minister, and fears around China’s offensive capabilities grow.

The strategic partnership commits both the UK and Japan to work together to address global cyber threats, based on three main pillars. Firstly, detecting, deterring and defending against cyber threats, secondly, enhancing whole-of-society cyber resilience, and finally, building an innovation ecosystem.

Both nationals have agreed to use their available cyber capabilities to help deter cyber threats facing both nations, and have reaffirmed their commitment to close collaboration, including around developing new technical standards, information sharing policies, and protecting both nation’s critical national infrastructure. 

The new measures reaffirm the previous Japan-UK Cyber Partnership as part of the so-called Hiroshima Accord, established by former prime ministers Rishi Sunak and Fumio Kishida in 2023. Closer collaboration between the Japanese and British cyber sectors could create greater market access for UK vendors, as well as offering more investment and partnership opportunities and a stronger deterrence posture against hostile states.


Parliamentarians urge stronger Cabinet action to tackle cyber-crime

Parliamentarians pressed the Government to step up efforts to combat cyber-crime, highlighting both the growing scale of the threat and the importance of home-grown cyber skills.

Responding to questions in the House, Dan Jarvis, the Minister of State for Security for the Cabinet Office, reaffirmed that the Government is ‘absolutely committed’ to using all available tools to disrupt cyber-threats and keep the public safe. He pointed to the upcoming national cyber action plan, designed to address evolving cyber-threats and emerging technologies, and confirmed that ministers are working closely with police to deliver ‘real-world impact’ against cyber-criminals.

Jim Shannon, DUP MP for Strangford, drew attention to the scale of the problem, noting that cyber-crime and fraud now account for around 50% of all offences in the UK, costing the economy billions each year. 

Jarvis reiterated the seriousness with which the Government treats cyber-crime and pointed to existing support for victims, including free guidance, tools and incident response advice courtesy of NCSC, alongside targeted awareness campaigns.


NCSC Updates


Business & Industry

RUSI publishes new Cyber Strategy paper

The Royal United Services Institute (RUSI), the world’s oldest and the UK’s leading defence and security think tank, published a new paper calling for comprehensive updates to the UK’s current cyber strategy. 

With cyber attacks costing UK businesses billions each year, and incidents like the Jaguar Land Rover breach exposing serious gaps in resilience, RUSI is advocating for the upcoming National Cyber Action Plan to become a critical opportunity to reset the UK’s cyber resilience strategy.

They call for a sharper focus on economic security, a new threat-response model that properly balances state-backed attacks and cybercrime, and a cross-government joint assessments unit to improve coordination. 

The paper also urges tougher accountability in both the public and private sectors: stronger cyber performance in government, mandated board-level responsibility for cyber risk, and more transparent reporting from companies.

Finally, it argues that regulators must be properly funded and empowered, including through annual fees from regulated organisations to support enforcement. Taken together, these steps would help fix market failures, strengthen resilience and better protect the UK’s infrastructure, economy and national security.


JLR still feeling the impact of 2025 cyberattack

Jaguar Land Rover is still feeling the impact of last autumn’s major cyber attack, reporting a further £64 million in related costs and a sharp downturn in performance. The incident forced a five‑week production halt from 1 September, contributing to an underlying pre‑tax loss of £310 million in the quarter to 31st December, compared with a £523 million profit a year earlier. 

Revenues for the quarter fell 39% to £4.5 billion as sales volumes were hit, with production only back to normal by mid‑November. JLR has now booked £260 million in direct cyber‑related costs this year (£196 million previously plus £64 million this quarter), helping push year‑to‑date losses to £444 million, versus £1.6 billion in profits a year earlier.

JLR’s new chief executive has said it had been a ‘challenging quarter’ but stressed that production is now back at normal levels and that JLR expects a significant improvement in performance in the final quarter, with ‘clear plans to manage global challenges.’


Events

CBN March Member Meeting

CBN will be holding its second bi-monthly members meeting of 2026 soon for paying members – keep an eye on your emails for further details.

If you’d be interested in attending our next meeting,, please drop us an email at secretariat@cb-network.org.

To become a member and ensure you won’t miss any of our events, please visit ​​cb-network.org/join-us/.


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.

CBN Newsletter | January 2026

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector. 

This month, we take a look at the newly released Cyber Action Plan, the long-awaited second reading of the Cyber Security and Resilience Bill, where the House of Commons will take its first opportunity to scrutinise the main aspects of the Bill, as well as a number of high-profile cyber incidents that occurred as 2025 was wrapping up.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines


Cyber Security and Resilience Bill undergoes second reading in the House of Commons

Today, the Cyber Security and Resilience Bill has undergone its second reading in the House of Commons. The Bill is set to be passed through the lower house, with the expectation of Royal Assent in mid-2026. 

The legislation represents the most significant effort to date in modernising the UK’s cyber framework by expanding the scope of regulated services, strengthening reporting requirements, and providing regulators with enhanced tools to enforce compliance. The legislation further develops the UK’s NIS regime, bringing it closer in line with the EU’s NIS2 directive.

The legislation aims to establish new definitions for relevant digital service providers (including online marketplaces, search engines and cloud computing services), and incidents (to include events capable of affecting network and information systems, even where no data has been compromised) 

The Bill will mandate 24-hour initial incidence reporting, with a full report required after 72 hours, as well as widening the range of organisations subject to cybersecurity standards, introducing data centres, as essential services under joint oversight from Ofcom and the Secretary of State for DSIT.

Following its second reading, the Bill will enter committee stage, where a detailed clause-by-clause examination will take place. During this process, Parliament will look to agree more complete definitions of which entities are in scope, what the exact penalty regimes may be for non-compliance, and specify more detailed security and resilience requirements.

During committee stage, cyber industry experts may wish to appear as oral witnesses, or submit written evidence to the Public Bill Committee when it calls for it. 

If you have any questions around the Bill, or any amendments that parliament may propose in the Bill’s second reading, please contact secretariat@cb-network.org.


Government announces Cyber Action Plan to strengthen resilience and incidence reporting for public sector and government departments

Prior to the second reading of the Cyber Security and Resilience Bill, the government announced its Cyber Action Plan on the morning of the 6th January 2026. The plan aims to strengthen cyber defences and digital resilience across government departments and the public sector, backed by over £210m of government funding. It is notable that the £210m of funding is far less than the similar £2.6bn pledged in the 2022 National Cyber Strategy for modernising public sector legacy systems to become more resilient.

Driven by a newly formed ‘Government Cyber Unit’, this plan supports a wider strategy by the government to digitise public services, improve online service accessibility, reduce times spent in online queues, and centralise access to government support and resources.

The plan focuses on achieving clearer visibility of cyber risks across government departments, acting to strengthen mitigation efforts and implementing faster and more robust incident response procedures.

Additionally, the government has announced the Software Security Ambassador Scheme, which aims to reduce software supply chain attacks through a new Software Security Code of Practice. Cisco, Palo Alto Networks (PAN), Sage, Santander and NCC Group have agreed to act as ambassadors for the scheme.

If you have any questions around the Cyber Action Plan and what it might mean working in, or closely with, the public sector, please contact secretariat@cb-network.org.


UK and Europe are under threat from Russian ‘information warfare’, warns Foreign Secretary

In a speech commemorating the centenary of the signing of the Locarno Treaties in 1925, the Foreign Secretary Yvette Cooper warned that ‘hybrid threats’ from Russia are threatening the UK and Europe, aimed at destabilising democracy, undermining collective interests and weakening critical national infrastructure. 

These hybrid threats include, but are not limited to, ‘relentless’ cyberattacks against businesses and critical infrastructure, dissemination of social media disinformation (including utilising generative AI), and state-sponsored sabotage. 

Cooper cited Russia’s campaign of ‘information warfare’ as a driving force that has led the UK to develop, and continue develop, its defensive cybersecurity, law enforcement and intelligence capabilities. 

In addition to the threat posed by Russia, the Foreign Secretary also raised the issue of Chinese-origin cyber threats. She used the speech to announce new sanctions on two China-based companies, i-Soon and Integrity Technology Group, which the government allege have been involved in ‘vast and indiscriminate cyber activities against the UK and allies’.


Hackers set their sights on government, with cyberattacks against the Foreign Office and Westminster City Council

The end of 2025 saw two cyberattacks launched against two major departments of national and local government. The Foreign, Commonwealth and Development Office (FCDO) and Westminster City Council both experienced cyber incidents in a pertinent reminder that the government remains a key target for cyber criminals.

The cyberattack affecting the FCDO was confirmed by Chris Bryant MP, who stated that the government had been aware since October 2025. The minister has claimed that the risk of compromise to individual data was ‘low’. While Bryant claimed that the perpetrators were ‘unclear’, The Sun newspaper has pointed fingers at a Chinese hacking group named Storm 1849, who were behind the ‘ArcaneDoor’ campaign affecting Cisco infrastructure in 2024. 

The cyberattack against Westminster City Council took place in late November, with confirmation from the council that data had been copied by the perpetrators, which potentially included sensitive council data. This also included data on a server that was shared between Westminster City Council and Kensington and Chelsea Council, however Westminster Council remains primarily affected. The perpetrators are currently unclear.

Westminster Council has urged residents to follow NCSC advice and be wary of any suspicious calls or emails, and has set up a helpline and email address to assist with any public enquiries relating to the cyber incident.


Insights

What to expect from CBN in 2026

CBN will be ramping up its advocacy work in 2026, with the year set to be pivotal legislative and strategic year in the UK cyber landscape. Our work will focus on engaging proactively with the Government on key areas that directly impact our community and expand member’s opportunities within the UK market.
Cyber Security & Resilience Bill: With the expectation of Royal Assent later this year , this legislation will undergo extensive parliamentary scrutiny in early 2026, modernising and strengthening UK cyber defences, including the expansion of NIS/NIS2. CBN is taking a proactive role in advocacy to shape the bill’s legislation and implementation.

Policy & Political


New Chief of SIS focuses on cyber and technology in first major speech

Blaise Metrewelli, the newly appointed chief of the UK’s Secret Intelligence Service (SIS), more commonly known as MI6, emphasised the organisation’s focus on enhancing its technological and cybersecurity capabilities in a speech delivered on the 15th December 2025.

Metrewelli claimed that SIS is currently operating in a ‘space between peace and war’, in which advanced technologies are reshaping conflict, power and trust globally. She highlighted how converging fields such as AI, biotechnology, and quantum computing are accelerating threats to UK national security. 

She stressed that information had become weaponised through disinformation and manipulation tactics, exemplified by increasing threats posed by Russian hybrid warfare, including cyberattacks, drones, sabotage, and influence operations.

In response, SIS is refocusing its efforts on mastering its use of technology, particularly around AI and data, and integrating it into their work such that  officers are as comfortable with code as with human sources.

This would see the SIS deepen partnerships across the UK intelligence community and the wider technology ecosystem, recognising that the defining issue is not who has the most powerful tech, but who can apply it effectively.


The UK and South Korea agree to enhance cyber collaboration in a new joint statement

The governments of the UK and South Korea agreed a joint statement on deepening technology ecosystems and strengthening digital collaboration, following the second UK-ROK (Republic of Korea) Digital Partnership Forum in Seoul, on 16th December 2025.

Four key pillars were agreed as part of the joint statement. These pillars are: strengthening digital infrastructure, fostering technological innovation, reinforcing multi-stakeholder approaches, and enhancing cybersecurity and securing critical technologies

The fourth pillar sees a commitment from both states to further collaborate to strengthen cybersecurity, within the framework of the last UK-ROK Cyber Dialogue, which saw the UK and South Korea commit to working together to counter malicious cyber activity from malign states, namely North Korea, Russia and China. 

With the new joint statement, both states have renewed this commitment, as well as reinforcing a particular focus on the growing role of AI within the cybersecurity field.


NCSC Updates


Business & Industry

NHS Supplier DXS International confirms cyberattack

DXS International, a provider of clinical solutions for healthcare professionals and patients to the NHS, confirmed that they experienced a cyberattack on their office servers on the 14th December 2025. 

The incident has been reported as having ‘minimal impact on the company’s services’, leaving front-line clinical services ‘unaffected and operational’.

The prolific ransomware threat actor ‘DevMan’ claimed responsibility, stating that they had copied around 300GB of data, threatening to release it publicly. However, neither the NHS nor DXS have commented on this claim.


Scattered Spider attacks cost UK retailers millions in damages

Cyberattacks against major UK retailers are estimated to have cost affected businesses millions of pounds in damages. Two of the worst affected were M&S and the Co-op Group, who are estimating losses of approximately £300m and £200m respectively.

Taking place between April and May of 2025, the attacks utilised the DragonForce ransomware, with social engineering tactics deployed, such as voice phishing, to compromise company networks via internal IT helpdesks. Hackers then activated the main ransomware payload across compromised systems.. 

These attacks triggered serious disruption to the businesses, causing data loss and outages that led to a depreciation of the companies stock and revenue prices.  


Events

CBN January Member Meeting

CBN is holding its first bi-monthly members meeting of 2026 in London, on Wednesday, 21st January, 4:30pm – 7:30pm. This event will comprise of a roundtable style discussion to help shape our 2026 agenda, as well as a discussion around ongoing developments regarding the Cyber Security and Resilience Bill, following its second reading in the Commons this month.

Please note: This vital session is exclusively for paying members and partners. If you’d be interested in attending the event, please RSVP to secretariat@cb-network.org.

To become a member and ensure you won’t miss any of our events, please visit ​​cb-network.org/join-us/


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.

CBN Newsletter | December 2025

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector. 

This month, we take a look at our Inaugural Parliament & Cyber Conference, the Government’s Autumn budget, alongside a raft of other public and private sector announcements.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch. 

never miss a thing

Sign up for news and upcoming events

Headlines


Security Minister speaks at Parliament and Cyber Conference 

Minister for Security Dan Jarvis delivered the keynote speech at our first Parliament and Cyber Conference 2025, in which he called for stronger cyber resilience across government, business and society with the escalation of cyber threats in a hyper-connected world. 

Jarvis highlighted how, if cybercrime were an economy, it would be the third biggest in the world with global scams expecting to cost $27 trillion a year by 2027. The government is seeking to act with both legislation and policy, including the recently introduced Cyber Security and Resilience Bill, and the Counter Political Interference and Espionage Action Plan as well as support of the NCSC.

During his address at the conference, Jarvis noted that “Our tech sector is one of the most crucial chips in the economy’s motherboard. One that takes its cyber security seriously. I hope that, through Government support and their own initiative, that the rest of our business leaders follow in your footsteps.”


Government’s publishes Cyber Security and Resilience Bill

The Government introduced the Cyber Security and Resilience Bill for its First Reading in the House of Commons on 12 November 2025, marking the first time a UK Bill has included “cyber” in its title. The legislation represents a significant effort to modernise the UK’s cyber framework by expanding the scope of regulated services, strengthening reporting requirements and providing regulators with enhanced tools to enforce compliance. It builds on the Cyber Governance Code of Practice published in April 2025 and further develops the UK’s NIS regime, bringing it closer, though not fully in line with, the EU’s NIS2 directive.

The Bill widens the range of organisations subject to cybersecurity standards, introducing data centres as essential services under joint oversight from Ofcom and the DSIT Secretary of State.The Bill also, amongst other provisions:

Please contact secretariat@cb-network.org for more information on the Bill.


Policy panel: Designing a resilient future

At the Parliament and Cyber Conference, during the Panel “UK cyber policy: designing a resilient future”, speakers, including Cyber Innovation APPG officer Alison Griffiths MP, and Jonathon Ellison, National Resilience Director at the NCSC  emphasised the scale of the challenge and the importance of ensuring the Bill is implemented in a way that is both effective and proportionate. 

Across our events, there was clear consensus from both public and private sector voices on the need for sustained cross‑collaboration as the Bill progressed through Parliament, with particular focus on proportional definitions, workable reporting obligations and transparent approaches to designating critical suppliers.


Innovation panel: Securing our future in a world of AI and quantum 

The second panel at Parliament and Cyber Conference 2025, titled  “The next frontier: securing our future in a world of AI and quantum,” examined how emerging technologies are reshaping both opportunity and risk for the UK.

Artificial intelligence was discussed as a major driver of growth and productivity, but panellists underlined how it has already begun to transform the cyber threat landscape. Panellists highlighted escalating AI enabled fraud, the potential misuse of generative tools, and complex questions of accountability in autonomous defence systems. Looking ahead, they noted that the emergence of quantum computing could further disrupt existing cyber security protocols and undermine many of today’s cryptographic standards.

The panel focused on how the government can respond with agile and effective policy, working closely with industry to strengthen resilience and protect both the economy and wider society. 

Speakers included Daniel Aldridge MP, Chair of the APPG for Cyber Innovation, Zeki Turedi, Field CTO at CrowdStrike, Shaukat Ali Khan, CDIO at NHS West Yorkshire, Dr Melanie G., Associate Professor at UCL, and Sean Remnant, CSO at Exclusive Networks. 


Insights

What to expect in 2026 from CBN

Following our Conference it was clear that cyber resilience is now firmly established as a national priority.

With more than 150 parliamentarians, policymakers, academics and industry leaders there was a clear consensus from both public and private sector voices emphasising the need for sustained cross‑collaboration as the Bill progresses through Parliament, with particular focus on proportional definitions, workable reporting obligations and transparent approaches to designating critical suppliers.

In 2026, CBN looks forward to working constructively with the Government as it sets out its plans across Cyber Security, most notably the Cyber Security & Resilience Bill, as well as the forthcoming  National Cyber Action Plan, and broader government approaches. We are excited to develop on the progress made this year, including supporting the APPG for Cyber Innovation, to create further opportunities for engagement with key stakeholders. 

Please do get in touch with the team at secretariat@cb-network.org for more information. 


Policy & Political

Autumn Budget 2025

After much speculation and anticipation, the Chancellor’s Autumn Budget was unveiled – albeit  following a premature leak from the Office for Budget Responsibility

The Budget was presented as making the “fair and necessary choices” to ease pressures on households, strengthen public services and support growth. 

Cyber was predominantly absent from the Chancellor’s Budget speech. With her self-imposed rules preventing rises to income tax, National Insurance or VAT, she instead relied on freezing income thresholds and introducing a series of wider tax increases to reduce borrowing and create future fiscal headroom. Business rates for retail, hospitality and leisure will be permanently lowered, funded in part by higher rates for the most expensive properties. Notably: 

Technology also featured prominently, with commitments on AI infrastructure and data centres, new AI Growth Zones and a brief reaffirmation of previously published digital ID plans in the context of immigration control and efficiency savings, as well as reaffirmation of defence spending targets. 

Ministers and NCSC write to small business on cyber security

Minister Liz Lloyd, Minister Blair McDougall and the National Cyber Security Centre (NCSC) CEO Richard Horne have written to small businesses reminding them of the resources available to them to ensure that  they remain cyber secure – including the free Cyber Action Toolkit, Cyber Essentials, and Action Fraud.

The signatories urge small businesses to take these steps to remain resilient in the face of increasing cyber attacks; half of small businesses in the UK report having suffered a cyber attack in the previous 12 months and 35% of micro businesses reported phishing attacks.

The NCSC has also published a dedicated blog on these available resources, which can be seen here.

NCSC Stop! Think Fraud campaign

The NCSC has launched a nationwide Stop! Think Fraud campaign, offering advice to individuals and small businesses ahead of the busy festive period. The campaign encourages online shoppers to follow tips from the Home Office and the NCSC to avoid online scams, with individuals encouraged to report suspicious activity to the NCSC. 

Cyber recruits graduate from Defence Cyber Academy

An inaugural group of around 30 graduates will enter operational roles in cyber defence following their training at Defence Cyber Academy on their fast-track Cyber Direct Entry programme, with new training places available for people aged 18-39 for 2026.

The graduates will be joining the new Defence Cyber & Electromagnetic Force (DCEMF).

The entry route sees basic training reduced from 10 weeks to around one month, after which recruits undergo three months’ specialist training. 

In 2025, the UK faced 18 major cyber incidents – an almost 50% increase on the previous year and the third consecutive annual rise.

Research and analysis: Research on mapping the AI and software cyber security services market

The government is carrying out research on mapping the AI and software cyber security services market. Commissioned by DSIT, this project aims to better understand the skills, services, and tools available to support organisations in the UK in meeting the requirements of the Global Standard for AI Cyber Security and the Software Security Code of Practice.

The research will build on this market analysis, and will consist of a telephone survey of UK-based organisations that provide AI and/or software cyber security services.

NCSC Updates

Parliamentary Questions

This past month, questions were answered on army recruitment into their cyber stream, the growth of a grey area in cyber defence investment, and cyber-security based amendments to regulations of telecoms infrastructure One debate highlighted the role of the Council of Europe in tackling cyber crime, and the yearly debate on Remembrance Day outlined the growth of military personnel specialising in cyber warfare. The need to highlight cybersecurity training amongst SME’s was outlined,  and the House of Commons Business and Trade Committee outlined the need for cybersecurity to form part of an economic security safeguard for businesses. The Government further announced cyber counter-measures against Chinese espionage. 


Business & Industry

Major UK altnet data breach highlights supply chain risk

Alternative broadband provider Brsk, which recently merged with Netomnia, reported a major DDoS customer data breach that reportedly exposed around 230,000 customer records for sale on a hacking forum. The compromised database included names, email addresses, physical addresses, phone numbers, installation and booking details, internal IDs, location data and indicators of vulnerable customer status, although Brsk stated that no financial information, passwords or login credentials were affected.

Cyber attack on London councils triggers emergency response

Westminster City Council and the Royal Borough of Kensington and Chelsea activated emergency and business continuity plans following a cyber attack that disrupted shared IT systems and phone lines. Working with cyber specialists and the National Cyber Security Centre, both councils focused on maintaining critical services and support for vulnerable residents while systems were taken offline and restored.

The Information Commissioner’s Office was notified and investigations into the source, scale and any potential data compromise are ongoing. Other London boroughs, including Hammersmith and Fulham, were also believed to have been affected and were advised to warn staff about phishing risks, including suspicious emails and unexpected links, as services were not expected to be fully restored until later in the week.

KawaiiGPT shows how free AI tools are lowering the barrier to cybercrime

The growing use of KawaiiGPT has been outlined as aiding in lowering the barrier to commit cybercrime. KawaiiGPT, a free, open source “black hat” large language model that has been available since July 2025 and is now at version 2.5. Unlike paid tools such as WormGPT, KawaiiGPT could be installed from GitHub in minutes and used via a simple command line interface to generate convincing phishing emails, ransomware notes and working attack scripts, enabling even low skilled individuals, referred to informally as “script kiddies”, to launch sophisticated campaigns. With hundreds of users coordinating via Telegram, the tool illustrated how freely available offensive AI was compressing attack cycles and eroding traditional warning signs such as poor grammar, reinforcing the need for AI aware email filtering, anomaly detection and broader defensive controls.

Cyberattack exposes customer data of major financial institutions 

Real estate finance and tech vendor SitusAMC disclosed a cyber attack that may have exposed customer data from several leading US banks, including JPMorgan, Morgan Stanley and Citi, as well as other top‑tier institutions. The firm, which processes mortgage payments and manages real estate loan data for many of the top 20 US banks, reported that corporate accounting records, legal agreements and some client customer details were accessed, although no encrypting malware was involved. The incident currently remains under FBI investigation.


Events

Members should keep their eyes peeled as we will be launching our 2026 events and activity in the coming weeks.


Partner Events

Sign up for the CCUK Fraud Summit 2026

We are excited to announce the return of our highly anticipated Fraud Summit 2026, bringing together the industry’s most authoritative voices. CCUK is currently looking sponsors for the event, and has a range of sponsorship packages. 

Join CCUK on Wednesday 15th April 2026 at One Birdcage Walk in London for our second annual summit. We’ve built on the success of last year to create an even more powerful, insightful agenda focused on actionable intelligence and collaborative solutions.

This is your opportunity to gain unparalleled access to the decision-makers and experts who are shaping the UK’s response to security threats.

This year’s programme will feature an elite lineup of speakers from every critical sector, ensuring you get a 360-degree view of the fraud landscape. Connect with industry peers and key stakeholders in a focused, professional setting.

CBN members get discounted tickets, secure yours here

Would you like to raise your company profile by being the event’s supporter? Check our sponsorship pack here and contact team@commscouncil.uk for more information. 

Please do contact team@commscouncil.uk for more information. 


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

Membership to CBN is free for all cybersecurity organisations. If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.