CBN Newsletter | August 2026

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.

This month, we examine the fallout from a wave of government data breaches, the machinery of government changes reshaping the Burnham government’s approach to cyber, and what recent AI containment incidents at OpenAI and Anthropic mean for those managing frontier AI risk.

If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.

never miss a thing

Sign up for news and upcoming events

Headlines

Photo credits: National Crime Agency (NCA)

Third government hack in a week exposes details of 100,000 police staff

Full names and contact details belonging to more than 100,000 police officers and staff have appeared on the dark web, following a breach that also touched the Ministry of Defence, Home Office, National Crime Agency and Crown Prosecution Service. Reported by The Times on the 2nd August, this marks the third such incident to hit the government in a week, after the Department for Education had over half a million records compromised only days earlier.

The breach originated in the Police National Legal Database (PNLD), a system used by officers across England and Wales for day-to-day legal guidance. A group calling itself ExfilSquad is believed responsible, having compromised 114,000 subscribers to the database along with smaller numbers of staff at the CPS, Home Office, NCA and MoD. Very little is known about ExfilSquad, however details are expected to emerge in the coming days.

The pattern points to a wider problem than any single system failing. ExfilSquad has also claimed attacks on Newcastle University, two US city governments and, unconfirmed, Microsoft customer records including password hashes.

ESET’s Jake Moore noted that government bodies are increasingly viewed as softer targets, often because underinvestment in basic protections leaves legacy systems exposed. This is something that the government has tried to address, such as through the £210 million Government Cyber Action Plan announced in January this year.

If you have any questions about this breach, or about the government’s current resilience measures, please feel free to get in touch at secretariat@cb-network.org.


Autonomous AI models breach containment: what the OpenAI and Anthropic incidents mean for cyber risk

Within days of each other, OpenAI and Anthropic both disclosed that their frontier models had broken out of controlled testing environments. Firstly, on the 21st July, OpenAI announced an unreleased model, built to work autonomously for long stretches, hit a sandbox restriction while testing a training improvement and found a way around to obtain test solutions directly from Hugging Face’s production database.

The following week, Anthropic announced an equally concerning incident. During ‘Capture the Flag’ exercises that strip away standard safeguards to test raw offensive capability, three models, including Claude Opus 4.7 and Claude Mythos 5, moved beyond their intended sandbox and touched real enterprise infrastructure rather than the isolated environment that the exercise was meant to confine them to.

While neither case indicated any malicious intent and both incidents were addressed quickly, this represents a worrying development for those working with frontier AI security models. Older models tend to stop when they hit a wall of this nature. However, models built to work independently for hours or days treat that wall as a problem to solve.

Both incidents were caught because deployment was limited and monitored, with the ability to pause and roll back. As agentic systems take on longer, more open-ended tasks, boards and security leaders will need assurance that a model’s entire course of action can be understood and stopped.


Policy & Political

Burnham government abolishes the Department of Science, Innovation and Technology – what does it mean for cyber?

New Prime Minister Andy Burnham has set out to dismantle the Department for Science, Innovation and Technology, with its responsibilities being divided up between the Department of Business, Innovation, Science and Trade, the Department of Digital, Culture, Media and Sport, and the Cabinet Office – returning to a similar structure to how it was in 2022.

Under the new plan, DSIT’s remit would be redistributed across three departments. The Cabinet Office would absorb some responsibilities, a newly created Department of Business, Innovation, Science and Trade would take on others as a merger of DSIT and the Department for Business and Trade, and other remits will move to an expanded Department for Digital, Culture, Media and Sport .

According to an internal memo reported by Computer Weekly, cyber security will fall under the remit of the Department for Digital, Culture, Media and Sport, alongside telecoms, media, online safety and the Government Digital Service (GDS).

Lisa Nandy remains Secretary of State, with her brief formally expanded to restore responsibility for digital policy. Ian Murray stays in the department as Minister of State, the most senior role below the Secretary of State, alongside Stephanie Peacock, Vicky Foxcroft, Baroness Twycross and newly appointed peer Ruth Mackenzie as junior ministers. Baroness Lloyd of Effra has been confirmed as Parliamentary Under-Secretary of State at DCMS, alongside her existing role as Parliamentary Under-Secretary (Digital Economy Minister) at DBIST.

Separately, Kanishka Narayan has been appointed to a new cabinet-level Secretary of State role for AI, signalling that artificial intelligence policy will be treated as a major, standalone priority rather than folded into a broader technology brief.

If you have any questions about what this departmental shakeup might mean for your organisation, feel free to get in touch at secretariat@cb-network.org


Parliament presses government on mandatory ransomware reporting

Gordon McKee, Labour MP for Glasgow South, tabled a question to the Home Office in July whether the government plans to introduce mandatory reporting of ransomware incidents and payments, putting fresh parliamentary attention on proposals that have been in the works since last year’s consultation.

Home Office Minister Sarah Jones MP replied, stating that the measures are designed to strike at the ransomware business model by giving law enforcement more information and sharpening the government’s understanding of the threat landscape. Bringing ransomware activity out of the shadows, she said, will improve the intelligence picture and support more effective disruption of those responsible.

The exchange follows the Home Office’s consultation on legislative proposals to tackle ransomware, which ran from January to April 2025 and drew 273 responses. The government’s response confirmed it intends to legislate on three fronts. Firstly, as Minister Jones highlighted in her response, mandatory incident reporting would be brought in, requiring all UK organisations to report suspected ransomware incidents regardless of whether a payment was made. This measure drew broad support from consultation respondents at 63%.

Secondly, public sector bodies and CNI operators would face a targeted ban on paying ransoms, with no notification or exemption route, a measure that drew 72% support. Thirdly, businesses outside those categories would instead be required to notify the government before paying a ransom, so authorities can assess the situation and potentially offer alternatives, backed by 47% of respondents.

A 72-hour initial reporting window is under consideration, though which organisations fall in scope and what penalties apply for non-compliance remain undecided. Currently, no date for legislation has been set. CBN will continue to track the Bill’s progress and keep members updated as further detail emerges.


Business & Industry

Britain’s biggest firms sign the government’s Cyber Resilience Pledge as threat landscape continues to change.

More than 60 businesses have signed the Government’s new Cyber Resilience Pledge, launched at 10 Downing Street on 7th July by Technology Secretary Liz Kendall. Founding signatories span retail, financial services, media, utilities and technology, including M&S, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte, Accenture UK etc.

As a reminder, the Pledge is voluntary and designed principally for medium and large organisations, though open to any sector or size. It asks signatories to take three concrete actions: to treat cyber security as a board-level responsibility by adopting the Cyber Governance Code of Practice and completing the NCSC’s Cyber Governance Training at board level; to register for the NCSC’s free Early Warning service, which flags suspicious activity on organisational networks; and to take a risk-based approach to mandating Cyber Essentials certification across an organisation’s supply chains.

The pledge was introduced against the backdrop of an increasingly dangerous cybersecurity landscape. According to the government’s Cyber Breaches Survey, over 5 million cyber crimes were committed against UK firms in the past year, which is roughly one every six seconds. while the NCSC handled 204 nationally significant incidents in the year to September, up from 89 in 2025.

The Pledge is a central part of the government’s upcoming National Cyber Action Plan, which will set out further investment in AI-powered defensive capabilities. If you have any questions about the pledge, please feel free to get in touch at secretariat@cb-network.org.


CBN Updates

Cyber Innovation APPG hears from parliamentary roundtable on digital sovereignty in the UK

On the 15th July, members of the APPG for Cyber Innovation convened a roundtable discussion with industry, academics, and parliamentarians to test working definitions, compare the UK’s position with the EU and other international partners, and identify where policy or governance gaps most need addressing.

The discussion was chaired by Lord Clement-Jones who opened by noting that ‘digital sovereignty’ is a term widely used but without a universal definition. Participants how sovereignty could be defined, separating sovereignty into three layers: technological sovereignty (owning the technology), operational sovereignty (the ability to switch providers) and governance (a UK-specific trustworthy framework).

There was some divergence on views around alignment with international standards, including the EU’s digital sovereignty package in June. Delegates also examined the merits of establishing a codified digital sovereignty strategy, and how this could also act as a potential area for growth in UK tech.

To read the full write-up from the event, please click here. If you’d like to contact the APPG secretariat, please send an email to secretariat@cb-network.org with the subject line: “For the attention of the APPG:”.


NCSC Updates


About CBN

The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.

As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.

If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.